Secure Boot Code Recovery via Read-Only Storage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer recovery systems are complex and require user intervention or technician assistance to restore a corrupted operating system or firmware, and the recovery images themselves can be susceptible to data corruption, leading to costly and inefficient recovery processes.

Innovation Solution

A computing device with a secure read-only location for storing boot images, including multiple levels of boot code, which can automatically initiate a boot cycle, verify the usability of each level, and replace unusable boot code with secure code from this location, allowing the system to resume the boot cycle at a known good level, thereby facilitating self-recovery without external intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate recovery device (SD card or USB stick) is used, then the computer can restore itself from a corrupted operating system or firmware, but the user needs to manually create or update the recovery device, requiring additional steps and user intervention

Engineering Contradiction:
Improverecovery capabilityVSAvoidrecovery process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system automatically detects boot code corruption and initiates recovery by loading secure boot code from an integrated circuit chip without requiring user intervention to create or update external recovery devices. The recovery process is self-executing, eliminating manual steps while maintaining reliability

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

A secure boot code image is pre-stored in an integrated circuit chip during manufacturing, available immediately when corruption is detected. This eliminates the need for users to pre-create recovery devices, as the recovery capability is already in place and ready for automatic execution

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If manual updates of the recovery device are required, then the recovery device can remain compatible with system updates, but the process becomes more complex and time-consuming

Engineering Contradiction:
Improverecovery device compatibilityVSAvoidrecovery process steps
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system automatically detects when secure boot code updates are available and performs silent updates of the integrated circuit chip content without requiring user intervention. This maintains adaptability to system updates while eliminating manual update steps

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The secure boot code storage is integrated directly into the computer's integrated circuit chip rather than using separate external recovery devices. This merging eliminates the need for manual device management while maintaining adaptability, as the recovery capability is unified with the system itself

Inventive Principle:
Principle #5Merging (Combining)

3Adaptability or versatility

If boot code is stored in rewritable memory, then the operating system can be updated and modified, but the boot code becomes susceptible to corruption and compromise

Engineering Contradiction:
Improveoperating system update capabilityVSAvoidboot code integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The boot code is segmented into two parts: secure boot code stored in read-only integrated circuit chip memory (for integrity and reliability) and operating system stored in rewritable memory (for adaptability and update capability). This segmentation allows the OS to be updated while the secure boot code remains protected from corruption

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure boot code is pre-loaded into the integrated circuit chip during manufacturing with immutable protection. This preliminary action ensures that the boot code is established in a secure state before the operating system is installed, allowing subsequent OS updates without compromising boot code integrity

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9836606B2Secure recovery apparatus and method
Publication Date: 2017.12.05 GOOGLE LLC
  • US9836606B2 patent drawing
  • US9836606B2 patent drawing
  • US9836606B2 patent drawing

AI summary

A system and method is disclosed for recovering a boot image. Hardware instructions initiate a loading of a computer operating system on a computing device. During the loading of the operating system, multiple portions of boot code are verified and a determination is made whether each portion is valid. If a portion of boot code is determined to be invalid, a secure portion of the boot code is loaded to repair the invalid code and the loading of the operating system resumed.