Data protecting method and computing apparatus
Claim Score by NHIP
Abstract
A data protecting method, including the steps of: (a) upon receipt of a triggering command, configuring a hardware control module to store data in a hidden zone that is unidentifiable, unreadable and unwritable by an operating system block in communication with the hardware control module; and (b) upon receipt of a restore request command from an input device in direct communication with the hardware control module, configuring the hardware control module to execute the restore request command so as to transfer the data from the hidden zone to a working zone that is identifiable, readable and writable by the operating system block when a predetermined condition is satisfied.

Term
Projected expiry 19 November 2029.
- Priority
- Filed
- Published
- Today
- Projected expiry
16 claims: 2 independent, 14 dependent
- 1A data protecting method, comprising the steps of:(a) upon receipt of a triggering command, configuring a hardware control module to store data in a hidden zone that is unidentifiable, unreadable and unwritable by an operating system block in communication with the hardware control module;and (b) upon receipt of a restore request command from an input device indirect communication with the hardware control module, configuring the hardware control module to execute the restore request command so as to transfer the data from the hidden zone to a working zone that is identifiable, readable and writable by the operating system block when a predetermined condition is satisfied.
- 10Broadest claimClaim Score 68, broad(NHIP)A computing apparatus comprising:an operating system block;a data storage device including a hidden zone that is unidentifiable, unreadable and unwritable by said operating system block, and a working zone that is identifiable, readable and writable by said operating system block;and a hardware control module in communication with said operating system block, and responsive to a triggering command for storing data in said hidden zone of said data storage device;wherein said hardware control module is further responsive to a restore request command from an input device for executing the restore request command so as to transfer the data from said hidden zone to said working zone when it is determined by said hardware control module that a predetermined condition is satisfied.
Independent claims2
59 paragraphs in 5 sections, as filed
CROSS-REFERENCE TO RELATED APPLICATION
0001This application claims priority of Taiwanese Application No. 097146246, filed on Nov. 28, 2008.
BACKGROUND OF THE INVENTION
00021. Field of the Invention
0003The invention relates to a protecting method and an apparatus, more particularly to a data protecting method and a computing apparatus for implementing the same.
00042. Description of the Related Art
0005With the wide use of computing technology in everyday life, many people have experienced abnormal shutdown of operating systems, computer crashes, or have accidentally deleted or formatted important data, etc. Moreover, the advent of the Internet provides a spreading tool for computer viruses, which may result in data damages or destruction, sometimes causing unrecoverable losses.
0006Currently, two main ways of protecting data are as follows.
0007(1) Using a key to guard data access: For important data, such as personal information, a key is used to prevent unauthorized access thereto. However, this does not protect the data from damages or destructions due to computer viruses or other human factors and accidents.
0008(2) Using a recovery card: The recovery card provides an opportunity to recover data lost from computer virus infections, file deletion, or formatting a hard drive. However, a control program installed in an operating system is required to recover data in the hard drive. In other words, backup and recovery of the data are conducted by the control program. Therefore, when the operating system is corrupted by malicious software, operation of the control program may be interfered, such that the backup data may be tampered with, and even destroyed, leaving the computer vulnerable to unknown risks.
0009Consequently, how to effectively protect data from being tampered with or destroyed by computer viruses and malicious software is a goal that those in the computer field are striving to achieve.
SUMMARY OF THE INVENTION
0010Therefore, the object of the present invention is to provide a data protecting method that uses a hardware module to perform the backup of data and the recovery of operating systems.
0011According to one aspect of the present invention, there is provided a data protecting method that includes the steps of: (a) upon receipt of a triggering command, configuring a hardware control module to store data in a hidden zone that is unidentifiable, unreadable and unwritable by an operating system block in communication with the hardware control module; and (b) upon receipt of a restore request command from an input device in direct communication with the hardware control module, configuring the hardware control module to execute the restore request command so as to transfer the data from the hidden zone to a working zone that is identifiable, readable and writable by the operating system block when a predetermined condition is satisfied.
