User Trusted Device Boot Verification for Virtualization Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure booting from external media do not adequately verify whether the boot process is occurring in a genuine, non-virtualized environment, potentially allowing malicious virtualized environments to tamper with the clean operating system.

Innovation Solution

A user trusted device with a connection interface and persistent memory that enables a computer to boot from the device, executes virtualization sensitive code, and determines through completion data whether the execution occurred in a virtualized environment, ensuring the boot process continues only if it is not virtualized.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a computer restarts from external boot media to execute clean software, then security against malware is improved, but the system can still be compromised if the boot process occurs in a virtualized environment

Engineering Contradiction:
ImprovesecurityVSAvoidvirtualization tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs virtualization detection during the boot process before executing the clean operating system. The verification module executes virtualization-sensitive code and analyzes completion data to determine whether the boot process is occurring in a virtualized environment, preventing tampering before it can affect the clean OS

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The invention introduces a verification module as an intermediary between the boot media and the operating system. This module executes virtualization-sensitive code and analyzes completion data to determine whether the environment is virtualized, acting as a mediator that prevents malicious virtualized environments from tampering with the clean OS

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtualization detection code is executed during boot, then environment verification is improved, but boot time is increased

Engineering Contradiction:
Improveenvironment verificationVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system executes only the necessary virtualization-sensitive code and analysis during boot to determine the environment type. The verification module performs minimal but sufficient checks to detect virtualization, avoiding excessive computation that would significantly delay boot time while still achieving reliable environment verification

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10318724B2User trusted device for detecting a virtualized environment
Publication Date: 2019.06.11 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10318724B2 patent drawing
  • US10318724B2 patent drawing

AI summary

A computer to boot from a user trusted device, the user trusted device comprising a connection interface enabling connection with said computer, the method comprising: enabling said computer to start booting from the user trusted device upon connection of the user trusted device with said computer via said connection interface; instructing a processor of the computer to execute virtualization sensitive code and issue completion data upon completion of execution, which completion data depends on the virtualization sensitive code and its execution by the processor; determining, based on said completion data, whether the execution was not performed in a virtualized environment; and enabling said computer to complete booting from the user trusted device upon determining that the execution was not performed in a virtualized environment. The invention is further directed to a user trusted device enabling this method and to related systems.