System and method for protecting resources using a wide area network connection
By detecting network adapter removal and changing passwords to supervisory levels, the system ensures secure access to information resources even when the adapter is tampered with, addressing the vulnerability of continuous operation resource protection.
Patent Information
- Application Number
- DE102009012796
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2008-03-19
- Filing Date
- 2009-03-13
- Publication Date
- 2025-10-02
- Estimated Expiration
- 2029-03-13
AI Technical Summary
Existing network adapter removal or deactivation can counteract continuous operation resource protection in information processing systems, compromising the security of hardware and information resources.
Implementing a mechanism to detect network adapter removal by setting an apparent tampering indicator in non-volatile memory and changing hard disk and power-on passwords to supervisory levels if the adapter is removed, ensuring secure access only through authorized means.
Enhances resource protection by preventing unauthorized access to information stored on the hard disk and requiring authorized passwords to regain system access, even if the network adapter is tampered with or disabled.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The present invention relates to a system, a method, and a program product that protect information and computer resources using a wide area network connection of an information handling system.
[0002] JP 2004 - 362 366 A describes an information processing terminal, its operation and its operating program, which prevents the unauthorized reading of storage data of a data storage medium by a third person with a simple structure.
[0003] US 2006 / 0 179 293 A1 describes a method for starting a computer system only in a secure network, wherein a client is connected to a secure network server through the secure network, wherein the secure network server acts as an access control list manager and has an authorization table that lists clients that are authorized to start an operating system only when the client is connected to the secure network server.
[0004] US 2007 / 0 005 951 A1 describes a system and method for a secure operating system boot from a password-protected hard disk, whereby, if a user forgets the power-on password of his computer, he can press the "Enter" key or the "Access" key once to cause the BIOS to find the power-on password in memory and to unlock it in order to start a secure operating system.
[0005] US 6 609 207 B1 describes a data processing system and method for securing a docking station, a portable computer and attaching the docking station to the portable computer, wherein the portable computer can be coupled to the docking station.
[0006] Protecting assets is becoming increasingly important in almost every type of business. Not only are hardware assets, such as portable computers and accessories, expensive and important to protect, but the information assets stored within a computer system are often even more valuable. Information assets can contain a company's legally protected, extremely valuable intellectual property. If this valuable information falls into the wrong hands, such as those of a competitor, the company is likely to suffer irreparable damage.
[0007] Network technology that employs always-on protection is useful for protecting resources and information assets. Commands can be sent to an information processing system, such as a portable computer, instructing the computer to lock the system. Furthermore, systems with GPS functionality can use the network to inform a user of the resource's location. This way, the resource can be instructed to enter locked mode to protect information assets if the system is lost, stolen, or otherwise undetermined. Using GPS technology, the system can also inform the user of its whereabouts so that it can be tracked by owners or law enforcement.However, one problem with always-on resource protection is that the protection can be counteracted if the network adapter used to communicate with the system is removed or otherwise disabled.
[0008] It is an object of the present invention to provide improved protection of resources in a system having a network adapter.
[0009] This object is solved by the subject matter of main claim 1 and the independent claims 7 and 13, which define the present invention.
[0010] Preferred embodiments of the present invention are the subject of the subclaims.
[0011] It has been discovered that the above-mentioned problems can be solved by determining whether the network adapter has been removed from a computer system. If the network adapter, such as a wireless network adapter, has been removed from the computer system, then an indicator of apparent tampering (e.g., a bit) is set in a non-volatile memory area of the computer system. Additionally, a hard disk password is set to a different password according to a hard disk password policy. The hard disk password controls access to files stored on the hard disk. According to one embodiment, the hard disk password is set to a monitoring password.In this way, a malicious user, such as a computer system thief, attempting to circumvent the resource protection mechanism by removing the network adapter would be unable to access files stored on the hard drive without the new hard drive password (such as the monitor password). According to one embodiment, the power-on password is also set to a new password (e.g., a monitor password). In this embodiment, the user would have to enter the new power-on password upon initializing the computer system to access the files stored on the computer system.
[0012] The foregoing is a summary and therefore necessarily contains simplifications, generalizations, and omissions of detail; consequently, those skilled in the art will understand that the summary is illustrative only and is not intended to be limiting in any way. Other aspects, inventive features, and advantages of the present invention, as defined solely by the claims, will become apparent in the non-limiting, detailed description set forth below.
