Backup Permission via Telemetry Security Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Data stored in computing devices can become unusable due to malware attacks, such as ransomware, which encrypts files, and backup copies may also be compromised during backup operations, rendering them unusable.

Innovation Solution

A system that analyzes telemetry data from the computing device to determine if security is compromised before allowing backup-related operations, using a secure handshake-based verification to prevent malware attacks from affecting backup copies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup operations are performed on computing devices, then data can be restored in case of loss, but malware attacks during backup operations can compromise the backup copies and render them unusable

Engineering Contradiction:
Improvebackup copy usabilityVSAvoidmalware attack risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security verification through telemetry analysis and secure handshake protocols before allowing backup operations to proceed. This advance checking prevents compromised devices from creating infected backup copies, thereby maintaining backup reliability without requiring additional security measures during the actual backup process

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A secure handshake mechanism acts as an intermediary between the computing device and backup system. This intermediary layer verifies device security status through encrypted communication and telemetry validation, preventing malware from directly compromising backup operations while allowing legitimate backup processes to proceed

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security verification is performed before backup operations, then backup integrity is maintained, but system complexity increases due to additional verification steps

Engineering Contradiction:
Improvebackup integrityVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing device itself performs self-verification by providing telemetry data that indicates its security status. This self-service approach eliminates the need for complex external verification systems, as the device autonomously attests to its security state through embedded sensors and security modules, simplifying the overall system architecture while maintaining backup integrity

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system uses telemetry feedback from the computing device to dynamically determine backup permission. Security metrics such as threat detection status, antivirus scan results, and system integrity indicators are continuously monitored and fed back to the backup management system, enabling automated security verification without manual intervention or complex verification protocols

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240396889A1Permissions for backup-related operations
Publication Date: 2024.11.28 HEWLETT PACKARD ENTERPRISE DEV LP
  • US20240396889A1 patent drawing
  • US20240396889A1 patent drawing
  • US20240396889A1 patent drawing

AI summary

Example techniques for granting permissions for performing an operation related to a backup copy are described. The backup copy corresponds to first device data and the first device data is stored in a first device. In an example, in response to receiving a request to perform the operation related to the backup copy, telemetry data received from the first device is analyzed. Based on the analysis, it is determined that security of the first device is uncompromised. Based on the determination, a permission to perform the operation related to the backup copy is granted.