0012According to another aspect of the present invention, there is provided a computing apparatus that includes an operating system block, a data storage device, and a hardware control module. The data storage device includes a hidden zone that is unidentifiable, unreadable and unwritable by the operating system block, and a working zone that is identifiable, readable and writable by the operating system block. The hardware control module is in communication with the operating system block, and is responsive to a triggering command for storing data in the hidden zone of the data storage device. The hardware control module is further responsive to a restore request command from an input device for executing the restore request command so as to transfer the data from the hidden zone to the working zone when it is determined by the hardware control module that a predetermined condition is satisfied.
BRIEF DESCRIPTION OF THE DRAWINGS
0013Other features and advantages of the present invention will become apparent in the following detailed description of the preferred embodiments with reference to the accompanying drawings, of which:
0014<figref idrefs="DRAWINGS">FIG. 1</figref> is a block diagram of a computing apparatus according to the first and second preferred embodiments of the present invention;
0015<figref idrefs="DRAWINGS">FIG. 2</figref> is a flow chart, illustrating a data protecting method according to the first preferred embodiment of the present invention; and
0016<figref idrefs="DRAWINGS">FIG. 3A</figref> and <figref idrefs="DRAWINGS">FIG. 3B</figref> are flow charts, illustrating a data protecting method according to the second preferred embodiment of the present invention.
DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
0017Before the present invention is described in greater detail, it should be noted that like elements are denoted by the same reference numerals throughout the disclosure.
0018Referring to <figref idrefs="DRAWINGS">FIG. 1</figref>, according to the first and second preferred embodiments of the present invention, a computing apparatus includes an operating system block <b>4</b>, a data storage device <b>3</b>, and a hardware control module <b>1</b>.
0019The data storage device <b>3</b> includes a hidden zone <b>31</b> that is unidentifiable, unreadable and unwritable by the operating system block <b>4</b>, and a working zone <b>32</b> that is identifiable, readable and writable by the operating system block <b>4</b>. The data storage device <b>3</b> may be one of a hard drive, a flash memory, a solid state disk (SSD), or any other devices permitting storage of data.
0020The hardware control module <b>1</b> is in communication with the operating system block <b>4</b>, and is responsive to a triggering command for storing data in the hidden zone <b>31</b> of the data storage device <b>3</b>.
0021The hardware control module <b>1</b> is further responsive to a restore request command <b>22</b> from an input device <b>2</b> for executing the restore request command <b>22</b> so as to transfer the data from the hidden zone <b>31</b> to the working zone <b>32</b> when it is determined by the hardware control module <b>1</b> that a predetermined condition is satisfied. The input device <b>2</b> may be one of a keyboard, a mouse, a touch pad, or any other devices permitting input of information.
0022In particular, upon receipt of the restore request command <b>22</b>, the hardware control module <b>1</b> is configured to generate a key confirming request <b>131</b> to be displayed on a display device <b>5</b> (e.g., a liquid crystal display (LCD)) via the operating system block <b>4</b> to prompt a user for a key input <b>23</b>. Upon receipt of the key input <b>23</b>, the hardware control module <b>1</b> is configured to determine if the key input <b>23</b> matches a predefined key. When it is determined that the key input <b>23</b> matches the predefined key, the hardware control module <b>1</b> is configured to execute the restore request command <b>22</b> so as to transfer the data from the hidden zone <b>31</b> to the working zone <b>32</b>.
0023In particular, the hardware control module <b>1</b> includes a control unit <b>13</b>, a key verification unit <b>12</b>, and a firmware unit <b>11</b>. The control unit <b>13</b> is adapted to be coupled to the input device <b>2</b> for receiving the restore request command <b>22</b> therefrom, is coupled to the operating system block <b>4</b>, and generates the key confirming request <b>131</b> to be displayed on the display device <b>5</b> via the operating system block <b>4</b> upon receipt of the restore request command <b>22</b> to prompt the user for the key input <b>23</b>. The key verification unit <b>12</b> is coupled to the control unit <b>13</b>, determines, upon receipt of the key input <b>23</b> by the user, if the key input <b>23</b> matches a predefined key, and transmits a comparison result to the control unit <b>13</b>. The firmware unit <b>11</b> is coupled to the control unit <b>13</b> and the data storage device <b>3</b>.
