IP Library Granted Patent US 9,483,246
Granted Patent B2
US 9,483,246 · App. 14/055,008 · Granted Nov 1, 2016

Automated modular and secure boot firmware update

Inventors: Gyan Prakash (Beaverton, OR); Saurabh Dadu (Tigard, OR); Selim Aissi (Menlo Park, CA); Hormuzd M. Khosravi (Portland, OR); Duncan Glendinning (Chandler, AZ); Cris Rhodes (Chandler, AZ)
Assignee: Intel Corporation
G06F8/65G06F21/572G06F9/24G06Q10/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,483,246
App. No.
14/055,008
Granted
Nov 1, 2016
Kind
B2
Abstract

A method, apparatus, system, and computer program product for an automated modular and secure boot firmware update. An updated boot firmware code module is received in a secure partition of a system, the updated boot firmware code module to replace one original boot firmware code module for the system. Only the one original boot firmware code module is automatically replaced with the updated boot firmware code module. The updated boot firmware code module is automatically executed with the plurality of boot firmware code modules for the system and without user intervention when the system is next booted. The updated boot firmware code module may be written to an update partition of a firmware volume, wherein the update partition of the firmware volume is read along with another partition of the firmware volume containing the plurality of boot firmware code modules when the system is booted.

Claims (17)

1. A computer-implemented method comprising:

sending an updated boot firmware code module to a secure partition implemented in a microprocessor of a system, the secure partition being isolated from a host operating system of the system, the updated boot firmware code module to automatically replace one original boot firmware code module of a plurality of boot firmware code modules stored in a different partition of the system, wherein only the one original boot firmware code module is replaced with the updated boot firmware code module and wherein the updated boot firmware code module is executed with the plurality of boot firmware code modules of the system when the system is next booted;

receiving a status from the secure partition of the system, the status indicating whether the system was successfully booted using the updated boot firmware code module; and

sending another version of the updated boot firmware code module to the secure partition of the system when the status indicates that the system was not successfully booted using the updated boot firmware code module.

2. The method of claim 1 , wherein the sending the updated boot firmware code module to the secure partition comprises sending the updated boot firmware code module in an encrypted signed manifest.

3. A computer program product comprising:

a non-transitory computer-readable storage medium; and

instructions in the computer-readable storage medium, wherein the instructions, when executed in a processing system, cause the processing system to perform operations comprising:

sending an updated boot firmware code module to a secure partition of the system, the secure partition being isolated from a host operating system of the system, the updated boot firmware code module to automatically replace one original boot firmware code module of a plurality of boot firmware code modules stored in a different partition of the system, wherein only the one original boot firmware code module is replaced with the updated boot firmware code module and wherein the updated boot firmware code module is executed with the plurality of boot firmware code modules of the system when the system is next booted;

receiving a status from the secure partition of the system, the status indicating whether the system was successfully booted using the updated boot firmware code module; and

sending another version of the updated boot firmware code module to the secure partition of the system when the status indicates that the system was not successfully booted using the updated boot firmware code module.

4. The computer program product of claim 3 , wherein the sending the updated boot firmware code module to the secure partition comprises sending the updated boot firmware code module in an encrypted signed manifest.

5. An enterprise service platform comprising:

at least one processor to execute an enterprise service; and

an update service partition coupled to the at least one processor, the update service partition to send an updated boot firmware code module to a secure partition of a system, the secure partition being isolated from a host operating system of the system, the updated boot firmware code module to automatically replace one original boot firmware code module of a plurality of boot firmware code modules stored in a different partition of the system, wherein only the one original boot firmware code module is to be replaced with the updated boot firmware code module and wherein the updated boot firmware code module is to be executed with the plurality of boot firmware code modules of the system when the system is next booted, the update service partition to receive a status from the secure partition of the system, the status indicating whether the system was successfully booted using the updated boot firmware code module, and

wherein the update service partition is to send another version of the updated boot firmware code module to the secure partition of the system when the status indicates that the system was not successfully booted using the updated boot firmware code module.

6. The platform of claim 5 , wherein send the updated boot firmware code module to the secure partition comprises sending the updated boot firmware code module in an encrypted signed manifest.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 5, 2022
From: INTEL CORPORATION
To: MEDIATEK INC.
Reel/Frame 059828/0105 →
Continuity (2)
Division 12592605 · Nov 30, 2009
Related Publication 20140047428A1 · Feb 13, 2014