Secure BIOS Architecture with Isolated Private Network Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computers are inherently vulnerable to Internet-based malware attacks due to their reliance on external firewalls that cannot effectively block all incoming traffic, leading to security threats that compromise military and economic security worldwide.

Innovation Solution

Implementing inner hardware-based access barriers or firewalls within computers that strictly limit access to only authorized sources, using simple one-way buses and switches to create isolated, protected zones, disconnected from the Internet, and managed through secure private networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If external firewalls are used to block incoming traffic, then network security is improved, but unauthorized access cannot be fully prevented due to inherent vulnerabilities

Engineering Contradiction:
Improvenetwork securityVSAvoidunauthorized access
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The computer system is divided into two distinct units: a public unit connected to the Internet and a private unit disconnected from the Internet. The hardware firewall creates a fundamental segmentation that prevents malware from the public Internet from reaching the private unit, as there is no direct network path for unauthorized access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A hardware firewall acts as an intermediary between the public unit and the private unit. This physical barrier mediates all communication, allowing only authorized data transfers from the public unit to the private unit while blocking all incoming traffic from the Internet, thus resolving the contradiction between network connectivity and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the private unit is completely disconnected from the Internet, then security against malware is improved, but administrative and operational functions deteriorate

Engineering Contradiction:
Improvesecurity against malwareVSAvoidadministrative functions
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The hardware firewall serves as a controlled intermediary that enables administrative functions while maintaining security. It allows authorized data transfers from the public unit (where administrative interfaces may reside) to the private unit, providing remote management capabilities without exposing the private unit to Internet-based malware threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If hardware firewalls with strict access control are implemented, then security is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control securityVSAvoidfirewall architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is segmented into public and private units with a clear hardware boundary. This segmentation simplifies the firewall architecture by eliminating the need for complex software-based access control lists and routing rules, as the physical separation inherently enforces security policies.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The hardware firewall automatically enforces security policies through its physical design rather than requiring complex configuration management. The unidirectional data transfer capability is built into the hardware architecture itself, making the security mechanism self-enforcing and reducing operational complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12401619B2Computer or microchip with a secure system bios having a separate private network connection to a separate private network
Publication Date: 2025.08.26 ELLIS
  • US12401619B2 patent drawing
  • US12401619B2 patent drawing
  • US12401619B2 patent drawing

AI summary

A method for a computer or microchip with one or more inner hardware-based access barriers or firewalls that establish one or more private units disconnected from a public unit or units having connection to the public Internet and one or more of the private units have a connection to one or more non-Internet-connected private networks for private network control of the configuration of the computer or microchip using active hardware configuration, including field programmable gate arrays (FPGA). The hardware-based access barriers include a single out-only bus and/or another in-only bus with a single on/off switch.