TPM-Based Multi-Node BIOS Reconfiguration Against Rollback
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Multi-node systems are vulnerable to rollback attacks where an attacker reconfigures a compute node with an older BIOS version to become the primary node, exploiting known vulnerabilities, and existing methods fail to prevent unauthorized updates.
Innovation Solution
A method and system that utilize a Trusted Platform Module (TPM) to ensure that only a user's manual assertion of physical presence can reconfigure a secondary node with a newer BIOS version to become the primary node, using non-volatile indices and logical values to secure the boot process, preventing unauthorized changes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a compute node with an older BIOS version is reconfigured to serve as the primary node, then the multi-node system can boot from the older BIOS version, but the system becomes vulnerable to rollback attacks exploiting known vulnerabilities
Solution Approach 1:
The patent introduces a Trusted Platform Module (TPM) as an intermediary security component that mediates between the reconfiguration request and the actual boot process. The TPM verifies digital signatures of the BIOS firmware and maintains a chain of trust, allowing the system to accept reconfiguration requests while preventing unauthorized rollback to vulnerable older versions. The TPM acts as the mediator that validates whether a reconfiguration to a specific BIOS version is secure and authorized.
Solution Approach 2:
The patent implements preliminary security measures by pre-configuring the TPM with trusted BIOS versions and pre-establishing digital signatures before any reconfiguration occurs. The system performs preliminary verification of the BIOS version's security status and authorization before allowing the reconfiguration to take effect. This preliminary action ensures that only authorized and secure BIOS versions can be deployed as the primary node.
2Reliability
If existing methods are used to prevent unauthorized BIOS updates, then firmware rollback protection is achieved, but the system cannot securely allow authorized reconfiguration to newer BIOS versions
Solution Approach 1:
The patent implements a feedback mechanism where the TPM continuously monitors and verifies the BIOS version, its digital signature, and the reconfiguration requests. The system provides feedback about the security status of the current BIOS version and the validity of reconfiguration requests. This feedback loop allows the system to maintain rollback protection while enabling authorized updates to newer, more secure BIOS versions through verified reconfiguration processes.
3Reliability
If manual physical presence verification is required for reconfiguration, then unauthorized reconfiguration attempts are prevented, but the reconfiguration process becomes more complex
Solution Approach 1:
The patent implements self-service authentication where the physical presence verification is automatically handled by the TPM hardware component without requiring manual intervention in the reconfiguration process. The system automatically detects physical presence, verifies it against stored credentials, and enables or disables reconfiguration requests accordingly. This self-service approach maintains strong authorization verification while simplifying the overall reconfiguration process by automating the verification steps.
Data Source
AI summary
A computer program product includes computer readable program code for initiating boot of a multi-node system including a first compute node scaled together with a second compute node, wherein the multi-node system boots from a basic input output system of the first compute node that is identified as a primary node by a trusted platform module of the first compute node. The computer program product further comprises computer readable program code for receiving a request to reconfigure the multi-node system so that the second compute node would become the primary node, and computer readable program code for reconfiguring the multi-node system so that the second node is the primary mode only in response to a user manually asserting physical presence to a trusted platform module of the first compute node.


