UEFI Firmware Security Database Protection via SMM

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

UEFI-compliant devices face vulnerabilities due to unauthorized modifications in flash ROM regions, particularly in the Authenticated Variable region and firmware store, which can be exploited by malicious software like rootkits and Trojan Boot Viruses, as existing protection mechanisms do not allow selective updates by trusted authorities.

Innovation Solution

Implementing firmware modules that operate only in System Management Mode (SMM), which receive and process signed requests for security database modifications and firmware updates, ensuring that only authorized entities can perform alterations by transitioning the CPU to SMM for validation and execution, thereby preventing unauthorized access and modifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the Authenticated Variable region and firmware store are made accessible for updates, then firmware can be updated and security database can be modified, but unauthorized malware can tamper with these critical regions

Engineering Contradiction:
Improvefirmware update capabilityVSAvoidunauthorized modification vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces SMM as an intermediary execution environment that mediates all access to the Authenticated Variable region and firmware store. The CPU transitions to SMM mode before executing any code that accesses these protected regions, creating a trusted intermediary layer between untrusted user-mode software and the critical firmware storage areas. This intermediary mechanism allows legitimate updates while blocking unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into distinct execution modes (normal mode and SMM) with different access privileges. By dividing the execution environment into segmented modes with hierarchical access control, the patent ensures that only code running in the privileged SMM can access the Authenticated Variable region and firmware store, while user-mode code is restricted from direct access.

Inventive Principle:
Principle #1Segmentation

2Reliability

If signature checking is implemented to validate software before execution, then unauthorized software can be blocked, but the system complexity increases due to additional validation layers

Engineering Contradiction:
Improvesoftware authorization validationVSAvoidsignature validation mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements signature checking as a preliminary action that occurs before software is allowed to execute or access protected regions. The firmware validates digital signatures of boot loaders, drivers, and update packages before permitting their execution or allowing them to access the Authenticated Variable region. This preliminary validation prevents unauthorized software from ever gaining execution privileges.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The SMM acts as an intermediary that enforces signature validation policies. Rather than having complex validation logic distributed throughout the system, the SMM serves as a centralized intermediary that validates signatures and makes authorization decisions, simplifying the overall system architecture while maintaining strong security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If the CPU operates in normal mode with full access to memory, then system operation is efficient, but security-critical regions can be accessed by malicious code

Engineering Contradiction:
Improvesystem operation efficiencyVSAvoidmalware access capability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent makes the CPU execution mode dynamic, allowing transition between normal mode and SMM based on the security requirements of the current operation. The CPU operates in normal mode for most tasks to maintain efficiency, but dynamically transitions to SMM when accessing protected regions or executing security-critical code, providing adaptive security that maintains performance for unprivileged operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different access qualities to different memory regions and code paths. The Authenticated Variable region and firmware store are marked as security-critical and require SMM execution for access, while other regions can be accessed from normal mode. This local differentiation of access quality allows efficient access to non-critical resources while protecting critical regions.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9372699B2System and method for processing requests to alter system security databases and firmware stores in a unified extensible firmware interface-compliant computing device
Publication Date: 2016.06.21 INSYDE SOFTWARE CORP
  • US9372699B2 patent drawing
  • US9372699B2 patent drawing
  • US9372699B2 patent drawing

AI summary

A mechanism for allowing firmware in a UEFI-compliant device to implement the UEFI specification driver signing and Authenticated Variable elements while at the same time protecting the system security database holding the library of approved keys and lists of allowed and forbidden programs from unauthorized modifications is discussed.