Trusted Firmware Verification via Multi-Checkpoint Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Enterprises face challenges in verifying the trustworthiness of firmware status responses from managed devices, as these responses may be compromised, posing risks to security vulnerabilities such as theft, loss, and unauthorized access, especially when devices are used outside protected areas for personal use.

Innovation Solution

Implementing a multi-checkpoint verification process that includes verifying certificate data, signature data, and exit codes in firmware status responses, along with the use of a session key encrypted token or nonce, to ensure the integrity and trustworthiness of the responses, and taking compliance actions if any verification step fails.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If firmware status responses are obtained from managed devices through OEM tools, then device monitoring capability is improved, but response trustworthiness deteriorates due to potential compromise

Engineering Contradiction:
Improvedevice monitoring capabilityVSAvoidresponse trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a management service as an intermediary between the managed device and the enterprise administrator. This service receives firmware status responses from the device, performs verification using multiple checkpoints (certificate validation, signature verification, exit code checking), and only relays trusted information to the administrator. This mediator approach allows continuous monitoring while filtering out compromised or untrustworthy responses.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary verification actions before accepting firmware status responses. The management service performs multiple checkpoint verifications (certificate data validation, signature verification, exit code verification) in advance before processing or relaying the response information. This preliminary action ensures that only verified, trustworthy firmware status information is accepted and acted upon.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If multiple verification checkpoints are implemented, then response verification accuracy is improved, but system complexity increases

Engineering Contradiction:
Improveverification accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the verification process into distinct, modular checkpoints: certificate data verification, signature verification, and exit code verification. Each checkpoint is an independent verification step that can be executed separately. This segmentation allows the system to achieve high verification accuracy through multiple checks while maintaining manageable complexity through clear separation of verification functions.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12086257B2Trusted firmware verification
Publication Date: 2024.09.10 OMNISSA LLC
  • US12086257B2 patent drawing
  • US12086257B2 patent drawing
  • US12086257B2 patent drawing

AI summary

Disclosed are various examples for verification and management of firmware for client devices enrolled with a management service of an enterprise. The firmware verification includes a verification process using multiple checkpoints for determining whether status responses associated with firmware installed on and received from a managed client device can be trusted. The multiple checkpoints can include verifying certificate data, signature data, and an exit code included in status responses received from managed devices. In the event that one of the verification steps fails, the device can be considered compromised and subject to various compliance actions. The compliance actions can include limiting access to enterprise data, limiting access to one or more applications, wiping a device clean to reset the devices to the original factory settings, sending a notification to an enterprise administrator providing an indication of the detected compromise, and other types of compliance actions.