Security Processor Memory Training Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems are vulnerable to attacks due to the lack of authentication of BIOS execution code during boot-up, which allows malicious users to compromise the system if the authentication window is not managed effectively.

Innovation Solution

A security processor is used to load and authenticate multiple blocks of data from boot media, including bootloaders and configuration blocks, to initialize and train the system memory before releasing the main processors from reset, ensuring secure execution of the BIOS code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the BIOS execution code is authenticated during boot-up, then system security is improved, but the boot-up time increases

Engineering Contradiction:
Improvesystem securityVSAvoidboot-up time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-authenticating the BIOS execution code during the boot-up process before it is executed. The security processor authenticates the BIOS code stored in system memory during initialization, ensuring that only authenticated code can be executed by the main processor. This preliminary authentication step closes the security vulnerability window while minimizing boot-up time impact by performing authentication during the essential boot sequence rather than adding it as a separate post-processing step.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If the window between authenticating and executing the BIOS code is extended, then security verification is improved, but system vulnerability increases

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a security processor as an intermediary component that manages the authentication and execution of BIOS code. The security processor acts as a mediator between the BIOS authentication process and the main processor execution. It loads the BIOS execution code into a protected region of system memory, authenticates it, and then controls its execution. This intermediary mechanism ensures that the BIOS code remains in a secure, authenticated state throughout the execution process, eliminating the vulnerability window that exists in traditional systems where code could be executed before or during authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If a security processor is added to authenticate boot media, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a security processor that performs multiple functions within a single integrated component. The security processor not only authenticates the BIOS execution code but also loads boot media, initializes system memory, and manages the transition of control to the main processor. By consolidating these security-critical functions into a single multi-functional processor, the patent reduces the overall system complexity compared to having separate dedicated components for each function, while still providing comprehensive security verification during the boot-up process.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10311236B2Secure system memory training
Publication Date: 2019.06.04 ADVANCED MICRO DEVICES INC
  • US10311236B2 patent drawing
  • US10311236B2 patent drawing
  • US10311236B2 patent drawing

AI summary

Systems, apparatuses, and methods for performing secure system memory training are disclosed. In one embodiment, a system includes a boot media, a security processor with a first memory, a system memory, and one or more main processors coupled to the system memory. The security processor is configured to retrieve first data from the boot media and store and authenticate the first data in the first memory. The first data includes a first set of instructions which are executable to retrieve, from the boot media, a configuration block with system memory training parameters. The security processor also executes a second set of instructions to initialize and train the system memory using the training parameters. After training the system memory, the security processor retrieves, authenticates, and stores boot code in the system memory and releases the one or more main processors from reset to execute the boot code.