User Trusted Device Boot Verification for Virtualization Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for secure booting from external media do not adequately verify whether the boot process is occurring in a genuine, non-virtualized environment, potentially allowing malicious virtualized environments to tamper with the clean operating system.
Innovation Solution
A user trusted device with a connection interface and persistent memory that enables a computer to boot from the device, executes virtualization sensitive code, and determines through completion data whether the execution occurred in a virtualized environment, ensuring the boot process continues only if it is not virtualized.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a computer restarts from external boot media to execute clean software, then security against malware is improved, but the system can still be compromised if the boot process occurs in a virtualized environment
Solution Approach 1:
The system performs virtualization detection during the boot process before executing the clean operating system. The verification module executes virtualization-sensitive code and analyzes completion data to determine whether the boot process is occurring in a virtualized environment, preventing tampering before it can affect the clean OS
Solution Approach 2:
The invention introduces a verification module as an intermediary between the boot media and the operating system. This module executes virtualization-sensitive code and analyzes completion data to determine whether the environment is virtualized, acting as a mediator that prevents malicious virtualized environments from tampering with the clean OS
2Reliability
If virtualization detection code is executed during boot, then environment verification is improved, but boot time is increased
Solution Approach 1:
The system executes only the necessary virtualization-sensitive code and analysis during boot to determine the environment type. The verification module performs minimal but sufficient checks to detect virtualization, avoiding excessive computation that would significantly delay boot time while still achieving reliable environment verification
Data Source
AI summary
A computer to boot from a user trusted device, the user trusted device comprising a connection interface enabling connection with said computer, the method comprising: enabling said computer to start booting from the user trusted device upon connection of the user trusted device with said computer via said connection interface; instructing a processor of the computer to execute virtualization sensitive code and issue completion data upon completion of execution, which completion data depends on the virtualization sensitive code and its execution by the processor; determining, based on said completion data, whether the execution was not performed in a virtualized environment; and enabling said computer to complete booting from the user trusted device upon determining that the execution was not performed in a virtualized environment. The invention is further directed to a user trusted device enabling this method and to related systems.

