Pre-boot Wi-Fi Credential Vault for Secure Auto-Connect

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Pre-boot environments in information handling systems lack the ability to store Wi-Fi credentials securely, leading to inconvenient manual input requirements and limitations in auto-connect and network switching, especially when connecting to enterprise Wi-Fi networks, due to security and technical constraints.

Innovation Solution

Implementing a secure storage vault accessible from the pre-boot environment for Wi-Fi credentials, allowing seamless connection and auto-switching by using an OEM-specific secure vault with access policies and privileged-access memory, enabling secure storage and retrieval of Wi-Fi profiles, including enterprise profiles, and utilizing a Wi-Fi supplicant agent for dynamic auto-switching and re-authorization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If Wi-Fi credentials are stored in BIOS-managed NVRAM, then auto-connect functionality can be implemented, but security vulnerability increases due to unauthorized access risks

Engineering Contradiction:
Improveauto-connect functionalityVSAvoidsecurity vulnerability
Core Design Contradiction:
Extent of automationVSReliability

Solution Approach 1:

The patent segments the storage system into two parts: a secure encrypted vault for storing Wi-Fi credentials (SSID, password, security type) and the pre-boot environment access layer. This segmentation allows automated connection functionality while protecting credentials through encryption and controlled access, resolving the contradiction between automation and security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If manual Wi-Fi credential input is required each time, then security is maintained, but user convenience and time efficiency deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by storing Wi-Fi credentials in the encrypted vault during system setup or first connection. This pre-stored information enables automatic reconnection without requiring user input during subsequent pre-boot environments, improving ease of operation while maintaining security through the encrypted storage mechanism.

Inventive Principle:
Principle #10Preliminary action

3Loss of energy

If download process is aborted on stalled connection, then resource waste is prevented, but productivity and time efficiency worsen due to repeated manual reconnection

Engineering Contradiction:
Improveresource waste preventionVSAvoiddownload recovery time
Core Design Contradiction:
Loss of energyVSProductivity

Solution Approach 1:

The patent implements feedback mechanisms where the pre-boot environment continuously monitors download status and network connection health. When a download stalls or network changes are detected, the system automatically detects these conditions and initiates reconnection using stored credentials without requiring user intervention, thus maintaining productivity while preventing resource waste through intelligent monitoring.

Inventive Principle:
Principle #23Feedback

4Adaptability or versatility

If enterprise Wi-Fi networks with 802.1x authentication are supported, then network versatility improves, but system complexity increases due to certificate management requirements

Engineering Contradiction:
Improveenterprise network supportVSAvoidcertificate management
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal encrypted vault architecture that can store multiple types of credentials including WPA/WPA2 passwords and 802.1x certificates. This multi-functional storage system handles different authentication types through a unified interface, enabling enterprise Wi-Fi support while abstracting away the complexity of certificate management from the user.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250103348A1BIOS network safe assurance method
Publication Date: 2025.03.27 DELL PROD LP
  • US20250103348A1 patent drawing
  • US20250103348A1 patent drawing
  • US20250103348A1 patent drawing

AI summary

An information handling system may include at least one processor; and a wireless network interface adapter; wherein the information handling system is configured to: store credentials for a wireless network in a secure storage vault accessible from a pre-boot environment; and during execution of the pre-boot environment, connect the wireless network interface adapter to the wireless network based on the credentials without requiring user input of the credentials.