Network-Based BIOS Authorization for Portable Computer Location Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable computers lack mechanisms to restrict their usage to specific authorized locations, potentially leading to inappropriate use of sensitive data or applications.

Innovation Solution

Incorporating a BIOS-driven authorization process that uses network information to determine if the computer is in an authorized location by matching current network profiles with stored profiles, preventing operation if not authorized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If portable computers are designed to be easily transported and used at many different locations, then portability and versatility are improved, but security control over usage location deteriorates

Engineering Contradiction:
Improveusage location flexibilityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system pre-configures authorized location information (network identifiers, MAC addresses, SSIDs) into the portable computer before deployment. During operation, the computer automatically compares current network environment against these pre-stored authorized locations, enabling security control without real-time human intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces network information (MAC addresses, SSIDs, network identifiers) as an intermediary to verify location authenticity. Instead of directly tracking physical location, the system uses network environment characteristics as a mediator to determine whether the computer is in an authorized location, providing indirect but effective security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If no location restriction mechanism is implemented, then ease of operation is improved, but security risk increases

Engineering Contradiction:
Improveunrestricted usageVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The portable computer performs self-verification by automatically checking its current network environment against stored authorized location information. The system autonomously determines whether it is in an authorized location and takes appropriate action (allow or block operation) without requiring external verification or user intervention, achieving security control through self-service.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors the current network environment and compares it with authorized location data, providing feedback control. When the computer detects that it is in an unauthorized location, the system responds by blocking operation, creating a closed-loop feedback mechanism that automatically adjusts system behavior based on location verification results.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7793339B2Devices and methods of using network information in an authorization process
Publication Date: 2010.09.07 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US7793339B2 patent drawing
  • US7793339B2 patent drawing
  • US7793339B2 patent drawing

AI summary

A device comprises a network interface and a programmable processor to execute software that performs an authorization process that is a function of network information received by the network interface. The network information comprises information indicative of a network with which the network interface is able to communicate, and the software causes the device to perform a boot process such that if the authorization process is not successful, the device does not successfully complete the boot process.