Secure Boot Firmware for Service Processor Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service processors in computing systems are vulnerable to attacks that modify firmware or software, compromising system security and integrity, especially since they control critical aspects of host systems.

Innovation Solution

Implementing a secure boot mechanism using a tamper-resistant secure trusted dedicated microprocessor, combined with an integrity management subsystem, to record and verify measurements of software and firmware, ensuring only trusted and unmodified code is executed, and continuously monitoring for any modifications or attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a service processor is used to provide remote monitoring and management of host systems, then system control and monitoring capabilities are improved, but vulnerability to attacks that modify firmware or software increases

Engineering Contradiction:
Improveremote monitoring and management capabilityVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements secure boot firmware that executes before the operating system kernel to record measurements of boot code in tamper-resistant registers. This preliminary action establishes a trusted foundation before the system becomes operational, preventing malicious code from executing without detection.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an integrity management subsystem as an intermediary layer between the boot firmware and the operating system. This subsystem continuously monitors and records measurements of executed code, acting as a mediator that detects and prevents unauthorized modifications without interfering with normal system operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure boot firmware is implemented to record measurements in tamper-resistant registers, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the security functionality into distinct segments: secure boot firmware for initial measurement recording, an integrity management subsystem for continuous monitoring, and an operating system kernel with security policies. This segmentation allows each component to have a specific, well-defined security responsibility, making the overall system more manageable despite increased functionality.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If an integrity management subsystem is enabled to record measurements of executed software, then detection of unauthorized changes is improved, but processing overhead increases

Engineering Contradiction:
Improvedetection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The integrity management subsystem implements selective monitoring by recording measurements of specific security-relevant files and code segments rather than all executed software. This partial action approach provides sufficient security detection capability while minimizing the processing overhead associated with continuous full-system monitoring.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11176255B2Securely booting a service processor and monitoring service processor integrity
Publication Date: 2021.11.16 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11176255B2 patent drawing
  • US11176255B2 patent drawing
  • US11176255B2 patent drawing

AI summary

Mechanisms for booting a service processor are provided. With these mechanisms, the service processor executes a secure boot operation of secure boot firmware to boot an operating system kernel of the service processor. The secure boot firmware records first measurements of code executed by the secure boot firmware when performing the boot operation, in one or more registers of a tamper-resistant secure trusted dedicated microprocessor of the service processor. The operating system kernel executing in the service processor enables an integrity management subsystem of the operating system kernel which records second measurements of software executed by the operating system kernel, in the one or more registers of the tamper-resistant secure trusted dedicated microprocessor.