Portable Guest OS Secure Boot for Host Computers

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for maintaining a consistent and secure operating environment across multiple computers are limited, as they either restrict portability, fail to transport personal files and applications, or lack effective security measures against malware and data exposure.

Innovation Solution

A system utilizing an encrypted computer-readable portable storage medium with a guest portable operation system, which includes a processor for user-dependent decryption and device-dependent authentication, allowing for the creation of a connected-state guest operation environment on a host computer that authorizes access to intellectual property data and accommodates peripheral devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a portable apparatus stores an operating system and personal files to maintain a consistent operating environment across multiple computers, then the user experience and consistency are improved, but security risks such as malware transmission and data exposure increase

Engineering Contradiction:
Improveconsistent operating environmentVSAvoidmalware transmission and data exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a secure boot loader as an intermediary component that runs between the portable apparatus and the host computer. This boot loader establishes a trusted execution environment that mediates all interactions, allowing the consistent operating environment to run while blocking malware transmission and protecting sensitive data through cryptographic verification of the execution chain.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If a portable apparatus is made fully portable by storing the operating system on it, then adaptability to different host computers is improved, but device complexity increases

Engineering Contradiction:
ImproveportabilityVSAvoidportable apparatus complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the system into distinct functional components: a lightweight boot loader on the portable apparatus that handles authentication and environment setup, and the full operating system that runs in a controlled manner on the host computer. This segmentation reduces the complexity of the portable apparatus while maintaining full portability capability.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If personal files and applications are stored on a portable apparatus for use across multiple computers, then user convenience is improved, but the risk of data loss and unauthorized access increases

Engineering Contradiction:
Improveuser convenienceVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent changes the security parameters of the portable apparatus by implementing cryptographic authentication mechanisms. The boot loader verifies digital signatures of the operating system and authorized applications, and encrypts sensitive user data. These parameter changes maintain user convenience while significantly improving data security and preventing unauthorized access.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10356086B1Methods and apparatuses for securely operating shared host computers with portable apparatuses
Publication Date: 2019.07.16 RPX CORP
  • US10356086B1 patent drawing
  • US10356086B1 patent drawing
  • US10356086B1 patent drawing

AI summary

The present invention provides methods and apparatuses that utilize a portable apparatus to securely operate a host electronic device. Typically, each portable apparatus includes a data storage unit which stores an operating system and other software. In one example, a portable apparatus can provide a virtual operating environment on top of a host's operating system for a host device. In another example, a portable apparatus containing its operating system can directly boot a host device with one or more hardware profiles. Furthermore, a device-dependent protection against software piracy, a user-dependent protection against sensitive data leaks, a controllable host operating environment to prevent unwanted information exposure, and a secure restoration procedure to prevent virus infection between the host device users may be incorporated. Moreover, a pre-defined information may also be utilized to authorize a connected-state guest operation environment in the host device.