Secure Startup Device for Computer Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure start-up methods for computer installations require local storage of cryptographic keys and impose constraints on users, such as using the same operating system and restrictive authentication, which limits personalized user environments and secure execution of programs.

Innovation Solution

A secure start-up device with interfaces for connecting to a computer installation and an external data medium, featuring means for securing data and executable codes, including authentication and cryptographic verification, allowing secure transmission and execution of specific start-up programs, thereby overcoming the constraints of local key storage and restrictive authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If cryptographic keys are stored locally in a secure manner on the internal hard disk, then program integrity can be verified, but the system becomes restricted and cannot support multiple users with personalized environments

Engineering Contradiction:
Improveprogram integrity verificationVSAvoidmulti-user personalized environment support
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an external data medium as an intermediary carrier that stores cryptographic keys and authentication data separately from the computer installation. This mediator enables multiple users to have their own personalized environments while maintaining secure program verification, resolving the contradiction between integrity verification and multi-user adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the storage of cryptographic keys and authentication data from the main computer installation by using an external data medium. This segmentation allows the system to maintain security while supporting multiple users with personalized settings, as each user's data can be stored separately on the external medium.

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication data is stored locally in a secure manner, then user authentication can be performed, but the device complexity increases due to the need for secure storage and verification mechanisms

Engineering Contradiction:
Improveuser authenticationVSAvoidsecure storage and verification mechanisms
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external data medium acts as an intermediary that handles secure storage and verification of authentication data. This reduces the complexity of the main computer installation by offloading these functions to a separate, dedicated storage medium, while still providing reliable user authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If the same operating system must be used for all users, then authentication can be simplified, but the versatility of personalized working environments is limited

Engineering Contradiction:
Improveauthentication simplicityVSAvoidpersonalized working environment
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The external data medium serves as a mediator that stores user-specific authentication data and environment configurations. This allows different users to have personalized working environments while using the same operating system, as each user's preferences and settings are stored separately on the external medium and loaded during authentication.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2077515B1Device, systems and method for securely starting up a computer system
Publication Date: 2018.03.07 BULL SA
  • EP2077515B1 patent drawingFigure 1~2
  • EP2077515B1 patent drawingFigure 3~4

AI summary

The device (30) has connection interfaces (34, 36) connected to a computer facility (10) and an external data medium (20) i.e. Universal serial bustype key, respectively. A securing unit, formed of a microprocessor (32) and storage units (42, 44), secures data (22) and executable codes (24) of a startup program of the facility. A transmission unit formed of a storage unit (40) transmits the data and the codes from the data medium towards the facility, after execution of the securing unit, for starting up the facility using the transmitted data and the codes. Independent claims are also included for the following: (1) a computer system comprising a starting up device connected with a computer facility (2) an informatics system for securely starting up a computer facility (3) a method for securely starting up a computer facility.