Hard Drive Anti-Theft Locking Through Boot Firmware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Transaction terminal hard drives are vulnerable to theft due to the value of the data and the drive itself, with existing security measures like password protection requiring manual entry and being cumbersome, especially in remote locations, and full disk encryption being costly and time-consuming.
Innovation Solution
Implementing boot firmware that sets and obfuscates a password for hard drives, either standalone or online, ensuring the password is never stored on the drive, allowing auto-fill during boots, thus securing the drive without manual entry and reducing reliance on network access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual password entry is required on boot to unlock the hard drive, then the hard drive is secured against theft, but the operation becomes cumbersome and time-consuming
Solution Approach 1:
The system performs preliminary actions by automatically retrieving and applying the password during the boot process before the user needs to access the hard drive. The password is fetched from a remote server or stored securely in the terminal's memory during boot, eliminating the need for manual password entry by the user while maintaining security.
2Reliability
If full disk encryption is implemented to protect hard drive data, then security is improved, but the system becomes more costly and time-consuming to implement
Solution Approach 1:
The invention extracts the password protection function from the hard drive itself and places it in the terminal's boot firmware and memory. The password is stored in the terminal, not on the hard drive, separating the security mechanism from the storage device. This allows the hard drive to remain simpler while still providing strong protection, as the password is required to unlock it.
3Ease of operation
If the password is stored on the hard drive for easy access, then the unlock process is simplified, but the security is compromised as the drive itself provides the password information
Solution Approach 1:
The terminal's boot firmware and memory act as an intermediary between the user and the hard drive password. Instead of storing the password on the hard drive, the system uses the terminal's memory and boot process as an intermediate layer to securely store and provide the password. This intermediary prevents the hard drive from providing its own password, maintaining security while enabling easy access through automated retrieval during boot.
Data Source
AI summary
Boot firmware of a terminal sets a lock password on a hard disk drive of the terminal to lock the hard disk drive from access. The password is obfuscated in boot variables or stored separately on a server independently of the terminal. During subsequent boots of the terminal, the firmware de-obfuscates the password from the boot variables or obtains the password from the server and provides the password to the hard disk drive, which causes the hard disk drive to unlock for operation with the terminal following the subsequent boots.


