Platform Management Device for Secure Laptop Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for securing mobile electronic devices, such as laptops, are inadequate as they often require an active network connection for GPS-based tracking and can be easily circumvented by disabling timing hardware or obtaining unauthorized passwords, leading to increased risks of identity theft and productivity losses.

Innovation Solution

A platform management device that provides secure connection and control by using biometric recognition, flash memory for storage, and GPS location capabilities, ensuring two-factor authentication and remote disabling of devices when not in authorized possession, with functionality enabled only through a provisioned USB or wireless connection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If GPS transponders are used to track lost computers, then location monitoring capability is improved, but the system requires an active network connection which may not be available in buildings or underground structures

Engineering Contradiction:
Improvelocation tracking capabilityVSAvoidoperational capability without network connection
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by storing location data locally in the device's memory before network connection is lost or unavailable. The computer continues to record and save GPS coordinates and timestamp information in its local storage, allowing the location data to be preserved and later transmitted when network connectivity is restored, thus maintaining operational capability without continuous network connection.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If timeout solutions are implemented to secure lost computers, then security against unauthorized access is improved, but the protection can be easily circumvented by removing or turning off timing hardware

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidvulnerability to hardware manipulation
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary element - a cryptographic authentication mechanism that mediates between the user and the system resources. Instead of relying solely on timing hardware that can be manipulated, the system uses cryptographic keys and authentication protocols that verify user identity through software-based security, making circumvention through hardware removal ineffective.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If passwords are used for authentication, then access control is improved, but unauthorized users may obtain the password without permission or knowledge of the authorized user

Engineering Contradiction:
Improveaccess control capabilityVSAvoidrisk of password compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system replaces the mechanical/password-based authentication system with a biometric authentication system. Instead of relying on knowledge-based passwords that can be stolen or guessed, the system uses fingerprint or other biometric data that is inherent to the user's physical characteristics, making unauthorized access significantly more difficult as biometric data cannot be easily replicated or stolen.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If a platform management device is inserted into USB port to enable the laptop, then security control is improved, but the device requires physical possession of the management device which may be lost or stolen

Engineering Contradiction:
Improvesecurity control capabilityVSAvoidconvenience of device access
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges the platform management device with the laptop by integrating the security control functionality directly into the laptop's existing hardware and software infrastructure. The management device communicates with the laptop through the USB connection, but the actual security controls are enforced by the laptop's firmware and operating system, creating a unified security system that doesn't require separate physical possession of additional devices.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS8307055B2Secure platform management device
Publication Date: 2012.11.06 ABSOLUTE SOFTWARE CORPORATION
  • US8307055B2 patent drawing
  • US8307055B2 patent drawing
  • US8307055B2 patent drawing

AI summary

A platform management device configured to control the functionality of a provisioned electronic device is disclosed. The platform management device includes a processor operative to execute commands. A memory maintains a series of instructions that when executed by the processor, causes the processor to: (1) establish a connection with a corresponding electronic device; and (2) transfer operating parameters to the corresponding electronic device, such that access to and operation of the electronic device may be controlled. Examples of device control include denying access to an unauthorized user and forcing the electronic device into a disabled state by remote operation from an authorized user.