Device, system and method for modifying a pre-boot regulation

A device and method for secure pre-boot directive modifications in BIOS systems address the inability to communicate with servers, enabling secure and efficient updates before the operating system boots, enhancing security and functionality.

DE102009014981B4Active Publication Date: 2026-02-12LENOVO (SINGAPORE) PTE LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
DE102009014981
Authority / Receiving Office
DE · DE
Patent Type
Patents
Current Assignee / Owner
Priority Date
2008-03-31
Filing Date
2009-03-30
Publication Date
2026-02-12
Estimated Expiration
2029-03-30

AI Technical Summary

Technical Problem

Existing BIOS systems lack the ability to communicate with servers over a network, preventing firmware updates and other configurations before the operating system boots, making them vulnerable to attacks and unable to receive necessary updates.

Method used

A device and method that includes a key module for secure key exchange, a communication module for encrypted rule reception, a decryption module for pre-boot rule decryption, and an update module for booting the computer using the decrypted rule, enabling secure pre-boot directive modifications.

Benefits of technology

Enables secure and efficient pre-boot directive modifications, allowing BIOS to receive updates and configurations before the operating system boots, enhancing security and functionality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 00000000_0000_ABST
    Figure 00000000_0000_ABST
Patent Text Reader

Abstract

A computer program product comprising a computer-usable medium which has a computer-readable program stored on a hardware storage device, wherein the computer-readable program, when executed on a computer, causes the computer to do the following: Using a post-boot operating system to exchange a key with a server in a secure environment; Receiving a regulation encrypted with the key; Decrypting the encrypted rule using the key and saving the rule setting value before booting an operating system on the computer; and Booting the computer using the instructions.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This invention relates to the modification of a regulation and in particular to the modification of a pre-boot regulation.

[0002] Computers are often organized as clients within a computer system. Each computer can communicate with a server over a network. The server can provide a number of services to each computer. For example, the server can create a backup of each computer, provide software applications for each computer, and make databases available to each computer.

[0003] The server can also configure and manage each computer in the computer system. For example, the server can install and update software, perform virus scans, and similar tasks. The server typically communicates with each computer's operating system when performing these maintenance functions.

[0004] Computers typically use a pre-boot environment, such as a binary input / output system (BIOS), to boot an operating system. The BIOS may contain executable code that tests the computer, configures it, and loads the operating system from a storage device. The operating system can then provide all the functionality the computer requires.

[0005] US patent 2005 / 0114682 A1 discloses a method for updating the pre-boot system via the internet. The problem is that internet servers are known to be vulnerable to attacks (such as hacking). This is remedied by having each computer (client) individually authenticate a key before the new software is downloaded.

[0006] Publication US 2005 / 0021968 A1 discloses a method for updating company software (for example, BIOS) by rewriting data stored in the company software storage platform. To prevent the download of viruses or similarly harmful programs, a authentication technique is used. For example, the update may require a digital signature, which is obtained using a certificate containing a local key to perform a signature check on the new software.

[0007] The BIOS can apply a directive to configure the computer. For example, the BIOS can read one or more directive setting values ​​from the directive and configure the computer accordingly.

[0008] Unfortunately, the BIOS typically lacks the functionality to communicate with the server over the network. Consequently, the BIOS may be unable to receive firmware updates from the server and therefore may be unable to boot the computer with the updates.

[0009] Based on the preceding discussion, there is a need for a device, a system, and a method for modifying the pre-boot directive. Advantageously, such a device, system, and method would modify a directive before a computer completes a boot function.

[0010] The present invention was developed in response to the existing state of the art, and in particular to the problems and requirements of the prior art that have not yet been fully solved by the currently available methods for modifying a regulation. Accordingly, the foregoing invention was developed to provide a device, a system, and a method for modifying a pre-boot regulation that overcomes many or all of the aforementioned shortcomings of the prior art.

[0011] The device for modifying a pre-boot instruction is equipped with a plurality of modules configured to functionally execute the steps of exchanging a key, receiving an instruction, decrypting the instruction, and booting the computer. In the described embodiments, these modules comprise a key module, a communication module, a decryption module, and an update module.

[0012] The key module exchanges a key with a server in a secure environment. The communication module receives a rule encrypted with the key. The decryption module decrypts the encrypted rule using the key and saves the rule setting value to the computer before the operating system boots. The update module then boots the computer using the rule.

[0013] A system of the present invention for modifying a pre-boot instruction is also presented. The system can be implemented in a client / server system.

