Storage Device Firmware Anti-Malware Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current anti-virus/anti-malware approaches lack mechanisms to detect and prevent modifications to data stored on storage devices by malware, particularly rootkits, which can hide their presence and alter data, leading to untrusted reads and writes, and there is no secure storage available to protect against such threats.

Innovation Solution

The implementation of enhanced firmware in storage devices that establishes trusted communication channels using protocols like Opal, Trusted Send/Receive, and Security Protocol In/Out, along with firmware-based redirection of LBA requests and secure storage features, to ensure secure reads and writes, and provides secure storage for sensitive information like signature databases and passwords.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If AV/AM approaches are used to protect storage devices, then malware detection capability is improved, but the system cannot detect modifications to data by rootkits because they operate below the AV/AM protection layer

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidrootkit stealth attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a new dimension of security by implementing firmware-level protection within the storage device itself, operating at a different layer (firmware/I/O level) than traditional AV/AM software. This firmware-based approach creates a trusted execution environment that can detect and prevent rootkit attacks independently of the compromised OS layer.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent employs firmware as an intermediary layer between the storage media and the host system. This firmware mediator establishes trusted communication channels and validates all I/O operations, preventing both malware and rootkits from directly compromising data integrity without detection.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If the system allows read/write operations to storage devices, then data accessibility is improved, but malware can modify or redirect data without detection (lack of trusted reads/writes)

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata trustworthiness
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent implements feedback mechanisms where the firmware continuously monitors and validates I/O operations. Trusted read operations verify data integrity before presenting it to the host, while trusted write operations confirm successful data commitment to storage, providing real-time feedback on the trustworthiness of each operation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary validation actions through firmware before data is read or written. The firmware establishes trusted communication channels in advance and validates I/O requests before they reach the storage media, preventing malware from intercepting or modifying data during transmission.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If firmware-based security features are implemented in storage devices, then protection against malware and rootkits is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidfirmware implementation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements multi-functional firmware that handles multiple security tasks: establishing trusted communication channels, validating I/O operations, detecting malware and rootkits, and providing secure storage. This universal firmware approach consolidates multiple security functions into a single integrated component, managing complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS9183390B2Systems and methods for providing anti-malware protection on storage devices
Publication Date: 2015.11.10 TAHOE RES LTD
  • US9183390B2 patent drawing
  • US9183390B2 patent drawing
  • US9183390B2 patent drawing

AI summary

Systems and methods for providing anti-malware protection on storage devices are described. In one embodiment, a storage device includes a controller, firmware, and memory. The firmware communicates with an authorized entity (e.g., external entity, operating system) to establish a secure communication channel. The system includes secure storage to securely store data.