[0013] The present invention will be better understood and its numerous objects, features and advantages will become apparent to those skilled in the art by reference to the accompanying drawings, in which: Fig. 1 is a block diagram of a data processing system in which the methods described herein may be implemented; Fig. 2 an extension of the Fig. 1 to demonstrate that the methods described herein may be performed in a variety of information processing systems operating in a networked environment; Fig. 3 is a network diagram showing an information processing system with a network adapter that receives remote security commands over a computer network; Fig. 4 is a flowchart showing the steps performed due to setup rules used by the information handling system when the network adapter is removed; Fig. 5 is a flowchart showing the steps performed when the network adapter is removed while the information handling system is in operation; and Fig. Figure 6 is a flowchart showing steps performed by the information handling system during initialization to check for tampering and the presence of the network adapter.
[0014] Certain details are set forth in the following description and figures in order to provide a thorough understanding of various embodiments of the invention. However, certain well-known details, often associated with computer and software technology, are omitted from the following description to avoid obscuring the various embodiments of the invention. Furthermore, those skilled in the art will understand that they can practice other embodiments of the invention without one or another of the details described below. Finally, by describing various methods in the following description with reference to steps and procedures, the description itself is intended to provide a clear implementation of the embodiments of the invention, and the steps and procedures of the steps should not be construed as necessary to practice this invention.Instead, the following is intended to provide a detailed description of an example of the invention and should not be considered limiting of the invention itself. Rather, all variations fall within the scope of the invention, which is defined by the claims following the description.
[0015] The following detailed description generally follows the summary of the invention as set forth above, and further explains and expands, where necessary, the definitions of the various aspects and embodiments of the invention. To this end, this detailed description sets forth a computing environment in Fig. 1 suitable for implementing the software and / or hardware techniques associated with the invention. A networked environment is Fig. 2 is presented as an extension of the basic computing environment to demonstrate that modern computing techniques can be implemented using a variety of discrete components.
[0016] Fig. 1 illustrates an information handling system 100, which is a simplified example of a computer system capable of performing the computing operations described herein. The information handling system 100 includes one or more processors 110 connected to a processor interface bus 112. The processor interface bus 112 connects the processors 110 to the northbridge 115, also known as the memory controller hub (MCH). The northbridge 115 is connected to the system memory 120 and provides a means for the processor(s) 110 to access the system memory. The graphics controller 125 is also connected to the northbridge 115. In one embodiment, a PCI Express bus 118 is used to connect the northbridge 115 to the graphics controller 125. The graphics controller 125 is connected to a display device 130, such as a computer monitor.
[0017] The northbridge 115 and a southbridge 135 are interconnected and utilize bus 119. According to one embodiment, the bus is a Direct Media Interface (DMI) bus that transfers data at high speeds in each direction between the northbridge 115 and the southbridge 135. According to another embodiment, a Peripheral Component Interconnect (PCI) bus is used to connect the northbridge and the southbridge. The southbridge 135, also known as the I / O Controller Hub (ICH), is a chip that generally implements capabilities that operate at slower speeds than those provided by the northbridge. The southbridge 135 typically provides various buses used to connect different devices. These buses may include PCI and PCI Express buses, an ISA bus, a System Management Bus (SMBus or SMB), and a Low Pin Count (LPC) bus.The LPC bus is often used to connect low-bandwidth components such as the boot ROM 196 and legacy I / O components (which use a Super I / O chip). The legacy I / O components (198) may include serial and parallel ports, a keyboard, a mouse, and a floppy disk drive controller. The LPC bus is also used to connect the southbridge 135 to a Trusted Platform Module (TPM) 195. Other components often included in the southbridge 135 include a direct memory access (DMA) controller, a programmable interrupt controller (PIC), and a storage device controller, which connect the southbridge 135 to a non-volatile storage device 300, such as a hybrid hard disk drive, using the bus 184.
