IP Library › Granted Patent US 12,579,327
Granted Patent B2
US 12,579,327 · App. 17/531,735 · Granted Mar 17, 2026

Secure coprocessor enforced system firmware feature enablement

Inventors: Tan Peng (Santa Clara, CA); Scott Swanstrom (Austin, TX)
Assignee: Advanced Micro Devices, Inc.
G06F21/76G06F21/33G06F21/552G06F21/554G06F21/572G06F21/602G06F21/6209G06F21/107
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,579,327
App. No.
17/531,735
Granted
Mar 17, 2026
Kind
B2
Abstract

A method includes, in response to a request to enable a set of firmware features in a processing device, performing a validation process based on a key certificate associating a first entity identifier with a firmware feature description file indicating the set of firmware features, and in response to a violation detected during the validation process, enabling a countermeasure in the processing device.

Claims (62)

1 . A method, comprising:

in response to a request to enable a set of firmware features in a processing device, performing a validation process based on a key certificate associating a first entity identifier with a firmware feature description file indicating the set of firmware features, wherein the first entity identifier is associated with a user entity; and

in response to a violation detected during the validation process, enabling a countermeasure in the processing device.

2 . The method of claim 1 , further comprising obtaining the key certificate from a monitoring party by:

receiving the first entity identifier from the monitoring party;

transmitting a certificate signing request based on a public key and the first entity identifier; and

receiving the key certificate, wherein the key certificate associates the public key with the first entity identifier.

3 . The method of claim 1 , further comprising:

generating the firmware feature description file by receiving a selection in an interfacing tool of an initial set of firmware features from available firmware features of the processing device, wherein:

the initial set of firmware features is included in the requested set of firmware features, and

each of the available firmware features is associated with one or more functions of firmware in the processing device; and

automatically selecting one or more prerequisite firmware feature sets in the requested set of firmware features in response to determining that the initial set of firmware features is dependent on the one or more prerequisite firmware feature sets.

4 . The method of claim 1 , further comprising:

signing the firmware feature description file using a private key;

storing the key certificate and the signed firmware feature description file in a memory device accessible to a secure coprocessor coupled with the processing device, wherein the key certificate further associates the first entity identifier with a public key;

enabling the set of firmware features in the processing device in response to the secure coprocessor authenticating the key certificate by determining that the public key corresponds to the private key; and

in response to authenticating the key certificate, recording the first entity identifier, a model identifier, and the requested set of firmware features in one-time programmable memory in the processing device.

5 . The method of claim 4 , wherein:

enabling the requested set of firmware features is performed by the secure coprocessor based on:

determining that the requested set of firmware features is included in an approved set of firmware features associated with the first entity identifier; and

determining that the first entity identifier matches a second entity identifier recorded in the processing device.

6 . The method of claim 1 , wherein enabling the countermeasure comprises: disabling one or more of a cache device and a processing core in the processing device.

7 . The method of claim 1 , wherein enabling the countermeasure comprises: transmitting an indication of the violation to a remote server device; and limiting a clock frequency of one or more circuit components in the processing device.

8 . The method of claim 1 , further comprising:

detecting the violation by detecting a mismatch between a public key and the firmware feature description file, wherein the key certificate associates the first entity identifier with the public key.

9 . The method of claim 1 , further comprising:

detecting the violation in response to a mismatch between the first entity identifier and a second entity identifier recorded in the processing device.

10 . The method of claim 1 , further comprising:

detecting the violation when the set of firmware features exceeds an approved set of firmware features.

11 . A computing device, comprising:

authentication logic circuitry configured to, in response to a request to enable a set of firmware features in a processing device, perform a validation process based on a key certificate associating a first entity identifier with a firmware feature description file indicating the set of firmware features, wherein the first entity identifier is associated with a user entity; and

countermeasure logic circuitry coupled with the authentication logic circuitry and configured to, in response to a violation detected during the validation process, enable a countermeasure in the processing device.

12 . The computing device of claim 11 , wherein the countermeasure logic circuitry is further configured to enable the countermeasure by:

disabling one or more of a cache device and a processing core in the processing device.

