One of HP’s key announcements this spring was its revamped security initiative for PCs that includes hardware, software, and deep learning-based approaches. The software and DL parts of the things were discussed earlier this month, but the hardware-based Endpoint Security Controller remained more or less a mystery. This is why we asked HP to talk about it in more detail.

When it was announced, the company said that the HP Endpoint Security Controller is indeed a separate piece of silicon that sits inside HP’s PCs and performs certain security-based tasks. The ESC features a general-purpose processor core, HP’s custom hardware IP blocks, and embedded software. What is interesting is that HP has been installing the controller into its laptops since the EliteBook 800 G1 series launched in 2013, but has been very secretive about it until recently.

Initially, HP used the Endpoint Security Controller only for its Sure Start technology that can 'heal'/recover the system BIOS. Fast forward to 2019, and the controller has gained capabilities. HP now uses it to protect Intel’s Management Engine, and to enable its Sure Run and Sure Recover capabilities.

HP stresses that it is focused to continue to explore features of its ESC to make its HP Elite as well as select HP Pro business computers and select ZBook workstations the most secure mobile PCs on the market. Without disclosing any future plans, HP essentially implies that in the future it can use the Endpoint Security Controller for other security-related features.

HP’s ESC with all the bells and whistles is currently used in the company's sixth-generation EliteBook 800-series as well as HP ZBook 14u and 15u workstations. Eventually, capabilities of the Endpoint Security Controller will migrate to other systems too.

One of the key things about the ESC disclosure is that it shows PC makers are prepared to implement their own hardware-based methods to improve security of their premium PCs aimed at professionals. One would hope that this is a good news, assuming the controllers are sufficiently audited and not just obfuscated, but it will be interesting to see when and if HP incorporates its Endpoint Security Controller into premium consumer and mainstream consumer PCs.

Related Reading

Source: HP