IP Library Granted Patent US 12,265,623
Granted Patent B2
US 12,265,623 · App. 17/151,418 · Granted Apr 1, 2025

Firmware protection using multi-chip storage of firmware image

Inventors: Tomer Shachar (Omer, IL); Maxim Balin (Gan Yavne, IL); Yevgeni Gehtman (Modi'in, IL); Or Herman Saffar (Beer Sheva, IL)
Assignee: EMC IP Holding Company LLC
G06F21/572G06F11/1415G06F21/602G06F21/79
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,265,623
App. No.
17/151,418
Granted
Apr 1, 2025
Kind
B2
Abstract

Techniques are provided for firmware protection using multi-chip storage of firmware images. One method comprises obtaining a firmware image; encrypting the firmware image; splitting the encrypted firmware image into a plurality of encrypted firmware image portions; and storing the plurality of encrypted firmware image portions on a plurality of recovery chips, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips are needed to reconstruct the firmware image. The threshold number of the encrypted firmware image portions can be obtained from the at least two different recovery chips and a validation can be applied to the obtained encrypted firmware image portions. The threshold number of encrypted firmware image portions may be obtained in response to a chip that stores the firmware image being inactive.

Claims (49)

1. A method, comprising:

obtaining a firmware image associated with a given processing device, wherein the given processing device comprises a plurality of distinct recovery chips, a firmware image chip that stores the firmware image and a processor coupled to a memory, and wherein at least two of the plurality of distinct recovery chips are physically within the given processing device;

encrypting, by the given processing device, the firmware image;

splitting, by the given processing device, the encrypted firmware image into a designated number of encrypted firmware image portions;

storing, by the given processing device, the designated number of encrypted firmware image portions on respective ones of the plurality of distinct recovery chips of the given processing device, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips of the given processing device are needed by the given processing device to reconstruct the firmware image; and

in response to determining that the firmware image chip is not responsive:

(i) initiating an obtaining of at least the threshold number of the encrypted firmware image portions from the plurality of distinct recovery chips physically within the given processing device;

(ii reconstructing the firmware image using a reconstruction process and the at least the threshold number of the encrypted firmware image portions obtained from the plurality of distinct recovery chips physically within the given processing device; and

(iii) restoring the reconstructed firmware image in the firmware image chip that stores the firmware image;

wherein, in response to the reconstruction process determining that one or more of the threshold number of the encrypted firmware image portions is one or more of corrupted and cannot be obtained from the plurality of distinct recovery chips physically within the given processing device, the reconstruction process obtains a different encrypted firmware image portion from a different distinct recovery chip physically within the given processing device.

2. The method of claim 1 , wherein the designated number of the encrypted firmware image portions is greater than the threshold number.

3. The method of claim 1 , wherein the threshold number of the encrypted firmware image portions is obtained from the at least two different recovery chips and a validation is applied to the obtained encrypted firmware image portions.

4. The method of claim 3 , wherein at least one additional encrypted firmware image portion is obtained from at least one of the at least two different recovery chips in response to at least one obtained encrypted firmware image portion failing the validation.

5. The method of claim 3 , further comprising merging the obtained encrypted firmware image portions to generate merged encrypted firmware image portions.

6. The method of claim 5 , wherein the firmware image is reconstructed by decrypting the merged encrypted firmware image portions.

7. The method of claim 1 , wherein the determining that the firmware image chip is not responsive comprises determining whether the firmware image chip (i) responds to a message communicated to the given processing device using a one-way network diode or (ii) sends a heartbeat message.

8. An apparatus comprising:

at least one processing device comprising a processor coupled to a memory;

the at least one processing device being configured to implement the following steps:

obtaining a firmware image associated with a given processing device, wherein the given processing device comprises a plurality of distinct recovery chips, a firmware image chip that stores the firmware image and a processor coupled to a memory, and wherein at least two of the plurality of distinct recovery chips are physically within the given processing device;

encrypting, by the given processing device, the firmware image;

splitting, by the given processing device, the encrypted firmware image into a designated number of encrypted firmware image portions;

storing, by the given processing device, the designated number of encrypted firmware image portions on respective ones of the plurality of distinct recovery chips of the given processing device, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips of the given processing device are needed by the given processing device to reconstruct the firmware image; and

in response to determining that the firmware image chip is not responsive:

(i) initiating an obtaining of at least the threshold number of the encrypted firmware image portions from the plurality of distinct recovery chips physically within the given processing device;

(ii) reconstructing the firmware image using a reconstruction process and the at least the threshold number of the encrypted firmware image portions obtained from the plurality of distinct recovery chips physically within the given processing device; and

(iii) restoring the reconstructed firmware image in the firmware image chip that stores the firmware image;

wherein, in response to the reconstruction process determining that one or more of the threshold number of the encrypted firmware image portions is one or more of corrupted and cannot be obtained from the plurality of distinct recovery chips physically within the given processing device, the reconstruction process obtains a different encrypted firmware image portion from a different distinct recovery chip physically within the given processing device.

9. The apparatus of claim 8 , wherein the designated number of the encrypted firmware image portions is greater than the threshold number.

10. The apparatus of claim 8 , wherein the threshold number of the encrypted firmware image portions is obtained from the at least two different recovery chips and a validation is applied to the obtained encrypted firmware image portions.

11. The apparatus of claim 10 , wherein at least one additional encrypted firmware image portion is obtained from at least one of the at least two different recovery chips in response to at least one obtained encrypted firmware image portion failing the validation.

