FIELD: physics, computer engineering.
SUBSTANCE: invention relates to deployment of a basic input/output system (BIOS) and other firmware code in computer systems. The computer-implemented method of deploying a signed root firmware image involves obtaining a signed firmware image which contains a first code module signed by a first code owner and an access control list which authorises the first code owner to update the first code module. The method also includes a step of obtaining an updated first code module which contains an updated code for the first code module, and an updated access control list delegating authority for updating the first code module from the first code owner to a second code owner. The method further involves confirming that the updated first code module is signed by the second code owner and that the second code owner is authorised for updating based on part of the access control list.
EFFECT: improved firmware verification.
10 cl, 11 dwg
Authors
Dates
2014-04-10—Published
2011-06-10—Filed