Removable Bootable Drive Vault for Secure Laptop Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Small form factor (SFF) and laptop computers are vulnerable to both external and internal security threats, including theft and malicious code placement, and existing systems have not effectively protected against these threats.

Innovation Solution

A secure access system using removable bootable drives (RBDs) with a physical vault that releases an RBD configured for specific usage contexts, featuring a robust interface and tracking technology, allowing secure insertion and operation within SFF or laptop devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If removable bootable drives are made permanently installed to improve system reliability, then security protection against theft and malicious code is reduced

Engineering Contradiction:
Improvesystem reliabilityVSAvoidsecurity threats
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the bootable drive into a removable component that can be separated from the host system. The RBD enclosure contains the bootable drive, which can be removed and replaced independently, allowing the system to maintain reliability through consistent secure boot processes while improving security through physical separation and controlled access to the boot medium.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The RBD enclosure acts as an intermediary between the host system and the bootable drive. It provides a controlled interface that manages power and data connections while preventing direct access to the drive's internal components, thereby maintaining system reliability through standardized interfaces while enhancing security through physical protection and controlled access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If RBD access is restricted to specific usage contexts to improve security, then ease of operation is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidRBD access convenience
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system dynamically adjusts RBD access control based on the host system's operational context. Different usage contexts (e.g., maintenance mode, normal operation, secure boot) enable or disable RBD access automatically, providing security when needed while maintaining ease of operation when the system is in a safe state. The access control mechanism adapts its behavior according to system state rather than being statically restricted.

Inventive Principle:
Principle #15Dynamics

3Reliability

If robust RBD interface is used to withstand frequent insertions, then device complexity increases

Engineering Contradiction:
Improveinterface durabilityVSAvoidinterface structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The power interface and data interface are merged into a single integrated connector on the RBD enclosure. This unified interface structure reduces the number of separate components and connection points, thereby decreasing device complexity while maintaining the robustness needed for frequent insertions and removals. The combined interface ensures that both power and data connections are established simultaneously, improving reliability.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS20170300340A1Secure computer access using removable bootable drives
Publication Date: 2017.10.19 CRU DATA SECURITY GRP LLC
  • US20170300340A1 patent drawing
  • US20170300340A1 patent drawing
  • US20170300340A1 patent drawing

AI summary

Systems, methods, and non-transitory computer-readable media for providing access to small form factor (SFF) and laptop computers using removable bootable drives (RBD(s)) are disclosed herein. In some implementations, a physical RBD vault that contains RBD(s) is provided instructions to release an RBD for a specific secured usage that corresponds to a usage context of a user of a specific secured system. The RBD may comprise an SFF RBD that is configured to be inserted into an RBD enclosure created for an SFF laptop. The RBD may comprise a laptop RBD that is configured to be inserted into an RBD enclosure that is, in turn, built into a battery pack of the laptop computer.