Performing an action based on a pre-boot measurement of a firmware image
Abstract
Examples disclosed herein relate to performing an action based on a pre-boot measurement of a firmware image. In an example, at a firmware component in a system, a measurement of a firmware image may be determined prior to booting of the system, beginning from a hardware root of trust boot block, by a Trusted Platform Module (TPM) emulator engine that emulates a hardware-based TPM. A pre-determined measurement of the firmware image may be retrieved from a storage location within the system. The measurement of the firmware image may be compared with the pre-determined measurement of the firmware image prior to booting of the system. In response to a determination that the measurement of the firmware image is different from the pre-determined measurement of the firmware image, performing an action.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method comprising:
determining, at a firmware component in a system, a measurement of a firmware image prior to booting of the system, wherein the measurement is performed, beginning from a hardware root of trust boot block; retrieving, at the firmware component, a pre-determined measurement of the firmware image from a storage location; comparing, at the firmware component, the measurement of the firmware image with the pre-determined measurement of the firmware image prior to booting of the system; and continuing the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system.
22 . The method of claim 21 , wherein the firmware component is a management processor.
23 . The method of claim 21 , storing the measurement of the firmware image in a virtual Platform Configuration Register (PCR) in the firmware component.
24 . The method of claim 21 , wherein determining the measurement of the firmware image comprises generating a hash of the firmware image.
25 . The method of claim 21 , wherein the system is running on auxiliary power.
26 . The method of claim 21 , wherein the system is without a hardware-based TPM.
27 . A system comprising:
a processor; a management processor separate from the processor; and a memory to store firmware instructions that, when executed by the management processor, cause the management processor to:
access a firmware image;
determine a measurement of the firmware image beginning from a hardware root of trust boot block prior to booting of the system, storing the measurement of the firmware image in a virtual Platform Configuration Register (PCR), and continuing the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system;
retrieve a pre-determined measurement of the firmware image from a whitelisted database;
compare the measurement of the firmware image with the pre-determined measurement of the firmware image prior to booting of the system; and
perform an action, in response to a determination whether the measurement of the firmware image is different from the pre-determined measurement of the firmware image.
28 . The system of claim 27 , further comprising a remote server management processor that allows management of the system from a remote location.
29 . The system of claim 27 , wherein the measurement includes a hash of the firmware image.
30 . The system of claim 27 , the determination of the measurement emulates a service provided by a hardware-based TPM.
31 . The system of claim 27 , further comprising one of an input/output (I/O) component, a complex programmable logic device (CPLD), and a power supply component.
32 . The system of claim 27 , wherein the action includes disabling a firmware component associated with the firmware image.
33 . A non-transitory machine-readable storage medium comprising instructions, the instructions executable by a management processor to:
receive, a request to attest a firmware image, generate, a hash of the firmware image, prior to boot of the system, wherein the hash is generated, beginning from a hardware root of trust boot block; retrieve a pre-determined measurement of the firmware image from a storage location external to the system; compare, the measurement of the firmware image with the pre-determined measurement of the firmware image prior to boot of the system; and continue the measurement along a chain of trust based on the hardware root of trust boot block during boot of the system.
34 . The storage medium of claim 33 , further comprising instructions to perform an action, in response to a determination whether the measurement of the firmware image is different from the pre-determined measurement of the firmware image;
35 . The storage medium of claim 33 , further comprising instructions to allow boot of the system, in response to a determination that the measurement of the firmware image is not different from the pre-determined measurement of the firmware image.
36 . The storage medium of claim 33 , wherein the firmware image includes a firmware image of a second firmware component in the system.
37 . The storage medium of claim 33 , wherein the action is defined in a user-defined policy.
38 . The storage medium of claim 33 , wherein the firmware image includes a firmware image of system firmware of the system.
39 . The storage medium of claim 33 , wherein the action includes disabling a power supply to the system.
40 . The storage medium of claim 33 , wherein the measurement along the chain of trust includes validation of another piece of code after comparison of the firmware image.Join the waitlist — get patent alerts
Track US2020272739A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.