BIOS Access Control via Remote Directory Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing BIOS settings across multiple computing devices in an enterprise environment is complicated by the need for secure access control, as local passwords can lead to administrative burdens and security weaknesses when each device has a unique password, or when all devices share the same password.

Innovation Solution

Implementing a remote directory server to manage user credentials and permissions, allowing computing devices to validate user access requests and grant access based on credentials and group memberships stored centrally, simplifying administration and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If each computing device has a unique local password for BIOS access control, then security is improved, but administrative complexity increases and security weaknesses arise when passwords need to be managed across multiple devices

Engineering Contradiction:
ImprovesecurityVSAvoidadministrative complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote directory server as an intermediary between computing devices and BIOS access control. The directory server stores and manages user credentials and permissions centrally, eliminating the need for administrators to manage unique passwords on each device. When BIOS access is requested, the local BIOS module communicates with the remote directory server to validate credentials and determine permissions, thereby improving security while reducing administrative complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If all computing devices share the same password for BIOS access, then administrative complexity is reduced, but security is weakened as discovery of the password grants access to all devices

Engineering Contradiction:
Improveease of administrationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The remote directory server acts as a mediator that enables both ease of administration and strong security simultaneously. Administrators can easily manage user credentials and permissions from a central location without needing to access each device individually. At the same time, security is maintained because the directory server validates credentials and enforces device-specific permissions, ensuring that even if one device's credentials are compromised, access to other devices remains protected.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements local quality by allowing each computing device to have its own specific permission settings stored in the remote directory server. While credential management is centralized for ease of administration, each device can have customized access control policies. This means that security permissions can be tailored to individual devices or users, providing both centralized management simplicity and device-specific security control.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If local passwords are used for BIOS access control, then device autonomy is maintained, but credential management becomes complicated across multiple devices

Engineering Contradiction:
Improvedevice autonomyVSAvoidcredential management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The remote directory server provides universal credential management functionality that serves all computing devices in the enterprise. Instead of each device needing independent password management capabilities, the centralized directory server handles authentication and authorization for all devices. This maintains device autonomy at the BIOS level while eliminating the complexity of distributed credential management, as the directory server provides a unified interface for managing access control across the entire device fleet.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9519784B2Managing basic input/output system (BIOS) access
Publication Date: 2016.12.13 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US9519784B2 patent drawing
  • US9519784B2 patent drawing
  • US9519784B2 patent drawing

AI summary

Example embodiments disclosed herein relate to managing basic input/output system (BIOS) access. Example embodiments include communicating with a remote directory server in response to an attempt to access a setting of a BIOS module.