13 . The computing device of claim 11 , wherein the countermeasure logic circuitry is further configured to enable the countermeasure by:

transmitting an indication of the violation to a remote server; and

limiting a clock frequency of one or more circuit components in the processing device.

14 . The computing device of claim 11 , further comprising:

a memory device coupled with the authentication logic circuitry and configured to store the key certificate, wherein:

the key certificate associates the first entity identifier with a public key, and

the authentication logic circuitry is configured to detect the violation by detecting a mismatch between the public key and the firmware feature description file.

15 . The computing device of claim 11 , further comprising:

a memory device coupled with the authentication logic circuitry and configured to store the key certificate; and

wherein the authentication logic circuitry is configured to detect the violation in response to a mismatch between the first entity identifier and a second entity identifier recorded in the processing device.

16 . The computing device of claim 11 , further comprising:

a one-time programmable memory region coupled with the authentication logic circuitry and configured to record the first entity identifier and an approved set of firmware features, wherein the authentication logic circuitry is further configured to detect the violation when the set of firmware features exceeds the approved set of firmware features.

17 . A computing system, comprising:

a server device configured to generate a key certificate; and

a processing device coupled with the server device, comprising:

authentication logic circuitry configured to, in response to a request to enable a set of firmware features in the processing device, perform a validation process based on the key certificate, wherein the key certificate associates a first entity identifier with a firmware feature description file indicating the set of firmware features, wherein the first entity identifier is associated with a user entity; and

countermeasure logic circuitry coupled with the authentication logic circuitry and configured to, in response to a violation detected during the validation process, enable a countermeasure in the processing device.

18 . The computing system of claim 17 , wherein:

the server device is further configured to:

in response to receiving an entity identifier request from a user entity, perform a lookup of the user entity in a database,

in response to determining that the user entity is not associated with an existing entity identifier, associate the user entity with a new entity identifier in the database, and

in response to receiving a certificate signing request including a public key of the user entity, generate the key certificate associating the user entity with the public key by signing the public key using a root key associated with the processing device; and

the authentication logic circuitry is further configured to perform the validation process based on the new entity identifier.

19 . The computing system of claim 17 , wherein the server device is configured to:

in response to receiving a certificate signing request including a public key of a user entity, generate a key certificate associating the user entity with the public key by signing the public key using a root key associated with the processing device.

20 . The computing system of claim 17 , wherein:

the server device is further configured to, after enabling of the requested set of firmware features, receive operational data recorded during operation of the processing device; and

the countermeasure logic circuitry is further configured to transmit an indication of the violation and the enabled countermeasure to the server device.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 20, 2021
From: PENG, TAN; SWANSTROM, SCOTT
To: ADVANCED MICRO DEVICES, INC.
Reel/Frame 058172/0477 →
Continuity (2)
Provisional Application 63142467 · Jan 27, 2021
Related Publication 20220237297A1 · Jul 28, 2022
References Cited (13)
US 8966657B2 · Martinez et al. · 2015 [cited by applicant]
US 11080387B1 · Lattin et al. · 2021 [cited by applicant]
US 20090055695A1 · Maddali · 2009 [cited by examiner]
US 20160191253A1 · Pyle · 2016 [cited by applicant]
US 20170003956A1 · Chang · 2017 [cited by examiner]
US 20190073212A1 · Ishimoto et al. · 2019 [cited by applicant]
US 20210288821A1 · Young · 2021 [cited by examiner]
US 20220207125A1 · Young · 2022 [cited by examiner]
“Public key certificate”, wikipedia, https://en.wikipedia.org/wiki/Public_key_certificate, Dec. 2020, 11 pages (Year: 2020). [cited by examiner]
Non-Final Office Action issued in U.S. Appl. No. 17/546,577, mailed Jun. 20, 2024, 14 pages. [cited by applicant]
Non-Final Office Action issued in U.S. Appl. No. 17/565.577, mailed Oct. 24, 2024, 19 pages. [cited by applicant]
Non-Final Office Action mailed Apr. 8, 2025 for U.S. Appl. No. 17/546,577, 22 pages. [cited by applicant]
Final Office Action mailed Jul. 30, 2025 for U.S. Appl. No. 17/546,577, 5 pages. [cited by applicant]