How to respond safely to violations of security policies
The method addresses the challenge of securely responding to security policy violations by authenticating security agents and applications, monitoring resource access, and performing defined actions, thereby enhancing security and reducing vulnerabilities.
Patent Information
- Application Number
- JP2024560835
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-04-19
- Filing Date
- 2023-04-19
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2043-04-19
AI Technical Summary
Existing computer security systems lack effective methods for securely responding to violations of security policies, leading to potential security breaches and vulnerabilities.
A method that involves authenticating security agents and applications with security devices based on identity information, monitoring resource access, and performing predefined actions in response to policy violations, thereby ensuring secure state transitions.
The solution effectively reduces security vulnerabilities by ensuring that only authorized applications access resources, and by promptly responding to policy violations to prevent potential security incidents.
Smart Images

Figure 2025514707000001_ABST
Abstract
Description
[Technical field]
[0001] The present invention relates generally to the field of computer security, and more particularly to a novel and useful method for securely responding to violations of security policies in the field of computer security.
[0002] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims the benefit of U.S. Provisional Application No. 63 / 332,680, filed April 19, 2022, which is incorporated by reference in its entirety.
[0003] This application is related to U.S. patent application Ser. No. 16 / 937,299, filed July 23, 2020, U.S. patent application Ser. No. 17 / 856,661, filed July 1, 2022, and U.S. patent application Ser. No. 18 / 081,833, filed December 15, 2022, each of which is incorporated by reference in its entirety. [Brief description of the drawings]
[0004] [Figure 1] FIG. 1 is a flow chart diagram of the method. [Diagram 2] FIG. 2 is a flow chart diagram of one embodiment of the present method. [Diagram 3] FIG. 3 is a flow chart diagram of one embodiment of the present method. [Figure 4] FIG. 4 is a flow chart diagram of one embodiment of the present method. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0005] The following description of the embodiments of the present invention is not intended to limit the invention to those embodiments, but is intended to enable those skilled in the art to make and use the present invention. The aspects, configurations, embodiments, exemplary aspects, and examples described herein are optional and are not limited to the aspects, configurations, embodiments, exemplary aspects, and examples described therein. The invention described herein may include any combination of those aspects, configurations, embodiments, exemplary aspects, and examples.
[0006] 1. Method 1 and 2, method S100 includes, in a security agent executing on a computing platform including a set of resources, an operating system, and a first application, authenticating the security agent with a security device during a first time period based on first identity information associated with the security agent, the first identity information being stored on the security device, at block S110, and accessing a configuration profile from the security device in response to authenticating the security agent, at block S112. The first configuration profile may define second identity information associated with the operating system, third identity information associated with the first application, and a first security policy, which may define a subset of resources in the set of resources that the first application is permitted to access, and a first action responsive to a first violation of the first security policy.
[0007] The method S100 further includes, at block S116, authenticating the operating system based on the second identity information, and, at block S120, authenticating the first application based on the third identity information.
[0008] Method S100 further includes, during a second period following the first period, monitoring, at block S130, a set of resources corresponding to execution of a first application on the computing platform, and performing, at block S136, a first action in response to detecting access by the first application to a first resource in the set of resources, where the first resource is excluded from the subset of resources.
[0009] 1.1 Variation: Network Communication Channel Access Violation As shown in Figures 1 and 2, one variation of method S100 includes, during a first period, at a security device including a first set of resources including a hardware security module, authenticating the first set of resources based on first identity information associated with the first set of resources in block S104, where the first identity information is stored in the hardware security module, and authenticating a configuration profile based on the first identity information in block S108, where the configuration profile is associated with a computing platform communicatively connected to the security device and includes a second set of resources, an operating system and a first application.
[0010] A variation of this method S100 further includes authenticating, with a security agent executing on the computing platform during a second time period subsequent to the first time period, the security agent with the security device based on second identity information associated with the security agent, the second identity information being indicated in a configuration profile, in block S110, and accessing the configuration profile from the security device in response to authenticating the security agent, in block S112. The configuration profile may define third identity information associated with the operating system, fourth identity information associated with the first application, and a first security policy, which may define a subset of network communication channels in the set of network communication channels that the first application is authorized to access, and a first action responsive to a first violation of the first security policy.
[0011] A variation of this method S100 further includes authenticating the operating system based on the third identity information, at block S116, and authenticating the first application based on the fourth identity information, at block S120.
[0012] A variation of this method S100 further includes, during a third period following the second period, monitoring, at the security agent, at block S130, a second set of resources corresponding to execution of the first application on the computing platform, and performing, at block S136, a first action in response to detecting access by the first application to a first network communication channel in the set of network communication channels, where the first communication channel is excluded from the subset of network communication channels.
[0013] 1.2 Variation: Safe responses to violations of security policy As shown in Figures 1 and 2, one variation of method S100 includes, in a security agent executing on a computing platform including a set of resources and a first application, during a first period, authenticating the security agent with a security device based on first identity information associated with the security agent in block S110, and in response to authenticating the security agent, accessing a configuration profile from the security device in block S112, the configuration profile being generated based on second identity information associated with the security device, the first configuration profile defining third identity information associated with the first application and a first security policy, the first security policy defining a subset of resources in the set of resources that the first application is authorized to access, and authenticating the first application based on the third identity information in block S120.
