BIOS Activation via Reserved SMI API for Offline OS Upgrades
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in activating new or upgraded operating systems on field-deployed computers without internet connectivity, as the onboard BIOS only includes the original factory-installed OEM activation string, limiting the ability to upgrade from one OS version to another without manual intervention and potential piracy risks.
Innovation Solution
Implementing a replacement BIOS code with a reserved System Management Interface (SMI) API function that allows for the installation of an updated OEM activation string in non-volatile memory, enabling the SLIC table to be unlocked, enabled, and locked without internet communication, using a private security key to secure the process and prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the onboard BIOS only includes the original factory-installed OEM activation string, then the system maintains security and prevents piracy, but the ability to upgrade OS versions is limited and requires manual intervention
Solution Approach 1:
The patent applies preliminary action by pre-configuring the BIOS with a reserved SMI API function and private security key during manufacturing, but keeping the SLIC table locked and disabled until activation is needed. This allows the system to be ready for OS upgrades without actually enabling the upgrade capability until the proper activation string is provided, thus maintaining security while enabling future upgrades.
Solution Approach 2:
The patent introduces an intermediary mechanism - the reserved SMI API function - that acts as a mediator between the BIOS and the activation process. This API function, accessible only through the private security key, enables the BIOS to unlock and enable the SLIC table for receiving new OEM activation strings, facilitating OS upgrades without requiring changes to the core BIOS structure.
2Reliability
If the SLIC table is locked and disabled after OEM manufacturing, then piracy is prevented, but OS activation cannot be performed without internet communication
Solution Approach 1:
The patent applies self-service by enabling the BIOS to perform activation functions autonomously through the reserved SMI API. Once the private security key is provided, the BIOS can automatically unlock the SLIC table, receive and process new OEM activation strings, and lock the table again without requiring external internet communication or manual intervention, thus maintaining security while simplifying the activation process.
3Adaptability or versatility
If a reserved SMI API function is provided in replacement BIOS code, then OS activation can be facilitated without internet connectivity, but the system requires additional BIOS components and update procedures
Solution Approach 1:
The patent applies universality by designing the reserved SMI API function to serve multiple purposes: it can be used to unlock the SLIC table, enable/disable the SLIC table, and process different types of OEM activation strings. This multi-functional API reduces the need for separate dedicated functions for each activation task, thereby limiting the increase in BIOS complexity while maintaining high adaptability.
4Adaptability or versatility
If the SLIC table is unlocked and enabled for activation, then new OEM activation strings can be installed, but the system becomes vulnerable to unauthorized access and piracy
Solution Approach 1:
The patent applies preliminary anti-action by pre-establishing the private security key and reserved SMI API function in the BIOS during manufacturing, but keeping the SLIC table locked and disabled by default. The activation capability is only enabled when the correct private security key is provided through a controlled process, preventing unauthorized access before it can occur. The table is locked again immediately after activation to maintain security.
Data Source
AI summary
Systems and methods are disclosed that may be implemented to install and use a replacement BIOS code stored in non-volatile memory of the system BIOS to facilitate activation of a new or replacement OS on an information handling system. The replacement BIOS code may include an activation certificate of authority information to activate a different version operating system for use on an information handling system that has been previously configured with a different operating system version along with a previous BIOS code that did not include the updated OEM activation string.


