Service Processor Boot Authorization via Remote Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems are vulnerable to malicious access and infiltration, especially when physical access is compromised, as security measures like TPM and third-party authentication services do not adequately protect against boot attacks by rogue systems.

Innovation Solution

A system and method where a service processor manages the boot process by obtaining authentication from a third-party service through a network, locking the boot of the operating system until authorized, using a boot authorization module that interfaces with a remote authentication service to provide a token for unlocking the boot process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If physical access protection measures (TPM, hardware encryption) are implemented, then data security is improved, but security is compromised when physical access is obtained through theft or malicious software

Engineering Contradiction:
Improvedata securityVSAvoidvulnerability to physical access compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a service processor as an intermediary component between the operating system and the hardware platform. This service processor manages the boot process and coordinates authentication with external authentication services, acting as a mediator that prevents direct access to security-critical components even when physical access is compromised

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent moves the authentication mechanism from the local physical platform to a remote authentication service accessible through network communication. By adding this network dimension, the system enables authentication verification outside the physically compromised environment, allowing security validation to occur in a different spatial dimension (remote server vs. local device)

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Speed

If local authentication services are used, then authentication speed is improved, but security is reduced due to centralized database storage on the same platform

Engineering Contradiction:
Improveauthentication speedVSAvoidauthentication security
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent relocates the authentication service from the local information handling system to a remote authentication service accessible through network communication. This spatial separation ensures that even if the local platform is physically compromised, the centralized authentication database remains protected on a remote server, eliminating the security risk of local database storage while maintaining authentication functionality

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Ease of operation

If rogue systems are allowed to boot, then system accessibility is improved, but network security is compromised by infiltration

Engineering Contradiction:
Improvesystem accessibilityVSAvoidnetwork infiltration risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary authentication verification through the service processor before the operating system boot process completes. By performing authentication checks during the early boot stage (before full system accessibility is achieved), the system can prevent rogue systems from infiltrating the network while still allowing legitimate systems to boot normally, thus maintaining security without unduly restricting accessibility

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8219792B2System and method for safe information handling system boot
Publication Date: 2012.07.10 DELL PROD LP
  • US8219792B2 patent drawing
  • US8219792B2 patent drawing
  • US8219792B2 patent drawing

AI summary

Information handling system security is maintained by locking the information handling system from boot of an operating system with a service processor of the information handling system. The service processor obtains authorization for boot from a third party authentication service by providing authentication information to the authentication service and requiring a successful authentication for boot. For example, the service processor releases a token upon successful authentication to authorize boot. In one embodiment, the authentication service sends a token to the service processor for the service processor to use to authorize boot.