public inbox for devel@edk2.groups.io
 help / color / mirror / Atom feed
* [edk2-platforms] [patch 0/2] Add UserInterfaceFeaturePkg and UserAuthentication modules
@ 2019-06-16  4:25 Dandan Bi
  2019-06-16  4:25 ` [edk2-platforms] [patch 1/2] Platform/Intel: Add UserInterfaceFeaturePkg Dandan Bi
  2019-06-16  4:25 ` [edk2-platforms] [patch 2/2] Platform/Intel/UserInterfaceFeaturePkg: Add UserAuthentication modules Dandan Bi
  0 siblings, 2 replies; 3+ messages in thread
From: Dandan Bi @ 2019-06-16  4:25 UTC (permalink / raw)
  To: devel; +Cc: Eric Dong, Liming

REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1545

Patch1 add a new package UserInterfaceFeaturePkg where put
the UserAuthentication modules into.
Package name follows the discussion in:
https://edk2.groups.io/g/devel/message/42286

Patch 2 add This password based user authentication modules.

Cc: Eric Dong <eric.dong@intel.com>
Cc: Liming Gao <liming.gao@intel.com
Dandan Bi (2):
  Platform/Intel: Add UserInterfaceFeaturePkg
  Platform/Intel/UserInterfaceFeaturePkg: Add UserAuthentication modules

 Maintainers.txt                               |   4 +
 .../Include/Guid/UserAuthentication.h         |  45 +
 .../Include/Library/PlatformPasswordLib.h     |  48 ++
 .../Include/Library/UserPasswordLib.h         |  70 ++
 .../Include/Library/UserPasswordUiLib.h       |  37 +
 .../PlatformPasswordLibNull.c                 |  78 ++
 .../PlatformPasswordLibNull.inf               |  39 +
 .../PlatformPasswordLibNull.uni               |  19 +
 .../Library/UserPasswordLib/UserPasswordLib.c | 274 ++++++
 .../UserPasswordLib/UserPasswordLib.inf       |  37 +
 .../UserPasswordUiLib/UserPasswordUiLib.c     | 522 ++++++++++++
 .../UserPasswordUiLib/UserPasswordUiLib.inf   |  41 +
 .../UserAuthentication/KeyService.c           | 133 +++
 .../UserAuthentication/KeyService.h           |  88 ++
 .../UserAuthentication2Dxe.c                  | 478 +++++++++++
 .../UserAuthentication2Dxe.h                  |  55 ++
 .../UserAuthentication2Dxe.inf                |  53 ++
 .../UserAuthenticationDxe.c                   | 780 ++++++++++++++++++
 .../UserAuthenticationDxe.h                   | 138 ++++
 .../UserAuthenticationDxe.inf                 |  63 ++
 .../UserAuthenticationDxeFormset.h            |  23 +
 .../UserAuthenticationDxePassword.c           | 319 +++++++
 .../UserAuthenticationDxeStrings.uni          |  30 +
 .../UserAuthenticationDxeVfr.vfr              |  39 +
 .../UserAuthenticationSmm.c                   | 674 +++++++++++++++
 .../UserAuthenticationSmm.h                   |  52 ++
 .../UserAuthenticationSmm.inf                 |  53 ++
 .../UserInterfaceFeaturePkg.dec               |  34 +
 .../UserInterfaceFeaturePkg.dsc               |  78 ++
 29 files changed, 4304 insertions(+)
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Guid/UserAuthentication.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/PlatformPasswordLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordUiLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.uni
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeFormset.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxePassword.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeStrings.uni
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeVfr.vfr
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc

-- 
2.18.0.windows.1


^ permalink raw reply	[flat|nested] 3+ messages in thread

* [edk2-platforms] [patch 1/2] Platform/Intel: Add UserInterfaceFeaturePkg
  2019-06-16  4:25 [edk2-platforms] [patch 0/2] Add UserInterfaceFeaturePkg and UserAuthentication modules Dandan Bi
@ 2019-06-16  4:25 ` Dandan Bi
  2019-06-16  4:25 ` [edk2-platforms] [patch 2/2] Platform/Intel/UserInterfaceFeaturePkg: Add UserAuthentication modules Dandan Bi
  1 sibling, 0 replies; 3+ messages in thread
From: Dandan Bi @ 2019-06-16  4:25 UTC (permalink / raw)
  To: devel; +Cc: Eric Dong, Liming Gao

REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1545

Add new package UserInterfaceFeaturePkg in Platform/Intel/
folder. It will keep UI related modules in this package.

We plan add UserAuthentication modules in Platform/Intel.
Firstly we add a new package UserInterfaceFeaturePkg where
add the UserAuthentication modules into.
Package name follows the discussion in:
https://edk2.groups.io/g/devel/message/42286

Cc: Eric Dong <eric.dong@intel.com>
Cc: Liming Gao <liming.gao@intel.com>
Signed-off-by: Dandan Bi <dandan.bi@intel.com>
---
 Maintainers.txt                               |  4 ++++
 .../UserInterfaceFeaturePkg.dec               | 19 +++++++++++++++
 .../UserInterfaceFeaturePkg.dsc               | 23 +++++++++++++++++++
 3 files changed, 46 insertions(+)
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc

diff --git a/Maintainers.txt b/Maintainers.txt
index cb9e15e880..c55a285fa1 100644
--- a/Maintainers.txt
+++ b/Maintainers.txt
@@ -71,10 +71,14 @@ R: Liming Gao <liming.gao@intel.com>
 
 Platform/Intel/DebugFeaturePkg
 M: Eric Dong <eric.dong@intel.com>
 R: Liming Gao <liming.gao@intel.com>
 
+Platform/Intel/UserInterfaceFeaturePkg
+M: Dandan Bi <dandan.bi@intel.com>
+R: Liming Gao <liming.gao@intel.com>
+
 Platform/Intel/ClevoOpenBoardPkg
 M: Michael Kubacki <michael.a.kubacki@intel.com>
 M: Ankit Sinha <ankit.sinha@intel.com>
 M: Nate DeSimone <nathaniel.l.desimone@intel.com>
 
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
new file mode 100644
index 0000000000..7162637e24
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
@@ -0,0 +1,19 @@
+## @file
+# This package provides UI related modules.
+#
+# The DEC files are used by the utilities that parse DSC and
+# INF files to generate AutoGen.c and AutoGen.h files
+# for the build infrastructure.
+#
+# Copyright (c) 2019, Intel Corporation. All rights reserved.<BR>
+#
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  DEC_SPECIFICATION = 0x00010017
+  PACKAGE_NAME      = UserInterfaceFeaturePkg
+  PACKAGE_VERSION   = 0.1
+  PACKAGE_GUID      = 5A92199C-C2ED-4A3F-9ED0-C278DEA0DA47
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc
new file mode 100644
index 0000000000..7098affee9
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc
@@ -0,0 +1,23 @@
+## @file
+# This package provides UI related modules.
+#
+# The DEC files are used by the utilities that parse DSC and
+# INF files to generate AutoGen.c and AutoGen.h files
+# for the build infrastructure.
+#
+# Copyright (c) 2019, Intel Corporation. All rights reserved.<BR>
+#
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  PLATFORM_NAME                  = UserInterfaceFeaturePkg
+  PLATFORM_GUID                  = 66536B4C-84A3-42FD-B0AE-603414A4CE9E
+  PLATFORM_VERSION               = 0.1
+  DSC_SPECIFICATION              = 0x00010005
+  OUTPUT_DIRECTORY               = Build/UserInterfaceFeaturePkg
+  SUPPORTED_ARCHITECTURES        = IA32|X64
+  BUILD_TARGETS                  = DEBUG|RELEASE|NOOPT
+  SKUID_IDENTIFIER               = DEFAULT
+
-- 
2.18.0.windows.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* [edk2-platforms] [patch 2/2] Platform/Intel/UserInterfaceFeaturePkg: Add UserAuthentication modules
  2019-06-16  4:25 [edk2-platforms] [patch 0/2] Add UserInterfaceFeaturePkg and UserAuthentication modules Dandan Bi
  2019-06-16  4:25 ` [edk2-platforms] [patch 1/2] Platform/Intel: Add UserInterfaceFeaturePkg Dandan Bi
@ 2019-06-16  4:25 ` Dandan Bi
  1 sibling, 0 replies; 3+ messages in thread
From: Dandan Bi @ 2019-06-16  4:25 UTC (permalink / raw)
  To: devel; +Cc: Eric Dong, Liming Gao

REF: https://bugzilla.tianocore.org/show_bug.cgi?id=1545

This password based user authentication is to verify user when a user
wants to enter BIOS setup page or enter other boot path.

1. The UserAuthenticationDxe driver registers report status code listener.
When it gets (EFI_SOFTWARE_DXE_BS_DRIVER | EFI_SW_PC_USER_SETUP) progress
code, it will let the user input password, validate and set the password.
It also registers a setup page in setup browser, so that user may update
the password.
UserAuthenticationDxe driver communicates with UserAuthenticationSmm driver
to do the password verification and management.

2. UserAuthentication2Dxe driver only registesr a setup page in setup browser,
so that user may update the password.

UserPasswordLib will provide services to set/verify password.
UserPasswordUiLib will provide services to do password authentication.

3. UserAuthenticationSmm driver registers SMI handler to perform the
request from UserAuthenticationDxe or UserPasswordLib.

If the SMM driver will detect IsPasswordCleared() at the entry point and
clear the password if IsPasswordCleared() is TRUE. This can be used when
the user forgets the password.

4. PlatformPasswordLib LibraryClass provides a platform-specific method
to return password policy.(whether need enroll password or clean password)

Cc: Eric Dong <eric.dong@intel.com>
Cc: Liming Gao <liming.gao@intel.com>
Signed-off-by: Dandan Bi <dandan.bi@intel.com>
---
 .../Include/Guid/UserAuthentication.h         |  45 +
 .../Include/Library/PlatformPasswordLib.h     |  48 ++
 .../Include/Library/UserPasswordLib.h         |  70 ++
 .../Include/Library/UserPasswordUiLib.h       |  37 +
 .../PlatformPasswordLibNull.c                 |  78 ++
 .../PlatformPasswordLibNull.inf               |  39 +
 .../PlatformPasswordLibNull.uni               |  19 +
 .../Library/UserPasswordLib/UserPasswordLib.c | 274 ++++++
 .../UserPasswordLib/UserPasswordLib.inf       |  37 +
 .../UserPasswordUiLib/UserPasswordUiLib.c     | 522 ++++++++++++
 .../UserPasswordUiLib/UserPasswordUiLib.inf   |  41 +
 .../UserAuthentication/KeyService.c           | 133 +++
 .../UserAuthentication/KeyService.h           |  88 ++
 .../UserAuthentication2Dxe.c                  | 478 +++++++++++
 .../UserAuthentication2Dxe.h                  |  55 ++
 .../UserAuthentication2Dxe.inf                |  53 ++
 .../UserAuthenticationDxe.c                   | 780 ++++++++++++++++++
 .../UserAuthenticationDxe.h                   | 138 ++++
 .../UserAuthenticationDxe.inf                 |  63 ++
 .../UserAuthenticationDxeFormset.h            |  23 +
 .../UserAuthenticationDxePassword.c           | 319 +++++++
 .../UserAuthenticationDxeStrings.uni          |  30 +
 .../UserAuthenticationDxeVfr.vfr              |  39 +
 .../UserAuthenticationSmm.c                   | 674 +++++++++++++++
 .../UserAuthenticationSmm.h                   |  52 ++
 .../UserAuthenticationSmm.inf                 |  53 ++
 .../UserInterfaceFeaturePkg.dec               |  15 +
 .../UserInterfaceFeaturePkg.dsc               |  55 ++
 28 files changed, 4258 insertions(+)
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Guid/UserAuthentication.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/PlatformPasswordLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordUiLib.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.uni
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeFormset.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxePassword.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeStrings.uni
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeVfr.vfr
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.c
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.h
 create mode 100644 Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf

diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Include/Guid/UserAuthentication.h b/Platform/Intel/UserInterfaceFeaturePkg/Include/Guid/UserAuthentication.h
new file mode 100644
index 0000000000..c8012c3e4f
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Include/Guid/UserAuthentication.h
@@ -0,0 +1,45 @@
+/** @file
+  GUID is for UserAuthentication SMM communication.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __USER_AUTHENTICATION_GUID_H__
+#define __USER_AUTHENTICATION_GUID_H__
+
+#define PASSWORD_MIN_SIZE    9  // MIN number of chars of password, including NULL.
+#define PASSWORD_MAX_SIZE    33 // MAX number of chars of password, including NULL.
+
+#define USER_AUTHENTICATION_GUID \
+  { 0xf06e3ea7, 0x611c, 0x4b6b, { 0xb4, 0x10, 0xc2, 0xbf, 0x94, 0x3f, 0x38, 0xf2 } }
+
+extern EFI_GUID gUserAuthenticationGuid;
+
+typedef struct {
+  UINTN       Function;
+  EFI_STATUS  ReturnStatus;
+} SMM_PASSWORD_COMMUNICATE_HEADER;
+
+#define SMM_PASSWORD_FUNCTION_IS_PASSWORD_SET       1
+#define SMM_PASSWORD_FUNCTION_SET_PASSWORD          2
+#define SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD       3
+#define SMM_PASSWORD_FUNCTION_SET_VERIFY_POLICY     4
+#define SMM_PASSWORD_FUNCTION_GET_VERIFY_POLICY     5
+#define SMM_PASSWORD_FUNCTION_WAS_PASSWORD_VERIFIED 6
+
+typedef struct {
+  CHAR8                                 NewPassword[PASSWORD_MAX_SIZE];
+  CHAR8                                 OldPassword[PASSWORD_MAX_SIZE];
+} SMM_PASSWORD_COMMUNICATE_SET_PASSWORD;
+
+typedef struct {
+  CHAR8                                 Password[PASSWORD_MAX_SIZE];
+} SMM_PASSWORD_COMMUNICATE_VERIFY_PASSWORD;
+
+typedef struct {
+  BOOLEAN                               NeedReVerify;
+} SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY;
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/PlatformPasswordLib.h b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/PlatformPasswordLib.h
new file mode 100644
index 0000000000..d3aa40e076
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/PlatformPasswordLib.h
@@ -0,0 +1,48 @@
+/** @file
+  Provides a platform-specific method to return password policy.
+
+  Copyright (c) 2017, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __PLATFORM_PASSWORD_LIB_H__
+#define __PLATFORM_PASSWORD_LIB_H__
+
+/**
+  This function is called at password driver entrypoint.
+  This function should be called only once, to clear the password.
+
+  This function provides a way to reset the password, just in case
+  the platform owner forgets the password.
+  The platform should provide a secure way to make sure
+  only the platform owner is allowed to clear password.
+
+  Once the password is cleared, the platform should provide a way
+  to set a new password.
+
+  @retval TRUE  There is a platform request to clear the password.
+  @retval FALSE There is no platform request to clear the password.
+**/
+BOOLEAN
+EFIAPI
+IsPasswordCleared (
+  VOID
+  );
+
+/**
+  This function is called if the password driver finds that the password is not enrolled,
+  when the password is required to input.
+
+  This function should return the action according to platform policy.
+
+  @retval TRUE  The caller should force the user to enroll the password.
+  @retval FALSE The caller may skip the password enroll.
+**/
+BOOLEAN
+EFIAPI
+NeedEnrollPassword (
+  VOID
+  );
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordLib.h b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordLib.h
new file mode 100644
index 0000000000..46be21ce48
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordLib.h
@@ -0,0 +1,70 @@
+/** @file
+  Provides services to set/verify password and return if the password is set.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __USER_PASSWORD_LIB_H__
+#define __USER_PASSWORD_LIB_H__
+
+/**
+  Validate if the password is correct.
+
+  @param[in] Password               The user input password.
+  @param[in] PasswordSize           The size of Password in byte.
+
+  @retval EFI_SUCCESS               The password is correct.
+  @retval EFI_SECURITY_VIOLATION    The password is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to verify the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+**/
+EFI_STATUS
+EFIAPI
+VerifyPassword (
+  IN CHAR16         *Password,
+  IN UINTN          PasswordSize
+  );
+
+/**
+  Set a new password.
+
+  @param[in] NewPassword            The user input new password.
+                                    NULL means clear password.
+  @param[in] NewPasswordSize        The size of NewPassword in byte.
+  @param[in] OldPassword            The user input old password.
+                                    NULL means no old password.
+  @param[in] OldPasswordSize        The size of OldPassword in byte.
+
+  @retval EFI_SUCCESS               The NewPassword is set successfully.
+  @retval EFI_SECURITY_VIOLATION    The OldPassword is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+  @retval EFI_UNSUPPORTED           NewPassword is not strong enough.
+  @retval EFI_ALREADY_STARTED       NewPassword is in history.
+**/
+EFI_STATUS
+EFIAPI
+SetPassword (
+  IN CHAR16         *NewPassword,     OPTIONAL
+  IN UINTN          NewPasswordSize,
+  IN CHAR16         *OldPassword,     OPTIONAL
+  IN UINTN          OldPasswordSize
+  );
+
+/**
+  Return if the password is set.
+
+  @retval TRUE      The password is set.
+  @retval FALSE     The password is not set.
+**/
+BOOLEAN
+EFIAPI
+IsPasswordInstalled (
+  VOID
+  );
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordUiLib.h b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordUiLib.h
new file mode 100644
index 0000000000..a426050d33
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Include/Library/UserPasswordUiLib.h
@@ -0,0 +1,37 @@
+/** @file
+  Provides services to do password authentication.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __USER_PASSWORD_UI_LIB_H__
+#define __USER_PASSWORD_UI_LIB_H__
+
+/**
+  Do password authentication.
+
+  @retval EFI_SUCCESS               Password authentication pass.
+**/
+EFI_STATUS
+EFIAPI
+UiDoPasswordAuthentication (
+  VOID
+  );
+
+/**
+  Set password verification policy.
+
+  @param[in] NeedReVerify           Need re-verify or not.
+
+  @retval EFI_SUCCESS               Set verification policy successfully.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set verification policy.
+**/
+EFI_STATUS
+EFIAPI
+UiSetPasswordVerificationPolicy (
+  IN BOOLEAN    NeedReVerify
+  );
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.c b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.c
new file mode 100644
index 0000000000..18e608f3f1
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.c
@@ -0,0 +1,78 @@
+/** @file
+  NULL PlatformPasswordLib instance does NOT really detect whether the password is cleared
+  but returns the PCD value directly. This instance can be used to verify security
+  related features during platform enabling and development. It should be replaced
+  by a platform-specific method(e.g. Button pressed) in a real platform for product.
+
+  Copyright (c) 2017, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+BOOLEAN       mPasswordCleared      = FALSE;
+
+/**
+  This function is called at password driver entrypoint.
+  This function should be called only once, to clear the password.
+
+  This function provides a way to reset the password, just in case
+  the platform owner forgets the password.
+  The platform should provide a secure way to make sure
+  only the platform owner is allowed to clear password.
+
+  Once the password is cleared, the platform should provide a way
+  to set a new password.
+
+  @retval TRUE  There is a platform request to clear the password.
+  @retval FALSE There is no platform request to clear the password.
+**/
+BOOLEAN
+EFIAPI
+IsPasswordCleared (
+  VOID
+  )
+{
+  return mPasswordCleared;
+}
+
+/**
+  This function is called if the password driver finds that the password is not enrolled,
+  when the password is required to input.
+
+  This function should return the action according to platform policy.
+
+  @retval TRUE  The caller should force the user to enroll the password.
+  @retval FALSE The caller may skip the password enroll.
+**/
+BOOLEAN
+EFIAPI
+NeedEnrollPassword (
+  VOID
+  )
+{
+  return FALSE;
+}
+
+
+/**
+  Save password clear state from a PCD to mPasswordCleared.
+
+  @param  ImageHandle   ImageHandle of the loaded driver.
+  @param  SystemTable   Pointer to the EFI System Table.
+
+  @retval  EFI_SUCCESS          PcdPasswordCleared is got successfully.
+
+**/
+EFI_STATUS
+EFIAPI
+PlatformPasswordLibNullConstructor (
+  IN EFI_HANDLE        ImageHandle,
+  IN EFI_SYSTEM_TABLE  *SystemTable
+  )
+{
+
+  mPasswordCleared = PcdGetBool(PcdPasswordCleared);
+
+  return EFI_SUCCESS;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
new file mode 100644
index 0000000000..cc9ec3dc59
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
@@ -0,0 +1,39 @@
+## @file
+#  NULL platform password library instance that returns the password clear state based upon PCD.
+#
+#  NULL PlatformPasswordLib instance does NOT really detect whether the password is cleared
+#  but returns the PCD value directly. This instance can be used to verify security
+#  related features during platform enabling and development. It should be replaced
+#  by a platform-specific method(e.g. Button pressed) in a real platform for product.
+#
+# Copyright (c) 2017, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  INF_VERSION                    = 0x00010006
+  BASE_NAME                      = PlatformPasswordLibNull
+  MODULE_UNI_FILE                = PlatformPasswordLibNull.uni
+  FILE_GUID                      = 27417BCA-0CCD-4089-9711-AD069A33C555
+  MODULE_TYPE                    = DXE_DRIVER
+  VERSION_STRING                 = 1.0
+  LIBRARY_CLASS                  = PlatformPasswordLib|DXE_RUNTIME_DRIVER DXE_SMM_DRIVER DXE_DRIVER
+  CONSTRUCTOR                    = PlatformPasswordLibNullConstructor
+
+#
+# The following information is for reference only and not required by the build tools.
+#
+#  VALID_ARCHITECTURES           = IA32 X64 EBC
+#
+
+[Sources]
+  PlatformPasswordLibNull.c
+
+[Packages]
+  MdePkg/MdePkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[Pcd]
+  gEfiUserInterfaceFeaturePkgTokenSpaceGuid.PcdPasswordCleared    ## CONSUMES
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.uni b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.uni
new file mode 100644
index 0000000000..8a4904f91a
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.uni
@@ -0,0 +1,19 @@
+// /** @file
+// NULL platform password library instance that returns the password clear state based upon PCD.
+//
+// NULL PlatformPasswordLib instance does NOT really detect whether the password is cleared
+// but returns the PCD value directly. This instance can be used to verify security
+// related features during platform enabling and development. It should be replaced
+// by a platform-specific method(e.g. Button pressed) in a real platform for product.
+//
+// Copyright (c) 2017, Intel Corporation. All rights reserved.<BR>
+//
+// SPDX-License-Identifier: BSD-2-Clause-Patent
+//
+// **/
+
+
+#string STR_MODULE_ABSTRACT             #language en-US "NULL platform password library instance that returns the password clear state based upon PCD."
+
+#string STR_MODULE_DESCRIPTION          #language en-US "NULL PlatformPasswordLib instance does NOT really detect whether the password is cleared but returns the PCD value directly. This instance can be used to verify security related features during platform enabling and development. It should be replaced by a platform-specific method(e.g. Button pressed) in a real platform for product."
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.c b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.c
new file mode 100644
index 0000000000..6bd51995b6
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.c
@@ -0,0 +1,274 @@
+/** @file
+  UserPasswordLib instance implementation provides services to
+  set/verify password and return if the password is set.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include <Protocol/SmmCommunication.h>
+
+#include <Guid/PiSmmCommunicationRegionTable.h>
+#include <Guid/UserAuthentication.h>
+
+#include <Library/DebugLib.h>
+#include <Library/UefiBootServicesTableLib.h>
+#include <Library/UefiLib.h>
+#include <Library/BaseMemoryLib.h>
+
+/**
+  Initialize the communicate buffer using DataSize and Function.
+
+  @param[out]      DataPtr          Points to the data in the communicate buffer.
+  @param[in]       DataSize         The data size to send to SMM.
+  @param[in]       Function         The function number to initialize the communicate header.
+
+  @return Communicate buffer.
+**/
+VOID*
+UserPasswordLibInitCommunicateBuffer (
+  OUT     VOID                              **DataPtr OPTIONAL,
+  IN      UINTN                             DataSize,
+  IN      UINTN                             Function
+  )
+{
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+  VOID                                      *Buffer;
+  EDKII_PI_SMM_COMMUNICATION_REGION_TABLE   *SmmCommRegionTable;
+  EFI_MEMORY_DESCRIPTOR                     *SmmCommMemRegion;
+  UINTN                                     Index;
+  UINTN                                     Size;
+  EFI_STATUS                                Status;
+
+  Buffer = NULL;
+  Status = EfiGetSystemConfigurationTable (
+             &gEdkiiPiSmmCommunicationRegionTableGuid,
+             (VOID **) &SmmCommRegionTable
+             );
+  if (EFI_ERROR (Status)) {
+    return NULL;
+  }
+  ASSERT (SmmCommRegionTable != NULL);
+  SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) (SmmCommRegionTable + 1);
+  Size = 0;
+  for (Index = 0; Index < SmmCommRegionTable->NumberOfEntries; Index++) {
+    if (SmmCommMemRegion->Type == EfiConventionalMemory) {
+      Size = EFI_PAGES_TO_SIZE ((UINTN) SmmCommMemRegion->NumberOfPages);
+      if (Size >= (DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER))) {
+        break;
+      }
+    }
+    SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) ((UINT8 *) SmmCommMemRegion + SmmCommRegionTable->DescriptorSize);
+  }
+  ASSERT (Index < SmmCommRegionTable->NumberOfEntries);
+
+  Buffer = (VOID*)(UINTN)SmmCommMemRegion->PhysicalStart;
+  ASSERT (Buffer != NULL);
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  CopyGuid (&SmmCommunicateHeader->HeaderGuid, &gUserAuthenticationGuid);
+  SmmCommunicateHeader->MessageLength = DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *) SmmCommunicateHeader->Data;
+  ZeroMem (SmmPasswordFunctionHeader, DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER));
+  SmmPasswordFunctionHeader->Function = Function;
+  if (DataPtr != NULL) {
+    *DataPtr = SmmPasswordFunctionHeader + 1;
+  }
+
+  return Buffer;
+}
+
+/**
+  Send the data in communicate buffer to SMM.
+
+  @param[in]   Buffer                 Points to the data in the communicate buffer.
+  @param[in]   DataSize               The data size to send to SMM.
+
+  @retval      EFI_SUCCESS            Success is returned from the function in SMM.
+  @retval      Others                 Failure is returned from the function in SMM.
+
+**/
+EFI_STATUS
+UserPasswordLibSendCommunicateBuffer (
+  IN      VOID                              *Buffer,
+  IN      UINTN                             DataSize
+  )
+{
+  EFI_STATUS                                Status;
+  UINTN                                     CommSize;
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+  EFI_SMM_COMMUNICATION_PROTOCOL            *SmmCommunication;
+
+  //
+  // Locates SMM Communication protocol.
+  //
+  Status = gBS->LocateProtocol (&gEfiSmmCommunicationProtocolGuid, NULL, (VOID **) &SmmCommunication);
+  ASSERT_EFI_ERROR (Status);
+
+  CommSize = DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  Status = SmmCommunication->Communicate (SmmCommunication, Buffer, &CommSize);
+  ASSERT_EFI_ERROR (Status);
+
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *)SmmCommunicateHeader->Data;
+  return SmmPasswordFunctionHeader->ReturnStatus;
+}
+
+/**
+  Validate if the password is correct.
+
+  @param[in] Password               The user input password.
+  @param[in] PasswordSize           The size of Password in byte.
+
+  @retval EFI_SUCCESS               The password is correct.
+  @retval EFI_SECURITY_VIOLATION    The password is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to verify the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+**/
+EFI_STATUS
+EFIAPI
+VerifyPassword (
+  IN   CHAR16       *Password,
+  IN   UINTN        PasswordSize
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_PASSWORD  *VerifyPassword;
+
+  ASSERT (Password != NULL);
+
+  if (PasswordSize > sizeof(VerifyPassword->Password) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  Buffer = UserPasswordLibInitCommunicateBuffer (
+             (VOID**)&VerifyPassword,
+             sizeof(*VerifyPassword),
+             SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  Status = UnicodeStrToAsciiStrS (Password, VerifyPassword->Password, sizeof(VerifyPassword->Password));
+  if (EFI_ERROR(Status)) {
+    goto EXIT;
+  }
+
+  Status = UserPasswordLibSendCommunicateBuffer (Buffer, sizeof(*VerifyPassword));
+
+EXIT:
+  ZeroMem (VerifyPassword, sizeof(*VerifyPassword));
+  return Status;
+}
+
+/**
+  Set a new password.
+
+  @param[in] NewPassword            The user input new password.
+                                    NULL means clear password.
+  @param[in] NewPasswordSize        The size of NewPassword in byte.
+  @param[in] OldPassword            The user input old password.
+                                    NULL means no old password.
+  @param[in] OldPasswordSize        The size of OldPassword in byte.
+
+  @retval EFI_SUCCESS               The NewPassword is set successfully.
+  @retval EFI_SECURITY_VIOLATION    The OldPassword is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+  @retval EFI_UNSUPPORTED           NewPassword is not strong enough.
+  @retval EFI_ALREADY_STARTED       NewPassword is in history.
+**/
+EFI_STATUS
+EFIAPI
+SetPassword (
+  IN   CHAR16       *NewPassword,     OPTIONAL
+  IN   UINTN        NewPasswordSize,
+  IN   CHAR16       *OldPassword,     OPTIONAL
+  IN   UINTN        OldPasswordSize
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+  SMM_PASSWORD_COMMUNICATE_SET_PASSWORD     *SetPassword;
+
+  if (NewPasswordSize > sizeof(SetPassword->NewPassword) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+  if (OldPasswordSize > sizeof(SetPassword->OldPassword) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  Buffer = UserPasswordLibInitCommunicateBuffer (
+             (VOID**)&SetPassword,
+             sizeof(*SetPassword),
+             SMM_PASSWORD_FUNCTION_SET_PASSWORD
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  if (NewPassword != NULL) {
+    Status = UnicodeStrToAsciiStrS (NewPassword, SetPassword->NewPassword, sizeof(SetPassword->NewPassword));
+    if (EFI_ERROR(Status)) {
+      goto EXIT;
+    }
+  } else {
+    SetPassword->NewPassword[0] = 0;
+  }
+
+  if (OldPassword != NULL) {
+    Status = UnicodeStrToAsciiStrS (OldPassword, SetPassword->OldPassword, sizeof(SetPassword->OldPassword));
+    if (EFI_ERROR(Status)) {
+      goto EXIT;
+    }
+  } else {
+    SetPassword->OldPassword[0] = 0;
+  }
+
+  Status = UserPasswordLibSendCommunicateBuffer (Buffer, sizeof(*SetPassword));
+
+EXIT:
+  ZeroMem (SetPassword, sizeof(*SetPassword));
+  return Status;
+}
+
+/**
+  Return if the password is set.
+
+  @retval TRUE      The password is set.
+  @retval FALSE     The password is not set.
+**/
+BOOLEAN
+EFIAPI
+IsPasswordInstalled (
+  VOID
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+
+  Buffer = UserPasswordLibInitCommunicateBuffer (
+             NULL,
+             0,
+             SMM_PASSWORD_FUNCTION_IS_PASSWORD_SET
+             );
+  if (Buffer == NULL) {
+    return FALSE;
+  }
+
+  Status = UserPasswordLibSendCommunicateBuffer (Buffer, 0);
+  if (EFI_ERROR (Status)) {
+    return FALSE;
+  }
+
+  return TRUE;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
new file mode 100644
index 0000000000..be8cd5a8a8
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
@@ -0,0 +1,37 @@
+## @file
+#  UserPasswordLib instance provides services to set/verify password
+#  and return if the password is set.
+#
+# Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  INF_VERSION                    = 0x00010005
+  BASE_NAME                      = UserPasswordLib
+  FILE_GUID                      = 422BA58A-F162-4ECC-BD9A-AD84FE940F37
+  MODULE_TYPE                    = DXE_DRIVER
+  VERSION_STRING                 = 1.0
+  LIBRARY_CLASS                  = UserPasswordLib|DXE_RUNTIME_DRIVER DXE_SMM_DRIVER DXE_DRIVER UEFI_APPLICATION
+
+[Sources]
+  UserPasswordLib.c
+
+[Packages]
+  MdePkg/MdePkg.dec
+  MdeModulePkg/MdeModulePkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[LibraryClasses]
+  UefiBootServicesTableLib
+  DebugLib
+  UefiLib
+  BaseMemoryLib
+
+[Guids]
+  gUserAuthenticationGuid                       ## CONSUMES  ## GUID
+  gEdkiiPiSmmCommunicationRegionTableGuid       ## CONSUMES  ## SystemTable
+
+[Protocols]
+  gEfiSmmCommunicationProtocolGuid              ## CONSUMES
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.c b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.c
new file mode 100644
index 0000000000..7edf2af954
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.c
@@ -0,0 +1,522 @@
+/** @file
+  UserPasswordUiLib instance provides services to do password authentication.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include <Protocol/SmmCommunication.h>
+
+#include <Guid/PiSmmCommunicationRegionTable.h>
+#include <Guid/UserAuthentication.h>
+
+#include <Library/UefiBootServicesTableLib.h>
+#include <Library/UefiRuntimeServicesTableLib.h>
+#include <Library/DebugLib.h>
+#include <Library/UefiLib.h>
+#include <Library/MemoryAllocationLib.h>
+#include <Library/BaseMemoryLib.h>
+#include <Library/PrintLib.h>
+#include <Library/PlatformPasswordLib.h>
+#include <Library/UserPasswordLib.h>
+
+/**
+  Initialize the communicate buffer using DataSize and Function.
+
+  @param[out]      DataPtr          Points to the data in the communicate buffer.
+  @param[in]       DataSize         The data size to send to SMM.
+  @param[in]       Function         The function number to initialize the communicate header.
+
+  @return Communicate buffer.
+**/
+VOID*
+UserPasswordUiLibInitCommunicateBuffer (
+  OUT     VOID                              **DataPtr OPTIONAL,
+  IN      UINTN                             DataSize,
+  IN      UINTN                             Function
+  )
+{
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+  VOID                                      *Buffer;
+  EDKII_PI_SMM_COMMUNICATION_REGION_TABLE   *SmmCommRegionTable;
+  EFI_MEMORY_DESCRIPTOR                     *SmmCommMemRegion;
+  UINTN                                     Index;
+  UINTN                                     Size;
+  EFI_STATUS                                Status;
+
+  Buffer = NULL;
+  Status = EfiGetSystemConfigurationTable (
+             &gEdkiiPiSmmCommunicationRegionTableGuid,
+             (VOID **) &SmmCommRegionTable
+             );
+  if (EFI_ERROR (Status)) {
+    return NULL;
+  }
+  ASSERT (SmmCommRegionTable != NULL);
+  SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) (SmmCommRegionTable + 1);
+  Size = 0;
+  for (Index = 0; Index < SmmCommRegionTable->NumberOfEntries; Index++) {
+    if (SmmCommMemRegion->Type == EfiConventionalMemory) {
+      Size = EFI_PAGES_TO_SIZE ((UINTN) SmmCommMemRegion->NumberOfPages);
+      if (Size >= (DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER))) {
+        break;
+      }
+    }
+    SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) ((UINT8 *) SmmCommMemRegion + SmmCommRegionTable->DescriptorSize);
+  }
+  ASSERT (Index < SmmCommRegionTable->NumberOfEntries);
+
+  Buffer = (VOID*)(UINTN)SmmCommMemRegion->PhysicalStart;
+  ASSERT (Buffer != NULL);
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  CopyGuid (&SmmCommunicateHeader->HeaderGuid, &gUserAuthenticationGuid);
+  SmmCommunicateHeader->MessageLength = DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *) SmmCommunicateHeader->Data;
+  ZeroMem (SmmPasswordFunctionHeader, DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER));
+  SmmPasswordFunctionHeader->Function = Function;
+  if (DataPtr != NULL) {
+    *DataPtr = SmmPasswordFunctionHeader + 1;
+  }
+
+  return Buffer;
+}
+
+/**
+  Send the data in communicate buffer to SMM.
+
+  @param[in]   Buffer                 Points to the data in the communicate buffer.
+  @param[in]   DataSize               The data size to send to SMM.
+
+  @retval      EFI_SUCCESS            Success is returned from the function in SMM.
+  @retval      Others                 Failure is returned from the function in SMM.
+
+**/
+EFI_STATUS
+UserPasswordUiLibSendCommunicateBuffer (
+  IN      VOID                              *Buffer,
+  IN      UINTN                             DataSize
+  )
+{
+  EFI_STATUS                                Status;
+  UINTN                                     CommSize;
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+  EFI_SMM_COMMUNICATION_PROTOCOL            *SmmCommunication;
+
+  //
+  // Locates SMM Communication protocol.
+  //
+  Status = gBS->LocateProtocol (&gEfiSmmCommunicationProtocolGuid, NULL, (VOID **) &SmmCommunication);
+  ASSERT_EFI_ERROR (Status);
+
+  CommSize = DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  Status = SmmCommunication->Communicate (SmmCommunication, Buffer, &CommSize);
+  ASSERT_EFI_ERROR (Status);
+
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *)SmmCommunicateHeader->Data;
+  return SmmPasswordFunctionHeader->ReturnStatus;
+}
+
+/**
+  Set password verification policy.
+
+  @param[in] NeedReVerify           Need re-verify or not.
+
+  @retval EFI_SUCCESS               Set verification policy successfully.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set verification policy.
+**/
+EFI_STATUS
+EFIAPI
+UiSetPasswordVerificationPolicy (
+  IN BOOLEAN    NeedReVerify
+  )
+{
+  VOID                                      *Buffer;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    *SetVerifyPolicy;
+
+  Buffer = UserPasswordUiLibInitCommunicateBuffer (
+             (VOID**)&SetVerifyPolicy,
+             sizeof(*SetVerifyPolicy),
+             SMM_PASSWORD_FUNCTION_SET_VERIFY_POLICY
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  SetVerifyPolicy->NeedReVerify = NeedReVerify;
+
+  return UserPasswordUiLibSendCommunicateBuffer (Buffer, sizeof(*SetVerifyPolicy));
+}
+
+/**
+  Get a user input string.
