BIOS Password Verification Via Dedicated Controller
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing device management methods relying on firmware program passwords are complex, prone to security risks, and interfere with ongoing operations, especially in diverse deployment scenarios like edge and cloud computing, where password leakage can lead to unauthorized access and data tampering.
Innovation Solution
Storing verification passwords in a dedicated controller independent of the device, allowing secure comparison and authentication through communication between the firmware program and the dedicated controller, enabling flexible and secure password management without physical contact.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the startup password is stored in the firmware program, then the device can be controlled to start and modify configuration, but the password is prone to leakage and security risks increase
Solution Approach 1:
The patent divides the password storage function into two separate components: the firmware program contains the password verification logic, while the dedicated controller stores the actual password credentials. This segmentation prevents password leakage within the firmware while maintaining security control, directly resolving the contradiction between device security and password leakage risk.
Solution Approach 2:
The dedicated controller acts as an intermediary between the firmware program and the password verification process. It receives password input from the firmware, compares it with stored credentials, and returns verification results. This intermediary mechanism eliminates direct password storage in the firmware, reducing leakage risks while maintaining authentication functionality.
2Ease of operation
If the password verification is performed in the firmware program, then the startup control is simplified, but the system complexity increases due to security requirements
Solution Approach 1:
The patent extracts the password verification functionality from the firmware program and relocates it to a dedicated controller. This extraction simplifies the firmware while introducing a specialized security component, reducing overall system complexity by separating security functions from core startup logic.
Solution Approach 2:
The dedicated controller serves multiple functions: storing password credentials, performing password verification, and providing secure communication with the firmware program. This multi-functionality consolidates security operations into a single component, reducing the need for multiple separate security mechanisms and thereby reducing system complexity.
3Adaptability or versatility
If the password is stored in the firmware program, then the authentication is integrated, but password updates become complex and interfere with ongoing operations
Solution Approach 1:
The patent implements dynamic password management by storing credentials in the dedicated controller rather than the firmware. This allows passwords to be updated, rotated, or changed without modifying the firmware program, enabling flexible adaptability while avoiding interruptions to ongoing device operations.
Solution Approach 2:
The dedicated controller is pre-configured with password storage and verification capabilities before deployment. This preliminary setup enables seamless password updates and changes without requiring firmware modifications or device reboots, thereby reducing operational complexity and maintaining continuous operation.
Data Source
AI summary
A method includes determining a first user password input to a firmware program (e.g., a basic input/output system) of a device (e.g., a server). The method further includes determining whether the first user password is the same as the verification password stored in a dedicated controller (e.g., a baseboard management controller of the server). The method further includes, in response to the first user password being the same as the verification password stored in the dedicated controller, determining to start the device. In this way, the verification password can be stored in the dedicated controller independently of the device, thereby reducing the risk of password leakage and enhancing the security of the device. The verification password can also be adjusted at any time as required, without physical contact or local login to the device, which simplifies the update process and reduces security risks while enhancing the flexibility of password management.