[0014] A variation of this method S100 further includes, during a second period following the first period, monitoring, in block S130, a set of resources corresponding to execution of a first application on the computing platform, and, in block S148, issuing a command to transition the computing platform to a secure state in response to detecting access by the first application to a first resource in the set of resources, where the first resource is excluded from the subset of resources.
[0015] 2. Application In general, the blocks of method S100 may be executed by a computer system (hereinafter the "system") to associate a computing platform (e.g., a machine, a robot, a vehicle) with a security device capable of performing functionally secure operations, and to instantiate a security agent (on the computing platform) that cooperates with the security device to manage security and safety on the computing platform.
[0016] More specifically, the blocks of method S100 can be executed by the system to authenticate the security device based on pre-provisioned information stored on the security device, access a configuration profile defining identity information associated with a set of security agents, operating systems and applications to be executed on the computing platform, authenticate the configuration profile based on the pre-provisioned information, and authenticate the set of security agents, operating systems and applications (based on the identity information) prior to execution on the computing platform.
[0017] Thus, the blocks of method S100 can be executed by the system to verify that the configuration profile corresponds to the computing platform and security device, thereby enabling the system to verify that the set of security agents, operating systems and applications running on the computing platform are authentic, unaltered and authorized on the computing platform based on the configuration profile.
[0018] 2.1 Violation of security policy and response Additionally, the blocks of method S100, when executed by the system, establish a chain of trust (starting at the security device) that extends through the security agent to the operating system and set of applications, thereby enabling the security agent and security device to perform security and / or secure actions associated with the computing platform.
[0019] Additionally, the blocks of method S100 may be executed by the system to access a configuration profile that defines a security policy associated with the application, monitor execution of the application on the computing platform, and, in response to detecting a violation of the security policy, perform an action, such as issuing a command to transition the computing platform to a predefined state (e.g., a secure state).
[0020] Thus, by combining a computing platform (which does not meet functional safety standards and does not include security features) with a security device, the system can extend the functional safety and security features of the security device to the computing platform via the security agent, thereby mitigating security vulnerabilities that may lead to operational downtime, theft of intellectual property, destruction of work product, personal injury and / or death due to attempted or successful intrusion.
[0021] 2.2 Working Example In one exemplary application, the blocks of method S100 are executed by a system including a first robot (in a set of robots operating in a work zone) and a first security device mounted on the first robot to authenticate the first security device based on encryption information pre-provided in a hardware security module of the first security device, access a configuration profile defining identity information associated with a security agent, an operating system, and an object detection application executed by the first robot, authenticate the configuration profile based on the encryption information, and initialize a security agent on the first robot.
[0022] In this example, blocks of method S100 are executed by a security agent on a first robot to authenticate with a first security device, access a configuration profile, and authenticate the operating system and object detection application based on identity information defined in the configuration profile.
[0023] Additionally, blocks of method S100 are executed by a security agent on the first robot to access a configuration profile (associated with the object detection application) that further defines a security policy that defines a subset of memory addresses that the object detection application is permitted to access, and to monitor execution of the object detection application. In response to detecting an access (by the object detection application) to a memory address that is excluded from the subset of memory addresses, the security agent issues a command to the first security device to transition the first robot to a secure state. The first security device then sends a signal to an emergency stop device (coupled to the first robot) to transition the first robot to a secure state.
[0024] Thus, the blocks of method S100 are executed by the first robot and the first security device to verify and monitor execution of the object detection application on the first robot, and in response to detecting unexpected execution behavior of the object detection application (which may be indicative of a cyber attack), transition the first robot to a safe state. Thus, the system enables each robot (in a set of robots) to detect security breaches and trigger safety-critical responses locally, thereby preventing or mitigating damage to work products, personal injury, and / or fatalities in the set of robots or work area.
[0025] 2.2 Violation of Operating System Security Policies and Responses Method S100 as described herein is performed by a security agent executing on a computing platform to monitor the execution of applications on the computing platform and to take action in response to detecting a violation of a security policy associated with the application. However, the security agent may also perform the blocks of method S100 to monitor the execution of an operating system on the computing platform and to take action in response to detecting a violation of a security policy associated with the operating system.
[0026] 3. Terminology In general, a "private key" as referred to herein is a key associated with a particular entity (eg, controller, device) in a collection of devices, and known only to that particular entity and the key server.
[0027] Generally, a "symmetric key" as referred to herein is a cryptographic key used for encryption and decryption.
[0028] In general, an "asymmetric key pair" as referred to herein is a pair of cryptographic keys (associated with a particular entity) that includes a public key and a private key.
[0029] 4. System Generally, the system may include a computing platform, a security device communicatively connected to the computing platform, and a management server (e.g., the computing platform), as shown in Figure 1. The computing platform and the security device may be communicatively connected to the management server via a communications network (e.g., a local area network, a wide area network, the Internet).
