BIOS Secure Boot Customization via External Key Database
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in customizing Secure Boot extensions due to size constraints and complexities in managing cryptographic keys, which limit manufacturer feature enhancements and customer customization options, particularly when integrating custom keys with Secure Boot databases.
Innovation Solution
An information handling system that includes memory circuitry with a BIOS and a separate physical storage medium for a custom database of cryptographic keys, allowing the system to load and execute BIOS extensions by authenticating with keys from the custom database, thereby bypassing the need for updating the BIOS firmware and accommodating customer-specific key management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cryptographic keys are included in the BIOS Secure Boot database to enable manufacturer feature enhancements, then code integrity verification is improved, but the system becomes restricted when customers require their own custom key databases
Solution Approach 1:
The patent segments the Secure Boot key management into two separate databases: the traditional BIOS Secure Boot database and a new custom Secure Boot database stored on a removable storage device. This segmentation allows manufacturer keys and customer keys to coexist independently, resolving the conflict between maintaining code integrity verification and supporting custom key databases.
Solution Approach 2:
The patent introduces a custom database file as an intermediary between the BIOS and customer key management requirements. This intermediary layer allows the BIOS to verify code integrity using manufacturer keys while simultaneously enabling customers to provide their own keys without modifying the BIOS firmware.
2Adaptability or versatility
If the Secure Boot database is updated to include custom customer keys, then customer customization options are improved, but Bitlocker recovery functionality is restricted or lost
Solution Approach 1:
The patent separates customer custom keys into a distinct custom database file on removable storage, isolating them from the BIOS Secure Boot database that contains manufacturer keys required for Bitlocker recovery. This segmentation allows customers to customize their key database without affecting the integrity verification needed for Bitlocker functionality.
Solution Approach 2:
The custom database file acts as an intermediary that provides customer customization capabilities while preserving the original BIOS Secure Boot database intact, thereby maintaining Bitlocker recovery functionality.
3Adaptability or versatility
If BIOS firmware is updated to support custom Secure Boot databases, then feature enhancements are enabled, but the complexity of deployment and key management increases
Solution Approach 1:
The patent uses a custom database file on removable storage as an intermediary layer that adds customization capabilities without requiring BIOS firmware updates. This approach enables Secure Boot customization while keeping the BIOS firmware simple and avoiding the complexity of firmware update deployment.
Data Source
AI summary
An information handling system may include memory circuitry comprising a BIOS and a database including a first set of one or more cryptographic keys usable to authenticate code executable by the BIOS; and a physical storage medium other than the memory circuitry, wherein the physical storage medium includes a custom database including a second set of one or more cryptographic keys usable to authenticate code executable by the BIOS. The information handling system is configured to load a BIOS extension into the BIOS by: determining that the first set of one or more cryptographic keys does not include any key usable to authenticate the BIOS extension; determining that the second set of one or more cryptographic keys includes a particular key usable to authenticate the BIOS extension; authenticating the BIOS extension via the particular key; and in response to the authenticating, loading and executing the BIOS extension.


