UEFI iSCSI Target Mapping via M-Search Security Metadata

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for loading an operating system (OS) from a remote source during processor boot are vulnerable to security threats due to the lack of authentication mechanisms in non-EFI or non-executable files, particularly in UEFI-based systems using insecure protocols like M-Search, which can lead to cross-site scripting vulnerabilities and unauthorized access.

Innovation Solution

A system and method that securely maps a UEFI iSCSI target by using a modified Redfish discovery protocol with UEFI-based security metadata in the M-Search command option, ensuring authentication of the OS source before mapping it for boot, thereby eliminating vulnerabilities in the discovery process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If OS is loaded from remote source during processor boot, then system flexibility and remote management capability are improved, but security vulnerability and risk of malicious code execution increase

Engineering Contradiction:
Improveremote OS loading capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing authentication and validation of the remote OS image before the processor boot process begins. The UEFI firmware verifies digital signatures and authenticates the OS source in advance, ensuring that only verified images are loaded, thus preventing security vulnerabilities before they can affect the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary authentication mechanism between the processor and the remote OS source. The UEFI firmware acts as an intermediary that validates security metadata, digital signatures, and authentication tokens, mediating the trust relationship and blocking malicious code from reaching the processor directly.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If insecure protocol like M-Search is used for OS discovery, then ease of operation and compatibility are improved, but security vulnerability and unauthorized access risk increase

Engineering Contradiction:
ImproveOS discovery simplicityVSAvoidcross-site scripting vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces security metadata as an intermediary layer between the M-Search protocol and the OS discovery process. This metadata includes authentication tokens and security identifiers that verify the legitimacy of discovered OS images, preventing cross-site scripting vulnerabilities while maintaining the simplicity of the discovery protocol.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameters of the M-Search protocol by adding security metadata fields and authentication requirements to the discovery process. This modifies the protocol to include security verification steps without fundamentally changing its operational simplicity or compatibility.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If authentication mechanism is added to UEFI discover protocol, then security and integrity are improved, but device complexity and implementation difficulty increase

Engineering Contradiction:
Improveboot process integrityVSAvoidprotocol complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the authentication mechanism into distinct modular components: security metadata generation, digital signature verification, and authentication token validation. Each component is implemented as a separate function in the UEFI firmware, making the overall complex system manageable and maintainable through clear separation of concerns.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11106471B2System and method to securely map UEFI ISCSI target for OS boot using secure M-Search command option in UEFI discover protocol
Publication Date: 2021.08.31 DELL PROD LP
  • US11106471B2 patent drawing
  • US11106471B2 patent drawing

AI summary

A method for secure data communications using an insecure protocol, comprising generating a data message at a data processor client. Adding a security key to the data message using the data processor client. Transmitting the data message to a remote data processor receiver over a data network. Determining whether the data message is authentic at the remote data processor receiver. Automatically responding to the data message with a location where additional data can be obtained from the remote data processor receiver if it is determined by the remote data processor receiver that the data message is authentic.