Security Processor Configuration Certificate Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing Information Handling Systems (IHSs) lack effective mechanisms for validating the authenticity and integrity of configurations and components, particularly during transfers of ownership and usage, which can lead to security and reliability issues.

Innovation Solution

The integration of security processors within IHSs that generate and manage configuration certificates, utilizing embedded certificate authorities to validate pre-boot configurations and authenticate hardware components, allowing for secure transfer and management of security credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security processors are integrated into IHS to validate configuration authenticity, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improveconfiguration authenticity validationVSAvoidsecurity processor integration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A security processor is introduced as an intermediary component between the IHS configuration and the validation process. The security processor contains an embedded certificate authority that issues digital certificates for pre-boot configurations, enabling third-party or remote validation of configuration authenticity without requiring complex validation logic in the main IHS system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security processor performs preliminary actions by generating and storing signed configuration certificates during factory provisioning or trusted administration, before the IHS is deployed or before configuration changes occur. This allows rapid validation later by simply comparing current configurations against the pre-stored signed certificates.

Inventive Principle:
Principle #10Preliminary action

2Stability of the object's composition

If configuration certificates are generated and stored during factory provisioning, then configuration integrity is improved, but manufacturing complexity increases

Engineering Contradiction:
Improveconfiguration integrityVSAvoidfactory provisioning process
Core Design Contradiction:
Stability of the object's compositionVSEase of manufacture

Solution Approach 1:

The security processor is designed to autonomously generate and store configuration certificates during factory provisioning without requiring external validation infrastructure. The embedded certificate authority within the security processor enables self-service certificate generation, eliminating the need for complex external certificate management systems during manufacturing.

Inventive Principle:
Principle #25Self-service

3Reliability

If pre-boot configuration validation is implemented, then security against tampering is improved, but boot time increases

Engineering Contradiction:
Improvetamper protectionVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Configuration certificates are generated and stored in advance during factory provisioning or trusted administration, before deployment or before configuration changes. This preliminary action enables rapid validation during boot by simply comparing current pre-boot configurations against the pre-stored signed certificates, avoiding time-consuming cryptographic verification operations during the critical boot process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11822668B2Systems and methods for authenticating configurations of an information handling system
Publication Date: 2023.11.21 DELL PROD LP
  • US11822668B2 patent drawing
  • US11822668B2 patent drawing
  • US11822668B2 patent drawing

AI summary

As part of a factory provisioning of an Information Handling System (IHS), a configuration certificate is stored that identifies a pre-boot configuration of the IHS resulting from the factory provisioning. Upon a transfer of control or ownership of the IHS, a pre-boot configuration of the IHS is identified and the configuration certificate is utilized to validate that the identified pre-boot configuration is the same as the pre-boot configuration of the IHS resulting from the factory provisioning. A security processor of the IHS may support boot code operations for generating additional configuration certificates that can be used to validate the integrity of any changes the IHS configuration, such as upon its next power cycle.