SOC Root of Trust Resilient Boot Firmware Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern computing devices with system on chip (SOC) architectures face challenges in ensuring the resilience of boot firmware against attacks and damage, as existing solutions are not adequately effective in managing and updating firmware components across multiple microcontrollers.

Innovation Solution

The implementation of a root of trust within the SOC, which includes a trusted region that assumes control during resets, authenticates update packages, and applies updates to firmware components, leveraging a resiliency switcher and secure authentication mechanisms to ensure seamless and secure firmware updates, even in the presence of corruption or boot failures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional system BIOS solutions are used, then basic boot functionality is provided, but the system is vulnerable to attacks and damage with no effective resiliency

Engineering Contradiction:
Improveboot firmware resilienceVSAvoidfirmware management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firmware update process into distinct phases: secure boot phase that verifies authenticity, update phase that applies changes, and recovery phase that handles failures. This segmentation allows the system to maintain simplicity while achieving resilience through structured error handling and verification at each stage

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by performing authentication and verification of update packages before applying them to the boot firmware. The system prepares recovery mechanisms in advance, including backup firmware images and verification protocols, so that if an attack or damage occurs during updating, the system can recover without external intervention

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If firmware updates are implemented without external tools, then BOM costs are reduced, but update security and reliability may be compromised

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidupdate security
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements self-service by enabling the computing device to autonomously download, authenticate, and apply firmware updates without external programming tools. The system includes built-in cryptographic verification, secure boot protocols, and automatic recovery mechanisms that ensure update security is maintained while eliminating the need for external update equipment

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces cryptographic authentication mechanisms as an intermediary layer between the firmware update source and the boot firmware. This intermediary verifies the authenticity and integrity of updates through digital signatures and hash verification, ensuring that only authorized updates are applied while maintaining system security

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If multiple microcontrollers with boot firmware are used, then system functionality is enhanced, but the attack surface and vulnerability to damage increase

Engineering Contradiction:
Improvesystem functionalityVSAvoidfirmware vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a universal firmware update mechanism that can update boot firmware across multiple different microcontrollers within the same computing device. The system uses a common authentication protocol and update process that works regardless of the specific microcontroller type, allowing the same security framework to protect diverse firmware components throughout the system

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11556327B2SOC-assisted resilient boot
Publication Date: 2023.01.17 INTEL CORP
  • US11556327B2 patent drawing
  • US11556327B2 patent drawing
  • US11556327B2 patent drawing

AI summary

Systems, apparatuses and methods may provide for technology that assumes, by a root of trust located in a trusted region of a system on chip (SOC), control over a reset of the SOC and conducting, by the root of trust, an authentication of an update package in response to an update condition. The root of trust technology may also apply the update package to firmware located in non-volatile memory (NVM) associated with a microcontroller of the SOC if the authentication is successful.