Processor Firmware Update Manager for SoC Component Independence

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing SoC firmware update processes rely heavily on security controllers, limiting the independence of individual components and requiring migration of services to achieve self-sufficiency, which complicates the integration and verification of firmware updates.

Innovation Solution

A processor-based approach that utilizes a component firmware update manager and microcode to verify the authenticity and integrity of firmware updates, allowing components to securely load and apply updates independently without relying on security controllers, using a firmware verification instruction and secure memory regions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security controller is used to verify and manage firmware updates for multiple IPs, then centralized security control is achieved, but component independence and system complexity are reduced

Engineering Contradiction:
Improvefirmware update securityVSAvoidsecurity controller dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the firmware verification function into two parts: the security controller verifies the manifest (centralized verification), while each IP block independently verifies its own firmware using its embedded public key (decentralized verification). This segmentation allows the security controller to step back after manifest verification, enabling IP independence while maintaining overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each IP block is equipped with its own public key and firmware verification capability, allowing it to independently verify its firmware against the manifest without requiring the security controller to be involved in every verification operation. This self-service approach enhances component independence while maintaining security through the manifest-based verification mechanism.

Inventive Principle:
Principle #25Self-service

2Reliability

If firmware verification is centralized in a security controller, then unified security policy is enforced, but update speed and component autonomy are reduced

Engineering Contradiction:
Improvefirmware verification securityVSAvoidfirmware update speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The manifest containing verification data for multiple IP firmware is prepared in advance and stored in a accessible location. This preliminary preparation allows IP blocks to independently and rapidly verify their firmware without real-time intervention from the security controller, significantly speeding up the update process while maintaining security through pre-established verification criteria.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The manifest acts as an intermediary that carries verification data from the security controller to multiple IP blocks. Once the security controller creates and stores the manifest, it serves as a self-service verification mechanism that eliminates the need for continuous security controller involvement in individual firmware verification operations, thereby improving update speed.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If IP blocks depend on the security controller for firmware loading, then centralized management is achieved, but integration complexity and verification difficulty increase

Engineering Contradiction:
Improvefirmware management controlVSAvoidcomponent integration complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the firmware verification function from the security controller and embeds it directly into each IP block through embedded public keys. This extraction allows IP blocks to independently verify and load their firmware without relying on the security controller, reducing integration complexity and verification difficulty while maintaining manageable security through the manifest-based approach.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10789061B2Processor based component firmware update method and apparatus
Publication Date: 2020.09.29 INTEL CORP
  • US10789061B2 patent drawing
  • US10789061B2 patent drawing
  • US10789061B2 patent drawing

AI summary

Apparatuses, methods and storage mediums associated with updating firmware of a component of a computer platform, are disclosed herein. In some embodiments, a processor includes an instruction decoder; and a storage having microcode arranged to implement an instruction to verify updates to firmware of a component of a computer platform hosting the processor and the component. The computer platform may include a component firmware update manager. The firmware of a component may include a firmware update plug-in. Other embodiments are also described, and may be claimed.