The security of Intel products and our customers' trust is a top priority. This document provides product guidance for customers interested in enhanced platform firmware resiliency such as described in NIST Special Publication 800-193 Platform Firmware Resiliency Guidelines, referred to later in this document as NIST SP800-193.
This document reviews the resiliency capabilities of several Intel® Ethernet LAN products, as well as best-known design practices guidance to system designers using Intel® Ethernet products to improve the overall platform firmware resiliency against accidental or malicious modification of device firmware. As Intel® Ethernet products are only one ingredient in a system solution, this guidance is intended to complement an overall comprehensive system-level firmware resilience architecture.
The NIST SP800-193 publication was released in March 2018. Intel® Ethernet products released prior to 2018 require additional external circuitry, board, or system design support to implement a NIST SP800-193 compliant design. This document outlines several strategies that can be used to provide security solutions for these prior devices.
As no one firmware resilience solution addresses all customer needs and requirements, this document provides design guidance relevant at the Intel® Ethernet component level, as well as highlighting existing relevant system manageability features, and lastly design consideration applicable at the board-layout level. System designers and integrators are encouraged to review and decide which recommendation best fits their specific combination of product usage and security considerations, design complexity, and ease of use.
Firmware Resiliency with Intel® Ethernet Products Application Note