+
+  @param[in]       PopUpString      A popup string to inform user.
+  @param[in, out]  UserInput        The user input string
+  @param[in]       UserInputMaxLen  The max unicode count of the UserInput without NULL terminator.
+**/
+EFI_STATUS
+GetUserInput (
+  IN     CHAR16      *PopUpString,
+  IN OUT CHAR16      *UserInput,
+  IN     UINTN       UserInputMaxLen
+  )
+{
+  EFI_INPUT_KEY                InputKey;
+  UINTN                        InputLength;
+  CHAR16                       *Mask;
+
+  UserInput[0] = 0;
+  Mask = AllocateZeroPool ((UserInputMaxLen + 1) * sizeof(CHAR16));
+  if (Mask == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  InputLength = 0;
+
+  while (TRUE) {
+    if (InputLength < UserInputMaxLen) {
+      Mask[InputLength] = L'_';
+    }
+    CreatePopUp (
+      EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+      &InputKey,
+      PopUpString,
+      L"--------------------------------",
+      Mask,
+      NULL
+      );
+    if (InputKey.ScanCode == SCAN_NULL) {
+      //
+      // Check whether finish inputing password.
+      //
+      if (InputKey.UnicodeChar == CHAR_CARRIAGE_RETURN && InputLength > 0) {
+        //
+        // Add the null terminator.
+        //
+        UserInput[InputLength] = 0;
+        break;
+      } else if ((InputKey.UnicodeChar == CHAR_NULL) ||
+                 (InputKey.UnicodeChar == CHAR_LINEFEED) ||
+                 (InputKey.UnicodeChar == CHAR_CARRIAGE_RETURN)
+                ) {
+        continue;
+      } else {
+        //
+        // delete last key entered
+        //
+        if (InputKey.UnicodeChar == CHAR_BACKSPACE) {
+          if (InputLength > 0) {
+            UserInput[InputLength] = 0;
+            Mask[InputLength] = 0;
+            InputLength--;
+          }
+        } else {
+          if (InputLength == UserInputMaxLen) {
+            Mask[InputLength] = 0;
+            continue;
+          }
+          //
+          // add Next key entry
+          //
+          UserInput[InputLength] = InputKey.UnicodeChar;
+          Mask[InputLength] = L'*';
+          InputLength++;
+        }
+      }
+    }
+  }
+  FreePool (Mask);
+  return EFI_SUCCESS;
+}
+
+/**
+  Display a message box to end user.
+
+  @param[in] DisplayString   The string in message box.
+**/
+VOID
+MessageBox (
+  IN CHAR16  *DisplayString
+  )
+{
+  EFI_INPUT_KEY  Key;
+
+  do {
+    CreatePopUp (
+      EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+      &Key,
+      L"",
+      DisplayString,
+      L"Press ENTER to continue ...",
+      L"",
+      NULL
+      );
+  } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+}
+
+/**
+  Force system reset.
+**/
+VOID
+ForceSystemReset (
+  VOID
+  )
+{
+  MessageBox (L"Password retry count reach, reset system!");
+  gRT->ResetSystem (EfiResetCold, EFI_SUCCESS, 0, NULL);
+  CpuDeadLoop();
+}
+
+/**
+  Display message for set password.
+
+  @param[in]  ReturnStatus   The return status for set password.
+**/
+VOID
+PrintSetPasswordStatus (
+  IN EFI_STATUS  ReturnStatus
+  )
+{
+  CHAR16         *DisplayString;
+  CHAR16         *DisplayString2;
+
+  EFI_INPUT_KEY  Key;
+
+  if (ReturnStatus == EFI_UNSUPPORTED) {
+    DisplayString  = L"New password is not strong enough!";
+    DisplayString2 = L"Password must at least 8 chars and include lowercase, uppercase alphabetic, number and symbol";
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        DisplayString2,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  } else {
+    if (ReturnStatus == EFI_SUCCESS) {
+      DisplayString = L"New password is updated successfully!";
+    } else if (ReturnStatus == EFI_ALREADY_STARTED) {
+      DisplayString = L"New password is found in the history passwords!";
+    } else {
+      DisplayString = L"New password update fails!";
+    }
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  }
+}
+
+/**
+  Get password verification policy.
+
+  @param[out] VerifyPolicy          Verification policy.
+
+  @retval EFI_SUCCESS               Get verification policy successfully.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to get verification policy.
+**/
+EFI_STATUS
+GetPasswordVerificationPolicy (
+  OUT SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    *VerifyPolicy
+  )
+{
+  EFI_STATUS                                    Status;
+  VOID                                          *Buffer;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY        *TempVerifyPolicy;
+
+  Buffer = UserPasswordUiLibInitCommunicateBuffer (
+             (VOID**)&TempVerifyPolicy,
+             sizeof(*TempVerifyPolicy),
+             SMM_PASSWORD_FUNCTION_GET_VERIFY_POLICY
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  Status = UserPasswordUiLibSendCommunicateBuffer (Buffer, sizeof(*TempVerifyPolicy));
+  if (!EFI_ERROR (Status)) {
+    CopyMem (VerifyPolicy, TempVerifyPolicy, sizeof (SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY));
+  }
+
+  return Status;
+}
+
+/**
+  Return if the password was verified.
+
+  @retval TRUE      The password was verified.
+  @retval FALSE     The password was not verified.
+**/
+BOOLEAN
+WasPasswordVerified (
+  VOID
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+
+  Buffer = UserPasswordUiLibInitCommunicateBuffer (
+             NULL,
+             0,
+             SMM_PASSWORD_FUNCTION_WAS_PASSWORD_VERIFIED
+             );
+  if (Buffer == NULL) {
+    return FALSE;
+  }
+
+  Status = UserPasswordUiLibSendCommunicateBuffer (Buffer, 0);
+  if (EFI_ERROR (Status)) {
+    return FALSE;
+  }
+
+  return TRUE;
+}
+
+/**
+  Require user input password.
+
+  @retval TRUE   User input correct password successfully.
+  @retval FALSE  The password is not set.
+**/
+BOOLEAN
+RequireUserPassword (
+  VOID
+  )
+{
+  EFI_STATUS                                Status;
+  CHAR16                                    UserInputPw[PASSWORD_MAX_SIZE];
+  CHAR16                                    *PopUpString;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    VerifyPolicy;
+
+  Status = EFI_SUCCESS;
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+
+  if (!IsPasswordInstalled ()) {
+    return FALSE;
+  }
+
+  Status = GetPasswordVerificationPolicy (&VerifyPolicy);
+  if (!EFI_ERROR (Status)) {
+    if (WasPasswordVerified() && (!VerifyPolicy.NeedReVerify)) {
+      DEBUG ((DEBUG_INFO, "Password was verified and Re-verify is not needed\n"));
+      return TRUE;
+    }
+  }
+
+  PopUpString = L"Please input admin password";
+
+  while (TRUE) {
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString, UserInputPw, PASSWORD_MAX_SIZE - 1);
+
+    Status = VerifyPassword (UserInputPw, StrSize(UserInputPw));
+    if (!EFI_ERROR(Status)) {
+      break;
+    }
+    if (Status == EFI_ACCESS_DENIED) {
+      //
+      // Password retry count reach.
+      //
+      ForceSystemReset ();
+    }
+    MessageBox (L"Incorrect password!");
+  }
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+
+  gST->ConOut->ClearScreen(gST->ConOut);
+
+  return TRUE;
+}
+
+/**
+  Set user password.
+
+**/
+VOID
+SetUserPassword (
+  VOID
+  )
+{
+  EFI_STATUS                   Status;
+  CHAR16                       UserInputPw[PASSWORD_MAX_SIZE];
+  CHAR16                       TmpPassword[PASSWORD_MAX_SIZE];
+  CHAR16                       *PopUpString;
+  CHAR16                       *PopUpString2;
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+  ZeroMem(TmpPassword, sizeof(TmpPassword));
+
+  PopUpString = L"Please set admin password";
+
+  while (TRUE) {
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString, UserInputPw, PASSWORD_MAX_SIZE - 1);
+
+    PopUpString2 = L"Please confirm your new password";
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString2, TmpPassword, PASSWORD_MAX_SIZE - 1);
+    if (StrCmp (TmpPassword, UserInputPw) != 0) {
+      MessageBox (L"Password are not the same!");
+      continue;
+    }
+
+    Status = SetPassword (UserInputPw, StrSize(UserInputPw), NULL, 0);
+    PrintSetPasswordStatus (Status);
+    if (!EFI_ERROR(Status)) {
+      break;
+    }
+  }
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+  ZeroMem(TmpPassword, sizeof(TmpPassword));
+
+  gST->ConOut->ClearScreen(gST->ConOut);
+}
+
+/**
+  Do password authentication.
+
+  @retval EFI_SUCCESS               Password authentication pass.
+**/
+EFI_STATUS
+EFIAPI
+UiDoPasswordAuthentication (
+  VOID
+  )
+{
+  BOOLEAN   PasswordSet;
+
+  PasswordSet = RequireUserPassword ();
+  if (PasswordSet) {
+    DEBUG ((DEBUG_INFO, "Welcome Admin!\n"));
+  } else {
+    DEBUG ((DEBUG_INFO, "Admin password is not set!\n"));
+    if (NeedEnrollPassword()) {
+      SetUserPassword ();
+    }
+  }
+
+  return EFI_SUCCESS;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf
new file mode 100644
index 0000000000..5126115ca4
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf
@@ -0,0 +1,41 @@
+## @file
+#  UserPasswordUiLib instance provides services to do password authentication.
+#
+# Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  INF_VERSION                    = 0x00010005
+  BASE_NAME                      = UserPasswordUiLib
+  FILE_GUID                      = E2E92636-F511-46BC-A08B-02F815AFA884
+  MODULE_TYPE                    = DXE_DRIVER
+  VERSION_STRING                 = 1.0
+  LIBRARY_CLASS                  = UserPasswordUiLib|DXE_RUNTIME_DRIVER DXE_SMM_DRIVER DXE_DRIVER UEFI_APPLICATION
+
+[Sources]
+  UserPasswordUiLib.c
+
+[Packages]
+  MdePkg/MdePkg.dec
+  MdeModulePkg/MdeModulePkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[LibraryClasses]
+  UefiBootServicesTableLib
+  UefiRuntimeServicesTableLib
+  DebugLib
+  UefiLib
+  MemoryAllocationLib
+  BaseMemoryLib
+  PrintLib
+  PlatformPasswordLib
+  UserPasswordLib
+
+[Guids]
+  gUserAuthenticationGuid                       ## CONSUMES  ## GUID
+  gEdkiiPiSmmCommunicationRegionTableGuid       ## CONSUMES  ## SystemTable
+
+[Protocols]
+  gEfiSmmCommunicationProtocolGuid              ## CONSUMES
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.c b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.c
new file mode 100644
index 0000000000..d1f87c787b
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.c
@@ -0,0 +1,133 @@
+/** @file
+  Password key service.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include <Uefi.h>
+#include <Library/DebugLib.h>
+#include <Library/MemoryAllocationLib.h>
+#include <Library/BaseCryptLib.h>
+#include "KeyService.h"
+
+/**
+  Compares the contents of two buffers with slow algorithm
+
+  This function compares Length bytes of SourceBuffer to Length bytes of DestinationBuffer.
+  If all Length bytes of the two buffers are identical, then 0 is returned.  Otherwise, the
+  value returned is the first mismatched byte in SourceBuffer subtracted from the first
+  mismatched byte in DestinationBuffer.
+
+  If Length > 0 and DestinationBuffer is NULL, then ASSERT().
+  If Length > 0 and SourceBuffer is NULL, then ASSERT().
+  If Length is greater than (MAX_ADDRESS - DestinationBuffer + 1), then ASSERT().
+  If Length is greater than (MAX_ADDRESS - SourceBuffer + 1), then ASSERT().
+
+  @param  DestinationBuffer The pointer to the destination buffer to compare.
+  @param  SourceBuffer      The pointer to the source buffer to compare.
+  @param  Length            The number of bytes to compare.
+
+  @return 0                 All Length bytes of the two buffers are identical.
+  @retval -1                The SourceBuffer is not identical to DestinationBuffer.
+
+**/
+INTN
+EFIAPI
+KeyLibSlowCompareMem (
+  IN CONST VOID  *DestinationBuffer,
+  IN CONST VOID  *SourceBuffer,
+  IN UINTN       Length
+  )
+{
+  UINT8  Delta;
+  UINTN  Index;
+  UINT8  *Destination;
+  UINT8  *Source;
+
+  Destination = (UINT8 *)DestinationBuffer;
+  Source = (UINT8 *)SourceBuffer;
+  Delta = 0;
+  for (Index = 0; Index < Length; Index++) {
+    Delta |= Destination[Index] ^ Source[Index];
+  }
+  if (Delta == 0) {
+    return 0;
+  } else {
+    return -1;
+  }
+}
+
+/**
+  Generate Salt value.
+
+  @param[in, out]   SaltValue           Points to the salt buffer
+  @param[in]        SaltSize            Size of the salt buffer
+
+  @retval      TRUE           Salt is generated.
+  @retval      FALSE          Salt is not generated.
+**/
+BOOLEAN
+EFIAPI
+KeyLibGenerateSalt (
+  IN OUT UINT8  *SaltValue,
+  IN UINTN      SaltSize
+  )
+{
+  if (SaltValue == NULL) {
+    return FALSE;
+  }
+  RandomSeed(NULL, 0);
+  RandomBytes(SaltValue, SaltSize);
+  return TRUE;
+}
+
+/**
+  Hash the password with PBKDF2.
+
+  @param[in]   HashType         Hash type
+  @param[in]   Key              Points to the key buffer
+  @param[in]   KeySize          Key buffer size
+  @param[in]   SaltValue        Points to the salt buffer
+  @param[in]   SaltSize         Size of the salt buffer
+  @param[out]  KeyHash          Points to the hashed result
+  @param[in]   KeyHashSize      Size of the hash buffer
+
+  @retval      TRUE           Hash the data successfully.
+  @retval      FALSE          Failed to hash the data.
+
+**/
+BOOLEAN
+EFIAPI
+KeyLibGeneratePBKDF2Hash (
+  IN   UINT32              HashType,
+  IN   VOID                *Key,
+  IN   UINTN               KeySize,
+  IN   UINT8               *SaltValue,
+  IN   UINTN               SaltSize,
+  OUT  UINT8               *KeyHash,
+  IN   UINTN               KeyHashSize
+  )
+{
+  BOOLEAN  Result;
+
+  if (HashType != HASH_TYPE_SHA256) {
+    return FALSE;
+  }
+  if (KeyHashSize != SHA256_DIGEST_SIZE) {
+    return FALSE;
+  }
+
+  Result = Pkcs5HashPassword (
+             KeySize,
+             Key,
+             SaltSize,
+             SaltValue,
+             DEFAULT_PBKDF2_ITERATION_COUNT,
+             SHA256_DIGEST_SIZE,
+             KeyHashSize,
+             KeyHash
+             );
+  return Result;
+}
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.h b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.h
new file mode 100644
index 0000000000..9b16b1bdbd
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/KeyService.h
@@ -0,0 +1,88 @@
+/** @file
+  Header file for key service.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __KEY_LIB_H__
+#define __KEY_LIB_H__
+
+/**
+  Compares the contents of two buffers with slow algorithm
+
+  This function compares Length bytes of SourceBuffer to Length bytes of DestinationBuffer.
+  If all Length bytes of the two buffers are identical, then 0 is returned.  Otherwise, the
+  value returned is the first mismatched byte in SourceBuffer subtracted from the first
+  mismatched byte in DestinationBuffer.
+
+  If Length > 0 and DestinationBuffer is NULL, then ASSERT().
+  If Length > 0 and SourceBuffer is NULL, then ASSERT().
+  If Length is greater than (MAX_ADDRESS - DestinationBuffer + 1), then ASSERT().
+  If Length is greater than (MAX_ADDRESS - SourceBuffer + 1), then ASSERT().
+
+  @param  DestinationBuffer The pointer to the destination buffer to compare.
+  @param  SourceBuffer      The pointer to the source buffer to compare.
+  @param  Length            The number of bytes to compare.
+
+  @return 0                 All Length bytes of the two buffers are identical.
+  @retval -1                The SourceBuffer is not identical to DestinationBuffer.
+
+**/
+INTN
+EFIAPI
+KeyLibSlowCompareMem (
+  IN CONST VOID  *DestinationBuffer,
+  IN CONST VOID  *SourceBuffer,
+  IN UINTN       Length
+  );
+
+/**
+  Generate Salt value.
+
+  @param[in, out]   SaltValue           Points to the salt buffer
+  @param[in]        SaltSize            Size of the salt buffer
+
+  @retval      TRUE           Salt is generated.
+  @retval      FALSE          Salt is not generated.
+**/
+BOOLEAN
+EFIAPI
+KeyLibGenerateSalt(
+  IN OUT UINT8  *SaltValue,
+  IN UINTN      SaltSize
+  );
+
+#define HASH_TYPE_SHA256                0x000B
+#define DEFAULT_PBKDF2_ITERATION_COUNT  1000
+
+/**
+  Hash the password with PBKDF2.
+
+  @param[in]   HashType         Hash type
+  @param[in]   Key              Points to the key buffer
+  @param[in]   KeySize          Key buffer size
+  @param[in]   SaltValue        Points to the salt buffer
+  @param[in]   SaltSize         Size of the salt buffer
+  @param[out]  KeyHash          Points to the hashed result
+  @param[in]   KeyHashSize      Size of the hash buffer
+
+  @retval      TRUE           Hash the data successfully.
+  @retval      FALSE          Failed to hash the data.
+
+**/
+BOOLEAN
+EFIAPI
+KeyLibGeneratePBKDF2Hash (
+  IN   UINT32              HashType,
+  IN   VOID                *Key,
+  IN   UINTN               KeySize,
+  IN   UINT8               *SaltValue,
+  IN   UINTN               SaltSize,
+  OUT  UINT8               *KeyHash,
+  IN   UINTN               KeyHashSize
+  );
+
+#endif
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.c b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.c
new file mode 100644
index 0000000000..82f9494333
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.c
@@ -0,0 +1,478 @@
+/** @file
+  This Driver mainly provides Setup Form to change password.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include "UserAuthentication2Dxe.h"
+
+USER_AUTHENTICATION_PRIVATE_DATA   *mUserAuthenticationData = NULL;
+
+EFI_GUID mUserAuthenticationVendorGuid = USER_AUTHENTICATION_FORMSET_GUID;
+HII_VENDOR_DEVICE_PATH mHiiVendorDevicePath = {
+  {
+    {
+      HARDWARE_DEVICE_PATH,
+      HW_VENDOR_DP,
+      {
+        (UINT8) (sizeof (VENDOR_DEVICE_PATH)),
+        (UINT8) ((sizeof (VENDOR_DEVICE_PATH)) >> 8)
+      }
+    },
+    USER_AUTHENTICATION_FORMSET_GUID
+  },
+  {
+    END_DEVICE_PATH_TYPE,
+    END_ENTIRE_DEVICE_PATH_SUBTYPE,
+    {
+      (UINT8) (END_DEVICE_PATH_LENGTH),
+      (UINT8) ((END_DEVICE_PATH_LENGTH) >> 8)
+    }
+  }
+};
+
+/**
+  Display a message box to end user.
+
+  @param[in] DisplayString   The string in message box.
+**/
+VOID
+MessageBox (
+  IN CHAR16  *DisplayString
+  )
+{
+  EFI_INPUT_KEY  Key;
+
+  do {
+    CreatePopUp (
+      EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+      &Key,
+      L"",
+      DisplayString,
+      L"Press ENTER to continue ...",
+      L"",
+      NULL
+      );
+  } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+}
+
+/**
+  Force system reset.
+**/
+VOID
+ForceSystemReset (
+  VOID
+  )
+{
+  MessageBox (L"Password retry count reach, reset system!");
+  gRT->ResetSystem (EfiResetCold, EFI_SUCCESS, 0, NULL);
+  CpuDeadLoop();
+}
+
+/**
+  Display message for set password.
+
+  @param[in]  ReturnStatus   The return status for set password.
+**/
+VOID
+PrintSetPasswordStatus (
+  IN EFI_STATUS  ReturnStatus
+  )
+{
+  CHAR16         *DisplayString;
+  CHAR16         *DisplayString2;
+
+  EFI_INPUT_KEY  Key;
+
+  if (ReturnStatus == EFI_UNSUPPORTED) {
+    DisplayString  = L"New password is not strong enough!";
+    DisplayString2 = L"Password must at least 8 chars and include lowercase, uppercase alphabetic, number and symbol";
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        DisplayString2,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  } else {
+    if (ReturnStatus == EFI_SUCCESS) {
+      DisplayString = L"New password is updated successfully!";
+    } else if (ReturnStatus == EFI_ALREADY_STARTED) {
+      DisplayString = L"New password is found in the history passwords!";
+    } else {
+      DisplayString = L"New password update fails!";
+    }
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  }
+}
+
+/**
+  This function allows a caller to extract the current configuration for one
+  or more named elements from the target driver.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Request                A null-terminated Unicode string in
+                                 <ConfigRequest> format.
+  @param  Progress               On return, points to a character in the Request
+                                 string. Points to the string's null terminator if
+                                 request was successful. Points to the most recent
+                                 '&' before the first failing name/value pair (or
+                                 the beginning of the string if the failure is in
+                                 the first name/value pair) if the request was not
+                                 successful.
+  @param  Results                A null-terminated Unicode string in
+                                 <ConfigAltResp> format which has all values filled
+                                 in for the names in the Request string. String to
+                                 be allocated by the called function.
+
+  @retval EFI_SUCCESS            The Results is filled with the requested values.
+  @retval EFI_OUT_OF_RESOURCES   Not enough memory to store the results.
+  @retval EFI_INVALID_PARAMETER  Request is illegal syntax, or unknown name.
+  @retval EFI_NOT_FOUND          Routing data doesn't match any storage in this
+                                 driver.
+
+**/
+EFI_STATUS
+EFIAPI
+ExtractConfig (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  CONST EFI_STRING                       Request,
+  OUT EFI_STRING                             *Progress,
+  OUT EFI_STRING                             *Results
+  )
+{
+  if (Progress == NULL || Results == NULL) {
+    return EFI_INVALID_PARAMETER;
+  }
+  *Progress = Request;
+  return EFI_NOT_FOUND;
+}
+
+
+/**
+  This function processes the results of changes in configuration.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Configuration          A null-terminated Unicode string in <ConfigResp>
+                                 format.
+  @param  Progress               A pointer to a string filled in with the offset of
+                                 the most recent '&' before the first failing
+                                 name/value pair (or the beginning of the string if
+                                 the failure is in the first name/value pair) or
+                                 the terminating NULL if all was successful.
+
+  @retval EFI_SUCCESS            The Results is processed successfully.
+  @retval EFI_INVALID_PARAMETER  Configuration is NULL.
+  @retval EFI_NOT_FOUND          Routing data doesn't match any storage in this
+                                 driver.
+
+**/
+EFI_STATUS
+EFIAPI
+RouteConfig (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  CONST EFI_STRING                       Configuration,
+  OUT EFI_STRING                             *Progress
+  )
+{
+  if (Configuration == NULL || Progress == NULL) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  *Progress = Configuration;
+
+  return EFI_NOT_FOUND;
+}
+
+/**
+  HII update Admin Password status.
+
+**/
+VOID
+HiiUpdateAdminPasswordStatus (
+  VOID
+  )
+{
+  if (IsPasswordInstalled ()) {
+    HiiSetString (
+      mUserAuthenticationData->HiiHandle,
+      STRING_TOKEN (STR_ADMIN_PASSWORD_STS_CONTENT),
+      L"Installed",
+      NULL
+      );
+  } else {
+    HiiSetString (
+      mUserAuthenticationData->HiiHandle,
+      STRING_TOKEN (STR_ADMIN_PASSWORD_STS_CONTENT),
+      L"Not Installed",
+      NULL
+      );
+  }
+}
+
+/**
+  This function processes the results of changes in configuration.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Action                 Specifies the type of action taken by the browser.
+  @param  QuestionId             A unique value which is sent to the original
+                                 exporting driver so that it can identify the type
+                                 of data to expect.
+  @param  Type                   The type of value for the question.
+  @param  Value                  A pointer to the data being sent to the original
+                                 exporting driver.
+  @param  ActionRequest          On return, points to the action requested by the
+                                 callback function.
+
+  @retval EFI_SUCCESS            The callback successfully handled the action.
+  @retval EFI_OUT_OF_RESOURCES   Not enough storage is available to hold the
+                                 variable and its data.
+  @retval EFI_DEVICE_ERROR       The variable could not be saved.
+  @retval EFI_UNSUPPORTED        The specified Action is not supported by the
+                                 callback.
+
+**/
+EFI_STATUS
+EFIAPI
+UserAuthenticationCallback (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  EFI_BROWSER_ACTION                     Action,
+  IN  EFI_QUESTION_ID                        QuestionId,
+  IN  UINT8                                  Type,
+  IN  EFI_IFR_TYPE_VALUE                     *Value,
+  OUT EFI_BROWSER_ACTION_REQUEST             *ActionRequest
+  )
+{
+  EFI_STATUS  Status;
+  CHAR16      *UserInputPassword;
+
+  Status = EFI_SUCCESS;
+
+  if (((Value == NULL) && (Action != EFI_BROWSER_ACTION_FORM_OPEN) && (Action != EFI_BROWSER_ACTION_FORM_CLOSE)) ||
+      (ActionRequest == NULL)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  switch (Action) {
+  case EFI_BROWSER_ACTION_FORM_OPEN:
+    {
+      switch (QuestionId) {
+      case ADMIN_PASSWORD_KEY_ID:
+        HiiUpdateAdminPasswordStatus ();
+      default:
+        break;
+      }
+    }
+    break;
+  case EFI_BROWSER_ACTION_CHANGING:
+    {
+      switch (QuestionId) {
+      case ADMIN_PASSWORD_KEY_ID:
+        if ((Type == EFI_IFR_TYPE_STRING) && (Value->string == 0) &&
+            (mUserAuthenticationData->PasswordState == BROWSER_STATE_SET_PASSWORD)) {
+          mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+          ZeroMem (mUserAuthenticationData->OldPassword, sizeof(mUserAuthenticationData->OldPassword));
+          return EFI_INVALID_PARAMETER;
+        }
+        //
+        // The Callback is responsible for validating old password input by user,
+        // If Callback return EFI_SUCCESS, it indicates validation pass.
+        //
+        switch (mUserAuthenticationData->PasswordState) {
+        case BROWSER_STATE_VALIDATE_PASSWORD:
+          UserInputPassword = HiiGetString (mUserAuthenticationData->HiiHandle, Value->string, NULL);
+          if ((StrLen (UserInputPassword) >= PASSWORD_MAX_SIZE)) {
+            Status = EFI_NOT_READY;
+            break;
+          }
+          if (UserInputPassword[0] == 0) {
+            //
+            // Setup will use a NULL password to check whether the old password is set,
+            // If the validation is successful, means there is no old password, return
+            // success to set the new password. Or need to return EFI_NOT_READY to
+            // let user input the old password.
+            //
+            Status = VerifyPassword (UserInputPassword, StrSize (UserInputPassword));
+            if (Status == EFI_SUCCESS) {
+              mUserAuthenticationData->PasswordState = BROWSER_STATE_SET_PASSWORD;
+            } else {
+              Status = EFI_NOT_READY;
+            }
+            break;
