Bootable USB Secure Environment for Untrusted Hosts

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to provide a secure computing environment for remote users and disaster recovery scenarios, as they often rely on unmanaged computers and compromise security when accessing corporate resources from untrusted machines, with limitations in controlling and isolating the computing environment.

Innovation Solution

A secure computing environment is provided through an encrypted carrier media, such as a bootable USB key, that takes control of the host system, performs pre-boot authentication, and ensures complete isolation from the host's operating system, with data storage and secure erasure capabilities, allowing secure access to corporate resources without relying on trust in external software or user trust.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtualised systems are used to manage remote computing environments, then businesses can control and secure the environment, but the system becomes invasive requiring software installation on user machines and cannot prevent tampering or replication

Engineering Contradiction:
Improvesecurity controlVSAvoidsoftware installation requirement
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the secure computing environment from the host machine by using a virtual machine that can be removed and transferred to different devices. The virtual machine contains all necessary software and configuration, eliminating the need for permanent installation or modification of the host system. This allows the business to maintain security control while avoiding invasive software installation on user machines.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a virtual machine as an intermediary between the user and the corporate network. This virtual machine acts as a controlled environment that mediates all interactions, providing security without requiring direct software installation on the host. The virtual machine can be freely moved between devices while maintaining the same security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are enforced during normal operations, then corporate resources are protected, but during disaster recovery security emphasis is sidelined to keep business running

Engineering Contradiction:
Improvesecurity protectionVSAvoiddisaster recovery flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent makes the security environment dynamic by allowing the virtual machine to be moved between trusted and untrusted environments based on operational needs. During normal operations, the virtual machine runs in a controlled environment with full security measures. During disaster recovery, the same virtual machine can be moved to untrusted devices while maintaining its security boundaries, providing both security protection and disaster recovery flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The virtual machine is designed to be universal and can function in multiple environments - both trusted corporate devices and untrusted external devices. This multi-functionality allows the same security environment to serve both normal operations and disaster recovery scenarios, eliminating the need to compromise security during emergency situations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If untrusted machines are used for remote access or disaster recovery, then access to corporate resources is enabled, but security is compromised and footprints remain after use

Engineering Contradiction:
Improveremote access capabilityVSAvoidsecurity compromise and footprint
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the entire computing environment into a portable virtual machine that can be moved to untrusted devices. This extraction allows users to access corporate resources from any device without leaving footprints on the host machine. The virtual machine contains all necessary software and data, and when removed, no trace remains on the untrusted device.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent treats the virtual machine instance on untrusted devices as temporary and disposable. Each time the virtual machine is moved to a new device, it creates a fresh instance that leaves no permanent footprint. This approach enables easy remote access from untrusted machines while eliminating security concerns about persistent footprints or backdoors.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

4Adaptability or versatility

If home computers are used for remote work, then users can work flexibly, but businesses cannot effectively manage or secure these devices

Engineering Contradiction:
Improveremote work flexibilityVSAvoidmanagement control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a virtual machine as an intermediary that allows businesses to maintain management control while enabling remote work flexibility. The virtual machine runs on the user's home computer but contains all corporate policies, security settings, and software configurations. This intermediary approach provides the flexibility of using personal devices while maintaining full management control over the computing environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the computing environment into a separate virtual machine that can be independently managed. This segmentation allows the business to control and secure the virtual machine environment while leaving the host operating system and hardware unmanaged. The virtual machine contains all necessary corporate resources and security measures, providing both flexibility and control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP2135186B1System and method for providing a secure computing environment
Publication Date: 2017.10.04 BECRYPT
  • EP2135186B1 patent drawingFigure 1
  • EP2135186B1 patent drawingFigure 2
  • EP2135186B1 patent drawingFigure 3

AI summary

A system and method for providing a secure computing environment to untrusted computer systems is described. A carrier media and an interface are provided, the interface being connectable to a computer to enable communication between the computer and the carrier media. The carrier media encodes a secure computing environment and a boot system, upon connection of the system via the interface to a computer system and booting of the computer system, the boot system is operative to take over the boot process of the computer system and to authenticate the user, wherein upon successful authentication, the boot system is arranged to load the secure computing environment on the computer system, the secure computing environment being configured to prevent predetermined interaction from outside the secure computing environment when it is running.