Trusted Channel for Anti-Malware Operations in Storage Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional anti-malware solutions struggle to detect and remove rootkits and other malware with high privilege access, as they can intercept and alter anti-virus scans, making it difficult to eliminate malware from storage devices.
Innovation Solution
Establishing a trusted connection between the host and storage device controller using encryption techniques, allowing anti-malware software to transmit encrypted operations and authenticate commands, thereby bypassing malware attempts to redirect or hide infected locations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional anti-virus solutions are used to scan storage devices, then basic malware detection is possible, but rootkits with supervisor privilege can intercept and alter scan queries to hide infected locations
Solution Approach 1:
The patent introduces a trusted channel as an intermediary communication path between the host and storage device controller. This trusted channel mediates anti-malware operations by providing a secure, authenticated pathway that bypasses malware-infected standard interfaces. The trusted channel includes authentication mechanisms that verify the identity of communicating parties, preventing rootkits from intercepting or altering commands. This resolves the contradiction by maintaining reliable malware detection while eliminating the malware's ability to intercept communications through the standard storage interface.
2Productivity
If malware is allowed to execute with high privileges, then system operations can be performed efficiently, but the malware can redirect anti-malware operations to preserve infected storage locations
Solution Approach 1:
The patent segments the communication channel into two distinct paths: a standard storage interface and a trusted channel. The trusted channel is a separate, authenticated communication path that handles anti-malware operations independently from the standard interface that malware may have compromised. This segmentation allows the system to maintain efficient operations through the standard interface while ensuring anti-malware operation integrity through the isolated, secure trusted channel. The separation prevents malware from redirecting anti-malware operations while preserving system productivity.
3Ease of operation
If standard storage interfaces are used for anti-malware operations, then ease of operation is maintained, but malware can alter commands to hide infected locations
Solution Approach 1:
The patent implements preliminary authentication actions within the trusted channel before executing anti-malware operations. The authentication mechanism verifies the identity and authority of the host and controller beforehand, establishing a secure context for subsequent operations. This preliminary verification ensures command authenticity without complicating the user interface or operation flow. The authentication happens automatically in the background, maintaining ease of operation while preventing malware from altering commands, as any tampered commands would fail authentication verification.
Data Source
AI summary
Disclosed is a system and method for extending anti-malware protection to systems having multiple storage devices, such as RAID. In embodiments, a trusted connection may be established between a host and a controller of the multiple storage devices. The trusted connection may use various information encryption techniques to undermine attempts by malware to preserve malware-infected locations on the storage devices by redirecting anti-malware protection related operations by the host. Through an encrypted and trusted connection between the host and a controller of the multiple storage devices, anti-virus and/or anti-malware software (hereinafter, AVS) may transmit encrypted anti-malware protection related operations to the controller of the multiple storage devices, overcoming detection and/or diversion by the malware. Other embodiments may be described and claimed.


