I was answering some questions about secure boot recently, and 'Building Secure Firmware' https://link.springer.com/book/10.1007/978-1-4842-6106-4 was mentioned.
While visiting the book site I was curious about who was citing it these days https://link.altmetric.com/details/93414671/citations.
This list is always interesting to compare against the big G's citations https://scholar.google.com/scholar?oi=bibs&hl=en&cites=16997507852059049037. Not surprisingly Scholar omits the above citation - perhaps the big G's Skynet is deprioritizing jobs on Scholar and Patents in lieu of training and serving the latest Gemini?
Regarding the Apress citations, I was intrigued by the 2027 confidential computing (CC) book chapter mention. After clicking in I was happily surprised (well, maybe not so 'surprised' given the energy and intelligence of the author) to find https://www.sciencedirect.com/book/monograph/9780443540677/confidential-computing
by Jiewen Yao. Although several years have passed since I've had contact with Jiewen, he was my collaborator on the Secure Firmware book and many other projects, patents, presentations and papers back in the day for the EDKII and security space at Intel. In fact upon retiring from Intel I asked him to take up my chair of the UEFI Security Subteam and seat on the Trusted Computing Group Technical Committee (as Intel's rep).
When he dove into confidential computing many moons ago, I joked to myself that he 'graduated' from UEFI middle school into confidential computing college, whereas I stayed back in the UEFI classroom.
Speaking of graduation, I'm honored to be among the members of the network he mentions (one of the thirty or so Intel souls cited), too https://www.sciencedirect.com/science/chapter/monograph/pii/B9780443540677050014
Although I dabbled in various uses of SGX for firmware, the precursor of the virtualization-based TDX for CC, I spent less energy on TDX while at Intel. One bridge from TDX to host firmware, though, is https://patents.google.com/patent/US20250258963A1/en
Interesting that the above is classified under 'Secure Boot' by the USPTO. Apparently I have a few under that category https://patents.google.com/?q=(G06F21%2f575)&inventor=vincent+zimmer&oq=(G06F21%2f575)+vincent+zimmer I'm curious as to how they manager their taxonomies at the USPTO.
A fortiori, I still want to fulfill my drive to add more formal rigor to the host firmware domain. A scan of this blog and some of my earlier talks and books will make that ambition no surprise. One example of my post-Intel work in this vein includes a paper https://zenodo.org/records/22834103 I'll present in late October https://www.ieee-cars.org/program/papers?q=zimmer
This paper's definitely incomparable to a full-up book, weighing in at 8 versus 400 pp., but it is some small signal of how I'm still trying to move the needle in my perhaps Quixotic quest to formalize UEFI. I started here with some formalization of the circa 2008/9 Firmware Management Protocol https://www.intel.com/content/dam/doc/guide/uefi-secure-firmware-lockdown-idf2009-presentation.pdf and Capsule (from 2006 https://www.amazon.com/Beyond-BIOS-Implementing-Extensible-Interface/dp/0974364908)
update flows https://uefi.org/specs/UEFI/2.11/Frontmatter/Revision_History.html and open source artifacts https://github.com/tianocore/edk2.
As far as more books on my side, hats off to Jiewen for his accomplishment. From my book publication run of 2006 to 2022, memories of getting hounded by editors for some of those nine texts still gives me the night sweats at times. Writing a book while balancing an intense tech-industry job is like having two jobs concurrently.
Who knows, though, given the rapid advance of technology it's definitely a target-rich environment I might tap into again? Tech books definitely don't yield any real pecuniary gain but to me they help scale technologies and pass on wisdom learned through hard-fought years of technical investment. I often challenge myself to write a book that I wish I'd had way back when I started in a domain myself.
Well, maybe it's time to close another Saturday entry into my decidedly peripatetic blog. Now back to work.








No comments:
Post a Comment