com.intel.ManagementEngine.ISHC

This Intel Management partition contains boot code for the Integrated Sensors Hub (ISH) and is digitally signed by the OEM.

Size 196.0 KiB
Entropy 8.0
GUID ca8cee10-ebf4-5cca-a356-91f27c413d72
SHA256 eb6c9436f947cc39b8f902fea74574737ad6e0104a3cff6aa2c558249726b1d3

com.intel.ManagementEngine.UTOK

This Intel Management block partition stores an OEM unlock token used to unlock debugging for the ME or Integrated Sensor Hub (ISH). This token is cryptographically signed by either the Intel private key or by an OEM private key, granting a level of access depending on which key was used. GREEN access is the default, when no UTOK is present and only allows TraceHub tracing and debug of the host CPU. ORANGE unlock allows debug of the Intel Sensor Hub, and RED unlock allows debugging the ME but will clear secrets from its memory before doing so.

Size 8.0 KiB
GUID d62fac2d-36c1-59e4-977c-28ccbaa64a74
SHA256 7d2c7ac4888bfd75cd5f56e8d61f69595121183afc81556c876732fd3782c62f

com.intel.ManagementEngine.FLOG

This Intel Management partition provides a flash log that contains error and warning messages generated by ME modules, the data written here is a subset of the data output to the Tracehub.

Size 4.0 KiB
GUID dfa881ba-d45b-5ef1-9fcf-4882cea6e1db
SHA256 f47a8ec3e9aff2318d896942282ad4fe37d6391c82914f54a5da8a37de1300c6

com.intel.ManagementEngine.LOCL

This Intel Management partition provides translations for various AMT strings.

Size 12.0 KiB
Entropy 2.43
GUID 80d4b98b-664d-5b56-ae7f-05add217383a
SHA256 594bf43ea31d441bc015bdf28ec46ebdb9cfd2e29503e3a674a28ef9235d9fc3

com.intel.ManagementEngine.WCOD

This Intel Management partition contains the Wireless LAN microcode.

Size 512.0 KiB
Entropy 7.14
GUID b86d5ac6-fe84-5d4b-a885-19ff3edb2f5e
SHA256 98d490853d7098cdecfd4b46c6f73a0c81af982d9fdc20e581a019563d3b2513

com.intel.ManagementEngine.NFTP

This Intel Management partition is a code Non-Fault Tolerant Partition and provides additional code to the BUP. It is digitally signed by Intel.

Size 3.0 MiB
Entropy 7.66
GUID 2749ab68-bcde-5e19-9f2f-b802d6f7e1d7
SHA256 45a4f3ba0801f3fc24169b23b86f78f586f35f0317004ff55235b060b37c00ad

com.intel.ManagementEngine.MFS

This Intel Management partition stores a file system that contains ME-related data stored between runs. The low-level MFS implementation does not support file names or sizes. Files are identified by numbers.

Size 1.2 MiB
Entropy 0.24
GUID 5abfb339-331f-55af-9bf9-31f4aa80387e
SHA256 febc49788ee47d665df9205087ed6a0ae53f32c8cb16826d69090e57c2bee750

com.intel.ManagementEngine.IVBP

This Intel Management encrypted block partition is used for “warm” start (like hibernate restoration) and is integrity protected with HMAC. It is unique for each platform (PCH-chip) and each boot.

Size 16.0 KiB
GUID 6312624b-3631-5317-9f47-519260d8eb52
SHA256 0fbba07a833d4dcfc7024eaf313661a0ba8f80a05c6d29b8801c612e10e60dee

com.intel.ManagementEngine.PSVN

This optional Intel Management partition stores the previous SVN (Secure Version Number) value and is used to calculate “previous security keys”. It must be impossible to install ME firmware with previous SVN without direct writing SPI Flash with chip programmer. Updates to the SVN causes alteration of related security keys. Having access to both “previous” and “current” keys allows migration of the MFS file system from old to new keys.

Size 512.0 B
GUID cb1536bf-79b3-5f45-a765-344360a4327b
SHA256 9f56cda75fefeab90f6fa5d5ddc9601544b121732c5ecccab32e631060453a5d

com.intel.ManagementEngine.DLMP

This Intel Management partition stores the IDLM module and is the only place (except ROM) where reading data from fuses is possible. The IDLM is signed with RSA-2048 and the owner of permitted RSA signing key can extract the HMAC key. The DLMP can overlap other partitions by design.

Size 12.0 KiB
Entropy 3.01
GUID 10b47df9-a35f-5685-82cf-1e54f612337b
SHA256 a590183a9260e6b2c5e65a6e2e7c7ae62b12d1ad3a88c7b71dee59d44be908db

com.intel.ManagementEngine.FTUP

This Intel Management partition is a combination of the NFTP, WCOD and LOCL partitions.

Size 3.6 MiB
Entropy 7.58
GUID c044ddce-74c3-5160-b4c1-bda92824a6f4
SHA256 6bcc6f9c7bd7e351996e95ec4e588feff49cc35eb1fbb8f9abf7b222725aec04

com.intel.ManagementEngine.FTPR

This Intel Management partition is a Fault Tolerant Partition (FTP) code partition. Digitally signed processes of the correct type are started from this module, much like autorun. It is digitally signed by Intel.

Size 1.2 MiB
Entropy 6.2
GUID cbe73b88-8057-5046-80f5-0a5586268634
SHA256 4639603f6e6d4a76a96dcedac1d8177930fcc069b60c54f3964fd6ced91bfb6a

com.github.LongSoft.UEFITool

UEFI firmware image viewer and editor

Size 135.0 B
Entropy 4.36
GUID 463191c7-fade-51b1-a0ba-eef794d26632
SHA256 ebc7c0e586aee58eeda2b296ca50f63542230619390104a9661a99fd84116a3f
SHA1 e7593c97f492983554dacb53c6f0ce9d391929de

org.uefi.Driver

Size 88.1 KiB
Entropy 5.44
GUID 0162d06e-41ef-43ca-bb59-90a00cf88592
SHA256 38f854dc6621b258bb06eacb8ef7a0500af9622ae830c80b7de83498015c52e3
SHA1 1bdcbfcbdfc5a3931ecf9cf56741294ae672dc04

org.uefi.Driver

Size 74.5 KiB
Entropy 5.88
GUID 91a5e4a3-1839-4aba-ab51-1ea8519a374a
SHA256 e137c59b58b58f23bcd06cc9c3cc8904a205e7f4aac2f55672985d4bdc5fe75c
SHA1 fa8f0d015ee10e7f4fc6fd33bf7f1a0e948e401a

LVFS © 2015 Richard Hughes with icons from Font Awesome and GeoIP data from IP2Location.

Linux Vendor Firmware Service Project a Series of LF Projects, LLC :: Charter