IP Library › Granted Patent US 11,409,877
Granted Patent B2
US 11,409,877 · App. 16/832,152 · Granted Aug 9, 2022

Firmware verification mechanism

Inventors: Prashant Dewan (Portland, OR); Chao Zhang (Shanghai, CN); Nivedita Aggarwal (Portland, OR); Aditya Katragada (Austin, TX); Mohamed Haniffa (Tamilnadu, IN); Kenji Chen (Taiwan, CN)
Assignee: Intel Corporation
G06F21/572G06F8/65G06F21/64G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,409,877
App. No.
16/832,152
Filed
Mar 27, 2020
Granted
Aug 9, 2022
Kind
B2
Art Unit
2435
USPC
726/25
Abstract

An apparatus to verify firmware in a computing system, comprising a non-volatile memory, including firmware memory to store agent firmware associated with each of a plurality of interconnect protocol (IP) agents and version memory to store security version numbers (SVNs) included in the agent firmware, a security controller comprising verifier logic to verify an integrity of the version memory by applying a hash algorithm to contents of the version memory to generate a SVN hash, and a trusted platform module (TPM) to store the SVN hash.

Claims (37)

1. An apparatus to verify firmware in a computing system, comprising:

a non-volatile memory, including:

firmware memory to store agent firmware associated with each of a plurality of interconnect protocol (IP) agents; and

version memory to store security version numbers (SVNs) included in the agent firmware;

a security controller comprising:

commit logic to store the SVNs into the version memory upon a determination that functionality of the received agent firmware has been validated; and

verifier logic to verify an integrity of the version memory by applying a hash algorithm to contents of the version memory to generate a SVN hash; and

a trusted platform module (TPM) to store the SVN hash.

2. The apparatus of claim 1 , wherein the verifier logic verifies an integrity of the version memory upon receiving agent firmware by applying the hash algorithm to contents of the version memory to generate a check hash and comparing the check hash to the SVN hash stored in the TPM.

3. The apparatus of claim 2 , wherein the verifier logic verifies an integrity of the agent firmware upon determining that the check hash matches the SVN hash.

4. The apparatus of claim 3 , wherein the verifier logic verifies the integrity of the agent firmware by determining whether a SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

5. The apparatus of claim 4 , wherein the received agent firmware is stored in the firmware memory upon a determination that the SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

6. The apparatus of claim 1 , wherein the verifier logic further performs a SVN rollback to store refurbished agent firmware.

7. At least one non-transitory computer readable medium having instructions stored thereon, which when executed by one or more processors, cause the processors to:

store security version numbers (SVNs) associated with agent firmware into a version memory included in a non-volatile memory upon a determination that functionality of received agent firmware has been validated;

verify an integrity of the version memory, including applying a hash algorithm to contents of the version memory to generate a SVN hash; and

store the SVN hash in a trusted platform module (TPM).

8. The computer readable medium of claim 7 , having instructions stored thereon, which when executed by one or more processors, further cause the processors to:

receive agent firmware;

verify an integrity of the version memory upon by applying the hash algorithm to contents of the version memory to generate a check hash; and

compare the check hash to the SVN hash stored in the TPM.

9. The computer readable medium of claim 8 , having instructions stored thereon, which when executed by one or more processors, further cause the processors to verify an integrity of the agent firmware upon determining that the check hash matches the SVN hash.

10. The computer readable medium of claim 9 , wherein verifying an integrity of the agent firmware comprises determining whether a SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

11. The computer readable medium of claim 10 , having instructions stored thereon, which when executed by one or more processors, cause the processors to store the received agent firmware in a firmware memory upon a determination that the SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

12. The computer readable medium of claim 11 , having instructions stored thereon, which when executed by one or more processors, cause the processors to store the SVN included in the received agent firmware into the version memory upon storing the received agent firmware in the firmware memory.

13. A method to verify firmware in a computing system, comprising:

storing security version numbers (SVNs) associated with agent firmware into a version memory included in a non-volatile memory upon a determination that functionality of received agent firmware has been validated;

verifying an integrity of the version memory, including applying a hash algorithm to contents of the version memory to generate a SVN hash; and

storing the SVN hash in a trusted platform module (TPM).

14. The method of claim 13 , further comprising:

receiving agent firmware;

verifying an integrity of the version memory upon by applying the hash algorithm to contents of the version memory to generate a check hash; and

comparing the check hash to the SVN hash stored in the TPM.

15. The method of claim 14 , further comprising verifying an integrity of the agent firmware upon determining that the check hash matches the SVN hash.

16. The method of claim 15 , wherein verifying an integrity of the agent firmware comprises determining whether a SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

17. The method of claim 16 , further comprising storing the received agent firmware in a firmware memory upon a determination that the SVN included in the received agent firmware is greater than a SVN associated with the agent firmware stored in the version memory.

18. The method of claim 17 , further comprising storing the SVN included in the received agent firmware into the version memory upon storing the received agent firmware in the firmware memory.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 11, 2021
From: DEWAN, PRASHANT; ZHANG, CHAO; AGGARWAL, NIVEDITA; KATRAGADA, ADITYA; HANIFFA, MOHAMED; CHEN, KENJI
To: INTEL CORPORATION
Reel/Frame 056514/0700 →
Continuity (1)
Related Publication 20200226261A1 · Jul 16, 2020