BIOS Boot Control for Secure Software Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing and managing software installations in computer systems lack efficiency and scalability, particularly in large-scale deployments, as they often require significant labor and do not adequately address software integrity and resilience to failures throughout the production and distribution chain.

Innovation Solution

A method and system that utilizes a USB memory stick as secondary media for booting, incorporating digital signature verification and a watchdog function within the BIOS to ensure system integrity and resilience, allowing for secure and unattended software installations and upgrades by prioritizing booting from secondary media until verification is successful, then switching to primary media if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional software installation methods are used, then software can be installed on computer systems, but significant labor and support personnel are required, reducing efficiency and scalability

Engineering Contradiction:
Improvesoftware installation efficiencyVSAvoidlabor requirement
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The system enables unattended software installation and upgrades by implementing automatic digital signature verification in the BIOS boot process. The BIOS automatically verifies the integrity of software images loaded from secondary media using digital signatures, eliminating the need for manual intervention or support personnel during the installation process.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent implements preliminary verification of software integrity through digital signatures before the software is actually installed or executed. The BIOS performs signature verification during the boot process, ensuring that only authenticated software images are loaded and installed, preventing malicious or corrupted software from being installed.

Inventive Principle:
Principle #10Preliminary action

2Ease of manufacture

If software is distributed through multiple entities in the production chain, then manufacturing costs are reduced, but software integrity and security cannot be guaranteed

Engineering Contradiction:
Improvemanufacturing costVSAvoidsoftware integrity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system implements a feedback mechanism where the BIOS continuously verifies the digital signatures of software images during the boot process. This verification provides feedback on the integrity of the software, ensuring that only authenticated software from authorized sources can be executed, thereby maintaining security trust across the distributed production chain.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces digital signatures as an intermediary mechanism between the software distributor and the end system. The digital signature acts as a trusted mediator that verifies the authenticity and integrity of software images, allowing multiple entities in the production chain to distribute software securely without compromising integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If software security products are implemented, then viruses and malicious software can be detected and removed, but security depends on the operating system not being compromised during bootstrap

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidsecurity system dependency
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent moves the security verification function to the BIOS level, performing digital signature verification before the operating system is loaded and executed. This preliminary action ensures that the security mechanism operates independently of the operating system state, verifying software integrity at the bootstrap phase before any OS-based security products can function.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The digital signature verification mechanism serves as an intermediary security layer between the hardware and the operating system. By verifying software authenticity at the BIOS level, the system creates a trusted foundation that operates independently of the OS, reducing dependency on OS-based security products.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Ease of operation

If preinstalled operating software is provided, then systems are operable right out-of-the-box, but software may be illegally copied or pirated at the lower end of the supply chain

Engineering Contradiction:
Improveout-of-box functionalityVSAvoidsoftware piracy
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system implements feedback through digital signature verification that confirms the authenticity of preinstalled software. The BIOS verifies the software image signature during boot, providing feedback that the software is genuine and authorized, thereby preventing piracy while maintaining out-of-box functionality.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses digital signatures as a cryptographic copy-protection mechanism. The software image is signed with a private key, and the corresponding public key is stored in the BIOS. This creates a verifiable copy-protection system where the software can be copied and distributed, but its authenticity can be verified through the digital signature, preventing unauthorized piracy.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS8694763B2Method and system for secure software provisioning
Publication Date: 2014.04.08 ONITEO
  • US8694763B2 patent drawing
  • US8694763B2 patent drawing
  • US8694763B2 patent drawing

AI summary

A method and system for the provisioning of software that enable large scale installation and management of software in computer units in a highly secure manner. The BIOS of the target computer unit is adapted such that upon power up the system attempts to boot from an external media. The BIOS features functions within the code for the implementing a system watchdog for assuring the system remains in a known state, a function for digital signature verification, and loads drivers for a file system. The external media includes the operating system (OS) image and other bootstrap files, each having been digitally signed with an asymmetric private key that corresponds to the public key. A programmable read-only parameter memory on the motherboard is configured to store the public keys and the (failure) state of the system independently of the primary and secondary media enabling reboot from an alternative boot path.