Network Boot System for Consumer Devices with Secure OS Download

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Next-generation consumer computing devices require reduced Flash memory costs and high security to prevent unauthorized hacking of A/V content, as current network boot systems are inadequate for securing digital rights management.

Innovation Solution

A system and method where consumer computing devices download the operating system from a network server, utilizing encryption and Digital Rights Management (DRM) technology, and implement security-in-the-chip techniques to validate boot programs and ensure the integrity of the operating system image, reducing the need for local Flash memory and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the operating system is stored in local Flash memory, then security against unauthorized hacking is improved, but device cost increases due to expensive Flash memory

Engineering Contradiction:
ImprovesecurityVSAvoiddevice cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts the operating system from local Flash memory storage and relocates it to network-based storage. The device boots by downloading the OS from the network server, eliminating the need for expensive local Flash memory while maintaining security through network-based authentication and encryption mechanisms.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a universal boot architecture that can operate in multiple modes: network boot mode for secure centralized OS delivery, and local boot mode as fallback. This multi-functionality allows the system to achieve both cost reduction and security requirements through flexible boot source selection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Ease of manufacture

If network boot systems are used to reduce Flash memory requirements, then device cost is reduced, but security against unauthorized hacking deteriorates

Engineering Contradiction:
Improvedevice costVSAvoidsecurity
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The patent implements preliminary authentication and verification actions during the network boot process. Before the operating system is downloaded and executed, the system performs security checks including digital signature verification, authentication with the network server, and validation of the boot image integrity, ensuring security is established before any code execution.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure network server as an intermediary between the device and the operating system. This server acts as a trusted mediator that authenticates devices, verifies OS images, and controls the boot process, thereby maintaining security even though the OS is delivered over the network rather than stored locally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If abbreviated operating systems are used to reduce memory requirements, then device functionality is reduced, but device cost is reduced

Engineering Contradiction:
Improvedevice costVSAvoiddevice functionality
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent implements a dynamic operating system architecture where the OS can be updated, replaced, or upgraded through network downloads. This dynamic capability allows the system to adapt to different functionality requirements over time, transforming a potentially static limited OS into a flexible, updatable system that can provide full functionality when needed.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7558958B2System and method for securely booting from a network
Publication Date: 2009.07.07 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7558958B2 patent drawing
  • US7558958B2 patent drawing
  • US7558958B2 patent drawing

AI summary

A consumer device is presented that utilizes a system and method for downloading from a network server the run time image of the device's operating system and/or application program. As such, the amount of Flash memory required to store the operating system may be greatly reduced, which also reduces the cost associated with such Flash memory. Since the run time image is downloaded from a network server, the image can be updated at the server for bug fixes and feature enhancements. For devices operating in audio/video distribution, additional security is provided to maintain the digital rights management of the A/V content. This security is provided through a combination of hardware and software security features including ROM in the CPU or board mounted Flash memory with an unwritable section. Further, each boot load program checks the digital signature of the program it is loading before that program is allowed to execute.