BIOS Authentication via Segmented Nonvolatile Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems, particularly in wagering game machines, face challenges in protecting and authenticating BIOS data from hacking, modification, and deletion, as existing architectures complicate the verification process due to storing network addresses and BIOS code in the same nonvolatile memory, making it difficult to ensure data integrity and compliance with gaming regulations.

Innovation Solution

A computer architecture that separates the storage of BIOS code and network addresses, using a nonvolatile memory for BIOS code and a different memory for network addresses, with the latter being derived from the former, ensuring unique addresses for each network port and allowing for independent authentication of BIOS data across multiple machines using a single digital signature.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If BIOS code and network addresses are stored in the same nonvolatile memory, then device complexity is reduced, but data integrity and authentication reliability deteriorate

Engineering Contradiction:
Improvememory architecture complexityVSAvoidBIOS data authentication reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent divides the storage system into two separate nonvolatile memory devices: one dedicated to storing BIOS code and another dedicated to storing network addresses. This segmentation allows independent authentication of BIOS data while maintaining manageable device complexity. The BIOS authentication can proceed without being compromised by network address storage, thus resolving the contradiction between simplicity and reliability.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If BIOS code is made writable for updates, then adaptability is improved, but security and data integrity deteriorate

Engineering Contradiction:
ImproveBIOS update capabilityVSAvoidunauthorized modification risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a preliminary action by creating a secure authentication mechanism that verifies BIOS code integrity before allowing execution. The system authenticates the BIOS code against stored authentication data in a separate memory device, ensuring that only authorized BIOS versions can run. This preliminary verification enables safe BIOS updates while preventing unauthorized modifications, resolving the contradiction between adaptability and security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication data is stored separately from BIOS code, then authentication reliability is improved, but device complexity and manufacturing cost increase

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidmanufacturing complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent makes the second nonvolatile memory device (originally intended for network addresses) serve a dual function: storing both network addresses and BIOS authentication data. This multi-functionality approach allows the system to achieve high authentication reliability without adding excessive manufacturing complexity, as the same hardware component performs multiple security-related functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9886282B2Computer BIOS protection and authentication
Publication Date: 2018.02.06 LNW GAMING INC
  • US9886282B2 patent drawing
  • US9886282B2 patent drawing
  • US9886282B2 patent drawing

AI summary

In some embodiments, a wagering game machine includes: a carrier board comprising a first network port and a second network port, the first network port having a first network address and the second network port having a second network address; a processor located on the carrier board; a first nonvolatile memory located on the carrier board and communicatively coupled to the first network port, the first nonvolatile memory configured to store the first network address; and a second nonvolatile memory located on the carrier board, wherein the second nonvolatile memory is configured to store Basic Input and Output System (BIOS) code that includes a system BIOS code and an application BIOS code, wherein the BIOS code is hardware write-protected, wherein the processor is configured to derive the second network address from the first network address during execution of boot-up operations of the apparatus.