Trusted Channel for Anti-Malware Operations in Storage Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional anti-malware solutions struggle to detect and remove rootkits and other malware with high privilege access, as they can intercept and alter anti-virus scans, making it difficult to eliminate malware from storage devices.

Innovation Solution

Establishing a trusted connection between the host and storage device controller using encryption techniques, allowing anti-malware software to transmit encrypted operations and authenticate commands, thereby bypassing malware attempts to redirect or hide infected locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional anti-virus solutions are used to scan storage devices, then basic malware detection is possible, but rootkits with supervisor privilege can intercept and alter scan queries to hide infected locations

Engineering Contradiction:
Improveanti-malware detection reliabilityVSAvoidmalware interception capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted channel as an intermediary communication path between the host and storage device controller. This trusted channel mediates anti-malware operations by providing a secure, authenticated pathway that bypasses malware-infected standard interfaces. The trusted channel includes authentication mechanisms that verify the identity of communicating parties, preventing rootkits from intercepting or altering commands. This resolves the contradiction by maintaining reliable malware detection while eliminating the malware's ability to intercept communications through the standard storage interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If malware is allowed to execute with high privileges, then system operations can be performed efficiently, but the malware can redirect anti-malware operations to preserve infected storage locations

Engineering Contradiction:
Improvesystem operation efficiencyVSAvoidanti-malware operation integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the communication channel into two distinct paths: a standard storage interface and a trusted channel. The trusted channel is a separate, authenticated communication path that handles anti-malware operations independently from the standard interface that malware may have compromised. This segmentation allows the system to maintain efficient operations through the standard interface while ensuring anti-malware operation integrity through the isolated, secure trusted channel. The separation prevents malware from redirecting anti-malware operations while preserving system productivity.

Inventive Principle:
Principle #1Segmentation

3Ease of operation

If standard storage interfaces are used for anti-malware operations, then ease of operation is maintained, but malware can alter commands to hide infected locations

Engineering Contradiction:
Improveanti-malware operation simplicityVSAvoidcommand authenticity
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements preliminary authentication actions within the trusted channel before executing anti-malware operations. The authentication mechanism verifies the identity and authority of the host and controller beforehand, establishing a secure context for subsequent operations. This preliminary verification ensures command authenticity without complicating the user interface or operation flow. The authentication happens automatically in the background, maintaining ease of operation while preventing malware from altering commands, as any tampered commands would fail authentication verification.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9027148B2Anti-malware protection operation with instruction included in an operand
Publication Date: 2015.05.05 INTEL CORP
  • US9027148B2 patent drawing
  • US9027148B2 patent drawing
  • US9027148B2 patent drawing

AI summary

Disclosed is a system and method for extending anti-malware protection to systems having multiple storage devices, such as RAID. In embodiments, a trusted connection may be established between a host and a controller of the multiple storage devices. The trusted connection may use various information encryption techniques to undermine attempts by malware to preserve malware-infected locations on the storage devices by redirecting anti-malware protection related operations by the host. Through an encrypted and trusted connection between the host and a controller of the multiple storage devices, anti-virus and/or anti-malware software (hereinafter, AVS) may transmit encrypted anti-malware protection related operations to the controller of the multiple storage devices, overcoming detection and/or diversion by the malware. Other embodiments may be described and claimed.