[0018] The ExpressCard 155 is a slot used to connect hot-pluggable components to the information processing system. The ExpressCard 155 supports both PCI Express and USB connectivity by connecting to the Southbridge 135 using both the Universal Serial Bus (USB) and the PCI Express bus. The Southbridge 135 features a USB controller 140, which provides USB connectivity to components that interface with USB. These components include a webcam (camera) 150, an infrared (IR) receiver 148, a Bluetooth assembly 146 providing wireless local area networks (PANs), a keyboard and track pad 144, and other various USB-connected devices 142, such as a mouse, removable non-volatile memory devices 145, modems, network cards, ISDN connectors, fax machines, printers, USB hubs, and many other types of USB-connected devices.While a removable non-volatile storage device 145 is shown as a USB-connected device, the non-volatile storage device 145 could be coupled using a different interface, such as a Firewire interface, etc. The removable storage device 145 may also be a hybrid disk drive, such as the one shown in FIGS. Fig. Hybrid disk drive 300 shown in Figures 3 to 6.
[0019] The wireless local area network (LAN) device 175 is connected to the southbridge 135 via the PCI or PCI Express bus 172. The LAN device 175 typically implements one of the IEEE 802.11 standards of wireless modulation techniques, all of which use the same protocol to communicate wirelessly between the information handling system 100 and another computer system or device. An optical storage device 190 is connected to the southbridge 135 using a Serial ATA (SATA) bus 188. Serial ATA adapters and devices communicate via a high-speed serial port. The Serial ATA bus is also used to connect the southbridge 135 to other forms of storage devices, such as hard disk drives. Audio circuitry 160, such as a sound card, is connected to the southbridge 135 via bus 158.Audio circuitry 160 is used to provide functionality such as audio line-in and optical digital audio at connector 162, an optical digital output and headphone jack 164, internal speakers 166, and an internal microphone 168. An Ethernet controller 170 is connected to the southbridge 135 using a bus such as the PCI or PCI Express bus. The Ethernet controller 170 is used to connect the information handling system 100 to a computer network such as a local area network (LAN), the Internet, and other public and private computer networks.
[0020] While Fig. 1 shows an information processing system, an information processing system may take various forms. For example, an information processing system may take the form of a workstation, a server, a portable computer, a laptop, a notebook, or a differently sized computer or data processing system. In addition, an information processing system may take other forms such as an organizer (Personal Digital Assistant (PDA)), a gaming device, an ATM machine, a mobile phone, a communications device, or other devices having a processor and a memory.
[0021] The Trusted Platform Module (TPM 195), which is used in the Fig. 1 and described herein as providing security functions, is only one example of a hardware security module (HSM). Therefore, the TPM described and claimed herein includes any type of HSM that has, but is not limited to, a hardware security device that complies with the Trusted Computing Groups (TCG) standard and is referred to as "Trusted Platform Module (TPM) Specification Version 1.2." The TPM is a hardware security subsystem that may be included in any information processing system, such as those described in the Fig. 2 are shown.
[0022] The Fig. 2 gives an extension of the Fig. 1 to illustrate that the methods described herein can be carried out on a wide variety of information processing systems operating in a networked environment. The types of information processing systems range from small handheld devices, such as handheld computer / mobile phone 210, to large mainframe systems, such as mainframe computer 270. Examples of handheld computers 210 include personal digital assistants (PDAs), entertainment devices such as MP3 players, portable televisions, and CD players. Other examples of information processing systems include a pen or tablet computer 220, a laptop or notebook computer 230, a workstation 240, a personal computer system 250, and a server 260. Other types of information processing systems described in the Fig. 2 are not shown individually, are represented by the information processing system 280. As shown, the various information processing systems may be networked together using the computer network 200. Types of computer networks that may be used to interconnect the various information processing systems include local area networks (LANs), wireless local area networks (WLANs), the Internet, the public switched telephone network (PSTN), other wireless networks, and any other network topology that may be used to interconnect the information processing systems. Many of the information processing systems include non-volatile data storage, such as hard disks and / or non-volatile memory. Some of the Fig. The information handling systems shown in Figure 2 are shown with separate non-volatile data storage devices. (The server 260 is shown with the non-volatile data storage devices 265, the mainframe computer 270 is shown with the non-volatile data storage devices 275, and the information handling system 280 is shown with the non-volatile data storage devices 285.) The non-volatile data storage devices may be a component external to the various information handling systems or internal to one of the information handling systems. Additionally, the removable non-volatile storage device 145 may be shared between two or more information handling systems using various techniques, such as connecting the removable non-volatile storage device 145 to a USB port or other port of the information handling system.
