Secure OS Memory Segmentation via Firmware Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems with multiple operating environments face challenges in maintaining security and isolation between active and sleep states, leading to potential data alteration and interference between OS environments.

Innovation Solution

The system employs separate random access memories connected through different controllers, with system firmware managing transitions between active and sleep states, and blocking access to prevent data alteration, using a removable nonvolatile memory module for enhanced security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple operating systems are loaded into the same main memory, then the system can execute multiple OSs coexisting, but security against data alteration between OS states cannot be ensured

Engineering Contradiction:
Improveability to execute multiple operating systemsVSAvoidsecurity against data alteration
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the main memory into multiple independent logical memory blocks, with each block dedicated to a specific operating system. This segmentation ensures that each OS operates in an isolated memory space, preventing data alteration between OS states while maintaining the ability to execute multiple operating systems simultaneously or in suspended states.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system firmware acts as an intermediary that manages memory allocation and access control between multiple operating systems. It loads each OS into its assigned logical memory block and controls transitions between active and suspended states, ensuring that security requirements are met while enabling multi-OS execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the system loads all operating systems into the same memory space, then switching between OSs is simple, but interference between OS environments occurs

Engineering Contradiction:
Improvesimplicity of OS switchingVSAvoidinterference between OS environments
Core Design Contradiction:
Ease of operationVSObject-generated harmful factors

Solution Approach 1:

The patent segments the memory space into distinct logical memory blocks, with each block assigned to a specific operating system. This segmentation prevents interference between OS environments by ensuring that each OS operates in its own isolated memory space, while the system firmware manages transitions between these segmented environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Each logical memory block is given local quality characteristics specific to its assigned operating system, including isolated access permissions and controlled transition states. This allows each OS to have its own protected environment while maintaining overall system coordination through the firmware's management of active and suspended states.

Inventive Principle:
Principle #3Local quality

3Reliability

If separate random access memories with different controllers are used for each operating system, then security and isolation are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and isolation between OS statesVSAvoidnumber of memory controllers
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the existing main memory into multiple logical memory blocks with independent access control, rather than using physically separate memory modules. This approach provides the security and isolation benefits of separate memories while avoiding the increased device complexity of multiple physical memory controllers.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system firmware serves multiple functions: it manages memory allocation across logical blocks, controls OS loading and switching, enforces security policies, and coordinates transitions between active and suspended states. This multi-functional approach consolidates control that would otherwise require separate hardware components.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9483278B2Arrangement for secure independent operating environments in a computer
Publication Date: 2016.11.01 LENOVO (SINGAPORE) PTE LTD
  • US9483278B2 patent drawing
  • US9483278B2 patent drawing
  • US9483278B2 patent drawing

AI summary

The present invention protects a memory image of an OS in a sleep state. A CPU executes a first OS or a second OS while switching there between. The first OS is loaded into a main memory, and the second OS is loaded into an auxiliary memory. The auxiliary memory may be connected to a chipset through a PCIe interface. The main memory and the auxiliary memory are configured such that, when one is in an active state where the right of access to the CPU is obtained, the other makes a transition to the sleep state where there is no right of access to the CPU while maintaining the memory image. In order to prevent one OS in the active state from accessing the main memory or the auxiliary memory in which the memory image of the other OS in the sleep state is stored, the BIOS may set a corresponding controller to disabled during a POST.