+          }
+          Status = VerifyPassword (UserInputPassword, StrSize (UserInputPassword));
+          if (Status == EFI_SUCCESS) {
+            mUserAuthenticationData->PasswordState = BROWSER_STATE_SET_PASSWORD;
+            StrCpyS (
+              mUserAuthenticationData->OldPassword,
+              sizeof(mUserAuthenticationData->OldPassword)/sizeof(CHAR16),
+              UserInputPassword
+              );
+          } else {
+            //
+            // Old password mismatch, return EFI_NOT_READY to prompt for error message.
+            //
+            if (Status == EFI_ACCESS_DENIED) {
+              //
+              // Password retry count reach.
+              //
+              ForceSystemReset ();
+            }
+            Status = EFI_NOT_READY;
+          }
+          break;
+
+        case BROWSER_STATE_SET_PASSWORD:
+          UserInputPassword = HiiGetString (mUserAuthenticationData->HiiHandle, Value->string, NULL);
+          if ((StrLen (UserInputPassword) >= PASSWORD_MAX_SIZE)) {
+            Status = EFI_NOT_READY;
+            break;
+          }
+          Status = SetPassword (UserInputPassword, StrSize (UserInputPassword), mUserAuthenticationData->OldPassword, StrSize(mUserAuthenticationData->OldPassword));
+          PrintSetPasswordStatus (Status);
+          ZeroMem (mUserAuthenticationData->OldPassword, sizeof(mUserAuthenticationData->OldPassword));
+          mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+          HiiUpdateAdminPasswordStatus ();
+          break;
+
+        default:
+          break;
+        }
+      default:
+        break;
+      }
+    }
+    break;
+  default:
+    break;
+  }
+  return Status;
+}
+
+/**
+  User Authentication entry point.
+
+  @param ImageHandle     The image handle.
+  @param SystemTable     The system table.
+
+  @retval EFI_SUCCESS    The entry point is executed successfully.
+  @return  other         Contain some other errors.
+
+**/
+EFI_STATUS
+EFIAPI
+UserAuthentication2Entry (
+  IN EFI_HANDLE           ImageHandle,
+  IN EFI_SYSTEM_TABLE     *SystemTable
+  )
+{
+  EFI_STATUS        Status;
+  EFI_HANDLE        DriverHandle;
+  EFI_HII_HANDLE    HiiHandle;
+
+  DriverHandle  = NULL;
+
+  mUserAuthenticationData = AllocateZeroPool (sizeof (USER_AUTHENTICATION_PRIVATE_DATA));
+  if (mUserAuthenticationData == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  mUserAuthenticationData->ConfigAccess.ExtractConfig = ExtractConfig;
+  mUserAuthenticationData->ConfigAccess.RouteConfig = RouteConfig;
+  mUserAuthenticationData->ConfigAccess.Callback = UserAuthenticationCallback;
+  mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+
+  //
+  // Install Config Access protocol to driver handle.
+  //
+  Status = gBS->InstallMultipleProtocolInterfaces (
+                  &DriverHandle,
+                  &gEfiDevicePathProtocolGuid,
+                  &mHiiVendorDevicePath,
+                  &gEfiHiiConfigAccessProtocolGuid,
+                  &mUserAuthenticationData->ConfigAccess,
+                  NULL
+                  );
+  ASSERT_EFI_ERROR (Status);
+  mUserAuthenticationData->DriverHandle = DriverHandle;
+
+  //
+  // Add HII data to database.
+  //
+  HiiHandle = HiiAddPackages (
+                   &mUserAuthenticationVendorGuid,
+                   DriverHandle,
+                   UserAuthentication2DxeStrings,
+                   UserAuthenticationDxeVfrBin,
+                   NULL
+                   );
+  if (HiiHandle == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+  mUserAuthenticationData->HiiHandle = HiiHandle;
+
+  return EFI_SUCCESS;
+}
+
+/**
+  Unloads the application and its installed protocol.
+
+  @param[in]  ImageHandle       Handle that identifies the image to be unloaded.
+
+  @retval EFI_SUCCESS           The image has been unloaded.
+**/
+EFI_STATUS
+EFIAPI
+UserAuthentication2Unload (
+  IN EFI_HANDLE  ImageHandle
+  )
+{
+  ASSERT (mUserAuthenticationData != NULL);
+
+  //
+  // Uninstall Config Access Protocol.
+  //
+  if (mUserAuthenticationData->DriverHandle != NULL) {
+    gBS->UninstallMultipleProtocolInterfaces (
+           mUserAuthenticationData->DriverHandle,
+           &gEfiDevicePathProtocolGuid,
+           &mHiiVendorDevicePath,
+           &gEfiHiiConfigAccessProtocolGuid,
+           &mUserAuthenticationData->ConfigAccess,
+           NULL
+           );
+    mUserAuthenticationData->DriverHandle = NULL;
+  }
+
+  //
+  // Remove Hii Data.
+  //
+  if (mUserAuthenticationData->HiiHandle != NULL) {
+    HiiRemovePackages (mUserAuthenticationData->HiiHandle);
+  }
+
+  FreePool (mUserAuthenticationData);
+  mUserAuthenticationData = NULL;
+
+  return EFI_SUCCESS;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.h b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.h
new file mode 100644
index 0000000000..896460b889
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.h
@@ -0,0 +1,55 @@
+/** @file
+  Header file for UserAuthentication2Dxe.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef _USER_AUTHENTICATION_DXE_H_
+#define _USER_AUTHENTICATION_DXE_H_
+
+
+#include <Protocol/ReportStatusCodeHandler.h>
+#include <Protocol/HiiConfigAccess.h>
+
+#include <Guid/MdeModuleHii.h>
+#include <Guid/HiiPlatformSetupFormset.h>
+#include <Guid/UserAuthentication.h>
+
+#include <Library/DebugLib.h>
+#include <Library/BaseMemoryLib.h>
+#include <Library/UefiRuntimeServicesTableLib.h>
+#include <Library/UefiDriverEntryPoint.h>
+#include <Library/UefiBootServicesTableLib.h>
+#include <Library/BaseLib.h>
+#include <Library/UefiLib.h>
+#include <Library/HiiLib.h>
+#include <Library/DevicePathLib.h>
+#include <Library/MemoryAllocationLib.h>
+#include <Library/UserPasswordLib.h>
+
+#include "UserAuthenticationDxeFormset.h"
+
+extern UINT8  UserAuthenticationDxeVfrBin[];
+extern UINT8  UserAuthentication2DxeStrings[];
+
+typedef struct {
+  EFI_HII_CONFIG_ACCESS_PROTOCOL       ConfigAccess;
+  EFI_HANDLE                           DriverHandle;
+  EFI_HII_HANDLE                       HiiHandle;
+  UINT8                                PasswordState;
+  CHAR16                               OldPassword[PASSWORD_MAX_SIZE];
+} USER_AUTHENTICATION_PRIVATE_DATA;
+
+#pragma pack(1)
+///
+/// HII specific Vendor Device Path definition.
+///
+typedef struct {
+  VENDOR_DEVICE_PATH             VendorDevicePath;
+  EFI_DEVICE_PATH_PROTOCOL       End;
+} HII_VENDOR_DEVICE_PATH;
+#pragma pack()
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf
new file mode 100644
index 0000000000..bf787b95e5
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf
@@ -0,0 +1,53 @@
+## @file
+#  User Authentication 2 Dxe Driver.
+#
+#  This Driver mainly provides Setup Form to change password.
+#
+# Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  INF_VERSION                    = 0x00010005
+  BASE_NAME                      = UserAuthentication2Dxe
+  FILE_GUID                      = 4EF592F4-C716-40CC-8C07-1E4E3BD71F11
+  MODULE_TYPE                    = DXE_DRIVER
+  VERSION_STRING                 = 2.0
+  ENTRY_POINT                    = UserAuthentication2Entry
+  UNLOAD_IMAGE                   = UserAuthentication2Unload
+
+[Sources]
+  UserAuthentication2Dxe.c
+  UserAuthentication2Dxe.h
+  UserAuthenticationDxeFormset.h
+  UserAuthenticationDxeVfr.vfr
+  UserAuthenticationDxeStrings.uni
+
+[Packages]
+  MdePkg/MdePkg.dec
+  MdeModulePkg/MdeModulePkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[LibraryClasses]
+  BaseLib
+  UefiBootServicesTableLib
+  UefiDriverEntryPoint
+  UefiRuntimeServicesTableLib
+  BaseMemoryLib
+  DebugLib
+  UefiLib
+  HiiLib
+  DevicePathLib
+  MemoryAllocationLib
+  UserPasswordLib
+
+[Protocols]
+  gEfiDevicePathProtocolGuid                    ## PRODUCES
+  gEfiHiiConfigAccessProtocolGuid               ## PRODUCES
+
+[Depex]
+  gEfiSimpleTextOutProtocolGuid      AND
+  gEfiSmmCommunicationProtocolGuid   AND
+  gEfiVariableArchProtocolGuid       AND
+  gEfiVariableWriteArchProtocolGuid
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.c b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.c
new file mode 100644
index 0000000000..745a814c17
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.c
@@ -0,0 +1,780 @@
+/** @file
+  This Driver mainly provides Setup Form to change password and
+  does user authentication before entering Setup.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include "UserAuthenticationDxe.h"
+
+EFI_EVENT                           mExitBootServicesEvent  = NULL;
+EFI_RSC_HANDLER_PROTOCOL           *mRscHandlerProtocol     = NULL;
+USER_AUTHENTICATION_PRIVATE_DATA   *mUserAuthenticationData = NULL;
+EFI_SMM_COMMUNICATION_PROTOCOL     *mSmmCommunication       = NULL;
+
+EFI_GUID mUserAuthenticationVendorGuid = USER_AUTHENTICATION_FORMSET_GUID;
+HII_VENDOR_DEVICE_PATH mHiiVendorDevicePath = {
+  {
+    {
+      HARDWARE_DEVICE_PATH,
+      HW_VENDOR_DP,
+      {
+        (UINT8) (sizeof (VENDOR_DEVICE_PATH)),
+        (UINT8) ((sizeof (VENDOR_DEVICE_PATH)) >> 8)
+      }
+    },
+    USER_AUTHENTICATION_FORMSET_GUID
+  },
+  {
+    END_DEVICE_PATH_TYPE,
+    END_ENTIRE_DEVICE_PATH_SUBTYPE,
+    {
+      (UINT8) (END_DEVICE_PATH_LENGTH),
+      (UINT8) ((END_DEVICE_PATH_LENGTH) >> 8)
+    }
+  }
+};
+
+/**
+  Get a user input string.
+
+  @param[in]       PopUpString      A popup string to inform user.
+  @param[in, out]  UserInput        The user input string
+  @param[in]       UserInputMaxLen  The max unicode count of the UserInput without NULL terminator.
+**/
+EFI_STATUS
+GetUserInput (
+  IN     CHAR16      *PopUpString,
+  IN OUT CHAR16      *UserInput,
+  IN     UINTN       UserInputMaxLen
+  )
+{
+  EFI_INPUT_KEY                InputKey;
+  UINTN                        InputLength;
+  CHAR16                       *Mask;
+
+  UserInput[0] = 0;
+  Mask = AllocateZeroPool ((UserInputMaxLen + 1) * sizeof(CHAR16));
+  if (Mask == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  InputLength = 0;
+
+  while (TRUE) {
+    if (InputLength < UserInputMaxLen) {
+      Mask[InputLength] = L'_';
+    }
+    CreatePopUp (
+      EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+      &InputKey,
+      PopUpString,
+      L"--------------------------------",
+      Mask,
+      NULL
+      );
+    if (InputKey.ScanCode == SCAN_NULL) {
+      //
+      // Check whether finish inputing password.
+      //
+      if (InputKey.UnicodeChar == CHAR_CARRIAGE_RETURN && InputLength > 0) {
+        //
+        // Add the null terminator.
+        //
+        UserInput[InputLength] = 0;
+        break;
+      } else if ((InputKey.UnicodeChar == CHAR_NULL) ||
+                 (InputKey.UnicodeChar == CHAR_LINEFEED) ||
+                 (InputKey.UnicodeChar == CHAR_CARRIAGE_RETURN)
+                ) {
+        continue;
+      } else {
+        //
+        // delete last key entered
+        //
+        if (InputKey.UnicodeChar == CHAR_BACKSPACE) {
+          if (InputLength > 0) {
+            UserInput[InputLength] = 0;
+            Mask[InputLength] = 0;
+            InputLength--;
+          }
+        } else {
+          if (InputLength == UserInputMaxLen) {
+            Mask[InputLength] = 0;
+            continue;
+          }
+          //
+          // add Next key entry
+          //
+          UserInput[InputLength] = InputKey.UnicodeChar;
+          Mask[InputLength] = L'*';
+          InputLength++;
+        }
+      }
+    }
+  }
+  FreePool (Mask);
+  return EFI_SUCCESS;
+}
+
+/**
+  Display a message box to end user.
+
+  @param[in] DisplayString   The string in message box.
+**/
+VOID
+MessageBox (
+  IN CHAR16  *DisplayString
+  )
+{
+  EFI_INPUT_KEY  Key;
+
+  do {
+    CreatePopUp (
+      EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+      &Key,
+      L"",
+      DisplayString,
+      L"Press ENTER to continue ...",
+      L"",
+      NULL
+      );
+  } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+}
+
+/**
+  Force system reset.
+**/
+VOID
+ForceSystemReset (
+  VOID
+  )
+{
+  MessageBox (L"Password retry count reach, reset system!");
+  gRT->ResetSystem (EfiResetCold, EFI_SUCCESS, 0, NULL);
+  CpuDeadLoop();
+}
+
+/**
+  Display message for set password.
+
+  @param[in]  ReturnStatus   The return status for set password.
+**/
+VOID
+PrintSetPasswordStatus (
+  IN EFI_STATUS  ReturnStatus
+  )
+{
+  CHAR16         *DisplayString;
+  CHAR16         *DisplayString2;
+
+  EFI_INPUT_KEY  Key;
+
+  if (ReturnStatus == EFI_UNSUPPORTED) {
+    DisplayString  = L"New password is not strong enough!";
+    DisplayString2 = L"Password must at least 8 chars and include lowercase, uppercase alphabetic, number and symbol";
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        DisplayString2,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  } else {
+    if (ReturnStatus == EFI_SUCCESS) {
+      DisplayString = L"New password is updated successfully!";
+    } else if (ReturnStatus == EFI_ALREADY_STARTED) {
+      DisplayString = L"New password is found in the history passwords!";
+    } else {
+      DisplayString = L"New password update fails!";
+    }
+
+    do {
+      CreatePopUp (
+        EFI_LIGHTGRAY | EFI_BACKGROUND_BLUE,
+        &Key,
+        L"",
+        DisplayString,
+        L"Press ENTER to continue ...",
+        L"",
+        NULL
+        );
+    } while (Key.UnicodeChar != CHAR_CARRIAGE_RETURN);
+  }
+}
+
+/**
+  Require user input password.
+
+  @retval TRUE   User input correct password successfully.
+  @retval FALSE  The password is not set.
+**/
+BOOLEAN
+RequireUserPassword (
+  VOID
+  )
+{
+  EFI_STATUS                                    Status;
+  CHAR16                                        UserInputPw[PASSWORD_MAX_SIZE];
+  CHAR16                                        *PopUpString;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY        VerifyPolicy;
+
+  Status = EFI_SUCCESS;
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+
+  if (!IsPasswordInstalled ()) {
+    return FALSE;
+  }
+
+  Status = GetPasswordVerificationPolicy (&VerifyPolicy);
+  if (!EFI_ERROR (Status)) {
+    if (WasPasswordVerified() && (!VerifyPolicy.NeedReVerify)) {
+      DEBUG ((DEBUG_INFO, "Password was verified and Re-verify is not needed\n"));
+      return TRUE;
+    }
+  }
+
+  PopUpString = L"Please input admin password";
+
+  while (TRUE) {
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString, UserInputPw, PASSWORD_MAX_SIZE - 1);
+
+    Status = VerifyPassword (UserInputPw, StrSize(UserInputPw));
+    if (!EFI_ERROR(Status)) {
+      break;
+    }
+    if (Status == EFI_ACCESS_DENIED) {
+      //
+      // Password retry count reach.
+      //
+      ForceSystemReset ();
+    }
+    MessageBox (L"Incorrect password!");
+  }
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+
+  gST->ConOut->ClearScreen(gST->ConOut);
+
+  return TRUE;
+}
+
+/**
+  Set user password.
+
+**/
+VOID
+SetUserPassword (
+  VOID
+  )
+{
+  EFI_STATUS                   Status;
+  CHAR16                       UserInputPw[PASSWORD_MAX_SIZE];
+  CHAR16                       TmpPassword[PASSWORD_MAX_SIZE];
+  CHAR16                       *PopUpString;
+  CHAR16                       *PopUpString2;
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+  ZeroMem(TmpPassword, sizeof(TmpPassword));
+
+  PopUpString = L"Please set admin password";
+
+  while (TRUE) {
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString, UserInputPw, PASSWORD_MAX_SIZE - 1);
+
+    PopUpString2 = L"Please confirm your new password";
+    gST->ConOut->ClearScreen(gST->ConOut);
+    GetUserInput (PopUpString2, TmpPassword, PASSWORD_MAX_SIZE - 1);
+    if (StrCmp (TmpPassword, UserInputPw) != 0) {
+      MessageBox (L"Password are not the same!");
+      continue;
+    }
+
+    Status = SetPassword (UserInputPw, StrSize(UserInputPw), NULL, 0);
+    PrintSetPasswordStatus (Status);
+    if (!EFI_ERROR(Status)) {
+      break;
+    }
+  }
+
+  ZeroMem(UserInputPw, sizeof(UserInputPw));
+  ZeroMem(TmpPassword, sizeof(TmpPassword));
+
+  gST->ConOut->ClearScreen(gST->ConOut);
+}
+
+/**
+  Check password before entering into setup.
+
+  @param  CodeType      Indicates the type of status code being reported.  Type EFI_STATUS_CODE_TYPE is defined in "Related Definitions" below.
+
+  @param  Value         Describes the current status of a hardware or software entity.
+                        This included information about the class and subclass that is used to classify the entity
+                        as well as an operation.  For progress codes, the operation is the current activity.
+                        For error codes, it is the exception.  For debug codes, it is not defined at this time.
+                        Type EFI_STATUS_CODE_VALUE is defined in "Related Definitions" below.
+                        Specific values are discussed in the Intel? Platform Innovation Framework for EFI Status Code Specification.
+
+  @param  Instance      The enumeration of a hardware or software entity within the system.
+                        A system may contain multiple entities that match a class/subclass pairing.
+                        The instance differentiates between them.  An instance of 0 indicates that instance information is unavailable,
+                        not meaningful, or not relevant.  Valid instance numbers start with 1.
+
+
+  @param  CallerId      This optional parameter may be used to identify the caller.
+                        This parameter allows the status code driver to apply different rules to different callers.
+                        Type EFI_GUID is defined in InstallProtocolInterface() in the UEFI 2.0 Specification.
+
+
+  @param  Data          This optional parameter may be used to pass additional data
+
+  @retval EFI_SUCCESS             Status code is what we expected.
+  @retval EFI_UNSUPPORTED         Status code not supported.
+
+**/
+EFI_STATUS
+EFIAPI
+CheckForPassword (
+  IN EFI_STATUS_CODE_TYPE     CodeType,
+  IN EFI_STATUS_CODE_VALUE    Value,
+  IN UINT32                   Instance,
+  IN EFI_GUID                 *CallerId, OPTIONAL
+  IN EFI_STATUS_CODE_DATA     *Data      OPTIONAL
+  )
+{
+  BOOLEAN   PasswordSet;
+
+  if (((CodeType & EFI_STATUS_CODE_TYPE_MASK) == EFI_PROGRESS_CODE) &&
+      (Value == (EFI_SOFTWARE_DXE_BS_DRIVER | EFI_SW_PC_USER_SETUP))) {
+    //
+    // Check whether enter setup page.
+    //
+    PasswordSet = RequireUserPassword ();
+    if (PasswordSet) {
+      DEBUG ((DEBUG_INFO, "Welcome Admin!\n"));
+    } else {
+      DEBUG ((DEBUG_INFO, "Admin password is not set!\n"));
+      if (NeedEnrollPassword()) {
+        SetUserPassword ();
+      }
+    }
+
+    return EFI_SUCCESS;
+  } else{
+    return EFI_UNSUPPORTED;
+  }
+}
+
+/**
+  This function allows a caller to extract the current configuration for one
+  or more named elements from the target driver.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Request                A null-terminated Unicode string in
+                                 <ConfigRequest> format.
+  @param  Progress               On return, points to a character in the Request
+                                 string. Points to the string's null terminator if
+                                 request was successful. Points to the most recent
+                                 '&' before the first failing name/value pair (or
+                                 the beginning of the string if the failure is in
+                                 the first name/value pair) if the request was not
+                                 successful.
+  @param  Results                A null-terminated Unicode string in
+                                 <ConfigAltResp> format which has all values filled
+                                 in for the names in the Request string. String to
+                                 be allocated by the called function.
+
+  @retval EFI_SUCCESS            The Results is filled with the requested values.
+  @retval EFI_OUT_OF_RESOURCES   Not enough memory to store the results.
+  @retval EFI_INVALID_PARAMETER  Request is illegal syntax, or unknown name.
+  @retval EFI_NOT_FOUND          Routing data doesn't match any storage in this
+                                 driver.
+
+**/
+EFI_STATUS
+EFIAPI
+ExtractConfig (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  CONST EFI_STRING                       Request,
+  OUT EFI_STRING                             *Progress,
+  OUT EFI_STRING                             *Results
+  )
+{
+  if (Progress == NULL || Results == NULL) {
+    return EFI_INVALID_PARAMETER;
+  }
+  *Progress = Request;
+  return EFI_NOT_FOUND;
+}
+
+
+/**
+  This function processes the results of changes in configuration.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Configuration          A null-terminated Unicode string in <ConfigResp>
+                                 format.
+  @param  Progress               A pointer to a string filled in with the offset of
+                                 the most recent '&' before the first failing
+                                 name/value pair (or the beginning of the string if
+                                 the failure is in the first name/value pair) or
+                                 the terminating NULL if all was successful.
+
+  @retval EFI_SUCCESS            The Results is processed successfully.
+  @retval EFI_INVALID_PARAMETER  Configuration is NULL.
+  @retval EFI_NOT_FOUND          Routing data doesn't match any storage in this
+                                 driver.
+
+**/
+EFI_STATUS
+EFIAPI
+RouteConfig (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  CONST EFI_STRING                       Configuration,
+  OUT EFI_STRING                             *Progress
+  )
+{
+  if (Configuration == NULL || Progress == NULL) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  *Progress = Configuration;
+
+  return EFI_NOT_FOUND;
+}
+
+/**
+  HII update Admin Password status.
+
+**/
+VOID
+HiiUpdateAdminPasswordStatus (
+  VOID
+  )
+{
+  if (IsPasswordInstalled ()) {
+    HiiSetString (
+      mUserAuthenticationData->HiiHandle,
+      STRING_TOKEN (STR_ADMIN_PASSWORD_STS_CONTENT),
+      L"Installed",
+      NULL
+      );
+  } else {
+    HiiSetString (
+      mUserAuthenticationData->HiiHandle,
+      STRING_TOKEN (STR_ADMIN_PASSWORD_STS_CONTENT),
+      L"Not Installed",
+      NULL
+      );
+  }
+}
+
+/**
+  This function processes the results of changes in configuration.
+
+  @param  This                   Points to the EFI_HII_CONFIG_ACCESS_PROTOCOL.
+  @param  Action                 Specifies the type of action taken by the browser.
+  @param  QuestionId             A unique value which is sent to the original
+                                 exporting driver so that it can identify the type
+                                 of data to expect.
+  @param  Type                   The type of value for the question.
+  @param  Value                  A pointer to the data being sent to the original
+                                 exporting driver.
+  @param  ActionRequest          On return, points to the action requested by the
+                                 callback function.
+
+  @retval EFI_SUCCESS            The callback successfully handled the action.
+  @retval EFI_OUT_OF_RESOURCES   Not enough storage is available to hold the
+                                 variable and its data.
+  @retval EFI_DEVICE_ERROR       The variable could not be saved.
+  @retval EFI_UNSUPPORTED        The specified Action is not supported by the
+                                 callback.
+
+**/
+EFI_STATUS
+EFIAPI
+UserAuthenticationCallback (
+  IN  CONST EFI_HII_CONFIG_ACCESS_PROTOCOL   *This,
+  IN  EFI_BROWSER_ACTION                     Action,
+  IN  EFI_QUESTION_ID                        QuestionId,
+  IN  UINT8                                  Type,
+  IN  EFI_IFR_TYPE_VALUE                     *Value,
+  OUT EFI_BROWSER_ACTION_REQUEST             *ActionRequest
+  )
+{
+  EFI_STATUS  Status;
+  CHAR16      *UserInputPassword;
+
+  Status = EFI_SUCCESS;
+
+  if (((Value == NULL) && (Action != EFI_BROWSER_ACTION_FORM_OPEN) && (Action != EFI_BROWSER_ACTION_FORM_CLOSE)) ||
+      (ActionRequest == NULL)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  switch (Action) {
+  case EFI_BROWSER_ACTION_FORM_OPEN:
+    {
+      switch (QuestionId) {
+      case ADMIN_PASSWORD_KEY_ID:
+        HiiUpdateAdminPasswordStatus ();
+      default:
+        break;
+      }
+    }
+    break;
+  case EFI_BROWSER_ACTION_CHANGING:
+    {
+      switch (QuestionId) {
+      case ADMIN_PASSWORD_KEY_ID:
+        if ((Type == EFI_IFR_TYPE_STRING) && (Value->string == 0) &&
+            (mUserAuthenticationData->PasswordState == BROWSER_STATE_SET_PASSWORD)) {
+          mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+          ZeroMem (mUserAuthenticationData->OldPassword, sizeof(mUserAuthenticationData->OldPassword));
+          return EFI_INVALID_PARAMETER;
+        }
+        //
+        // The Callback is responsible for validating old password input by user,
+        // If Callback return EFI_SUCCESS, it indicates validation pass.
+        //
+        switch (mUserAuthenticationData->PasswordState) {
+        case BROWSER_STATE_VALIDATE_PASSWORD:
+          UserInputPassword = HiiGetString (mUserAuthenticationData->HiiHandle, Value->string, NULL);
+          if ((StrLen (UserInputPassword) >= PASSWORD_MAX_SIZE)) {
+            Status = EFI_NOT_READY;
+            break;
+          }
+          if (UserInputPassword[0] == 0) {
+            //
+            // Setup will use a NULL password to check whether the old password is set,
+            // If the validation is successful, means there is no old password, return
+            // success to set the new password. Or need to return EFI_NOT_READY to
+            // let user input the old password.
+            //
+            Status = VerifyPassword (UserInputPassword, StrSize (UserInputPassword));
+            if (Status == EFI_SUCCESS) {
+              mUserAuthenticationData->PasswordState = BROWSER_STATE_SET_PASSWORD;
+            } else {
+              Status = EFI_NOT_READY;
+            }
+            break;
+          }
+          Status = VerifyPassword (UserInputPassword, StrSize (UserInputPassword));
+          if (Status == EFI_SUCCESS) {
+            mUserAuthenticationData->PasswordState = BROWSER_STATE_SET_PASSWORD;
+            StrCpyS (
+              mUserAuthenticationData->OldPassword,
+              sizeof(mUserAuthenticationData->OldPassword)/sizeof(CHAR16),
+              UserInputPassword
+              );
+          } else {
+            //
+            // Old password mismatch, return EFI_NOT_READY to prompt for error message.
+            //
+            if (Status == EFI_ACCESS_DENIED) {
+              //
+              // Password retry count reach.
