Shadow Boot Program Server Authentication for Secure Data Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional PC systems face challenges in protecting confidential information and restricting application execution, as software must be executable by a CPU, allowing private information to be analyzed and making it difficult to add service-specific applications, leading to vulnerabilities in electronic appliance platforms.

Innovation Solution

An information recording apparatus with a drive unit and host unit that executes a shadow boot program prior to the boot program, performs server authentication, and unlocks user data storage only when authentication is successful, using a password verification mechanism to secure access and protect service provider information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software is made executable by CPU with private information and algorism included, then content distribution service can be provided, but private information can be acquired by analyzing instructions executed by CPU

Engineering Contradiction:
Improvecontent distribution service capabilityVSAvoidprivate information analysis vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the confidential information (algorism and private data) from the executable software and stores it separately in protected memory areas within the recording medium. The software executes normally to provide content distribution services, but the sensitive information is isolated and protected from CPU analysis, resolving the vulnerability while maintaining service functionality.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a nested structure where the confidential information is embedded within the recording medium in a protected manner. The executable software operates at one level while the protected information resides in a nested, secured layer that is accessible only under specific conditions, preventing analysis while enabling controlled access for legitimate operations.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Productivity

If applications are restricted for performance reasons, then electronic appliance performance is maintained, but user cannot add service-specific applications

Engineering Contradiction:
Improveelectronic appliance performanceVSAvoidapplication addition capability
Core Design Contradiction:
ProductivityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal platform where a single recording medium can serve multiple service providers and applications. The protected information storage mechanism works consistently across different services, allowing users to add various service-specific applications without compromising system performance, as the same protective framework handles all confidential information uniformly.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If different platforms are used for different service providers, then service provider information is protected, but production cost increases

Engineering Contradiction:
Improveservice provider information protectionVSAvoidproduction cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements a universal protected information storage mechanism that can be used across different service providers and applications. Instead of creating separate protection systems for each provider, the same recording medium structure and protected storage approach serves multiple purposes, reducing production costs while maintaining reliable protection of each service provider's confidential information.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10547604B2Information recording apparatus with shadow boot program for authentication with a server
Publication Date: 2020.01.28 KIOXIA CORP
  • US10547604B2 patent drawing
  • US10547604B2 patent drawing
  • US10547604B2 patent drawing

AI summary

An information recording apparatus has a drive unit to record digital information including digital contents; and a host unit to control reading and writing of the digital information for the drive unit. The host unit has a network processing unit to communicate with a server, a shadow determination unit to determine whether a shadow boot program to be executed prior to a boot program is executable, a shadow reading unit to read the shadow program from the drive unit when the shadow determination unit determines to be executable, a shadow execution unit to execute the shadow program, a server authentication unit to perform authentication with the server in accordance with a processing of the shadow program, and a password transmitter to transmit to the drive unit a password used for unlock of the drive unit when the authentication with the server is successful.