Preboot Micro-System for Secure Configuration Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer operating systems are vulnerable to virus attacks during the download and installation of updates, as existing methods require connecting to a network, which can lead to infection before or during the update process.

Innovation Solution

A micro-system independent of the target operating system, utilizing Preboot Execution Environment technology to acquire and update configuration packages from a server before the system boots, ensuring that only necessary operations are performed outside the operating system, reducing the risk of virus invasion.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the computer system connects to the network to download update packages, then the system can obtain operating system patches and virus databases, but the system becomes vulnerable to virus infection during the download process

Engineering Contradiction:
Improvesystem securityVSAvoidvirus infection risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary action by performing the update package download and installation before the operating system boots. The micro-system downloads configuration packages containing operating system patches and virus databases in advance, extracts the necessary data, and updates the target system configurations before the vulnerable operating system environment is activated. This timing ensures that the download and update processes occur in a controlled environment with minimal attack surface.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent segments the update process into distinct functional units: an acquisition unit for downloading configuration packages, an extraction unit for extracting target configuration data, and a configuration updating unit for applying updates. This segmentation isolates the vulnerable network download operation from the running operating system, creating separate functional boundaries that reduce the risk of virus propagation to the main system.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the update process is performed within the target operating system, then the system can apply patches and updates, but the operating system processes and services become potential entry points for virus attacks

Engineering Contradiction:
Improveupdate capabilityVSAvoidvirus invasion through system processes
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a micro-system as an intermediary between the network and the target operating system. This micro-system performs all update-related operations including downloading configuration packages, extracting data, and applying updates without requiring the target operating system to be running. The micro-system acts as a mediator that bridges the update functionality while isolating the vulnerable operating system processes from direct involvement in the update workflow, thereby eliminating potential virus entry points through system processes.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The update operations are performed as preliminary actions before the target operating system boots. By completing the download, extraction, and configuration update steps in advance during the micro-system execution phase, the patent ensures that when the operating system starts, it already has the updated configurations without needing to execute vulnerable update processes within the operating system environment itself.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8140841B2Method and micro-system for updating configurations of target system in computer
Publication Date: 2012.03.20 SERVICENOW INC
  • US8140841B2 patent drawing
  • US8140841B2 patent drawing
  • US8140841B2 patent drawing

AI summary

A technique for updating configurations of a target system in a computer. The method comprises booting, based on Preboot Execution Environment technology, a micro-system for updating configurations of a target system before booting the target system, the micro-system performing the steps of: (a) acquiring target configuration packages via a network from a server; (b) extracting target configuration data from said target configuration packages; and (c) updating the configurations of said target system by using said target configuration data, wherein said micro-system is independent of said target system.