Secure BIOS Mechanism with Tamper Detection and Randomized Checks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing a Basic Input/Output System (BIOS) in computing systems face challenges in balancing accessibility for upgrades with the need to protect against unauthorized tampering, as moving BIOS storage onto the microprocessor die restricts upgrades and encryption methods degrade system performance.

Innovation Solution

An apparatus and method that includes a BIOS ROM with plaintext contents and an encrypted message digest, a tamper detector, a random number generator, and a JTAG control chain to periodically check for tampering, using a fuse to disable unauthorized JTAG activities and ensure the integrity of BIOS contents without degrading system performance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BIOS storage is moved onto the microprocessor die to protect from tampering, then security is improved, but ease of upgrade deteriorates

Engineering Contradiction:
ImproveBIOS securityVSAvoidBIOS upgradeability
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The invention separates the BIOS storage into two distinct locations: a first BIOS ROM on the microprocessor die for security-critical functions, and a second BIOS ROM externally accessible for upgradeability. This segmentation allows each component to fulfill its specific function without compromising the other.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a nested structure where the first BIOS ROM (on-die) contains core security functions, while the second BIOS ROM (external) contains additional functionality that can be upgraded. The microprocessor coordinates between these nested layers, allowing the external BIOS to be updated without affecting the secure on-die BIOS.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Reliability

If encryption is applied to BIOS contents to protect from tampering, then security is improved, but system performance deteriorates

Engineering Contradiction:
ImproveBIOS protectionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts only the essential security verification element (message digest) and encrypts it, rather than encrypting the entire BIOS content. This selective encryption approach maintains security while minimizing the performance overhead associated with decryption operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of applying full encryption to all BIOS contents, the patent applies partial encryption only to the message digest portion. This partial action provides sufficient security protection while avoiding the excessive computational burden of encrypting and decrypting the entire BIOS image during system operation.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If frequent BIOS checks are performed to detect tampering, then detection capability is improved, but system performance deteriorates

Engineering Contradiction:
Improvetamper detection capabilityVSAvoidsystem performance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements periodic BIOS integrity checks at predetermined time intervals rather than continuous monitoring. This periodic action provides adequate tamper detection capability while allowing the system to operate normally between checks, thus maintaining system performance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The check interval is made dynamic rather than fixed, allowing the system to adjust the frequency of BIOS integrity checks based on operational conditions. This dynamic approach optimizes the balance between detection capability and performance impact.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentEP3316167B1Programmable secure BIOS mechanism in a trusted computing system
Publication Date: 2021.04.07 VIA TECH INC
  • EP3316167B1 patent drawingFigure 1~2
  • EP3316167B1 patent drawingFigure 3
  • EP3316167B1 patent drawingFigure 4

AI summary

An apparatus is provided for protecting a basic input/output system (BIOS) in a computing system. The apparatus includes a BIOS read only memory (ROM), a tamper detector, a random number generator, and a JTAG control chain. The BIOS ROM includes BIOS contents stored as plaintext, and an encrypted message digest, where the encrypted message digest has an encrypted version of a first message digest that corresponds to the BIOS contents. The tamper detector is operatively coupled to the BIOS ROM, and is configured to generate a BIOS check interrupt at a combination of prescribed intervals and event occurrences, and is configured to access the BIOS contents and the encrypted message digest upon assertion of the BIOS check interrupt, and is configured to direct a microprocessor to generate a second message digest corresponding to the BIOS contents and a decrypted message digest corresponding to the encrypted message digest, and is configured to compare the second message digest with the decrypted message digest, and is configured to preclude the operation of the microprocessor if the second message digest and the decrypted message digest are not equal. The random number generator disposed within the microprocessor, and generates a random number at completion of a current BIOS check, which is employed to set a following prescribed interval, whereby the prescribed intervals are randomly varied. The JTAG control chain is configured to program the combination of prescribed intervals and event occurrences within tamper detection microcode storage.