Password Management Outside BIOS via TPM NVRAM
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing password management systems in computer systems are vulnerable to security breaches when the power-on password (POP) is the same as the hard disk password (HDP), allowing unauthorized access to the hard drive contents.
Innovation Solution
Managing the POP in a more secure location, specifically within the non-volatile random access memory (NVRAM) of a Trusted Platform Module (TPM), where the BIOS can access and employ code to authenticate and unlock the system, thereby keeping the POP secure and separate from the BIOS.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If the POP is stored in the BIOS memory, then the system can easily access and verify the password during booting, but the security is compromised because the POP can be read out of the BIOS memory
Solution Approach 1:
The patent extracts the POP storage function from the BIOS memory and relocates it to a separate secure element (such as a secure enclave, TPM, or dedicated secure memory region). This physical and logical separation ensures that the POP cannot be read out of the BIOS memory, eliminating the security vulnerability while maintaining the ability to verify passwords during booting through controlled authentication interfaces.
Solution Approach 2:
The patent introduces an intermediary authentication module or secure element that acts as a mediator between the BIOS and the POP storage. This intermediary component securely holds the POP and provides controlled access during the authentication process, preventing direct reading of the POP from BIOS memory while enabling password verification functionality.
2Ease of operation
If the POP and HDP are the same password, then the user convenience is improved, but the security breach risk increases significantly
Solution Approach 1:
The patent segments the password management system into distinct components: the POP is stored and managed in a secure element separate from the BIOS, while the HDP manages hard drive access. This segmentation allows the system to maintain user convenience (same password can be used) while preventing security breaches, because compromise of one password does not automatically compromise the other through separate storage and verification mechanisms.
3Ease of operation
If the POP is read out of BIOS memory, then the password can be accessed and used for authentication, but unauthorized access to hard drive contents becomes possible
Solution Approach 1:
The patent extracts the POP from BIOS memory storage and places it in a dedicated secure element that prevents reading the password out of the BIOS. The secure element provides controlled authentication interfaces that verify the password without exposing it to the BIOS or other system components, thereby maintaining password accessibility for authentication while preventing unauthorized access to hard drive contents.
Data Source
AI summary
In accordance with at least one presently preferred embodiment of the present invention, there is broadly contemplated herein the managing of a POP not solely in the BIOS but at least partly in a more secure location. In accordance with a particularly preferred embodiment of the present invention, this location could be in a NVRAM (non-volatile random access memory) inside a TPM (trusted platform module). Most preferably, this location will contain code that the BIOS preferably will need to access and employ in order to complete the booting of the system.


