Boot Device Password Protection via BIOS Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional data processing systems are vulnerable to unauthorized booting due to emerging peripheral connection technologies like USB 2.0, which allows high-data-rate devices to be connected externally, making it easy for unauthorized users to access PCs by swapping devices, thus bypassing existing security mechanisms.

Innovation Solution

Implementing a password protection system that requires boot devices to provide a unique combination of manufacturer-supplied model and serial numbers as a password, which is stored and verified by the BIOS configuration routine before allowing the system to boot, thereby ensuring only trusted devices can initiate the boot process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If USB 2.0 high-data-rate devices are allowed to be connected externally, then device versatility and data transfer capability are improved, but system security against unauthorized booting deteriorates

Engineering Contradiction:
Improvedevice compatibilityVSAvoidboot security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The BIOS configuration routine performs preliminary verification of the boot device's password (model and serial number combination) before allowing the system to boot. This advance checking prevents unauthorized devices from booting the system, thereby maintaining security while allowing USB 2.0 device connectivity.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If password protection is implemented for boot devices, then boot security is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveboot securityVSAvoidboot process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The boot device itself provides the password information (model and serial number) automatically when queried by the BIOS configuration routine. The user does not need to manually enter a password or configure security settings, as the device self-identifies through its unique manufacturer-supplied identifiers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS7814532B2Data processing system and method for password protecting a boot device
Publication Date: 2010.10.12 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US7814532B2 patent drawing
  • US7814532B2 patent drawing
  • US7814532B2 patent drawing

AI summary

A data processing system and method of password protecting the boot of a data processing system are disclosed. According to the method, in response to an attempt to boot the data processing system utilizing a boot device, the boot device is interrogated for a password. If the boot device supplies password information corresponding to that of a trusted boot device, the data processing system boots utilizing the boot device. If, however, the boot device does not supply password information corresponding to that of a trusted boot device, booting from the boot device is inhibited. In a preferred embodiment, the password information comprises a unique combination of the boot device's manufacturer-supplied model and serial numbers.