External Boot Validation for Portable Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing PC security mechanisms fail to verify the integrity of a host platform when booting from an external device, as they were designed assuming a Trusted Platform Module (TPM) for internal boot sequences, and are not effective against malicious software on foreign PCs.
Innovation Solution
A portable device with a digital storage medium includes a platform validation program that runs tests on the host platform to ensure its safety, presenting a user-identifiable message only after successful validation, allowing secure access to encrypted data and applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TCG compliant PCs use TPM to verify integrity of boot sequence, then security of internal boot is improved, but booting from external storage devices cannot be verified
Solution Approach 1:
The patent applies preliminary action by measuring and recording the hash values of boot components (BIOS, bootloader, kernel) before the actual boot process occurs. These pre-computed measurements are stored in a secure location and used during runtime verification, allowing the system to validate external boot devices without requiring TPM hardware that wasn't designed for this purpose.
Solution Approach 2:
The patent introduces an intermediary validation mechanism that sits between the boot components and the operating system. This intermediary layer computes hash values of boot components and compares them against known good values, acting as a mediator that provides security verification without requiring the original TPM hardware architecture.
2Reliability
If users store sensitive data in encrypted form on portable media, then data protection against loss is improved, but data remains vulnerable to malicious software on foreign PCs
Solution Approach 1:
The patent applies preliminary anti-action by performing security validation of the host platform before allowing decryption credentials to be entered or processed. The system pre-checks the host environment for malicious software and validates the integrity of boot components before the user's encrypted data becomes accessible, preventing malicious software from compromising the data even if encryption credentials are exposed.
Solution Approach 2:
The patent provides beforehand cushioning by creating a secure validation layer that protects against potential threats before they can affect the encrypted data. By validating the host platform's security state in advance and only proceeding with data access when validation succeeds, the system cushions the encrypted data from exposure to malicious software on foreign PCs.
3Ease of operation
If users provide decryption credentials on foreign PCs, then data access convenience is improved, but data security is compromised by potential malware
Solution Approach 1:
The patent applies preliminary action by validating the host platform's security integrity before prompting the user to enter decryption credentials. The system performs security checks, validates boot components, and assesses the threat level of the foreign PC before the data access process begins, ensuring that credentials are only requested when the environment is deemed safe.
Solution Approach 2:
The patent introduces an intermediary security validation layer between the user's decryption credentials and the foreign PC environment. This intermediary validates the host platform and controls whether credential input is permitted, acting as a mediator that protects credentials from malicious software while still allowing convenient data access on validated platforms.
Data Source
AI summary
A portable device for connecting to a host information processing platform includes: a digital information storage medium storing an operating system image, secure data, applications, and system state of an owner of the portable device, wherein the medium is in read only mode until a set of tests are run on the host platform; and a platform validation program for: running the plurality of tests on the host computer to determine whether the host is safe, depending on the outcome of the tests, presenting the owner with a user-identifiable message, prompting the owner to enter decryption credentials, and receiving the decryption credentials. The portable device could also optionally include subsystems that provide additional functionality to the owner such as media playback, communications, and entertainment.


