Storage Firewall Authentication and Encryption for Malware Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network and PC defensive mechanisms are inadequate in preventing malware infections, especially from new threats that arise daily, as they rely on outdated security technologies and are vulnerable to zero-day attacks, leading to compromised data integrity and confidentiality.

Innovation Solution

An improved storage firewall architecture that provides application software authentication, user authentication and authorization, monitoring of storage access requests, encryption of data and software, and server-based system administration to prevent malware penetration, with a secure synchronization link to a configuration and patch management server.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional network firewalls and anti-virus software are used, then basic network perimeter protection is provided, but they are vulnerable to zero-day attacks and new malware threats

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidability to defend against new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements preliminary action by creating a secure boot environment and establishing a trusted computing base before the system operates. The secure boot process verifies cryptographic signatures of system components before execution, preventing malware from establishing itself in the first place. This proactive approach addresses the vulnerability to zero-day attacks by ensuring system integrity from startup.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer between the hardware and software through virtualization technology. A virtual machine monitor (VMM) creates a isolated environment where applications run with restricted access to underlying hardware resources. This intermediary prevents malware from directly compromising system components while maintaining functional access, thus improving reliability without sacrificing adaptability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security measures are implemented, then protection against malware is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the system into distinct isolated environments using virtualization. The secure boot environment, virtual machine monitor, and application execution layers are separated into independent segments with controlled communication channels. This modular architecture improves security effectiveness while managing complexity through clear boundaries and defined interfaces between segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements self-service through automated cryptographic verification during the secure boot process. The system automatically verifies digital signatures of system components, enforces access control policies, and manages security credentials without requiring manual intervention. This automation maintains high security effectiveness while reducing operational complexity.

Inventive Principle:
Principle #25Self-service

3Reliability

If application authentication and storage protection are implemented, then data integrity and confidentiality are improved, but access performance may be reduced

Engineering Contradiction:
Improvedata integrity and confidentialityVSAvoidstorage access speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by establishing cryptographic authentication and access control policies before storage operations occur. Application credentials are verified and access rights are determined during the initialization phase, allowing subsequent storage operations to proceed with pre-established security parameters. This reduces the overhead during actual data access while maintaining strong security protections.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS7743260B2Firewall+storage apparatus, method and system
Publication Date: 2010.06.22 FETIK RICHARD
  • US7743260B2 patent drawing
  • US7743260B2 patent drawing
  • US7743260B2 patent drawing

AI summary

A storage firewall architecture, method and system that works in parallel with existing security technologies and, inter alia, provides application software authentication, user authentication & authorization in the execution of an application, examination, verification, and authentication of all storage access requests, monitoring of protected storage to detect & repair anomalous changes, encryption of protected storage, both data and software, provisioning (deployment) of patches, configuration changes, and software through a secure synchronization link to a configuration and patch management server, and server-based system administration & configuration to prevent malware from penetrating local configuration mechanisms.