Boot-loader Firmware Security Agent Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security measures for organizational networks are vulnerable to tampering by malicious employees who can bypass or remove security agents, allowing unauthorized data transfer, especially when employees have administrator rights and access to external storage devices.

Innovation Solution

Associating the content of storage devices with a security agent and a boot-loader program, using encryption keys stored in firmware, and implementing a mini operating system that monitors and controls data transfers, ensuring the integrity of the security agent and operating system by intercepting and encrypting data and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security agents are installed locally on user's machines to enforce organizational security rules, then security control capability is improved, but vulnerability to tampering by malicious employees increases

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidvulnerability to tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a nested security architecture where a boot-loader program embeds encryption keys that protect the security agent, which in turn protects organizational data. The boot-loader resides in firmware and loads the security agent into memory, creating nested layers of protection where each layer safeguards the next, making tampering increasingly difficult at each level.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent performs preliminary actions by storing encryption keys in the boot-loader firmware before the operating system or security agent can be loaded or modified. This pre-establishment of cryptographic protection occurs during system initialization, preventing malicious employees from accessing or tampering with security credentials before they are needed.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If administrator rights are granted to employees for operational flexibility, then ease of operation is improved, but ability to bypass security measures increases

Engineering Contradiction:
Improveoperational flexibilityVSAvoidability to bypass security
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary cryptographic layer between the employee and the security agent. Even employees with administrator rights must pass through the boot-loader's encryption verification and the security agent's policy enforcement, which act as intermediaries that cannot be bypassed through normal administrative privileges.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the parameter of security verification from administrative permissions to cryptographic authentication. Instead of relying on OS-level administrator rights that can be modified, the system uses cryptographic keys embedded in firmware that cannot be changed through normal administrative operations, fundamentally altering how access is validated.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security policies are enforced strictly to prevent data leakage, then security reliability is improved, but productivity decreases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidemployee productivity
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies partial action by allowing employees to use external storage devices under specific controlled conditions defined by security policies. Rather than completely blocking all external device access, the system permits authorized operations (such as reading authorized files or writing to approved devices) while maintaining security controls, thus preserving productivity for legitimate tasks while preventing data leakage.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If encryption keys are stored in firmware to protect data, then security protection is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the boot-loader firmware serve multiple functions: it performs the standard system initialization role of loading the operating system, while simultaneously storing encryption keys, implementing cryptographic verification, and protecting the security agent. This multi-functionality reduces the need for separate dedicated security hardware or software components, thereby limiting the increase in overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9424430B2Method and system for defending security application in a user's computer
Publication Date: 2016.08.23 SUPERCOM IP LLC
  • US9424430B2 patent drawing
  • US9424430B2 patent drawing
  • US9424430B2 patent drawing

AI summary

Protecting the integrity and the effectiveness of a security agent that is installed in a user's device while the user's device operates online or offline. The security agent may be used for enforcing a security policy required by an organization or network to which the user's computer belongs. One aspect of exemplary embodiments of the present invention is to associate the content of one or more storage devices of the user's computer with the security agent and with a boot-loader program used by the user's computer.