US2018157849A1PendingUtilityA1
Anti-theft in firmware
Est. expiryOct 25, 2032(~6.2 yrs left)· nominal 20-yr term from priority
G06F 9/4406G06F 21/32G06F 21/602G06F 21/575
56
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Methods, systems and storage media are disclosed for enhanced system boot processing that authenticates boot code based on biometric information of the user before loading the boot code to system memory. For at least some embodiments, the bio -metric authentication augments authentication of boot code based on a unique platform identifier. The enhanced boot code authentication occurs before loading of the operating system, and may be performed during a Unified Extensible Firmware Interface (UEFI) boot sequence. Other embodiments are described and claimed.
Claims
exact text as granted — not AI-modified1 - 75 . (canceled)
76 . At least one non-transitory machine accessible storage medium including one or more sequences of instructions, the sequences of instructions including instructions which when executed cause a computing device to:
receive notification of a reset event; receive, from one or more biometric devices, biometric information associated with a user; encrypt firmware instructions to be executed during a boot sequence, wherein encryption is based on at least three credentials including a unique identifier associated with the computing device, the biometric information, and user-based information, wherein encryption is performed during the boot sequence; and perform additional processing to load the operating system.
77 . The storage medium of claim 76 , wherein the user-based information includes possession of a token.
78 . The storage medium of claim 76 , wherein the user-based information includes a password.
79 . The storage medium of claim 76 , wherein the user-based information includes a passphrase.
80 . The storage medium of claim 76 , wherein the user-based information includes a location of the user.
81 . The storage medium of claim 76 , wherein the unique identifier includes a product serial number.
82 . The storage medium of claim 76 , wherein the unique identifier includes a media access control (MAC) address of an Ethernet device.
83 . The storage medium of claim 76 , wherein the unique identifier includes a product serial number.
84 . The storage medium of claim 76 , wherein the unique identifier includes a Trusted Platform Module (TPM) key.
85 . The storage medium of claim 76 , wherein encryption is to be performed prior to loading of an operating system.
86 . The storage medium of claim 76 , wherein encryption is to be performed during a driver execution environment phase of the boot sequence.
87 . The storage medium of claim 76 , the instructions further comprising instructions which when executed cause the computing device to:
perform one or more platform initialization instructions, and initialize the one or more biometric devices.
88 . At least one non-transitory machine accessible storage medium including one or more sequences of instructions, the sequences of instructions including instructions which when executed cause a computing device to:
receive notification of a reset event; receive, from one or more biometric devices, biometric information associated with a user; decrypt firmware instructions to be executed during a boot sequence, said decrypting based on at least three credentials including a unique identifier associated with the computing device, the biometric information, and user-based information, wherein decryption is performed during the boot sequence; and perform additional processing to load the operating system.
89 . The storage medium of claim 88 , the instructions further comprising instructions which when executed cause the computing device to:
perform one or more platform initialization instructions, and initialize the one or more biometric devices.
90 . The storage medium of claim 89 , wherein the user-based information comprises one or more of: (a) possession of a token, (b) password, (c) passphrase, and (d) location of the user.
91 . A method, comprising:
performing initial operations of a boot sequence in a computing system, responsive to receiving notification of a reset event; decrypting boot sequence firmware code during a driver execution environment phase of a boot sequence using at least three credentials including a unique identifier associated with the computing device, the biometric information, and data associated with a user, the biometric information comprises readings from one or more biometric devices; responsive to the decrypting, performing additional operations of the boot sequence, wherein the additional operations include loading of operating system code into system memory of the computing system; and terminating the boot sequence without loading the operating system code if the decrypting is unsuccessful.
92 . The method of claim 91 , wherein the boot sequence is a UEFI boot sequence.
93 . The method of claim 91 , wherein the decrypting of boot sequence firmware code further comprises decrypting of UEFI driver code.
94 . The method of claim 91 , wherein said initial operations of the boot sequence include one or more operations to initialize a processor of the computing system.
95 . The method of claim 91 , further comprising:
initializing one or more biometric devices.
96 . The method of claim 91 , further comprising:
collecting the biometric information from one or more biometric devices.Join the waitlist — get patent alerts
Track US2018157849A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.