Bios network safe assurance method
An information handling system may include at least one processor; and a wireless network interface adapter; wherein the information handling system is configured to: store credentials for a wireless network in a secure storage vault accessible from a pre-boot environment; and during execution of the pre-boot environment, connect the wireless network interface adapter to the wireless network based on the credentials without requiring user input of the credentials.
1 . An information handling system comprising:
at least one processor;
a secure storage vault; and
a wireless network interface adapter;
wherein the information handling system is configured to:
store credentials for a wireless network in the secure storage vault, the secure storage vault being accessible from a pre-boot environment, in the information handling system wherein the wireless network is an enterprise Wi-Fi network, and wherein the credentials include an 802.1x certificate associated with the enterprise Wi-Fi network; and
during execution of the pre-boot environment, connect the wireless network interface adapter to the wireless network based on the credentials without requiring user input of the credentials;
wherein the pre-boot environment includes a plurality of modules, and wherein the secure storage vault is accessible only to a pre-authorized subset of the plurality of modules.
2 . The information handling system of claim 1 , wherein the secure storage vault is an encrypted data store of an embedded controller (EC) of the information handling system.
3 . The information handling system of claim 1 , wherein the pre-boot environment is a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS).
4 . The information handling system of claim 1 , wherein the information handling system is further configured to execute a software agent during execution of an operating system, wherein the software agent is configured to update the secure storage vault with new credentials.
5 . The information handling system of claim 1 , wherein the secure storage vault is further configured to store credentials for a home Wi-Fi network, the credentials for the home Wi-Fi network comprising a service set identifier (SSID) and password associated with the home Wi-Fi network.
6 . A method comprising:
an information handling system storing credentials for a wireless network in a secure storage vault of the information handling system, the secure storage vault being accessible from a pre-boot environment, in the information handling system wherein the wireless network is an enterprise Wi-Fi network, and wherein the credentials include an 802.1x certificate associated with the enterprise Wi-Fi network; and
during execution of the pre-boot environment, the information handling system connecting a wireless network interface adapter thereof to the wireless network based on the credentials without requiring user input of the credentials;
wherein the pre-boot environment includes a plurality of modules, and wherein the secure storage vault is accessible only to a pre-authorized subset of the plurality of modules.
7 . The method of claim 6 , further comprising the information handling system executing a software agent during execution of an operating system, wherein the software agent is configured to update the secure storage vault with new credentials.
8 . The method of claim 6 , wherein the secure storage vault is an encrypted data store of an embedded controller (EC) of the information handling system.
9 . The method of claim 6 , wherein the pre-boot environment is a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS).
10 . The method of claim 6 , wherein the secure storage vault is further configured to store credentials for a home Wi-Fi network, the credentials for the home Wi-Fi network comprising a service set identifier (SSID) and password associated with the home Wi-Fi network.
11 . An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:
storing credentials for a wireless network in a secure storage vault of the information handling system, the secure storage vault being accessible from a pre-boot environment, in the information handling system wherein the wireless network is an enterprise Wi-Fi network, and wherein the credentials include an 802.1x certificate associated with the enterprise Wi-Fi network; and
during execution of the pre-boot environment, connecting a wireless network interface adapter of the information handling system to the wireless network based on the credentials without requiring user input of the credentials;
wherein the pre-boot environment includes a plurality of modules, and wherein the secure storage vault is accessible only to a pre-authorized subset of the plurality of modules.
12 . The article of claim 11 , wherein the secure storage vault is further configured to store credentials for a home Wi-Fi network, the credentials for the home Wi-Fi network comprising a service set identifier (SSID) and password associated with the home Wi-Fi network.
13 . The article of claim 11 , wherein the computer-executable code is further executable for executing a software agent during execution of an operating system, wherein the software agent is configured to update the secure storage vault with new credentials.
14 . The article of claim 11 , wherein the secure storage vault is an encrypted data store of an embedded controller (EC) of the information handling system.
15 . The article of claim 11 , wherein the pre-boot environment is a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS).