Boot-loader Firmware Security Agent Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for organizational networks are vulnerable to tampering by malicious employees who can bypass or remove security agents, allowing unauthorized data transfer, especially when employees have administrator rights and access to external storage devices.
Innovation Solution
Associating the content of storage devices with a security agent and a boot-loader program, using encryption keys stored in firmware, and implementing a mini operating system that monitors and controls data transfers, ensuring the integrity of the security agent and operating system by intercepting and encrypting data and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security agents are installed locally on user's machines to enforce organizational security rules, then security control capability is improved, but vulnerability to tampering by malicious employees increases
Solution Approach 1:
The patent implements a nested security architecture where a boot-loader program embeds encryption keys that protect the security agent, which in turn protects organizational data. The boot-loader resides in firmware and loads the security agent into memory, creating nested layers of protection where each layer safeguards the next, making tampering increasingly difficult at each level.
Solution Approach 2:
The patent performs preliminary actions by storing encryption keys in the boot-loader firmware before the operating system or security agent can be loaded or modified. This pre-establishment of cryptographic protection occurs during system initialization, preventing malicious employees from accessing or tampering with security credentials before they are needed.
2Ease of operation
If administrator rights are granted to employees for operational flexibility, then ease of operation is improved, but ability to bypass security measures increases
Solution Approach 1:
The patent introduces an intermediary cryptographic layer between the employee and the security agent. Even employees with administrator rights must pass through the boot-loader's encryption verification and the security agent's policy enforcement, which act as intermediaries that cannot be bypassed through normal administrative privileges.
Solution Approach 2:
The patent changes the parameter of security verification from administrative permissions to cryptographic authentication. Instead of relying on OS-level administrator rights that can be modified, the system uses cryptographic keys embedded in firmware that cannot be changed through normal administrative operations, fundamentally altering how access is validated.
3Reliability
If security policies are enforced strictly to prevent data leakage, then security reliability is improved, but productivity decreases
Solution Approach 1:
The patent applies partial action by allowing employees to use external storage devices under specific controlled conditions defined by security policies. Rather than completely blocking all external device access, the system permits authorized operations (such as reading authorized files or writing to approved devices) while maintaining security controls, thus preserving productivity for legitimate tasks while preventing data leakage.
4Reliability
If encryption keys are stored in firmware to protect data, then security protection is improved, but device complexity increases
Solution Approach 1:
The patent makes the boot-loader firmware serve multiple functions: it performs the standard system initialization role of loading the operating system, while simultaneously storing encryption keys, implementing cryptographic verification, and protecting the security agent. This multi-functionality reduces the need for separate dedicated security hardware or software components, thereby limiting the increase in overall system complexity.
Data Source
AI summary
Protecting the integrity and the effectiveness of a security agent that is installed in a user's device while the user's device operates online or offline. The security agent may be used for enforcing a security policy required by an organization or network to which the user's computer belongs. One aspect of exemplary embodiments of the present invention is to associate the content of one or more storage devices of the user's computer with the security agent and with a boot-loader program used by the user's computer.


