Platform Trust Beyond BIOS Using the Unified Extensible Firmware Interface.
Vincent Zimmer · Security and Management · 2007
The Unified Extensible Firmware Interface (UEFI) provides a consistent set of interfaces designed to support the booting of shrink-wrap operating systems, loading of drivers that replace legacy PC/AT option ROM’s, and support operating-system absent diagnostics and applications. In addition to this, UEFI capabilities are exported by C-callable interfaces, thus allowing for UEFI platforms to span a large class of platform and CPU microarchitecture. These interfaces run in the native machine mode and go beyond today’s 16-bit real-mode BIOS. Inherent in the business deployment and interoperability of “extensibility”, there is also the peril, namely control of system policy. One such policy, such as integrity control of the platform firmware and authorization of module launch, will be discussed in light of these business challenges and the emergent wave of malware in the market.