Pre-boot Security Verification for Self-Service Terminals

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-Service Terminals (SSTs) like ATMs and SSCSs are vulnerable to fraud and malware attacks due to manipulation of computer configurations, leading to significant financial losses, and existing security measures are inadequate in preventing unauthorized transactions and ensuring secure boot states post-servicing.

Innovation Solution

Implementing a pre-boot security verification system that launches a pre-boot Operating System (OS) before the main OS, identifies variances in configuration settings and properties, and performs remedial actions to ensure the system is in a secure state, including launching the main OS only when no variances are found and stopping the pre-boot OS.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures are used without pre-boot verification, then the system complexity remains low and ease of operation is maintained, but security reliability is insufficient and financial losses occur from attacks and configuration issues

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a pre-boot verification process that executes security checks before the main operating system loads. This preliminary action verifies the boot device order, checks for unauthorized modifications, and validates system configuration before allowing normal operation, thereby establishing security reliability in advance without requiring complex security mechanisms during normal operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent divides the boot process into distinct segments: a pre-boot verification phase and a main operation phase. The pre-boot phase handles security verification independently, checking boot device order and system configuration, while the main phase handles normal transactions. This segmentation isolates security functions from the main system, improving reliability without significantly increasing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If pre-boot verification and remedial actions are implemented, then security reliability improves and unauthorized transactions are prevented, but device complexity increases due to additional verification layers

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements automated remedial actions that allow the system to self-correct security issues without external intervention. When verification failures are detected, the system automatically performs remediation such as restoring proper boot device order or correcting configuration settings, then re-verification is performed. This self-service approach improves security reliability while minimizing the need for complex manual security management procedures

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent incorporates a feedback mechanism where the pre-boot verification process continuously monitors system state, compares it against expected secure states, and triggers remedial actions when deviations are detected. The system provides feedback loops that re-verify after remediation to ensure security requirements are met, thereby improving reliability through systematic verification and correction without requiring proportionally complex security infrastructure

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security verification is performed during boot, then loss prevention improves by identifying attacks and configuration issues, but productivity decreases due to extended boot time and additional verification steps

Engineering Contradiction:
Improveloss preventionVSAvoidboot time
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements a targeted verification approach that focuses on critical security parameters such as boot device order and essential system configuration rather than performing exhaustive checks of all system components. This partial verification of the most security-critical elements provides sufficient loss prevention while minimizing the time penalty associated with comprehensive scanning of the entire system

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent performs security verification in the pre-boot phase before the main operating system and transaction processing load the system. By completing verification activities beforehand, the system ensures security checks do not interrupt or delay normal transaction processing once the system is operational, thereby maintaining productivity during business operations while achieving loss prevention through advance verification

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If technicians manually verify system state after servicing, then ease of operation is maintained with simple manual checks, but security reliability is insufficient as technicians may fail to return boot device order or configuration to secure settings

Engineering Contradiction:
Improveease of servicingVSAvoidsecurity state verification
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements an automated verification system that performs security checks without requiring technician intervention. The pre-boot verification process automatically checks boot device order, system configuration, and security settings, eliminating reliance on technician memory or attention. This self-service approach maintains ease of servicing while dramatically improving security state verification reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent provides automated feedback to technicians and system operators regarding the security verification status. When verification fails or configuration issues are detected, the system generates alerts and can automatically initiate remedial actions, providing clear feedback loops that ensure security requirements are met without requiring technicians to manually verify each security parameter

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3136281B1Computer pre-boot security verification, enforcement, and remediation
Publication Date: 2020.09.09 NCR VOYIX CORP
  • EP3136281B1 patent drawingFigure 1
  • EP3136281B1 patent drawingFigure 2
  • EP3136281B1 patent drawingFigure 3

AI summary

Various embodiments herein each include at least one of systems, methods, and software for computer pre-boot security verification. Some embodiments are implemented during a boot sequence of a computer (210) that controls Self-Service Terminal (102) operation before a main Operating System (OS) of the computer (210) is loaded. One such embodiment in the form of a method (300) includes starting a pre-boot OS upon start of a computer that controls operation of an SST (step 302) and identifying any variances between a current state of the computer and data representative of a reference state within a computing environment of the pre-boot OS (step 304). This example method further includes performing at least one remedial action when any variance is identified (step 306) and launching a main OS and stopping and unloading the pre-boot OS when no variance is identified (step 308).