Manageability Engine Hardware Isolation for OS-Independent Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional access control mechanisms for computer platforms are OS-dependent, making them vulnerable to malware attacks and backdoor installations, which can bypass authentication software, necessitating a more robust and OS-independent authentication technique.
Innovation Solution
A manageability engine (ME) is introduced that utilizes hardware-based security mechanisms to isolate authentication clients from malware attacks, providing a trusted path for authentication factors like passwords and biometrics, and performs multi-factor authentication independent of the OS execution environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If OS-dependent authentication mechanisms are used, then ease of operation is improved, but reliability deteriorates due to vulnerability to malware attacks and backdoor installations
Solution Approach 1:
The system divides authentication into two independent paths: a trusted hardware-based path that bypasses the OS, and the conventional OS-based path. The manageability engine and authentication client are isolated in a separate execution environment, segmenting the authentication function from the vulnerable OS layer.
Solution Approach 2:
The manageability engine acts as an intermediary between the authentication client and the OS. It provides a trusted communication channel that does not rely on OS integrity, mediating the authentication process to prevent malware interference while maintaining ease of use.
2Reliability
If hardware-based isolation is implemented, then reliability is improved, but device complexity increases
Solution Approach 1:
The manageability engine is designed to perform multiple functions including authentication, system management, and secure communication. By making this component multi-functional, the patent reduces the need for additional dedicated hardware components, thereby limiting the increase in device complexity while maintaining security improvements.
Data Source
AI summary
A manageability engine, and/or operations thereof, for controlling access to one or more resources of a computer device. In an embodiment, the manageability engine executes an authentication agent to perform authentication of a local user of a computer platform which includes the manageability engine. In another embodiment, the manageability engine includes a device driver to control an input/output device for the local user to exchange an authentication factor via a trusted path between the input/output device and the manageability engine.