[0014] In particular, according to one embodiment, the system comprises a network, a server, and a plurality of client computers.

[0015] The server is communicating with the network. Most computers are also communicating with the server over the network. Each computer has a key module, a communication module, a decryption module, and an update module.

[0016] The key module exchanges a key with the server in a secure environment. The communication module receives a rule encrypted with the key. The decryption module decrypts the encrypted rule using the key and saves the rule setting value to the computer before the operating system boots. The update module boots the client using the rule.

[0017] A method according to the present invention is also presented for modifying a pre-boot instruction. In the disclosed embodiments, the method essentially comprises the steps necessary to perform the functions described above with respect to the function of the described device and system. According to one embodiment, the method includes exchanging a key, receiving an instruction, decrypting the instruction, and booting the computer.

[0018] A key module exchanges a key with a server in a secure environment. A communication module receives a rule encrypted with the key. A decryption module decrypts the encrypted rule using the key and saves the rule setting value to the computer before the operating system boots. An update module boots the computer using the rule.

[0019] References in this description to features, advantages, or similar expressions do not imply that all of the features and advantages that may be realized with the present invention are intended to be, or are, present in every single embodiment of the invention. On the contrary, expressions referring to features and advantages are to be understood as meaning that a particular feature, advantage, or property described in connection with an embodiment is included in at least one embodiment of the present invention. Therefore, the discussion of features and advantages and similar expressions in this description may, but need not, refer to the same embodiment.

[0020] Furthermore, the described features, advantages, and properties of the invention can be combined in any suitable way in one or more embodiments. A person skilled in the art will recognize that the invention can be practically implemented without one or more of the specific features or advantages of a particular embodiment. In other cases, additional features and advantages may be clearly recognizable in certain embodiments that are not present in all embodiments of the invention.

[0021] The present invention modifies instructions used during the boot process of a computer before the boot process is complete. These features and advantages of the present invention will become clearer with reference to the following description and appended claims, or can be ascertained through the practical implementation of the invention as set forth below.

[0022] To facilitate understanding of the advantages of the invention, a more specific description of the invention briefly described above is given with reference to certain embodiments illustrated in the attached drawings. Understood that these drawings only depict typical embodiments of the invention and therefore do not serve to limit its scope of protection, the invention is described and explained with greater precision and detail using the attached drawings, which: Fig. 1 is a schematic block diagram representing an embodiment of a client / server system according to the present invention; Fig. 2 is a schematic block diagram representing an embodiment of a computer of the present invention; Fig. 3 is a schematic block diagram representing an embodiment of a device for pre-boot modification of the present invention; Fig. Figure 4 is a schematic block diagram representing an embodiment of encrypted regulation communication of the present invention; Fig. Figure 5 is a schematic block diagram representing an alternative embodiment of the encrypted regulation communication of the present invention; and Fig. Figure 6 is a schematic flowchart that represents an embodiment of a method for modifying a pre-boot instruction of the present invention.

[0023] Many of the functional units described in this description are referred to as modules to emphasize their independence in implementation. Modules can include hardware circuits such as one or more processors with memory, very low-level integration (VLSI) circuits, gate arrays, programmable logic, and / or discrete components. The hardware circuits can perform hard-wired logic functions, execute computer-readable programs stored in hardware memory devices, and / or execute programmed functions. The computer-readable programs, in combination with a computer system, can perform the functions of the invention.

[0024] Reference in this description to "an embodiment" or to a similar expression means that a particular feature, structure, or property described in connection with the embodiment is included in at least one embodiment of the present invention. Therefore, the use of the expression "in an embodiment" and similar expressions in this description may, but does not necessarily, refer to the same embodiment.

[0025] Furthermore, the described features, structures, or properties of the invention can be combined in any suitable way in one or more embodiments. The following description provides a multitude of specific details, such as examples of programming, software modules, user selection, network transactions, database queries, database structures, hardware modules, hardware circuits, hardware chips, etc., to provide a complete understanding of the embodiments of the invention. However, a person skilled in the art will recognize that the invention can be practically implemented without one or more of these specific details or using other methods, elements, materials, and so on. In other cases, well-known structures, materials, or operations are not shown or described in detail to avoid obscuring aspects of the invention.

[0026] Fig. Figure 1 is a schematic block diagram illustrating an embodiment of a client / server system 100 according to the present invention. The system 100 comprises one or more client computers 110, a network 115, and the server 120. The client computers 110 are hereinafter referred to as computers 110.

