Tektagon XFR Archives - AMI https://www.ami.com/blog/tag/tektagon-xfr/ The World Runs On AMI Tue, 13 Sep 2022 14:00:56 +0000 en-US hourly 1 https://wordpress.org/?v=6.6.1 https://www.ami.com/wp-content/uploads/2021/11/ami-ico-1.svg Tektagon XFR Archives - AMI https://www.ami.com/blog/tag/tektagon-xfr/ 32 32 AMI Releases Tektagon XFR Platform Root of Trust Firmware Security Solution to Protect Critical Compute Infrastructure with Built-in Cyber Resiliency https://www.ami.com/blog/2022/09/12/ami-releases-tektagon-xfr-platform-root-of-trust-firmware-security-solution-to-protect-critical-compute-infrastructure-with-built-in-cyber-resiliency/ Mon, 12 Sep 2022 21:47:00 +0000 https://www.ami.com/?p=237562 ATLANTA, GEORGIA –  AMI, a global leader in the Dynamic Firmware market for worldwide computing, today announces the latest version of its Tektagon™ XFR Platform Root of Trust Firmware Protection Security Solution. Recent news of high-profile breaches confirm that platform firmware increasingly presents a large and ever-expanding attack surface. Earlier this year, the U.S. Department of Homeland Security (DHS) and Department of Commerce issued a new joint report on supply chain security in the US IT and communications industries, outlining how firmware is now a priority target for hackers and represents a significant threat vector for computer systems and IT infrastructure. It urged businesses and individuals to take steps to protect their critical infrastructure from such firmware attacks. To address this growing threat and provide users with the latest tools in firmware protection and security, today’s release of Tektagon XFR adds several new features to this already robust solution from AMI. Key among them is support for the Mach™-NX FPGAs from Lattice Semiconductor, which enables Tektagon XFR to deliver dual SPI support and real-time platform security monitoring. Tektagon XFR now also offers support for server architectures from AMD and Arm®, bringing affordable, easy-to-deploy Platform Firmware Resilience (PFR) to an even […]

The post AMI Releases Tektagon XFR Platform Root of Trust Firmware Security Solution to Protect Critical Compute Infrastructure with Built-in Cyber Resiliency appeared first on AMI.

]]>
ATLANTA, GEORGIA –  AMI, a global leader in the Dynamic Firmware market for worldwide computing, today announces the latest version of its Tektagon™ XFR Platform Root of Trust Firmware Protection Security Solution.

Recent news of high-profile breaches confirm that platform firmware increasingly presents a large and ever-expanding attack surface. Earlier this year, the U.S. Department of Homeland Security (DHS) and Department of Commerce issued a new joint report on supply chain security in the US IT and communications industries, outlining how firmware is now a priority target for hackers and represents a significant threat vector for computer systems and IT infrastructure. It urged businesses and individuals to take steps to protect their critical infrastructure from such firmware attacks.

To address this growing threat and provide users with the latest tools in firmware protection and security, today’s release of Tektagon XFR adds several new features to this already robust solution from AMI. Key among them is support for the Mach™-NX FPGAs from Lattice Semiconductor, which enables Tektagon XFR to deliver dual SPI support and real-time platform security monitoring. Tektagon XFR now also offers support for server architectures from AMD and Arm®, bringing affordable, easy-to-deploy Platform Firmware Resilience (PFR) to an even wider range of platforms for datacenter and cloud service provider applications.

Additional new features in this latest release of Tektagon XFR include Intel® PFR 3.0 support, seamless updates for the next-generation Intel® Xeon® (“Eagle Stream”) data center platform, attestation support and integration with our Aptio® V UEFI Firmware and MegaRAC® SP-X BMC Firmware. Tektagon XFR also gains support for AES, SHA and ECDSA encryption, key management and support for MegaRAC OpenEdition™ BMC Firmware from AMI.

