Virtual ACPI Driver Firmware Security for Compromised Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information handling systems, such as laptops and portable devices, are vulnerable to unauthorized access and data breaches when compromised, and existing security measures often require initial setup or deployment of agents before securing the system.

Innovation Solution

An information handling system with a virtual advanced configuration and power interface device that includes a processor downloading a device driver with a security feature and a signed file containing a list of compromised systems, allowing remote security features to be applied without prior setup, such as disabling access or encrypting data, to secure compromised devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security agents or initial setup procedures are deployed to protect information handling systems, then security protection capability is improved, but device complexity and ease of operation deteriorate due to requiring prior configuration

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsetup complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds security verification logic and compromise detection mechanisms into the firmware itself before the system is deployed or used. The firmware contains pre-configured security policies and authentication mechanisms that automatically execute upon system initialization, eliminating the need for post-deployment security agent installation or manual security configuration by users.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The firmware performs self-verification of system integrity and automatically detects compromised states without requiring external security software. The system autonomously monitors its own security status, validates firmware integrity, and executes security responses independently, removing the need for separate security management agents or manual intervention.

Inventive Principle:
Principle #25Self-service

2Reliability

If security features are implemented after system compromise, then security response capability is improved, but response time deteriorates due to detection and deployment delays

Engineering Contradiction:
Improvesecurity response capabilityVSAvoidsecurity response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Security verification and compromise detection are performed during firmware initialization and system boot-up sequences before the operating system or applications can be compromised. The firmware contains pre-loaded security policies and authentication mechanisms that automatically execute upon system initialization, enabling security verification to occur before potential attacks can take effect.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors its own operational status and security integrity through feedback mechanisms embedded in the firmware. The firmware validates system state, detects anomalies or compromise indicators in real-time, and automatically triggers security responses based on predefined policies, creating a closed-loop security system that responds immediately without external intervention delays.

Inventive Principle:
Principle #23Feedback

3Reliability

If remote security updates and firmware patches are deployed, then security vulnerability protection is improved, but system stability may deteriorate due to update installation risks

Engineering Contradiction:
Improvevulnerability protectionVSAvoidsystem stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

Firmware updates and security patches are validated for integrity and authenticity before being installed on the system. The firmware contains verification mechanisms that check update signatures and validate compatibility before applying changes, ensuring that only authorized and verified updates are deployed. This preliminary verification prevents malicious or corrupted updates from compromising system stability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements rollback mechanisms and backup storage of previous firmware versions before applying updates. If an update fails or causes system instability, the firmware can automatically revert to the previous stable version, cushioning against potential damage from faulty updates and maintaining system availability.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS11281472B2System and method for securing compromised information handling systems
Publication Date: 2022.03.22 DELL PROD LP
  • US11281472B2 patent drawing
  • US11281472B2 patent drawing
  • US11281472B2 patent drawing

AI summary

An information handling system includes a basic input/output system having a virtual advanced configuration and power interface device. A processor may download a device driver for a particular virtual advanced configuration and power interface device, wherein the device driver includes a code for a security feature and a signed file that includes a list of identifiers of compromised information handling systems. The processor may determine whether the information handling system is compromised based on the list of identifiers of compromised information handling systems in the signed file, and execute the code for the security feature.