BIOS Boot Integrity Verification Before Computer Startup

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer boot methods are vulnerable to security risks due to tampering or damage of the BIOS program file, leading to potential security incidents and information leakage.

Innovation Solution

A computer boot method involving a controller that checks the integrity of the BIOS program file before establishing a connection with the computer hardware system, ensuring only secure BIOS files are used for booting, and optionally replacing or deleting tampered files to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the BIOS program file is stored in the flash of the BIOS hardware system, then the computer can be booted, but the system becomes vulnerable to tampering and security risks

Engineering Contradiction:
Improveboot securityVSAvoidtampering with BIOS file
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a controller as an intermediary component between the BIOS hardware system and the computer hardware system. This controller reads the BIOS program file from the flash storage, verifies its integrity through cryptographic signatures, and only enables booting if the verification passes. The controller acts as a security mediator that prevents tampered BIOS files from compromising system bootability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the BIOS program file is tampered with or damaged, then user settings and security permissions are lost, but the computer can still attempt to boot

Engineering Contradiction:
Improvesystem boot reliabilityVSAvoiduser settings and security permissions
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements preliminary verification of the BIOS program file before the booting process begins. The controller checks the cryptographic signature of the BIOS file stored in the flash memory before allowing the computer hardware system to load and execute it. This preliminary action prevents tampered or damaged BIOS files from causing loss of user settings and security permissions during the boot process.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If a check mechanism is added to verify the BIOS program file, then boot security is improved, but the device complexity increases

Engineering Contradiction:
Improveboot securityVSAvoidcontroller and verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The controller is designed as a multi-functional component that performs various tasks including reading the BIOS program file from flash storage, verifying its cryptographic signature, controlling the booting process, and managing system initialization. By consolidating these multiple functions into a single controller component, the patent achieves boot security verification without proportionally increasing overall device complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP3971749B1Computer starting method, controller, storage medium and system
Publication Date: 2025.10.01 XFUSION DIGITAL TECH CO LTD
  • EP3971749B1 patent drawingFigure 1~2
  • EP3971749B1 patent drawingFigure 3
  • EP3971749B1 patent drawingFigure 4

AI summary

Embodiments of this application disclose a computer boot method, a controller, a storage medium, and a system, to improve a boot security level of a computer, and avoid a security risk caused by using a tampered boot program file. In a method, a controller is separately connected to a computer hardware system and a BIOS file storage apparatus. The method includes: The controller obtains a first boot program file in the BIOS file storage apparatus when the controller is powered on and runs, where the first boot program file is a BIOS file pre-stored in the BIOS file storage apparatus. The controller checks the first boot program file. The controller establishes a connection between the BIOS file storage apparatus and the computer hardware system when the first boot program file is successfully checked, so that when the connection between the BIOS file storage apparatus and the computer hardware system is successfully established, the computer hardware system completes power-on and running by using the first boot program file.