0024When the key verification unit <b>12</b> determines that the key input <b>23</b> matches the predefined key, the key verification unit <b>12</b> is configured to transmit a key verification success message <b>122</b> to the control unit <b>13</b>, and the control unit <b>13</b> executes the restore request command <b>22</b> by controlling the firmware unit <b>11</b> to transfer the data from the hidden zone <b>31</b> to the working zone <b>32</b> upon receipt of the restore request command <b>22</b> from the input device <b>2</b>.
0025When the key verification unit <b>12</b> determines that the key input <b>23</b> does not match the predefined key, the key verification unit <b>12</b> is configured to transmit a key verification failure message <b>121</b> to the control unit <b>13</b>, and the control unit <b>13</b> is configured to refuse to execute the restore request command <b>22</b> upon receipt of the key verification failure message <b>121</b>.
0026It should be noted herein that, in practice, upon receipt of the restore request command <b>22</b>, the control unit <b>13</b> may generate a list of at least one restore point for selection by the user, where each restore point corresponds to a point in time where the data is stored in the hidden zone <b>31</b>. The data corresponding to a selected restore point is transferred from the hidden zone <b>31</b> to the working zone <b>32</b> when it is determined that the key input <b>23</b> matches the predefined key. Such variations should be readily apparent to those skilled in the art, and the disclosure herein should not be taken to limit the scope of the present invention.
0027According to the first preferred embodiment, upon receipt of the triggering command, the control unit <b>13</b> controls the firmware unit <b>11</b> to store data in the hidden zone <b>31</b> of the data storage device <b>3</b>.
0028According to the second preferred embodiment, the triggering command is a data hiding backup command <b>21</b> received from the input device <b>2</b>. Upon receipt of the data hiding backup command <b>21</b>, the control unit <b>13</b> generates the key confirming request <b>131</b> to be displayed on the display device <b>5</b> via the operating system block <b>4</b> to prompt the user for the key input <b>23</b>. Upon receipt of the key input <b>23</b> by the user, the key verification unit <b>12</b> determines if the key input <b>23</b> matches the predefined key.
0029When it is determined by the key verification unit <b>12</b> that the key input <b>23</b> matches the predefined key, the key verification unit <b>12</b> is configured to transmit a key verification success message <b>122</b> to the control unit <b>13</b>, and the hardware control module <b>1</b> is configured to execute the data hiding backup command <b>21</b>, where the control unit <b>13</b> controls the firmware unit <b>11</b> so as to store data in the hidden zone <b>31</b> of the data storage device <b>3</b>.
0030When the key verification unit <b>12</b> determines that the key input <b>23</b> does not match the predefined key, the key verification unit <b>12</b> is configured to transmit a key verification failure message <b>121</b> to the control unit <b>13</b>, and the control unit <b>13</b> is configured to refuse to execute the data hiding backup command <b>21</b> upon receipt of the key verification failure message <b>121</b>.
0031It should be noted herein that in the second preferred embodiment, the data hiding backup command <b>21</b> is provided manually by the user via the input device <b>2</b>. However, in practice, the data hiding backup command <b>21</b> may be generated automatically once the computing apparatus is turned on to operate, or once every predetermined period of time (e.g., 10 minutes) during operation of the computing apparatus so as to backup system data. Such variations should be readily apparent to those skilled in the art, and the disclosure herein should not be taken to limit the scope of the present invention.
0032It should be further noted herein that the key input <b>23</b> provided by the user is provided only to the hardware control module <b>1</b>, that key comparison is performed by the key verification unit <b>12</b> of the hardware control module <b>1</b>, and that only the comparison result (match or does not match) is provided to the operating system block <b>4</b>. Consequently, even if the operating system block <b>4</b> is attacked by a malicious software, the key necessary for performing data backup or system restore will not be stolen, tampered, or destroyed by the malicious software.
