Pre-boot BIOS SSO Token Provisioning for Cross-OS Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In information handling systems, users often need to re-authenticate when accessing additional network resources after being single-signed onto the Windows OS from pre-boot authentication, leading to inefficiencies and potential security risks due to repetitive authentication events and the need for intermediary credentials.

Innovation Solution

Implementing single sign-on (SSO) authentication in the pre-boot BIOS environment, which securely provisions authentication tokens to the post-boot OS, eliminating the need for re-authentication and intermediary credentials by using Kerberos tickets obtained from a Kerberos server during the boot process, and leveraging generic APIs for communication between OS authentication services and lower-level modules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If pre-boot authentication is implemented to authenticate users before OS booting, then user access efficiency is improved, but the system requires complex authentication token provisioning mechanisms between pre-boot and post-boot environments

Engineering Contradiction:
Improveuser access efficiencyVSAvoidauthentication token provisioning mechanism
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary mechanism that captures authentication tokens during pre-boot authentication and automatically provisions them to the post-boot OS environment. This intermediary layer eliminates the need for manual credential transfer while maintaining seamless authentication continuity across the boot process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs authentication actions in advance during the pre-boot environment before the OS fully loads. By completing authentication token acquisition and provisioning before the OS booting process, the system eliminates re-authentication requirements and improves user access efficiency.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If conventional pre-boot authentication is used, then user authentication is performed in BIOS, but users must re-authenticate when accessing network resources after OS booting

Engineering Contradiction:
Improvepre-boot authenticationVSAvoidre-authentication time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent ensures authentication continuity by capturing authentication tokens during pre-boot authentication and automatically provisioning them to the post-boot OS environment. This continuous authentication state eliminates the need for re-authentication when accessing network resources, maintaining seamless access from pre-boot through post-boot environments.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The patent implements a feedback mechanism where the pre-boot authentication system provides authentication tokens back to the post-boot OS through standardized interfaces. This feedback loop ensures that authentication state is maintained and shared between different boot environments, eliminating redundant authentication steps.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If intermediary credentials are used for authentication between pre-boot and post-boot environments, then authentication can be bridged, but security is reduced due to potential replay attacks

Engineering Contradiction:
Improveauthentication bridging capabilityVSAvoidsecurity against replay attacks
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent changes the authentication parameter from intermediary credentials to direct Kerberos ticket-granting tickets (TGTs). By obtaining TGTs directly from the Kerberos server during pre-boot authentication and provisioning them to the OS, the system eliminates the security vulnerabilities associated with intermediary credentials while maintaining authentication bridging capability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent uses disposable, single-use authentication tokens obtained during pre-boot authentication. These tokens are obtained directly from the Kerberos server and provisioned to the OS without creating persistent intermediary credential stores, thereby reducing security risks while enabling authentication bridging.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Reliability

If multiple authentication events occur during boot process, then comprehensive authentication is achieved, but network traffic increases and performance is impacted

Engineering Contradiction:
Improveauthentication completenessVSAvoidnetwork traffic and processing energy
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent performs all necessary authentication actions during the pre-boot environment before the OS fully loads and before network connections are established. By completing authentication token acquisition and provisioning in advance, the system eliminates subsequent authentication events that would generate additional network traffic and processing overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent rushes through the authentication process during pre-boot by obtaining Kerberos TGTs directly from the Kerberos server without requiring subsequent re-authentication events. This streamlined approach skips redundant authentication steps that would otherwise occur during post-boot operation, reducing network traffic and processing energy consumption.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS11347859B2Systems and methods for leveraging authentication for cross operating system single sign on (SSO) capabilities
Publication Date: 2022.05.31 DELL PROD LP
  • US11347859B2 patent drawing
  • US11347859B2 patent drawing
  • US11347859B2 patent drawing

AI summary

Systems and methods are provided that may be implemented during a pre-boot environment to authenticate a user in the basic input/output system (BIOS) of an information handling system, and to securely provision a resulting authentication token to post-boot operating system (OS) login components of the system. In addition, single sign-on user authentication may be performed during a pre-boot BIOS environment and then extended to the post-boot OS environment without requiring exchange of pins or other intermediary authentication factors between the OS and pre-boot authentication (PBA) for the user to gain access to the information handling system or other network resources.