+              //
+              ForceSystemReset ();
+            }
+            Status = EFI_NOT_READY;
+          }
+          break;
+
+        case BROWSER_STATE_SET_PASSWORD:
+          UserInputPassword = HiiGetString (mUserAuthenticationData->HiiHandle, Value->string, NULL);
+          if ((StrLen (UserInputPassword) >= PASSWORD_MAX_SIZE)) {
+            Status = EFI_NOT_READY;
+            break;
+          }
+          Status = SetPassword (UserInputPassword, StrSize (UserInputPassword), mUserAuthenticationData->OldPassword, StrSize(mUserAuthenticationData->OldPassword));
+          PrintSetPasswordStatus (Status);
+          ZeroMem (mUserAuthenticationData->OldPassword, sizeof(mUserAuthenticationData->OldPassword));
+          mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+          HiiUpdateAdminPasswordStatus ();
+          break;
+
+        default:
+          break;
+        }
+      default:
+        break;
+      }
+    }
+    break;
+  default:
+    break;
+  }
+  return Status;
+}
+
+/**
+  Unregister status code callback functions.
+
+  @param  Event         Event whose notification function is being invoked.
+  @param  Context       Pointer to the notification function's context, which is
+                        always zero in current implementation.
+
+**/
+VOID
+EFIAPI
+UnregisterBootTimeHandlers (
+  IN EFI_EVENT        Event,
+  IN VOID             *Context
+  )
+{
+  mRscHandlerProtocol->Unregister (CheckForPassword);
+}
+
+/**
+  User Authentication entry point.
+
+  @param ImageHandle     The image handle.
+  @param SystemTable     The system table.
+
+  @retval EFI_SUCCESS    The entry point is executed successfully.
+  @return  other         Contain some other errors.
+
+**/
+EFI_STATUS
+EFIAPI
+UserAuthenticationEntry (
+  IN EFI_HANDLE           ImageHandle,
+  IN EFI_SYSTEM_TABLE     *SystemTable
+  )
+{
+  EFI_STATUS        Status;
+  EFI_HANDLE        DriverHandle;
+  EFI_HII_HANDLE    HiiHandle;
+
+  DriverHandle  = NULL;
+
+  mUserAuthenticationData = AllocateZeroPool (sizeof (USER_AUTHENTICATION_PRIVATE_DATA));
+  if (mUserAuthenticationData == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  mUserAuthenticationData->ConfigAccess.ExtractConfig = ExtractConfig;
+  mUserAuthenticationData->ConfigAccess.RouteConfig = RouteConfig;
+  mUserAuthenticationData->ConfigAccess.Callback = UserAuthenticationCallback;
+  mUserAuthenticationData->PasswordState = BROWSER_STATE_VALIDATE_PASSWORD;
+
+  //
+  // Install Config Access protocol to driver handle.
+  //
+  Status = gBS->InstallMultipleProtocolInterfaces (
+                  &DriverHandle,
+                  &gEfiDevicePathProtocolGuid,
+                  &mHiiVendorDevicePath,
+                  &gEfiHiiConfigAccessProtocolGuid,
+                  &mUserAuthenticationData->ConfigAccess,
+                  NULL
+                  );
+  ASSERT_EFI_ERROR (Status);
+  mUserAuthenticationData->DriverHandle = DriverHandle;
+
+  //
+  // Add HII data to database.
+  //
+  HiiHandle = HiiAddPackages (
+                   &mUserAuthenticationVendorGuid,
+                   DriverHandle,
+                   UserAuthenticationDxeStrings,
+                   UserAuthenticationDxeVfrBin,
+                   NULL
+                   );
+  if (HiiHandle == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+  mUserAuthenticationData->HiiHandle = HiiHandle;
+
+  //
+  // Locate report status code protocol.
+  //
+  Status = gBS->LocateProtocol (
+                  &gEfiRscHandlerProtocolGuid,
+                  NULL,
+                  (VOID **) &mRscHandlerProtocol
+                  );
+  ASSERT_EFI_ERROR (Status);
+
+  //
+  //Register the callback function for ReportStatusCode() notification.
+  //
+  mRscHandlerProtocol->Register (CheckForPassword, TPL_HIGH_LEVEL);
+
+  //
+  // Unregister boot time report status code listener at ExitBootService Event.
+  //
+  Status = gBS->CreateEventEx (
+                  EVT_NOTIFY_SIGNAL,
+                  TPL_NOTIFY,
+                  UnregisterBootTimeHandlers,
+                  NULL,
+                  &gEfiEventExitBootServicesGuid,
+                  &mExitBootServicesEvent
+                  );
+  ASSERT_EFI_ERROR (Status);
+
+  //
+  // Locates SMM Communication protocol.
+  //
+  Status = gBS->LocateProtocol (&gEfiSmmCommunicationProtocolGuid, NULL, (VOID **) &mSmmCommunication);
+  ASSERT_EFI_ERROR (Status);
+
+  return EFI_SUCCESS;
+}
+
+/**
+  Unloads the application and its installed protocol.
+
+  @param[in]  ImageHandle       Handle that identifies the image to be unloaded.
+
+  @retval EFI_SUCCESS           The image has been unloaded.
+**/
+EFI_STATUS
+EFIAPI
+UserAuthenticationUnload (
+  IN EFI_HANDLE  ImageHandle
+  )
+{
+  ASSERT (mUserAuthenticationData != NULL);
+
+  //
+  // Uninstall Config Access Protocol.
+  //
+  if (mUserAuthenticationData->DriverHandle != NULL) {
+    gBS->UninstallMultipleProtocolInterfaces (
+           mUserAuthenticationData->DriverHandle,
+           &gEfiDevicePathProtocolGuid,
+           &mHiiVendorDevicePath,
+           &gEfiHiiConfigAccessProtocolGuid,
+           &mUserAuthenticationData->ConfigAccess,
+           NULL
+           );
+    mUserAuthenticationData->DriverHandle = NULL;
+  }
+
+  //
+  // Remove Hii Data.
+  //
+  if (mUserAuthenticationData->HiiHandle != NULL) {
+    HiiRemovePackages (mUserAuthenticationData->HiiHandle);
+  }
+
+  FreePool (mUserAuthenticationData);
+  mUserAuthenticationData = NULL;
+
+  return EFI_SUCCESS;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.h b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.h
new file mode 100644
index 0000000000..9a002d2a7c
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.h
@@ -0,0 +1,138 @@
+/** @file
+  Header file for UserAuthenticationDxe.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef _USER_AUTHENTICATION_DXE_H_
+#define _USER_AUTHENTICATION_DXE_H_
+
+
+#include <Protocol/ReportStatusCodeHandler.h>
+#include <Protocol/HiiConfigAccess.h>
+#include <Protocol/SmmCommunication.h>
+
+#include <Guid/MdeModuleHii.h>
+#include <Guid/HiiPlatformSetupFormset.h>
+#include <Guid/PiSmmCommunicationRegionTable.h>
+#include <Guid/UserAuthentication.h>
+
+#include <Library/PrintLib.h>
+#include <Library/DebugLib.h>
+#include <Library/BaseMemoryLib.h>
+#include <Library/UefiRuntimeServicesTableLib.h>
+#include <Library/UefiDriverEntryPoint.h>
+#include <Library/UefiBootServicesTableLib.h>
+#include <Library/BaseLib.h>
+#include <Library/UefiLib.h>
+#include <Library/HiiLib.h>
+#include <Library/DevicePathLib.h>
+#include <Library/MemoryAllocationLib.h>
+#include <Library/PlatformPasswordLib.h>
+
+#include "UserAuthenticationDxeFormset.h"
+
+extern UINT8  UserAuthenticationDxeVfrBin[];
+extern UINT8  UserAuthenticationDxeStrings[];
+extern EFI_SMM_COMMUNICATION_PROTOCOL *mSmmCommunication;
+
+typedef struct {
+  EFI_HII_CONFIG_ACCESS_PROTOCOL       ConfigAccess;
+  EFI_HANDLE                           DriverHandle;
+  EFI_HII_HANDLE                       HiiHandle;
+  UINT8                                PasswordState;
+  CHAR16                               OldPassword[PASSWORD_MAX_SIZE];
+} USER_AUTHENTICATION_PRIVATE_DATA;
+
+#pragma pack(1)
+///
+/// HII specific Vendor Device Path definition.
+///
+typedef struct {
+  VENDOR_DEVICE_PATH             VendorDevicePath;
+  EFI_DEVICE_PATH_PROTOCOL       End;
+} HII_VENDOR_DEVICE_PATH;
+#pragma pack()
+
+/**
+  Validate if the password is correct.
+
+  @param[in] Password               The user input password.
+  @param[in] PasswordSize           The size of Password in byte.
+
+  @retval EFI_SUCCESS               The password is correct.
+  @retval EFI_SECURITY_VIOLATION    The password is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to verify the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+**/
+EFI_STATUS
+VerifyPassword (
+  IN   CHAR16       *Password,
+  IN   UINTN        PasswordSize
+  );
+
+/**
+  Set a new password.
+
+  @param[in] NewPassword            The user input new password.
+                                    NULL means clear password.
+  @param[in] NewPasswordSize        The size of NewPassword in byte.
+  @param[in] OldPassword            The user input old password.
+                                    NULL means no old password.
+  @param[in] OldPasswordSize        The size of OldPassword in byte.
+
+  @retval EFI_SUCCESS               The NewPassword is set successfully.
+  @retval EFI_SECURITY_VIOLATION    The OldPassword is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+  @retval EFI_UNSUPPORTED           NewPassword is not strong enough.
+  @retval EFI_ALREADY_STARTED       NewPassword is in history.
+**/
+EFI_STATUS
+SetPassword (
+  IN   CHAR16       *NewPassword,     OPTIONAL
+  IN   UINTN        NewPasswordSize,
+  IN   CHAR16       *OldPassword,     OPTIONAL
+  IN   UINTN        OldPasswordSize
+  );
+
+/**
+  Return if the password is set.
+
+  @retval TRUE      The password is set.
+  @retval FALSE     The password is not set.
+**/
+BOOLEAN
+IsPasswordInstalled (
+  VOID
+  );
+
+/**
+  Get password verification policy.
+
+  @param[out] VerifyPolicy          Verification policy.
+
+  @retval EFI_SUCCESS               Get verification policy successfully.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to get verification policy.
+**/
+EFI_STATUS
+GetPasswordVerificationPolicy (
+  OUT SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    *VerifyPolicy
+  );
+
+/**
+  Return if the password was verified.
+
+  @retval TRUE      The password was verified.
+  @retval FALSE     The password was not verified.
+**/
+BOOLEAN
+WasPasswordVerified (
+  VOID
+  );
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf
new file mode 100644
index 0000000000..66b59bd26b
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf
@@ -0,0 +1,63 @@
+## @file
+#  User Authentication Dxe Driver.
+#
+#  This Driver mainly provides Setup Form to change password and
+#  does user authentication before entering Setup.
+#
+# Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+[Defines]
+  INF_VERSION                    = 0x00010005
+  BASE_NAME                      = UserAuthenticationDxe
+  FILE_GUID                      = 0683FB88-664C-4BA6-9ED4-1C0916EE43A4
+  MODULE_TYPE                    = DXE_DRIVER
+  VERSION_STRING                 = 2.0
+  ENTRY_POINT                    = UserAuthenticationEntry
+  UNLOAD_IMAGE                   = UserAuthenticationUnload
+
+
+[Sources]
+  UserAuthenticationDxe.c
+  UserAuthenticationDxe.h
+  UserAuthenticationDxePassword.c
+  UserAuthenticationDxeFormset.h
+  UserAuthenticationDxeVfr.vfr
+  UserAuthenticationDxeStrings.uni
+
+[Packages]
+  MdePkg/MdePkg.dec
+  MdeModulePkg/MdeModulePkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[LibraryClasses]
+  BaseLib
+  UefiBootServicesTableLib
+  UefiDriverEntryPoint
+  UefiRuntimeServicesTableLib
+  BaseMemoryLib
+  DebugLib
+  UefiLib
+  HiiLib
+  DevicePathLib
+  MemoryAllocationLib
+  PlatformPasswordLib
+  PrintLib
+
+[Guids]
+  gUserAuthenticationGuid                       ## CONSUMES  ## GUID
+  gEfiEventExitBootServicesGuid                 ## CONSUMES  ## Event
+  gEdkiiPiSmmCommunicationRegionTableGuid       ## CONSUMES  ## SystemTable
+
+[Protocols]
+  gEfiRscHandlerProtocolGuid                    ## CONSUMES
+  gEfiDevicePathProtocolGuid                    ## PRODUCES
+  gEfiHiiConfigAccessProtocolGuid               ## PRODUCES
+  gEfiSmmCommunicationProtocolGuid              ## CONSUMES
+
+[Depex]
+  gEfiSimpleTextOutProtocolGuid      AND
+  gEfiSmmCommunicationProtocolGuid   AND
+  gEfiVariableArchProtocolGuid       AND
+  gEfiVariableWriteArchProtocolGuid
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeFormset.h b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeFormset.h
new file mode 100644
index 0000000000..721a038a7a
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeFormset.h
@@ -0,0 +1,23 @@
+/** @file
+  Header file for UserAuthentication formset.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef _USER_AUTHENTICATION_DXE_FORMSET_H_
+#define _USER_AUTHENTICATION_DXE_FORMSET_H_
+
+//
+// Vendor GUID of the formset
+//
+#define USER_AUTHENTICATION_FORMSET_GUID \
+  { 0x760e3022, 0xf149, 0x4560, {0x9c, 0x6f, 0x33, 0xaa, 0x7d, 0x48, 0x75, 0xfa} }
+
+#define ADMIN_PASSWORD_KEY_ID       0x2001
+
+#define MAX_PASSWORD_LEN  32
+#define MIN_PASSWORD_LEN  0
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxePassword.c b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxePassword.c
new file mode 100644
index 0000000000..3645e5c12b
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxePassword.c
@@ -0,0 +1,319 @@
+/** @file
+  UserAuthentication DXE password wrapper.
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include "UserAuthenticationDxe.h"
+
+/**
+  Initialize the communicate buffer using DataSize and Function.
+
+  @param[out]      DataPtr          Points to the data in the communicate buffer.
+  @param[in]       DataSize         The data size to send to SMM.
+  @param[in]       Function         The function number to initialize the communicate header.
+
+  @return Communicate buffer.
+**/
+VOID*
+InitCommunicateBuffer (
+  OUT     VOID                              **DataPtr OPTIONAL,
+  IN      UINTN                             DataSize,
+  IN      UINTN                             Function
+  )
+{
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+  VOID                                      *Buffer;
+  EDKII_PI_SMM_COMMUNICATION_REGION_TABLE   *SmmCommRegionTable;
+  EFI_MEMORY_DESCRIPTOR                     *SmmCommMemRegion;
+  UINTN                                     Index;
+  UINTN                                     Size;
+  EFI_STATUS                                Status;
+
+  Buffer = NULL;
+  Status = EfiGetSystemConfigurationTable (
+             &gEdkiiPiSmmCommunicationRegionTableGuid,
+             (VOID **) &SmmCommRegionTable
+             );
+  if (EFI_ERROR (Status)) {
+    return NULL;
+  }
+  ASSERT (SmmCommRegionTable != NULL);
+  SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) (SmmCommRegionTable + 1);
+  Size = 0;
+  for (Index = 0; Index < SmmCommRegionTable->NumberOfEntries; Index++) {
+    if (SmmCommMemRegion->Type == EfiConventionalMemory) {
+      Size = EFI_PAGES_TO_SIZE ((UINTN) SmmCommMemRegion->NumberOfPages);
+      if (Size >= (DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER))) {
+        break;
+      }
+    }
+    SmmCommMemRegion = (EFI_MEMORY_DESCRIPTOR *) ((UINT8 *) SmmCommMemRegion + SmmCommRegionTable->DescriptorSize);
+  }
+  ASSERT (Index < SmmCommRegionTable->NumberOfEntries);
+
+  Buffer = (VOID*)(UINTN)SmmCommMemRegion->PhysicalStart;
+  ASSERT (Buffer != NULL);
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  CopyGuid (&SmmCommunicateHeader->HeaderGuid, &gUserAuthenticationGuid);
+  SmmCommunicateHeader->MessageLength = DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *) SmmCommunicateHeader->Data;
+  ZeroMem (SmmPasswordFunctionHeader, DataSize + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER));
+  SmmPasswordFunctionHeader->Function = Function;
+  if (DataPtr != NULL) {
+    *DataPtr = SmmPasswordFunctionHeader + 1;
+  }
+
+  return Buffer;
+}
+
+/**
+  Send the data in communicate buffer to SMM.
+
+  @param[in]   Buffer                 Points to the data in the communicate buffer.
+  @param[in]   DataSize               The data size to send to SMM.
+
+  @retval      EFI_SUCCESS            Success is returned from the function in SMM.
+  @retval      Others                 Failure is returned from the function in SMM.
+
+**/
+EFI_STATUS
+SendCommunicateBuffer (
+  IN      VOID                              *Buffer,
+  IN      UINTN                             DataSize
+  )
+{
+  EFI_STATUS                                Status;
+  UINTN                                     CommSize;
+  EFI_SMM_COMMUNICATE_HEADER                *SmmCommunicateHeader;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmPasswordFunctionHeader;
+
+  CommSize = DataSize + OFFSET_OF (EFI_SMM_COMMUNICATE_HEADER, Data) + sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  Status = mSmmCommunication->Communicate (mSmmCommunication, Buffer, &CommSize);
+  ASSERT_EFI_ERROR (Status);
+
+  SmmCommunicateHeader = (EFI_SMM_COMMUNICATE_HEADER *) Buffer;
+  SmmPasswordFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *)SmmCommunicateHeader->Data;
+  return  SmmPasswordFunctionHeader->ReturnStatus;
+}
+
+/**
+  Validate if the password is correct.
+
+  @param[in] Password               The user input password.
+  @param[in] PasswordSize           The size of Password in byte.
+
+  @retval EFI_SUCCESS               The password is correct.
+  @retval EFI_SECURITY_VIOLATION    The password is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to verify the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+**/
+EFI_STATUS
+VerifyPassword (
+  IN   CHAR16       *Password,
+  IN   UINTN        PasswordSize
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_PASSWORD  *VerifyPassword;
+
+  ASSERT (Password != NULL);
+
+  if (PasswordSize > sizeof(VerifyPassword->Password) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  Buffer = InitCommunicateBuffer (
+             (VOID**)&VerifyPassword,
+             sizeof(*VerifyPassword),
+             SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  Status = UnicodeStrToAsciiStrS (Password, VerifyPassword->Password, sizeof(VerifyPassword->Password));
+  if (EFI_ERROR(Status)) {
+    goto EXIT;
+  }
+
+  Status = SendCommunicateBuffer (Buffer, sizeof(*VerifyPassword));
+
+EXIT:
+  ZeroMem (VerifyPassword, sizeof(*VerifyPassword));
+  return Status;
+}
+
+/**
+  Set a new password.
+
+  @param[in] NewPassword            The user input new password.
+                                    NULL means clear password.
+  @param[in] NewPasswordSize        The size of NewPassword in byte.
+  @param[in] OldPassword            The user input old password.
+                                    NULL means no old password.
+  @param[in] OldPasswordSize        The size of OldPassword in byte.
+
+  @retval EFI_SUCCESS               The NewPassword is set successfully.
+  @retval EFI_SECURITY_VIOLATION    The OldPassword is incorrect.
+  @retval EFI_INVALID_PARAMETER     The password or size is invalid.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to set the password.
+  @retval EFI_ACCESS_DENIED         Password retry count reach.
+  @retval EFI_UNSUPPORTED           NewPassword is not strong enough.
+  @retval EFI_ALREADY_STARTED       NewPassword is in history.
+**/
+EFI_STATUS
+SetPassword (
+  IN   CHAR16       *NewPassword,     OPTIONAL
+  IN   UINTN        NewPasswordSize,
+  IN   CHAR16       *OldPassword,     OPTIONAL
+  IN   UINTN        OldPasswordSize
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+  SMM_PASSWORD_COMMUNICATE_SET_PASSWORD     *SetPassword;
+
+  if (NewPasswordSize > sizeof(SetPassword->NewPassword) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+  if (OldPasswordSize > sizeof(SetPassword->OldPassword) * sizeof(CHAR16)) {
+    return EFI_INVALID_PARAMETER;
+  }
+
+  Buffer = InitCommunicateBuffer (
+             (VOID**)&SetPassword,
+             sizeof(*SetPassword),
+             SMM_PASSWORD_FUNCTION_SET_PASSWORD
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  if (NewPassword != NULL) {
+    Status = UnicodeStrToAsciiStrS (NewPassword, SetPassword->NewPassword, sizeof(SetPassword->NewPassword));
+    if (EFI_ERROR(Status)) {
+      goto EXIT;
+    }
+  } else {
+    SetPassword->NewPassword[0] = 0;
+  }
+
+  if (OldPassword != NULL) {
+    Status = UnicodeStrToAsciiStrS (OldPassword, SetPassword->OldPassword, sizeof(SetPassword->OldPassword));
+    if (EFI_ERROR(Status)) {
+      goto EXIT;
+    }
+  } else {
+    SetPassword->OldPassword[0] = 0;
+  }
+
+  Status = SendCommunicateBuffer (Buffer, sizeof(*SetPassword));
+
+EXIT:
+  ZeroMem (SetPassword, sizeof(*SetPassword));
+  return Status;
+}
+
+/**
+  Return if the password is set.
+
+  @retval TRUE      The password is set.
+  @retval FALSE     The password is not set.
+**/
+BOOLEAN
+IsPasswordInstalled (
+  VOID
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+
+  Buffer = InitCommunicateBuffer (
+             NULL,
+             0,
+             SMM_PASSWORD_FUNCTION_IS_PASSWORD_SET
+             );
+  if (Buffer == NULL) {
+    return FALSE;
+  }
+
+  Status = SendCommunicateBuffer (Buffer, 0);
+  if (EFI_ERROR (Status)) {
+    return FALSE;
+  }
+
+  return TRUE;
+}
+
+/**
+  Get password verification policy.
+
+  @param[out] VerifyPolicy          Verification policy.
+
+  @retval EFI_SUCCESS               Get verification policy successfully.
+  @retval EFI_OUT_OF_RESOURCES      Insufficient resources to get verification policy.
+**/
+EFI_STATUS
+GetPasswordVerificationPolicy (
+  OUT SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    *VerifyPolicy
+  )
+{
+  EFI_STATUS                                    Status;
+  VOID                                          *Buffer;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY        *GetVerifyPolicy;
+
+  Buffer = InitCommunicateBuffer (
+             (VOID**)&GetVerifyPolicy,
+             sizeof(*GetVerifyPolicy),
+             SMM_PASSWORD_FUNCTION_GET_VERIFY_POLICY
+             );
+  if (Buffer == NULL) {
+    return EFI_OUT_OF_RESOURCES;
+  }
+
+  Status = SendCommunicateBuffer (Buffer, sizeof(*GetVerifyPolicy));
+  if (!EFI_ERROR (Status)) {
+    CopyMem (VerifyPolicy, GetVerifyPolicy, sizeof (SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY));
+  }
+
+  return Status;
+}
+
+/**
+  Return if the password was verified.
+
+  @retval TRUE      The password was verified.
+  @retval FALSE     The password was not verified.
+**/
+BOOLEAN
+WasPasswordVerified (
+  VOID
+  )
+{
+  EFI_STATUS                                Status;
+  VOID                                      *Buffer;
+
+  Buffer = InitCommunicateBuffer (
+             NULL,
+             0,
+             SMM_PASSWORD_FUNCTION_WAS_PASSWORD_VERIFIED
+             );
+  if (Buffer == NULL) {
+    return FALSE;
+  }
+
+  Status = SendCommunicateBuffer (Buffer, 0);
+  if (EFI_ERROR (Status)) {
+    return FALSE;
+  }
+
+  return TRUE;
+}
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeStrings.uni b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeStrings.uni
new file mode 100644
index 0000000000..5cfedd2539
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeStrings.uni
@@ -0,0 +1,30 @@
+/** @file
+// String definitions for User Authentication formset.
+//
+// Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+//
+// SPDX-License-Identifier: BSD-2-Clause-Patent
+//
+**/
+
+#langdef en-US  "English"
+#langdef fr-FR  "Francais"
+
+
+#string STR_FORM_SET_TITLE             #language en-US "User Password Management"
+                                       #language fr-FR "User Password Management"
+#string STR_FORM_SET_TITLE_HELP        #language en-US "This Driver mainly handle user's password"
+                                       #language fr-FR "This Driver mainly handle user's password"
+#string STR_FORM_TITLE                 #language en-US "Password Management Form"
+                                       #language fr-FR "Password Management Form"
+#string STR_ADMIN_PASSWORD_PROMPT      #language en-US "Change Admin Password"
+                                       #language fr-FR "Change Admin Password"
+#string STR_ADMIN_PASSWORD_HELP        #language en-US "Input old admin password if it was set, then you can change the password to a new one. After the change action, you may need input the new password when you enter UI. The new password must be between 8 and 32 chars include lowercase, uppercase alphabetic, number, and symbol. Input an empty password can clean old admin password, then no need input password to enter UI."
+                                       #language fr-FR "Input old admin password if it was set, then you can change the password to a new one. After the change action, you may need input the new password when you enter UI. The new password must be between 8 and 32 chars include lowercase, uppercase alphabetic, number, and symbol. Input an empty password can clean old admin password, then no need input password to enter UI."
+#string STR_ADMIN_PASSWORD_STS_HELP    #language en-US "Current Admin Password status: Installed or Not Installed."
+                                       #language fr-FR "Current Admin Password status: Installed or Not Installed."
+#string STR_ADMIN_PASSWORD_STS_PROMPT  #language en-US "Admin Password Status"
+                                       #language fr-FR "Admin Password Status"
+#string STR_ADMIN_PASSWORD_STS_CONTENT #language en-US ""
+                                       #language fr-FR ""
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeVfr.vfr b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeVfr.vfr
new file mode 100644
index 0000000000..b0aacdb00c
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxeVfr.vfr
@@ -0,0 +1,39 @@
+///** @file
+// UserAuthentication formset.
+//
+// Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+// SPDX-License-Identifier: BSD-2-Clause-Patent
+//
+//**/
+
+#include <Guid/HiiPlatformSetupFormset.h>
+#include "UserAuthenticationDxeFormset.h"
+
+formset
+  guid      = USER_AUTHENTICATION_FORMSET_GUID,
+  title     = STRING_TOKEN(STR_FORM_SET_TITLE),
+  help      = STRING_TOKEN(STR_FORM_SET_TITLE_HELP),
+  classguid = EFI_HII_PLATFORM_SETUP_FORMSET_GUID,
+
+  form formid = 1,
+      title  = STRING_TOKEN(STR_FORM_TITLE);
+
+      grayoutif  TRUE;
+        text
+          help  = STRING_TOKEN(STR_ADMIN_PASSWORD_STS_HELP),
+          text  = STRING_TOKEN(STR_ADMIN_PASSWORD_STS_PROMPT),
+          text  = STRING_TOKEN(STR_ADMIN_PASSWORD_STS_CONTENT);
+      endif;
+
+      password
+          prompt  = STRING_TOKEN(STR_ADMIN_PASSWORD_PROMPT),
+          help    = STRING_TOKEN(STR_ADMIN_PASSWORD_HELP),
+          flags   = INTERACTIVE,
+          key     = ADMIN_PASSWORD_KEY_ID,
+          minsize = MIN_PASSWORD_LEN,
+          maxsize = MAX_PASSWORD_LEN,
+      endpassword;
+
+  endform;
+
+endformset;
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.c b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.c
new file mode 100644
index 0000000000..ac341e57f6
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.c
@@ -0,0 +1,674 @@
+/** @file
+
+  Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#include "UserAuthenticationSmm.h"
+
+EFI_SMM_VARIABLE_PROTOCOL       *mSmmVariable;
+
+UINTN                           mAdminPasswordTryCount = 0;
+
+BOOLEAN                         mNeedReVerify = TRUE;
+BOOLEAN                         mPasswordVerified = FALSE;
+
+/**
+  Verify if the password is correct.
