Storage Firewall Authentication and Encryption for Malware Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network and PC defensive mechanisms are inadequate in preventing malware infections, especially from new threats that arise daily, as they rely on outdated security technologies and are vulnerable to zero-day attacks, leading to compromised data integrity and confidentiality.
Innovation Solution
An improved storage firewall architecture that provides application software authentication, user authentication and authorization, monitoring of storage access requests, encryption of data and software, and server-based system administration to prevent malware penetration, with a secure synchronization link to a configuration and patch management server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional network firewalls and anti-virus software are used, then basic network perimeter protection is provided, but they are vulnerable to zero-day attacks and new malware threats
Solution Approach 1:
The patent implements preliminary action by creating a secure boot environment and establishing a trusted computing base before the system operates. The secure boot process verifies cryptographic signatures of system components before execution, preventing malware from establishing itself in the first place. This proactive approach addresses the vulnerability to zero-day attacks by ensuring system integrity from startup.
Solution Approach 2:
The patent introduces an intermediary layer between the hardware and software through virtualization technology. A virtual machine monitor (VMM) creates a isolated environment where applications run with restricted access to underlying hardware resources. This intermediary prevents malware from directly compromising system components while maintaining functional access, thus improving reliability without sacrificing adaptability.
2Reliability
If comprehensive security measures are implemented, then protection against malware is improved, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the system into distinct isolated environments using virtualization. The secure boot environment, virtual machine monitor, and application execution layers are separated into independent segments with controlled communication channels. This modular architecture improves security effectiveness while managing complexity through clear boundaries and defined interfaces between segments.
Solution Approach 2:
The patent implements self-service through automated cryptographic verification during the secure boot process. The system automatically verifies digital signatures of system components, enforces access control policies, and manages security credentials without requiring manual intervention. This automation maintains high security effectiveness while reducing operational complexity.
3Reliability
If application authentication and storage protection are implemented, then data integrity and confidentiality are improved, but access performance may be reduced
Solution Approach 1:
The patent implements preliminary action by establishing cryptographic authentication and access control policies before storage operations occur. Application credentials are verified and access rights are determined during the initialization phase, allowing subsequent storage operations to proceed with pre-established security parameters. This reduces the overhead during actual data access while maintaining strong security protections.
Data Source
AI summary
A storage firewall architecture, method and system that works in parallel with existing security technologies and, inter alia, provides application software authentication, user authentication & authorization in the execution of an application, examination, verification, and authentication of all storage access requests, monitoring of protected storage to detect & repair anomalous changes, encryption of protected storage, both data and software, provisioning (deployment) of patches, configuration changes, and software through a secure synchronization link to a configuration and patch management server, and server-based system administration & configuration to prevent malware from penetrating local configuration mechanisms.


