Pre-boot Wi-Fi Credential Vault for Secure Auto-Connect
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Pre-boot environments in information handling systems lack the ability to store Wi-Fi credentials securely, leading to inconvenient manual input requirements and limitations in auto-connect and network switching, especially when connecting to enterprise Wi-Fi networks, due to security and technical constraints.
Innovation Solution
Implementing a secure storage vault accessible from the pre-boot environment for Wi-Fi credentials, allowing seamless connection and auto-switching by using an OEM-specific secure vault with access policies and privileged-access memory, enabling secure storage and retrieval of Wi-Fi profiles, including enterprise profiles, and utilizing a Wi-Fi supplicant agent for dynamic auto-switching and re-authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If Wi-Fi credentials are stored in BIOS-managed NVRAM, then auto-connect functionality can be implemented, but security vulnerability increases due to unauthorized access risks
Solution Approach 1:
The patent segments the storage system into two parts: a secure encrypted vault for storing Wi-Fi credentials (SSID, password, security type) and the pre-boot environment access layer. This segmentation allows automated connection functionality while protecting credentials through encryption and controlled access, resolving the contradiction between automation and security.
2Reliability
If manual Wi-Fi credential input is required each time, then security is maintained, but user convenience and time efficiency deteriorate
Solution Approach 1:
The patent implements preliminary action by storing Wi-Fi credentials in the encrypted vault during system setup or first connection. This pre-stored information enables automatic reconnection without requiring user input during subsequent pre-boot environments, improving ease of operation while maintaining security through the encrypted storage mechanism.
3Loss of energy
If download process is aborted on stalled connection, then resource waste is prevented, but productivity and time efficiency worsen due to repeated manual reconnection
Solution Approach 1:
The patent implements feedback mechanisms where the pre-boot environment continuously monitors download status and network connection health. When a download stalls or network changes are detected, the system automatically detects these conditions and initiates reconnection using stored credentials without requiring user intervention, thus maintaining productivity while preventing resource waste through intelligent monitoring.
4Adaptability or versatility
If enterprise Wi-Fi networks with 802.1x authentication are supported, then network versatility improves, but system complexity increases due to certificate management requirements
Solution Approach 1:
The patent implements a universal encrypted vault architecture that can store multiple types of credentials including WPA/WPA2 passwords and 802.1x certificates. This multi-functional storage system handles different authentication types through a unified interface, enabling enterprise Wi-Fi support while abstracting away the complexity of certificate management from the user.
Data Source
AI summary
An information handling system may include at least one processor; and a wireless network interface adapter; wherein the information handling system is configured to: store credentials for a wireless network in a secure storage vault accessible from a pre-boot environment; and during execution of the pre-boot environment, connect the wireless network interface adapter to the wireless network based on the credentials without requiring user input of the credentials.


