BIOS Boot Drive Switching via External Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional information processing apparatuses face security risks and OS restrictions when attempting to update or change maintenance programs, as they require booting from internal devices and lack flexibility in switching boot drives during BIOS boot-up, especially when external devices are connected.

Innovation Solution

An information processing apparatus with a connection section for external recording media, which determines the presence and authenticity of authentication information on connected media, allowing booting from either an internal or external program based on authentication verification, ensuring security by only booting authorized programs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the system boots from the internal recording medium (first program) to ensure security, then security is maintained, but flexibility to update maintenance programs via external media is lost

Engineering Contradiction:
ImprovesecurityVSAvoidflexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system dynamically switches between static boot modes (internal-only or external-only) based on authentication results. The boot drive selection is no longer fixed but adapts according to whether authentication information is present on the external recording medium, resolving the contradiction between security and flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the boot parameter (boot drive selection) based on the presence or absence of authentication information. When authentication information is detected on external media, the system changes the boot parameter to prioritize external media; otherwise, it maintains internal media as the boot drive, thus balancing security and flexibility.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If the system allows booting from external recording media to enable program updates, then flexibility is improved, but security risks increase due to unauthorized access

Engineering Contradiction:
ImproveflexibilityVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication verification on the external recording medium before allowing boot operations. By checking for authentication information in advance (before booting), the system ensures that only authorized external media can be booted, thus enabling flexibility while preventing security risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Authentication information acts as an intermediary between the external recording medium and the boot system. This intermediary mechanism verifies the legitimacy of external media before allowing access, thus enabling program updates from external sources while maintaining security through the authentication barrier.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the system requires authentication steps for maintenance program access, then security is improved, but operation complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidoperation complexity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs self-authentication by automatically detecting authentication information on the inserted external recording medium without requiring manual intervention. The authentication process is embedded in the boot sequence itself, eliminating the need for separate authentication steps and reducing operational complexity while maintaining security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7953967B2Information processing apparatus and program
Publication Date: 2011.05.31 KONICA MINOLTA BUSINESS TECH INC
  • US7953967B2 patent drawing
  • US7953967B2 patent drawing
  • US7953967B2 patent drawing

AI summary

An information processing apparatus including: a first recording medium which stores a first program; a connection section which is capable of connecting with a second recording medium from outside; and a controller which determines, during BIOS boot-up operation, whether or not the connection section is connected with the second recording medium which stores predetermined authentication information, and if connected, boots a second program stored in the second recording medium, while if not connected, boots the first program stored in the first recording medium.