BIOS Policy Change Authorization via Dual-Memory Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
BIOS policies and code are susceptible to attacks and corruption, with no backup mechanism for configuration changes, making it difficult to detect unauthorized changes and execute corrupt policies, especially when stored in memory accessible by the central processing unit.
Innovation Solution
Implementing a dual-memory system where a BIOS policy change is authorized before storage, with a first copy stored in accessible memory and a second copy encrypted and stored in isolated memory, allowing validation through comparison of values to detect corruption and tampering, and using the isolated memory as a backup.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If BIOS policy is stored in memory accessible by CPU, then ease of operation is improved, but reliability deteriorates due to susceptibility to attacks and corruption
Solution Approach 1:
The patent divides BIOS storage into two separate memory locations: first memory accessible by CPU for operational access, and second memory isolated from CPU for secure backup storage. This segmentation allows the system to maintain ease of operation through CPU-accessible memory while improving reliability through isolated secure storage that protects against attacks and corruption.
2Productivity
If BIOS policy change is authorized and stored in first memory, then productivity is improved, but object-affected harmful factors worsen due to potential corruption and unauthorized changes
Solution Approach 1:
The patent implements preliminary authorization verification before storing BIOS policy changes in the first memory. The system checks authorization status prior to committing changes, preventing unauthorized or corrupt modifications from being stored. This preliminary action ensures that only validated BIOS updates are applied, improving productivity while mitigating the risk of harmful factors like corruption and unauthorized changes.
3Reliability
If dual-memory system with validation is implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The patent creates a copy of the BIOS policy and stores it in the second isolated memory. This copying mechanism enables reliability improvement through validation comparison between the first and second memory copies, while keeping the implementation relatively simple by using straightforward duplication rather than complex verification algorithms or additional hardware validation circuits.
Data Source
AI summary
Examples herein disclose receiving a basic input output system (BIOS) policy change and authorizing the BIOS policy change. Upon the authorization of the BIOS policy change, a first copy of the BIOS policy is stored in a first memory accessible by a central processing unit. Additionally, a second copy of the BIOS policy change is transmitted for storage in a second memory electrically isolated from the central processing unit.