[0027] The network can be a wide area network (WAN), a local area network (LAN), the internet, or similar. Server 120 can also be configured as a mainframe computer, a blade server, or similar.

[0028] Server 120 can manage each computer 110. For example, Server 120 can back up the data on each computer 110, load and manage software on each computer 110, and manage the configuration of each computer 110.

[0029] Each computer 110 can run an operating system. The server 120 can communicate with the operating system of each computer 110 via the network 115. Unfortunately, the server 120 may be unable to communicate with and configure the computer 110 if the operating systems are not running. Consequently, in the past, the server 120 may have been unable to configure the computer 110 before it booted. The present invention supports the pre-boot modification of computer instructions, as described below.

[0030] Fig. Figure 2 is a schematic block diagram illustrating an embodiment of a computer 110 of the present invention. The computer 110 is a computer 110 of the Fig. 1. The description of Computer 110 refers to elements of the Fig. 1, where the same reference numerals refer to the same elements. The computer 110 has a processor module 205, a cache module 210, a memory module 215, a northbridge module 220, a southbridge module 225, a graphics module 230, a display module 235, a BIOS module 240, a network module 245, a peripheral connection module (“PCI module”) 260, and a memory module 265.

[0031] The processor module 205, the cache module 210, the memory module 215, the northbridge module 220, the southbridge module 225, the graphics module 230, the display module 235, the BIOS module 240, the network module 245, the PCI module 260, and the memory module 265, hereinafter referred to as elements, can be manufactured from semiconductor gates on one or more semiconductor substrates. Each semiconductor substrate can be packaged in one or more semiconductor devices mounted on printed circuit boards. Connections between the elements can be made via the semiconductor metal layers, substrate-to-substrate wiring, chip card strands, and / or wires connecting the semiconductor devices.

[0032] The memory module 215 stores software instructions and data. The processor module 205 executes the software instructions and manipulates the data, as is well known to experts. The software instructions and data can be configured as one or more programs readable by a computer.

[0033] Programs readable by a computer can be physically stored in the memory module 265. The memory module 265 can be a hard disk, an optical storage device, a holographic storage device, a micromechanical storage device, a semiconductor storage device, or the like.

[0034] Programs readable by a computer can include an operating system. The operating system can manage computer 110, run applications on computer 110, and communicate over the network 115. Unfortunately, the operating system and its functionality are typically not available until computer 110 has booted.

[0035] The processor module 205 can communicate with the cache module 210 via a processor interface bus to reduce the average access time to the memory module 215. The cache module 210 can store copies of data from the most frequently used memory module 215 locations. The computer 110 can utilize one or more cache modules 210, such as a DDR2 cache memory or similar.

[0036] The Northbridge module 220 can communicate with the processor module 205, the graphics module 230, the memory module 215, and the cache module 210, providing a bridging function between them. For example, the processor module 205 can be connected to the Northbridge module 220 via a 667 MHz front-side bus.

[0037] The Northbridge module 220 can be connected to the Southbridge module 225 via a direct medium interface bus (DMI bus). The DMI bus can establish a very fast, bidirectional point-to-point connection, supporting a clock rate of, for example, one gigabyte per second (1 GB / s) in each direction between the Northbridge module 220 and the Southbridge module 225. The Southbridge module 225 can power and communicate with the BIOS module 240, the network module 245, the PCI module 260, and the memory module 265.

[0038] The PCI 260 module can communicate with the Southbridge 225 module to transmit data or power to peripheral devices. The PCI 260 module can have a PCI bus for connecting peripheral devices. The PCI bus can logically connect multiple peripheral devices via the same set of connections. These peripheral devices can include printers, joysticks, scanners, and the like. The PCI 260 module can also function as an expansion card, as is well known to professionals.

[0039] The network module 245 can communicate with the southbridge module 225 to allow the computer 110 to communicate with other devices, such as the server 120, over the network 115. These devices can include routers, bridges, computers, printers, and the like.

[0040] The Display Module 235 can communicate with the Graphics Module 230 to display the topological representation of the user interface elements, as described below. The Display Module 235 can be a CRT (Column Display Unit), a liquid crystal display (LCD), or the like.

[0041] The BIOS module 240 can communicate commands via the southbridge module 225 to boot the computer 110, allowing software instructions stored on the memory module 265 to be loaded, executed on the processor module 205, and enabling the computer 110 to take control. According to one embodiment, the BIOS module instructions are stored in a flash memory device of the BIOS module 240. It is understood that the BIOS module instructions can be stored in other types of non-volatile memory devices.