[0023] Fig. Figure 3 is a network diagram illustrating an information handling system with a network adapter that receives remote security commands over a computer network. The information handling system 100 includes a network adapter 300, such as a wireless wide area network (WWAN) card shown. In a preferred embodiment, this network adapter is "ON" whenever the information handling system is powered on and enables the information handling system to receive commands to lock the information handling system in the event that the system is lost or stolen, preventing access to the information stored on the information handling system's hard drive.As used herein, "network adapter" includes any wired or wireless network adapter that allows the information handling system to communicate with another information system, such as using the computer network 200. Examples of network adapters include Ethernet adapters, Token Ring adapters, 802.11 type wireless adapters, Bluetooth adapters, and any other adapter that allows the information handling system to interface with another information handling system and / or a computer network, such as the computer network 200.
[0024] The administrator 305, such as the owner of the information handling system or an IT professional responsible for resource protection and security within a company, sends commands 310 to the information handling system. The commands 310, such as "lock the system," are transmitted through the computer network 200, such as the Internet, and are received by the network adapter 300 of the information handling system. Obviously, the network adapter 300 is a critical point in the communication path between the administrator 305 and the information handling system 100. A malicious user, such as a thief of the information handling system 100, may attempt to counteract the receipt of commands designed to protect resources stored on the information handling system 100 by removing or otherwise disabling the network adapter 300.However, when this happens, the information processing system detects that the network adapter has been removed or disabled and responds with various security measures, as described in the . Fig. 4 to 6.
[0025] The Fig. Figure 4 is a flowchart showing the steps performed to establish policies used by the information handling system when the network adapter is removed. This establishment is performed by user 410. User 410 may be only the user who establishes the information handling system (e.g., an administrator or IT professional), with another user being assigned to the information handling system after it has been established. This is particularly the case if the enterprise wishes passwords used by the system when tampering is apparent to be unknown to the assigned user, but only to the IT professionals responsible for protecting the enterprise's information resources.
[0026] The flow begins at 400, after which, in step 420, the information handling system receives the hard disk password to be used if the network adapter is removed from the information handling system. For example, the policy may be established to set the hard disk password to the system's monitor password (SVP), the power-on password (POP), or another password. In one embodiment, the password (e.g., the SVP) is unknown to the user of the information handling system, but instead is known to the IT department within the company. This embodiment prevents the user from knowingly or unknowingly disclosing the password to others, such as a thief of the system. In step 425, the hard disk password policy is stored in a non-volatile memory area 450, which is accessed by an initialization process (e.g.,the BIOS), which runs when the information processing system is initialized.
[0027] In step 430, the information handling system receives the new power-on password to be used if the network adapter is removed from the information handling system. For example, the policy may be established to set the hard disk password to the monitor password (SVP) or another password. According to one embodiment, the password (such as the SVP) is unknown to the user of the information handling system, but instead is known to the IT department within a company. This embodiment prevents the user from knowingly or unknowingly revealing the password to others, such as a thief of the system. In step 435, the power-on password policy is stored in the non-volatile memory area 450, which can be accessed through an initialization process.In step 440, an apparent tamper indicator, such as a tamper-indicating bit, is preset to "NO" (e.g., "0") to indicate that no tampering is apparent with the information handling system's network adapter. This apparent tamper indicator is stored in non-volatile memory 450. If tampering is detected, this bit is set to "YES" (e.g., "1"), and the initialization process takes appropriate security measures to secure the information handling system by setting the hard disk password and the power-on password, as described in FIGS. Fig. 5 and Fig. 6. The setup process then ends at 495.
[0028] The Fig. 5 is a flowchart illustrating the steps performed when the network adapter is removed while the information handling system is in operation. As used herein, the term "removed," when used with reference to the network adapter of the information handling system, includes both physically removing the network adapter from the information handling system (e.g., removing a wireless wide area network (WWAN) card from the information handling system, etc.) and disabling the network adapter (e.g., turning off the network adapter so that network communications cannot be received, damaging the network adapter, or otherwise disabling the network adapter) such that the network adapter is "removed" from communication with the information handling system.
[0029] Flow begins at step 500, after which, at step 510, the network adapter is checked to ensure that the network adapter has not been removed from the information handling system (physically removed or disabled). A decision is made as to whether the network adapter is electrically present in the information handling system (decision 520). If the network adapter, such as a wireless wide area network (WWAN) card, is electrically present in the information handling system, decision 520 branches to the "yes" state 515 to continually check for the presence of the network adapter (e.g., checking for card presence every few seconds).
