Storage Device Security Management Program for Seamless OS Boot

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securely encrypted storage devices with authentication require manual user intervention and customized BIOS to unlock, limiting their use as system disks and providing a poor user experience.

Innovation Solution

A secure execution method and system where a security management program pre-stored on a first storage device is loaded and executed to decrypt and verify identity information, allowing the operating system to be loaded without extending the BIOS or manual intervention, utilizing a dual storage area setup where the first area is externally visible and the second, larger area is locked but usable after successful verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual user intervention and customized BIOS are used to unlock the storage device, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security management program is pre-stored in the storage device and automatically executes during the boot process before the operating system loads. This preliminary action enables automatic authentication without requiring manual user intervention, thus maintaining security while improving ease of operation.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If customized BIOS is used to unlock the storage device, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The authentication function is extracted from the BIOS and implemented as a separate security management program stored in the storage device itself. This extraction eliminates the need for customized BIOS while maintaining security, thus reducing device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If the storage device is unlocked in advance to store the operating system, then adaptability is improved, but security deteriorates

Engineering Contradiction:
ImproveadaptabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The storage device is segmented into different storage areas with different access controls. The first storage area is accessible before authentication, allowing the OS to load, while the second storage area remains locked and is only accessible after successful authentication. This segmentation enables the device to function as both a system disk and a secure data disk, improving adaptability while maintaining security.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentEP3805969B1Safe operation method and system for storage data
Publication Date: 2024.03.06 HUNAN GOKE MICROELECTRONICS CO LTD
  • EP3805969B1 patent drawingFigure 1
  • EP3805969B1 patent drawingFigure 2
  • EP3805969B1 patent drawingFigure 3~4

AI summary

The present invention relates to the technical field of information, and provides a safe operation method and system for storage data. The safe operation method and system for storage data comprises: when a second storage device is detected, reading encrypted identity information pre-stored in the second storage device; then, sending the encrypted identity information to a first storage device; next, loading system data after the identity information is decrypted in the first storage device and passes verification; and finally, operating an operating system according to the system data. Safe operation of the operating system is realized, without extension of a BIOS and manual intervention, and therefore, the user experience is good; moreover, a security management program is pre-stored in the first storage device, thereby saving a storage space of a host.