Trusted Device Bootloader for Secure OS Provisioning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Remote desktop systems face scalability issues, high infrastructure costs, and vulnerability to server or network outages, while existing OS streaming solutions require a trusted hypervisor, limiting usability and security when using untrusted user terminals.
Innovation Solution
A method and device using a trusted, tamper-resistant portable device with bootloader logic and security data to securely provision an operating system image from a server to an untrusted user terminal, allowing secure booting, authentication, and streaming of OS images for execution, enabling offline operation without relying on the terminal's trustworthiness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If remote desktop systems are used to execute applications remotely over a network, then manageability is improved and users can access from any terminal, but scalability deteriorates and infrastructure costs increase linearly with the number of users
Solution Approach 1:
The system segments the operating system into a core component that remains on the server and a provisioned image that is streamed to the user terminal. This allows the terminal to execute applications locally using its own resources while the server maintains control and security, thereby improving scalability without sacrificing manageability.
Solution Approach 2:
A provisioning server acts as an intermediary between the central server and user terminals. The provisioning server streams OS images to terminals and manages the provisioning process, allowing the system to scale to multiple users without requiring proportional increases in central server resources, thus resolving the scalability contradiction.
2Adaptability or versatility
If remote desktop systems are used, then users are not tied to specific machines, but the system becomes vulnerable to server or network outages and prevents offline work
Solution Approach 1:
The system performs preliminary provisioning of the operating system image to the user terminal before offline work is needed. The OS image is streamed and stored locally on the terminal, enabling users to work offline without requiring continuous server connection, thus maintaining both terminal flexibility and system availability.
3Productivity
If OS images are streamed to user terminals for local execution, then terminal resources are utilized effectively, but security deteriorates when using untrusted terminals
Solution Approach 1:
A provisioning server with a trusted hypervisor acts as an intermediary between the untrusted user terminal and the OS image. The hypervisor creates a virtualized environment that isolates the OS execution from the terminal's potentially malicious software, allowing secure resource utilization on untrusted terminals while maintaining security through virtualization boundaries.
Solution Approach 2:
Instead of running the OS directly on the untrusted terminal, the system creates a copy of the OS in a virtualized environment controlled by the trusted hypervisor. This copied instance runs in isolation, allowing the terminal to utilize its resources effectively while the virtualization layer prevents security compromises from affecting the actual OS or terminal.
4Reliability
If a trusted hypervisor is required for OS streaming, then security is improved, but usability deteriorates because any user may compromise the terminal
Solution Approach 1:
The provisioning server with the trusted hypervisor serves as an intermediary that enables secure OS streaming to any terminal without requiring the terminal itself to be trusted. The hypervisor's virtualization capabilities create a secure execution environment that works on any standard terminal hardware, thereby maintaining both security and broad usability across different terminal types.
Data Source
Figure 1~6
Figure 3
Figure 4
AI summary
Methods and apparatus are provided for provisioning an operating system image from a server (2) to an untrusted user terminal (4) via a data communications network (3). A trusted device (5) such as a pocket USB device has tamper-resistant storage (9) containing bootloader logic, for controlling booting of a user terminal, and security data. On connection of the trusted device (5) to an untrusted user terminal (4), the user terminal is booted via the bootloader logic on the trusted device. Under control of the bootloader logic, a connection is established to the server (2) via the network (3) and the server is authenticated using the security data on the trusted device (5). An operating system boot image is received from the server (2) via this connection. The boot image is used to provision an operating system image from the server (2) to the user terminal (4) for execution of the operating system at the user terminal (4).