[0030] On the other hand, if any of the checks determine that the network adapter has been removed (e.g., physically removed, disabled, damaged, or otherwise unable to receive network communications), then decision 520 branches to the "No" branch 525 for appropriate treatment. In step 530, the apparent tamper indicator (e.g., a tamper-indicating bit, etc.) in non-volatile memory 450 is set to indicate that tampering with the network adapter has occurred (e.g., by setting the indicator to "YES," "TRUE," "1," or a similar value used to indicate tampering). In step 535, the hard disk password policy is read from non-volatile memory 450, indicating how the hard disk password should be set if tampering is detected (e.g.,The policy may be to set the hard disk password to a "monitor" password or any other password. In step 540, the power-on password policy is read from non-volatile memory 450. The power-on password policy indicates how the power-on password should be set if tampering is detected (e.g., changing the normal power-on password to the monitor password, which requires both the power-on password and the monitor password during the power-on sequence, etc.). In step 545, the hard disk password 555, which protects files stored on one or more hard disks 550, is changed according to the hard disk password policy read in step 535. In step 560, the power-on password 570, stored in non-volatile memory, is changed according to the power-on password policy read in step 540.After the hard disk password and power-on password have been set according to appropriate protocols, the system is shut down in step 580, requiring the user (e.g., someone who has stolen the information handling system, etc.) to reboot the system. In the predefined process 590, the system is rebooted by the user and used during the startup process (in . Fig. 6), steps are taken to protect the information processing system and the information stored therein.
[0031] The Fig. 6 is a flowchart illustrating the steps performed by the information handling system during initialization to check for tampering and the presence of the network adapter. The process begins at 600, after which, at step 602, the apparent tamper indicator (e.g., a tamper-indicating bit, etc.) stored in non-volatile memory 450 is checked to determine whether tampering with the network adapter has been detected during a previous use of the information handling system. A decision is made as to whether the apparent tamper indicator indicates that tampering (e.g., removal, damage, deactivation, etc.) of the network adapter has occurred (decision 604).If tampering is evident based on the indicator, then decision 604 branches to the "Yes" branch 606, after which, in step 608, the startup sequence requests one or more power-on passwords from the user according to the power-on password policy (e.g., need the monitor password (SVP), need both the SVP and the normal power-on password, etc.). In step 610, the passwords entered by the user are validated. A decision is made as to whether the password responses entered by the user are the correct passwords (decision 612). If one or more of the passwords are incorrect, then decision 612 branches to the "No" branch 614, and the flow loops back and requires the user to re-enter the password. According to one embodiment, a time delay is included so that a thief or malicious user cannot quickly attempt to guess the passwords (e.g.,when using a hacking routine, etc.). According to another embodiment, the time delay in each loop of branch 614 is increased to further counteract the efforts of a thief or unauthorized user. On the other hand, if the user (e.g., a system administrator with knowledge of the SVP, an authorized user, etc.) enters the correct password(s), decision 612 branches to "yes" branch 616, and the user is permitted to access the information handling system and the files stored on the hard disks.
[0032] Returning to decision 604, if the apparent tampering indicator does not indicate that tampering occurred during a previous use of the information handling system, then decision 604 branches to the “no” branch 620 to determine whether the network adapter was removed (e.g., physically removed, disabled, damaged, or otherwise unable to receive network communications) while the information handling system was powered off (before the Fig. 6). In step 622, the network adapter is checked to determine if the network adapter has been removed from the information handling system (e.g., physically removed, disabled, damaged, or otherwise unable to receive network communications). A decision is made as to whether the network adapter has been removed (decision 624). If the network adapter has not been removed (e.g., it can receive network messages, is not disabled, damaged, etc.), then decision 624 branches to the "no" branch 625, whereupon normal start-up of the information handling system begins in step 626. Normal start-up of the information handling system involves the user entering the normal power-on password (if one has been set for the system).In addition, it should be noted that during normal operation of the information processing system, the status of the network adapter is periodically checked, as described in . Fig. 5 so that if the network adapter is removed after the system has started, appropriate steps are taken to protect the information handling system and the data stored therein.
