TPM PCR Resealing for Secure Boot Firmware Upgrades
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure boot systems face challenges in managing platform configuration register (PCR) brittleness during planned changes such as firmware upgrades or CRU replacements, leading to potential security compromises and loss of sealed TPM objects, which traditional solutions address inadequately.
Innovation Solution
A framework is introduced to manage PCR transitions during planned changes, ensuring secure and seamless updates by maintaining TPM object integrity without disabling secure boot, allowing seamless migration and resealing of TPM values, and minimizing the risk of objects becoming unsealable.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional secure boot systems perform planned changes such as firmware upgrades or CRU replacements, then system updates can be applied, but PCR brittleness causes sealed TPM objects to become unsealable and security is compromised
Solution Approach 1:
The patent segments the PCR management process into distinct phases: capturing the pre-change PCR state, performing the planned change, and restoring the captured PCR state. This segmentation allows the system to isolate the impact of changes and prevent PCR brittleness from compromising security, while still enabling necessary system updates and maintenance operations.
2Adaptability or versatility
If secure boot is disabled to allow firmware upgrades or CRU replacements, then planned changes can be performed, but security protection is lost
Solution Approach 1:
The patent captures and stores the pre-change PCR state before performing any firmware upgrades or CRU replacements. This preliminary action ensures that the original secure boot measurements are preserved, allowing the system to restore security integrity after the change is completed without needing to disable secure boot protection.
3Reliability
If PCR state is restored after planned changes, then TPM objects remain sealable and security is maintained, but additional complexity is introduced to manage PCR transitions
Solution Approach 1:
The patent introduces a PCR state capture and restoration mechanism that acts as an intermediary between the planned changes and the secure boot process. This intermediary captures the pre-change PCR state, allows the change to proceed, and then restores the captured state, thereby maintaining TPM object sealability without requiring complex manual intervention for each change operation.
Data Source
AI summary
A method for managing an information handing system (IHS) includes: receiving an entry from a firmware (FW) upgrade service executing on the IHS; unsealing a trusted platform module (TPM) object to access data in the TPM object; generating a temporary database based on data and an event log; obtaining a first hash value (HV) of the temporary database; identifying a combination of FW HVs; updating the event log to generate an updated event log; updating the temporary database to obtain an updated database; predicting a second HV of the updated database; employing a logical OR model against the first HV and second HV to seal the TPM object; initiating a performance of the FW upgrade on the IHS; and unsealing the TPM object to access second data of the TPM object and to initiate providing a computer-implemented service to a user of the IHS.


