BIOS Secure Boot Customization via External Key Database

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in customizing Secure Boot extensions due to size constraints and complexities in managing cryptographic keys, which limit manufacturer feature enhancements and customer customization options, particularly when integrating custom keys with Secure Boot databases.

Innovation Solution

An information handling system that includes memory circuitry with a BIOS and a separate physical storage medium for a custom database of cryptographic keys, allowing the system to load and execute BIOS extensions by authenticating with keys from the custom database, thereby bypassing the need for updating the BIOS firmware and accommodating customer-specific key management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are included in the BIOS Secure Boot database to enable manufacturer feature enhancements, then code integrity verification is improved, but the system becomes restricted when customers require their own custom key databases

Engineering Contradiction:
Improvecode integrity verificationVSAvoidcustom key database compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the Secure Boot key management into two separate databases: the traditional BIOS Secure Boot database and a new custom Secure Boot database stored on a removable storage device. This segmentation allows manufacturer keys and customer keys to coexist independently, resolving the conflict between maintaining code integrity verification and supporting custom key databases.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a custom database file as an intermediary between the BIOS and customer key management requirements. This intermediary layer allows the BIOS to verify code integrity using manufacturer keys while simultaneously enabling customers to provide their own keys without modifying the BIOS firmware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the Secure Boot database is updated to include custom customer keys, then customer customization options are improved, but Bitlocker recovery functionality is restricted or lost

Engineering Contradiction:
Improvecustomer customization optionsVSAvoidBitlocker recovery
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent separates customer custom keys into a distinct custom database file on removable storage, isolating them from the BIOS Secure Boot database that contains manufacturer keys required for Bitlocker recovery. This segmentation allows customers to customize their key database without affecting the integrity verification needed for Bitlocker functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The custom database file acts as an intermediary that provides customer customization capabilities while preserving the original BIOS Secure Boot database intact, thereby maintaining Bitlocker recovery functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If BIOS firmware is updated to support custom Secure Boot databases, then feature enhancements are enabled, but the complexity of deployment and key management increases

Engineering Contradiction:
ImproveSecure Boot customizationVSAvoidkey management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent uses a custom database file on removable storage as an intermediary layer that adds customization capabilities without requiring BIOS firmware updates. This approach enables Secure Boot customization while keeping the BIOS firmware simple and avoiding the complexity of firmware update deployment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11989300B2Firmware secure boot customization extensions
Publication Date: 2024.05.21 DELL PROD LP
  • US11989300B2 patent drawing
  • US11989300B2 patent drawing
  • US11989300B2 patent drawing

AI summary

An information handling system may include memory circuitry comprising a BIOS and a database including a first set of one or more cryptographic keys usable to authenticate code executable by the BIOS; and a physical storage medium other than the memory circuitry, wherein the physical storage medium includes a custom database including a second set of one or more cryptographic keys usable to authenticate code executable by the BIOS. The information handling system is configured to load a BIOS extension into the BIOS by: determining that the first set of one or more cryptographic keys does not include any key usable to authenticate the BIOS extension; determining that the second set of one or more cryptographic keys includes a particular key usable to authenticate the BIOS extension; authenticating the BIOS extension via the particular key; and in response to the authenticating, loading and executing the BIOS extension.