Full Disk Encryption Update via Pre-Boot Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing full disk encryption (FDE) software updates on boot drives often require complete decryption and re-encryption of data, leading to compatibility issues and prolonged downtime, as well as potential confidentiality risks.
Innovation Solution
A method and system for updating FDE software on a computer that involves blocking operations, installing updated components, deploying a pre-boot compatibility verification component to check hardware compatibility without decrypting the boot disk, and authenticating the user before booting the operating system, thereby avoiding decryption and re-encryption.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complete decryption and re-encryption is performed during FDE software updates, then compatibility of the updated software is ensured, but data confidentiality is compromised and update time is prolonged
Solution Approach 1:
The patent performs compatibility verification in advance by creating a test virtual disk and attempting to mount it with the updated FDE software before actually updating the production disk. This preliminary test allows the system to determine compatibility without decrypting actual user data, thus maintaining confidentiality while ensuring future compatibility.
Solution Approach 2:
The patent introduces a test virtual disk as an intermediary object to verify compatibility. Instead of testing directly on the encrypted production disk (which would require decryption), the system creates a separate test disk, attempts to mount it with updated software, and uses the result to determine whether to proceed with the update. This intermediary approach eliminates the need to decrypt sensitive data.
2Reliability
If complete decryption and re-encryption is performed during FDE software updates, then compatibility of the updated software is ensured, but update duration is increased
Solution Approach 1:
The patent performs compatibility verification in advance by creating a test virtual disk and attempting to mount it with the updated FDE software before actually updating the production disk. This preliminary test allows the system to determine compatibility without decrypting actual user data, thus maintaining confidentiality while ensuring future compatibility.
Solution Approach 2:
The patent introduces a test virtual disk as an intermediary object to verify compatibility. Instead of testing directly on the encrypted production disk (which would require decryption), the system creates a separate test disk, attempts to mount it with updated software, and uses the result to determine whether to proceed with the update. This intermediary approach eliminates the need to decrypt sensitive data.
3Productivity
If pre-boot authentication module is updated without verification, then software is kept up-to-date, but hardware compatibility issues may prevent system booting
Solution Approach 1:
The patent performs compatibility verification in advance by creating a test virtual disk and attempting to mount it with the updated FDE software before actually updating the production disk. This preliminary test allows the system to determine compatibility without decrypting actual user data, thus maintaining confidentiality while ensuring future compatibility.
Solution Approach 2:
The patent implements a feedback mechanism where the result of the compatibility test (successful mount or failure) determines whether to proceed with the update. If the test disk mounts successfully, the update is applied; if it fails, the update is aborted and the original software version is restored. This feedback loop ensures that updates are only applied when they will not compromise system bootability.
Data Source
AI summary
Disclosed are systems and method or updating full disk encryption (FDE) software on a computer. An example method comprises: blocking operations of the FDE software on a boot drive of the computer; installing one or more components of the updated FDE software; deploying an updated pre-boot compatibility verification component of updated FDE software; rebooting the computer and executing, before booting of an operating system, the updated pre-boot compatibility verification component; determining, by the updated pre-boot compatibility verification component, a compatibility of the boot disk with the updated FDE software without decrypting and encrypting the boot disk of the computer by the updated FDE software; if the boot disk is determined to be compatible with the updated FDE software, authenticating a computer user and booting the operating system of the computer; and unblocking one or more operations of the updated FDE software on the boot drive.


