IP Library Granted Patent US 11,556,327
Granted Patent B2
US 11,556,327 · App. 16/988,976 · Granted Jan 17, 2023

SOC-assisted resilient boot

Inventors: Karunakara Kotary (Portland, OR); Michael Kubacki (Hillsboro, OR); Sean Dardis (Hillsboro, OR)
Assignee: Intel Corporation
G06F8/65G06F8/654G06F8/66G06F9/4401G06F21/44G06F21/57G06F21/575G06F8/71G06F21/12G06F21/566G06F21/572G06F21/577G06F21/64G06F21/74G06F21/78G06F21/82
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,556,327
App. No.
16/988,976
Granted
Jan 17, 2023
Kind
B2
Abstract

Systems, apparatuses and methods may provide for technology that assumes, by a root of trust located in a trusted region of a system on chip (SOC), control over a reset of the SOC and conducting, by the root of trust, an authentication of an update package in response to an update condition. The root of trust technology may also apply the update package to firmware located in non-volatile memory (NVM) associated with a microcontroller of the SOC if the authentication is successful.

Claims (37)

1. A computing device comprising:

non-volatile memory including firmware; and

a system on chip (SOC) including a plurality of microcontrollers and a trusted region, the trusted region including logic instructions to:

assume, via a root of trust, control over a reset of the SOC, wherein the root of trust is implemented in the trusted region of the SOC to prevent corruption,

conduct an authentication of an update package in response to an update condition, wherein the authentication includes determining boot critical portions and non-boot critical portions of the update package, and

apply the boot critical portions of the update package to the firmware if the authentication is successful, wherein the root of trust is to accelerate application of the update package to the firmware in response to the firmware being designated as boot critical firmware.

2. The computing device of claim 1 , wherein the control over the reset is assumed from an operating system of the SOC, and wherein the logic instructions, when executed, cause the computing device to transfer control over the reset back to the operating system via system firmware in response to the update package being successfully applied.

3. The computing device of claim 1 , wherein the update condition includes one or more of an update flag or a recovery flag being set.

4. The computing device of claim 3 , wherein the logic instructions are to clear one or more of the update flag or the recovery flag in response to the update package being successfully applied to the firmware.

5. The computing device of claim 1 , further comprising a boot media that includes an operating system of the SOC and a partition containing the update package, wherein the logic is to retrieve the update package from the partition.

6. A semiconductor apparatus comprising:

one or more substrates; and

logic coupled to the one or more substrates, wherein the logic is implemented in one or more of configurable logic or fixed-functionality hardware logic, the logic coupled to the one or more substrates to:

assume, via a root of trust, control over a reset of a system on chip (SOC), wherein the root of trust is implemented in a trusted region of the SOC to prevent corruption;

conduct an authentication of an update package in response to an update condition wherein the authentication includes determining boot critical portions and non-boot critical portions of the update package; and

apply the boot critical portions of the update package to firmware located in non-volatile memory associated with a microcontroller of the SOC if the authentication is successful, wherein the root of trust is to accelerate application of the update package to the firmware in response to the firmware being designated as boot critical firmware.

7. The apparatus of claim 6 , wherein the control over the reset is assumed from an operating system of the SOC, and wherein the logic coupled to the one or more substrates is to transfer control over the reset back to the operating system via system firmware in response to the update package being successfully applied.

8. The apparatus of claim 6 , wherein the update condition includes one or more of an update flag or a recovery flag being set.

9. The apparatus of claim 8 , wherein the logic coupled to the one or more substrates is to clear one or more of the update flag or the recovery flag in response to the update package being successfully applied to the firmware.

10. The apparatus of claim 6 , wherein the logic is to retrieve the update package from a partition in a boot media that contains an operating system of the SOC.

11. The apparatus of claim 6 , wherein the logic coupled to the one or more substrates includes transistor channel regions that are positioned within the one or more substrates.

12. At least one non-transitory computer readable storage medium comprising a set of instructions, which when executed by a computing device, cause the computing device to:

assume, via a root of trust, control over a reset of a system on chip (SOC), wherein the root of trust is implemented in a trusted region of the SOC to prevent corruption;

conduct an authentication of an update package in response to an update condition wherein the authentication includes determining boot critical portions and non-boot critical portions of the update package; and

apply the boot critical portions of the update package to firmware located in non-volatile memory associated with a microcontroller of the SOC if the authentication is successful, wherein the root of trust is to accelerate application of the update package to the firmware in response to the firmware being designated as boot critical firmware.

13. The at least one non-transitory computer readable storage medium of claim 12 , wherein the control over the reset is assumed from an operating system of the SOC, and wherein the instructions, when executed, cause the computing device to transfer control over the reset back to the operating system via system firmware in response to the update package being successfully applied.

14. The at least one non-transitory computer readable storage medium of claim 12 , wherein the update condition includes one or more of an update flag or a recovery flag being set.

15. The at least one non-transitory computer readable storage medium of claim 14 , wherein the instructions, when executed, cause the computing device to clear one or more of the update flag or the recovery flag in response to the update package being successfully applied to the firmware.

16. The at least one non-transitory computer readable storage medium of claim 12 , wherein the instructions, when executed, cause the computing device to retrieve the update package from a partition in a boot media that contains an operating system of the SOC.

17. A method comprising:

assuming, via a root of trust, control over a reset of a system on chip (SOC), wherein the root of trust is implemented in a trusted region of the SOC to prevent corruption;

conducting an authentication of an update package in response to an update condition, wherein the authentication includes determining boot critical portions and non-boot critical Portions of the update package; and

applying the boot critical portions of the update package to firmware located in non-volatile memory associated with a microcontroller of the SOC if the authentication is successful, wherein the root of trust accelerates application of the update package to the firmware in response to the firmware being designated as boot critical firmware.

18. The method of claim 17 , wherein the control over the reset is assumed from an operating system of the SOC, and wherein the method further includes transferring control over the reset back to the operating system via system firmware in response to the update package being successfully applied.

19. The method of claim 17 , wherein the update condition includes one or more of an update flag or a recovery flag being set.

20. The method of claim 19 , further including clearing one or more of the update flag or the recovery flag in response to the update package being successfully applied to the firmware.

21. The method of claim 17 , further including retrieving the update package from a partition in a boot media that contains an operating system of the SOC.

Continuity (2)
Continuation 15998801 · Aug 16, 2018
Related Publication 20210096840A1 · Apr 1, 2021