IP Library Granted Patent US 12,399,997
Granted Patent B2
US 12,399,997 · App. 17/923,390 · Granted Aug 26, 2025

Authentication of hardware component firmware

Inventors: Christopher H Stewart (Spring, TX); Baraneedharan Anbazhagan (Spring, TX)
Assignee: Hewlett-Packard Development Company, L.P.
G06F21/572G06F21/64
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,399,997
App. No.
17/923,390
Granted
Aug 26, 2025
Kind
B2
Abstract

An example apparatus may include a hardware component, a memory, and a processor. The processor may retrieve a firmware for the hardware component subsequent to the firmware being loaded on the hardware component. The processor may determine that a firmware signature associated with the firmware is stored in the memory. In some examples, in response to a determination that the firmware signature associated with the firmware is stored in the memory, the processor may initiate authentication of the firmware.

Claims (48)

1. An apparatus comprising:

a hardware component;

a memory; and

a processor to:

retrieve a firmware for the hardware component subsequent to the firmware being loaded on the hardware component;

determine whether a firmware signature associated with the firmware is stored in the memory;

in response to a determination that the firmware signature associated with the firmware is absent from the memory, initiate a recovery process to recover the firmware on the hardware component, wherein to initiate the recovery process, the processor is to:

disallow connection of the hardware component to a bus;

disable the hardware component;

replace the firmware for the hardware component; and

generate a notification indicating an authentication status of the firmware of the hardware component; and

in response to a determination that the firmware signature associated with the firmware is stored in the memory, initiate authentication of the firmware.

2. The apparatus of claim 1 , wherein the processor is to determine that the firmware is not authentic in response to the determination that the firmware signature associated with the firmware is not stored in the memory.

3. The apparatus of claim 1 , wherein, in response to a determination that the firmware signature associated with the firmware is stored in the memory, the processor is further to retrieve the firmware signature from the memory to a basic input/output system (BIOS) to authenticate the firmware.

4. The apparatus of claim 1 , wherein the processor is to:

determine whether a firmware update associated with the hardware component is stored in the memory; and

in response to a determination that the firmware is not authentic, initiate a firmware replacement process to replace the firmware with the firmware update.

5. The apparatus of claim 1 , wherein the memory is a storage of an embedded controller.

6. The apparatus of claim 5 , wherein:

the memory and the firmware signature are stored in the embedded controller; and

the processor is to execute a BIOS to allow or disallow connection of the hardware component during bootup of the apparatus in response to the firmware being authenticated using the firmware signature.

7. An apparatus comprising:

a hardware component;

a basic input/output system (BIOS);

an embedded controller having a memory; and

a processor to execute the BIOS to:

retrieve a firmware for the hardware component;

determine whether the firmware is inauthentic in response to a firmware signature associated with the firmware being absent from the memory of the embedded controller; and

in response to the determination that the firmware is inauthentic, initiate a recovery process to recover the firmware for the hardware component, wherein to initiate the recovery process, the process is to execute the BIOS to:

disallow connection of the hardware component to a bus;

disable the hardware component;

replace the firmware for the hardware component; and

generate a notification indicating an authentication status of the firmware of the hardware component.

8. The apparatus of claim 7 , wherein the processor is to execute the BIOS to further determine that the firmware is inauthentic in response to a verification process to authenticate the firmware using the firmware signature associated with the firmware.

9. The apparatus of claim 7 , wherein a firmware update associated with the hardware component is stored in the memory, and

in response to a determination that the firmware is inauthentic, the processor is to execute the BIOS to recover the firmware on the hardware component by replacing the firmware with the firmware update.

10. A non-transitory computer-readable medium on which is stored computer-readable instructions that when executed cause a processor of a computing device to:

retrieve a firmware for a hardware component of the computing device at bootup of the computing device, the firmware being previously updated at the hardware component;

initiate authentication of the firmware using a firmware signature stored in a memory;

in response to a determination that the authentication of the firmware has failed, initiate a recovery process, wherein to initiate the recovery process the instructions further cause the processor to:

disallow connection of the hardware component to a bus;

disable the hardware component

determine that a firmware update for the hardware component is stored in the memory;

replace the firmware with the firmware update at the hardware component;

generate a notification indicating an authentication status of the firmware of the hardware component; and

authorize the hardware component to establish a connection to the bus based on the firmware update.

11. The non-transitory computer-readable medium of claim 10 , wherein the instructions are further to cause the processor to:

determine that the authentication of the firmware has failed in response to a determination that the firmware signature does not match the firmware or in response to a determination that the firmware signature is absent from the memory.

Continuity (1)
Related Publication 20250077675A1 · Mar 6, 2025
References Cited (15)
US 8898654B2 · Young et al. · 2014 [cited by applicant]
US 9747094B2 · Shroni et al. · 2017 [cited by applicant]
US 20050021968A1 · Zimmer et al. · 2005 [cited by applicant]
US 20060143600A1 · Cottrell et al. · 2006 [cited by applicant]
US 20090327741A1 · Zimmer et al. · 2009 [cited by applicant]
US 20130013905A1 · Held et al. · 2013 [cited by applicant]
US 20140068594A1 · Young et al. · 2014 [cited by applicant]
US 20150089209A1 · Jacobs et al. · 2015 [cited by applicant]
US 20180089435A1 · Zander · 2018 [cited by examiner]
US 20190042229A1 · Kotary · 2019 [cited by examiner]
US 20200257518A1 · Liedtke · 2020 [cited by examiner]
US 20210216638A1 · Park · 2021 [cited by examiner]
US 20220179960A1 · Spangler · 2022 [cited by examiner]
EP 2141625B1 · 2015 [cited by applicant]
Cooper, D., et al., “BIOS Protection Guidelines”, Recommendations of the National Institute of Standards and Technology, Apr. 2011, NIST Special Publication 800-147, 26 pages [cited by applicant]