Secure Boot Minimized Reboots via Alternate Credential
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for computing systems, such as pre-boot authentication environments, prolong boot times when resuming from a power-off state due to the necessity of running the pre-boot environment each time, which is inefficient and increases boot time unnecessarily.
Innovation Solution
Implementing a biometric device, like a fingerprint reader, to authenticate users prior to releasing a value that unlocks encrypted drives without requiring the conventional pre-boot environment to run, thereby allowing secure booting from a power-off state without the added time of running the pre-boot environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If pre-boot authentication environment is run each time to unlock encrypted drives, then security is ensured, but boot time is prolonged
Solution Approach 1:
The patent applies preliminary action by establishing an alternate credential during the initial pre-boot authentication environment execution. This credential is stored in the BIOS and can be used subsequently without re-running the pre-boot environment. The alternate credential acts as a pre-prepared authentication mechanism that eliminates the need to execute the time-consuming pre-boot environment on subsequent boots while maintaining security requirements.
2Reliability
If conventional pre-boot environment is executed to authenticate users, then drive unlocking is secured, but boot process time increases
Solution Approach 1:
The patent extracts the essential authentication function from the pre-boot environment by creating an alternate credential that captures the authentication verification capability. This extracted credential is then stored in the BIOS and used independently without requiring the full pre-boot environment execution. This separation allows authentication security to be maintained while eliminating the time-consuming pre-boot environment execution on subsequent boots.
3Reliability
If encrypted drives are used to protect data, then data security is improved, but additional authentication steps are required increasing boot time
Solution Approach 1:
The patent applies preliminary action by pre-establishing an alternate credential during the initial boot process that enables subsequent authentication without re-executing the pre-boot environment. This credential is stored in the BIOS and can be quickly verified on subsequent boots, maintaining encrypted drive security while significantly reducing the time required for authentication steps.
Data Source
AI summary
Systems, methods and products are described that provide secure boot with a minimum number of re-boots. One aspect provides a method including receiving an indication to boot from a power off state at a computing device; responsive to authenticating a user at one or more input devices, releasing a value derived from authenticating the user at the one or more input devices; responsive to releasing the value, unlocking one or more encrypted drives with a previously established alternate credential; and thereafter proceeding to boot from the power off state. By not having to call the non-BIOS software each boot, this minimizes the number of reboots for each boot cycle.


