Field Replaceable Unit Authentication via Boot Metrics

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hardware authentication systems for information handling systems are vulnerable to unauthorized devices due to compromised authentication servers and software, which fail to effectively detect and isolate spurious hardware.

Innovation Solution

An information handling system incorporating a trusted platform module and platform management controller that generates and verifies boot metric data to authenticate the network operating system engine, providing a secure authentication mechanism within the system without relying on external servers or dongles.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If traditional network-based authentication servers and software are used, then authentication can be performed over the network, but the system becomes vulnerable to compromised authentication servers allowing unauthorized devices

Engineering Contradiction:
Improveauthentication capabilityVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the authentication functionality from external network-based authentication servers and relocates it into the information handling system itself through a trusted platform module. This removes the vulnerability of relying on external servers that could be compromised, while preserving the authentication capability within the system boundaries.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The trusted platform module acts as an intermediary between the hardware components and the authentication process. It generates and stores boot metric data that serves as a cryptographic proof of system integrity, mediating the authentication verification without requiring external authentication servers.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If hardware authentication is performed using external authentication servers, then network-based authentication is enabled, but unauthorized devices cannot be effectively detected and isolated

Engineering Contradiction:
Improveauthentication flexibilityVSAvoidunauthorized device detection
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The system performs preliminary authentication verification during the boot process by measuring and storing boot metric data in the trusted platform module before the operating system fully loads. This preliminary action enables early detection of unauthorized hardware modifications, allowing the system to prevent booting or isolate compromised devices before they can cause harm.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If authentication relies on external servers and software, then network connectivity is required, but the system becomes dependent on external components that can be compromised

Engineering Contradiction:
Improveauthentication functionalityVSAvoidexternal dependency
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The information handling system performs authentication self-service through its own trusted platform module, which independently generates, stores, and verifies boot metric data without requiring external authentication servers. This self-contained approach eliminates external dependencies while maintaining authentication functionality, reducing the system to its essential self-authenticating components.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10057221B2Field replaceable unit authentication system
Publication Date: 2018.08.21 DELL PROD LP
  • US10057221B2 patent drawing
  • US10057221B2 patent drawing
  • US10057221B2 patent drawing

AI summary

A field replaceable unit authentication system provides for a field replaceable unit device to be positioned in a chassis. A trusted platform module is included in the field replaceable unit device. A network operating system engine may be provided in the field replaceable unit device and coupled to the trusted platform module. The network operating system engine participates in a boot process with a booting subsystem to generate current boot metric data that is provided for storage in the trusted platform module. A platform management controller in the field replaceable unit device retrieves the current boot metric data from the trusted platform module, authenticates the trusted platform module, and compares the current boot metric data to previously stored boot metric data to determine whether to authenticate the network operating system engine. If authenticated, the network operating system engine then authenticates the platform management controller.