+
+  @param[in]  Password               The user input password.
+  @param[in]  PasswordSize           The size of Password in byte.
+  @param[in]  UserPasswordVarStruct  The storage of password in variable.
+
+  @retval EFI_SUCCESS              The password is correct.
+  @retval EFI_SECURITY_VIOLATION   The password is incorrect.
+**/
+EFI_STATUS
+VerifyPassword (
+  IN CHAR8                          *Password,
+  IN UINTN                          PasswordSize,
+  IN USER_PASSWORD_VAR_STRUCT       *UserPasswordVarStruct
+  )
+{
+  BOOLEAN  HashOk;
+  UINT8    HashData[PASSWORD_HASH_SIZE];
+
+  HashOk = KeyLibGeneratePBKDF2Hash (
+             HASH_TYPE_SHA256,
+             (UINT8 *)Password,
+             PasswordSize,
+             UserPasswordVarStruct->PasswordSalt,
+             sizeof(UserPasswordVarStruct->PasswordSalt),
+             HashData,
+             sizeof(HashData)
+             );
+  if (!HashOk) {
+    return EFI_DEVICE_ERROR;
+  }
+  if (KeyLibSlowCompareMem (UserPasswordVarStruct->PasswordHash, HashData, PASSWORD_HASH_SIZE) == 0) {
+    return EFI_SUCCESS;
+  } else {
+    return EFI_SECURITY_VIOLATION;
+  }
+}
+
+/**
+  Get hash data of password from non-volatile variable region.
+
+  @param[in]   UserGuid               The user GUID of the password variable.
+  @param[in]   Index                  The index of the password.
+                                      0 means current password.
+                                      Non-0 means the password history.
+  @param[out]  UserPasswordVarStruct  The storage of password in variable.
+
+  @retval EFI_SUCCESS             The password hash is returned successfully.
+  @retval EFI_NOT_FOUND           The password hash is not found.
+**/
+EFI_STATUS
+GetPasswordHashFromVariable (
+  IN  EFI_GUID                       *UserGuid,
+  IN  UINTN                          Index,
+  OUT USER_PASSWORD_VAR_STRUCT       *UserPasswordVarStruct
+  )
+{
+  UINTN                             DataSize;
+  CHAR16                            PasswordName[sizeof(USER_AUTHENTICATION_VAR_NAME)/sizeof(CHAR16) + 5];
+
+  if (Index != 0) {
+    UnicodeSPrint (PasswordName, sizeof (PasswordName), L"%s%04x", USER_AUTHENTICATION_VAR_NAME, Index);
+  } else {
+    UnicodeSPrint (PasswordName, sizeof (PasswordName), L"%s", USER_AUTHENTICATION_VAR_NAME);
+  }
+
+  DataSize = sizeof(*UserPasswordVarStruct);
+  return mSmmVariable->SmmGetVariable (
+                         PasswordName,
+                         UserGuid,
+                         NULL,
+                         &DataSize,
+                         UserPasswordVarStruct
+                         );
+}
+
+/**
+  Save password hash data to non-volatile variable region.
+
+  @param[in]   UserGuid               The user GUID of the password variable.
+  @param[in]   UserPasswordVarStruct  The storage of password in variable.
+
+  @retval EFI_SUCCESS             The password hash is saved successfully.
+  @retval EFI_OUT_OF_RESOURCES    Insufficient resources to save the password hash.
+**/
+EFI_STATUS
+SavePasswordHashToVariable (
+  IN EFI_GUID                       *UserGuid,
+  IN USER_PASSWORD_VAR_STRUCT       *UserPasswordVarStruct
+  )
+{
+  EFI_STATUS                        Status;
+
+  if (UserPasswordVarStruct == NULL) {
+    Status = mSmmVariable->SmmSetVariable (
+                             USER_AUTHENTICATION_VAR_NAME,
+                             UserGuid,
+                             EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_NON_VOLATILE,
+                             0,
+                             NULL
+                             );
+  } else {
+    Status = mSmmVariable->SmmSetVariable (
+                             USER_AUTHENTICATION_VAR_NAME,
+                             UserGuid,
+                             EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_NON_VOLATILE,
+                             sizeof(*UserPasswordVarStruct),
+                             UserPasswordVarStruct
+                             );
+  }
+  if (EFI_ERROR (Status)) {
+    DEBUG ((DEBUG_ERROR, "SavePasswordHashToVariable fails with %r\n", Status));
+  }
+
+  return Status;
+}
+
+/**
+  Save old password hash data to non-volatile variable region as history.
+
+  The number of password history variable is limited.
+  If all the password history variables are used, the new password history
+  will override the oldest one.
+
+  @param[in]   UserGuid               The user GUID of the password variable.
+  @param[in]   UserPasswordVarStruct  The storage of password in variable.
+
+  @retval EFI_SUCCESS             The password hash is saved successfully.
+  @retval EFI_OUT_OF_RESOURCES    Insufficient resources to save the password hash.
+**/
+EFI_STATUS
+SaveOldPasswordToHistory (
+  IN EFI_GUID                       *UserGuid,
+  IN USER_PASSWORD_VAR_STRUCT       *UserPasswordVarStruct
+  )
+{
+  EFI_STATUS                        Status;
+  UINTN                             DataSize;
+  UINT32                            LastIndex;
+  CHAR16                            PasswordName[sizeof(USER_AUTHENTICATION_VAR_NAME)/sizeof(CHAR16) + 5];
+
+  DEBUG ((DEBUG_INFO, "SaveOldPasswordToHistory\n"));
+
+  DataSize = sizeof(LastIndex);
+  Status = mSmmVariable->SmmGetVariable (
+                           USER_AUTHENTICATION_HISTORY_LAST_VAR_NAME,
+                           UserGuid,
+                           NULL,
+                           &DataSize,
+                           &LastIndex
+                           );
+  if (EFI_ERROR(Status)) {
+    LastIndex = 0;
+  }
+  if (LastIndex >= PASSWORD_HISTORY_CHECK_COUNT) {
+    LastIndex = 0;
+  }
+
+  LastIndex ++;
+  UnicodeSPrint (PasswordName, sizeof (PasswordName), L"%s%04x", USER_AUTHENTICATION_VAR_NAME, LastIndex);
+
+
+  Status = mSmmVariable->SmmSetVariable (
+                           PasswordName,
+                           UserGuid,
+                           EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_NON_VOLATILE,
+                           sizeof(*UserPasswordVarStruct),
+                           UserPasswordVarStruct
+                           );
+  DEBUG ((DEBUG_INFO, "  -- to %s, %r\n", PasswordName, Status));
+  if (!EFI_ERROR(Status)) {
+    Status = mSmmVariable->SmmSetVariable (
+                             USER_AUTHENTICATION_HISTORY_LAST_VAR_NAME,
+                             UserGuid,
+                             EFI_VARIABLE_BOOTSERVICE_ACCESS | EFI_VARIABLE_NON_VOLATILE,
+                             sizeof(LastIndex),
+                             &LastIndex
+                             );
+    DEBUG ((DEBUG_INFO, " LastIndex - 0x%04x, %r\n", LastIndex, Status));
+  }
+
+  return Status;
+}
+
+/**
+  Calculate password hash data and save it to non-volatile variable region.
+
+  @param[in]  UserGuid               The user GUID of the password variable.
+  @param[in]  Password               The user input password.
+                                     NULL means delete the password variable.
+  @param[in]  PasswordSize           The size of Password in byte.
+
+  @retval EFI_SUCCESS             The password hash is calculated and saved.
+  @retval EFI_OUT_OF_RESOURCES    Insufficient resources to save the password hash.
+**/
+EFI_STATUS
+SavePasswordToVariable (
+  IN  EFI_GUID                      *UserGuid,
+  IN  CHAR8                         *Password,  OPTIONAL
+  IN  UINTN                         PasswordSize
+  )
+{
+  EFI_STATUS                        Status;
+  USER_PASSWORD_VAR_STRUCT          UserPasswordVarStruct;
+  BOOLEAN                           HashOk;
+
+  //
+  // If password is NULL, it means we want to clean password field saved in variable region.
+  //
+  if (Password != NULL) {
+    KeyLibGenerateSalt (UserPasswordVarStruct.PasswordSalt, sizeof(UserPasswordVarStruct.PasswordSalt));
+    HashOk = KeyLibGeneratePBKDF2Hash (
+               HASH_TYPE_SHA256,
+               (UINT8 *)Password,
+               PasswordSize,
+               UserPasswordVarStruct.PasswordSalt,
+               sizeof(UserPasswordVarStruct.PasswordSalt),
+               UserPasswordVarStruct.PasswordHash,
+               sizeof(UserPasswordVarStruct.PasswordHash)
+               );
+    if (!HashOk) {
+      return EFI_DEVICE_ERROR;
+    }
+    Status = SavePasswordHashToVariable (UserGuid, &UserPasswordVarStruct);
+    //
+    // Save Password data to history variable
+    //
+    if (!EFI_ERROR(Status)) {
+      SaveOldPasswordToHistory (UserGuid, &UserPasswordVarStruct);
+    }
+  } else {
+    Status = SavePasswordHashToVariable (UserGuid, NULL);
+  }
+
+  return Status;
+}
+
+/**
+  Verify the password.
+  If the password variable does not exist, it passes the verification.
+  If the password variable exists, it does verification based upon password variable.
+
+  @param[in]  UserGuid               The user GUID of the password variable.
+  @param[in]  Password               The user input password.
+  @param[in]  PasswordSize           The size of Password in byte.
+
+  @retval TRUE    The verification passes.
+  @retval FALSE   The verification fails.
+**/
+BOOLEAN
+IsPasswordVerified (
+  IN EFI_GUID                       *UserGuid,
+  IN CHAR8                          *Password,
+  IN UINTN                          PasswordSize
+  )
+{
+  USER_PASSWORD_VAR_STRUCT          UserPasswordVarStruct;
+  EFI_STATUS                        Status;
+  UINTN                             *PasswordTryCount;
+
+  PasswordTryCount = &mAdminPasswordTryCount;
+
+  Status = GetPasswordHashFromVariable (UserGuid, 0, &UserPasswordVarStruct);
+  if (EFI_ERROR(Status)) {
+    return TRUE;
+  }
+
+  //
+  // Old password exists
+  //
+  Status = VerifyPassword (Password, PasswordSize, &UserPasswordVarStruct);
+  if (EFI_ERROR(Status)) {
+    if (Password[0] != 0) {
+      *PasswordTryCount = *PasswordTryCount + 1;
+    }
+    return FALSE;
+  }
+
+  return TRUE;
+}
+
+/**
+  Return if the password is set.
+
+  @param[in]  UserGuid               The user GUID of the password variable.
+
+  @retval TRUE    The password is set.
+  @retval FALSE   The password is not set.
+**/
+BOOLEAN
+IsPasswordSet (
+  IN EFI_GUID                       *UserGuid
+  )
+{
+  USER_PASSWORD_VAR_STRUCT          UserPasswordVarStruct;
+  EFI_STATUS                        Status;
+
+  Status = GetPasswordHashFromVariable(UserGuid, 0, &UserPasswordVarStruct);
+  if (EFI_ERROR(Status)) {
+    return FALSE;
+  }
+  return TRUE;
+}
+
+/**
+  Return if the password is strong.
+  Criteria:
+  1) length >= PASSWORD_MIN_SIZE
+  2) include lower case, upper case, number, symbol.
+
+  @param[in]  Password               The user input password.
+  @param[in]  PasswordSize           The size of Password in byte.
+
+  @retval TRUE    The password is strong.
+  @retval FALSE   The password is weak.
+**/
+BOOLEAN
+IsPasswordStrong (
+  IN CHAR8   *Password,
+  IN UINTN   PasswordSize
+  )
+{
+  UINTN   Index;
+  BOOLEAN HasLowerCase;
+  BOOLEAN HasUpperCase;
+  BOOLEAN HasNumber;
+  BOOLEAN HasSymbol;
+
+  if (PasswordSize < PASSWORD_MIN_SIZE) {
+    return FALSE;
+  }
+
+  HasLowerCase = FALSE;
+  HasUpperCase = FALSE;
+  HasNumber = FALSE;
+  HasSymbol = FALSE;
+  for (Index = 0; Index < PasswordSize - 1; Index++) {
+    if (Password[Index] >= 'a' && Password[Index] <= 'z') {
+      HasLowerCase = TRUE;
+    } else if (Password[Index] >= 'A' && Password[Index] <= 'Z') {
+      HasUpperCase = TRUE;
+    } else if (Password[Index] >= '0' && Password[Index] <= '9') {
+      HasNumber = TRUE;
+    } else {
+      HasSymbol = TRUE;
+    }
+  }
+  if ((!HasLowerCase) || (!HasUpperCase) || (!HasNumber) || (!HasSymbol)) {
+    return FALSE;
+  }
+  return TRUE;
+}
+
+/**
+  Return if the password is set before in PASSWORD_HISTORY_CHECK_COUNT.
+
+  @param[in]  UserGuid               The user GUID of the password variable.
+  @param[in]  Password               The user input password.
+  @param[in]  PasswordSize           The size of Password in byte.
+
+  @retval TRUE    The password is set before.
+  @retval FALSE   The password is not set before.
+**/
+BOOLEAN
+IsPasswordInHistory (
+  IN EFI_GUID                       *UserGuid,
+  IN CHAR8                          *Password,
+  IN UINTN                          PasswordSize
+  )
+{
+  EFI_STATUS                     Status;
+  USER_PASSWORD_VAR_STRUCT       UserPasswordVarStruct;
+  UINTN                          Index;
+
+  for (Index = 1; Index <= PASSWORD_HISTORY_CHECK_COUNT; Index++) {
+    Status = GetPasswordHashFromVariable (UserGuid, Index, &UserPasswordVarStruct);
+    if (!EFI_ERROR(Status)) {
+      Status = VerifyPassword (Password, PasswordSize, &UserPasswordVarStruct);
+      if (!EFI_ERROR(Status)) {
+        return TRUE;
+      }
+    }
+  }
+
+  return FALSE;
+}
+
+/**
+  Communication service SMI Handler entry.
+
+  This SMI handler provides services for password management.
+
+  @param[in]     DispatchHandle  The unique handle assigned to this handler by SmiHandlerRegister().
+  @param[in]     RegisterContext Points to an optional handler context which was specified when the
+                                 handler was registered.
+  @param[in, out] CommBuffer     A pointer to a collection of data in memory that will
+                                 be conveyed from a non-SMM environment into an SMM environment.
+  @param[in, out] CommBufferSize The size of the CommBuffer.
+
+  @retval EFI_SUCCESS                         The interrupt was handled and quiesced. No other handlers
+                                              should still be called.
+  @retval EFI_WARN_INTERRUPT_SOURCE_QUIESCED  The interrupt has been quiesced but other handlers should
+                                              still be called.
+  @retval EFI_WARN_INTERRUPT_SOURCE_PENDING   The interrupt is still pending and other handlers should still
+                                              be called.
+  @retval EFI_INTERRUPT_PENDING               The interrupt could not be quiesced.
+**/
+EFI_STATUS
+EFIAPI
+SmmPasswordHandler (
+  IN     EFI_HANDLE                 DispatchHandle,
+  IN     CONST VOID                 *RegisterContext,
+  IN OUT VOID                       *CommBuffer,
+  IN OUT UINTN                      *CommBufferSize
+  )
+{
+  EFI_STATUS                                Status;
+  SMM_PASSWORD_COMMUNICATE_HEADER           *SmmFunctionHeader;
+  UINTN                                     CommBufferPayloadSize;
+  UINTN                                     TempCommBufferSize;
+  SMM_PASSWORD_COMMUNICATE_SET_PASSWORD     SmmCommunicateSetPassword;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_PASSWORD  SmmCommunicateVerifyPassword;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    SmmCommunicateSetVerifyPolicy;
+  SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY    *SmmCommunicateGetVerifyPolicy;
+  UINTN                                     PasswordLen;
+  EFI_GUID                                  *UserGuid;
+  UINTN                                     *PasswordTryCount;
+
+  //
+  // If input is invalid, stop processing this SMI
+  //
+  if (CommBuffer == NULL || CommBufferSize == NULL) {
+    return EFI_SUCCESS;
+  }
+
+  TempCommBufferSize = *CommBufferSize;
+  PasswordLen = 0;
+
+  if (TempCommBufferSize < sizeof (SMM_PASSWORD_COMMUNICATE_HEADER)) {
+    DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: SMM communication buffer size invalid!\n"));
+    return EFI_SUCCESS;
+  }
+
+  CommBufferPayloadSize = TempCommBufferSize - sizeof (SMM_PASSWORD_COMMUNICATE_HEADER);
+
+  Status   = EFI_SUCCESS;
+  SmmFunctionHeader = (SMM_PASSWORD_COMMUNICATE_HEADER *)CommBuffer;
+
+  UserGuid = &gUserAuthenticationGuid;
+  PasswordTryCount = &mAdminPasswordTryCount;
+
+  switch (SmmFunctionHeader->Function) {
+  case SMM_PASSWORD_FUNCTION_IS_PASSWORD_SET:
+    PasswordTryCount = NULL;
+    if (CommBufferPayloadSize != 0) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: IS_PASSWORD_SET payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    if (IsPasswordSet(UserGuid)) {
+      Status = EFI_SUCCESS;
+    } else {
+      Status = EFI_NOT_FOUND;
+    }
+    break;
+  case SMM_PASSWORD_FUNCTION_SET_PASSWORD:
+    if (*PasswordTryCount >= PASSWORD_MAX_TRY_COUNT) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: SET_PASSWORD try count reach!\n"));
+      PasswordTryCount = NULL;
+      Status = EFI_ACCESS_DENIED;
+      goto EXIT;
+    }
+    if (CommBufferPayloadSize != sizeof(SMM_PASSWORD_COMMUNICATE_SET_PASSWORD)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: SET_PASSWORD payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    CopyMem (&SmmCommunicateSetPassword, SmmFunctionHeader + 1, sizeof(SmmCommunicateSetPassword));
+
+    PasswordLen = AsciiStrnLenS(SmmCommunicateSetPassword.OldPassword, sizeof(SmmCommunicateSetPassword.OldPassword));
+    if (PasswordLen == sizeof(SmmCommunicateSetPassword.OldPassword)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: OldPassword invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+
+    if (!IsPasswordVerified (UserGuid, SmmCommunicateSetPassword.OldPassword, PasswordLen + 1)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: PasswordVerify - FAIL\n"));
+      Status = EFI_SECURITY_VIOLATION;
+      goto EXIT;
+    }
+
+    PasswordLen = AsciiStrnLenS(SmmCommunicateSetPassword.NewPassword, sizeof(SmmCommunicateSetPassword.NewPassword));
+    if (PasswordLen == sizeof(SmmCommunicateSetPassword.NewPassword)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: NewPassword invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    if (PasswordLen != 0 && !IsPasswordStrong (SmmCommunicateSetPassword.NewPassword, PasswordLen + 1)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: NewPassword too weak!\n"));
+      Status = EFI_UNSUPPORTED;
+      goto EXIT;
+    }
+    if (PasswordLen != 0 && IsPasswordInHistory (UserGuid, SmmCommunicateSetPassword.NewPassword, PasswordLen + 1)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: NewPassword in history!\n"));
+      Status = EFI_ALREADY_STARTED;
+      goto EXIT;
+    }
+
+    if (PasswordLen == 0) {
+      Status = SavePasswordToVariable (UserGuid, NULL, 0);
+    } else {
+      Status = SavePasswordToVariable (UserGuid, SmmCommunicateSetPassword.NewPassword, PasswordLen + 1);
+    }
+    break;
+
+  case SMM_PASSWORD_FUNCTION_VERIFY_PASSWORD:
+    if (*PasswordTryCount >= PASSWORD_MAX_TRY_COUNT) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: VERIFY_PASSWORD try count reach!\n"));
+      PasswordTryCount = NULL;
+      Status = EFI_ACCESS_DENIED;
+      goto EXIT;
+    }
+    if (CommBufferPayloadSize != sizeof(SMM_PASSWORD_COMMUNICATE_VERIFY_PASSWORD)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: VERIFY_PASSWORD payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    CopyMem (&SmmCommunicateVerifyPassword, SmmFunctionHeader + 1, sizeof(SmmCommunicateVerifyPassword));
+
+    PasswordLen = AsciiStrnLenS(SmmCommunicateVerifyPassword.Password, sizeof(SmmCommunicateVerifyPassword.Password));
+    if (PasswordLen == sizeof(SmmCommunicateVerifyPassword.Password)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: Password invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    if (!IsPasswordVerified (UserGuid, SmmCommunicateVerifyPassword.Password, PasswordLen + 1)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: PasswordVerify - FAIL\n"));
+      Status = EFI_SECURITY_VIOLATION;
+      goto EXIT;
+    }
+    mPasswordVerified = TRUE;
+    Status = EFI_SUCCESS;
+    break;
+
+  case SMM_PASSWORD_FUNCTION_SET_VERIFY_POLICY:
+    PasswordTryCount = NULL;
+    if (CommBufferPayloadSize != sizeof(SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: SET_VERIFY_POLICY payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    CopyMem (&SmmCommunicateSetVerifyPolicy, SmmFunctionHeader + 1, sizeof(SmmCommunicateSetVerifyPolicy));
+    mNeedReVerify = SmmCommunicateSetVerifyPolicy.NeedReVerify;
+    break;
+
+  case SMM_PASSWORD_FUNCTION_GET_VERIFY_POLICY:
+    PasswordTryCount = NULL;
+    if (CommBufferPayloadSize != sizeof(SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY)) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: GET_VERIFY_POLICY payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    SmmCommunicateGetVerifyPolicy = (SMM_PASSWORD_COMMUNICATE_VERIFY_POLICY *) (SmmFunctionHeader + 1);
+    SmmCommunicateGetVerifyPolicy->NeedReVerify = mNeedReVerify;
+    break;
+  case SMM_PASSWORD_FUNCTION_WAS_PASSWORD_VERIFIED:
+    PasswordTryCount = NULL;
+    if (CommBufferPayloadSize != 0) {
+      DEBUG ((DEBUG_ERROR, "SmmPasswordHandler: WAS_PASSWORD_VERIFIED payload buffer invalid!\n"));
+      Status = EFI_INVALID_PARAMETER;
+      goto EXIT;
+    }
+    if (mPasswordVerified) {
+      Status = EFI_SUCCESS;
+    } else {
+      Status = EFI_NOT_STARTED;
+    }
+    break;
+
+  default:
+    PasswordTryCount = NULL;
+    Status = EFI_UNSUPPORTED;
+    break;
+  }
+
+EXIT:
+  if (PasswordTryCount != NULL) {
+    if (Status == EFI_SUCCESS) {
+      *PasswordTryCount = 0;
+    }
+  }
+  SmmFunctionHeader->ReturnStatus = Status;
+
+  return EFI_SUCCESS;
+}
+
+/**
+  Main entry for this driver.
+
+  @param ImageHandle     Image handle this driver.
+  @param SystemTable     Pointer to SystemTable.
+
+  @retval EFI_SUCESS     This function always complete successfully.
+
+**/
+EFI_STATUS
+EFIAPI
+PasswordSmmInit (
+  IN EFI_HANDLE                         ImageHandle,
+  IN EFI_SYSTEM_TABLE                   *SystemTable
+  )
+{
+  EFI_STATUS                            Status;
+  EFI_HANDLE                            SmmHandle;
+  EDKII_VARIABLE_LOCK_PROTOCOL          *VariableLock;
+  CHAR16                                PasswordHistoryName[sizeof(USER_AUTHENTICATION_VAR_NAME)/sizeof(CHAR16) + 5];
+  UINTN                                 Index;
+
+  ASSERT (PASSWORD_HASH_SIZE == SHA256_DIGEST_SIZE);
+  ASSERT (PASSWORD_HISTORY_CHECK_COUNT < 0xFFFF);
+
+  Status = gSmst->SmmLocateProtocol (&gEfiSmmVariableProtocolGuid, NULL, (VOID**)&mSmmVariable);
+  ASSERT_EFI_ERROR (Status);
+
+  //
+  // Make password variables read-only for DXE driver for security concern.
+  //
+  Status = gBS->LocateProtocol (&gEdkiiVariableLockProtocolGuid, NULL, (VOID **) &VariableLock);
+  if (!EFI_ERROR (Status)) {
+    Status = VariableLock->RequestToLock (VariableLock, USER_AUTHENTICATION_VAR_NAME, &gUserAuthenticationGuid);
+    ASSERT_EFI_ERROR (Status);
+
+    for (Index = 1; Index <= PASSWORD_HISTORY_CHECK_COUNT; Index++) {
+      UnicodeSPrint (PasswordHistoryName, sizeof (PasswordHistoryName), L"%s%04x", USER_AUTHENTICATION_VAR_NAME, Index);
+      Status = VariableLock->RequestToLock (VariableLock, PasswordHistoryName, &gUserAuthenticationGuid);
+      ASSERT_EFI_ERROR (Status);
+    }
+    Status = VariableLock->RequestToLock (VariableLock, USER_AUTHENTICATION_HISTORY_LAST_VAR_NAME, &gUserAuthenticationGuid);
+    ASSERT_EFI_ERROR (Status);
+  }
+
+  SmmHandle = NULL;
+  Status    = gSmst->SmiHandlerRegister (SmmPasswordHandler, &gUserAuthenticationGuid, &SmmHandle);
+  ASSERT_EFI_ERROR (Status);
+  if (EFI_ERROR (Status)) {
+    return Status;
+  }
+
+  if (IsPasswordCleared()) {
+    DEBUG ((DEBUG_INFO, "IsPasswordCleared\n"));
+    SavePasswordToVariable (&gUserAuthenticationGuid, NULL, 0);
+  }
+
+  return EFI_SUCCESS;
+}
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.h b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.h
new file mode 100644
index 0000000000..2f8c3c8c67
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.h
@@ -0,0 +1,52 @@
+/** @file
+  Header file for UserAuthenticationSmm.
+
+  Copyright (c) 2018, Intel Corporation. All rights reserved.<BR>
+  SPDX-License-Identifier: BSD-2-Clause-Patent
+
+**/
+
+#ifndef __USER_AUTHENTICATION_SMM_H__
+#define __USER_AUTHENTICATION_SMM_H__
+
+#include <PiSmm.h>
+
+#include <Protocol/SmmVariable.h>
+#include <Protocol/VariableLock.h>
+
+#include <Guid/UserAuthentication.h>
+
+#include <Library/DebugLib.h>
+#include <Library/BaseLib.h>
+#include <Library/BaseMemoryLib.h>
+#include <Library/PrintLib.h>
+#include <Library/UefiBootServicesTableLib.h>
+#include <Library/SmmServicesTableLib.h>
+#include <Library/MemoryAllocationLib.h>
+#include <Library/SmmServicesTableLib.h>
+#include <Library/BaseCryptLib.h>
+#include <Library/PlatformPasswordLib.h>
+
+#include "KeyService.h"
+
+#define PASSWORD_SALT_SIZE   32
+#define PASSWORD_HASH_SIZE   32 // SHA256_DIGEST_SIZE
+
+#define PASSWORD_MAX_TRY_COUNT  3
+#define PASSWORD_HISTORY_CHECK_COUNT  5
+
+//
+// Name of the variable
+//
+#define USER_AUTHENTICATION_VAR_NAME L"Password"
+#define USER_AUTHENTICATION_HISTORY_LAST_VAR_NAME L"PasswordLast"
+
+//
+// Variable storage
+//
+typedef struct {
+  UINT8        PasswordHash[PASSWORD_HASH_SIZE];
+  UINT8        PasswordSalt[PASSWORD_SALT_SIZE];
+} USER_PASSWORD_VAR_STRUCT;
+
+#endif
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf
new file mode 100644
index 0000000000..b8b3512a3f
--- /dev/null
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf
@@ -0,0 +1,53 @@
+## @file
+#  User Authentication Smm Driver.
+#
+#  This driver provides SMM services for DXE user authentication module.
+#
+# Copyright (c) 2017 - 2018, Intel Corporation. All rights reserved.<BR>
+# SPDX-License-Identifier: BSD-2-Clause-Patent
+#
+##
+
+[Defines]
+  INF_VERSION                    = 0x00010005
+  BASE_NAME                      = UserAuthenticationSmm
+  FILE_GUID                      = 8fc6aaaa-4561-4815-8cf7-b87312992dce
+  MODULE_TYPE                    = DXE_SMM_DRIVER
+  VERSION_STRING                 = 1.0
+  PI_SPECIFICATION_VERSION       = 0x0001000A
+  ENTRY_POINT                    = PasswordSmmInit
+
+[Sources]
+  UserAuthenticationSmm.c
+  UserAuthenticationSmm.h
+  KeyService.c
+  KeyService.h
+
+[Packages]
+  MdePkg/MdePkg.dec
+  MdeModulePkg/MdeModulePkg.dec
+  CryptoPkg/CryptoPkg.dec
+  UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+
+[LibraryClasses]
+  UefiBootServicesTableLib
+  UefiDriverEntryPoint
+  DebugLib
+  BaseLib
+  BaseMemoryLib
+  PrintLib
+  SmmServicesTableLib
+  MemoryAllocationLib
+  UefiLib
+  BaseCryptLib
+  PlatformPasswordLib
+
+[Guids]
+  gUserAuthenticationGuid                       ## CONSUMES  ## GUID
+
+[Protocols]
+  gEdkiiVariableLockProtocolGuid                ## CONSUMES
+  gEfiSmmVariableProtocolGuid                   ## CONSUMES
+
+[Depex]
+  gEfiSmmVariableProtocolGuid AND gEfiVariableWriteArchProtocolGuid
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
index 7162637e24..fc93c72d20 100644
--- a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dec
@@ -15,5 +15,20 @@ [Defines]
   DEC_SPECIFICATION = 0x00010017
   PACKAGE_NAME      = UserInterfaceFeaturePkg
   PACKAGE_VERSION   = 0.1
   PACKAGE_GUID      = 5A92199C-C2ED-4A3F-9ED0-C278DEA0DA47
 
