Trusted Diskless OS for Out-of-Band Security Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

User devices can become inoperable or compromised due to corrupted operating systems or malware infections, which allow attackers to gain administrator access and evade detection by antivirus systems.

Innovation Solution

A secured augmented trusted diskless operating system image is launched via device hardware components like BIOS, allowing for out-of-band security inspections and scans without executing the compromised OS, using a security agent to detect issues, hibernate the system, and boot into a trusted image for security scanning and repair.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a compromised operating system is used for security inspections, then the inspection process can be performed, but the inspection results may be inaccurate or evaded due to malware manipulation

Engineering Contradiction:
Improvesecurity inspection accuracyVSAvoidmalware manipulation
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a trusted third-party inspection system that operates independently from the compromised operating system. This intermediary system boots from external media (USB drive or network) and performs security inspections without executing code from the potentially infected local storage, thereby eliminating malware manipulation of inspection results.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The inspection system extracts itself from the compromised operating system environment by booting from external media. This separation removes the inspection process from the harmful context of the compromised OS, allowing unbiased security analysis without interference from malware.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If the operating system is hibernated or rebooted for security scanning, then malware detection can be performed, but device availability and operational continuity are reduced

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddevice availability time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security inspections during the boot process before the compromised operating system fully loads. By detecting threats during this preliminary phase and isolating them, the system can perform security scans without requiring full system hibernation or extended reboots, minimizing disruption to device availability.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If antivirus systems and security checks are used within the compromised OS, then security monitoring can be performed, but these systems can be subverted by attackers to hide from detection

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoiddetection evasion
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The inspection system operates as an external intermediary that does not rely on the compromised OS's own security mechanisms. Instead, it brings its own trusted security checks from external media, eliminating the vulnerability where attackers can subvert built-in antivirus systems to hide their presence.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The security inspection process is segmented from the compromised operating system by booting from separate external media. This segmentation ensures that the inspection mechanisms remain independent and trusted, while the compromised OS is analyzed as an external target rather than executing its own potentially manipulated security checks.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20220382636A1Security inspections
Publication Date: 2022.12.01 HEWLETT PACKARD DEVELOPMENT COMPANY LP
  • US20220382636A1 patent drawing
  • US20220382636A1 patent drawing

AI summary

In some examples, a method for performing an out-of-band security inspection of a device comprises generating a snapshot of the state of the device, storing data representing the snapshot to a non-volatile storage of the device, and storing a hash of the snapshot in a device BIOS, transitioning the power state of the device, triggering boot of a trusted diskless operating system image, providing the data representing the snapshot and the hash of the snapshot to the trusted diskless operating system image, and executing a script selected on the basis of a trigger event and the hash of the snapshot to analyse at least a portion of the non-volatile storage of the device.