Secure BIOS Attribute System Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional BIOS interfaces in information handling systems lack secure mechanisms for modifying BIOS attributes, allowing unauthorized access and potential disabling of security features like Secure Boot due to weak password protection.

Innovation Solution

An Information Handling System (IHS) with a processing system and memory that includes instructions to provide a BIOS engine for authenticating BIOS attribute modification requests using a certificate stored in a secure storage subsystem, ensuring only authorized modifications can be made by validating requests with a key.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional BIOS interfaces with password protection are used, then ease of operation is improved, but security is worsened due to weak password protection

Engineering Contradiction:
ImproveBIOS attribute modification accessibilityVSAvoidBIOS security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces the mechanical/password-based protection system with a cryptographic authentication system using certificates and public key infrastructure. Instead of relying on weak passwords, the system uses cryptographic keys stored in secure elements to authenticate BIOS attribute modification requests, providing stronger security while maintaining ease of operation through automated cryptographic verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If password protection is activated for BIOS interfaces, then security is improved, but ease of operation is worsened due to additional authentication steps

Engineering Contradiction:
ImproveBIOS securityVSAvoidBIOS attribute modification accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service authentication where the secure element automatically performs cryptographic verification of BIOS attribute modification requests without requiring user intervention for password entry. The authenticated private key within the secure element handles authentication autonomously, eliminating the need for users to manually enter or manage passwords while maintaining strong security.

Inventive Principle:
Principle #25Self-service

3Reliability

If certificate-based authentication is implemented, then security is improved, but device complexity is worsened due to secure storage subsystem requirements

Engineering Contradiction:
ImproveBIOS securityVSAvoidsecure storage subsystem
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds the authentication private key and certificate verification capabilities within the existing secure element of the information handling system. The cryptographic authentication mechanism is nested within the BIOS firmware and leverages the secure element's existing hardware security features, avoiding the need for separate external security hardware and minimizing overall system complexity while providing strong security.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS10824731B2Secure bios attribute system
Publication Date: 2020.11.03 DELL PROD LP
  • US10824731B2 patent drawing
  • US10824731B2 patent drawing
  • US10824731B2 patent drawing

AI summary

A secure Basic Input/Output System (BIOS) attribute system includes a secure server system coupled to a computing device through a network. The computing device receives a first BIOS attribute modification request, and authenticates the first BIOS attribute modification request using a first certificate that was previously stored in the computing device in response to validating the first certificate based on a key provided by the secure server system. In response to authenticating the first BIOS attribute modification request using the first certificate, the computing device modifies at least one BIOS attribute stored in the computing device.