+[Includes]
+  Include
+
+[Guids]
+  gEfiUserInterfaceFeaturePkgTokenSpaceGuid  = { 0x13c2147c, 0x75b6, 0x48ee, { 0xa4, 0x4b, 0xfc, 0x4, 0xb, 0x44, 0x97, 0xbd } }
+  ## Include Include/Guid/UserAuthentication.h
+  gUserAuthenticationGuid = { 0xee24a7f7, 0x606b, 0x4724, { 0xb3, 0xc9, 0xf5, 0xae, 0x4a, 0x3b, 0x81, 0x65} }
+
+[PcdsFixedAtBuild, PcdsPatchableInModule]
+  ## Indicate whether the password is cleared.
+  # When it is configured to Dynamic or DynamicEx, it can be set through detection using
+  # a platform-specific method (e.g. Board Jumper set) in a actual platform in early boot phase.<BR><BR>
+  # @Prompt The password clear status
+  gEfiUserInterfaceFeaturePkgTokenSpaceGuid.PcdPasswordCleared|FALSE|BOOLEAN|0x0001001C
+
diff --git a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc
index 7098affee9..2c24e43f95 100644
--- a/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc
+++ b/Platform/Intel/UserInterfaceFeaturePkg/UserInterfaceFeaturePkg.dsc
@@ -19,5 +19,60 @@ [Defines]
   OUTPUT_DIRECTORY               = Build/UserInterfaceFeaturePkg
   SUPPORTED_ARCHITECTURES        = IA32|X64
   BUILD_TARGETS                  = DEBUG|RELEASE|NOOPT
   SKUID_IDENTIFIER               = DEFAULT
 
