Pre-boot BIOS SSO Token Provisioning for Cross-OS Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In information handling systems, users often need to re-authenticate when accessing additional network resources after being single-signed onto the Windows OS from pre-boot authentication, leading to inefficiencies and potential security risks due to repetitive authentication events and the need for intermediary credentials.
Innovation Solution
Implementing single sign-on (SSO) authentication in the pre-boot BIOS environment, which securely provisions authentication tokens to the post-boot OS, eliminating the need for re-authentication and intermediary credentials by using Kerberos tickets obtained from a Kerberos server during the boot process, and leveraging generic APIs for communication between OS authentication services and lower-level modules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If pre-boot authentication is implemented to authenticate users before OS booting, then user access efficiency is improved, but the system requires complex authentication token provisioning mechanisms between pre-boot and post-boot environments
Solution Approach 1:
The patent introduces an intermediary mechanism that captures authentication tokens during pre-boot authentication and automatically provisions them to the post-boot OS environment. This intermediary layer eliminates the need for manual credential transfer while maintaining seamless authentication continuity across the boot process.
Solution Approach 2:
The patent performs authentication actions in advance during the pre-boot environment before the OS fully loads. By completing authentication token acquisition and provisioning before the OS booting process, the system eliminates re-authentication requirements and improves user access efficiency.
2Ease of operation
If conventional pre-boot authentication is used, then user authentication is performed in BIOS, but users must re-authenticate when accessing network resources after OS booting
Solution Approach 1:
The patent ensures authentication continuity by capturing authentication tokens during pre-boot authentication and automatically provisioning them to the post-boot OS environment. This continuous authentication state eliminates the need for re-authentication when accessing network resources, maintaining seamless access from pre-boot through post-boot environments.
Solution Approach 2:
The patent implements a feedback mechanism where the pre-boot authentication system provides authentication tokens back to the post-boot OS through standardized interfaces. This feedback loop ensures that authentication state is maintained and shared between different boot environments, eliminating redundant authentication steps.
3Adaptability or versatility
If intermediary credentials are used for authentication between pre-boot and post-boot environments, then authentication can be bridged, but security is reduced due to potential replay attacks
Solution Approach 1:
The patent changes the authentication parameter from intermediary credentials to direct Kerberos ticket-granting tickets (TGTs). By obtaining TGTs directly from the Kerberos server during pre-boot authentication and provisioning them to the OS, the system eliminates the security vulnerabilities associated with intermediary credentials while maintaining authentication bridging capability.
Solution Approach 2:
The patent uses disposable, single-use authentication tokens obtained during pre-boot authentication. These tokens are obtained directly from the Kerberos server and provisioned to the OS without creating persistent intermediary credential stores, thereby reducing security risks while enabling authentication bridging.
4Reliability
If multiple authentication events occur during boot process, then comprehensive authentication is achieved, but network traffic increases and performance is impacted
Solution Approach 1:
The patent performs all necessary authentication actions during the pre-boot environment before the OS fully loads and before network connections are established. By completing authentication token acquisition and provisioning in advance, the system eliminates subsequent authentication events that would generate additional network traffic and processing overhead.
Solution Approach 2:
The patent rushes through the authentication process during pre-boot by obtaining Kerberos TGTs directly from the Kerberos server without requiring subsequent re-authentication events. This streamlined approach skips redundant authentication steps that would otherwise occur during post-boot operation, reducing network traffic and processing energy consumption.
Data Source
AI summary
Systems and methods are provided that may be implemented during a pre-boot environment to authenticate a user in the basic input/output system (BIOS) of an information handling system, and to securely provision a resulting authentication token to post-boot operating system (OS) login components of the system. In addition, single sign-on user authentication may be performed during a pre-boot BIOS environment and then extended to the post-boot OS environment without requiring exchange of pins or other intermediary authentication factors between the OS and pre-boot authentication (PBA) for the user to gain access to the information handling system or other network resources.


