BIOS-Controlled Optical Drive Read-Only Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods fail to securely set a storage unit to a read-only mode, especially in systems with rewritable optical disc drives, leading to potential data leaks and security risks, as they can be bypassed by application software or alternative OS installations.

Innovation Solution

A method where a BIOS confirms the presence of a security function in a storage unit during the boot process, sets the storage unit to a read-only mode, and maintains this setting even when control is transferred to the operating system, preventing direct access changes by application software or alternative OS installations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a rewritable optical disc drive is used to reduce component types and cost, then device complexity and manufacturing cost are reduced, but security reliability deteriorates because the drive can be accessed and modified by application software or alternative OS installations

Engineering Contradiction:
Improvenumber of optical disc drive typesVSAvoidsecurity setting stability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The BIOS performs preliminary security configuration by setting the optical disc drive to read-only mode during the boot process, before the operating system or application software can access and potentially modify the drive settings. This advance action ensures security is established prior to any software interference.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent separates security configuration into distinct layers: BIOS-level security settings that are independent from the operating system layer. This segmentation allows the BIOS to maintain secure read-only settings while the OS layer operates normally, preventing software from compromising security settings.

Inventive Principle:
Principle #1Segmentation

2Reliability

If BIOS-controlled security settings are implemented to prevent unauthorized writing, then security reliability is improved, but ease of operation deteriorates because supervisor access is required to modify settings

Engineering Contradiction:
Improvesecurity setting stabilityVSAvoidsetting modification accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies different access levels to different operational needs: supervisor password protection for security setting modifications, while normal users retain full access to read and use the optical disc drive. This localized quality control ensures security settings remain stable while normal operations remain convenient.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If the optical disc drive is set to read-only mode to prevent data leaks, then security is improved, but adaptability deteriorates because the drive cannot be used for writable operations

Engineering Contradiction:
Improvedata leak preventionVSAvoiddrive functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent makes the drive mode dynamic rather than static: the optical disc drive operates in read-only mode during normal operations to prevent data leaks, but can be temporarily switched to writable mode when a supervisor enters the correct password. This dynamic adjustment maintains security while preserving necessary functionality.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8566951B2Apparatus and methods for setting security to storage unit and computer
Publication Date: 2013.10.22 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US8566951B2 patent drawing
  • US8566951B2 patent drawing
  • US8566951B2 patent drawing

AI summary

Methods and apparatus are provided for inhibiting data writing to an optical disc drive connected to a computer. A BIOS confirms presence of a security function of an optical disc drive. When the optical disc drive possesses the security function, the BIOS delivers a command to the optical disc drive to set it to a read-only mode. The optical disc drive that has received the command sets the drive per se to operate in the read-only mode. Since a command for setting it to the read-only mode and a command for releasing it are delivered to the optical disc drive only by the BIOS, when a control is transferred to an Operating System (OS), setting of the read-only mode cannot be released by the OS and other OS's, or application software.