Processor SMRAM Security via APIC Mapping Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern CPUs using SMRAM and APICs face security threats due to APIC interference with SMRAM, allowing unauthorized access and attacks, compromising the security of proprietary data.

Innovation Solution

Modifications to processors and northbridge designs that include additional registers and logic to track SMRAM location and size, and control APIC mapping, reducing APIC interference and enhancing security by routing requests appropriately during SMM operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the APIC mapping is allowed to be moved freely within physical memory, then the flexibility and adaptability of the system is improved, but the security of SMRAM is compromised due to potential overlap and interference

Engineering Contradiction:
ImproveAPIC mapping flexibilityVSAvoidSMRAM security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary anti-action by detecting potential APIC-SMRAM overlaps before they can cause security breaches. The system proactively identifies when APIC mapping attempts to overlap with SMRAM regions and preemptively blocks or redirects these mappings, preventing the security threat before it materializes. This is achieved through hardware logic that monitors APIC base address register writes and compares them against SMRAM location ranges.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary mechanism between the APIC and SMRAM - a hardware logic component that acts as a mediator to control APIC mapping. This intermediary monitors and manages the interaction between APIC and SMRAM, allowing legitimate APIC operations while blocking unauthorized access to SMRAM. The intermediary translates or redirects APIC memory access requests to prevent direct interference with protected SMRAM regions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If the APIC mapping is placed over SMRAM, then the device complexity is reduced by utilizing existing memory space, but harmful interference with SMRAM operations occurs

Engineering Contradiction:
Improvememory mapping complexityVSAvoidAPIC interference with SMRAM
Core Design Contradiction:
Device complexityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts the harmful interference aspect from the APIC-SMRAM interaction by separating their operational spaces. Instead of allowing direct memory mapping overlap, the system extracts the conflict by implementing dedicated hardware logic that isolates APIC mapping control from general memory management. This extraction ensures that even if APIC and SMRAM share physical memory space, their operational interference is removed through controlled access paths.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by creating different access characteristics for different memory regions. SMRAM regions are given special protected status with restricted access rules, while other memory regions maintain normal APIC accessibility. The hardware logic implements region-specific quality control, allowing APIC to map to unprotected memory spaces while automatically preventing mappings to protected SMRAM regions, thus resolving the conflict through localized access policies.

Inventive Principle:
Principle #3Local quality

3Reliability

If additional registers and logic are added to track SMRAM location and control APIC mapping, then the security of SMRAM is improved, but the processor complexity increases

Engineering Contradiction:
ImproveSMRAM securityVSAvoidprocessor structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the new security functionality with existing processor structures by integrating SMRAM tracking registers and APIC control logic into the existing memory management and interrupt control infrastructure. Rather than adding completely separate security subsystems, the invention combines security functions with existing components, such as utilizing existing base address register mechanisms for APIC and integrating SMRAM location tracking with existing memory management units, thereby reducing the net increase in complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements multi-functionality by designing registers and logic components that serve both traditional purposes and new security functions. For example, existing memory management registers are enhanced to simultaneously handle traditional memory allocation and SMRAM protection tasks. The APIC control logic is designed to universally manage both standard interrupt controller operations and security-critical mapping restrictions, allowing single components to fulfill multiple roles and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7925815B1Modifications to increase computer system security
Publication Date: 2011.04.12 INTELLECTUAL VENTURES HOLDING 81 LLC
  • US7925815B1 patent drawing
  • US7925815B1 patent drawing
  • US7925815B1 patent drawing

AI summary

Methods and systems for processing more securely. More specifically, embodiments provide effective and efficient mechanisms for reducing APIC interference with accesses to SMRAM, where processor and/or northbridge modifications implementing these mechanisms effectively reduce APIC attacks and increase the security of proprietary, confidential or otherwise secure data stored in SMRAM.