[0042] The BIOS module 240 typically does not possess the functionality typically found in an operating system. For example, in the past, the BIOS module 240 may have been unable to communicate with the server 120 via the network module 245 over the network 115. The present invention supports secure communication with the server 120, which can modify a directive used by the BIOS module 240 when booting the computer 110.

[0043] Fig. Figure 3 is a schematic block diagram illustrating an embodiment of a pre-boot modification device 300 of the present invention. The pre-boot modification device 300 can be installed in any computer 110 of the Fig. 1- Fig. 2. According to a particular embodiment, the pre-boot modification device 300 is contained in the BIOS module 240 of the Fig. 2 included. The description of the Pre-Boot Modification Device 300 refers to elements of the Fig. 1- Fig. 2, where the same reference numerals refer to the same elements. The device 300 comprises a key module 305, a communication module 310, a decryption module 315, and an update module 320.

[0044] The key module 305 exchanges a key with the server 120 in a secure environment. The operating system can create this secure environment. For example, the operating system can communicate the key using a key pair consisting of a private key and a public key. According to one embodiment, the key module 305 is implemented in the computer program product, which has a computer-usable medium containing a computer-readable program stored in a hardware storage device such as the BIOS module 240 and / or the memory module 265.

[0045] The communication module 310 receives a directive encrypted with the key. This directive can be applied by the BIOS module 240 to configure the computer 110 during the boot process. For example, the BIOS module 240 can store directive settings and use these settings when the computer 110 boots. Therefore, the directive can be requested by the BIOS module 240 before the boot process is complete and the operating system is running on the computer 110.

[0046] According to one embodiment, the regulation is a group regulation for the majority of computers 110 of the Fig. 1. For example, the server 120 can apply the same rule to each of the plurality of computers 110. In one embodiment, the group rule includes a BIOS password. Alternatively, the group rule can include a hard disk password. According to one embodiment, the communication module 310 is implemented in a computer program product that includes a computer-usable medium containing a computer-readable program stored in a hardware storage device such as the BIOS module 240 and / or the memory module 265.

[0047] The decryption module 315 decrypts the encrypted regulation using the key and stores the regulation setting value before the operating system boots on the computer 110. According to one embodiment, the decryption module 315 is implemented in a computer program product that has a computer-usable medium containing a computer-readable program stored in a hardware storage device such as the BIOS module 240 and / or the memory module 265.

[0048] The update module 320 boots the computer 110 using the specified procedure. According to one embodiment, the update module 320 is included in a computer program product that has a computer-usable medium containing a computer-readable program stored in a hardware storage device such as the BIOS module 240 and / or the memory module 265.

[0049] Fig. Figure 4 is a schematic block diagram illustrating an embodiment of the encrypted regulation communication 400 of the present invention. The communication 400 represents the communication of a regulation 405 from the server 120 to the computer 110. The description of the communication 400 refers to elements of the Fig. 1- Fig. 3, where the same reference sign refers to the same elements.

[0050] Server 120 is shown, comprising a key 410 and the instruction 405. In one embodiment, the key 410 is a string of alphanumeric digits. In another embodiment, the key 410 is a string of numeric digits. The key 410 can have a specific length, for example, 120 digits. A person skilled in the art will recognize that the present invention can be practically implemented with other configurations of a key 410.

[0051] Regulation 405 can contain one or more settings used to boot computer 110. For example, regulation 405 can contain a hard drive password. Alternatively, regulation 405 can contain a network address for computer 110.

[0052] Both server 120 and computer 110 share the key 410. Server 120 and computer 110 can securely communicate using the key 410, as is well known to experts. For example, the operating system of computer 110 can securely receive the key 410 encrypted by server 120.

[0053] According to one embodiment, the computer 110 has a BIOS mail space 415. The BIOS mail space 415 can contain a plurality of memory data words in the BIOS module 240. Alternatively, the BIOS mail space 415 can contain a plurality of memory data words in the memory module 265.

[0054] Server 120 can encrypt regulation 405 with key 410. According to one embodiment, server 120 encrypts regulation 405 with key 410 by applying an algorithm to both regulation 405 and key 410 to form an alphanumeric string, as is well known to those skilled in the art. The encrypted regulation 420 is represented by regulation 405 surrounded by key 410, wherein the encrypted regulation 420 is the combination of key 410 and regulation 405.

