BIOS Password Verification Via Dedicated Controller

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing device management methods relying on firmware program passwords are complex, prone to security risks, and interfere with ongoing operations, especially in diverse deployment scenarios like edge and cloud computing, where password leakage can lead to unauthorized access and data tampering.

Innovation Solution

Storing verification passwords in a dedicated controller independent of the device, allowing secure comparison and authentication through communication between the firmware program and the dedicated controller, enabling flexible and secure password management without physical contact.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the startup password is stored in the firmware program, then the device can be controlled to start and modify configuration, but the password is prone to leakage and security risks increase

Engineering Contradiction:
Improvedevice securityVSAvoidpassword leakage risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the password storage function into two separate components: the firmware program contains the password verification logic, while the dedicated controller stores the actual password credentials. This segmentation prevents password leakage within the firmware while maintaining security control, directly resolving the contradiction between device security and password leakage risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The dedicated controller acts as an intermediary between the firmware program and the password verification process. It receives password input from the firmware, compares it with stored credentials, and returns verification results. This intermediary mechanism eliminates direct password storage in the firmware, reducing leakage risks while maintaining authentication functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the password verification is performed in the firmware program, then the startup control is simplified, but the system complexity increases due to security requirements

Engineering Contradiction:
Improvestartup controlVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent extracts the password verification functionality from the firmware program and relocates it to a dedicated controller. This extraction simplifies the firmware while introducing a specialized security component, reducing overall system complexity by separating security functions from core startup logic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The dedicated controller serves multiple functions: storing password credentials, performing password verification, and providing secure communication with the firmware program. This multi-functionality consolidates security operations into a single component, reducing the need for multiple separate security mechanisms and thereby reducing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If the password is stored in the firmware program, then the authentication is integrated, but password updates become complex and interfere with ongoing operations

Engineering Contradiction:
Improvepassword management flexibilityVSAvoidpassword update complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic password management by storing credentials in the dedicated controller rather than the firmware. This allows passwords to be updated, rotated, or changed without modifying the firmware program, enabling flexible adaptability while avoiding interruptions to ongoing device operations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The dedicated controller is pre-configured with password storage and verification capabilities before deployment. This preliminary setup enables seamless password updates and changes without requiring firmware modifications or device reboots, thereby reducing operational complexity and maintaining continuous operation.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250335571A1Method, device, and computer program product for verifying password
Publication Date: 2025.10.30 DELL PROD LP
  • US20250335571A1 patent drawing
  • US20250335571A1 patent drawing
  • US20250335571A1 patent drawing

AI summary

A method includes determining a first user password input to a firmware program (e.g., a basic input/output system) of a device (e.g., a server). The method further includes determining whether the first user password is the same as the verification password stored in a dedicated controller (e.g., a baseboard management controller of the server). The method further includes, in response to the first user password being the same as the verification password stored in the dedicated controller, determining to start the device. In this way, the verification password can be stored in the dedicated controller independently of the device, thereby reducing the risk of password leakage and enhancing the security of the device. The verification password can also be adjusted at any time as required, without physical contact or local login to the device, which simplifies the update process and reduces security risks while enhancing the flexibility of password management.