Virtualizing Storage Firmware for Portable Device Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Portable computing devices, such as smartphones and tablets, face vulnerabilities in their operating systems that can allow malware to access and defeat storage encryption, making existing information-at-rest protection methods ineffective against data theft.

Innovation Solution

A virtualizing and obfuscating storage firmware module is integrated into the main applications processor of portable devices, intercepting storage access requests to obfuscate data without relying on specialized hardware, using memory protection and privilege mode facilities to provide a higher level of assurance in data protection, while keeping authentication and encryption processes isolated from the main operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If storage encryption is incorporated into the portable device operating system, then storage encryption functionality is provided, but the system becomes vulnerable to malware and hackers who can obtain root access and defeat the encryption layer

Engineering Contradiction:
Improveease of deploymentVSAvoidsecurity reliability
Core Design Contradiction:
Ease of manufactureVSReliability

Solution Approach 1:

The system separates the encryption functionality into a distinct, isolated component that operates independently from the main operating system. This segmentation ensures that even if the OS is compromised, the encryption module remains secure and cannot be accessed by malware with root access.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An intermediary layer is introduced between the operating system and the storage device. This intermediary handles all encryption/decryption operations and acts as a protected buffer, preventing direct access to encrypted data by the OS or any applications running on it.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If self-encrypting drives are used in laptops, then hardware-based isolation of cryptographic functions is provided, but specialized hardware is required which is not amenable to solid-state storage systems in smartphones and tablets

Engineering Contradiction:
Improvecryptographic isolationVSAvoidhardware compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent replaces specialized hardware-based encryption (SEDs) with a software-based encryption system that runs in an isolated environment within the processor. This substitution allows the same cryptographic isolation benefits to be achieved without requiring specialized hardware, making it compatible with standard solid-state storage systems in smartphones and tablets.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The encryption system is designed to work with any standard solid-state storage device without requiring specialized hardware. The universal software-based approach can be deployed across different device types and storage technologies, providing both cryptographic isolation and broad hardware compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If authentication processes execute on the platform operating system, then user authentication is enabled, but key logger malware can steal the user's passphrase and allow attackers to access sensitive data

Engineering Contradiction:
Improveauthentication functionalityVSAvoidmalware vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

An intermediary authentication layer is introduced that handles passphrase input and verification in an isolated environment. This intermediary captures authentication credentials before they can be intercepted by malware in the operating system, and verifies them without exposing the actual passphrase to the vulnerable OS environment.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The authentication process is extracted from the vulnerable operating system environment and placed into an isolated, trusted execution environment. By taking out the authentication functionality from the OS, the system eliminates the attack surface that key logger malware would otherwise exploit.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10325105B2Single-chip virtualizing and obfuscating storage system for portable computing devices
Publication Date: 2019.06.18 GREEN HILLS SOFTWARE LLC
  • US10325105B2 patent drawing
  • US10325105B2 patent drawing
  • US10325105B2 patent drawing

AI summary

In certain embodiments, an information obfuscation service may be incorporated directly into the main applications processor of a portable computing device such that the applications processor and its relevant storage peripherals may be securely shared via a virtualization firmware module, avoiding the use of specialized hardware or major modifications of the operating system. The virtualizing and obfuscating storage firmware module may enable a much higher level of assurance in information-at-rest protection while using only the memory protection and privilege mode facilities inherent in common portable device applications microprocessors. The virtualizing and obfuscating storage firmware may interpose storage accesses originating from the operating system. This interposition may be performed seamlessly, without explicit knowledge of the operating system.