Boot Device Password Protection via BIOS Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional data processing systems are vulnerable to unauthorized booting due to emerging peripheral connection technologies like USB 2.0, which allows high-data-rate devices to be connected externally, making it easy for unauthorized users to access PCs by swapping devices, thus bypassing existing security mechanisms.
Innovation Solution
Implementing a password protection system that requires boot devices to provide a unique combination of manufacturer-supplied model and serial numbers as a password, which is stored and verified by the BIOS configuration routine before allowing the system to boot, thereby ensuring only trusted devices can initiate the boot process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If USB 2.0 high-data-rate devices are allowed to be connected externally, then device versatility and data transfer capability are improved, but system security against unauthorized booting deteriorates
Solution Approach 1:
The BIOS configuration routine performs preliminary verification of the boot device's password (model and serial number combination) before allowing the system to boot. This advance checking prevents unauthorized devices from booting the system, thereby maintaining security while allowing USB 2.0 device connectivity.
2Reliability
If password protection is implemented for boot devices, then boot security is improved, but ease of operation deteriorates
Solution Approach 1:
The boot device itself provides the password information (model and serial number) automatically when queried by the BIOS configuration routine. The user does not need to manually enter a password or configure security settings, as the device self-identifies through its unique manufacturer-supplied identifiers.
Data Source
AI summary
A data processing system and method of password protecting the boot of a data processing system are disclosed. According to the method, in response to an attempt to boot the data processing system utilizing a boot device, the boot device is interrogated for a password. If the boot device supplies password information corresponding to that of a trusted boot device, the data processing system boots utilizing the boot device. If, however, the boot device does not supply password information corresponding to that of a trusted boot device, booting from the boot device is inhibited. In a preferred embodiment, the password information comprises a unique combination of the boot device's manufacturer-supplied model and serial numbers.


