BIOS Recovery Key Storage with TPM-Protected Local Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in managing and securely storing recovery keys, particularly due to user unawareness of built-in encryption technologies and potential loss or misplacement of recovery keys, leading to inaccessible data and increased manufacturer contact.

Innovation Solution

A system and method for local key storage and management of recovery keys by encrypting and securely storing them in the Basic Input/Output System (BIOS) of the information handling system, allowing access through a local administrator account without needing network credentials.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If recovery keys are stored locally in the information handling system, then data accessibility and recovery convenience are improved, but security risks increase due to potential unauthorized access

Engineering Contradiction:
Improverecovery key accessibilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The recovery key is nested within multiple layers of security structures - stored in encrypted form within the BIOS firmware, protected by TPM hardware module, and encrypted with AES encryption. This nested security architecture allows the key to be locally accessible while maintaining multiple barriers against unauthorized access.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The system changes the state of the recovery key from plaintext to encrypted form using AES encryption, and further protects it through TPM hardware-based cryptographic operations. This parameter transformation ensures the key remains inaccessible in usable form while being available for authorized recovery operations.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If recovery keys are stored remotely on network servers, then security is improved through centralized management, but data accessibility deteriorates when network access is unavailable

Engineering Contradiction:
ImprovesecurityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system segments the recovery key storage into two parts: an encrypted version stored locally in the BIOS/TPM for immediate accessibility, and another copy stored remotely on network servers for centralized security management. This segmentation allows the system to benefit from both local accessibility and remote security management simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The BIOS firmware acts as an intermediary layer that mediates between the local hardware (TPM, storage) and remote network resources. It manages the recovery key locally while enabling secure communication with remote servers, allowing the system to operate autonomously when needed while maintaining connection to centralized security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If encryption is implemented on storage devices, then data security is improved, but user awareness and proper key management deteriorate

Engineering Contradiction:
Improvedata securityVSAvoidkey management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service key management by automatically generating, storing, and managing recovery keys within the BIOS and TPM without requiring user intervention. The encrypted recovery key is automatically available through the BIOS setup utility or recovery environment, eliminating the need for users to manually manage complex cryptographic keys while maintaining strong security.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12430450B2Recovery key management and storage
Publication Date: 2025.09.30 DELL PROD LP
  • US12430450B2 patent drawing
  • US12430450B2 patent drawing
  • US12430450B2 patent drawing

AI summary

An information handling system retrieves a recovery key and secures the recovery key by encrypting the recovery key. Subsequent to securing the recovery key, the system injects the recovery key within a basic input/output system.