0033With further reference to <figref idrefs="DRAWINGS">FIG.2</figref>, the data protecting method according to the first preferred embodiment of the present invention includes the following steps.
0034In step <b>60</b>, upon receipt of the data hiding backup command <b>21</b>, the control unit <b>13</b> is configured to control the firmware unit <b>11</b> to store data in the hidden zone <b>31</b> that is unidentifiable, unreadable and unwritable by the operating system block <b>4</b>.
0035In step <b>61</b>, upon receipt of the restore request command <b>22</b> from the input device <b>2</b>, the control unit <b>13</b> is configured to generate the key confirming request <b>131</b> to be displayed on the display device <b>5</b> to prompt the user for the key input <b>23</b>.
0036In this embodiment, the control unit <b>13</b> is configured to transmit the key confirming request <b>131</b> to a monitoring bridge program <b>41</b> installed in the operating system block <b>4</b> for displaying the key confirming request <b>131</b> on the display device <b>5</b>. The monitoring bridge program <b>41</b> has the ability of assisting communication between the hardware control module <b>1</b> and the operating system block <b>4</b>, thereby aiding in the storage of the data in the hidden zone <b>31</b> so as to protect the data from a possibly corrupted operating system block <b>4</b>, and in the restoration of the operating system block <b>4</b> using the data that has been transferred from the hidden zone <b>31</b> into the working zone <b>32</b> when such a restoration is required by the user.
0037In step <b>62</b>, upon receipt of the key input <b>23</b>, the key verification unit <b>12</b> is configured to determine if the predetermined condition is satisfied by determining whether the key input <b>23</b> matches the predefined key.
0038When it is determined in step <b>62</b> that the key input <b>23</b> matches the predefined key, the flow goes to step <b>63</b>, where the key verification unit <b>12</b> is configured to transmit the key verification success message <b>122</b> to the control unit <b>13</b>.
0039In step <b>64</b>, the control unit <b>13</b> is configured to execute the restore request command <b>22</b> by controlling the firmware unit <b>11</b> so as to transfer the data from the hidden zone <b>31</b> to the working zone <b>32</b>.
0040In step <b>65</b>, the control unit <b>13</b> of the hardware control module <b>1</b> is configured to use the data to restore the operating system block <b>4</b>.
0041It should be noted herein that there may be a step <b>68</b> in between steps <b>64</b> and <b>65</b>, where the control unit <b>13</b> is configured to generate the list of at least one restore point for selection by the user, and later on in step <b>65</b>, the operating system block <b>4</b> is restored using the data corresponding to the selected restore point. Each restore point corresponds to a point in time where the data hiding backup command <b>21</b> is executed.
0042When it is determined in step <b>62</b> that the key input does not match the predefined key, the flow goes to step <b>66</b>, wherein the key verification unit <b>12</b> is configured to transmit the key verification failure message <b>122</b> to the control unit <b>13</b>.
0043In step <b>67</b>, the control unit <b>13</b> is configured to refuse to execute the restore request command <b>22</b>.
0044A practical operational application is presented hereinbelow with reference to <figref idrefs="DRAWINGS">FIG. 1</figref> to better illustrate the first preferred embodiment of the present invention.
0045First, when a user wishes to transfer data from the working zone <b>32</b> to the hidden zone <b>31</b> in order to prevent the data from being corrupted by computer viruses, malicious software, or due to other factors, the user inputs the data hiding backup command <b>21</b> into the control unit <b>13</b> of the hardware control module <b>1</b> via the input device <b>2</b>.
0046Subsequently, upon receipt of the data hiding backup command <b>21</b>, the control unit <b>13</b> controls the firmware unit <b>11</b> to store the data in the hidden zone <b>31</b> that is unidentifiable, unreadable and unwritable by the operating system block <b>4</b>.
