One of HP’s key announcements this spring was its revamped security initiative for PCs that includes hardware, software, and deep learning-based approaches. The software and DL parts of the things were discussed earlier this month, but the hardware-based Endpoint Security Controller remained more or less a mystery. This is why we asked HP to talk about it in more detail.

When it was announced, the company said that the HP Endpoint Security Controller is indeed a separate piece of silicon that sits inside HP’s PCs and performs certain security-based tasks. The ESC features a general-purpose processor core, HP’s custom hardware IP blocks, and embedded software. What is interesting is that HP has been installing the controller into its laptops since the EliteBook 800 G1 series launched in 2013, but has been very secretive about it until recently.

Initially, HP used the Endpoint Security Controller only for its Sure Start technology that can 'heal'/recover the system BIOS. Fast forward to 2019, and the controller has gained capabilities. HP now uses it to protect Intel’s Management Engine, and to enable its Sure Run and Sure Recover capabilities.

HP stresses that it is focused to continue to explore features of its ESC to make its HP Elite as well as select HP Pro business computers and select ZBook workstations the most secure mobile PCs on the market. Without disclosing any future plans, HP essentially implies that in the future it can use the Endpoint Security Controller for other security-related features.

HP’s ESC with all the bells and whistles is currently used in the company's sixth-generation EliteBook 800-series as well as HP ZBook 14u and 15u workstations. Eventually, capabilities of the Endpoint Security Controller will migrate to other systems too.

One of the key things about the ESC disclosure is that it shows PC makers are prepared to implement their own hardware-based methods to improve security of their premium PCs aimed at professionals. One would hope that this is a good news, assuming the controllers are sufficiently audited and not just obfuscated, but it will be interesting to see when and if HP incorporates its Endpoint Security Controller into premium consumer and mainstream consumer PCs.

Related Reading

Source: HP

Comments Locked

33 Comments

View All Comments

  • id4andrei - Friday, May 3, 2019 - link

    Isn't this similar to Apple's security chip? Why is Apple praised for it and HP vilified?
  • Santoval - Friday, May 3, 2019 - link

    Because Apple, for all its faults, never kept Secure Enclave secret and has provided extensive documentation to developers about how it (and iOS & iPhone security in general) operates. Furthermore, documentation helps third party security researchers to audit Secure Enclave and iOS for bugs and exploitable flaws.

    On the contrary, "security by obscurity", which appears to be what HP have been doing, has never worked, does not work and will never work. This is just a sample of Apple's documentation on the Secure Enclave : https://developer.apple.com/documentation/security...
  • kelvinluise998 - Tuesday, September 8, 2020 - link

    Knowledge4sure is giving the best and productive approach to get HP HP2-I17 Exam by HP2-I17 Exam Questions and HP Sales Certified HP2-I17 practice test software. We are acclaimed for conveying the best HP Sales Certified Test Dumps to HP understudies. We ensure your success is guaranteed. Prepare your HP2-I17 Selling HP Printing Hardware 2020 Exam from our legitimate HP2-I17 Practice Tests and be ensured. Visit the site for complete subtleties: https://www.knowledge4sure.com/HP2-I17-exam-questi...

Log in

Don't have an account? Sign up now