[0033] On the other hand, if it is determined that the network adapter has been removed (e.g., physically removed, disabled, damaged, or otherwise unable to receive network communications) before the information handling system has been powered on, then decision 624 branches to the "Yes" branch 628 for appropriate treatment. In step 630, the apparent tamper indicator (e.g., a tamper-indicating bit, etc.) in non-volatile memory 450 is set to indicate that tampering with the network adapter has occurred (e.g., by setting the indicator to "Yes," "True," "1," or the like value used to indicate tampering). In step 635, the hard disk password policy is read from non-volatile memory 450, indicating how the hard disk password should be set if tampering is detected (e.g.,the policy may be to set the hard disk password to a "monitor" password or to another password). In step 640, the power-on password policy is read from non-volatile memory 450. The power-on password policy indicates how the power-on password should be set if tampering is detected (e.g., changing the normal power-on password to the monitor password, which requires both the power-on password and the monitor password during the power-on sequence, etc.). In step 645, the hard disk password 555 protecting data stored on one or more hard disks 550 is changed according to the hard disk password policy read in step 635. In step 660, the power-on password 570 stored in non-volatile memory is changed according to the power-on password policy read in step 640.In step 665, the flow loops back to step 602. The apparent tampering indicator has now been set, and appropriate steps are taken to protect the information processing system and the data stored therein (decision 604 now branches to "yes" branch 606 and requests one or more power-on passwords according to the power-on password policy).
[0034] One of the preferred embodiments of the invention is a client application, namely a set of instructions (program code) or other functionally descriptive material in a code module located, for example, in the computer's main memory. Until required by the computer, the set of instructions may be stored in another computer memory, for example, on a hard disk or in removable storage, such as an optical disk (for eventual use in a CD-ROM) or a floppy disk (for eventual use in a floppy disk drive), or may be downloaded from the Internet or other computer network. Therefore, the present invention may be embodied as a computer program product for use in a computer.Additionally, although the various methods described are typically implemented in a selectively activated or software-reconfigured general-purpose computer, one skilled in the art would also recognize that such methods may be embodied in hardware, firmware, or more specialized devices configured to perform the necessary method steps. Functionally descriptive material is information that conveys functionality to a machine. Functionally descriptive material includes, but is not limited to, computer programs, instructions, rules, conditions, definitions of computable functions, objects, and data structures.
Claims
[1] A computer-implemented method (500) comprising: Determining (510, 520) whether a network adapter has been removed from a computer system; and in response to detecting that the network adapter has been removed from the computer system: Setting (530) an indicator of apparent tampering in a non-volatile memory of the computer system; Changing (545) a power-on password to a monitoring password according to a power-on password policy, wherein the power-on password is entered by a user of the computer system when the computer system is initialized; and Changing (560) a hard disk password according to a hard disk password policy, wherein the hard disk password protects files stored on the hard disk. [2] The method (500) of claim 1, wherein the network adapter is a wireless network adapter. [3] The method (500) of claim 1, further comprising: while the computer system is in operation, repeatedly checking (510, 515, 520) whether the network adapter has been removed; if during one of the repeated checks it is determined that the network adapter has been removed: Setting (530) the indicator for obvious tampering in the non-volatile memory; Reading (535) the hard disk password policy; setting (545) a new hard disk password based on the hard disk password rule, wherein setting the hard disk password sets the hard disk password to the set new hard disk password; Reading (540) a power-on password rule; based on the power-on password rule, setting (560) a new power-on password, wherein a power-on password that is used when the computer system is initialized, is set to the specified new power-on password; and shutting down (580) the computer system. [4] The method (500) of claim 3, further comprising: after the computer system has been shut down: Restarting (590) the computer system by a user; during an initialization process performed by the computer system, requesting that the user enter the new power-on password; receiving a password response from the user; comparing the password response received from the user with the new power-on password; Ending the initialization process and allowing the user to access files stored on the hard disk in response to the comparison showing a match between the password response and the new power-on password; and Deny the user access to the files stored on the hard disk in response to the comparison showing no match between the password response and the new power-on password. [5] The method (500) of claim 1, further comprising: Checking the indicator of apparent tampering in non-volatile memory during an initialization process that occurs when the computer system is initialized; in response to the obvious tampering indicator indicating tampering with the network adapter during a previous use of the computer system: Requesting one or more power-on passwords from the user in accordance with a power-on password policy; Receiving one or more password responses from the user; Comparing the password responses received from the user with one or more stored power-on passwords; Ending the initialization process and allowing the user to access files