[0030] Additionally, the system may include user devices (e.g., status indicators, control panels, terminals, mobile devices, smartphones) communicatively connected to the security devices, computing platforms, and / or management servers. In one example, the user devices may be communicatively connected to the security devices and / or computing platforms by a direct communication channel over the communications network. In another example, the user devices may be communicatively connected to the security devices and / or computing platforms through the management servers. In yet another example, the user devices may be connected (e.g., directly connected) to the security devices and / or computing platforms.
[0031] The system may include additional computing platforms and / or security devices communicatively connected to the management server via a communications network. More specifically, the system may include a set of computing platforms and a set of security devices, where each security device (in the set of security devices) corresponds to a computing platform in the set of computing platforms. For example, each security device (in the set of security devices) may be mounted on a corresponding computing platform in the set of computing platforms.
[0032] The system may include additional user devices communicatively connected to one or more security devices, one or more computing platforms and / or a management server.
[0033] 5. Computing Platform Generally, computing platforms may include sensors (e.g., radar sensors, LiDAR sensors, ultrasonic sensors, infrared cameras), machines, robots, vehicles (e.g., autonomous vehicles, semi-autonomous vehicles), control systems, emergency stop systems (e.g., line break sensors, emergency stop buttons), and / or industrial systems (e.g., manufacturing systems, agricultural systems, construction systems, power systems, transportation systems), etc.
[0034] In one embodiment, a computing platform may include a set of resources, such as a set of processors, volatile memory (e.g., random access memory or "RAM"), non-volatile memory (e.g., flash storage), input / output interfaces, a set of network interfaces (e.g., wireless local area network interfaces, wired local area network interfaces, Bluetooth network interfaces), input devices (e.g., sensors, user interfaces), output devices (e.g., motors, actuators, hydraulic arms), etc.
[0035] Additionally, the computing platform may further include (e.g., stored in non-volatile memory) an operating system (or kernel) and a set of applications. The computing platform may utilize a set of resources to execute the operating system and / or the set of applications, such as, for example, an object detection application and a path planning application.
[0036] In another embodiment, the computing platform may include a security agent that cooperates with security devices and / or a management server to manage the security of the computing platform, as described below.
[0037] 5.1 Machine Identity In general, a computing platform may exhibit a machine identity that uniquely identifies the computing platform within a set of computing platforms. For example, a computing platform may exhibit a machine identity based on a serial number that uniquely identifies the computing platform.
[0038] In one implementation, a computing platform may exhibit a machine identity based on a set of hardware specific elements of the computing platform. In one example, a computing platform may exhibit a machine identity based on a unique identifier embedded in a chip (such as a unique identifier for the processor) associated with the computing platform's processor. In another example, a computing platform may exhibit a machine identity based on a network interface hardware address (e.g., a media access controller address or "MAC address") associated with the computing platform's network interface.
[0039] Additionally or alternatively, a computing platform may exhibit a machine identity based on cryptographic information (e.g., private key, symmetric key, asymmetric key pair) that correlates with a set of hardware-specific elements of the computing platform.
[0040] Thus, a particular computing platform (within a set of computing platforms that may be mass-produced in the same build) can be uniquely identified based on its unique machine identity, and the system can ensure that this particular computing platform includes the appropriate firmware, software, configuration information, licenses, and other information that corresponds to that machine identity.
[0041] 6. Security Devices In general, a security device may perform safety-critical diagnostic and control functions. For example, a security device may include hardware and / or software that meets functional safety standards (e.g., IEC 61508, ISO 13849, ISO 26262).
[0042] In one embodiment, the security device may include a safety subsystem configured to perform functionally secure operations, such as outputting commands to transition a corresponding computing platform (or group of computing platforms) to a secure state, input validation, command validation, system health monitoring, communication integrity encapsulation and / or output control, as described in U.S. patent application Ser. No. 16 / 937,299, U.S. patent application Ser. No. 17 / 856,661, and U.S. patent application Ser. No. 18 / 081,833.
[0043] Additionally, the security agent may cooperate with the security device to perform safety-critical diagnostic and control functions (on the computing platform) as well.
[0044] In one embodiment, the security device can cooperate with a security agent executing on the computing platform to authenticate software (e.g., a security agent, an operating system, a set of applications) executing on the computing platform in accordance with a configuration profile associated with the computing platform, monitor the execution of the software on the computing platform, detect violations of a security policy (defined by the configuration profile) based on the execution of the software on the computing platform, and respond to such violations in accordance with actions specified by the security policy.
[0045] Thus, by combining a computing platform (which may not meet functional safety standards and may not include security features) with a security device, the system can extend the functional safety and security features of the security device to the computing platform via the security agent, thereby mitigating security vulnerabilities that may result in operational downtime, theft of intellectual property, destruction of work product, personal injury and / or death due to attempted or successful intrusion.
[0046] 6.1 Security Device Architecture In general, a security device may include a set of resources, such as a set of controllers, volatile memory (e.g., RAM), non-volatile memory (e.g., flash storage), a set of network interfaces (e.g., wireless local area network interfaces, wired local area network interfaces, Bluetooth network interfaces), input / output interfaces, and / or a hardware security module, etc. Additionally, a security device may further include firmware, an operating system (or kernel), a set of applications and / or logic.
