Trusted Port Queues for Secure Runtime Firmware Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face security vulnerabilities in firmware management due to exploitable flaws in runtime services, particularly in unprotected work queues, which can compromise the effectiveness of security mechanisms that rely on telemetry for identifying suspicious behavior.

Innovation Solution

Implementing a distributed BIOS with trusted queue management operations to authorize device-specific communication through a device-specific buffer handling operation, ensuring secure firmware management by protecting trusted event queues from malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional firmware management operations are used, then device communication is enabled, but security vulnerabilities exist in unprotected work queues

Engineering Contradiction:
Improvefirmware management securityVSAvoidexploitable flaws in runtime services
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the BIOS into a distributed architecture where firmware management operations are separated from device-specific communication. This creates distinct trusted queues for firmware events and device-specific queues for hardware communication, preventing exploitation of runtime services while maintaining both security and functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces trusted queue management operations as an intermediary layer between device-specific communication and firmware management. This mediator validates and authorizes communications through enumerated trusted ports, blocking malicious attacks while allowing legitimate device interactions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If BIOS components are tightly coupled, then system operation is simplified, but security mechanisms are compromised

Engineering Contradiction:
Improvesecurity mechanism effectivenessVSAvoidBIOS component interrelationships
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the BIOS into distributed components with clear separation between firmware management functions and device-specific operations. Trusted queues are segmented into firmware event queues and device-specific queues, eliminating security vulnerabilities caused by tight coupling while maintaining system functionality through defined interfaces.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If work queues are unprotected for ease of operation, then device communication is simplified, but security vulnerabilities are introduced

Engineering Contradiction:
Improvedevice communication simplicityVSAvoidfirmware management security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces trusted queue management operations as an intermediary that automatically validates and authorizes device communications. This mediator maintains simple device communication interfaces while implementing security checks in the background, preventing exploitation without complicating the user interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted queue management system performs self-service security validation by automatically enumerating trusted ports and authorizing device-specific communications. This eliminates the need for manual security configuration while maintaining protection against exploits, keeping the system both secure and easy to operate.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20260030342A1Trusted Port Based Communication Queues for Secure Runtime Device Specific Execution
Publication Date: 2026.01.29 DELL PROD LP
  • US20260030342A1 patent drawing
  • US20260030342A1 patent drawing
  • US20260030342A1 patent drawing

AI summary

A firmware management operation. The firmware management operation includes providing an information handling system with a distributed BIOS; identifying device specific data associated with a device of the information handling system; enumerating a trusted port via a trusted queue management operation; and, authorizing device specific communication via the trusted port, the device specific communication using a device-specific buffer handling operation.