US2020272739A1PendingUtilityA1

Performing an action based on a pre-boot measurement of a firmware image

Assignee: HEWLETT PACKARD ENTPR DEV LPPriority: May 12, 2017Filed: May 14, 2020Published: Aug 27, 2020
Est. expiryMay 12, 2037(~10.8 yrs left)· nominal 20-yr term from priority
G06F 8/63H04L 9/0897G06F 2221/2141G06F 21/575G06F 9/4401H04L 9/3234
58
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Examples disclosed herein relate to performing an action based on a pre-boot measurement of a firmware image. In an example, at a firmware component in a system, a measurement of a firmware image may be determined prior to booting of the system, beginning from a hardware root of trust boot block, by a Trusted Platform Module (TPM) emulator engine that emulates a hardware-based TPM. A pre-determined measurement of the firmware image may be retrieved from a storage location within the system. The measurement of the firmware image may be compared with the pre-determined measurement of the firmware image prior to booting of the system. In response to a determination that the measurement of the firmware image is different from the pre-determined measurement of the firmware image, performing an action.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method comprising:
 determining, at a firmware component in a system, a measurement of a firmware image prior to booting of the system, wherein the measurement is performed, beginning from a hardware root of trust boot block;   retrieving, at the firmware component, a pre-determined measurement of the firmware image from a storage location;   comparing, at the firmware component, the measurement of the firmware image with the pre-determined measurement of the firmware image prior to booting of the system; and   continuing the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system.   
     
     
         22 . The method of  claim 21 , wherein the firmware component is a management processor. 
     
     
         23 . The method of  claim 21 , storing the measurement of the firmware image in a virtual Platform Configuration Register (PCR) in the firmware component. 
     
     
         24 . The method of  claim 21 , wherein determining the measurement of the firmware image comprises generating a hash of the firmware image. 
     
     
         25 . The method of  claim 21 , wherein the system is running on auxiliary power. 
     
     
         26 . The method of  claim 21 , wherein the system is without a hardware-based TPM. 
     
     
         27 . A system comprising:
 a processor;   a management processor separate from the processor; and   a memory to store firmware instructions that, when executed by the management processor, cause the management processor to:
 access a firmware image; 
 determine a measurement of the firmware image beginning from a hardware root of trust boot block prior to booting of the system, storing the measurement of the firmware image in a virtual Platform Configuration Register (PCR), and continuing the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system; 
 retrieve a pre-determined measurement of the firmware image from a whitelisted database; 
 compare the measurement of the firmware image with the pre-determined measurement of the firmware image prior to booting of the system; and 
 perform an action, in response to a determination whether the measurement of the firmware image is different from the pre-determined measurement of the firmware image. 
   
     
     
         28 . The system of  claim 27 , further comprising a remote server management processor that allows management of the system from a remote location. 
     
     
         29 . The system of  claim 27 , wherein the measurement includes a hash of the firmware image. 
     
     
         30 . The system of  claim 27 , the determination of the measurement emulates a service provided by a hardware-based TPM. 
     
     
         31 . The system of  claim 27 , further comprising one of an input/output (I/O) component, a complex programmable logic device (CPLD), and a power supply component. 
     
     
         32 . The system of  claim 27 , wherein the action includes disabling a firmware component associated with the firmware image. 
     
     
         33 . A non-transitory machine-readable storage medium comprising instructions, the instructions executable by a management processor to:
 receive, a request to attest a firmware image,   generate, a hash of the firmware image, prior to boot of the system, wherein the hash is generated, beginning from a hardware root of trust boot block;   retrieve a pre-determined measurement of the firmware image from a storage location external to the system;   compare, the measurement of the firmware image with the pre-determined measurement of the firmware image prior to boot of the system; and   continue the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system.   
     
     
         34 . The storage medium of  claim 33 , further comprising instructions to perform an action, in response to a determination whether the measurement of the firmware image is different from the pre-determined measurement of the firmware image; 
     
     
         35 . The storage medium of  claim 33 , further comprising instructions to allow boot of the system, in response to a determination that the measurement of the firmware image is not different from the pre-determined measurement of the firmware image. 
     
     
         36 . The storage medium of  claim 33 , wherein the firmware image includes a firmware image of a second firmware component in the system. 
     
     
         37 . The storage medium of  claim 33 , wherein the action is defined in a user-defined policy. 
     
     
         38 . The storage medium of  claim 33 , wherein the firmware image includes a firmware image of system firmware of the system. 
     
     
         39 . The storage medium of  claim 33 , wherein the action includes disabling a power supply to the system. 
     
     
         40 . The storage medium of  claim 33 , wherein the measurement along the chain of trust includes validation of another piece of code after comparison of the firmware image.

Join the waitlist — get patent alerts

Track US2020272739A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.