[0055] According to one embodiment, server 120 communicates the encrypted regulation 420 to a post-boot operating system of computer 110 before the BIOS module 240 reboots computer 110. The post-boot operating system can be the normal computer operating system 110. Alternatively, the post-boot operating system can be a special operating system for configuring the client computer 110.

[0056] The operating system of computer 110 can store the encrypted regulation 420 in the BIOS mail space 415. The communication module 310 can receive the encrypted regulation 420 when the BIOS module 240 boots computer 110.

[0057] According to one embodiment, software instructions from BIOS module 240, running on processor module 205, decrypt the encrypted regulation 420 to restore regulation 405. The regulation setting values ​​of regulation 405 can be stored in BIOS module 240.

[0058] According to an alternative embodiment, the 405 instruction can be written to the memory module 215. The BIOS module 240 then boots the computer 110 using the 405 instruction.

[0059] Fig. Figure 5 is a schematic block diagram representing an alternative embodiment of the encrypted regulation communication 500 of the present invention. The communication 500 represents an alternative communication of the regulation 405 from the server 120 to the computer 110. The description of the communication 500 refers to elements of the Fig. 1- Fig. 4, where the same reference sign refers to the same elements.

[0060] In one embodiment, the communication module 310 requests the regulation 405 from the server 120. The communication module 310 can communicate a message 505 to the server 120 to request a regulation 405. In one embodiment, the communication module 310 authenticates the message 505 by encrypting the message 505 with the key 410. Alternatively, the communication module 310 can authenticate the message 505 by encrypting a character with the key 410 and inserting the encrypted character into the message 505.

[0061] The communication module 310 can be configured to activate the network module 245 and communicate with the server 120 via the network module 245 and the network 115. According to one embodiment, the communication module's functionality for communicating via the network 115 is limited to requesting and exchanging the encrypted regulation 420 with the server 120.

[0062] The communication module 310 can receive the encrypted regulation 420 from the server 120. In one embodiment, the server 120 communicates the encrypted regulation 420 through the network 115 and the network module 245. Software instructions from the BIOS module 240, running on a processor module 205, can decrypt the encrypted regulation 420 to restore the regulation 405. The regulation 405 can be stored in the BIOS module 240. In an alternative embodiment, the regulation 405 can be stored in a memory module 215.

[0063] The BIOS module 240 boots the computer 110 using standard settings from standard 405. The present invention provides for an update and / or modification of standard 405 before the operating system boots the computer 110. Therefore, settings applied during booting can be modified.

[0064] The following schematic flowchart is generally presented as a logical flowchart. Thus, the depicted sequence and the marked steps are characteristic of one embodiment of the present method. Other steps and procedures may be devised that are equivalent in function, logic, or effect to the depicted method with respect to one or more steps or parts thereof. Additionally, the format and symbols used are indicated to explain the logical steps of the method and are understood as not limiting the scope of protection of the method. Although different arrow and line types may be used in the flowcharts, they are understood as not limiting the scope of protection of the corresponding method. Indeed, some arrows or connectors may be used simply to represent the logical sequence of the method.For example, an arrow can represent a waiting or display period of indefinite duration between individually named steps of the depicted procedure. Additionally, the sequence in which a particular procedure is carried out may or may not be closely related to the sequence of the corresponding steps shown.

[0065] Fig. Figure 6 is a schematic flowchart illustrating an embodiment of Method 600 for modifying a pre-boot instruction of the present invention. Method 600 essentially comprises the steps of performing the functions described above with respect to the function of the described device and system. Fig. 1- Fig.5. According to one embodiment, the method 600 is implemented with a computer program product comprising a computer-readable medium containing a computer-readable program. The computer-readable program can be executed by the computer 110.

[0066] Key module 305 exchanges key 410 with server 120 in a secure environment. According to one embodiment, key module 305 exchanges key 410 with server 120 when computer 110 is initialized to run on the client / server system 100. Alternatively, computer 110's operating system can establish a secure communication channel with server 120 over network 115. The operating system can then receive key 410 over this secure communication channel.

[0067] In one embodiment, the key module 305 and the server 120 each store the key 410 in secure memory. For example, the key module 305 and the server 120 can store the key 410 in a Trusted Platform Module (TPM module), as is well known to those skilled in the art. Alternatively, the key module 305 and the server 120 can each encrypt the key 410 and store the encrypted key. In one embodiment, the key module 305 stores the key 410 in non-volatile memory, such as flash memory in the BIOS module 240. Only the BIOS module 240 can access the key 410.