About Tektagon XFR

Tektagon XFR is a hardware-based platform firmware security solution for servers that utilizes an AMI firmware stack on Lattice FPGA devices, strengthening system security by protecting firmware from unauthorized modification, detecting firmware-based malware and recovering the platform to a known good state. These capabilities make Tektagon XFR the perfect solution for protecting critical infrastructure firmware from unauthorized modification during power up and runtime.

Tektagon XFR is compliant with NIST Platform Firmware Resiliency (PFR) Guidelines (NIST SP 800-193) and compatible with the current draft of the Data Center Secure Control Module (DC-SCM) 2.0 Specification under the management of the Open Compute Project (OCP). It also supports Security Protocol and Data Model (SPDM) from DMTF for monitoring of a server’s peripheral devices, enabling firmware attestation for Broadcom’s MegaRAID™ 9600 Storage Adapter and 200G NIC family. With Tektagon XFR in place, you can be confident that your firmware is safe from tampering or corruption.

Recognizing the challenges that OEMs face developing a PFR solution from scratch, AMI and Lattice Semiconductor worked closely together to bring the industry an integrated, fully featured, pre-verified and secure PFR solution that is flexible, scalable, low cost, and easy to implement. Our partnership allows us to offer our PFR Firmware on secure FPGA solutions from Lattice, in combination with the Lattice Sentry™ solution stack and a full suite of design and development tools – for holistic, robust system security that conforms to PFR industry guidelines and represents a significant advancement in platform security for our customers.

Zachary Bobroff, Senior Director of Product Office at AMI, commented that “With security breaches becoming more prevalent, organizations must have a system to validate their platform firmware – to be aware of all firmware running on your platforms and ensure that it is trusted. AMI’s Tektagon solutions provide this root of trust, so you can be confident that your platform is secure against potential threats. Today’s new release is the next step in our vision for Tektagon XFR, bringing customers an affordable, flexible and comprehensive alternative to existing competitor solutions that is rooted in essential firmware security guidelines and truly breaks new ground in platform security.”

“As the security threat landscape continues to evolve, enabling system and platform developers to integrate added layers of protection and resilience is a key priority at Lattice,” said Nilesh Narayan, Marketing Director, Server Segment, Lattice Semiconductor. “We are excited to continue our strong collaboration with AMI by enabling Tektagon XFR with broader support for our award-winning low power product portfolio, giving our customers more ways to implement next-generation security and cyber resiliency.”

Zee Shirazi, Global Head of Marketing, Business Operations and Strategy, Data Center Solutions Group, Broadcom added that “With the growing number of sophisticated security threats, the Security Protocol and Data Model (SPDM) specification from DMTF will play a central role in platform security for both hyperscale and enterprise data centers by ensuring only authentic hardware and firmware components are being used. We are pleased to see that AMI has added a SPDM feature, to the Tektagon XFR platform, that supports our storage and server components including our MegaRAID™ 9600 storage adapter, 200G NIC, and PEX89xxx PCIe switch products— seamlessly protecting the same security attestation umbrella as other platform firmware.”

Lattice Mach™-NX and Lattice Sentry™ are trademarks of Lattice Semiconductor. MegaRAID™ is a trademark of Broadcom Inc. Intel® and Xeon® are registered trademarks of Intel Corporation. All other trademarks and registered trademarks are the property of their respective owners in the US and other countries.

The post AMI Releases Tektagon XFR Platform Root of Trust Firmware Security Solution to Protect Critical Compute Infrastructure with Built-in Cyber Resiliency appeared first on AMI.

