Secure BIOS Attribute System Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional BIOS interfaces in information handling systems lack secure mechanisms for modifying BIOS attributes, allowing unauthorized access and potential disabling of security features like Secure Boot due to weak password protection.
Innovation Solution
An Information Handling System (IHS) with a processing system and memory that includes instructions to provide a BIOS engine for authenticating BIOS attribute modification requests using a certificate stored in a secure storage subsystem, ensuring only authorized modifications can be made by validating requests with a key.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If conventional BIOS interfaces with password protection are used, then ease of operation is improved, but security is worsened due to weak password protection
Solution Approach 1:
The patent replaces the mechanical/password-based protection system with a cryptographic authentication system using certificates and public key infrastructure. Instead of relying on weak passwords, the system uses cryptographic keys stored in secure elements to authenticate BIOS attribute modification requests, providing stronger security while maintaining ease of operation through automated cryptographic verification.
2Reliability
If password protection is activated for BIOS interfaces, then security is improved, but ease of operation is worsened due to additional authentication steps
Solution Approach 1:
The system implements self-service authentication where the secure element automatically performs cryptographic verification of BIOS attribute modification requests without requiring user intervention for password entry. The authenticated private key within the secure element handles authentication autonomously, eliminating the need for users to manually enter or manage passwords while maintaining strong security.
3Reliability
If certificate-based authentication is implemented, then security is improved, but device complexity is worsened due to secure storage subsystem requirements
Solution Approach 1:
The patent embeds the authentication private key and certificate verification capabilities within the existing secure element of the information handling system. The cryptographic authentication mechanism is nested within the BIOS firmware and leverages the secure element's existing hardware security features, avoiding the need for separate external security hardware and minimizing overall system complexity while providing strong security.
Data Source
AI summary
A secure Basic Input/Output System (BIOS) attribute system includes a secure server system coupled to a computing device through a network. The computing device receives a first BIOS attribute modification request, and authenticates the first BIOS attribute modification request using a first certificate that was previously stored in the computing device in response to validating the first certificate based on a key provided by the secure server system. In response to authenticating the first BIOS attribute modification request using the first certificate, the computing device modifies at least one BIOS attribute stored in the computing device.


