Preboot Micro-System for Secure Configuration Updates
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer operating systems are vulnerable to virus attacks during the download and installation of updates, as existing methods require connecting to a network, which can lead to infection before or during the update process.
Innovation Solution
A micro-system independent of the target operating system, utilizing Preboot Execution Environment technology to acquire and update configuration packages from a server before the system boots, ensuring that only necessary operations are performed outside the operating system, reducing the risk of virus invasion.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the computer system connects to the network to download update packages, then the system can obtain operating system patches and virus databases, but the system becomes vulnerable to virus infection during the download process
Solution Approach 1:
The patent applies preliminary action by performing the update package download and installation before the operating system boots. The micro-system downloads configuration packages containing operating system patches and virus databases in advance, extracts the necessary data, and updates the target system configurations before the vulnerable operating system environment is activated. This timing ensures that the download and update processes occur in a controlled environment with minimal attack surface.
Solution Approach 2:
The patent segments the update process into distinct functional units: an acquisition unit for downloading configuration packages, an extraction unit for extracting target configuration data, and a configuration updating unit for applying updates. This segmentation isolates the vulnerable network download operation from the running operating system, creating separate functional boundaries that reduce the risk of virus propagation to the main system.
2Reliability
If the update process is performed within the target operating system, then the system can apply patches and updates, but the operating system processes and services become potential entry points for virus attacks
Solution Approach 1:
The patent introduces a micro-system as an intermediary between the network and the target operating system. This micro-system performs all update-related operations including downloading configuration packages, extracting data, and applying updates without requiring the target operating system to be running. The micro-system acts as a mediator that bridges the update functionality while isolating the vulnerable operating system processes from direct involvement in the update workflow, thereby eliminating potential virus entry points through system processes.
Solution Approach 2:
The update operations are performed as preliminary actions before the target operating system boots. By completing the download, extraction, and configuration update steps in advance during the micro-system execution phase, the patent ensures that when the operating system starts, it already has the updated configurations without needing to execute vulnerable update processes within the operating system environment itself.
Data Source
AI summary
A technique for updating configurations of a target system in a computer. The method comprises booting, based on Preboot Execution Environment technology, a micro-system for updating configurations of a target system before booting the target system, the micro-system performing the steps of: (a) acquiring target configuration packages via a network from a server; (b) extracting target configuration data from said target configuration packages; and (c) updating the configurations of said target system by using said target configuration data, wherein said micro-system is independent of said target system.


