TPM PCR Resealing for Secure Boot Firmware Upgrades

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure boot systems face challenges in managing platform configuration register (PCR) brittleness during planned changes such as firmware upgrades or CRU replacements, leading to potential security compromises and loss of sealed TPM objects, which traditional solutions address inadequately.

Innovation Solution

A framework is introduced to manage PCR transitions during planned changes, ensuring secure and seamless updates by maintaining TPM object integrity without disabling secure boot, allowing seamless migration and resealing of TPM values, and minimizing the risk of objects becoming unsealable.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional secure boot systems perform planned changes such as firmware upgrades or CRU replacements, then system updates can be applied, but PCR brittleness causes sealed TPM objects to become unsealable and security is compromised

Engineering Contradiction:
Improveability to perform planned changesVSAvoidsecurity integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the PCR management process into distinct phases: capturing the pre-change PCR state, performing the planned change, and restoring the captured PCR state. This segmentation allows the system to isolate the impact of changes and prevent PCR brittleness from compromising security, while still enabling necessary system updates and maintenance operations.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If secure boot is disabled to allow firmware upgrades or CRU replacements, then planned changes can be performed, but security protection is lost

Engineering Contradiction:
Improveability to perform firmware upgrades and CRU replacementsVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent captures and stores the pre-change PCR state before performing any firmware upgrades or CRU replacements. This preliminary action ensures that the original secure boot measurements are preserved, allowing the system to restore security integrity after the change is completed without needing to disable secure boot protection.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If PCR state is restored after planned changes, then TPM objects remain sealable and security is maintained, but additional complexity is introduced to manage PCR transitions

Engineering Contradiction:
ImproveTPM object sealabilityVSAvoidPCR transition management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a PCR state capture and restoration mechanism that acts as an intermediary between the planned changes and the secure boot process. This intermediary captures the pre-change PCR state, allows the change to proceed, and then restores the captured state, thereby maintaining TPM object sealability without requiring complex manual intervention for each change operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12518020B2Method and system for managing platform configuration register (PCR) brittleness for secure boot measurements
Publication Date: 2026.01.06 DELL PROD LP
  • US12518020B2 patent drawing
  • US12518020B2 patent drawing
  • US12518020B2 patent drawing

AI summary

A method for managing an information handing system (IHS) includes: receiving an entry from a firmware (FW) upgrade service executing on the IHS; unsealing a trusted platform module (TPM) object to access data in the TPM object; generating a temporary database based on data and an event log; obtaining a first hash value (HV) of the temporary database; identifying a combination of FW HVs; updating the event log to generate an updated event log; updating the temporary database to obtain an updated database; predicting a second HV of the updated database; employing a logical OR model against the first HV and second HV to seal the TPM object; initiating a performance of the FW upgrade on the IHS; and unsealing the TPM object to access second data of the TPM object and to initiate providing a computer-implemented service to a user of the IHS.