HP Sure Start with Runtime Intrusion Detection - White Paper
As implemented on HP EliteBook products equipped with  
7th generation AMD processors 
January 2017 
 HP Sure Start with Runtime Intrusion Detection 
© Copyright 2017 HP Inc. 
2 Appendix A 8 
As the microprocessor enters SMM, it asserts a hardware output pin, SMI Active (SMIACT). This pin serves notice to the 
chipset hardware that the microprocessor is entering SMM. An SMI can be asserted at any time, during any process 
operating mode, except from within SMM itself. The chipset hardware recognizes the SMIACT signal and redirects all 
subsequent memory cycles to a protected area of memory (sometimes referred to as the SMRAM area), reserved 
specifically for SMM. Immediately after receiving the SMI input and asserting the SMIACT output, the microprocessor begins 
to save its entire internal state to this protected memory area. 
After the microprocessor state has been stored to SMRAM memory, the special SMM handler code that also resides in 
SMRAM (placed there by system BIOS at boot time) begins to execute in a special SMM operation mode. While operating in 
this mode, most hardware and memory isolation mechanisms are suspended and the microprocessor can access virtually 
all resources in the platform to enable it to perform required tasks. The SMM code completes the required task, and then it's 
time to return the microprocessor to the previous operating mode. At that point, the SMM code executes the Return from 
System Management Mode (RSM) instruction to exit SMM. The RSM instruction causes the microprocessor to restore its 
previous internal state data from the copy saved in SMRAM upon SMM entry. Upon completion of RSM, the entire 
microprocessor state has been restored to the state just prior to the SMI event, and the previous program (OS, applications, 
hypervisor, etc.) resumes execution right where it left off. 
1. HP Sure Start with Runtime Intrusion Detection is available on HP EliteBook products equipped with 7th generation AMD processors. 
2. For more details on SMM and how it works, see Appendix A. 
3. HP Notification Software is required to be installed to view HP Sure Start events in the Windows Event Viewer.  
4. HP Notification Software is required to be installed to receive notifications.  
© Copyright 2017 HP Development Company, L.P. The information contained herein is subject to change without notice. AMD is a trademark of Advanced Micro 
Devices, Inc. Microsoft and Windows are either trademarks or registered trademarks of Microsoft Corporation in the U.S. and other countries. 
4AA6-9340ENW, February 2017 








