BIOS Extension Failover via Networked Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Split boot architecture in information handling systems lacks a secure mechanism for extended firmware storage, making it vulnerable to attacks and failing to provide failover mechanisms, leading to potential boot failures and inability to migrate firmware between stores.

Innovation Solution

An information handling system with a processor and non-transitory computer-readable media storing a BIOS core and an extension agent that identifies and enumerates firmware volumes, enabling failover and recovery from extended firmware information stored on networked storage resources in case of unavailability.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If split boot architecture is used to store extended BIOS functions in external storage, then BIOS functionality can be expanded beyond SPI flash memory limitations, but the system becomes vulnerable to security attacks and lacks failover mechanisms

Engineering Contradiction:
ImproveBIOS functionality expansionVSAvoidboot failure vulnerability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary authentication and verification of the extended firmware store before allowing BIOS execution to proceed. The BIOS core authenticates the extended store's integrity and security attributes beforehand, ensuring that only verified firmware can be executed. This preliminary action prevents boot failures caused by corrupted or unauthorized firmware while maintaining the ability to expand BIOS functionality.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication layer between the BIOS core and the extended firmware store. This intermediary verifies security attributes, authenticates firmware integrity, and mediates access control. By inserting this intermediary verification mechanism, the system can safely utilize external storage for extended BIOS functions without compromising reliability or security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If extended firmware is stored on local storage devices, then BIOS can access additional features and updates, but the system lacks secure mechanisms to protect against attacks and drive corruption

Engineering Contradiction:
Improvefirmware feature accessVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by implementing pre-execution authentication and integrity verification of the extended firmware store. Before the BIOS executes any extended firmware code, it verifies security attributes, digital signatures, and integrity checksums. This preliminary protective action neutralizes security vulnerabilities by preventing execution of corrupted or malicious firmware, while still allowing access to extended features and updates.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent implements feedback mechanisms where the BIOS core continuously monitors and verifies the integrity and security attributes of the extended firmware store during operation. If any corruption or unauthorized modification is detected, the system provides feedback to halt execution or trigger recovery procedures. This feedback loop maintains security while enabling extended firmware functionality.

Inventive Principle:
Principle #23Feedback

3Device complexity

If no failover mechanisms are implemented in extended firmware storage, then the system architecture remains simple, but boot failures occur when local storage becomes unavailable

Engineering Contradiction:
Improvearchitecture simplicityVSAvoidboot availability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a networked storage intermediary that serves as a backup extended firmware store when local storage is unavailable. The BIOS core can authenticate and execute firmware from networked storage resources, providing failover capability. This intermediary approach adds minimal complexity while significantly improving boot availability by allowing the system to retrieve firmware remotely when local storage fails.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements multi-functionality in the firmware storage architecture by enabling the BIOS to execute extended firmware from multiple sources: local storage devices and networked storage resources. This universal approach allows the system to adaptively select the appropriate firmware source based on availability, maintaining simplicity while improving reliability through flexible boot options.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11907071B2Storage failover protocol for secure and seamless extended firmware load
Publication Date: 2024.02.20 DELL PROD LP
  • US11907071B2 patent drawing
  • US11907071B2 patent drawing
  • US11907071B2 patent drawing

AI summary

An information handling system may include a processor and first non-transitory computer-readable media communicatively coupled to the processor and having stored thereon a basic input/output system (BIOS) core comprising BIOS core firmware sufficient to execute features of a BIOS of the information handling system to a particular portion of BIOS execution and an extension agent. The extension agent may be configured to identify and enumerate a firmware volume of a second non-transitory computer-readable media communicatively coupled to the processor and having stored thereon a BIOS extension comprising BIOS extension firmware for executing completion of BIOS execution from the particular portion of BIOS execution and in response to unavailability of the firmware volume of the second non-transitory computer-readable media, failover to and recover the BIOS extension from extended firmware information stored on a networked storage resource communicatively coupled to the information handling system.