Secure Out-of-Band Cryptoprocessor for Trusted Boot and Runtime Operation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing BIOS software distribution model exposes hardware intellectual property and increases support complexity and security risks as it provides source code to OEMs and IBVs, leading to IP concerns and malware vulnerabilities, especially with varying platform configurations and malicious attacks.

Innovation Solution

A secure out-of-band cryptoprocessor with semiconductor integrated code (SIC) maps UEFI variables into TPM non-volatile storage, providing a generic access method and secure storage using read-only and write-only attributes, ensuring confidentiality and integrity of initialization code and variables.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If source code is provided to OEMs and IBVs for BIOS development, then platform adaptability and customization capability are improved, but hardware intellectual property protection deteriorates and security vulnerabilities increase

Engineering Contradiction:
Improveplatform adaptabilityVSAvoidIP exposure and security risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the BIOS code from the traditional distribution model and places it within the processor itself as integrated code. This extraction removes the code from external exposure while maintaining its functionality across different platforms through standardized interfaces.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary layer (the processor's integrated BIOS code) that mediates between the hardware and various platform configurations. This intermediary provides standardized access points that allow platform adaptability without exposing the underlying code to OEMs and IBVs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If source code is distributed to multiple vendors, then platform configuration flexibility is improved, but support complexity and manufacturing costs increase

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsupport complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the BIOS functionality into two parts: core code integrated in the processor (maintained by the silicon manufacturer) and platform-specific configuration interfaces (accessible to OEMs and IBVs). This segmentation centralizes code management while preserving configuration flexibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates a universal BIOS interface within the processor that can serve multiple platform configurations. This single integrated solution provides multi-functionality across different vendors and platforms, eliminating the need for multiple code versions and reducing support complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If traditional BIOS distribution is used, then ease of customization for OEMs is improved, but security against malware deteriorates

Engineering Contradiction:
Improvecustomization easeVSAvoidsecurity against malware
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements preliminary security actions by integrating the BIOS code directly into the processor during manufacturing. This preliminary action ensures that the code is established in a trusted state before the system operates, preventing malware injection that would otherwise be possible with distributed code.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent converts the potential harm of code distribution into a benefit by using the processor's inherent security features (such as secure boot and code execution controls) to protect the integrated BIOS code. The same integration that prevents customization also provides inherent security against malware.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS9384352B2Trusted boot and runtime operation
Publication Date: 2016.07.05 SK HYNIX NAND PRODUCT SOLUTIONS CORP
  • US9384352B2 patent drawing
  • US9384352B2 patent drawing
  • US9384352B2 patent drawing

AI summary

An embodiment includes an apparatus comprising: an out-of-band cryptoprocessor including secure non-volatile storage that couples to a root index, having a fixed address, and comprises first and second variables referenced by the root index; and semiconductor integrated code (SIC) including embedded processor logic to initialize a processor and embedded memory logic to initialize a memory coupled to the processor; wherein (a) the SIC is to be executed responsive to resetting the processor and prior to providing control to boot code, and (b) the SIC is to perform pre-boot operations in response to accessing at least one of the first and second variables. Other embodiments are described herein.