Hardware Secured Flag Mechanism for Malware Subversion Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information handling systems face challenges in effectively protecting against malware, as existing solutions like System Health Agents and anti-malware scanners are limited in their ability to prevent user exposure and device subversion, often failing to provide immediate and robust protection against malicious software.
Innovation Solution
A hardware secured flag mechanism is activated by trusted Anti-Malware software, which reduces user exposure by performing actions such as displaying warnings, shutting down I/O devices, blocking network communications, and rebooting into a read-only recovery OS, and can only be reset by user intervention or a signed unlock key, ensuring continued protection even if the Anti-Malware software is subverted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If System Health Agents are used to assess system security and refuse connections, then system security is improved, but the protection is limited to software effects and can be subverted by malware
Solution Approach 1:
The patent introduces a hardware-based intermediary (secured flag mechanism in BIOS/firmware) that mediates between the software anti-malware solution and the system's security responses. This hardware layer acts as an unforgeable mediator that validates security states and prevents malware from subverting security decisions, directly resolving the contradiction between software-based security and malware subversion capability.
Solution Approach 2:
The patent replaces the purely software-based System Health Agent security mechanism with a hardware-based secured flag mechanism stored in BIOS or firmware. This substitution of software with hardware (mechanics substitution) creates a trusted execution environment that malware cannot subvert, while maintaining the security assessment and response functionality.
2Object-affected harmful factors
If hardware secured flag mechanism is activated to perform multiple protection actions, then user exposure to malware is reduced, but system complexity increases
Solution Approach 1:
The patent segments the malware protection functionality into distinct modular actions (displaying warnings, shutting down I/O devices, blocking network communications, rebooting to recovery OS). Each protection action is an independent module that can be individually activated by the hardware secured flag mechanism, reducing overall system complexity through functional segmentation while maintaining comprehensive protection capabilities.
Data Source
AI summary
A hardware secured flag mechanism which is activated by trusted Anti-Malware (AM) software. Upon being activated, the information handling system takes action to reduce user exposure even if the AM software is subsequently subverted. In certain embodiments, the flag mechanism is only reset by user intervention at a BIOS or other off-line mechanism. In certain embodiments, the flag mechanism may only be reset via a signed unlock key stored on an external memory device such as a universal serial bus (USB) key.