+[LibraryClasses]
+  UefiDriverEntryPoint|MdePkg/Library/UefiDriverEntryPoint/UefiDriverEntryPoint.inf
+  BaseLib|MdePkg/Library/BaseLib/BaseLib.inf
+  BaseMemoryLib|MdePkg/Library/BaseMemoryLib/BaseMemoryLib.inf
+  PrintLib|MdePkg/Library/BasePrintLib/BasePrintLib.inf
+  IoLib|MdePkg/Library/BaseIoLibIntrinsic/BaseIoLibIntrinsic.inf
+  UefiBootServicesTableLib|MdePkg/Library/UefiBootServicesTableLib/UefiBootServicesTableLib.inf
+  UefiRuntimeServicesTableLib|MdePkg/Library/UefiRuntimeServicesTableLib/UefiRuntimeServicesTableLib.inf
+  UefiLib|MdePkg/Library/UefiLib/UefiLib.inf
+  UefiHiiServicesLib|MdeModulePkg/Library/UefiHiiServicesLib/UefiHiiServicesLib.inf
+  HiiLib|MdeModulePkg/Library/UefiHiiLib/UefiHiiLib.inf
+  DevicePathLib|MdePkg/Library/UefiDevicePathLib/UefiDevicePathLib.inf
+  TimerLib|MdePkg/Library/BaseTimerLibNullTemplate/BaseTimerLibNullTemplate.inf
+  PcdLib|MdePkg/Library/BasePcdLibNull/BasePcdLibNull.inf
+  DebugLib|MdePkg/Library/BaseDebugLibNull/BaseDebugLibNull.inf
+  IntrinsicLib|CryptoPkg/Library/IntrinsicLib/IntrinsicLib.inf
+  OpensslLib|CryptoPkg/Library/OpensslLib/OpensslLib.inf
+  PlatformPasswordLib|UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
+  UserPasswordLib|UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
+
+[LibraryClasses.common.DXE_DRIVER]
+  MemoryAllocationLib|MdePkg/Library/UefiMemoryAllocationLib/UefiMemoryAllocationLib.inf
+
+[LibraryClasses.common.DXE_SMM_DRIVER]
+  MemoryAllocationLib|MdePkg/Library/SmmMemoryAllocationLib/SmmMemoryAllocationLib.inf
+  SmmServicesTableLib|MdePkg/Library/SmmServicesTableLib/SmmServicesTableLib.inf
+  BaseCryptLib|CryptoPkg/Library/BaseCryptLib/SmmCryptLib.inf
+
+###################################################################################################
+#
+# Components Section - list of the modules and components that will be processed by compilation
+#                      tools and the EDK II tools to generate PE32/PE32+/Coff image files.
+#
+# Note: The EDK II DSC file is not used to specify how compiled binary images get placed
+#       into firmware volume images. This section is just a list of modules to compile from
+#       source into UEFI-compliant binaries.
+#       It is the FDF file that contains information on combining binary files into firmware
+#       volume images, whose concept is beyond UEFI and is described in PI specification.
+#       Binary modules do not need to be listed in this section, as they should be
+#       specified in the FDF file. For example: Shell binary (Shell_Full.efi), FAT binary (Fat.efi),
+#       Logo (Logo.bmp), and etc.
+#       There may also be modules listed in this section that are not required in the FDF file,
+#       When a module listed here is excluded from FDF file, then UEFI-compliant binary will be
+#       generated for it, but the binary will not be put into any firmware volume.
+#
+###################################################################################################
+[Components]
+  UserInterfaceFeaturePkg/Library/PlatformPasswordLibNull/PlatformPasswordLibNull.inf
+  UserInterfaceFeaturePkg/Library/UserPasswordLib/UserPasswordLib.inf
+  UserInterfaceFeaturePkg/Library/UserPasswordUiLib/UserPasswordUiLib.inf
+
+  UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationDxe.inf
+  UserInterfaceFeaturePkg/UserAuthentication/UserAuthentication2Dxe.inf
+  UserInterfaceFeaturePkg/UserAuthentication/UserAuthenticationSmm.inf
+
-- 
2.18.0.windows.1


^ permalink raw reply related	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2019-06-16  4:25 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-06-16  4:25 [edk2-platforms] [patch 0/2] Add UserInterfaceFeaturePkg and UserAuthentication modules Dandan Bi
2019-06-16  4:25 ` [edk2-platforms] [patch 1/2] Platform/Intel: Add UserInterfaceFeaturePkg Dandan Bi
2019-06-16  4:25 ` [edk2-platforms] [patch 2/2] Platform/Intel/UserInterfaceFeaturePkg: Add UserAuthentication modules Dandan Bi

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox