BIOS Authentication Mechanism for Secure Remote Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current BIOS configuration management for servers is inefficient and insecure, as it requires human intervention and OS applications, limiting remote access and making servers vulnerable to malware and delayed updates due to restrictive access permissions.

Innovation Solution

Implementing a BIOS authentication mechanism that allows authorized users to unlock and modify BIOS settings using valid authentication information, such as passwords or biometrics, stored securely within the BIOS or management controllers, enabling secure remote access and updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BIOS settings are locked to prevent unauthorized access, then security is improved, but the ability to modify BIOS configurations remotely is worsened

Engineering Contradiction:
ImproveBIOS securityVSAvoidRemote BIOS modification capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces an authentication mechanism as an intermediary between the locked BIOS settings and modification requests. The BIOS authentication mechanism verifies credentials before allowing state transitions from locked to unlocked, enabling secure remote modification without requiring physical access or disabling security measures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If traditional human-to-machine interface and OS application are used to change BIOS configurations, then ease of operation is maintained, but productivity and remote management efficiency are worsened

Engineering Contradiction:
ImproveBIOS configuration interfaceVSAvoidServer configuration efficiency
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The patent replaces the mechanical interaction model (physical keyboard, monitor, and OS application) with an electronic authentication and control system. The BIOS authentication mechanism enables remote modification through digital credential verification, eliminating the need for physical presence or complex OS-based configuration tools.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Device complexity

If BIOS settings are preloaded with default configurations, then device complexity is reduced, but adaptability to different customer needs is worsened

Engineering Contradiction:
ImproveBIOS configuration complexityVSAvoidBIOS configuration flexibility
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic BIOS configuration system where settings can transition between locked and unlocked states based on authentication. This allows the BIOS to maintain a simple default state for most operations while enabling flexible customization when authorized, adapting to different customer needs without increasing overall system complexity.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9875113B2System and method for managing BIOS setting configurations
Publication Date: 2018.01.23 QUANTA COMPUTER INC
  • US9875113B2 patent drawing
  • US9875113B2 patent drawing
  • US9875113B2 patent drawing

AI summary

A BIOS settings configuration may be stored in BIOS of a computer system. A default BIOS status may be set as a locked state. The BIOS status can be changed from the locked state to an unlocked state when an authentication request is received and when the received authentication information matches stored authentication information in BIOS. In some embodiments, a BIOS settings change request can be received. The BIOS settings can be modified based on the BIOS settings change request. The BIOS status can be changed back to the locked state after the BIOS settings modification has been made.