IP Library › Granted Patent US 12,430,440
Granted Patent B2
US 12,430,440 · App. 17/739,832 · Granted Sep 30, 2025

System and method for firmware security event mitigation

Inventor: Timothy Andrew Lewis (El Dorado Hills, CA)
Assignee: Insyde Software Corp.
G06F21/572G06F9/545G06F21/554
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,430,440
App. No.
17/739,832
Granted
Sep 30, 2025
Kind
B2
Abstract

Systems and methods for performing security event mitigation with firmware are discussed. A firmware-based security event framework receives notifications of security events occurring in a firmware-controlled operating environment on a computing platform, logs information related to the event and optionally performs mitigation operations to address the security event.

Claims (33)

1. A non-transitory medium holding executable instructions for performing security event mitigation with firmware on a computing platform equipped with one or more processors, the instructions when executed causing the computing platform to:

receive notification of detection of an occurrence of a security event occurring within a privileged firmware-controlled operating environment running outside the control of a main hypervisor or operating system on the computing platform, the detection occurring during runtime following completion of a boot sequence for the computing platform and a transition of control to the privileged firmware-controlled operating environment from the main hypervisor or operating system,

wherein the security event detected is one of unauthorized memory access, unauthorized register access, unauthorized use of specified privileged instructions, buffer overflow or integer arithmetic faults;

log, with the firmware, information regarding the cause of the event in a non-volatile storage location;

generate, with the firmware, a notification of the security event;

reset the computing platform based on the detection before performing a mitigation of the security event and

perform, with the firmware, a mitigation of the security event after the resetting of the computing platform.

2. The medium of claim 1 , wherein the mitigation blocks a firmware module from executing after the reset of the computing platform.

3. The medium of claim 1 , wherein the mitigation re-flashes an entire BIOS image, a firmware volume that contains a module causing the security event, or a specific driver causing the security event.

4. The medium of claim 1 , wherein the security event is caused by code executing when one or more processors of the computing platform are in System Management Mode.

5. The medium of claim 1 , wherein the security event is detected using central processing unit and chipset resources.

6. The medium of claim 1 , wherein the security event is detected at runtime using code injected by a compiler during build time.

7. A method for performing security event mitigation with firmware on a computing platform equipped with one or more processors, comprising:

receiving notification of detection of an occurrence of a security event occurring within a privileged firmware-controlled operating environment running outside the control of a main hypervisor or operating system on the computing platform, the detection occurring during runtime following completion of a boot sequence for the computing platform and a transition of control to the privileged firmware-controlled operating environment from the main hypervisor or operating system,

wherein the security event detected is one of unauthorized memory access, unauthorized register access, unauthorized use of specified privileged instructions, buffer overflow or integer arithmetic faults;

logging, with the firmware, information regarding the cause of the event in a non-volatile storage location;

generating, with the firmware, a notification of the security event;

resetting the computing platform based on the detection before performing a mitigation of the security event; and

performing, with the firmware, a mitigation of the security event after the resetting of the computing platform.

8. The method of claim 7 , wherein the mitigation blocks a firmware module from executing after the reset of the computing platform.

9. The method of claim 7 , wherein the mitigation re-flashes an entire BIOS image, a firmware volume that contains a module causing the security event, or a specific driver causing the security event.

10. The method of claim 7 , wherein the security event is caused by code executing when one or more processors of the computing platform are in System Management Mode.

11. The method of claim 7 , wherein the security event is detected using central processing unit and chipset resources.

12. The method of claim 7 , wherein the security event is detected at runtime using code injected by a compiler during build time.

13. A computing platform, comprising:

one or more processors; and

firmware including a security event framework, the security event framework including one or more firmware modules that when executed:

receive notification of an occurrence of a security event occurring within a privileged firmware-controlled operating environment running outside the control of a main hypervisor or operating system on the computing platform, the detection occurring during runtime following completion of a boot sequence for the computing platform and a transition of control to the privileged firmware-controlled operating environment from the main hypervisor or operating system,

wherein the security event detected is one of unauthorized memory access, unauthorized register access, unauthorized use of specified privileged instructions, buffer overflow or integer arithmetic faults;

log, with the firmware, information regarding the cause of the event in a non-volatile storage location;

generate, with the firmware, a notification of the security event;

reset the computing platform based on the detection before performing a mitigation of the security event; and