]]>
Cyber Resiliency for Firmware Protections and Supply Chain Security Webinar Presented by Lattice Semiconductor https://www.ami.com/event/cyber-resiliency-for-firmware-protections-and-supply-chain-security-webinar-presented-by-lattice-semiconductor/ Mon, 06 Jun 2022 20:00:00 +0000 https://www.ami.com/?post_type=tribe_events&p=237326 Cyber Resiliency for Firmware Protections and Supply Chain Security Webinar Presented by Lattice Semiconductor This seminar will explore the challenges, opportunities, and latest solutions for the global hardware security industry. You’ll walk away with a better understanding of what a Cyber Resilient system requires, especially in compute architectures and the new supply chain paradigms that will reduce your supply chain security costs while increasing your protections. Security industry leaders from AMI and Lattice will also discuss ways to prepare for and respond to threats when building and operating secure systems in today’s complex and ever-changing technology ecosystem. DATE & TIME Monday, June 6, 2022 4 to 6 pm PDT SPEAKERS Eric Sivertson – VP, Security Business, Lattice Nilesh Narayan – Director, Server Marketing, Lattice Kenneth Tao – Director, Business Development, AMI AGENDA The Importance of Cyber Resilience & Supply Chain Security Current Threat & Risk Landscape Security & Protective Solutions Ecosystem Highlight – Platform Firmware Resiliency (PFR) Orchestration in Servers Q&A

The post Cyber Resiliency for Firmware Protections and Supply Chain Security Webinar Presented by Lattice Semiconductor appeared first on AMI.

]]>
Cyber Resiliency for Firmware Protections and Supply Chain Security Webinar

Presented by Lattice Semiconductor

This seminar will explore the challenges, opportunities, and latest solutions for the global hardware security industry. You’ll walk away with a better understanding of what a Cyber Resilient system requires, especially in compute architectures and the new supply chain paradigms that will reduce your supply chain security costs while increasing your protections. Security industry leaders from AMI and Lattice will also discuss ways to prepare for and respond to threats when building and operating secure systems in today’s complex and ever-changing technology ecosystem.

DATE & TIME

  • Monday, June 6, 2022
  • 4 to 6 pm PDT

SPEAKERS

  • Eric Sivertson – VP, Security Business, Lattice
  • Nilesh Narayan – Director, Server Marketing, Lattice
  • Kenneth Tao – Director, Business Development, AMI

AGENDA

  • The Importance of Cyber Resilience & Supply Chain Security
  • Current Threat & Risk Landscape
  • Security & Protective Solutions
  • Ecosystem Highlight – Platform Firmware Resiliency (PFR) Orchestration in Servers
  • Q&A
Register Now!

The post Cyber Resiliency for Firmware Protections and Supply Chain Security Webinar Presented by Lattice Semiconductor appeared first on AMI.

]]>
Platform Security Starts at the Root of Trust https://www.ami.com/blog/2021/10/24/platform-security-starts-at-the-root-of-trust/ Sun, 24 Oct 2021 16:22:22 +0000 https://amitkprd.wpengine.com/?p=236871 The post Platform Security Starts at the Root of Trust appeared first on AMI.

]]>

Tektagon™ XFR ,A Guide to Implementing HRoT with NIST PFR Guidelines

Data breaches are increasingly costly as the sophistication and funding (in some instances, state-sponsored) of hackers has increased. The Cost of a Data Breach Report 2021 by IBM states that “2021 had the highest average data breach cost in 17 years” rising from USD 3.86 million to USD 4.24 million.

While companies have taken steps in some areas to improve security, firmware is the next prime area for hackers. According to the March 2021 Security Signals (a report commissioned by Microsoft), “More than 80% of enterprises have experienced at least one firmware attack in the past two years.”

Firmware is emerging as a primary target for hackers because it is where sensitive information, including credentials and encryption keys, is stored in memory. If platform firmware is compromised, the entire platform is compromised.

With the largest technology companies seriously engaging and taking the next steps to implement a hardware root of trust (HRoT) solution, all original design manufacturers (ODMs) and original equipment manufacturers (OEMs) should be motivated and respond to the current situation.

Need for HRoT Protection

From the time that an OEM/ODM builds a server and it enters the supply chain, reaches the datacenter and then gets installed and becomes operational, there are numerous opportunities for disreputable actors to compromise the server.

