Boot Firmware Physical Presence Verification Token

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying user physical presence in information handling systems are insecure, as they can be spoofed by remote attacks, and do not establish a persistent trust relationship between firmware and software components.

Innovation Solution

The system verifies user physical presence during the pre-boot phase of the boot firmware, generating a physical presence bind token that establishes a unique trust relationship between the boot firmware and applications, using user input such as key presses, touch screen interactions, or challenge strings to ensure secure verification and authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OS-based verification methods are used to confirm user physical presence, then ease of operation is improved, but security is worsened because these methods can be spoofed by exploiting OS and AD vulnerabilities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a hardware-based intermediary (trusted platform module or secure enclave) that mediates between the OS and the verification process. This intermediary provides a secure hardware root of trust that cannot be spoofed, while still allowing the OS to perform user verification. The hardware component acts as a mediator that validates user presence through secure channels independent of OS vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the software-based mechanical verification system (OS keyboard hooks and driver parsing) with a hardware-based verification system. Instead of relying on OS-level input handling that can be exploited, the system uses hardware-level detection of physical user presence, substituting the vulnerable software mechanism with a more secure hardware mechanism.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If hardware-based physical presence verification is implemented, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages existing multi-functional hardware components (TPM or secure enclave) that already serve multiple security and system functions. By utilizing these existing universal components for physical presence verification, the patent avoids adding dedicated new hardware solely for this purpose, thereby minimizing the increase in device complexity while still achieving hardware-based security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If persistent trust relationship is established between firmware and applications, then reliability is improved, but device complexity is worsened due to token management

Engineering Contradiction:
ImprovereliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a self-service mechanism where the hardware security component automatically manages the persistent trust relationship and generates verification tokens as needed. The system does not require complex external token management infrastructure; instead, the hardware component autonomously handles token generation, validation, and persistence, reducing the overall system complexity while maintaining reliable trust verification.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10853086B2Information handling systems and related methods for establishing trust between boot firmware and applications based on user physical presence verification
Publication Date: 2020.12.01 DELL PROD LP
  • US10853086B2 patent drawing
  • US10853086B2 patent drawing
  • US10853086B2 patent drawing

AI summary

The present disclosure provides an information handling system (IHS) and related methods that use physical presence verification to establish unique trust relationships between boot firmware and one or more individual applications provided within an IHS. The IHS and methods disclosed herein provide secure verification of user physical presence by verifying the physical presence of a user during a pre-boot phase of the boot firmware (i.e., before an operating system (OS) is loaded and running). After user physical presence is verified during the pre-boot phase, the IHS and methods disclosed herein generate a physical presence (PP) bind token during OS runtime that may be used to establish a unique trust relationship between the boot firmware and one or more individual applications provided within the IHS.