Virtualizing Storage Firmware for Portable Device Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Portable computing devices, such as smartphones and tablets, face vulnerabilities in their operating systems that can allow malware to access and defeat storage encryption, making existing information-at-rest protection methods ineffective against data theft.
Innovation Solution
A virtualizing and obfuscating storage firmware module is integrated into the main applications processor of portable devices, intercepting storage access requests to obfuscate data without relying on specialized hardware, using memory protection and privilege mode facilities to provide a higher level of assurance in data protection, while keeping authentication and encryption processes isolated from the main operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If storage encryption is incorporated into the portable device operating system, then storage encryption functionality is provided, but the system becomes vulnerable to malware and hackers who can obtain root access and defeat the encryption layer
Solution Approach 1:
The system separates the encryption functionality into a distinct, isolated component that operates independently from the main operating system. This segmentation ensures that even if the OS is compromised, the encryption module remains secure and cannot be accessed by malware with root access.
Solution Approach 2:
An intermediary layer is introduced between the operating system and the storage device. This intermediary handles all encryption/decryption operations and acts as a protected buffer, preventing direct access to encrypted data by the OS or any applications running on it.
2Reliability
If self-encrypting drives are used in laptops, then hardware-based isolation of cryptographic functions is provided, but specialized hardware is required which is not amenable to solid-state storage systems in smartphones and tablets
Solution Approach 1:
The patent replaces specialized hardware-based encryption (SEDs) with a software-based encryption system that runs in an isolated environment within the processor. This substitution allows the same cryptographic isolation benefits to be achieved without requiring specialized hardware, making it compatible with standard solid-state storage systems in smartphones and tablets.
Solution Approach 2:
The encryption system is designed to work with any standard solid-state storage device without requiring specialized hardware. The universal software-based approach can be deployed across different device types and storage technologies, providing both cryptographic isolation and broad hardware compatibility.
3Ease of operation
If authentication processes execute on the platform operating system, then user authentication is enabled, but key logger malware can steal the user's passphrase and allow attackers to access sensitive data
Solution Approach 1:
An intermediary authentication layer is introduced that handles passphrase input and verification in an isolated environment. This intermediary captures authentication credentials before they can be intercepted by malware in the operating system, and verifies them without exposing the actual passphrase to the vulnerable OS environment.
Solution Approach 2:
The authentication process is extracted from the vulnerable operating system environment and placed into an isolated, trusted execution environment. By taking out the authentication functionality from the OS, the system eliminates the attack surface that key logger malware would otherwise exploit.
Data Source
AI summary
In certain embodiments, an information obfuscation service may be incorporated directly into the main applications processor of a portable computing device such that the applications processor and its relevant storage peripherals may be securely shared via a virtualization firmware module, avoiding the use of specialized hardware or major modifications of the operating system. The virtualizing and obfuscating storage firmware module may enable a much higher level of assurance in information-at-rest protection while using only the memory protection and privilege mode facilities inherent in common portable device applications microprocessors. The virtualizing and obfuscating storage firmware may interpose storage accesses originating from the operating system. This interposition may be performed seamlessly, without explicit knowledge of the operating system.


