Temporary Password Firmware Access System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for securing firmware access on computing devices are vulnerable to unauthorized access, particularly when passwords are written down and easily accessible to others, compromising device security.

Innovation Solution

A system that generates a temporary password for firmware access, involving a client device, server, and password receiving entity, where the client device requests credentials, authenticates, and receives a temporary password from the server, which is used to access firmware configurations without needing to memorize a permanent password, with expiration and update mechanisms to maintain security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a permanent password is used for firmware access, then security is maintained, but the user must memorize the password which creates physical security risks when written down

Engineering Contradiction:
Improvefirmware securityVSAvoidpassword management
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent transforms the static permanent password into a dynamic temporary password that automatically expires after a set period. This dynamic approach eliminates the need for long-term memorization while maintaining security, as the password becomes invalid after expiration and can be renewed through the same authentication process.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the temporal parameter of the password from permanent to temporary with automatic expiration. By modifying the validity duration parameter, the system resolves the contradiction between security and ease of operation, as users no longer need to permanently store or memorize passwords.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If no password is required for firmware access, then ease of operation is improved, but unauthorized access becomes possible

Engineering Contradiction:
Improvefirmware accessVSAvoidunauthorized access risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic authentication through expiring passwords that require renewal. This periodic action maintains security by ensuring that access credentials are time-limited, while still allowing legitimate users convenient access during the valid period without permanent memorization requirements.

Inventive Principle:
Principle #19Periodic action

3Reliability

If a temporary password with expiration is used, then security is enhanced by eliminating permanent memorization, but the system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidpassword system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements an automatic password expiration and renewal system that operates without manual intervention. The system automatically tracks password validity periods, enforces expiration, and allows users to renew passwords through the existing authentication mechanism, eliminating the need for complex manual password management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP3791300B1Firmware access based on temporary passwords
Publication Date: 2025.01.01 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • EP3791300B1 patent drawingFigure 1
  • EP3791300B1 patent drawingFigure 2
  • EP3791300B1 patent drawingFigure 3A~3C

AI summary

An example computing device includes a communication device, an input device, a storage device, firmware stored in the storage device, and a processor. The processor is to: in response to receiving a set of credentials, transmit a request to a server via the communication device, where the request includes the set of credentials and identification information of the computing device; receive a temporary password and expiration information of the temporary password from the server via the communication device; replace a password of the firmware with the temporary password; in response to receiving the temporary password via the input device, determine if the temporary password is valid based on the expiration information; and in response to a determination that the temporary password is valid, provide access to the firmware. firmware