BIOS Update Security Enforcement via OS Evaluation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The security of BIOS updates in information handling systems is compromised due to misconfigurations and vulnerabilities, which can lead to attacks and malware infections, especially when users disable security controls or attempt updates with outdated BIOS versions.

Innovation Solution

A method and system that evaluate BIOS configuration security controls, enforce a secure update policy by configuring security settings, and trigger a warm reboot to ensure a secure BIOS update process, applying a secure profile to the BIOS configuration during boot sessions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If BIOS security controls are enabled to protect against attacks, then system security is improved, but users cannot customize operating systems and BIOS updates may fail

Engineering Contradiction:
ImproveBIOS securityVSAvoidOS customization
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary evaluation of BIOS security controls before allowing updates. The operating system assesses whether security settings meet minimum thresholds beforehand, and if not, automatically configures appropriate security settings before the BIOS update process begins, ensuring security is maintained while enabling necessary customizations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The BIOS security configuration is made dynamic rather than static. The system can adjust security settings based on the update context - maintaining high security during normal operation but temporarily modifying settings to allow legitimate updates when evaluated as safe, then restoring security controls after the update completes.

Inventive Principle:
Principle #15Dynamics

2Ease of operation

If users disable BIOS security controls to customize operating systems, then ease of operation is improved, but system security is compromised and malware attacks become possible

Engineering Contradiction:
ImproveBIOS configuration flexibilityVSAvoidBIOS security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The operating system continuously monitors BIOS configuration state and provides feedback about security compliance. When security controls are weakened for customization, the system evaluates the new state and can trigger warnings or automatic remediation if security thresholds are breached, creating a closed-loop control system that balances flexibility and security.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system preemptively counteracts potential security threats by evaluating BIOS configurations before allowing updates that might compromise security. If a configuration change would create vulnerabilities, the system prevents the change or automatically restores secure settings before the update can be applied, countering potential attacks in advance.

Inventive Principle:
Principle #9Preliminary anti-action

3Adaptability or versatility

If BIOS updates are performed on systems with outdated BIOS versions, then BIOS functionality is improved, but security vulnerabilities may be exploited during the update process

Engineering Contradiction:
ImproveBIOS update capabilityVSAvoidmalware exploitation risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

Before initiating a BIOS update from an outdated version, the operating system performs a preliminary security evaluation of the current BIOS state. It checks for known vulnerabilities and assesses whether the update process can proceed safely. If security thresholds are not met, the update is blocked or security controls are automatically configured to mitigate risks before the update begins.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The operating system acts as an intermediary layer between the vulnerable outdated BIOS and the update process. It mediates the update by evaluating security conditions, controlling the update execution environment, and preventing direct exploitation of BIOS vulnerabilities during the update process, thereby protecting the system even when updating from insecure states.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12093393B2Systems and methods for safeguarding updates to a basic input/output system of an information handling system
Publication Date: 2024.09.17 DELL PROD LP
  • US12093393B2 patent drawing
  • US12093393B2 patent drawing
  • US12093393B2 patent drawing

AI summary

A method may include, in an operating system executing on an information handling system, obtaining information regarding basic input/output system (BIOS) configuration security controls, evaluating the BIOS configuration security controls to determine if the BIOS configuration security controls satisfy a standard for performing a BIOS-managed BIOS firmware update, and if the BIOS configuration security controls fail to satisfy the standard for performing the BIOS-managed BIOS firmware update, configuring the BIOS configuration security controls to enforce a secure BIOS update policy on a subsequent boot of the information handling system and triggering a warm reboot of the information handling system.