Boot Firmware Physical Presence Verification Token
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for verifying user physical presence in information handling systems are insecure, as they can be spoofed by remote attacks, and do not establish a persistent trust relationship between firmware and software components.
Innovation Solution
The system verifies user physical presence during the pre-boot phase of the boot firmware, generating a physical presence bind token that establishes a unique trust relationship between the boot firmware and applications, using user input such as key presses, touch screen interactions, or challenge strings to ensure secure verification and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OS-based verification methods are used to confirm user physical presence, then ease of operation is improved, but security is worsened because these methods can be spoofed by exploiting OS and AD vulnerabilities
Solution Approach 1:
The patent introduces a hardware-based intermediary (trusted platform module or secure enclave) that mediates between the OS and the verification process. This intermediary provides a secure hardware root of trust that cannot be spoofed, while still allowing the OS to perform user verification. The hardware component acts as a mediator that validates user presence through secure channels independent of OS vulnerabilities.
Solution Approach 2:
The patent replaces the software-based mechanical verification system (OS keyboard hooks and driver parsing) with a hardware-based verification system. Instead of relying on OS-level input handling that can be exploited, the system uses hardware-level detection of physical user presence, substituting the vulnerable software mechanism with a more secure hardware mechanism.
2Reliability
If hardware-based physical presence verification is implemented, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent leverages existing multi-functional hardware components (TPM or secure enclave) that already serve multiple security and system functions. By utilizing these existing universal components for physical presence verification, the patent avoids adding dedicated new hardware solely for this purpose, thereby minimizing the increase in device complexity while still achieving hardware-based security.
3Reliability
If persistent trust relationship is established between firmware and applications, then reliability is improved, but device complexity is worsened due to token management
Solution Approach 1:
The patent implements a self-service mechanism where the hardware security component automatically manages the persistent trust relationship and generates verification tokens as needed. The system does not require complex external token management infrastructure; instead, the hardware component autonomously handles token generation, validation, and persistence, reducing the overall system complexity while maintaining reliable trust verification.
Data Source
AI summary
The present disclosure provides an information handling system (IHS) and related methods that use physical presence verification to establish unique trust relationships between boot firmware and one or more individual applications provided within an IHS. The IHS and methods disclosed herein provide secure verification of user physical presence by verifying the physical presence of a user during a pre-boot phase of the boot firmware (i.e., before an operating system (OS) is loaded and running). After user physical presence is verified during the pre-boot phase, the IHS and methods disclosed herein generate a physical presence (PP) bind token during OS runtime that may be used to establish a unique trust relationship between the boot firmware and one or more individual applications provided within the IHS.


