Nova Patents
US20030196096A1

Microcode patch authentication

Claim Score by NHIP

Read claim 11, the broadest

Abstract

Microcode patches are encoded before delivery to a target processor that is to install the microcode patches. The target processor validates the microcode patches before installation. The security of the process may be enhanced by one or more of: 1) performing the validation in a secure memory, 2) using a public/private key pair for encryption and decryption of the microcode patch, 3) using at least one key that is embedded in the target processor and that cannot be read by non-secure software, and 4) using a hash value that is embedded in the target processor to validate at least one non-embedded key.

US20030196096A1, drawing sheet 1
Sheet 1 of 7

Term

Term ended

Projected expiry passed 12 April 2022, 4.5 years ago.

  1. Priority and filed
  2. Published
  3. Projected expiry
  4. Today

30 claims: 7 independent, 23 dependent

  1. 1
    A machine-readable medium that provides instructions, which when executed by a set of one or more processors, cause said set of processors to perform operations comprising:generating a hash digest for a microcode patch;encrypting the hash digest to generate a digital signature;and combining the digital signature and the microcode patch for delivery to a target processor to patch microcode in the target processor.
  2. 4
    A method, comprising:generating a hash digest for a microcode patch;encrypting the hash digest with a private key for an asymmetric cryptographic algorithm to generate a digital signature;and combining the digital signature and the microcode patch for delivery to a processor to patch microcode of the processor.
  3. 7
    A machine-readable medium containing data comprising:a microcode patch to patch microcode in a target system;and a digital signature produced by encrypting a digest created by performing a hash operation on the microcode patch.
  4. 11
    Broadest claimClaim Score 91, very broad(NHIP)An apparatus, comprising:a processor having microcode;a secure memory coupled to the processor to decode an encoded microcode patch;and a microcode patch memory coupled to the microcode to contain the decoded microcode patch.
  5. 16
    A method, comprising:obtaining a microcode patch and an associated digital signature;decrypting the digital signature in a secure memory to obtain a first hash digest;calculating a second hash digest with the microcode patch;comparing the first hash digest with the second hash digest;and installing the microcode patch in a microcode patch memory responsive to a match between the first and second hash digests.
  6. 22
    A machine-readable medium that provides instructions, which when executed by a set of one or more processors, cause said set of processors to perform operations comprising:obtaining a microcode patch and an associated digital signature;decrypting the digital signature to obtain a first hash digest;calculating a second hash digest with the microcode patch;comparing the first hash digest with the second hash digest;and installing the microcode patch responsive to a match between the first hash digest and the second hash digest.
  7. 28
    A system, comprising:a processor having microcode and an embedded key;and a microcode patch package residing in at least one of a storage device and a basic input-output system coupled with the processor, the microcode patch package including a microcode patch to patch the microcode and a digital signature to validate the microcode patch using the embedded key.