Enforced Storage Backup via BIOS Heartbeat
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Ransomware attacks increasingly encrypt files on computers, posing a threat to personal and business data, with existing solutions failing to effectively prevent unauthorized changes and ensure data recovery.
Innovation Solution
A system utilizing a BIOS security module and versioning module to create and manage encrypted backups of files, applying access policies to prevent unauthorized modifications and ensure data integrity by generating a chain of backup versions, and using a heartbeat mechanism to detect and mitigate tampering attempts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ransomware encrypts files on monitored storage, then data becomes inaccessible to users, but backup copies may also be encrypted if the ransomware gains access to the backup process
Solution Approach 1:
The system divides storage into monitored storage and enforced storage with distinct access policies. The versioning module segments the backup process into controlled operations that prevent ransomware from encrypting both original and backup copies simultaneously. By separating storage functions and implementing independent access control, the system ensures that even if monitored storage is compromised, enforced storage remains protected and available for recovery.
2Reliability
If access policies restrict modifications to enforced storage, then data integrity is maintained, but legitimate backup operations may be blocked
Solution Approach 1:
The versioning module implements a feedback mechanism where the monitored storage continuously reports file changes to the enforced storage. This feedback loop allows the system to automatically initiate backup operations only when necessary, ensuring that legitimate backup processes can access enforced storage through controlled interfaces while maintaining strict access policies that block unauthorized modifications. The feedback system provides the necessary information flow without compromising security.
3Reliability
If the system creates and manages encrypted backups continuously, then data protection is enhanced, but system resources and storage space are consumed
Solution Approach 1:
The system implements periodic backup operations triggered by file change events rather than continuous copying. The versioning module monitors storage for modifications and creates encrypted backups only when changes occur, using a retention policy that maintains a specified number of backup versions. This periodic approach provides comprehensive data protection while consuming minimal storage space by eliminating the need for continuous redundant copying and allowing old backup versions to be discarded after the retention period expires.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Examples associated with storage monitoring are described. One example system includes generating an encryption key and transmitting the encryption key to a basic input/output system (BIOS) security module. The BIOS security module uses the encryption key as a basis for a heartbeat. A provisioning module receives a signal identifying a monitored storage and generates an enforced storage associated with the monitored storage. The provisioning module also creates a manifest describing the relationship between the enforced storage and the monitored storage. The provisioning module transmits the manifest to the BIOS security module. A versioning module assigns a first access policy for the monitored storage and a second access policy to the enforced storage based on the manifest. The versioning module performs versioning for the monitored storage using the enforced storage, and periodically verifies operation to the BIOS security module using the heartbeat.