IP Library › Granted Patent US 12,670,258
Granted Patent B2
US 12,670,258 · App. 18/426,561 · Granted Jun 30, 2026

Firmware verification mechanism

Inventors: Prashant Dewan (Portland, OR); Chao Zhang (Shanghai, CN); Nivedita Aggarwal (Portland, OR); Aditya Katragada (Austin, TX); Mohamed Haniffa (Tamilnadu, IN); Kenji Chen (Taiwan, CN)
Assignee: Intel Corporation
G06F21/572G06F8/65G06F21/64G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,670,258
App. No.
18/426,561
Filed
Jan 30, 2024
Granted
Jun 30, 2026
Kind
B2
Art Unit
2435
USPC
726/25
Abstract

An apparatus to verify firmware in a computing system, comprising a non-volatile memory, including firmware memory to store agent firmware associated with each of a plurality of interconnect protocol (IP) agents and version memory to store security version numbers (SVNs) included in the agent firmware, a security controller comprising verifier logic to verify an integrity of the version memory by applying a hash algorithm to contents of the version memory to generate a SVN hash, and a trusted platform module (TPM) to store the SVN hash.

Claims (36)

1 . An apparatus comprising:

non-volatile memory coupled to processing circuitry, the non-volatile memory comprising:

firmware memory to store agent firmware associated with an interconnect protocol (IP) agent;

version memory to store security version numbers (SVNs) included in the agent firmware;

a security controller to examine a breadcrumb token indicating an IP agent having a version number that is to be updated and store a SVN in the version memory upon determining that the identifier indicates that the version number is to be updated, wherein the security controller to facilitate storing the SVN upon validating the agent firmware.

2 . The apparatus of claim 1 , further comprising a storage register to store the breadcrumb token.

3 . The apparatus of claim 2 , wherein the storage register comprises a persistent storage accessible by a basic input output system (BIOS) and an operating system.

4 . The apparatus of claim 1 , wherein the security controller is further to generate a SVN hash of the contents of the version memory.

5 . The apparatus of claim 4 , further comprising a trusted platform module (TPM) to store the SVN hash.

6 . The apparatus of claim 4 , wherein the security controller is further to verify integrity of the version memory by generating a check hash of the contents of the version memory and comparing the check hash to the SVN hash.

7 . The apparatus of claim 6 , wherein the security controller is further to verify the integrity of the agent firmware upon determining that the check hash matches the SVN hash.

8 . The apparatus of claim 1 , wherein the security controller is further to facilitate storing the SVNs store the SVN at the version memory upon storing the agent firmware in the firmware memory, the processing circuitry comprising application processing circuitry.

9 . At least one non-transitory computer readable medium having stored thereon instructions which, when executed, cause a computing device to perform operations comprising:

receiving agent firmware including a security version number (SVN);

examining a breadcrumb token indicating an interconnect protocol (IP) agent having a version number that is to be updated; and

storing the SVN in version memory of non-volatile memory of the computing device upon determining that the identifier indicates that the version number is to be updated, and further storing the SVN upon validating agent firmware.

10 . The non-transitory computer readable medium of claim 9 , wherein the operations further comprise:

generating a SVN hash of the contents of the version memory; and

storing the SVN hash.

11 . The non-transitory computer readable medium of claim 10 , wherein the operations further comprise:

generating a check hash of the contents of the version memory; and

comparing the check hash to the SVN hash.

12 . The non-transitory computer readable medium of claim 11 , wherein verifying the integrity of the agent firmware further comprises determining that the check hash matches the SVN hash.

13 . The non-transitory computer readable medium of claim 9 , wherein the operations further comprise storing the SVN at the version memory upon storing the received agent firmware in firmware memory of the non-volatile memory coupled with processing circuitry having application processing circuitry.

14 . A method comprising:

receiving agent firmware including a security version number (SVN);

examining a breadcrumb token indicating an interconnect protocol (IP) agent having a version number that is to be updated; and

storing the SVN in version memory of non-volatile memory of the computing device upon determining that the identifier indicates that the version number is to be updated, and further storing the SVN upon validating agent firmware.