While conventional thinking assumes that reimaging the system to its original state will wipe out any malware, some malware could survive a firmware update. However, HRoT solution will provide a foundational level of security since it establishes the authenticity of the firmware and validates that it has not been compromised before allowing a system to boot. If the firmware is compromised, it may be impossible to detect without specialized hardware. To address firmware integrity, the U.S. National Institute of Standards and Technology (NIST) added to its security guidelines.

NIST 800-193 Platform Firmware Resiliency (PFR) Guidelines

Released in May 2018, NIST Special Publication 800-193 Platform Firmware Resiliency (PFR) Guidelines were developed to help organizations prepare better against potentially destructive attacks to the collection of hardware and firmware components of a computer system. The security guidelines are based on the principles of protection, detection and recovery.

  • Protection: Solution must ensure that Platform Firmware code and critical data remain in a state of integrity and are protected from corruption, such as the process for ensuring the authenticity and integrity of firmware updates.
  • Detection:  Mechanisms must be in place for detecting when Platform Firmware code and critical data have been corrupted or otherwise changed from an authorized state.
  • Recovery: Finally, for recovery from a disruptive event, a system must have the capability to restore Platform Firmware code and critical data to a state of integrity when firmware code or critical data are detected to have been corrupted, or when forced to recover through an authorized mechanism. Recovery is limited to the ability to recover firmware code and critical data.

To be resilient, all three basic requirements for resilient firmware must be satisfied: the firmware must be protected from tampering, corrupted firmware must be detected, and compromised firmware must be restored.

Hardware Root of Trust from AMI

While NIST 800-193 describes what has to be done to detect, protect and recover firmware, it does not provide the “how to” portion. This is where over 35 years of firmware expertise of AMI comes into the picture. Tektagon™ XFR, formerly AMI PlatFire, is a comprehensive HRoT solution, a robust PFR product that utilizes Lattice FPGA to provide an independent HRoT with maximum flexibility to not only detect and protect against firmware attacks, but also recover and re-provision platform firmware, minimizing data center downtime and loss of confidential data.

Designed to Detect, Protect and Recover Firmware

Tektagon™ XFR is designed to detect, protect and recover firmware from unauthorized modification. The solution can continuously monitor and block unauthorized SPI and SMBus transactions during runtime to ensure no malicious read/write commands are executed. If necessary, it can detect when the platform firmware code and critical data is compromised or corrupted.  In the event platform firmware is corrupted, the solution can restore platform firmware and authenticate recovery image upon failure.  Compatible with most silicon vendors, this NIST 800-193 compliant HRoT solution minimizes platform ecosystem or vendor lock-in and can provide up to 30% cost savings on a combined chip solution compared to competitive alternatives.

What does Tektagon™ XFR Protect?

Utilizing the Baseboard Management Controller (BMC) HRoT engine, Tektagon™ XFR validates BMC and BIOS firmware. It is also capable of monitoring and securing any firmware accessible by the BMC, including add-in cards, power supplies, NICs and Non-volatile DIMMS.

To easily and quickly implement Tektagon™ XFR, a best-known configuration (BKC) reference design is offered to OEM/ODMs.

Prioritizing Platform Firmware Security and Resiliency

Tektagon™ XFR firmware protection is foundational security and security of a layer is only as good as the layer below it. So, trust must be established pre-boot and mechanisms must be there to protect, detect and restore platform firmware.

Timing is important and October is National Cybersecurity Awareness Month (NCSAM). Started in 2004 as an effort by the U.S. Department of Homeland Security, NCSAM is now an industrywide push that takes place in October to make organizations more aware of cyber threats. As part of your company’s response to October’s National Cybersecurity Awareness Month and to improve your company’s platform security, learn more about how AMI HRoT solutions can help you make your platform firmware more secure and resilient.

To learn more about Tektagon™ XFR, visit: ami.com/ami-hrot

To schedule a consultation, please visit: ami.com/contact

The post Platform Security Starts at the Root of Trust appeared first on AMI.

