Pre-Boot BIOS Feature Provisioning With Certificate-Verified Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing BIOS systems lack flexibility and security in pre-boot environments, with limited features and inadequate administration capabilities, and there are concerns regarding network access and code execution within these environments.

Innovation Solution

A method and system for providing secure and customized BIOS features in a pre-boot environment using signed certificates to verify and authenticate command and control clients, enabling remote administration and execution of authorized processes through a command and control client.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If BIOS features are extended with more functionality, then the versatility of the system is improved, but the security risks and complexity increase

Engineering Contradiction:
ImproveBIOS feature flexibilityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The BIOS system is segmented into multiple trusted components with distinct responsibilities: the command and control client handles communication, the enrollment process manages certificate issuance, and the execution request handling separates privileged operations. Each segment is independently verified through digital certificates, allowing feature extension without compromising overall security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A certificate-based authentication system acts as an intermediary between administrators and BIOS operations. Signed certificates verify the authenticity of command and control clients, enrollment requests, and execution requests, enabling secure remote administration without direct trusted connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If administrators gain remote access to BIOS features, then the ease of operation is improved, but the security vulnerabilities increase

Engineering Contradiction:
Improveremote administration capabilityVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary authentication through certificate verification before allowing any remote administration operations. Command and control clients must present valid signed certificates before gaining access, and execution requests are pre-validated against enrolled certificates, preventing unauthorized access before it can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The authentication system provides feedback through certificate validation results, accepting or rejecting access requests based on cryptographic verification. This automated feedback mechanism enables secure remote administration by continuously verifying credentials without requiring manual security checks.

Inventive Principle:
Principle #23Feedback

3Productivity

If code execution is enabled in pre-boot environment, then the productivity of system configuration is improved, but the reliability decreases due to security concerns

Engineering Contradiction:
Improvesystem configuration efficiencyVSAvoidcode execution security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system dynamically controls code execution in the pre-boot environment based on certificate validation results. Execution requests are processed conditionally - only those with verified signed certificates are permitted to execute, while others are rejected. This dynamic authorization enables productive system configuration while maintaining security through runtime verification.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12625970B2Providing bios features in a pre-boot environment for a client computer system
Publication Date: 2026.05.12 PHOENIX TECH EMEA LTD
  • US12625970B2 patent drawing
  • US12625970B2 patent drawing
  • US12625970B2 patent drawing

AI summary

A Method And System For Providing Secure And Customized Bios Features Via Execution Requests In A Pre-boot Environment For A Client Computer System. The Bios Features Are Provided To The Client Computer System Utilizing Signed Certificates For Verifying A Command And Control Client As Validated Firmware, Verifying Enrollment Of The Command And Control Client And Verifying Execution Requests Prior To Execution Of Processes In The Execution Request. The Execution Of The Processes Results In The Customized Bios Features For The Client Computer System.