Processor Firmware Update Manager for SoC Component Independence
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing SoC firmware update processes rely heavily on security controllers, limiting the independence of individual components and requiring migration of services to achieve self-sufficiency, which complicates the integration and verification of firmware updates.
Innovation Solution
A processor-based approach that utilizes a component firmware update manager and microcode to verify the authenticity and integrity of firmware updates, allowing components to securely load and apply updates independently without relying on security controllers, using a firmware verification instruction and secure memory regions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a security controller is used to verify and manage firmware updates for multiple IPs, then centralized security control is achieved, but component independence and system complexity are reduced
Solution Approach 1:
The patent divides the firmware verification function into two parts: the security controller verifies the manifest (centralized verification), while each IP block independently verifies its own firmware using its embedded public key (decentralized verification). This segmentation allows the security controller to step back after manifest verification, enabling IP independence while maintaining overall security.
Solution Approach 2:
Each IP block is equipped with its own public key and firmware verification capability, allowing it to independently verify its firmware against the manifest without requiring the security controller to be involved in every verification operation. This self-service approach enhances component independence while maintaining security through the manifest-based verification mechanism.
2Reliability
If firmware verification is centralized in a security controller, then unified security policy is enforced, but update speed and component autonomy are reduced
Solution Approach 1:
The manifest containing verification data for multiple IP firmware is prepared in advance and stored in a accessible location. This preliminary preparation allows IP blocks to independently and rapidly verify their firmware without real-time intervention from the security controller, significantly speeding up the update process while maintaining security through pre-established verification criteria.
Solution Approach 2:
The manifest acts as an intermediary that carries verification data from the security controller to multiple IP blocks. Once the security controller creates and stores the manifest, it serves as a self-service verification mechanism that eliminates the need for continuous security controller involvement in individual firmware verification operations, thereby improving update speed.
3Ease of operation
If IP blocks depend on the security controller for firmware loading, then centralized management is achieved, but integration complexity and verification difficulty increase
Solution Approach 1:
The patent extracts the firmware verification function from the security controller and embeds it directly into each IP block through embedded public keys. This extraction allows IP blocks to independently verify and load their firmware without relying on the security controller, reducing integration complexity and verification difficulty while maintaining manageable security through the manifest-based approach.
Data Source
AI summary
Apparatuses, methods and storage mediums associated with updating firmware of a component of a computer platform, are disclosed herein. In some embodiments, a processor includes an instruction decoder; and a storage having microcode arranged to implement an instruction to verify updates to firmware of a component of a computer platform hosting the processor and the component. The computer platform may include a component firmware update manager. The firmware of a component may include a firmware update plug-in. Other embodiments are also described, and may be claimed.


