BIOS Orchestration Instruction Authentication Against Replay and Tampering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in authenticating and executing one-time unique instructions left behind by containerized computing environments, which can be compromised or replayed across unauthorized systems, leading to unintended system behavior and potential manipulation.
Innovation Solution
Implementing a system and method that allows the BIOS to authenticate and execute instructions stored in public memory by a containerized computing environment, using Intel Measured Launch Environment (MLE) and Intel Trusted Execution Technology (TXT) to verify the authenticity and integrity of executable code, preventing unauthorized execution and manipulation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If instructions are stored in public memory by a containerized computing environment, then the instructions can be executed by the BIOS, but the instructions may be compromised or replayed across unauthorized systems
Solution Approach 1:
The patent applies preliminary action by having the containerized computing environment create and store orchestration instructions in public memory before the BIOS execution phase. The instructions are prepared with embedded authenticity indicators (monotonic counters, nonces) in advance, allowing the BIOS to verify them during execution without requiring the container environment to be actively present. This resolves the contradiction by enabling instruction execution while maintaining authenticity verification through pre-prepared verification mechanisms.
Solution Approach 2:
The patent introduces an intermediary mechanism in the form of authenticity indicators (monotonic counters, nonces, digital signatures) that mediate between the containerized computing environment and the BIOS. These indicators serve as trusted intermediaries that carry verification information from the instruction creation phase to the execution phase, enabling the BIOS to authenticate instructions stored in public memory without directly trusting the container environment. This resolves the contradiction by adding a verification layer that ensures instruction authenticity while allowing public memory storage.
2Adaptability or versatility
If privileged instructions are executed to perform system actions, then system functionality is enhanced, but unintended system behavior and manipulation risks increase
Solution Approach 1:
The patent implements feedback through monotonic counters and nonces that provide verification information back to the BIOS during instruction execution. The BIOS verifies these feedback indicators to confirm instruction authenticity and prevent replay attacks. This feedback mechanism allows the system to execute privileged instructions for enhanced functionality while simultaneously verifying instruction legitimacy, thus reducing manipulation risks. The feedback loop ensures that only authenticated instructions can trigger system actions.
Solution Approach 2:
The patent applies preliminary anti-action by embedding authenticity indicators and verification mechanisms into the orchestration instructions before they are executed. The BIOS performs preliminary verification of these indicators (monotonic counters, nonces, digital signatures) before allowing privileged instructions to execute. This preliminary anti-action prevents unauthorized or replayed instructions from executing, thereby reducing system manipulation risks while still allowing legitimate privileged operations to enhance system functionality.
3Ease of operation
If instructions are made accessible in public memory, then BIOS can retrieve and execute them, but instructions may be copied to unauthorized systems
Solution Approach 1:
The patent applies preliminary action by binding authenticity indicators (device identifiers, monotonic counters, nonces) to the orchestration instructions during their creation in the containerized computing environment. These indicators are embedded in the instructions before they are stored in public memory, enabling the BIOS to verify both accessibility and integrity. The preliminary binding of verification data allows instructions to be freely accessible in public memory while maintaining integrity through embedded authentication mechanisms.
Solution Approach 2:
The patent introduces authenticity indicators as intermediaries that accompany the orchestration instructions in public memory. These indicators (digital signatures, monotonic counters, nonces) serve as trusted mediators that enable the BIOS to distinguish authorized instructions from copied or tampered ones. The intermediary verification mechanism allows instruction accessibility while preventing unauthorized copying, as the BIOS can verify the authenticity of each instruction before execution.
Data Source
AI summary
Systems and methods are provided that may be implemented to provide a basic input/output system (BIOS) with the ability to authenticate and then execute one-time unique instructions that are previously left behind (i.e., stored) in public memory of an information handling system by a containerized computing environment session that is no longer executing on the information handling system. The disclosed systems and methods may be so implemented to share with the system BIOS privileged instructions to identify which executables are authorized for execution on a targeted information handling system. The privileged instructions may be previously created and optionally stored together with an executable code in system public memory, and these instructions may provide instructions on how to execute the executable code.