[0047] In one embodiment, a security device can include a set of resources, including a first controller (e.g., a first safety controller), a second controller (e.g., a second safety controller), a third controller (e.g., a security controller), and a communication bus. The communication bus can support bidirectional communication between the first controller and the second controller, bidirectional communication between the first controller and the third controller, and bidirectional communication between the second controller and the third controller.
[0048] In one embodiment, the first controller may include an arithmetic logic unit (hereinafter, "ALU"), a volatile memory (e.g., RAM), and a non-volatile memory (e.g., flash storage). The ALU may perform arithmetic and logic operations based on computer instructions executed by the first controller. The RAM may temporarily store data retrieved from the storage to perform the calculations. The flash storage may store data and / or instructions programmed into the first controller. The first controller may further include an input / output interface, an internal bus, and / or an internal oscillator. The first controller may include fewer or additional components.
[0049] The second controller may include the same (e.g., similar, identical) components as the first controller. For example, the first controller and the second controller may be redundant controllers that each include identical components.
[0050] Additionally, the third controller may include similar (e.g., similar, identical) components as the first controller. The third controller may further include a network interface (or set of network interfaces) for communication over a communication network.
[0051] 6.2 Security Device Identity In general, a security device can exhibit a machine identity that uniquely identifies the security device within a set of security devices, for example, a security device can exhibit a machine identity based on a serial number that uniquely identifies the security device.
[0052] In one implementation, a security device can indicate a machine identity based on a set of hardware-specific elements of the security device. In one example, a computing platform can indicate a machine identity based on a unique identifier embedded in a chip of the security platform, such as a unique identifier associated with a controller of the security device and / or a unique identifier associated with a hardware security module. In another example, a security device can indicate a machine identity based on a network interface hardware address (e.g., a MAC address) associated with a network interface of the security device.
[0053] Thus, a particular security device (within a set of security devices) can be uniquely identified based on this unique machine identity, and thus the system can ensure that this particular security device contains the appropriate firmware, software, configuration information, licenses, and other information that corresponds to that machine identity.
[0054] 6.3 Hardware Security Module In general, a security device may include identity information associated with the security device and with a computing platform. The security device may utilize the identity information to authenticate elements (e.g., hardware, software) of the security device and / or the computing platform.
[0055] In one embodiment, a security device may store identity information including cryptographic information such as private keys, symmetric keys, asymmetric key pairs for device identification, and / or asymmetric key pairs for communications.
[0056] In another embodiment, a security device may store identity information including the machine identity of the security device and / or the machine identity of a computing platform (eg, the machine identity of the computing platform corresponding to the security device).
[0057] In another embodiment, a security device can store identity information associated with a first set of resources included in the security device. More specifically, the security device can store identity information including cryptographic information that correlates with a set of hardware specific elements of the security device. For example, the security device can store identity information including cryptographic information that correlates with a unique identifier embedded in a chip of the security device (e.g., a unique identifier associated with a controller of the security device, a unique identifier associated with a hardware security module) and / or a network interface hardware address (e.g., a MAC address) associated with a network interface of the security device.
[0058] In one embodiment, a security device may store identity information associated with the firmware, operating system (or kernel), set of applications, and / or logic of the security device. In one example, a security device may store identity information including an identifier (e.g., unique identifier, version number) for each application and / or logic in the firmware, operating system, set of applications. In another example, a security device may store identity information including cryptographic information (e.g., private key, asymmetric key pair) that correlates with the identifier.
[0059] In another embodiment, the security device can store identity information associated with a second set of resources included in the computing platform. More specifically, the security device can store identity information including cryptographic information that correlates with a set of hardware specific elements of the computing platform. For example, the security device can store identity information including cryptographic information that correlates with a unique identifier embedded in a chip of the computing platform (e.g., a unique identifier associated with a processor of the computing platform) and / or a network interface hardware address (e.g., a MAC address) associated with a network interface of the computing platform.
[0060] In one embodiment, a security device may store identity information within a hardware security module of the security device. More specifically, the hardware security module may provision (or "pre-provision") the identity information (or a portion of the identity information) prior to deployment and / or runtime of the security device.
[0061] 7. Security Agent In one embodiment, a computing platform may include a security agent that interfaces with a corresponding security device and / or management platform.
[0062] In one example, a security agent (running on a computing platform) can cooperate with a security device, as described below, to authenticate the security agent, the operating system, and / or a set of applications on the computing platform according to a configuration profile.
[0063] In another example, a security agent may monitor the execution of a set of applications on a computing platform to generate runtime execution metrics, detect violations of a security policy (defined by a configuration profile) during the execution of the set of applications, and respond to the violations according to actions specified by the security policy. In this example, the security agent may send (to a management server) the runtime execution metrics and / or an alert indicating the violation.
[0064] 8. Management Server In general, the management server can generate a set of configuration profiles, each of which defines identity information associated with security agents, operating systems and / or applications included in the computing platform and a set of security policies associated with the security agents, operating systems and / or applications.
