Memory device with secure boot updates and self recovery
US-2024406008-A1 · Dec 5, 2024 · US
US9053323B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9053323-B2 |
| Application number | US-78687407-A |
| Country | US |
| Kind code | B2 |
| Filing date | Apr 13, 2007 |
| Priority date | Apr 13, 2007 |
| Publication date | Jun 9, 2015 |
| Grant date | Jun 9, 2015 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A trusted component update system comprises verify logic configured to validate integrity of an update to a trusted component of a computing device, and logic disposed in the trusted component and configured to validate integrity of the verify logic.
Opening claim text (preview).
What is claimed is: 1. A trusted component update system, comprising: a computing device comprising a hardware processing unit; verify logic stored in memory of the computing device and executed by the processing unit to validate integrity of an update to a trusted component of the computing device, the update to modify content of the trusted component; and logic stored in a boot block of trusted memory of the trusted component and executed by the processing unit to validate integrity of the verify logic before the verify logic validates the integrity of the update, wherein the update to the trusted component comprises an update to the boot block of trusted memory of the trusted component, wherein the boot block provides boot-up functionality to the computing device. 2. The system of claim 1 , wherein the logic in the trusted component is configured to hash at least a portion of the verify logic and compare the hash of the verify logic with a predetermined hash value stored in the boot block of trusted memory of the trusted component to validate the integrity of the verify logic. 3. The system of claim 1 , wherein the verify logic is configured to validate integrity of a signature associated with the update. 4. The system of claim 1 , wherein the verify logic is configured to hash at least a portion of the update and compare the hash of the update to a decrypted digital signature signed by a trusted party to validate the integrity of the update. 5. The system of claim 1 , wherein the boot block of the trusted component is configured to determine availability of the update upon booting of the computing device. 6. The system of claim 1 , wherein the trusted component comprises a firmware flash memory. 7. A trusted component update method, comprising: validating, by a hardware processing unit of a computing device, integrity of an update to a trusted component of the computing device using verify logic stored in memory of the computing device, the update to change existing contents of the trusted component; and before the validating of the integrity of the update, validating, by the processing unit of the computing device, integrity of the verify logic using logic stored in a boot block of trusted memory of the trusted component, wherein the update to the trusted component comprises an update to the boot block of trusted memory of the trusted component, wherein the boot block provides boot-up functionality to the computing device. 8. The method of claim 7 , wherein validating the integrity of the update comprises validating integrity of a signature associated with the update. 9. The method of claim 7 , wherein validating the integrity of the verify logic comprises hashing at least a portion of the verify logic and comparing the hash of the verify logic with a predetermined hash value stored in the boot block of trusted memory of the trusted component. 10. The method of claim 7 , wherein validating the integrity of the update comprises hashing at least a portion of the update and comparing the hash of the update to a decrypted digital signature signed by a trusted party. 11. The method of claim 7 , further comprising determining, by the boot block of the trusted component, availability of the update upon booting of the computing device. 12. The system of claim 1 , wherein the memory of the computing device comprises non-trusted system memory of the computing device. 13. The system of claim 1 , wherein the boot block of trusted memory resides in firmware memory of the trusted component. 14. The system of claim 1 , wherein the logic executed by the processing unit to validate integrity of the verify logic is stored in the boot block of trusted memory of the trusted component before the update is available. 15. The system of claim 1 , further comprising: boot instructions stored in the boot block of trusted memory of the trusted component. 16. The method of claim 7 , wherein the memory of the computing device comprises non-trusted system memory of the computing device. 17. The method of claim 7 , wherein the boot block of trusted memory resides in firmware memory of the trusted component.
Secure firmware programming, e.g. of basic input output system [BIOS] · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.