Secure SMI Memory Services for System Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems are vulnerable to destructive attacks on system memory, which can lead to data compromise and system failure, especially with the increasing complexity of memory usage and cost associated with erroneous behavior.
Innovation Solution
A system and method for providing secure System Management Interrupt (SMI) memory services that allocates memory for SMI drivers and ensures secure erasure of memory contents before exiting, preventing data leakage and reducing system costs by protecting against malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If memory size increases to meet growing information storage needs, then storage capacity is improved, but the likelihood of defective memory cells increases
Solution Approach 1:
The patent implements preliminary detection of memory defects during manufacturing or initialization, creating a map of defective cells before the system enters service. This preliminary action allows the system to proactively avoid using defective memory cells, thus maintaining high reliability while utilizing large memory capacity.
Solution Approach 2:
The patent introduces an intermediary layer (memory management software or firmware) that sits between the CPU and physical memory cells. This intermediary translates logical memory addresses to physical addresses, routing requests away from defective cells and redirecting them to functional equivalents, thereby maintaining reliability without reducing capacity.
2Productivity
If system memory is made more accessible for processing, then processing efficiency is improved, but vulnerability to destructive attacks increases
Solution Approach 1:
The patent segments memory into distinct security zones or compartments with different access privileges. Critical data and code are placed in protected segments that require authentication or specific permissions to access, while less sensitive areas remain more accessible. This segmentation allows efficient processing in open areas while protecting critical resources from attacks.
Solution Approach 2:
The patent implements preliminary security measures such as memory encryption, authentication mechanisms, and access control lists that are established before any processing occurs. These preliminary anti-actions prevent malicious code from corrupting memory or accessing protected data, even when memory is highly accessible for normal processing operations.
3Use of energy by moving object
If memory is frequently accessed for energy conservation mode operations, then energy efficiency is improved, but risk of data compromise increases
Solution Approach 1:
The patent introduces an intermediary security layer that monitors and controls all memory access operations, including those during energy conservation modes. This intermediary verifies the legitimacy of each access request and ensures proper authentication, allowing frequent memory access for power management while preventing unauthorized or malicious access that could compromise data security.
Data Source
AI summary
In accordance with the present disclosure, a system and method are herein disclosed for providing secure SMI memory services, including the protection of SMM memory from surreptitious attacks by, for example, rootkits. Information handling systems are susceptible to attacks, especially attacks on SMM memory. In one example, an SMI handler corresponding to the SMI Driver associated with an SMI interrupt performs validation of a password. An SSMS driver allocates memory for the SMI handler to use with the validation process and also performs a secure erase of allocated memory blocks upon completion of all secure SMI Memory Services. By controlling the validation and secure erase process through the use of the SMI handler and SSMS driver, information leakage can be prevented resulting in system data integrity.


