IP Library › Granted Patent US 9,384,351
Granted Patent B2
US 9,384,351 · App. 13/839,892 · Granted Jul 5, 2016

Method and apparatus for implementing a secure boot using multiple firmware sources

Inventors: Ivan Herrera Mejia (Folsom, CA); Kenneth D. Shoemaker (Los Altos Hills, CA)
Assignee: Intel Corporation
G06F21/575G06F21/572H01L27/11206
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,384,351
App. No.
13/839,892
Granted
Jul 5, 2016
Kind
B2
Abstract

Technologies for implementing a secure boot using multiple firmware sources are described. One or more fuses of a processing device can be configured. Based on such configuration, one or more keys can be generated. Based on the configuration of the various fuses, an operation of a firmware device can be initiated. Using the generated key(s), a protected section of the firmware device can be accessed.

Claims (44)

1. An apparatus for selecting a runtime firmware, the apparatus comprising:

a firmware device; and

a processing device coupled to the firmware device, the processing device having one or more fuses, wherein the processing device is to:

configure at least one of the one or more fuses in accordance with a fuse configuration sequence that corresponds to the firmware device;

generate, based on a configuration of the one or more fuses in accordance with the fuse configuration sequence, a Replay Protected Memory Block (RPMB) key;

initiate, based on the configuration of the at least one of the one or more fuses, operation of the firmware device; and

request, with the RPMB key, a firmware from the firmware device.

2. The apparatus of claim 1 , wherein the processing device is further to:

access, with the RPMB key, a protected section of the firmware device, the protected section containing the firmware.

3. The apparatus of claim 1 , wherein the configuration of the at least one of the one or more fuses comprises a configuration of the at least one of the one or more fuses that corresponds to the firmware device.

4. The apparatus of claim 1 , wherein the firmware device comprises a memory.

5. The apparatus of claim 1 , wherein the firmware device comprises a flash memory.

6. A method for selecting a runtime firmware, the method comprising:

configuring at least one of one or more fuses of a processing device in accordance with a fuse configuration sequence that corresponds to a firmware device;

generating, based on a configuration of the one or more fuses in accordance with the fuse configuration sequence, a Replay Protected Memory Block (RPMB) key;

initiating, based on a configuration of the at least one of the one or more fuses, operation of the firmware device; and

requesting, with the RPMB key, a firmware from the firmware device.

7. The method of claim 6 , further comprising:

accessing, with the RPMB key, a protected section of the firmware device, the protected section containing the firmware.

8. The method of claim 6 , wherein the configuration of the at least one of the one or more fuses comprises a configuration of the at least one of the one or more fuses that corresponds to the firmware device.

9. The method of claim 6 , wherein the firmware device comprises a memory.

10. The method of claim 6 , wherein the firmware device comprises a flash memory.

11. A non-transitory, computer-readable storage medium including instructions that, when executed by a computing system, cause the computing system to:

configure at least one of one or more fuses of a processing device in accordance with a fuse configuration sequence that corresponds to a firmware device;

generate, based on a configuration of the one or more fuses in accordance with the fuse configuration sequence, a Replay Protected Memory Block (RPMB) key;

initiate, based on a configuration of the at least one of the one or more fuses, operation of the firmware device; and

request, with the RPMB key, a firmware from the firmware device.

12. The storage medium 11 , further comprising instructions that, when executed by a computing system, cause the computing system to:

access, with the RPMB key, a protected section of the firmware device, the protected section containing the firmware.

13. The storage medium of claim 11 , wherein the configuration of the at least one of the one or more fuses comprises a configuration of the at least one of the one or more fuses that corresponds to the firmware device.

14. The storage medium of claim 11 , wherein the firmware device comprises a memory.

15. The storage medium of claim 11 , wherein the firmware device comprises a flash memory.

16. A system for selecting a runtime firmware, the system comprising:

a firmware device; and

a processor coupled to the firmware device, the processor having one or more fuses, wherein the processor is to:

configure at least one of the one or more fuses in accordance with a fuse configuration sequence that corresponds to the firmware device;

generate, based on a configuration of the one or more fuses in accordance with the fuse configuration sequence, a Replay Protected Memory Block (RPMB) key;

initiate, based on a configuration of the at least one of the one or more fuses, operation of the firmware device; and

request, with the RPMB key, a firmware from the firmware device.

17. The system of claim 16 , wherein the processor is further to:

access, with the RPMB key, a protected section of the firmware device, the protected section containing the firmware.

18. The system of claim 16 , wherein the configuration of the at least one of the one or more fuses comprises a configuration of the at least one of the one or more fuses that corresponds to the firmware device.

19. The system of claim 16 , wherein the firmware device comprises a memory.

20. The system of claim 16 , wherein the firmware device comprises a flash memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 10, 2013
From: HERRERA MEJIA, IVAN; SHOEMAKER, KENNETH D.
To: INTEL CORPORATION
Reel/Frame 030187/0363 →
Continuity (1)
Related Publication 20140281456A1 · Sep 18, 2014