Service Processor Boot Authorization via Remote Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information handling systems are vulnerable to malicious access and infiltration, especially when physical access is compromised, as security measures like TPM and third-party authentication services do not adequately protect against boot attacks by rogue systems.
Innovation Solution
A system and method where a service processor manages the boot process by obtaining authentication from a third-party service through a network, locking the boot of the operating system until authorized, using a boot authorization module that interfaces with a remote authentication service to provide a token for unlocking the boot process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If physical access protection measures (TPM, hardware encryption) are implemented, then data security is improved, but security is compromised when physical access is obtained through theft or malicious software
Solution Approach 1:
The patent introduces a service processor as an intermediary component between the operating system and the hardware platform. This service processor manages the boot process and coordinates authentication with external authentication services, acting as a mediator that prevents direct access to security-critical components even when physical access is compromised
Solution Approach 2:
The patent moves the authentication mechanism from the local physical platform to a remote authentication service accessible through network communication. By adding this network dimension, the system enables authentication verification outside the physically compromised environment, allowing security validation to occur in a different spatial dimension (remote server vs. local device)
2Speed
If local authentication services are used, then authentication speed is improved, but security is reduced due to centralized database storage on the same platform
Solution Approach 1:
The patent relocates the authentication service from the local information handling system to a remote authentication service accessible through network communication. This spatial separation ensures that even if the local platform is physically compromised, the centralized authentication database remains protected on a remote server, eliminating the security risk of local database storage while maintaining authentication functionality
3Ease of operation
If rogue systems are allowed to boot, then system accessibility is improved, but network security is compromised by infiltration
Solution Approach 1:
The patent implements preliminary authentication verification through the service processor before the operating system boot process completes. By performing authentication checks during the early boot stage (before full system accessibility is achieved), the system can prevent rogue systems from infiltrating the network while still allowing legitimate systems to boot normally, thus maintaining security without unduly restricting accessibility
Data Source
AI summary
Information handling system security is maintained by locking the information handling system from boot of an operating system with a service processor of the information handling system. The service processor obtains authorization for boot from a third party authentication service by providing authentication information to the authentication service and requiring a successful authentication for boot. For example, the service processor releases a token upon successful authentication to authorize boot. In one embodiment, the authentication service sends a token to the service processor for the service processor to use to authorize boot.


