Secure Boot Minimized Reboots via Alternate Credential

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for computing systems, such as pre-boot authentication environments, prolong boot times when resuming from a power-off state due to the necessity of running the pre-boot environment each time, which is inefficient and increases boot time unnecessarily.

Innovation Solution

Implementing a biometric device, like a fingerprint reader, to authenticate users prior to releasing a value that unlocks encrypted drives without requiring the conventional pre-boot environment to run, thereby allowing secure booting from a power-off state without the added time of running the pre-boot environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If pre-boot authentication environment is run each time to unlock encrypted drives, then security is ensured, but boot time is prolonged

Engineering Contradiction:
ImprovesecurityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by establishing an alternate credential during the initial pre-boot authentication environment execution. This credential is stored in the BIOS and can be used subsequently without re-running the pre-boot environment. The alternate credential acts as a pre-prepared authentication mechanism that eliminates the need to execute the time-consuming pre-boot environment on subsequent boots while maintaining security requirements.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional pre-boot environment is executed to authenticate users, then drive unlocking is secured, but boot process time increases

Engineering Contradiction:
Improveauthentication securityVSAvoidboot process duration
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The patent extracts the essential authentication function from the pre-boot environment by creating an alternate credential that captures the authentication verification capability. This extracted credential is then stored in the BIOS and used independently without requiring the full pre-boot environment execution. This separation allows authentication security to be maintained while eliminating the time-consuming pre-boot environment execution on subsequent boots.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If encrypted drives are used to protect data, then data security is improved, but additional authentication steps are required increasing boot time

Engineering Contradiction:
Improvedata securityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing an alternate credential during the initial boot process that enables subsequent authentication without re-executing the pre-boot environment. This credential is stored in the BIOS and can be quickly verified on subsequent boots, maintaining encrypted drive security while significantly reducing the time required for authentication steps.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8473747B2Secure boot with minimum number of re-boots
Publication Date: 2013.06.25 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8473747B2 patent drawing
  • US8473747B2 patent drawing
  • US8473747B2 patent drawing

AI summary

Systems, methods and products are described that provide secure boot with a minimum number of re-boots. One aspect provides a method including receiving an indication to boot from a power off state at a computing device; responsive to authenticating a user at one or more input devices, releasing a value derived from authenticating the user at the one or more input devices; responsive to releasing the value, unlocking one or more encrypted drives with a previously established alternate credential; and thereafter proceeding to boot from the power off state. By not having to call the non-BIOS software each boot, this minimizes the number of reboots for each boot cycle.