0047Next, when the user wishes to perform restoration on the operation system block <b>4</b>, the user inputs the restore request command <b>22</b> into the control unit <b>13</b> of the hardware control module <b>1</b> via the input device <b>2</b>.
0048Then, the control unit <b>13</b> generates the key confirming request <b>131</b> to be displayed on the display device <b>5</b> to prompt the user for the key input. After the user inputs the key input using the input device <b>2</b>, the key verification unit <b>12</b> compares the key input with the predefined key, and informs the control unit <b>13</b> of the verification result by selectively transmitting the key verification success message <b>122</b> or the key verification failure message <b>121</b> to the control unit <b>13</b>.
0049If the verification result shows that the key matches the predefined key, the control unit <b>13</b> executes the restore request command <b>22</b> by controlling the firmware unit <b>11</b> to transfer the data from the hidden zone <b>31</b> to the working zone <b>32</b>, and cooperates with the operating system block <b>4</b> to perform the restoration operation using the data.
0050With reference to <figref idrefs="DRAWINGS">FIG. 1</figref>, <figref idrefs="DRAWINGS">FIG. 3A</figref> and <figref idrefs="DRAWINGS">FIG. 3</figref><i>b, </i>the data protecting method according to the second preferred embodiment of the present invention is similar to the first preferred embodiment. The only difference between the first and second preferred embodiments is that according to the second preferred embodiment, the data hiding backup command <b>21</b> is only executed by the hardware control module <b>1</b> when the predefined condition identical to that for the restore request command <b>22</b> is satisfied. In other words, step <b>60</b>′ of the second preferred embodiment includes the following sub-steps.
0051In sub-step <b>601</b>′, upon receipt of the data hiding backup command <b>21</b>, the control unit <b>13</b> is configured to generate the key confirming request <b>131</b> to be displayed on the display device <b>5</b> to prompt the user for the key input <b>23</b>.
0052In sub-step <b>602</b>′, upon receipt of the key input <b>23</b>, the key verification unit <b>12</b> is configured to determine if the predetermined condition is satisfied by determining whether the key input <b>23</b> matches the predefined key.
0053When it is determined in sub-step <b>602</b>′ that the key input <b>23</b> matches the predefined key, the flow goes to sub-step <b>603</b>′, where the key verification unit <b>12</b> is configured to transmit the key verification success message <b>122</b> to the control unit <b>13</b>.
0054In sub-step <b>604</b>′, the control unit <b>13</b> is configured to execute the data hiding backup command <b>21</b> by controlling the firmware unit <b>11</b> so as to store the data in the hidden zone <b>31</b>.
0055When it is determined in sub-step <b>602</b>′ that the key input does not match the predefined key, the flow goes to sub-step <b>605</b>′, wherein the key verification unit <b>12</b> is configured to transmit the key verification failure message <b>122</b> to the control unit <b>13</b>.
0056In sub-step <b>606</b>′, the control unit <b>13</b> is configured to refuse to execute the data hiding backup command <b>21</b>.
0057It should be noted herein that the data stored in the hidden zone <b>31</b> is not limited to a normal file format data, but can also be a record of at least an operating command inputted from the input device <b>2</b>, such as a selection or key-in command from a keyboard or a series of operation commands from a mouse. Therefore, correspondingly, when the data backed up in the hidden zone <b>31</b> records the operating command inputted from the input device <b>2</b>, after the restore request command <b>22</b> is executed by the hardware control module <b>1</b> such that the data is transferred into the working zone <b>32</b>, the operating system block <b>4</b> is restored back to a state immediately before executing the recorded operating command by undoing the recorded operating command. Moreover, in one such circumstance, the restoration of the operating system block <b>4</b> may be presented in a form of images, such as visually going back a trace of the series of operation commands from the mouse on the display device <b>5</b>.
