Forced Registration Unit for BIOS Authentication Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Most computer users do not register BIOS passwords, leaving their devices vulnerable to unauthorized use, as the registration process relies on individual user initiative rather than enforced policies.

Innovation Solution

An information processing apparatus with a forced-registration unit that requires users to register new authentication information upon power-on, inhibiting device operation until the information is entered, and a system environment setting unit that allows supervisors to enforce this policy, ensuring authentication information is securely stored and not deleted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a BIOS password function is provided to prevent unauthorized use, then security against theft is improved, but user cooperation for password registration deteriorates because the registration process becomes mandatory and complex

Engineering Contradiction:
Improvesecurity against unauthorized useVSAvoiduser cooperation for password registration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system performs preliminary actions by automatically detecting whether authentication information is registered in advance, and prepares the forced-registration process beforehand. The system checks the registration status during power-on and automatically initiates the appropriate authentication or registration flow without requiring user judgment, thus improving ease of operation while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing users to automatically complete password registration through a guided interface during the forced-registration process. Users can register their own passwords without administrator intervention by following on-screen instructions, which improves ease of operation while ensuring security requirements are met.

Inventive Principle:
Principle #25Self-service

2Reliability

If forced-registration is implemented to ensure all users register passwords, then security reliability is improved, but device complexity increases due to additional control mechanisms

Engineering Contradiction:
Improveauthentication coverageVSAvoidauthentication control mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic control by adjusting the authentication flow based on real-time detection of registration status. The forced-registration function is activated only when authentication information is not registered, and deactivated once registration is complete. This dynamic adaptation ensures authentication coverage without permanently increasing system complexity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system uses feedback mechanisms to monitor whether authentication information is registered and automatically adjusts the power-on behavior accordingly. When no authentication is detected, the system feedbacks a forced-registration requirement; when authentication is detected, normal operation resumes. This feedback loop ensures reliable authentication coverage through simple conditional logic rather than complex continuous control.

Inventive Principle:
Principle #23Feedback

3Reliability

If the main body is inhibited from operating until authentication information is registered, then security against unauthorized use is improved, but productivity deteriorates due to operational delays

Engineering Contradiction:
Improveprotection against unauthorized useVSAvoidsystem boot-up speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies skipping by rapidly guiding users through the password registration process during forced-registration. The interface presents essential steps concisely and allows users to complete registration quickly without lengthy procedures. Once registered, the system immediately transitions to normal operation, minimizing the inhibition period and reducing impact on productivity.

Inventive Principle:
Principle #21Skipping (Rushing through)

Solution Approach 2:

The system performs preliminary detection of authentication status during power-on before full operation begins. By detecting whether registration is needed in advance and preparing the appropriate flow, the system avoids unnecessary delays. Users are only inhibited long enough to complete registration if truly needed, rather than undergoing repeated authentication checks that would slow down boot-up.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8387134B2Information processing apparatus and method of controlling authentication process
Publication Date: 2013.02.26 DYNABOOK INC
  • US8387134B2 patent drawing
  • US8387134B2 patent drawing
  • US8387134B2 patent drawing

AI summary

According to one embodiment, an information processing apparatus includes a main body, an authentication unit which performs an authentication process, upon power-on of the main body, if authentication information is registered in the main body, the authentication process including a process to authenticate a user based on authentication information input by the user and the authentication information registered in the main body, and a forced-registration unit which performs a forced-registration process to request the user to register new authentication information and inhibit the main body from operating until the new authentication information is registered, upon power-on of the main body.