Storage Device Security Management Program for Seamless OS Boot
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Securely encrypted storage devices with authentication require manual user intervention and customized BIOS to unlock, limiting their use as system disks and providing a poor user experience.
Innovation Solution
A secure execution method and system where a security management program pre-stored on a first storage device is loaded and executed to decrypt and verify identity information, allowing the operating system to be loaded without extending the BIOS or manual intervention, utilizing a dual storage area setup where the first area is externally visible and the second, larger area is locked but usable after successful verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual user intervention and customized BIOS are used to unlock the storage device, then security is improved, but ease of operation deteriorates
Solution Approach 1:
The security management program is pre-stored in the storage device and automatically executes during the boot process before the operating system loads. This preliminary action enables automatic authentication without requiring manual user intervention, thus maintaining security while improving ease of operation.
2Reliability
If customized BIOS is used to unlock the storage device, then security is improved, but device complexity increases
Solution Approach 1:
The authentication function is extracted from the BIOS and implemented as a separate security management program stored in the storage device itself. This extraction eliminates the need for customized BIOS while maintaining security, thus reducing device complexity.
3Adaptability or versatility
If the storage device is unlocked in advance to store the operating system, then adaptability is improved, but security deteriorates
Solution Approach 1:
The storage device is segmented into different storage areas with different access controls. The first storage area is accessible before authentication, allowing the OS to load, while the second storage area remains locked and is only accessible after successful authentication. This segmentation enables the device to function as both a system disk and a secure data disk, improving adaptability while maintaining security.
Data Source
Figure 1
Figure 2
Figure 3~4
AI summary
The present invention relates to the technical field of information, and provides a safe operation method and system for storage data. The safe operation method and system for storage data comprises: when a second storage device is detected, reading encrypted identity information pre-stored in the second storage device; then, sending the encrypted identity information to a first storage device; next, loading system data after the identity information is decrypted in the first storage device and passes verification; and finally, operating an operating system according to the system data. Safe operation of the operating system is realized, without extension of a BIOS and manual intervention, and therefore, the user experience is good; moreover, a security management program is pre-stored in the first storage device, thereby saving a storage space of a host.