Firmware-Based Device Authentication and Boot Refusal

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer provisioning methods fail to effectively prevent unauthorized use and secure data protection in case of loss or theft, as security measures can be overcome with sufficient time and effort, even with hard disk encryption.

Innovation Solution

Customizing the firmware of computer devices to use automated network-based provisioning procedures, including cryptographic authentication, and configuring them to periodically authenticate with a central service authority for continued operation, implementing security measures such as boot refusal or data erasure upon failure to authenticate.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hard disk encryption is implemented to protect data, then data security is improved, but the system can still be defeated if an attacker has physical possession and enough time to break the encryption

Engineering Contradiction:
Improvedata securityVSAvoidphysical possession vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication actions before allowing any operation. The computer must authenticate to the provisioning service at boot time and before each operation, ensuring that even if an attacker has physical possession, they cannot access the system without proper authentication credentials.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The provisioning service acts as an intermediary between the computer and all operations. Instead of relying solely on local hard disk encryption, the system introduces a remote authentication intermediary that must be contacted for each operation, making physical possession insufficient for unauthorized access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If standardized provisioning configurations are applied to all computers, then deployment efficiency is improved, but security customization and adaptability are reduced

Engineering Contradiction:
Improvedeployment efficiencyVSAvoidsecurity customization
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The system segments the provisioning process into a standardized initial configuration phase and a customized operational phase. During initial provisioning, standardized configurations are applied for efficient deployment. During operation, the system segments access control by requiring individual authentication for each operation, allowing customized security measures without compromising deployment efficiency.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8745730B1Secure computer provisioning and operation
Publication Date: 2014.06.03 AMAZON TECH INC
  • US8745730B1 patent drawing
  • US8745730B1 patent drawing
  • US8745730B1 patent drawing

AI summary

A networked computer device can be customized to contain provisioning and/or authorization logic in its firmware or the firmware of one of its subcomponents. The computer device is thus configured to provision itself from a provisioning server that is identified within the firmware, and to periodically query an operations authority for continued authorization to operate with the received provisioning. Upon failure to receive authorization, the firmware may implement various security measures, such as storage protection, boot protection, communications protection, and so forth. The firmware may also implement remote reporting, to assist an investigator when a device has been lost or stolen.