BIOS Pre-OS Resiliency via Event Threshold Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems face vulnerabilities at the pre-OS level due to tampering with boot-critical files on the EFI system partition, which can lead to malicious behavior and compromise system security.
Innovation Solution
Implementing a BIOS with executable instructions that determine malicious BIOS events during the boot process and initiate remedial actions, such as file restoration or repair, based on predetermined thresholds of detected events, to ensure pre-OS fault resiliency and safeguard boot-critical files.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If boot-critical files on the EFI system partition are made accessible for external updates and customization, then system adaptability and ease of repair are improved, but system security and reliability deteriorate due to tampering vulnerabilities at the pre-OS level
Solution Approach 1:
The patent implements preliminary protective actions by establishing a secure container for boot-critical files before the OS loads, configuring allowed paths and permissions in advance, and pre-defining security policies that automatically enforce protection during the boot process, preventing tampering before it can occur
Solution Approach 2:
The patent introduces an intermediary security layer between external access attempts and boot-critical files. This intermediary mechanism validates access requests, enforces permission policies, and mediates all interactions with protected files during pre-OS execution, blocking malicious access while allowing legitimate operations
2Reliability
If security controls are implemented at the pre-OS level to protect boot-critical files, then system reliability and security are improved, but device complexity and difficulty of operation increase
Solution Approach 1:
The patent implements self-service security mechanisms where the system automatically protects its own boot-critical files without requiring external security software or manual configuration. The pre-OS security layer autonomously validates access requests, enforces policies, and maintains protection during the boot process, reducing operational complexity
Solution Approach 2:
The patent segments the file system into protected and unprotected regions, isolating boot-critical files in a secure container with restricted access. This segmentation allows standard file operations in unprotected areas while maintaining simple, focused security controls only where needed, reducing overall system complexity
3Reliability
If tamper detection mechanisms are added to monitor BIOS events and detect malicious behavior, then system reliability is improved, but device complexity and processing overhead increase
Solution Approach 1:
The patent applies tamper detection selectively only to specific boot-critical files and BIOS events rather than monitoring the entire system. By focusing detection resources on locally relevant security threats at the pre-OS level, the mechanism achieves effective monitoring with minimal processing overhead and reduced complexity
4Reliability
If remedial actions are automatically executed in response to detected malicious events, then system reliability and security are improved, but loss of time and operational control increase
Solution Approach 1:
The patent prepares remedial actions in advance by pre-configuring recovery procedures and secure fallback options during system initialization. When malicious events are detected, pre-prepared remedial measures can be executed immediately without lengthy analysis or user intervention, reducing time loss while maintaining security
Solution Approach 2:
The patent implements partial remedial actions that address only the specific detected threat rather than executing comprehensive system-wide recovery procedures. This targeted approach applies minimal necessary corrections to maintain security while avoiding excessive processing time and operational disruption
Data Source
AI summary
An information handling system may include a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system; at least one processor; and a Basic Input/Output System (BIOS) including instructions that are executable by the at least one processor for: during a boot process, determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process; and in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, carrying out a remedial action during the boot process.

