Pre-OS Backup Partition Isolates Data from Ransomware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ransomware attacks often spread to and destroy both the operating system (OS) partition and external backups, making it difficult for users to recover their data, as existing backup solutions are susceptible to malware infection.

Innovation Solution

A method that initiates a reboot of the OS into a pre-OS environment, allowing data from the OS partition to be securely backed up to a separate backup partition, which is inaccessible to malware, ensuring the integrity of the backup data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data is backed up while the OS is running, then the backup process is simple and integrated, but the backup data is vulnerable to ransomware infection

Engineering Contradiction:
Improvebackup data integrityVSAvoidbackup process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by booting into a pre-OS environment before the main OS loads, allowing backup operations to occur in a clean state before malware could infect the system. This preliminary backup action ensures data integrity while maintaining automated operation through pre-configured backup partitions and scripts that execute automatically during the boot process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The pre-OS environment acts as an intermediary between the hardware and the main OS, providing a isolated sandbox environment for performing backup operations. This intermediary layer allows the system to access and backup data from the main OS partition without being affected by malware running in the main OS, while still maintaining automated operation through pre-configured partition structures.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a separate backup partition is used, then data isolation from malware is achieved, but access to backup partition requires pre-OS environment

Engineering Contradiction:
Improvebackup securityVSAvoidbackup access ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements self-service by automatically performing backup operations during the pre-OS boot phase without requiring user intervention. The pre-configured backup partition structure and automated scripts enable the system to service its own backup needs, ensuring secure data isolation while maintaining operational simplicity through automation. Users simply need to restore data from the isolated backup partition when needed.

Inventive Principle:
Principle #25Self-service

3Reliability

If automated backup is performed frequently, then data recovery capability is improved, but system resources are consumed during boot process

Engineering Contradiction:
Improvedata recovery capabilityVSAvoidboot process energy consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies partial action by performing only essential backup operations during the pre-OS boot phase, focusing on critical data protection without executing full system scans or redundant backup procedures. This selective backup approach improves data recovery capability for essential data while minimizing energy consumption during the boot process by avoiding excessive or unnecessary backup operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12001299B2Data backup on secure partition
Publication Date: 2024.06.04 LENOVO SWITZERLAND INTERNATIONAL GMBH
  • US12001299B2 patent drawing
  • US12001299B2 patent drawing
  • US12001299B2 patent drawing

AI summary

One embodiment provides a method, including: receiving, at an information handling device, an indication to backup data resident on an operating system (OS) partition of the information handling device; initiating, responsive to receiving the indication, a reboot of the OS into a pre-OS environment; accessing, in the pre-OS environment, a backup partition that is distinct and separate from the OS partition; and performing, subsequent to the accessing, a backup of the data from the OS partition to the backup partition. Other aspects are described and claimed.