stored on the hard disk in response to the comparison showing a match between the password answers and the stored power-on passwords; and Deny the user access to files stored on the hard disk in response to the comparison showing no match between one of the password answers and one of the stored power-on passwords. [6] The method (500) of claim 5, further comprising: in response to the apparent tamper indicator indicating no tampering with the network adapter during a previous use of the computer system: Checking (510, 520) whether the network adapter is currently present in the computer system; in response to the fact that the check shows that the network adapter is not present in the computer system: Setting (530) the indicator for obvious tampering in the non-volatile memory; Reading (535) the hard disk password policy; based on the hard disk password policy, setting (545) a new hard disk password, wherein setting the hard disk password sets the hard disk password to the specified new hard disk password; Reading (540) a power-on password policy; based on the power-on password policy, setting (560) one or more power-on passwords, wherein the set power-on passwords are required by the user to allow the user access to files stored on the hard disk; and Prompt the user to enter the one or more configured power-on passwords. [7] An information processing system (100) comprising: one or more processors (110); a memory (120) accessible to at least one of the processors (110); a non-volatile storage device accessible to at least one of the processors (110); a network adapter (300) accessible to at least one of the processors (110) and connecting the information processing system (100) to a computer network (200); and a set of instructions loaded into the memory (120) and executed by the at least one of the processors (110) to perform the following actions: determining whether the network adapter (300) has been removed from the information processing system; and in response to determining that the network adapter (300) has been removed from the information processing system (100): Setting an indicator for obvious tampering in a non-volatile memory of the information processing system (100); Changing a power-on password to a monitoring password according to a power-on password rule, wherein the power-on password is input by a user of the information processing system (100) when the information processing system (100) is initialized; and Changing a hard disk password according to a hard disk password policy, the hard disk password protecting files stored on a hard disk (185). [8] The information processing system (100) of claim 7, wherein the network adapter (300) is a wireless network adapter. [9] The information handling system (100) of claim 7, wherein the instructions executed by at least one of the processors (110) perform additional actions, comprising: while the information handling system (100) is in operation, repeatedly checking whether the network adapter (300) has been removed; If during one of the repeated checks it is determined that the network adapter (300) has been removed: Setting the indicator for obvious tampering in non-volatile memory; Reading the hard disk password policy; based on the hard disk password requirement, setting a new hard disk password, wherein setting the hard disk password sets the hard disk password to the specified new hard disk password; Reading a power-on password policy; based on the power-on password rule, setting a new power-on password, wherein a power-on password used when the computer system is initialized is set to the specified new power-on password; and Shutdown of the information processing system (100). [10] The information processing system (100) of claim 9, wherein the instructions executed by at least one of the processors (110) perform additional actions, comprising: after the information processing system (100) has been shut down: Restarting the information processing system by a user; during an initialization process performed by the information processing system (100), requesting that the user enter the new power-on password; Receiving a password response from the user; comparing the password response received from the user with the new power-on password; Terminating the initialization process and allowing the user to access files stored on the hard disk in response to the comparison showing a match between the password response and the new power-on password; and denying the user access to the files stored on the hard disk (185) in response to that the comparison shows no match between the password response and the new power-on password. [11] The information processing system (100) of claim 7, wherein the instructions executed by at least one of the processors (110) perform additional actions, comprising: Checking the apparent tamper indicator in the non-volatile memory during an initialization process that occurs when the information processing system (100) is initialized; in response to the apparent tampering indicator indicating tampering with the network adapter (300) during a previous use of the information processing system (100): Requesting one or more power-on passwords from the user in accordance with a power-on password policy; Receiving one or more password responses from the user; Comparing the password responses received from the user with one or more stored power-on passwords; Terminating the initialization process and allowing the user to access files stored on the hard disk (185) in response to the comparison finding a match between the password answers and shows the stored power-on passwords; and Deny the user access to files stored on the hard disk in response to the comparison showing no match between one of the password answers and one of the stored power-on passwords. [12] The information processing system (100) of claim 11, wherein the instructions executed by at least one of the processors (110) perform additional actions, comprising: in response to the apparent tampering indicator indicating no tampering with the network adapter (300) during a previous use of the information processing system (100): Checking whether the network adapter (300) is currently present in the information processing