Pre-OS Policy Enforcement for OS Configuration Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems face challenges in protecting against malicious programs that can alter operating system configuration values, compromising security and integrity during the boot process.

Innovation Solution

Implementing a pre-operating system environment that checks and enforces policies for operating system configuration values using firmware and a policy loader, ensuring only trusted changes are made and preventing unauthorized modifications by verifying digital signatures and trusted entities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the operating system is allowed to modify configuration values freely, then system adaptability and ease of operation are improved, but system security and integrity are compromised

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidsystem integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements a pre-operating system environment that establishes security policies and integrity checks before the operating system loads. This preliminary action creates a trusted foundation that prevents malicious configuration changes while allowing legitimate system adaptation, resolving the contradiction between flexibility and integrity.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a policy loader and pre-operating system environment as intermediary layers between hardware and the operating system. These intermediaries enforce security policies on configuration values, allowing the system to maintain integrity while permitting controlled adaptability through approved configuration changes.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If strict policy enforcement is implemented to prevent unauthorized changes, then system security is improved, but system complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidboot process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the boot process into distinct phases: a pre-operating system environment phase that handles security policy enforcement, and a subsequent operating system phase. This segmentation isolates the complexity of security checks to a specific phase, preventing it from propagating through the entire system and reducing overall perceived complexity.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The policy loader automatically verifies configuration values against security policies without requiring manual intervention. The system self-regulates configuration changes through automated integrity checks and trusted entity verification, reducing operational complexity while maintaining strict security enforcement.

Inventive Principle:
Principle #25Self-service

3Reliability

If configuration values are verified against security policies during boot, then system integrity is improved, but boot time increases

Engineering Contradiction:
Improveconfiguration integrityVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs security policy verification and configuration validation in the pre-operating system environment before the main operating system boots. By completing these integrity checks preliminarily, the patent ensures that once the operating system starts, no additional time-consuming verification is needed, thus minimizing the impact on overall boot time while maintaining configuration integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP2681689B1Protecting operating system configuration values
Publication Date: 2017.04.19 MICROSOFT TECHNOLOGY LICENSING LLC
  • EP2681689B1 patent drawingFigure 1
  • EP2681689B1 patent drawingFigure 2
  • EP2681689B1 patent drawingFigure 3

AI summary

In a pre-operating system environment on a device prior to loading and running an operating system on the device, a policy identifying configuration settings for the operating system is obtained. The operating system itself is prevented from changing this policy, but the policy can be changed under certain circumstances by components of the pre-operating system environment. The policy is compared to configuration values used by the operating system, and the operating system is allowed to boot with the configuration values if the configuration values satisfy the policy. However, if the configuration values do not satisfy the policy, then a responsive action is taken.