Pre-boot Compatibility Testing for Secure Disk Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing full disk encryption methods face compatibility issues during the pre-boot authentication stage, leading to potential inoperability of computers due to hardware compatibility problems with BIOS or UEFI interfaces, which can prevent successful booting and data protection when a computer is stolen or compromised.

Innovation Solution

A system and method for performing pre-boot compatibility testing to determine whether full disk encryption can be applied safely, involving a processor that conducts pre-boot compatibility tests, compares results with encryption policies, and decides on the application of full disk encryption, alerting administrators if encryption is not feasible, and allowing for optional on-demand testing without immediate encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If full disk encryption is applied to the boot disk, then data protection is improved, but hardware compatibility issues during pre-boot authentication may cause the computer to fail to start

Engineering Contradiction:
Improvedata protectionVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs pre-boot compatibility testing before applying full disk encryption to ensure the pre-boot authentication module will work with the computer's hardware. This preliminary action identifies and resolves potential compatibility issues before they can cause boot failures, allowing the system to maintain both data protection and hardware compatibility.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If pre-boot authentication module is integrated into the booting process, then data security is improved, but the complexity of the booting process increases

Engineering Contradiction:
Improvedata securityVSAvoidbooting process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the booting process into distinct phases: pre-boot compatibility testing, pre-boot authentication, and normal booting. By dividing the process into separate test and execution phases, the system can validate hardware compatibility independently before integrating the authentication module, thereby managing complexity while maintaining security.

Inventive Principle:
Principle #1Segmentation

3Reliability

If pre-boot compatibility tests are performed, then the risk of boot failure is reduced, but the time required for the booting process increases

Engineering Contradiction:
Improveboot success rateVSAvoidbooting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The compatibility tests are performed once during the pre-boot phase before full disk encryption is applied, rather than repeatedly during each boot. This preliminary testing establishes hardware compatibility in advance, ensuring reliable booting thereafter without adding ongoing time penalties to the normal booting process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9384353B2System and method for encryption of disk based on pre-boot compatibility testing
Publication Date: 2016.07.05 AO KASPERSKY LAB
  • US9384353B2 patent drawing
  • US9384353B2 patent drawing
  • US9384353B2 patent drawing

AI summary

Disclosed are systems, methods and computer program products for encryption of disk based on pre-boot compatibility testing. An example method includes upon determining, by a processor, no test booting of the computer, performing one or more pre-boot compatibility tests to boot an operating system of the computer; upon detecting a successful test booting, performing booting the operating system of the computer or performing the one or more pre-boot compatibility tests again; upon detecting an unsuccessful test booting, restoring a process of ordinary booting of the operating system and performing an ordinary booting of the operating system; determining one or more encryption policies applicable to a pre-boot execution stage of the computer; and comparing results of the one or more pre-boot compatibility tests with the encryption policies to determine whether to apply a full disk encryption to the boot disk.