USB Device Booting Inspection OS via Mode Switch
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer inspection tools face challenges in remaining undetectable to malicious software and may not function in systems with limited interfaces or space constraints, as they rely on common communication technologies like Ethernet for remote access.
Innovation Solution
A self-contained USB device that can switch between mass storage and computing modes, allowing it to boot an inspection operating system on a host computer and perform inspection and disinfection functions without being detected, using proprietary protocols and various interfaces like GPIO, Wi-Fi, or Bluetooth for connectivity.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If common communication technologies like Ethernet are used for remote client access to the hypervisor, then remote inspection capabilities are enabled, but the inspection activity becomes easily detectable by malicious software
Solution Approach 1:
The patent introduces a USB device as an intermediary between the external client and the infected host computer. The USB device contains a bootable hypervisor that inspects the host's operating system without requiring direct network communication. This intermediary approach enables remote inspection capabilities while avoiding the detectability issues of direct Ethernet-based hypervisor access, as the inspection occurs through the USB interface rather than network interfaces that malicious software can monitor.
2Adaptability or versatility
If multiple communication interfaces are provided for remote access, then inspection functionality is improved, but device complexity and space requirements increase
Solution Approach 1:
The USB device is designed as a multi-functional unit that combines hypervisor capabilities, client interface, and inspection tools within a single device. Rather than requiring separate network interfaces and external computers, the USB device performs multiple functions including hosting the hypervisor, providing remote access via its own interface to the client, and executing inspection tasks. This universal design reduces overall system complexity while maintaining versatile inspection functionality.
3Ease of operation
If the USB device operates as a mass storage device, then it is easily detected and accessed by the host computer, but it cannot provide independent computing resources for running the inspection operating system
Solution Approach 1:
The USB device dynamically switches between two operational modes: mass storage mode and computing mode. In mass storage mode, the device presents itself as a simple storage device for easy detection and access by the host computer's BIOS/UEFI, enabling the host to boot the inspection operating system from it. After the inspection OS is loaded, the device transitions to computing mode, where it operates as an independent computer with its own processor and memory, providing the computing resources needed to run the hypervisor and perform inspection tasks without being detected by malicious software on the host.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to a method for inspecting a host computer using a USB device, wherein the USB device is selectively operable in a mass storage mode and in a computing mode. The method comprises booting (S310; S320) an inspection operating system on the host computer from the USB device, when the USB device is operated in the mass storage mode, the inspection operating system providing one or more inspection functions for inspecting the host computer, switching (S316; S326) the USB device from the mass storage mode to the computing mode, and inspecting (S318; S328) the host computer using the one or more inspection functions of the inspection operating system, the one or more inspection functions being controlled from the USB device operated in the computing mode.