Offline System Time Protection Using BIOS and Logging Drivers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data processing systems are vulnerable to system time tampering in an off-line status, allowing users or malware to adjust the system time, which can lead to unauthorized extension of security application licenses and compromise information security.

Innovation Solution

Implement a data processing system with a hardware timer, BIOS device, and processor that includes a system timer driver, time logging driver, time data storage module, and application layer start/end time recording process to monitor and adjust system time within predefined thresholds, preventing unauthorized changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the data processing system is in an off-line status, then the system can operate independently without network connection, but the system time becomes vulnerable to tampering by users or malware

Engineering Contradiction:
Improveoff-line operation capabilityVSAvoidsystem time accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies preliminary action by recording the system time at the moment of power-on (Driver Start Time) and power-off (Driver End Time) before any potential tampering occurs. The time logging driver captures these timestamps and stores them in non-volatile memory, establishing a baseline that prevents unauthorized time adjustments even when the system is off-line.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements feedback by continuously monitoring the system time against the recorded Driver Start Time and Driver End Time. The time logging driver compares current system time readings with the stored timestamps and provides feedback when anomalies are detected, triggering protection functions to prevent or alert about unauthorized time modifications.

Inventive Principle:
Principle #23Feedback

2Ease of operation

If the system time can be adjusted freely, then users can change date and time for convenience, but security applications can be compromised by unauthorized time adjustments

Engineering Contradiction:
Improvedate and time adjustmentVSAvoidsecurity application vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by pre-establishing time boundaries (Driver Start Time and Driver End Time) that prevent unauthorized time adjustments. The time logging driver actively blocks attempts to modify system time outside these recorded boundaries, countering potential malicious actions before they can compromise security applications.

Inventive Principle:
Principle #9Preliminary anti-action

Solution Approach 2:

The patent introduces an intermediary mechanism - the time logging driver - that sits between the system time setting functionality and the security applications. This intermediary monitors and validates time adjustments, allowing legitimate operations while blocking harmful attempts to modify time parameters that could compromise security licenses.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If the security application is linked to a license server via Internet, then accurate license expiration determination is achieved, but the system requires continuous network connection

Engineering Contradiction:
Improvelicense expiration detection accuracyVSAvoidnetwork connection requirement
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by having the time logging driver record the system time at power-on and power-off events before any license verification occurs. This pre-recorded time data serves as a trusted baseline that enables accurate license expiration determination without requiring continuous network connectivity to external license servers.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements copying by creating a local copy of the time verification mechanism. Instead of relying solely on remote license server verification, the system copies the time validation function into the local time logging driver, which maintains accurate time tracking and license expiration detection independently of network connections.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12430441B2Data processing system capable of preventing system time from being tampered in off-line status
Publication Date: 2025.09.30 TRUSTONE SECURITY INC
  • US12430441B2 patent drawing
  • US12430441B2 patent drawing
  • US12430441B2 patent drawing

AI summary

A data processing system in an off-line status includes a BIOS device and at least one processor. The BIOS device is for calculating a current system time. The at least one processor executes an operating system. The operating system includes a time logging driver resident in a driver layer of the operating system and an application layer start/end time recording process resident in an application layer of the operating system. The time logging driver records a driver start time and a driver end time. The application layer start/end time recording process records an application layer start time and an application layer end time. The data processing system of the invention, according to the application layer start time, the application layer end time, the driver start time and the driver end time, adjusts the current system time to prevent the current system time from being tampered.