Shadow Boot Server Authentication for Drive Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional PC systems face challenges in securely protecting confidential information and restricting access to applications, as software must be executable by a CPU, allowing private information to be acquired through analysis, and it is difficult to add application-specific restrictions on electronic appliances, leading to vulnerabilities in protecting service provider information without relying on the service provider's platform.
Innovation Solution
An information recording apparatus with a drive unit and host unit that executes a shadow boot program prior to the boot program, performs server authentication, and uses a password to unlock user data storage, ensuring secure access and protection of digital contents by locking and unlocking data storage based on authentication results.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If software is made executable by a CPU to enable content distribution services, then service functionality is improved, but private information can be acquired by analyzing CPU-executed instructions step by step
Solution Approach 1:
The system divides the boot process into two separate programs: a shadow boot program stored in the drive unit and a regular boot program stored in the host unit. The shadow boot program executes first, performs server authentication, and only after successful authentication does the system proceed to execute the regular boot program. This segmentation isolates the authentication logic from the main service software, preventing analysis of private information in the service program while maintaining service functionality.
Solution Approach 2:
The shadow boot program performs server authentication and security verification before the regular boot program is executed. By conducting authentication in advance during the shadow boot phase, the system ensures that only authenticated users can proceed to load and execute service applications, preventing unauthorized access and analysis of private information before service functionality is compromised.
2Ease of manufacture
If a commonly applicable platform is used regardless of service provider to reduce electronic appliance cost, then manufacturing cost is reduced, but it is difficult to add application-specific restrictions and protect service provider information
Solution Approach 1:
The shadow boot program acts as an intermediary between the common platform hardware and the service-specific software. It mediates authentication between the user system and the service provider's server, enabling a standardized platform to support multiple service providers while maintaining individual service restrictions and protecting service provider information through centralized authentication control.
3Reliability
If encryption function is provided in storage device to encrypt data, then data security is improved, but access control requires PIN code registration which adds operational complexity
Solution Approach 1:
The shadow boot program automatically performs server authentication and password verification without requiring manual PIN code input from the user. The authentication process is self-executing during system boot, reducing operational complexity while maintaining strong encryption-based security for data stored in the drive unit.
Data Source
AI summary
An information recording apparatus has a drive unit to record digital information including digital contents; and a host unit to control reading and writing of the digital information for the drive unit. The host unit has a network processing unit to communicate with a server, a shadow determination unit to determine whether a shadow boot program to be executed prior to a boot program is executable, a shadow reading unit to read the shadow program from the drive unit when the shadow determination unit determines to be executable, a shadow execution unit to execute the shadow program, a server authentication unit to perform authentication with the server in accordance with a processing of the shadow program, and a password transmitter to transmit to the drive unit a password used for unlock of the drive unit when the authentication with the server is successful.


