Security Processor Memory Training Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems are vulnerable to attacks due to the lack of authentication of BIOS execution code during boot-up, which allows malicious users to compromise the system if the authentication window is not managed effectively.
Innovation Solution
A security processor is used to load and authenticate multiple blocks of data from boot media, including bootloaders and configuration blocks, to initialize and train the system memory before releasing the main processors from reset, ensuring secure execution of the BIOS code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the BIOS execution code is authenticated during boot-up, then system security is improved, but the boot-up time increases
Solution Approach 1:
The patent applies preliminary action by pre-authenticating the BIOS execution code during the boot-up process before it is executed. The security processor authenticates the BIOS code stored in system memory during initialization, ensuring that only authenticated code can be executed by the main processor. This preliminary authentication step closes the security vulnerability window while minimizing boot-up time impact by performing authentication during the essential boot sequence rather than adding it as a separate post-processing step.
2Reliability
If the window between authenticating and executing the BIOS code is extended, then security verification is improved, but system vulnerability increases
Solution Approach 1:
The patent introduces a security processor as an intermediary component that manages the authentication and execution of BIOS code. The security processor acts as a mediator between the BIOS authentication process and the main processor execution. It loads the BIOS execution code into a protected region of system memory, authenticates it, and then controls its execution. This intermediary mechanism ensures that the BIOS code remains in a secure, authenticated state throughout the execution process, eliminating the vulnerability window that exists in traditional systems where code could be executed before or during authentication.
3Reliability
If a security processor is added to authenticate boot media, then system security is improved, but device complexity increases
Solution Approach 1:
The patent implements a security processor that performs multiple functions within a single integrated component. The security processor not only authenticates the BIOS execution code but also loads boot media, initializes system memory, and manages the transition of control to the main processor. By consolidating these security-critical functions into a single multi-functional processor, the patent reduces the overall system complexity compared to having separate dedicated components for each function, while still providing comprehensive security verification during the boot-up process.
Data Source
AI summary
Systems, apparatuses, and methods for performing secure system memory training are disclosed. In one embodiment, a system includes a boot media, a security processor with a first memory, a system memory, and one or more main processors coupled to the system memory. The security processor is configured to retrieve first data from the boot media and store and authenticate the first data in the first memory. The first data includes a first set of instructions which are executable to retrieve, from the boot media, a configuration block with system memory training parameters. The security processor also executes a second set of instructions to initialize and train the system memory using the training parameters. After training the system memory, the security processor retrieves, authenticates, and stores boot code in the system memory and releases the one or more main processors from reset to execute the boot code.