]]>
AMI and Lattice Semiconductor Announce Joint Platform Firmware Resiliency Security Solution: Tektagon XFR Firmware with Lattice Sentry Solutions Stack https://www.ami.com/blog/2020/11/19/ami-and-lattice-semiconductor-announce-joint-platform-firmware-resiliency-security-solution-tektagon-xfr-firmware-with-lattice-sentry-solutions-stack/ Thu, 19 Nov 2020 10:00:00 +0000 https://amitkprd.wpengine.com/ami-and-lattice-semiconductor-announce-joint-platform-firmware-resiliency-security-solution-tektagon-xfr-firmware-with-lattice-sentry-solutions-stack/ DULUTH, GEORGIA / HILLSBORO, OREGON – AMI®, a global leader in powering, managing and securing the world’s connected digital infrastructure through its BIOS, BMC and security solutions, and Lattice Semiconductor, the low power programmable leader, are pleased to announce a new jointly-developed platform firmware security solution, Tektagon™ XFR Firmware, formerly AMI PlatFire®, with the Lattice Sentry™ solutions stack. The solution enables developers to quickly and easily implement system-level cyber resiliency that is pre-validated as compliant with NIST Platform Firmware Resiliency (PFR) Guidelines (NIST SP 800-193), making it easy for developers with limited hardware security expertise or limited time-to-market to implement PFR on the latest industry-standard server platforms. The solution combines technology from two of the leading names in PFR – AMI and Lattice Semiconductor – to bring the industry an integrated, fully-featured, pre-verified and secure Platform Root-of-Trust (PRoT) solution that is flexible, scalable, low cost, and easy to implement. The solution uses the Lattice Sentry stack, featuring a low-power Lattice MachXO3D™ secure control FPGA running pre-verified, PFR-compliant IP, to implement a PRoT on a server’s motherboard. The Tektagon™ XFR firmware then orchestrates the connection between the PRoT and other on-board components, such as SoCs and RoCs, to confirm the firmware […]

The post AMI and Lattice Semiconductor Announce Joint Platform Firmware Resiliency Security Solution: Tektagon XFR Firmware with Lattice Sentry Solutions Stack appeared first on AMI.

]]>
DULUTH, GEORGIA / HILLSBORO, OREGON – AMI®, a global leader in powering, managing and securing the world’s connected digital infrastructure through its BIOS, BMC and security solutions, and Lattice Semiconductor, the low power programmable leader, are pleased to announce a new jointly-developed platform firmware security solution, Tektagon™ XFR Firmware, formerly AMI PlatFire®, with the Lattice Sentry™ solutions stack. The solution enables developers to quickly and easily implement system-level cyber resiliency that is pre-validated as compliant with NIST Platform Firmware Resiliency (PFR) Guidelines (NIST SP 800-193), making it easy for developers with limited hardware security expertise or limited time-to-market to implement PFR on the latest industry-standard server platforms.
The solution combines technology from two of the leading names in PFR – AMI and Lattice Semiconductor – to bring the industry an integrated, fully-featured, pre-verified and secure Platform Root-of-Trust (PRoT) solution that is flexible, scalable, low cost, and easy to implement. The solution uses the Lattice Sentry stack, featuring a low-power Lattice MachXO3D™ secure control FPGA running pre-verified, PFR-compliant IP, to implement a PRoT on a server’s motherboard. The Tektagon™ XFR firmware then orchestrates the connection between the PRoT and other on-board components, such as SoCs and RoCs, to confirm the firmware they are running is valid.
“We’re excited by the growing interest from customers across markets in implementing PFR to protect their systems. Pairing our Sentry solutions stack with AMI’s new Tektagon™ XFR firmware provides a comprehensive, system-level PFR solution that helps developers quickly and easily protect their system firmware, making PFR support possible for a larger potential customer base,” said Esam Elashmawi, Chief Strategy and Marketing Officer, Lattice Semiconductor.
Sanjoy Maity, Chief Executive Officer of AMI, added that “Our Tektagon™ XFR PRoT firmware provides customers an affordable, flexible and comprehensive alternative to existing competitor solutions. By partnering with Lattice Semiconductor to deliver Tektagon™ XFR on a secure Lattice MachXO3D FPGA with the Lattice Sentry Security stack and a full suite of design and development tools, together we can offer complete system security that is fully compliant with NIST PFR Guidelines and is host CPU vendor agnostic – so customers don’t have to feel locked into a particular ecosystem or platform to have a secured system.”