0058In sum, the data protecting method and the computing apparatus of the present invention achieve the object of preventing data from being tampered with due to computer virus infection or the presence of a malicious software by ensuring that the transfer of the data from the hidden zone <b>31</b> to the working zone <b>32</b> of the storage device <b>3</b> is guarded by the hardware control module <b>1</b> with the predefined key, where the restore request command <b>22</b> (or even the data hiding backup command <b>21</b>) is only verified when the key inputted by the user matches the predefined key, that the key inputted by the user is only accessible by the hardware control module <b>1</b>, where key verification is performed by the key verification unit <b>12</b> of the hardware control module <b>1</b>, and that only the verification result (match or does not match) is provided to the operating system block <b>4</b>. Consequently, even if the operating system block <b>4</b> is attacked by a malicious software, the data stored in the hidden zone <b>31</b> necessary for performing certain functions (such as restoring the operating system block <b>4</b>) will not be damaged or tampered with by the malicious software.
0059While the present invention has been described in connection with what are considered the most practical and preferred embodiments, it is understood that this invention is not limited to the disclosed embodiments but is intended to cover various arrangements included within the spirit and scope of the broadest interpretation so as to encompass all such modifications and equivalent arrangements.
Contents5
5 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10216449B1 | Cited by | United States of America | Search report |
| CN104732166A | Cited by | China | Search report |
| US2015180655A1 | Cited by | United States of America | Pre-grant |
| TWI641958B | Cited by | Taiwan Province of China | Examiner |
| US2002116632A1 | Cites | United States of America | Pre-grant |
| US2004143765A1 | Cites | United States of America | Pre-grant |
| US2006200639A1 | Cites | United States of America | Pre-grant |
| US2006294298A1 | Cites | United States of America | Pre-grant |
| US2007180535A1 | Cites | United States of America | Pre-grant |
| US2008046781A1 | Cites | United States of America | Pre-grant |
| US2008046997A1 | Cites | United States of America | Pre-grant |
| US2009046858A1 | Cites | United States of America | Pre-grant |
| US2010077465A1 | Cites | United States of America | Pre-grant |
| US2010107248A1 | Cites | United States of America | Pre-grant |
| US2011252243A1 | Cites | United States of America | Pre-grant |
| US5586301A | Cites | United States of America | Pre-grant |
| US6792517B1 | Cites | United States of America | Pre-grant |
| US7941405B2 | Cites | United States of America | Pre-grant |
10 members in 7 offices
Priority claims4
| Document | Office | Kind | Date |
|---|---|---|---|
| 97146246 | Taiwan Province of China | A | |
| 97146246 | Taiwan Province of China | A | |
| 097146246 | – | – | – |
| TW20080146246 | – | – | – |
Members10
| Document | Office | Kind | |
|---|---|---|---|
| TW201020778A | Taiwan Province of China | A | |
| US2010138932A1 | United States of America | A1 | |
| KR20100061351A | Republic of Korea | A | |
| EP2194479A1 | European Patent Office (EPO) | A1 | |
| JP2010129095A | Japan | A | |
| AU2009233652A1 | Australia | A1 | |
| BRPI0904495A2 | Brazil | A2 | |
| JP2012238331A | Japan | A | |
| TWI409634B | Taiwan Province of China | B | |
| JP5319830B2 | Japan | B2 |
1 legal event, as the office reported them to INPADOC
Events
| Event | Code | |
|---|---|---|
| Information on status: application discontinuationABANDONED -- FAILURE TO RESPOND TO AN OFFICE ACTIONSTCB | STCB |
Numbers
- Publication
- 20100138932
- Publication, DOCDB
- 2010138932
- Publication, EPODOC
- US2010138932
- Application
- 12621583
- Application, DOCDB
- 62158309
- Application, EPODOC
- US20090621583
Titles
- English
- DATA PROTECTING METHOD AND COMPUTING APPARATUS
Classification
- CPC, 7
- G06F21/57
- G06F9/06
- G06F11/1446
- G06F21/74
- G06F21/78
- G06F21/80
- G06F2221/2105
- IPC, 1
- G06F21 24
- USPC, 1
- 726028000