15 . The method of claim 14 , further comprising:

generating a SVN hash of the contents of the version memory; and

storing the SVN hash.

16 . The method of claim 15 , further comprising:

generating a check hash of the contents of the version memory; and

comparing the check hash to the SVN hash.

17 . The method of claim 16 , wherein verifying the integrity of the agent firmware further comprises determining that the check hash matches the SVN hash.

18 . The method of claim 17 , wherein the operations further comprise storing the SVN at the version memory upon storing the received agent firmware in firmware memory of the non-volatile memory coupled with processing circuitry having application processing circuitry.

Continuity (3)
Continuation 17852814 · Jun 29, 2022
Continuation 16832152 · Mar 27, 2020
Related Publication 20240378294A1 · Nov 14, 2024
References Cited (37)
US 9274839B2 · Schluessler · 2016 [cited by examiner]
US 9397835B1 · Campagna et al. · 2016 [cited by applicant]
US 10311224B1 · Farhan et al. · 2019 [cited by applicant]
US 10366232B1 · Kuan et al. · 2019 [cited by applicant]
US 11281769B2 · Gu et al. · 2022 [cited by applicant]
US 11520891B1 · Karolitsky · 2022 [cited by examiner]
US 20040054501A1 · Barthel · 2004 [cited by examiner]
US 20060107032A1 · Paaske · 2006 [cited by examiner]
US 20070118530A1 · Chow et al. · 2007 [cited by applicant]
US 20070143629A1 · Hardjono et al. · 2007 [cited by applicant]
US 20080052698A1 · Olson · 2008 [cited by examiner]
US 20080195868A1 · Asokan et al. · 2008 [cited by applicant]
US 20090041252A1 · Hanna · 2009 [cited by applicant]
US 20090165097A1 · Cherian · 2009 [cited by examiner]
US 20090169017A1 · Smith et al. · 2009 [cited by applicant]
US 20110087872A1 · Shah · 2011 [cited by examiner]
US 20120137137A1 · Brickell et al. · 2012 [cited by applicant]
US 20140250290A1 · Ståhl et al. · 2014 [cited by applicant]
US 20150134970A1 · Jang · 2015 [cited by examiner]
US 20160028725A1 · Benoit et al. · 2016 [cited by applicant]
US 20160103994A1 · Murakami · 2016 [cited by examiner]
US 20160112203A1 · Thom et al. · 2016 [cited by applicant]
US 20160306977A1 · Zarakas et al. · 2016 [cited by applicant]
US 20170010875A1 · Martinez et al. · 2017 [cited by applicant]
US 20170010881A1 · Kawazu · 2017 [cited by examiner]
US 20170090896A1 · Lin · 2017 [cited by applicant]
US 20170249135A1 · Gandhi · 2017 [cited by examiner]
US 20170308705A1 · Karaginides et al. · 2017 [cited by applicant]
US 20180060607A1 · Tasher et al. · 2018 [cited by applicant]
US 20190042725A1 · Ruan · 2019 [cited by examiner]
US 20190138294A1 · Smith et al. · 2019 [cited by applicant]
US 20200019397A1 · Duran et al. · 2020 [cited by applicant]
US 20200226261A1 · Dewan et al. · 2020 [cited by applicant]
CN 113449284A · 2021 [cited by applicant]
Basnight, Zachry et al. “Firmware Modification Attacks on Programmable Logic Controllers”, International Journal of Critical Infrastructure Protection, vol. 6, Issue 2, 2013, pp. 76-84. (Year: 2013). [cited by applicant]
Notice of Allowance for U.S. Appl. No. 16/832,152 mailed Apr. 8, 2022, 9 pages. [cited by applicant]
Notice of Allowance for U.S. Appl. No. 17/852,814 mailed Nov. 13, 2023, 9 pages. [cited by applicant]