SmartNIC Boot Snapshots for Ransomware Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing ransomware protection methods focus on data protection, but if the IHS boot path is compromised, they require time-consuming manual intervention to restore the system, making it difficult to recover from boot device encryption.

Innovation Solution

A ransomware protection SmartNIC creates secure snapshots of the boot device and configures an alternate boot device in the boot order, allowing automatic recovery to the secure alternate device in case of an attack, with periodic snapshot creation and real-time ransomware detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing ransomware protection methods focus on data protection, then data security is improved, but the system requires time-consuming manual intervention to restore the boot device after compromise

Engineering Contradiction:
Improvedata securityVSAvoidmanual intervention time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system creates secure snapshots of the boot device periodically in advance, storing them on a separate storage device. When ransomware compromises the boot device, these pre-created snapshots are immediately available for restoration, eliminating the need for time-consuming manual intervention to recreate the boot device from scratch.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system creates a copy (snapshot) of the boot device's contents and stores it on a separate storage device. This copy can be restored to the boot device quickly during recovery operations, replacing the need for manual reconstruction of the boot device and significantly reducing restoration time.

Inventive Principle:
Principle #26Copying

2Object-affected harmful factors

If the IHS boot path is compromised by ransomware, then the system can encrypt and protect data, but the system becomes unusable and requires manual restoration

Engineering Contradiction:
Improveransomware encryptionVSAvoidsystem availability
Core Design Contradiction:
Object-affected harmful factorsVSEase of operation

Solution Approach 1:

The system performs preliminary actions by creating secure snapshots of the boot device before ransomware can compromise it. These snapshots are stored on a separate storage device and remain intact even if the primary boot device is encrypted, allowing the system to be restored to full functionality without manual intervention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary storage device that holds secure snapshots of the boot device. This intermediary storage acts as a safe haven for boot device contents, allowing restoration without direct interaction with the compromised boot device and maintaining system availability during recovery.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If manual intervention is required to restore the boot device, then data can be protected from ransomware, but productivity is reduced due to system downtime

Engineering Contradiction:
Improveransomware protectionVSAvoidsystem availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system enables self-service recovery by automatically restoring the boot device from pre-created secure snapshots stored on a separate storage device. This eliminates the need for manual intervention and allows the system to recover autonomously, minimizing downtime and maintaining productivity while still providing robust ransomware protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates secure snapshots in advance and stores them on separate storage devices, so that when ransomware attacks occur, the restoration process can begin immediately without manual intervention. This preliminary preparation ensures rapid recovery and minimizes productivity loss while maintaining reliable ransomware protection.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12468546B2Systems and methods for protecting information handling system boot using smart network interface controllers
Publication Date: 2025.11.11 DELL PROD LP
  • US12468546B2 patent drawing
  • US12468546B2 patent drawing
  • US12468546B2 patent drawing

AI summary

A ransomware protection smart network interface controller (SmartNIC) is configured to create a secure snapshot of a boot device of an information handling system (IHS), create a secure alternate boot device on each boot of the IHS, and export the boot device and the secure alternate boot device to the IHS. The IHS is configured to set a boot order of the IHS, with the secure alternate boot device immediately after the boot device in the boot order. The ransomware protection SmartNIC may also be configured to create a read and writeable snapshot from the secure snapshot of the IHS boot device, and may delete, on each subsequent boot of the IHS, the read and writeable snapshot for the prior boot, and create a new read and writeable snapshot from a secure snapshot of the IHS boot device from the subsequent boot of the IHS.