BIOS Runtime Modification Authentication via TPM Challenge
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional BIOS password systems do not prevent unauthorized modifications of BIOS settings during runtime in information handling systems, particularly in environments with low or unknown security.
Innovation Solution
A BIOS setting runtime modification authentication system that utilizes a Trusted Platform Module (TPM) device to generate and manage secrets, creating challenge information that allows only authorized platform owners to modify BIOS settings during runtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a BIOS password is used to prevent unauthorized modification of BIOS settings, then security during initialization is improved, but security during runtime is not enhanced
Solution Approach 1:
The system performs preliminary authentication actions during runtime by verifying the platform owner authentication value stored in the TPM device before allowing any BIOS settings modification. This preliminary verification ensures that only authorized users can modify settings during runtime operations.
Solution Approach 2:
The TPM device serves as an intermediary between the user and the BIOS settings modification process. It mediates the authentication by storing and verifying the platform owner authentication value, enabling secure runtime modification without compromising system integrity.
2Adaptability or versatility
If BIOS settings can be modified during runtime, then system flexibility is improved, but unauthorized access risk increases
Solution Approach 1:
The system implements feedback by continuously verifying the platform owner authentication value during runtime operations. Before allowing any BIOS settings modification, the system checks whether the authentication value provided matches the stored value in the TPM device, providing feedback control to prevent unauthorized access.
Solution Approach 2:
The TPM device acts as an intermediary that mediates between the user's modification requests and the BIOS settings. It verifies authentication credentials before permitting any changes, thus enabling flexible runtime configuration while mitigating unauthorized access risks.
3Reliability
If platform owner authentication is implemented via TPM device, then security authentication is improved, but device complexity increases
Solution Approach 1:
The TPM device performs self-service by autonomously storing and verifying the platform owner authentication value. The system leverages the TPM's built-in cryptographic capabilities to authenticate users without requiring complex external authentication infrastructure, thus improving security while minimizing added complexity.
Solution Approach 2:
The TPM device provides multi-functionality by serving multiple purposes: secure boot authentication, runtime modification authentication, and platform integrity verification. This universal authentication mechanism improves security across different operations without proportionally increasing system complexity.
Data Source
AI summary
A BIOS settings runtime modification authentication system includes a computing device having a user interface subsystem, a TPM device storing a platform owner authentication value, and a BIOS subsystem including BIOS settings. The BIOS subsystem generates a secret and creates challenge information with the TPM device using the secret. The challenge information is configured to allow the TPM device to retrieve the secret from the challenge information in response to the receiving the platform owner authentication value. During runtime operations for the computing device, the BIOS subsystem provides the challenge information via the user interface subsystem, receives a BIOS authentication request and the secret via the user interface subsystem and, in response, modifies at least one of the BIOS settings.


