User-Specific Port Configuration via NVRAM Segmentation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional access control mechanisms in computer systems are inadequate in managing ports controlled by NVRAM settings, as they are shared among users, allowing non-trusted individuals to compromise security by accessing or infecting systems with malware through 'open' ports.
Innovation Solution
The system retrieves user-specific identifiers, such as usernames and authentication codes, to configure hardware settings for ports, network interfaces, and storage devices, enabling or disabling them based on user identity before booting the operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If traditional NVRAM settings are configured with open ports for user access, then system usability and data transfer capability are improved, but system security and integrity deteriorate due to unauthorized access and malware introduction
Solution Approach 1:
The patent segments the shared NVRAM settings into user-specific configurations. Each user receives a customized set of hardware settings that enable or disable specific ports based on their trust level and job requirements. This segmentation allows trusted users to access open ports while non-trusted users receive restricted configurations, resolving the contradiction between accessibility and security.
Solution Approach 2:
The patent applies local quality by providing different port accessibility characteristics to different users. Instead of a uniform open or closed port configuration for all users, each user receives a customized configuration tailored to their specific needs and trust level. This allows ports to be locally optimized for each user's security clearance and operational requirements.
2Object-affected harmful factors
If user-specific hardware settings are implemented in NVRAM, then system security is improved by blocking unauthorized access, but device complexity increases due to multiple configuration sets
Solution Approach 1:
The patent applies preliminary action by pre-configuring user-specific hardware settings in NVRAM before users log in. During system initialization, the appropriate configuration set is automatically loaded based on user identification, eliminating the need for real-time configuration changes during user sessions. This preliminary setup simplifies runtime operations while maintaining security.
Solution Approach 2:
The patent introduces an intermediary mechanism that manages the complexity of multiple configuration sets. This intermediary layer handles the storage, retrieval, and application of user-specific settings, shielding users and applications from the underlying complexity. The system automatically selects and applies the appropriate configuration without requiring user intervention or manual management.
3Object-affected harmful factors
If ports are blocked for non-trusted users, then malware introduction is prevented, but system functionality and data transfer capability are reduced
Solution Approach 1:
The patent applies dynamics by making port configurations adaptive rather than static. Port accessibility is dynamically adjusted based on user identity, trust level, and specific operational requirements. Trusted users receive configurations with open ports for full functionality, while non-trusted users receive restricted configurations. This dynamic approach ensures each user experiences optimal functionality appropriate to their security clearance.
Solution Approach 2:
The patent changes the parameter of port accessibility from a fixed system-wide setting to a variable user-specific parameter. By storing multiple configuration sets in NVRAM with different port enablement states, the system can change the accessibility parameter based on which user is logged in. This allows the same physical port to be enabled for one user and disabled for another, maintaining both security and functionality.
Data Source
AI summary
An approach is provided that receives a user identifier from a user of the information handling system. The user identifier can include a username as well as a user authentication code, such as a password. Hardware settings that correspond to the user identifier are retrieved from a nonvolatile memory. Hardware devices, such as ports (e.g., USB controller), network interfaces, storage devices, and boot sequences, are configured using the retrieved hardware settings. After the hardware devices have been configured to correspond to the identified user, an operating system is booted.


