Read-Only Bootable Media for Secure Remote Work
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Companies with dispersed workforces face challenges in ensuring remote employees' security and data protection, as they cannot monitor work activities or prevent the misuse of confidential information, and their networks are vulnerable to viruses from employees' computers.
Innovation Solution
Implementing a read-only bootable media that provides a customized, secure operating system disabling persistent memory to prevent virus transfer and data misuse, and establishing a VPN tunnel for secure network access, while also allowing supervisors to remotely monitor and control remote agents' computers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Loss of energy
If employees use their own computers to log on to the company network, then the company can save costs on providing work computers, but the company network becomes susceptible to viruses and spy ware from employees' computers
Solution Approach 1:
A VPN tunnel acts as an intermediary layer between the employee's computer and the company network, enabling secure communication while isolating the internal network from direct exposure to potential threats on the employee's machine
Solution Approach 2:
The read-only bootable media creates a controlled, inert computing environment where the operating system runs from immutable storage, preventing malware from persisting or modifying system files, thus neutralizing the threat while allowing network access
2Loss of energy
If employees work remotely from home, then the company can save on office space and supplies, but employers lose the ability to monitor employees and ensure they are actually working
Solution Approach 1:
The system implements continuous feedback mechanisms through automated logging of all user activities, applications used, and network interactions, providing real-time visibility into employee work status and productivity without requiring physical presence
Solution Approach 2:
The customized operating system acts as an intermediary between the employee and the company, automatically collecting and reporting work activity data while maintaining the employee's productive work environment
3Reliability
If companies provide remote employees with dedicated work computers, then employees have secure equipment for work purposes, but it is costly and difficult to retrieve computers when employees leave
Solution Approach 1:
Instead of providing physical computers, the system delivers a virtualized work environment through read-only bootable media that can be loaded on any standard computer, eliminating the need to manage physical hardware assets while maintaining secure work capabilities
Solution Approach 2:
The read-only bootable media can be used on any standard computer hardware, making the work environment universally compatible and eliminating the need for company-specific equipment while maintaining security and control
4Reliability
If a customized operating system disables persistent memory to prevent virus transfer, then network security is improved, but employees cannot save confidential client information locally
Solution Approach 1:
The system uses the network connection as an intermediary for data storage and retrieval, allowing employees to access and work with confidential information through secure network protocols while preventing local persistence, effectively moving the storage function from local to remote without compromising security
Solution Approach 2:
Data is copied between the employee's temporary workspace and secure network storage as needed, allowing local access to information without permanent storage, enabling convenient data retrieval while maintaining security through repeated secure transfers rather than local persistence
Data Source
AI summary
A read-only bootable media is provided in which a remote agent loads the read-only bootable media onto a computer. The read-only bootable media provides a customized operating system that is run in the computer's volatile memory. The read-only media also disables any persistent storage connected to the agent computer or devices connected to the agent computer. This protects the agent's computer and any networks that the agent connects to from malicious software. Also, by disabling persistent storage, confidential information is protected from unauthorized retention by the agent.


