Flexible Computing Client for Preboot Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems face challenges in providing efficient and secure user authentication, especially with resource-intensive operating systems that take long to boot and present security exposures, and require configurations that vary based on user parameters and network conditions.
Innovation Solution
A flexible computing client is implemented for preboot authentication, embedded in non-volatile memory, using a trusted computing module and processor memory protection mechanisms, allowing instant-on user experience and secure boot processes, and can operate in various configurations based on user, device, and network conditions, including virtual machine environments and remote desktop protocols.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a resource-intensive operating system is booted to provide multiple computing roles, then the system can handle diverse computing tasks, but the boot time increases significantly and security exposures occur
Solution Approach 1:
The patent segments the computing system into multiple distinct operating systems (service OS, application OS, local OS) that can be independently loaded and executed. This allows the system to boot only the necessary OS for the current computing role rather than loading a resource-intensive general-purpose OS, thereby reducing boot time while maintaining versatility.
Solution Approach 2:
The patent implements preliminary authentication and OS selection before the main computing workload begins. The service OS performs user authentication and determines the appropriate application OS to load based on user credentials and computing requirements, allowing the system to prepare and boot only the necessary components in advance, reducing overall boot time.
2Adaptability or versatility
If a resource-intensive operating system is booted to provide multiple computing roles, then the system can handle diverse computing tasks, but security exposures increase
Solution Approach 1:
The patent segments the system into isolated operating system environments (service OS, application OS, local OS) with distinct security contexts. Each OS runs in its own protected memory space, preventing security vulnerabilities in one OS from affecting others. This segmentation maintains computing versatility while improving security through isolation.
Solution Approach 2:
The service OS acts as an intermediary between the user and the application OS, performing authentication and authorization before allowing access to computing resources. This intermediary layer enforces security policies and controls which application OS is loaded based on user credentials, thereby improving security while maintaining system versatility.
3Ease of operation
If traditional personal computer clients are used, then local storage and processing are available, but the system cannot easily adapt to different computing roles and network conditions
Solution Approach 1:
The patent implements a universal computing platform that can function as multiple types of clients (diskless client, remote desktop client, KVMoIP client, etc.) by loading different application OS images over the network. The service OS manages this universality by selecting and loading the appropriate application OS based on user credentials and computing requirements, allowing a single hardware platform to perform multiple client functions while maintaining local processing capability through the embedded service OS.
4Adaptability or versatility
If diskless clients, remote desktop clients, or KVMoIP clients are used, then computing resource flexibility is improved, but local processing capability and storage are reduced
Solution Approach 1:
The patent segments the computing functions into network-based services (provided by remote servers for diskless, remote desktop, and KVMoIP clients) and local embedded services (provided by the service OS). This segmentation allows the system to leverage network resources for storage and application execution while maintaining local processing capability for authentication, session management, and protocol handling, thereby achieving client flexibility without completely sacrificing local processing capability.
Data Source
AI summary
Methods and systems for providing embedded user authentication and/or providing computing services using an information handling system configured as flexible computing node, and which may be implemented to perform preboot authentication of users. The flexible computing node may also be configured to provision the appropriate work environment for a given user based on one or more user parameters (e.g. entitlements, location, network connection, and/or other parameters).