12. The apparatus of claim 10 , further comprising merging the obtained encrypted firmware image portions to generate merged encrypted firmware image portions.

13. The apparatus of claim 12 , wherein the firmware image is reconstructed by decrypting the merged encrypted firmware image portions.

14. The apparatus of claim 8 , wherein the determining that the firmware image chip is not responsive comprises determining whether the firmware image chip (i) responds to a message communicated to the given processing device using a one-way network diode or (ii) sends a heartbeat message.

15. A non-transitory processor-readable storage medium having stored therein program code of one or more software programs, wherein the program code when executed by at least one processing device causes the at least one processing device to perform the following steps:

obtaining a firmware image associated with a given processing device, wherein the given processing device comprises a plurality of distinct recovery chips, a firmware image chip that stores the firmware image and a processor coupled to a memory, and wherein at least two of the plurality of distinct recovery chips are physically within the given processing device;

encrypting, by the given processing device, the firmware image;

splitting, by the given processing device, the encrypted firmware image into a designated number of encrypted firmware image portions;

storing, by the given processing device, the designated number of encrypted firmware image portions on respective ones of the plurality of distinct recovery chips of the given processing device, wherein a threshold number of the encrypted firmware image portions from at least two different recovery chips of the given processing device are needed by the given processing device to reconstruct the firmware image; and

in response to determining that the firmware image chip is not responsive:

(i) initiating an obtaining of at least the threshold number of the encrypted firmware image portions from the plurality of distinct recovery chips physically within the given processing device;

(ii reconstructing the firmware image using a reconstruction process and the at least the threshold number of the encrypted firmware image portions obtained from the plurality of distinct recovery chips physically within the given processing device; and

(ii restoring the reconstructed firmware image in the firmware image chip that stores the firmware image;

wherein, in response to the reconstruction process determining that one or more of the threshold number of the encrypted firmware image portions is one or more of corrupted and cannot be obtained from the plurality of distinct recovery chips physically within the given processing device, the reconstruction process obtains a different encrypted firmware image portion from a different distinct recovery chip physically within the given processing device.

16. The non-transitory processor-readable storage medium of claim 15 , wherein the threshold number of the encrypted firmware image portions is obtained from the at least two different recovery chips and a validation is applied to the obtained encrypted firmware image portions.

17. The non-transitory processor-readable storage medium of claim 16 , wherein at least one additional encrypted firmware image portion is obtained from at least one of the at least two different recovery chips in response to at least one obtained encrypted firmware image portion failing the validation.

18. The non-transitory processor-readable storage medium of claim 16 , further comprising merging the obtained encrypted firmware image portions to generate merged encrypted firmware image portions.

19. The non-transitory processor-readable storage medium of claim 18 , wherein the firmware image is reconstructed by decrypting the merged encrypted firmware image portions.

20. The non-transitory processor-readable storage medium of claim 15 , wherein the determining that the firmware image chip is not responsive comprises determining whether the firmware image chip (i) responds to a message communicated to the given processing device using a one-way network diode or (ii) sends a heartbeat message.

Assignments (9)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0342) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0460 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (055479/0051) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0663 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (056136/0752) Recorded Jun 10, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
Reel/Frame 062021/0771 →
RELEASE OF SECURITY INTEREST AT REEL 055408 FRAME 0697 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC IP HOLDING COMPANY LLC
Reel/Frame 058001/0553 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 056136/0752 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0051 →
SECURITY INTEREST Recorded Mar 3, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
Reel/Frame 055479/0342 →
SECURITY AGREEMENT Recorded Feb 25, 2021
From: EMC IP HOLDING COMPANY LLC; DELL PRODUCTS L.P.
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
Reel/Frame 055408/0697 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 18, 2021
From: SHACHAR, TOMER; BALIN, MAXIM; GEHTMAN, YEVGENI; SAFFAR, OR HERMAN
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 054945/0493 →
Continuity (1)
Related Publication 20220229909A1 · Jul 21, 2022
References Cited (18)
US 10395054B2 · Resch · 2019 [cited by examiner]
US 10534618B2 · Balakrishnan · 2020 [cited by examiner]
US 20100199125A1 · Reche · 2010 [cited by examiner]
US 20120260106A1 · Zaks · 2012 [cited by examiner]
US 20140304520A1 · Bobzin · 2014 [cited by examiner]
US 20150365440A1 · Billau · 2015 [cited by examiner]
US 20190005245A1 · Laffey · 2019 [cited by examiner]
US 20190065747A1 · Gomes de Oliveira · 2019 [cited by examiner]
US 20190073481A1 · Angelino · 2019 [cited by examiner]
US 20200042710A1 · Liu · 2020 [cited by examiner]
US 20200202002A1 · Graham · 2020 [cited by examiner]
US 20210286884A1 · Lewis · 2021 [cited by examiner]
CN 114116305A · 2022 [cited by examiner]
https://www.microchip.com/forums/m224936.aspx, downloaded Jan. 13, 2021. [cited by applicant]
https://www.checkpoint.com/downloads/products/iot-protect-firmware-solution-brief.pdf, downloaded Jan. 13, 2021. [cited by applicant]
https://www.ti.com/lit/an/slaa682/slaa682.pdf?ts=1610560606007, downloaded Jan. 13, 2021. [cited by applicant]
https://securityboulevard.com/2020/02/firmware-attacks-what-they-are-how-i-can-protect-myself/, downloaded Jan. 13, 2021. [cited by applicant]
Zhang et al., “Threshold Changeable Secret Sharing Schemes Revisited”; Theoretical Computer Science 418; p. 106-15 (2012). [cited by applicant]