perform, with the firmware, a mitigation of the security event.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 9, 2022
From: LEWIS, TIMOTHY A.
To: INSYDE SOFTWARE CORP.
Reel/Frame 059873/0986 →
Continuity (2)
Provisional Application 63186522 · May 10, 2021
Related Publication 20220358222A1 · Nov 10, 2022
References Cited (42)
US 6922722B1 · Mann · 2005 [cited by examiner]
US 7206833B1 · Sarangam · 2007 [cited by examiner]
US 8874892B1 · Chan · 2014 [cited by examiner]
US 10855674B1 · Geusz · 2020 [cited by examiner]
US 11036543B1 · Swanson · 2021 [cited by examiner]
US 20040123090A1 · Zimmer · 2004 [cited by examiner]
US 20040236960A1 · Zimmer · 2004 [cited by examiner]
US 20050086523A1 · Zimmer · 2005 [cited by examiner]
US 20090300415A1 · Zhang · 2009 [cited by examiner]
US 20110320798A1 · Zimmer · 2011 [cited by examiner]
US 20130013905A1 · Held · 2013 [cited by examiner]
US 20130067534A1 · Soffer · 2013 [cited by examiner]
US 20140075549A1 · Lewis · 2014 [cited by examiner]
US 20160077905A1 · Menon · 2016 [cited by examiner]
US 20160212159A1 · Gupta · 2016 [cited by examiner]
US 20160217283A1 · Liu · 2016 [cited by examiner]
US 20160378576A1 · Jayakumar · 2016 [cited by examiner]
US 20170061130A1 · Ghafoor · 2017 [cited by examiner]
US 20170262352A1 · Jeansonne · 2017 [cited by examiner]
US 20180096151A1 · Ghetie · 2018 [cited by examiner]
US 20180203629A1 · Poornachandran · 2018 [cited by examiner]
US 20180232521A1 · Jeansonne · 2018 [cited by examiner]
US 20190207969A1 · Brown · 2019 [cited by examiner]
US 20200042324A1 · Ayolasomyajula · 2020 [cited by examiner]
US 20200050510A1 · Chien · 2020 [cited by examiner]
US 20200074086A1 · Bulygin · 2020 [cited by examiner]
US 20200250017A1 · Samuel · 2020 [cited by examiner]
US 20200257521A1 · Jayakumar · 2020 [cited by examiner]
US 20210026967A1 · Suryanarayana · 2021 [cited by examiner]
US 20210397713A1 · Ndu · 2021 [cited by examiner]
US 20220148675A1 · Chin · 2022 [cited by examiner]
US 20220222349A1 · Lambert · 2022 [cited by examiner]
US 20220358222A1 · Lewis · 2022 [cited by examiner]
US 20230018085A1 · Khatri · 2023 [cited by examiner]
CN 108292342A · 2018 [cited by examiner]
NPL Search History (Year: 2023). [cited by examiner]
NPL Search History (Year: 2024). [cited by examiner]
Brais, Visual C++ Support for Stack-Based Buffer Protection. MSDN Magazine, Retrieved online at: https://docs.microsoft.com/en-us/archive/msdn-magazine/2017/december/c-visual-c-support-for-stack-based-buffer-protection.… [cited by applicant]
Endicott, Secured-core PCs protect your data down to the hardware. Windows Central, Retrieved online at: https://www.windowscentral.com/secured-core-pcs-use-hardware-isolation-and-firmware-level-protection-secure-device… [cited by applicant]
Igor's Blog, In-depth dive into the security features of the Intel/Windows platform secure boot process. Retrieved online at: https://igor-blue.github.io/2021/02/04/secure-boot.html. 19 pages, Feb. 4, 2021. [cited by applicant]
Yao et al., Intel® Platform Firmware Resilience (Intel® PFR). Understanding UEFI Secure boot Chain. tianocore. Retrieved online at: https://edk2-docs.gitbook.io/understanding-the-uefi-secure-boot-chain/looking_forward__… [cited by applicant]
Yao et al., Stack Canaries. A Tour Beyond BIOS—Security Enhancement to Mitigate Buffer Overflow in UEFI. tianocore, Retrieved online at: https://edk2-docs.gitbook.io/a-tour-beyond-bios-mitigate-buffer-overflow-in-ue/sta… [cited by applicant]