Visual Policy Configuration for Platform Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing information handling systems face challenges in implementing dynamic and context-aware security policies across large IT environments, as current methods lack organized and connected user interfaces and enforcement mechanisms for BIOS-level settings and triggers.

Innovation Solution

A platform security operation system that enables configuration of dynamic security policies through visual block-level programming, using BIOS interpretation and enforcement, with scripting logic deployable in low-resource environments, supporting flexible cause-effect and incident-response policies, and maintaining persistence in non-volatile memory.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If visual block-level programming is used for security policy configuration, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity policy configurationVSAvoidpolicy configuration system
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

A visual policy configuration interface acts as an intermediary between users and the complex BIOS security enforcement system. This interface translates user-friendly visual block-level programming into the underlying complex security policies, shielding users from complexity while maintaining operational ease.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security policy configuration is segmented into discrete, manageable blocks that can be visually arranged and configured. Each block represents a specific security function or condition, allowing users to build complex policies through simple composition of modular elements rather than dealing with monolithic complexity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If BIOS-level security enforcement is implemented, then reliability is improved, but ease of operation worsens

Engineering Contradiction:
Improvesecurity policy enforcementVSAvoidsecurity policy configuration
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The visual configuration interface serves as a mediator that bridges the gap between user-friendly operations and BIOS-level enforcement. Users interact with simple visual blocks while the system automatically handles the complex BIOS integration, achieving both ease of operation and reliable enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs self-service by automatically translating visual block-level configurations into BIOS-level security policies without requiring users to manually configure low-level settings. The system handles the complexity of BIOS integration autonomously while users simply arrange visual blocks.

Inventive Principle:
Principle #25Self-service

3Productivity

If scripting logic is deployed to low-resource environments, then productivity is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity policy deploymentVSAvoidscripting infrastructure
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The complex scripting logic is extracted from the low-resource BIOS environment and placed in a richer host environment for configuration and management. Only the essential, optimized scripting capabilities are deployed to the BIOS, reducing the complexity burden on the low-resource system while maintaining deployment productivity.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of implementing full scripting capabilities in the resource-constrained BIOS, a simplified copy or representation of scripting logic is deployed that provides essential functionality without the overhead of the complete scripting infrastructure, balancing productivity with complexity constraints.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11252191B2Visual policy configuration and enforcement for platform security
Publication Date: 2022.02.15 DELL PROD LP
  • US11252191B2 patent drawing
  • US11252191B2 patent drawing
  • US11252191B2 patent drawing

AI summary

A system, method, and computer-readable medium are disclosed for performing a platform security operation, comprising: presenting a platform security user interface, the platform security user interface including a plurality of security blocks, each of the plurality of security blocks corresponding to a particular security policy function configuring a security policy via the platform security user interface, the configuring comprising combining a set of the security blocks according to a desired security function; converting the set of security blocks to information representing the security policy; and, deploying the security policy to an information handling system.