Manageability Engine Hardware Isolation for OS-Independent Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional access control mechanisms for computer platforms are OS-dependent, making them vulnerable to malware attacks and backdoor installations, which can bypass authentication software, necessitating a more robust and OS-independent authentication technique.

Innovation Solution

A manageability engine (ME) is introduced that utilizes hardware-based security mechanisms to isolate authentication clients from malware attacks, providing a trusted path for authentication factors like passwords and biometrics, and performs multi-factor authentication independent of the OS execution environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OS-dependent authentication mechanisms are used, then ease of operation is improved, but reliability deteriorates due to vulnerability to malware attacks and backdoor installations

Engineering Contradiction:
Improveease of useVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides authentication into two independent paths: a trusted hardware-based path that bypasses the OS, and the conventional OS-based path. The manageability engine and authentication client are isolated in a separate execution environment, segmenting the authentication function from the vulnerable OS layer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The manageability engine acts as an intermediary between the authentication client and the OS. It provides a trusted communication channel that does not rely on OS integrity, mediating the authentication process to prevent malware interference while maintaining ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware-based isolation is implemented, then reliability is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The manageability engine is designed to perform multiple functions including authentication, system management, and secure communication. By making this component multi-functional, the patent reduces the need for additional dedicated hardware components, thereby limiting the increase in device complexity while maintaining security improvements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8966600B2Method, apparatus and system for controlling access to computer platform resources
Publication Date: 2015.02.24 INTEL CORP
  • US8966600B2 patent drawing
  • US8966600B2 patent drawing
  • US8966600B2 patent drawing

AI summary

A manageability engine, and/or operations thereof, for controlling access to one or more resources of a computer device. In an embodiment, the manageability engine executes an authentication agent to perform authentication of a local user of a computer platform which includes the manageability engine. In another embodiment, the manageability engine includes a device driver to control an input/output device for the local user to exchange an authentication factor via a trusted path between the input/output device and the manageability engine.