UEFI Attestation Component for Hardware Inventory Integrity
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems, particularly open compute platforms and industrial PCs, face challenges in protecting against manipulation and ensuring the integrity and authenticity of hardware and software components, especially when these systems are expandable.
Innovation Solution
The implementation of an attestation component trained for a unified extensive firmware interface (UEFI) that creates an inventory data record of all hardware and software components, compares it with a reference data record, and provides a comparison result to enhance the integrity and authenticity of these components.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the base firmware is made extendable by end users to allow integration of subcomponents, then the adaptability and versatility of the system is improved, but the risk of tampering and manipulation of the firmware increases
Solution Approach 1:
The patent applies preliminary action by creating an inventory of hardware and software components during the boot process before the operating system loads. This inventory is generated in advance and stored in a secure location, allowing subsequent verification of component integrity without requiring continuous monitoring or intervention during system operation. The inventory creation happens proactively at the earliest possible moment in the boot sequence.
Solution Approach 2:
The patent implements feedback by comparing the generated inventory against a reference inventory and providing a comparison result that indicates whether components have been tampered with. This feedback mechanism allows the system to detect changes in hardware or software components and alert the user or system administrator, enabling proactive detection of tampering while maintaining the extendability of the firmware.
2Reliability
If Secure Boot is implemented to check integrity and authenticity of boot components, then the protection against manipulation is improved, but the complexity of the boot process increases
Solution Approach 1:
The patent applies segmentation by dividing the boot process into distinct phases: creating the inventory of components, storing the inventory securely, comparing the inventory against reference data, and providing comparison results. This segmentation allows each phase to be handled independently and simplifies the overall implementation of integrity checking without requiring a complete redesign of the boot process.
Solution Approach 2:
The patent uses an intermediary approach by introducing an inventory data structure as a mediator between the hardware/software components and the integrity verification process. Instead of directly verifying each component's authenticity through complex cryptographic operations, the system creates a summarized inventory that serves as an intermediary representation, which can then be efficiently compared against reference data to detect tampering.
3Measurement precision
If Measured Boot with TPM is used to create cryptographic checksums of boot components, then the measurement and tracking of component changes is improved, but the inability to prevent execution of malicious code under fault injection conditions remains
Solution Approach 1:
The patent applies copying by creating a copy of the system state in the form of an inventory data structure that captures hardware and software component information. This inventory copy can be stored, transmitted, and compared without affecting the actual system operation or requiring complex cryptographic operations during normal execution. The inventory serves as a static representation that can be analyzed later to detect changes or tampering.
Solution Approach 2:
The patent transitions from the traditional one-dimensional linear boot verification process to a multi-dimensional approach by capturing inventory data across multiple dimensions: hardware components, software components, their versions, and their relationships. This dimensional expansion allows for more comprehensive tracking and analysis of system state changes without adding complexity to the core verification mechanism.
Data Source
AI summary
The invention relates to an attestation component configured for a Unified Extensible Firmware Interface (222) of a technical system (1), the attestation component comprising: - a capture component configured to create an inventory data set (221), wherein the inventory data set (221) contains unique identification data for: o all currently existing hardware components and/or o all currently existing software components of the technical system (1), - a comparison component configured to create a comparison result (2221) by comparing the inventory data set (221) and a reference data set, and - a provisioning component configured to provide the comparison result (2221). The invention further relates to a Unified Extensible Firmware Interface (222), a main processor (22), a device (2), and a technical system (1), as well as an associated method.