Firmware Security Trends are Changing Faster than Ever

Firmware is an increasingly popular attack vector; the National Vulnerability Database reported that between 2016 and 2019 the number of firmware vulnerabilities grew over 700 percent1. The NIST PFR guidelines were written to help developers understand how to protect legitimate firmware, detect unauthorized firmware, and restore compromised firmware to a known good state by establishing a PRoT. PRoT solutions validate platform firmware at boot to ensure it has not been modified illegitimately. Currently, developers with PFR design expertise are in limited supply, and OEMs requiring support for PFR often have strict time-to-market requirements that preclude developing a PFR solution from scratch. Recognizing these trends, AMI and Lattice worked together to deliver a tightly integrated, pre-validated PFR solution. It provides a robust PRoT, for real-time I2C bus and SPI monitoring of both BIOS and BMC SPIs, so from the moment a system boots all transactions over the SPI bus are monitored.

What is Tektagon™ XFR?

AMI has applied its 35 years of deep expertise in BIOS and BMC firmware development to deliver a robust PFR solution designed to detect, protect and recover firmware from unauthorized modification. As implemented in the AMI-Lattice joint solution, the Tektagon™ XFR firmware executing on the Lattice MachXO3D with the Lattice Sentry solution stack orchestrates the connection between the solution’s PRoT and all other ICs on the motherboard. Moreover, Tektagon™ XFR firmware is host CPU-agnostic, to give system developers greater flexibility in supporting the CPU requirements of their chosen server platform.
Thanks to its seamless integration with Aptio® UEFI Firmware and MegaRAC® SPX BMC Firmware from AMI, Tektagon™ XFR delivers a truly turnkey PFR solution – making use of the Lattice MachXO3D IP blocks to support detection and recovery of platform firmware, together with runtime monitoring of SPI flash memory used to store the platform firmware.

What is Lattice Sentry?

The Lattice Sentry solutions stack delivers a robust combination of customizable embedded software, reference designs based on the Lattice MachXO3D secure control FPGA, IP, and development tools to accelerate the implementation of secure systems compliant with PFR guidelines. As the system controller, the MachXO3D is the first component to execute code and attest power sequencing logic at system startup, making it an ideal platform for establishing a PRoT. Thanks to the MachXO3D FPGA’s parallel processing architecture and flash memory, the device monitors for and detects attacks in real-time – a truly groundbreaking innovation as real-time monitoring is currently beyond the processing capabilities of competing PRoT solutions like MCUs.
For more information on the joint Tektagon™ XFR PRoT Firmware on Lattice Sentry solutions stack, please call 1-800-828-9264 to speak with an AMI Security Solutions expert or contact us via ami.com/contact.
For more information about Lattice Sentry, please visit https://www.latticesemi.com/latticesentry.
About Lattice Semiconductor
Lattice Semiconductor (NASDAQ: LSCC) is the low power programmable leader. We solve customer problems across the network, from the Edge to the Cloud, in the growing communications, computing, industrial, automotive, and consumer markets. Our technology, long-standing relationships, and commitment to world-class support lets our customers quickly and easily unleash their innovation to create a smart, secure and connected world.
1Source: National Vulnerability Database (2016 and 2019)
MachXO3D™ is a trademark of Lattice Semiconductor Corporation. All other trademarks and registered trademarks are the property of their respective owners.

The post AMI and Lattice Semiconductor Announce Joint Platform Firmware Resiliency Security Solution: Tektagon XFR Firmware with Lattice Sentry Solutions Stack appeared first on AMI.

]]>