Secure Out-of-Band Cryptoprocessor for Trusted Boot and Runtime Operation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing BIOS software distribution model exposes hardware intellectual property and increases support complexity and security risks as it provides source code to OEMs and IBVs, leading to IP concerns and malware vulnerabilities, especially with varying platform configurations and malicious attacks.
Innovation Solution
A secure out-of-band cryptoprocessor with semiconductor integrated code (SIC) maps UEFI variables into TPM non-volatile storage, providing a generic access method and secure storage using read-only and write-only attributes, ensuring confidentiality and integrity of initialization code and variables.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If source code is provided to OEMs and IBVs for BIOS development, then platform adaptability and customization capability are improved, but hardware intellectual property protection deteriorates and security vulnerabilities increase
Solution Approach 1:
The patent extracts the BIOS code from the traditional distribution model and places it within the processor itself as integrated code. This extraction removes the code from external exposure while maintaining its functionality across different platforms through standardized interfaces.
Solution Approach 2:
The patent introduces an intermediary layer (the processor's integrated BIOS code) that mediates between the hardware and various platform configurations. This intermediary provides standardized access points that allow platform adaptability without exposing the underlying code to OEMs and IBVs.
2Adaptability or versatility
If source code is distributed to multiple vendors, then platform configuration flexibility is improved, but support complexity and manufacturing costs increase
Solution Approach 1:
The patent segments the BIOS functionality into two parts: core code integrated in the processor (maintained by the silicon manufacturer) and platform-specific configuration interfaces (accessible to OEMs and IBVs). This segmentation centralizes code management while preserving configuration flexibility.
Solution Approach 2:
The patent creates a universal BIOS interface within the processor that can serve multiple platform configurations. This single integrated solution provides multi-functionality across different vendors and platforms, eliminating the need for multiple code versions and reducing support complexity.
3Ease of operation
If traditional BIOS distribution is used, then ease of customization for OEMs is improved, but security against malware deteriorates
Solution Approach 1:
The patent implements preliminary security actions by integrating the BIOS code directly into the processor during manufacturing. This preliminary action ensures that the code is established in a trusted state before the system operates, preventing malware injection that would otherwise be possible with distributed code.
Solution Approach 2:
The patent converts the potential harm of code distribution into a benefit by using the processor's inherent security features (such as secure boot and code execution controls) to protect the integrated BIOS code. The same integration that prevents customization also provides inherent security against malware.
Data Source
AI summary
An embodiment includes an apparatus comprising: an out-of-band cryptoprocessor including secure non-volatile storage that couples to a root index, having a fixed address, and comprises first and second variables referenced by the root index; and semiconductor integrated code (SIC) including embedded processor logic to initialize a processor and embedded memory logic to initialize a memory coupled to the processor; wherein (a) the SIC is to be executed responsive to resetting the processor and prior to providing control to boot code, and (b) the SIC is to perform pre-boot operations in response to accessing at least one of the first and second variables. Other embodiments are described herein.