[0068] The communication module 310 receives the regulation 405, encrypted with the key 410, from 610. In one embodiment, the server 120 communicates the encrypted regulation 420 to the operating system of the computer 110. The server 120 can instruct the operating system to store the encrypted regulation 420 in the BIOS mail space 415. In one embodiment, the server can communicate an authentication to the operating system. The authentication can authorize the operating system to store the encrypted regulation 420 in the BIOS mail space 415.

[0069] According to an alternative embodiment, the communication module 310 requests regulation 405 before the operating system boots on computer 110. The communication module 310 can use the key 410 to request regulation 405. For example, the communication module 310 can encrypt the request with the key 410. The communication module 310 can then receive the encrypted regulation 420 from server 120 as a response to the request.

[0070] Decryption module 315 decrypts the encrypted regulation 420 using key 410. Additionally, decryption module 315 can store a regulation setting before the operating system boots on computer 110. For example, regulation 405 can specify a regulation setting such as a network address for computer 110. One or more of the regulation setting values ​​may be immutable after computer 110 has booted, thus requiring pre-boot modification. Decryption module 315 can store the regulation setting values ​​for use by another executable code, such as update module 320.

[0071] Update module 320 boots computer 110 using regulation 405. In one embodiment, update module 320 boots the operating system using regulation settings from regulation 405. During booting, the operating system manages computer 110 using regulation settings.

[0072] The present invention modifies instructions used during the boot process of a computer 110 before the boot process is completed. The present invention may be implemented in other specific embodiments without deviating from its inventive concept or essential features. The described embodiments are in every respect intended only to be illustrative and not limiting. The scope of protection of the invention is therefore defined more by the appended claims than by the preceding description. All modifications within the literal meaning and scope of equivalence of the claims are included within their scope of protection.

Claims

[1] A computer program product comprising a computer-usable medium which has a computer-readable program stored on a hardware storage device, wherein the computer-readable program, when executed on a computer, causes the computer to: Using a post-boot operating system to exchange a key with a server in a secure environment; Receiving a regulation encrypted with the key; Decrypting the encrypted rule using the key and saving the rule setting value before booting an operating system on the computer; and Booting the computer using the instructions. [2] Computer program product according to claim 1, wherein the instruction is a group instruction for a plurality of computers. [3] Computer program product according to claim 2, wherein the group instruction includes a binary input / output system (BIOS) password. [4] Computer program product according to claim 2, wherein the group rule includes a hard disk password. [5] Computer program product according to claim 1, wherein the computer-readable program is further configured to cause the computer to request the instruction using the key prior to booting the operating system on the computer. [6] Computer program product according to claim 1, wherein the computer-readable program is further configured to cause the computer to apply a post-boot operating system to receive the instruction in a BIOS memory location. [7] Device comprising: a key module configured to apply a post-boot operating system to exchange a key with a server in a secure environment; a communication module configured to receive a regulation encrypted with the key; a decryption module configured to decrypt the encrypted regulation using the key and to save the regulation setting value before the computer boots an operating system; and an update module that is configured to boot the computer using the directive. [8] Device according to claim 7, wherein the instruction is a group instruction for a plurality of computers. [9] Device according to claim 8, wherein the group instruction includes a BIOS password. [10] Device according to claim 8, wherein the group instruction includes a hard disk password. [11] Device according to claim 7, wherein the communication module is further configured to request the instruction using the key before booting the operating system on the computer. [12] Device according to claim 7, wherein a post-boot operating system receives the instruction in a BIOS memory location. [13] System that features: a network; a server in communication with the network; a plurality of computers in communication with the server over the network, each computer having a key module configured to exchange a key with the server in a secure environment; a communication module configured to apply a post-boot operating system to exchange the key in a secure environment, to receive a regulation encrypted with the key; a decryption module configured to decrypt the encrypted regulation using the key and to save the regulation setting value before the computer boots an operating system; and an update module that is configured to boot the computer using the directive. [14] System according to claim 13, wherein the rule is a group rule for a plurality of computers. [15] System according to claim 14, wherein the group rule includes a BIOS password. [16] System according to claim 15, wherein the group rule includes a hard disk password. [17] System according to claim 13, wherein the communication module is further configured to request the instruction using the key before booting the operating system on the computer.

Citation Information

Patent Citations

  • Method for performing a trusted firmware / bios update

    US20050021968A1

  • Methods and apparatus for securely configuring a machine in a pre-operating system environment

    US20050114682A1