[0065] In one embodiment, a management server can generate a configuration profile based on identity information associated with a security device corresponding to the computing platform. More specifically, the management server can generate a configuration profile based on cryptographic information that correlates with a unique identifier associated with the security device (e.g., a controller unique identifier, a hardware security module unique identifier, a MAC address), thereby uniquely mapping the configuration profile to the security device.
[0066] Thus, because the management server generates each configuration profile that is uniquely mapped to a security device and corresponding computing platform, a security agent running on the security device and / or computing platform can authenticate applications on the computing platform based on the configuration profile and corresponding identity information securely stored on the security device, thereby enabling the system to uniquely identify applications running on the computing platform and impose specific security policies that apply to those applications while they are running on the computing platform.
[0067] 8.1 Registering a Security Device Generally, for each security device in the set of security devices, the management server may store identity information associated with the security device. For example, the management server may store identity information including a machine identity associated with the security device.
[0068] In one embodiment, a management server can receive registration information that links a security device (within a set of security devices) with a user identity associated with a user (e.g., an operator, a group of operators, an organization), thereby linking the security device with a group of computing platforms associated with the user identity.
[0069] In one example, an administrative server can receive registration information specifying a first serial number of a first security device (within a set of security devices) and a first user identity in a set of user identities. The administrative server can then link the first security device to a group of computing platforms associated with the first user identity.
[0070] In another example, an administrative server can receive registration information specifying a first serial number of a first security device and a second serial number of a first computing platform within a group of computing platforms associated with a first user identity, after which the administrative server can link the first security device to the first computing platform.
[0071] In response to linking the security device to a user identity and / or a computing platform, the management server can generate a configuration profile that defines a set of valid software for the computing platform. More specifically, the management server can generate a configuration profile that defines identity information for a set of security agents, operating systems, and / or applications on the computing platform, as described below.
[0072] 8.2 Software Registration In general, a management server may store validation information associated with software (eg, security agents, operating systems, applications) deployed on a computing platform.
[0073] In one embodiment, the management server may store validation information associated with a valid instruction set representing a security agent, a valid instruction set representing an operating system, and / or a valid instruction set representing each application in the set of applications. For example, the management server may receive validation information and / or the valid instruction sets from one or more software developers (associated with a security agent, an operating system, and / or a set of applications) during a software registration process.
[0074] Thus, the system can authenticate software executed on the computing platform based on the verification information, thereby verifying that the software executed on the computing platform is authentic and unaltered.
[0075] 9. Configuration Profiles In general, a management server can generate a configuration profile that defines identity information associated with a set of security agents, operating systems and / or applications included on a computing platform, and a set of security policies associated with the security agents, operating systems and applications.
[0076] 9.1 Computing Platform Configuration In one embodiment, a management server can receive a configuration of a computing platform associated with a user identity and generate a configuration profile based on the configuration. More specifically, the management server can receive a configuration that defines an operating system (or kernel) and applications to be deployed and executed on the computing platform. The management server can then generate a configuration profile that defines first identity information associated with a security agent, second identity information associated with the operating system, and third identity information associated with the applications. Additionally, the management server can generate the configuration profile based on fourth identity information associated with a security device linked with the computing platform.
[0077] For example, the management server may receive (from a user device associated with the user identity) a first configuration for a first computing platform in a group of computing platforms associated with the user identity, the configuration defining a first operating system in the set of operating systems (e.g., the first operating system indicating a first version identifier) and a subset of applications in the set of applications including the first application (e.g., an object detection application indicating a second version identifier) and a second application (e.g., a path planning application indicating a third version identifier).
[0078] In this example, in response to receiving a first configuration from the user device, the management server can generate a first configuration profile based on the first configuration. More specifically, the management server can generate the first configuration profile that defines first identity information associated with the security agent, second identity information associated with the first operating system, third identity information associated with the first application, and fourth identity information associated with the second application.
[0079] Further, in this example, the management server can generate the first configuration profile based on fifth identity information associated with a first security device linked to the first computing platform. More specifically, the management server can generate the first configuration profile based on the fifth identity information including cryptographic information correlating with a unique identifier of a hardware security module associated with the first security device, e.g., cryptographic information correlating with a unique identifier embedded in a chip of the security platform (e.g., a unique identifier associated with a controller of the first security device, a unique identifier associated with a hardware security module), and / or cryptographic information correlating with a network interface hardware address (e.g., a MAC address) associated with a network interface of the first security device.
[0080] Thus, the management server generates the first configuration profile based on the fifth identity information associated with the first security device, such that the first security device can authenticate the first configuration profile based on pre-provisioned identity information (that matches the fifth identity information) in the hardware security module of the first security device, thereby enabling the first security device to ensure that the first configuration profile is compatible with the first security device and the first computing platform.
[0081] In one embodiment, the management server can generate a configuration profile that further defines cryptographic information associated with the secure communications. For example, the management server can generate a configuration profile that further defines a set of symmetric keys and / or asymmetric key pairs that can be used by the security device and / or computing platform (e.g., a security agent executing on the computing platform) to participate in secure communications with other devices.