system (100); in response to the check showing that the network adapter (300) is not present in the information processing system (100): Setting the indicator for obvious tampering in non-volatile memory; Reading the hard disk password policy; setting a new hard disk password based on the hard disk password policy, wherein setting the hard disk password sets the hard disk password to the specified new hard disk password; Reading a power-on password policy; setting one or more power-on passwords based on the power-on password policy, wherein the set power-on passwords are required by the user to allow the user access to files stored on the hard disk (185); and requiring the user to enter the one or more set power-on passwords. [13] A computer program product stored on a computer-readable storage medium which, when executed by an information processing system, causes the information processing system to perform actions comprising: Determining whether a network adapter has been removed from the information handling system; and in response to determining that the network adapter has been removed from the information handling system: Setting (530) an indicator of apparent tampering in a non-volatile memory of the information processing system; Changing (560) a power-on password according to a power-on password policy to a monitoring password, wherein the power-on password is entered by a user of the information processing system when the information processing system is initialized; and Changing (545) a hard disk password according to a hard disk password policy, wherein the hard disk password protects files stored on the hard disk. [14] The computer program product of claim 13, wherein the network adapter is a wireless network adapter. [15] The computer program product of claim 13, further causing the information processing system to perform actions comprising: while the information processing system is in operation, repeatedly checking (510, 515, 520) whether the network adapter has been removed; If during one of the repeated checks it is determined that the network adapter has been removed: Setting (530) the indicator for obvious tampering in the non-volatile memory; Reading (535) the hard disk password policy; based on the hard disk password specification, setting (545) a new hard disk password, wherein setting the hard disk password sets the hard disk password to the specified new hard disk password; Reading (540) a power-on password rule; based on the power-on password rule, setting (560) a new power-on password, wherein a power-on password used when the computer system is initialized is set to the set new power-on password; and shutting down (580) the information processing system. [16] The computer program product of claim 15, further causing the information handling system to perform further actions, comprising: after the information handling system has been shut down: Restarting (590) the information processing system by a user; during an initialization process performed by the information processing system, requiring the user to enter the new power-on password; Receiving a password response from the user; comparing the password responses received from the user with the new power-on password; terminating the initialization process and allowing the user to access files stored on the hard disk in response to the comparison showing a match between the password response and the new power-on password; and denying the user access to the files stored on the hard disk in response to the comparison not showing a match between the password response and the new power-on password. [17] The computer program product of claim 13, further causing the information handling system to perform actions comprising: checking the apparent tamper indicator in the non-volatile memory during an initialization process that occurs when the information handling system is initialized; in response to the apparent tampering indicator indicating tampering with the network adapter during a previous use of the information processing system: Requesting one or more power-on passwords from the user in accordance with a power-on password policy; Receiving one or more password responses from the user; Comparing the password responses received from the user with one or more stored power-on passwords; Completing the initialization process and allowing the user to access files stored on the hard disk in response to the comparison showing a match between the password answers and the stored power-on passwords; and Deny the user access to the files stored on the hard disk in response to the comparison showing no match between one of the password answers and one of the stored power-on passwords. [18] The computer program product of claim 17, further causing the information processing system to perform further actions comprising: in response to the apparent tampering indicator not indicating any tampering with the network adapter during a previous use of the information processing system: Checking (510, 520) whether the network adapter is currently present in the information processing system; in response to the check showing that the network adapter is not present in the information processing system: Setting (530) the indicator for obvious tampering in the non-volatile memory; Reading (535) the hard disk password policy; based on the hard disk password policy, setting (545) a new hard disk password, wherein setting the hard disk password sets the hard disk password to the specified new hard disk password; reading (540) a power-on password policy; based on the power-on password policy, setting (560) one or more power-on passwords, wherein the set power-on passwords are required by the user to allow the user access to files stored on the hard disk; and requiring the user to enter the one or more set power-on passwords.
Citation Information
Patent Citations
Information processing terminal, its control method, and its control program
JP2004362366A
Method to boot computer system only to a secure network
US20060179293A1
System and method for secure O.S. boot from password-protected HDD
US20070005951A1
Data processing system and method for securing a docking station and its portable PC
US6609207B1
JP002004362366A