Trusted Device Bootloader for Secure OS Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Remote desktop systems face scalability issues, high infrastructure costs, and vulnerability to server or network outages, while existing OS streaming solutions require a trusted hypervisor, limiting usability and security when using untrusted user terminals.

Innovation Solution

A method and device using a trusted, tamper-resistant portable device with bootloader logic and security data to securely provision an operating system image from a server to an untrusted user terminal, allowing secure booting, authentication, and streaming of OS images for execution, enabling offline operation without relying on the terminal's trustworthiness.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If remote desktop systems are used to execute applications remotely over a network, then manageability is improved and users can access from any terminal, but scalability deteriorates and infrastructure costs increase linearly with the number of users

Engineering Contradiction:
ImprovemanageabilityVSAvoidscalability
Core Design Contradiction:
Ease of operationVSProductivity

Solution Approach 1:

The system segments the operating system into a core component that remains on the server and a provisioned image that is streamed to the user terminal. This allows the terminal to execute applications locally using its own resources while the server maintains control and security, thereby improving scalability without sacrificing manageability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A provisioning server acts as an intermediary between the central server and user terminals. The provisioning server streams OS images to terminals and manages the provisioning process, allowing the system to scale to multiple users without requiring proportional increases in central server resources, thus resolving the scalability contradiction.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If remote desktop systems are used, then users are not tied to specific machines, but the system becomes vulnerable to server or network outages and prevents offline work

Engineering Contradiction:
Improveterminal flexibilityVSAvoidsystem availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary provisioning of the operating system image to the user terminal before offline work is needed. The OS image is streamed and stored locally on the terminal, enabling users to work offline without requiring continuous server connection, thus maintaining both terminal flexibility and system availability.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If OS images are streamed to user terminals for local execution, then terminal resources are utilized effectively, but security deteriorates when using untrusted terminals

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

A provisioning server with a trusted hypervisor acts as an intermediary between the untrusted user terminal and the OS image. The hypervisor creates a virtualized environment that isolates the OS execution from the terminal's potentially malicious software, allowing secure resource utilization on untrusted terminals while maintaining security through virtualization boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of running the OS directly on the untrusted terminal, the system creates a copy of the OS in a virtualized environment controlled by the trusted hypervisor. This copied instance runs in isolation, allowing the terminal to utilize its resources effectively while the virtualization layer prevents security compromises from affecting the actual OS or terminal.

Inventive Principle:
Principle #26Copying

4Reliability

If a trusted hypervisor is required for OS streaming, then security is improved, but usability deteriorates because any user may compromise the terminal

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The provisioning server with the trusted hypervisor serves as an intermediary that enables secure OS streaming to any terminal without requiring the terminal itself to be trusted. The hypervisor's virtualization capabilities create a secure execution environment that works on any standard terminal hardware, thereby maintaining both security and broad usability across different terminal types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2761523B1Provisioning of operating systems to user terminals
Publication Date: 2019.01.02 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • EP2761523B1 patent drawingFigure 1~6
  • EP2761523B1 patent drawingFigure 3
  • EP2761523B1 patent drawingFigure 4

AI summary

Methods and apparatus are provided for provisioning an operating system image from a server (2) to an untrusted user terminal (4) via a data communications network (3). A trusted device (5) such as a pocket USB device has tamper-resistant storage (9) containing bootloader logic, for controlling booting of a user terminal, and security data. On connection of the trusted device (5) to an untrusted user terminal (4), the user terminal is booted via the bootloader logic on the trusted device. Under control of the bootloader logic, a connection is established to the server (2) via the network (3) and the server is authenticated using the security data on the trusted device (5). An operating system boot image is received from the server (2) via this connection. The boot image is used to provision an operating system image from the server (2) to the user terminal (4) for execution of the operating system at the user terminal (4).