[0082] 9.2 Identity Information In general, a management server can generate configuration profiles that define identity information for a set of security agents, operating systems (or kernels), and / or applications to be deployed and / or executed on a computing platform. Additionally, the management server can generate configuration profiles based on identity information for security devices that correspond to (e.g., are linked to) the computing platform.
[0083] 9.2.1 Security Agent Identity Information In one embodiment, an administrative server can generate a configuration profile that defines first identity information associated with a security agent. In one example, the administrative server can generate a configuration profile that defines first identity information that includes an identifier for the security agent (e.g., unique identifier, version number). Additionally or alternatively, the administrative server can generate a configuration profile that defines first identity information that includes cryptographic information that correlates with an identifier for the security agent (e.g., private key, asymmetric key pair). In another example, the administrative server can generate a configuration profile that defines first identity information that includes validation information associated with a valid instruction set indicative of the security agent. The administrative server can generate a configuration profile that defines first identity information that includes other information associated with the security agent.
[0084] 9.2.2 Operating System and Application Identity Information In one embodiment, a management server can perform similar methods and techniques to generate configuration profiles that define respective identity information associated with an operating system (or kernel) and / or each application in a set of applications. For example, the management server can generate configuration profiles that define respective identity information that defines an identifier (e.g., unique identifier, version number) of a software element (e.g., operating system, application), cryptographic information (e.g., private key, asymmetric key pair) that correlates with the software element's identifier, and / or validation information associated with a valid instruction set that represents the software element.
[0085] 9.3 Security Policy In general, the management server can generate a configuration profile that further defines a set of security policies. More specifically, the management server can generate a configuration profile that further defines a set of security policies, where each security policy (in the set of security policies) is associated with a security device and / or computing platform associated with the configuration profile.
[0086] In one embodiment, the management server can generate a configuration profile that further defines a set of security policies, where each security policy (in the set of security policies) defines a rule and a first action that corresponds to a violation of the rule. Additionally or alternatively, the management server can generate a configuration profile that further defines each security policy (in the set of security policies), where each security policy defines a rule and a second action that corresponds to compliance with the rule. The management server can generate a configuration profile that defines a security policy, where the security policy defines a set of rules and, for each rule in the set of rules, a set of actions that correspond to a violation (or compliance) of the rule.
[0087] 9.3.1 Security Policy: Authentication In general, the management server can generate configuration profiles that further define security policies associated with authentication. More specifically, the management server can generate configuration profiles that define security policies associated with authentication for a set of security devices, configuration profiles, security agents, operating systems, and / or applications.
[0088] In one embodiment, a management server can generate configuration profiles that define security policies associated with authentication during an initialization period (e.g., boot, startup) of a set of security devices, configuration profiles, security agents, operating systems, and / or applications.
[0089] For example, the management server can generate a configuration profile that defines a first security policy, the first security policy defining rules that specify authentication of the application (e.g., during initialization of the application (e.g., prior to runtime execution)) based on identity information associated with the application, and actions corresponding to violations of the first security policy (i.e., rules). More specifically, the management server can generate a configuration profile that defines a security policy that defines actions corresponding to detecting a failure to authenticate the application (during initialization of the application) based on identity information associated with the application.
[0090] Additionally or alternatively, the management server may similarly generate a configuration profile that defines a second security policy associated with authentication during a runtime execution period (e.g., following an initialization period) of a set of security devices, configuration profiles, security agents, operating systems and / or applications.
[0091] 9.3.2 Security Policy: Access to and Use of Resources In general, the management server can generate configuration profiles that further define security policies associated with access to a set of resources of the computing platform. More specifically, the management server can generate configuration profiles that define security policies associated with access to a set of resources of the computing platform by a set of security agents, operating systems, and / or applications.
[0092] In one embodiment, an administrative server can generate a configuration profile that defines a security policy that defines a subset of resources (within a set of resources of a computing platform) that a set of security agents, operating systems and / or applications are permitted to access (e.g., while executing) (e.g., processor resources, memory resources, network interface resources, input / output device resources) and an action in response to detecting a violation of the security policy (e.g., access to a resource that is excluded from the subset of resources).
[0093] In one example, the management server may generate a configuration profile defining a third security policy that defines a subset of memory addresses (within a set of resources of the computing platform) that the first application is allowed to access while executing, and a third action responsive to detecting access (or attempted access) by the first application to a first memory address that is excluded from the subset of memory addresses.
[0094] In another example, the management server may generate a configuration profile defining a fourth security policy that defines a subset of network interfaces (within a set of resources of the computing platform) that the first application is allowed to access while executing, and a fourth action responsive to detecting access (or attempted access) by the first application to a first network interface that is excluded from the subset of network interfaces.
[0095] In another embodiment, the management server can generate a configuration profile that defines a fifth security policy that defines a model characterizing an expected usage pattern (e.g., execution time, memory footprint, data rate of network messages) of a subset of running resources and a fifth action responsive to detecting a difference between the usage pattern and the first model exceeding a threshold value (e.g., 10%, 25%).
