Malware Scan via Server OS During Power Change

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware can hide in the kernel of an operating system, making it difficult to detect, as current solutions are inadequate for effectively scanning and removing such hidden threats.

Innovation Solution

A device uses a separate operating system from a server to execute a malware scan during power change conditions like sleep mode or restart, allowing for a trusted OS to be loaded into memory or executed remotely to scan the native OS and other software applications for malware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a native operating system performs malware scans, then the scan can be executed locally, but the malware can redirect the scan away from itself by hiding in the kernel

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidmalware hiding capability
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a separate trusted operating system from a server as an intermediary to perform malware scans. This external OS acts as a mediator that can scan the native OS without being compromised by malware embedded in the native OS kernel, thereby resolving the contradiction between local scan execution and malware redirection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of using the native OS to scan itself (self-scanning), the patent inverts the approach by using a separate trusted OS to scan the native OS. This inversion eliminates the ability of malware to redirect scans since the scanning process occurs in a different, trusted environment

Inventive Principle:
Principle #13The other way round (Inversion)

2Reliability

If a separate operating system from a server is used to perform malware scans, then malware hiding in the native OS kernel can be detected, but the system complexity increases

Engineering Contradiction:
Improvemalware detection reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent makes the server a universal resource that can provide trusted operating systems to multiple client devices for malware scanning. This multi-functionality reduces the need for each device to maintain its own separate scanning infrastructure, thereby managing system complexity while maintaining high detection reliability

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The server acts as an intermediary that hosts trusted operating systems, reducing the complexity burden on individual client devices. Instead of each device needing to maintain a separate trusted scanning environment, the server provides this capability externally, simplifying the overall system architecture

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11657156B2Malware scan in response to power change
Publication Date: 2023.05.23 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US11657156B2 patent drawing
  • US11657156B2 patent drawing
  • US11657156B2 patent drawing

AI summary

In one aspect, a device includes at least one processor and storage accessible to the at least one processor. The storage includes instructions executable by the at least one processor to identify a power change condition in the device, and responsive to the power change condition, execute a scan for malware on the device using an operating system (O.S.) loaded into memory of the device from a server separate from the device.