BIOS Pre-OS Resiliency via Event Threshold Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems face vulnerabilities at the pre-OS level due to tampering with boot-critical files on the EFI system partition, which can lead to malicious behavior and compromise system security.

Innovation Solution

Implementing a BIOS with executable instructions that determine malicious BIOS events during the boot process and initiate remedial actions, such as file restoration or repair, based on predetermined thresholds of detected events, to ensure pre-OS fault resiliency and safeguard boot-critical files.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If boot-critical files on the EFI system partition are made accessible for external updates and customization, then system adaptability and ease of repair are improved, but system security and reliability deteriorate due to tampering vulnerabilities at the pre-OS level

Engineering Contradiction:
Improvesystem adaptabilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary protective actions by establishing a secure container for boot-critical files before the OS loads, configuring allowed paths and permissions in advance, and pre-defining security policies that automatically enforce protection during the boot process, preventing tampering before it can occur

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security layer between external access attempts and boot-critical files. This intermediary mechanism validates access requests, enforces permission policies, and mediates all interactions with protected files during pre-OS execution, blocking malicious access while allowing legitimate operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security controls are implemented at the pre-OS level to protect boot-critical files, then system reliability and security are improved, but device complexity and difficulty of operation increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service security mechanisms where the system automatically protects its own boot-critical files without requiring external security software or manual configuration. The pre-OS security layer autonomously validates access requests, enforces policies, and maintains protection during the boot process, reducing operational complexity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent segments the file system into protected and unprotected regions, isolating boot-critical files in a secure container with restricted access. This segmentation allows standard file operations in unprotected areas while maintaining simple, focused security controls only where needed, reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

3Reliability

If tamper detection mechanisms are added to monitor BIOS events and detect malicious behavior, then system reliability is improved, but device complexity and processing overhead increase

Engineering Contradiction:
Improvesystem securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies tamper detection selectively only to specific boot-critical files and BIOS events rather than monitoring the entire system. By focusing detection resources on locally relevant security threats at the pre-OS level, the mechanism achieves effective monitoring with minimal processing overhead and reduced complexity

Inventive Principle:
Principle #3Local quality

4Reliability

If remedial actions are automatically executed in response to detected malicious events, then system reliability and security are improved, but loss of time and operational control increase

Engineering Contradiction:
Improvesystem securityVSAvoidboot process time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent prepares remedial actions in advance by pre-configuring recovery procedures and secure fallback options during system initialization. When malicious events are detected, pre-prepared remedial measures can be executed immediately without lengthy analysis or user intervention, reducing time loss while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial remedial actions that address only the specific detected threat rather than executing comprehensive system-wide recovery procedures. This targeted approach applies minimal necessary corrections to maintain security while avoiding excessive processing time and operational disruption

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11797682B2Pre-OS resiliency
Publication Date: 2023.10.24 DELL PROD LP
  • US11797682B2 patent drawing
  • US11797682B2 patent drawing

AI summary

An information handling system may include a physical storage resource having a portion thereof that includes files that are usable during boot of the information handling system; at least one processor; and a Basic Input/Output System (BIOS) including instructions that are executable by the at least one processor for: during a boot process, determining whether any of a plurality of BIOS events have taken place during a previous boot process, wherein the plurality of BIOS events are indicative of malicious behavior during the previous boot process; and in response to a determination that at least a predetermined number of the plurality of BIOS events have taken place during the previous boot process, carrying out a remedial action during the boot process.