Distributed BIOS Zero-Trust Access for Shared Resource Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing firmware management systems face challenges in ensuring secure and continuous authentication and authorization in shared resource environments, particularly in multi-processor systems, where vulnerabilities can lead to unauthorized access and security breaches due to inadequate protection mechanisms.

Innovation Solution

Implementing a distributed Basic Input Output System (BIOS) with a trusted enclave and a secured firmware zero trust protocol (SFZP) that uses Secure Production Identity Framework for Everyone (SPIFFE) and SPIFFE Verifiable Identity Document (SVID) format for dynamic security measures, providing a 3-factor authentication and authorization framework.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firmware management systems are used in shared resource environments, then system complexity is reduced, but security reliability deteriorates due to inadequate protection mechanisms and vulnerability to unauthorized access

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the firmware management system into multiple components: a distributed BIOS layer, a trusted execution environment (TEE), and application layers. Each layer has specific security responsibilities, with the TEE isolating critical security functions from the rest of the system. This segmentation allows complex security operations to be distributed across multiple modules rather than centralized, improving reliability while managing complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment (TEE) as an intermediary layer between the firmware and applications. The TEE acts as a mediator that handles sensitive operations such as key management, cryptographic operations, and secure boot verification. This intermediary protects the core security functions from direct access by applications while maintaining controlled interfaces, thereby improving security reliability without requiring all system components to be equally complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If zero trust access control is implemented, then security protection is improved, but authentication time increases due to continuous verification requirements

Engineering Contradiction:
Improvesecurity protectionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary authentication actions during system initialization, including secure boot verification, firmware integrity checks, and establishment of trusted execution environments before applications run. These preliminary actions ensure that the foundation of trust is established beforehand, allowing subsequent access decisions to be faster since the trust relationship has already been validated. The continuous verification requirement is partially satisfied in advance rather than continuously during operation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses cryptographic copies and hashes of firmware images and security credentials to verify integrity without requiring full re-verification of original sources. Instead of continuously accessing and verifying original firmware binaries, the system uses cryptographic copies (hashes, digital signatures) that can be rapidly checked. This copying mechanism maintains zero-trust verification while significantly reducing authentication time for subsequent access decisions.

Inventive Principle:
Principle #26Copying

3Reliability

If distributed BIOS with trusted enclave is deployed, then security measures are enhanced, but device complexity increases due to additional security layers

Engineering Contradiction:
Improvesecurity measuresVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a nested architecture where the trusted execution environment is embedded within the distributed BIOS structure, which itself runs on top of the hardware platform. The TEE is nested within the BIOS firmware, creating concentric layers of security where each layer protects the inner layers. This nesting allows complex security functionality to be contained within specific nested modules rather than distributed throughout the entire system, making the complexity manageable through hierarchical organization.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The distributed BIOS is designed with multi-functionality, serving both traditional system initialization roles and advanced security functions including trusted execution environment management, secure boot, and firmware updates. By making the BIOS universal and multi-functional, the patent avoids adding separate dedicated security hardware or firmware components, thereby enhancing security measures while limiting the increase in overall device complexity through consolidation of functions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20260023610A1Zero Trust Protocol for Attestation and Authorization of Applications and Shared Resources
Publication Date: 2026.01.22 DELL PROD LP
  • US20260023610A1 patent drawing
  • US20260023610A1 patent drawing
  • US20260023610A1 patent drawing

AI summary

A firmware management operation. The firmware management operation includes providing an information handling system with a distributed Basic Input Output System (BIOS) and a shared resource; identifying a processor environment installed on an information handling system from a plurality of processor environments, the processor environment comprising a processor architecture, the processor architecture comprising a plurality of processor core types; and, performing a shared resource trust operation via the distributed BIOS, the shared resource trust operation using shared resource trust information to provide security measures which enable zero trust access by an application to the shared resource of the information handling system.