Spoofed Firmware Detection in Information Handling Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Spoofed firmware images in information handling systems are difficult to detect and remediate as they mimic authentic behavior, evading vendor-provided security checks and updates.

Innovation Solution

A method and system that involves triggering a controller to execute a diagnostic image to test an image under scrutiny, identifying invalid test results as indicative of a spoofed image, generating an error message, and replacing the spoofed image with a trusted one.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If spoofed firmware images are loaded directly onto the information handling system, then the system can operate with modified firmware, but security is compromised as the spoofed images evade vendor-provided security checks

Engineering Contradiction:
Improvefirmware flexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary validation of firmware images before they are executed on the information handling system. A validation module checks the firmware image against a vendor-provided hash value before allowing the system to boot or operate with that firmware, preventing spoofed images from being loaded in the first place

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism between the firmware image and the system execution environment. The validation module acts as a mediator that verifies the authenticity of the firmware image by comparing its hash value against the vendor-provided hash, thereby securing the system without preventing firmware updates or modifications through proper channels

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If traditional vendor-provided firmware update methods are used, then security checks are performed, but spoofed images can still be loaded directly without relying on these methods

Engineering Contradiction:
Improvefirmware securityVSAvoidfirmware loading complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service security mechanism where the system automatically validates firmware images using vendor-provided hash values without requiring manual security checks or complex update procedures. The validation occurs transparently during the boot process or firmware loading, maintaining ease of operation while enhancing security

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The validation of firmware images is performed preliminarily before system execution, using automatically retrieved vendor-provided hash values. This preliminary check prevents spoofed images from being loaded while maintaining simple operation for legitimate firmware updates

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10628583B2Detecting a spoofed image in an information handling system
Publication Date: 2020.04.21 DELL PROD LP
  • US10628583B2 patent drawing
  • US10628583B2 patent drawing
  • US10628583B2 patent drawing

AI summary

A method, information handling system (IHS) and a detection system for detecting a spoofed firmware image in an IHS. The method includes a processor triggering a controller to execute a diagnostic image for testing an image under test. At least one first test result is received from the controller executing the diagnostic image. The method further includes determining whether the first test result is a valid first test result. In response to determining that the first test result is not a valid first test result, the image under test is identified as a spoofed image that has failed testing. An error message is generated that identifies the image under test as being a spoofed image and the error message is stored to an error log.