Pre-OS authentication
An information handling system may include at least one processor, an input device, and a display device. The information handling system may be configured to: prior to booting an operating system, display a displayable identifier on the display device, wherein the displayable identifier encodes information indicative of a system identifier of the information handling system, a time, and an encrypted shared secret, and wherein the displayable identifier is usable by a mobile information handling system to determine an access password for the information handling system; and in response to receiving the access password at the input device, booting the operating system.
1 . An information handling system comprising:
at least one processor;
an input device; and
an electronic display device;
wherein the information handling system is configured to:
receive a shared secret during provisioning, wherein the shared secret is also stored at a remote information handling system, and wherein the remote information handling system stores data indicative of users authorized to access the information handling system;
prior to booting an operating system, display a displayable identifier on the electronic display device, wherein the displayable identifier encodes information indicative of a system identifier of the information handling system, a time, and an encrypted version of the shared secret, and wherein the displayable identifier is usable by a mobile information handling system to determine an access password for the information handling system by transmitting the system identifier and the encrypted version of the shared secret to the remote information handling system, the remote information handling system being configured to return the access password to the mobile information handling system in response to a user of the mobile information handling system being included in the data indicative of users authorized to access the information handling system; and
in response to receiving the access password at the input device, booting the operating system.
2 . The information handling system of claim 1 , wherein the electronic display device is a monitor.
3 . The information handling system of claim 1 , wherein the input device is a keyboard.
4 . The information handling system of claim 1 , wherein the displayable identifier is displayed by a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS) of the information handling system.
5 . The information handling system of claim 1 , further configured to allow access to an encrypted storage resource in response to receiving the access password at the input device.
6 . The information handling system of claim 1 , wherein the mobile information handling system is a smartphone.
7 . A method comprising:
an information handling system receiving a shared secret during provisioning, wherein the shared secret is also stored at a remote information handling system, and wherein the remote information handling system stores data indicative of users authorized to access the information handling system;
the information handling system displaying a displayable identifier on an electronic display device prior to booting an operating system, wherein the displayable identifier encodes information indicative of a system identifier of the information handling system, a time, and an encrypted version of the shared secret, and wherein the displayable identifier is usable by a mobile information handling system to determine an access password for the information handling system by transmitting the system identifier and the encrypted version of the shared secret to the remote information handling system, the remote information handling system being configured to return the access password to the mobile information handling system in response to a user of the mobile information handling system being included in the data indicative of users authorized to access the information handling system; and
in response to receiving the access password at an input device, the information handling system booting the operating system.
8 . The method of claim 7 , wherein the electronic display device is a monitor.
9 . The method of claim 7 , wherein the input device is a keyboard.
10 . The method of claim 7 , wherein the displayable identifier is displayed by a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS) of the information handling system.
11 . The method of claim 7 , further comprising allowing access to an encrypted storage resource in response to receiving the access password at the input device.
12 . The method of claim 7 , wherein the mobile information handling system is a smartphone.
13 . An article of manufacture comprising a non-transitory, computer-readable medium having computer-executable code thereon that is executable by a processor of an information handling system for:
receiving a shared secret during provisioning, wherein the shared secret is also stored at a remote information handling system, and wherein the remote information handling system stores data indicative of users authorized to access the information handling system;
displaying a displayable identifier on an electronic display device prior to booting an operating system, wherein the displayable identifier encodes information indicative of a system identifier of the information handling system, a time, and an encrypted version of the shared secret, and wherein the displayable identifier is usable by a mobile information handling system to determine an access password for the information handling system by transmitting the system identifier and the encrypted version of the shared secret to the remote information handling system, the remote information handling system being configured to return the access password to the mobile information handling system in response to a user of the mobile information handling system being included in the data indicative of users authorized to access the information handling system; and
in response to receiving the access password at an input device, booting the operating system.
14 . The article of claim 13 , wherein the electronic display device is a monitor.
15 . The article of claim 13 , wherein the input device is a keyboard.
16 . The article of claim 13 , wherein the displayable identifier is displayed by a Unified Extensible Firmware Interface (UEFI) Basic Input/Output System (BIOS) of the information handling system.
17 . The article of claim 13 , wherein the code is further executable for allowing access to an encrypted storage resource in response to receiving the access password at the input device.
18 . The article of claim 13 , wherein the mobile information handling system is a smartphone.