External Boot Validation for Portable Storage Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing PC security mechanisms fail to verify the integrity of a host platform when booting from an external device, as they were designed assuming a Trusted Platform Module (TPM) for internal boot sequences, and are not effective against malicious software on foreign PCs.

Innovation Solution

A portable device with a digital storage medium includes a platform validation program that runs tests on the host platform to ensure its safety, presenting a user-identifiable message only after successful validation, allowing secure access to encrypted data and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If TCG compliant PCs use TPM to verify integrity of boot sequence, then security of internal boot is improved, but booting from external storage devices cannot be verified

Engineering Contradiction:
Improvesecurity verificationVSAvoidexternal device boot compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by measuring and recording the hash values of boot components (BIOS, bootloader, kernel) before the actual boot process occurs. These pre-computed measurements are stored in a secure location and used during runtime verification, allowing the system to validate external boot devices without requiring TPM hardware that wasn't designed for this purpose.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary validation mechanism that sits between the boot components and the operating system. This intermediary layer computes hash values of boot components and compares them against known good values, acting as a mediator that provides security verification without requiring the original TPM hardware architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If users store sensitive data in encrypted form on portable media, then data protection against loss is improved, but data remains vulnerable to malicious software on foreign PCs

Engineering Contradiction:
Improvedata protectionVSAvoidmalicious software vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by performing security validation of the host platform before allowing decryption credentials to be entered or processed. The system pre-checks the host environment for malicious software and validates the integrity of boot components before the user's encrypted data becomes accessible, preventing malicious software from compromising the data even if encryption credentials are exposed.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent provides beforehand cushioning by creating a secure validation layer that protects against potential threats before they can affect the encrypted data. By validating the host platform's security state in advance and only proceeding with data access when validation succeeds, the system cushions the encrypted data from exposure to malicious software on foreign PCs.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Ease of operation

If users provide decryption credentials on foreign PCs, then data access convenience is improved, but data security is compromised by potential malware

Engineering Contradiction:
Improvedata accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies preliminary action by validating the host platform's security integrity before prompting the user to enter decryption credentials. The system performs security checks, validates boot components, and assesses the threat level of the foreign PC before the data access process begins, ensuring that credentials are only requested when the environment is deemed safe.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary security validation layer between the user's decryption credentials and the foreign PC environment. This intermediary validates the host platform and controls whether credential input is permitted, acting as a mediator that protects credentials from malicious software while still allowing convenient data access on validated platforms.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7743422B2System and method for validating a computer platform when booting from an external device
Publication Date: 2010.06.22 X CORP
  • US7743422B2 patent drawing
  • US7743422B2 patent drawing
  • US7743422B2 patent drawing

AI summary

A portable device for connecting to a host information processing platform includes: a digital information storage medium storing an operating system image, secure data, applications, and system state of an owner of the portable device, wherein the medium is in read only mode until a set of tests are run on the host platform; and a platform validation program for: running the plurality of tests on the host computer to determine whether the host is safe, depending on the outcome of the tests, presenting the owner with a user-identifiable message, prompting the owner to enter decryption credentials, and receiving the decryption credentials. The portable device could also optionally include subsystems that provide additional functionality to the owner such as media playback, communications, and entertainment.