[0096] Thus, the system can define a subset of the computing platform's resources (which the application is permitted to access) based on the application's expected execution behavior and enforce access to the subset of resources during execution, thereby enabling the system to detect anomalous execution behavior of the application and mitigate security vulnerabilities associated with the anomalous execution behavior.
[0097] 9.3.3 Security Policy: Access to Network Communication Channels In general, the management server can generate configuration profiles that further define security policies associated with access to a set of network communication channels by a set of security agents, operating systems and / or applications.
[0098] In one embodiment, an administrative server can generate a configuration profile that defines a security policy that defines a subset of network communication channels (within the set of network communication channels) that a set of security agents, operating systems and / or applications are permitted to access (e.g., while running), and an action in response to detecting a violation of the security policy (e.g., access to a network communication channel that is excluded from the subset of network communication channels).
[0099] 9.3.4 Security Policy: Timing of Network Messages In general, the management server can generate configuration profiles that further define security policies associated with network messages generated and / or transmitted by a set of security agents, operating systems, and / or applications.
[0100] In one embodiment, a management server can generate a configuration profile that defines a security policy that defines periodic network messages at preset time intervals (e.g., 200 milliseconds, 5 minutes, 1 hour) and actions in response to detecting a violation of the security policy (e.g., detecting the absence of network messages for a time interval that exceeds the preset time interval).
[0101] 9.3.5 Security Policy: Actions In general, the management server can generate a configuration profile that defines a security policy that defines one or more actions in response to a violation of the security policy, such as, for example, logging an event associated with the violation, sending a notification to the user device and / or the management server indicating the violation, prompting the user device to acknowledge the violation, quarantining an application associated with the violation, and / or sending a command to transition the computing platform to a secure state, as described below.
[0102] 10. Authentication In general, the system can perform a series of authentication processes to establish trust of the security device and the computing platform. More specifically, during an initialization period (e.g., prior to a runtime execution period), the system can authenticate the security device based on identity information stored in a hardware security module of the security device, and can authenticate a configuration profile generated by a management server based on identity information stored in the hardware security module of the security device. In response to authenticating the configuration profile, the system can authenticate software elements of the computing platform (e.g., a security agent, an operating system, a set of applications) based on the configuration profile.
[0103] 10.1 Authentication of Security Devices Block S104 of method S100 depicts authenticating the first set of resources based on first identity information (stored in the hardware security module) associated with the first set of resources.
[0104] Generally, during an initialization period, a security device (including a first set of resources (e.g., controller, memory, network interface, hardware security module)) can perform an authentication process based on first identity information stored (e.g., pre-provided) in a hardware security module associated with the security device.
[0105] In one embodiment, in block S102, the security device may perform a secure boot.
[0106] In response to performing the secure boot, the security device can access first identity information stored in the hardware security module in block S104 and authenticate the first set of resources based on the first identity information. In one example, the security device can authenticate a first controller (in the first set of resources) based on the first identity information including cryptographic information that correlates with a unique identifier of the first controller. In another example, the security device can authenticate a first network interface (in the first set of resources) based on the first identity information including cryptographic information that correlates with a unique identifier of the first network interface.
[0107] Similarly, the security device may authenticate firmware, an operating system (or kernel), software applications, and / or logic of the security device based on the first identity information.
[0108] Thus, because the security device can authenticate elements of the security device based on trusted identity information stored in the hardware security module, the system can establish the security device as a root of trust for authenticating configuration profiles, a security agent, the operating system of the computing platform, and a set of applications on the computing platform, such that the system can extend a chain of trust from the security device to the set of applications based on the trusted identity information in the hardware security module.
[0109] 10.2 Configuration Profile Authentication Block S106 of method S100 depicts accessing a configuration profile from a management server, where the configuration profile is generated by the management server based on encrypted information that correlates with the first identity information.
[0110] Block S108 of method S100 depicts authenticating the configuration profile based on the first identity information.
[0111] Generally, in response to authenticating a resource of the security device, the security device can access a configuration profile and authenticate the authentication profile based on identity information stored in the hardware security module.
[0112] In one embodiment, in block S106, the security device can access (from the management server) a configuration profile associated with the security device and the corresponding computing platform. More specifically, the security device can receive the configuration profile from the management server over a secure communications channel based on cryptographic information (e.g., a first asymmetric key pair) stored in the hardware security module.
[0113] In another embodiment, in block S108, the security device can authenticate the configuration profile based on identity information stored in the hardware security module. More specifically, the management server generates the configuration profile based on identity information associated with the security device, so that the security device can authenticate the configuration profile based on identity information stored in the hardware security module.
[0114] For example, a security device can access a configuration profile from a management server (where the configuration profile is based on first encrypted information that correlates with a unique identifier of a hardware security module of the security device) and can access identity information (stored in the hardware security module) that includes second encrypted information that correlates with the unique identifier of the hardware security module. In this example, in response to the security device detecting a match between the first encrypted information and the second encrypted information, the security device can authenticate the configuration profile. If, however, the security device detects a difference between the first encrypted information and the second encrypted information, the security device can detect an authentication failure of the configuration profile. In response to detecting an authentication failure, the security device can perform actions such as logging the event, sending a notification to the user device, and / or sending a command to transition the computing platform to a secure state.
