Unused Firmware Memory Verification via Pre-determined Values
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional Information Handling Systems (IHS) are vulnerable to malign code attacks on firmware, which can compromise system integrity and lead to failure, as existing anti-malware tools are less effective at detecting malicious code at the privileged firmware level.
Innovation Solution
The system employs a method to prevent malign code attachment by using pre-determined values stored in non-volatile memory, calculated using an encryption key or hash algorithm unknown to third-party vendors, to identify and verify the integrity of firmware stored in non-contiguous areas, ensuring that malign code cannot spoof verification mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional IHS are used without pre-determined values in unused firmware memory, then the system is vulnerable to malign code attacks, but implementing verification mechanisms adds device complexity
Solution Approach 1:
The patent applies preliminary action by pre-filling unused firmware memory locations with pre-determined values before the firmware is written. This advance preparation creates a verification mechanism that checks whether these pre-determined values remain intact after firmware installation, thereby detecting malign code without adding complex runtime verification systems.
Solution Approach 2:
The patent uses pre-determined values as an intermediary element between the firmware and the verification process. These values serve as a mediator that can be checked to determine firmware integrity without requiring direct complex interaction between the firmware and verification systems, thus reducing overall device complexity.
2Ease of manufacture
If third-party vendors program NVM without pre-determined values, then manufacturing is easier, but system security is compromised
Solution Approach 1:
The IHS manufacturer performs preliminary action by generating and providing pre-determined values to third-party vendors before they program the NVM. This allows vendors to simply store these values without complex processing, maintaining ease of manufacture while ensuring security through the pre-configured verification mechanism.
Solution Approach 2:
The patent segments the manufacturing process into distinct roles: the IHS manufacturer generates and provides pre-determined values, while third-party vendors only responsible for storing them in NVM. This segmentation allows vendors to maintain simple programming processes while the security function is handled separately by the system manufacturer.
3Ease of manufacture
If unused firmware memory is left blank, then firmware installation is simpler, but malign code can be attached to unused memory
Solution Approach 1:
The patent converts the potentially harmful unused firmware memory into a beneficial security feature by filling it with pre-determined values. These values, which could be seen as unnecessary data, actually serve as verification markers that detect malign code attachment, thus converting a security vulnerability into a security mechanism.
Solution Approach 2:
The patent applies local quality by treating unused firmware memory locations differently from active firmware locations. Instead of leaving all memory uniform and blank, specific unused locations are filled with pre-determined values, creating local differentiation that enables security verification without affecting firmware installation simplicity.
Data Source
AI summary
Systems and methods for preventing attachment of malign code to unused firmware memory are described. In some embodiments, an Information Handling System (IHS) may include a processor and a memory coupled to the processor, the memory having program instructions stored thereon that, upon execution by the processor, cause the IHS to: read contents of a non-volatile memory (NVM); and determine that the NVM does not include malign code stored thereon, at least in part, by determining that selected memory locations in the NVM where firmware is not stored contain pre-determined values.


