Storage Device Firmware Anti-Malware Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current anti-virus/anti-malware approaches lack mechanisms to detect and prevent modifications to data stored on storage devices by malware, particularly rootkits, which can hide their presence and alter data, leading to untrusted reads and writes, and there is no secure storage available to protect against such threats.
Innovation Solution
The implementation of enhanced firmware in storage devices that establishes trusted communication channels using protocols like Opal, Trusted Send/Receive, and Security Protocol In/Out, along with firmware-based redirection of LBA requests and secure storage features, to ensure secure reads and writes, and provides secure storage for sensitive information like signature databases and passwords.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If AV/AM approaches are used to protect storage devices, then malware detection capability is improved, but the system cannot detect modifications to data by rootkits because they operate below the AV/AM protection layer
Solution Approach 1:
The patent introduces a new dimension of security by implementing firmware-level protection within the storage device itself, operating at a different layer (firmware/I/O level) than traditional AV/AM software. This firmware-based approach creates a trusted execution environment that can detect and prevent rootkit attacks independently of the compromised OS layer.
Solution Approach 2:
The patent employs firmware as an intermediary layer between the storage media and the host system. This firmware mediator establishes trusted communication channels and validates all I/O operations, preventing both malware and rootkits from directly compromising data integrity without detection.
2Ease of operation
If the system allows read/write operations to storage devices, then data accessibility is improved, but malware can modify or redirect data without detection (lack of trusted reads/writes)
Solution Approach 1:
The patent implements feedback mechanisms where the firmware continuously monitors and validates I/O operations. Trusted read operations verify data integrity before presenting it to the host, while trusted write operations confirm successful data commitment to storage, providing real-time feedback on the trustworthiness of each operation.
Solution Approach 2:
The patent performs preliminary validation actions through firmware before data is read or written. The firmware establishes trusted communication channels in advance and validates I/O requests before they reach the storage media, preventing malware from intercepting or modifying data during transmission.
3Reliability
If firmware-based security features are implemented in storage devices, then protection against malware and rootkits is improved, but device complexity increases
Solution Approach 1:
The patent implements multi-functional firmware that handles multiple security tasks: establishing trusted communication channels, validating I/O operations, detecting malware and rootkits, and providing secure storage. This universal firmware approach consolidates multiple security functions into a single integrated component, managing complexity through functional consolidation.
Data Source
AI summary
Systems and methods for providing anti-malware protection on storage devices are described. In one embodiment, a storage device includes a controller, firmware, and memory. The firmware communicates with an authorized entity (e.g., external entity, operating system) to establish a secure communication channel. The system includes secure storage to securely store data.


