Ransomware-Protection SmartNIC Secure Snapshots for IHS Repaving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing pave/repave techniques for Information Handling Systems (IHS) are slow, expensive, and prone to errors due to manual initialization and reliance on external sources for known firmware and software, posing security challenges and compliance issues.

Innovation Solution

Implement a ransomware protection SmartNIC or storage device with secure snapshots that create read and writable snapshots of the boot device, persisting across reboots and restoring the system to a known good state, providing protection against ransomware attacks and facilitating efficient, error-free pave/repave processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual pave/repave techniques using PXE or USB media are used, then system can be initialized to known state, but process is slow and expensive

Engineering Contradiction:
Improvesystem initialization to known stateVSAvoidpave/repave process speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system creates a read-only snapshot of the boot device in advance, storing it in non-volatile memory. This preliminary action allows the system to quickly restore to known state without performing slow manual PXE or USB media initialization processes during actual pave/repave operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent creates a snapshot copy of the boot device containing known good firmware and software images. This copy can be rapidly deployed to restore systems to known state, replacing the slow manual copying process of traditional PXE or USB media methods.

Inventive Principle:
Principle #26Copying

2Reliability

If manual pave/repave techniques are used, then system can be reinitialized, but process is prone to errors

Engineering Contradiction:
Improvesystem reinitializationVSAvoidpave/repave operation accuracy
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically manages the pave/repave process by detecting when reinitialization is needed and automatically restoring from the stored snapshot. This eliminates manual operations and associated errors, allowing the system to self-manage its initialization state.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system monitors the boot device and triggers repave operations when corruption or unauthorized changes are detected. This feedback mechanism ensures reliable reinitialization only when needed, reducing operational errors by avoiding unnecessary manual interventions.

Inventive Principle:
Principle #23Feedback

3Object-affected harmful factors

If external sources are used for known firmware and software, then security can be maintained, but operational costs increase

Engineering Contradiction:
Improveransomware protectionVSAvoidoperational efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent extracts the known good firmware and software images from external PXE servers or USB media and stores them locally in non-volatile memory as a snapshot. This eliminates dependency on external sources for critical recovery operations, reducing operational costs while maintaining security.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system prepares and stores known good images in advance within the system's non-volatile memory, creating a cushion against ransomware attacks and system failures. This beforehand preparation eliminates the need for expensive external recovery resources during critical events.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

Data Source

PatentUS12423425B2Pave and/or repave systems and methods using ransomware protection smart network interface controller or ransomware protection storage device secure snapshots
Publication Date: 2025.09.23 DELL PROD LP
  • US12423425B2 patent drawing
  • US12423425B2 patent drawing
  • US12423425B2 patent drawing

AI summary

An information handling system (IHS) smart network interface controller (SmartNIC) or storage device having a ransomware protection (engine) that paves an IHS by creating a secure snapshot of a boot device of the IHS, creating a read and writable snapshot from the secure snapshot, and exposing the read and writable snapshot of the secure snapshot to the IHS, through a unified extensible firmware interface (UEFI) or basic input/output system (BIOS) of the IHS, as a primary boot device. The ransomware protection (engine) may also repave the IHS by recreating the boot read and writable snapshot upon a reboot of the IHS, in response to receipt of a repave command (through a management interface of the SmartNIC), restoring the primary boot device to a known good state captured by the secure snapshot.