Secure Device Bypassing OS Security for Debugging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Customized OS modifications on computing devices, such as ATMs, often prevent access to core OS functionality, making it difficult for users to debug issues, leading to delays and potential loss of customizations, especially in critical devices like ATMs where downtime causes customer dissatisfaction.

Innovation Solution

A method and system that uses a secure device with a USB security key to bypass OS system security by loading a specific OS image with customized security settings into memory, allowing full access to native OS services and disabling user-implemented security restrictions, enabling enhanced debugging and modification capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If site customizations and security settings are applied to the OS image, then device security and control are improved, but access to core OS functionality is restricted

Engineering Contradiction:
Improvedevice securityVSAvoidaccess to core OS functionality
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the OS boot process into multiple pathways: a normal boot path that enforces site customizations and security settings, and a secure recovery path that bypasses these restrictions. This is achieved by dividing the boot configuration into separate configuration files (e.g., default.cfg and recovery.cfg) that can be selectively applied based on the boot mode, allowing both security and access needs to be met in different contexts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a secure device (such as a USB security key or hardware token) as an intermediary that mediates between the restricted OS environment and the user's need to access core functionality. This intermediary provides authentication and authorization mechanisms that allow privileged access to recovery modes while maintaining the security restrictions in normal operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If safe mode is used to disable startup applications, then debugging capability is improved, but OS services are disabled and customizations are lost

Engineering Contradiction:
Improvedebugging capabilityVSAvoidOS service availability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by creating a targeted recovery environment that selectively disables only the problematic startup applications or security settings while preserving essential OS services and other customizations. This is achieved through configuration files that specify which components to override in recovery mode, allowing debugging capabilities to be enabled locally without globally disabling services.

Inventive Principle:
Principle #3Local quality

3Ease of repair

If an onsite technician is called to fix OS issues, then device functionality is restored, but downtime increases and customizations may be lost

Engineering Contradiction:
Improvedevice functionality restorationVSAvoiddevice downtime
Core Design Contradiction:
Ease of repairVSLoss of time

Solution Approach 1:

The patent implements self-service capabilities by providing end-users with the tools and mechanisms to recover their devices independently. Users can insert a secure device during boot to automatically trigger the recovery pathway, which restores access to core OS functionality without requiring technician intervention. This eliminates downtime and preserves customizations since the recovery process is controlled and reversible.

Inventive Principle:
Principle #25Self-service

4Reliability

If ATMs are kept offline for security maintenance, then system security is improved, but customer satisfaction deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidcustomer service availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the security configuration flexible and changeable at runtime. The system can dynamically switch between secure restricted mode and accessible recovery mode based on user authentication and operational needs. This allows ATMs to maintain security during normal operation while enabling quick transitions to accessible modes for troubleshooting, minimizing downtime and maintaining customer service availability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11200066B2Secure device for bypassing operating system (OS) security
Publication Date: 2021.12.14 NCR VOYIX CORP
  • US11200066B2 patent drawing
  • US11200066B2 patent drawing
  • US11200066B2 patent drawing

AI summary

A portable device having a key is interfaced to a host computing device. The host computing device detects the key on the portable device and authenticates a user for using the key. A boot is forced of the host computing device and during the boot a customized image of an Operating System (OS) for the host computing device is loaded into volatile memory of the host computing device and customized security settings are applied to the OS based on a value of the key.