IP Library Granted Patent US 7,917,741
Granted Patent B2
US 7,917,741 · App. 11/733,599 · Granted Mar 29, 2011

Enhancing security of a system via access by an embedded controller to a secure storage device

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,917,741
App. No.
11/733,599
Granted
Mar 29, 2011
Kind
B2
Abstract

System and method for performing pre-boot security verification in a system that includes a host processor and memory, an embedded microcontroller with an auxiliary memory, e.g., an on-chip ROM, or memory controlled to prohibit user-tampering with the contents of the memory, and one or more pre-boot security components coupled to the embedded microcontroller. Upon power-up, but before host processor boot-up, the embedded microcontroller accesses the auxiliary memory and executes the program instructions to verify system security using the one or more pre-boot security components. The one or more pre-boot security components includes at least one identity verification component, e.g., a smart card, or a biometric sensor, e.g., a fingerprint sensor, a retinal scanner, and/or a voiceprint sensor, etc., and/or at least one system verification component, e.g., TPM, to query the system for system state information, and verify that the system has not been compromised.

Claims (51)

1. A system, comprising:

a host processor and memory;

an embedded microcontroller coupled to the host processor;

an auxiliary memory coupled to the embedded microcontroller, wherein the auxiliary memory stores program instructions for verifying system security; and

one or more pre-boot security components coupled to the embedded microcontroller;

wherein upon power-up, but before host processor boot-up, the embedded microcontroller is operable to:

execute the program instructions to verify system security using the one or more pre-boot security components; and

if system security is verified, permit the host processor to be booted;

wherein the embedded microcontroller is further configured to execute the program instructions to:

invoke one or more defensive measures if system security cannot be verified; and

control access to one or more devices coupled to the system, and wherein the one or more defensive measures comprises blocking access to the one or more devices; and

wherein at least one of the one or more pre-boot security components comprises a trusted platform module (TPM), wherein the one or more devices comprises at least one other of the one or more pre-boot security components, and wherein, to verify system security using the one or more pre-boot security components, the embedded microcontroller is configured to execute the program instructions to verify access rights using the TPM.

2. The system of claim 1 ,

wherein the one or more pre-boot security components comprise at least one identity verification component;

wherein, to verify system security using the one or more pre-boot security components, the program instructions are executable by the embedded microcontroller to invoke the at least one identity verification component to:

receive identification information from a user; and

verify that the user is authorized to use the system.

3. The system of claim 2 , wherein the at least one identity verification component comprises one or more of:

a smart card;

a TPM (Trusted Platform Module); or

at least one biometric sensor.

4. The system of claim 3 , wherein the at least one biometric sensor comprises one or more of:

a fingerprint sensor;

a retinal scanner; or

a voiceprint sensor.

5. The system of claim 1 , wherein the one or more pre-boot security components comprise at least one system verification component;

wherein, to verify system security using the one or more pre-boot security components, the program instructions are executable by the embedded microcontroller to invoke the at least one system verification component to:

query the system for system state information; and

verify that the system has not been compromised.

6. The system of claim 5 , wherein to verify that the system has not been compromised, the program instructions are executable by the embedded microcontroller to compare the system state information queried by the at least one system verification component with reference system state information.

7. The system of claim 5 , wherein the at least one system verification component comprises a TPM (Trusted Platform Module).

8. The system of claim 1 , wherein the auxiliary memory comprises a ROM.

9. The system of claim 1 , wherein the auxiliary memory comprises a memory protected by hardware to implement one-time writable memory.

10. The system of claim 1 , wherein the one or more defensive measures comprises:

preventing user access to the system.

11. The system of claim 10 , wherein said preventing user access to the system comprises one or more of:

preventing the host processor from booting by blocking access to a BIOS;

shutting down a power supply to the system.

12. The system of claim 1 , wherein the one or more defensive measures comprises:

alerting an external system coupled to the system.

13. The system of claim 1 ,

wherein the one or more pre-boot security components comprise a global positioning system (GPS); and

wherein, to verify system security using the one or more pre-boot security components, the program instructions are executable by the embedded microcontroller to:

invoke the GPS to determine the location of the system; and

verify that the system is at an authorized location.

14. A method for verifying security in a computer system comprising a host processor and memory, the method comprising:

upon power-up, but before host processor boot-up, an embedded microcontroller coupled to the host processor and memory accessing an auxiliary memory that stores program instructions for verifying system security, and executing the program instructions to verify system security using one or more pre-boot security components coupled to the embedded microcontroller;

if system security is verified, invoking boot-up of the host processor;

if system security cannot be verified, invoking one or more defensive measures; and

controlling access to one or more devices coupled to the system, wherein the one or more defensive measures comprises blocking access to the one or more devices;

wherein at least one of the one or more pre-boot security components comprises a trusted platform module (TPM), wherein the one or more devices comprises at least one other of the one or more pre-boot security components, and wherein executing the program instructions to verify system security using the one or more pre-boot security components comprises executing the program instructions verify access rights using the TPM.

Assignments (10)
RELEASE OF SECURITY INTEREST Recorded Mar 14, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 060894/0437 →
RELEASE OF SECURITY INTEREST Recorded Mar 11, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059363/0001 →
RELEASE OF SECURITY INTEREST Recorded Mar 10, 2022
From: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 059863/0400 →
SECURITY INTEREST Recorded Jun 4, 2021
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 057935/0474 →
SECURITY INTEREST Recorded Dec 24, 2020
From: MICROCHIP TECHNOLOGY INCORPORATED; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 055671/0612 →
SECURITY INTEREST Recorded Jun 5, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: WELLS FARGO BANK, NATIONAL ASSOCIATION
Reel/Frame 053468/0705 →
RELEASE OF SECURITY INTEREST Recorded May 30, 2020
From: JPMORGAN CHASE BANK, N.A, AS ADMINISTRATIVE AGENT
To: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
Reel/Frame 053466/0011 →
SECURITY INTEREST Recorded Apr 24, 2020
From: MICROCHIP TECHNOLOGY INC.; SILICON STORAGE TECHNOLOGY, INC.; ATMEL CORPORATION; MICROSEMI CORPORATION; MICROSEMI STORAGE SOLUTIONS, INC.
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 053311/0305 →
MERGER Recorded Dec 11, 2017
From: STANDARD MICROSYSTEMS CORPORATION
To: MICROCHIP TECHNOLOGY INCORPORATED
Reel/Frame 044824/0608 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 11, 2007
From: DUTTON, DREW J.; BERENBAUM, ALAN D.; WAHLER, RICHARD E.; WEISS, RAPHAEL
To: STANDARD MICROSYSTEMS CORPORATION
Reel/Frame 019145/0263 →