Encrypted OS Installation Media Boot Process

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for encrypting operating system installation media are cumbersome for customers, as they require technical expertise and specific equipment to decrypt and write the installation image to optical media.

Innovation Solution

A method and system that allows booting an information handling system from a boot image on a non-transitory storage medium, prompting for a password to decrypt an encrypted volume, loading a kernel, and using a specialized module to execute the operating system installation image, simplifying the installation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a vendor encrypts an installation image before delivering it to a customer, then security is improved, but the installation process becomes more complex and requires special equipment

Engineering Contradiction:
ImprovesecurityVSAvoidinstallation process
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a vendor-provided executable program as an intermediary that automatically performs the decryption and burning processes. This intermediary software bridges the gap between the encrypted installation image and the optical media, eliminating the need for customers to manually decrypt and burn the image while maintaining security through password protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary action by having the vendor pre-configure the encrypted installation image with embedded password protection and by providing the customer with a pre-configured executable program that knows how to decrypt and burn the image. This preliminary setup eliminates the need for customers to perform complex technical operations during installation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If a vendor encrypts an installation image before delivering it to a customer, then security is improved, but customer convenience deteriorates due to lack of technical expertise requirements

Engineering Contradiction:
ImprovesecurityVSAvoidcustomer convenience
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The vendor-provided executable program serves as an intermediary that handles all technical complexity of decryption and burning. Customers simply need to run this provided program, which automatically manages the encrypted image, eliminating the need for customers to have technical expertise while maintaining security through the embedded password system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements self-service by having the executable program automatically perform all necessary operations (decryption, verification, burning) without requiring customer intervention beyond providing the password. The program self-manages the entire installation media creation process, making it convenient for customers regardless of their technical expertise.

Inventive Principle:
Principle #25Self-service

3Reliability

If existing decryption methods are used, then security is maintained, but device complexity increases due to need for specialized equipment

Engineering Contradiction:
ImprovesecurityVSAvoidequipment requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces the mechanical/physical system of specialized decryption equipment with a software-based solution. The executable program running on the customer's existing computer performs all decryption operations, eliminating the need for specialized hardware devices while maintaining security through software-based password protection and encryption verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250013751A1Fully encrypted operating system installation media
Publication Date: 2025.01.09 EVERFOX HOLDINGS LLC
  • US20250013751A1 patent drawing
  • US20250013751A1 patent drawing
  • US20250013751A1 patent drawing

AI summary

A computer-implementable method may include booting an information handling system from a boot image stored on a non-transitory computer-readable storage medium, prompting, by the boot image, for a password for an encrypted volume of the non-transitory computer-readable storage medium, loading, by the boot image, a kernel stored within the encrypted volume, passing, by the boot image, the password to a specialized module stored within the encrypted volume, decrypting, by the specialized module, the encrypted volume using the password, and causing, by the specialized module, execution of an operating system installation image stored within the encrypted volume to install the operating system on the information handling system.