[0115] 10.3 Security Agent Authentication Block S110 of method S100 depicts authenticating the security agent with the security device based on first identity information stored on the security device that is associated with the security agent.
[0116] In general, a computing platform may perform a boot procedure to initialize (e.g., start) a security agent on the computing platform. The security agent may authenticate with a security device based on a configuration profile that defines identity information associated with the security agent.
[0117] In one embodiment, in block S110, the security agent can authenticate with the security device based on identity information associated with the security agent, where the identity information (associated with the security agent) is specified in a configuration profile and / or stored on the security device.
[0118] For example, a security agent may authenticate with a security device based on identity information associated with the security agent by transmitting first identity information (e.g., an identifier, encrypted information correlated with the identifier) associated with the security agent to the security device. In response to receiving the first identity information, the security device may access a configuration profile that defines second identity information associated with the security agent, and in response to detecting a match between the first identity information and the second identity information, the security device may authenticate the security agent. In response to a discrepancy between the first identity information and the second identity information, however, the system (e.g., security agent, security device) may detect a failure to authenticate the security agent and may perform actions such as logging the event, sending a notification to the user device, and / or sending a command to transition the computing platform to a secure state.
[0119] Thus, the security agent can cooperate with the security device to authenticate the security agent on the computing platform, thereby enabling the system to extend trust from the security device to the security agent, thereby enabling the security agent to manage security on the computing platform and to implement safety-critical responses to security breaches.
[0120] 10.4 Operating System and Application Certification Block S112 of method S100 illustrates accessing a configuration profile from the security device in response to authenticating the security agent, where a first configuration profile defines second identity information associated with the operating system and third identity information associated with the first application.
[0121] Block S114 of method S100 depicts authenticating the configuration profile based on cryptographic information that correlates with a unique identifier associated with a hardware security module of the security device, in response to accessing the configuration profile from the security device, the cryptographic information being stored in the hardware security module.
[0122] The blocks of method S100 include authenticating the operating system based on the second identity information in block S116, and authenticating the first application based on the third identity information in block S120.
[0123] In general, a security agent may have access to a configuration profile that defines a configuration (e.g., a software configuration) of a computing platform. More specifically, a security agent may have access to a configuration profile that defines identity information associated with an operating system (or kernel) and identity information associated with a first application. A security agent may have access to a configuration profile that defines additional information (e.g., identity information associated with additional applications).
[0124] In one embodiment, the security agent can access the configuration profile from the security device in block S112. For example, in response to the security agent authenticating with the security device, the security agent can receive the configuration profile from the security device over a secure communications channel based on cryptographic information (e.g., a second asymmetric key pair) stored in the hardware security module.
[0125] In block S114, in response to accessing the configuration profile, the security agent can authenticate the configuration profile based on identity information associated with the security device. For example, the security agent can authenticate the configuration profile based on cryptographic information that correlates with a unique identifier associated with a hardware security module of the security device.
[0126] In general, a security agent may authenticate an operating system (or kernel) and a set of applications of a computing platform in response to accessing and / or authenticating a configuration profile. For example, the security agent may authenticate the operating system (or kernel) and a set of applications during an initialization period prior to a runtime execution period of the operating system and the set of applications.
[0127] In one embodiment, in block S116, the security agent can authenticate the operating system (or kernel) based on identity information (associated with the operating system) defined in a configuration profile.
[0128] For example, the security agent can access an identifier (e.g., a version number) associated with the operating system and can access identity information associated with the operating system defined in a configuration profile. In this example, the security agent can authenticate the operating system in response to detecting a match between the identifier and the identity information associated with the operating system.
[0129] Thus, by authenticating a computing system's operating system, a security agent can extend trust to the operating system, including its core resources for process management and network communication, thereby allowing the security agent to utilize those core resources in a trusted manner.
[0130] However, in response to detecting a discrepancy between the identifier associated with the operating system and the identity information, the security agent may detect an authentication failure of the operating system and may perform actions (e.g., actions defined in a security policy of the configuration profile), such as logging the event, sending a notification to the user device, and / or sending a command to transition the computing platform to a secure state.
[0131] In another embodiment, the security agent may perform similar methods and techniques to authenticate the first application in block S120. More specifically, in response to authenticating the operating system, the security agent may authenticate the first application based on identity information (associated with the first application) defined in a configuration profile.
[0132] For example, the security agent can access an identifier (e.g., a version number) associated with the first application and can access identity information associated with the first application defined in the configuration profile. In this example, the security agent can authenticate the first application in response to detecting a match between the identifier and the identity information associated with the first application.
[0133] Thus, by authenticating a first application of a computing system, the security agent can complete a chain of trust that extends from the security device to the first application.
[0134] The security device can perform similar methods and techniques to perform actions in response to detecting an authentication failure of the first application. For example, in response to detecting a difference between the identifier and the identity information associated with the first application, the security agent can detect an authentication failure of the first application and can perform actions (e.g., actions defined in a security policy of a configuration profile) such as logging the event, sending a notification to a user device, quarantining the first application, and / or sending a command to transition the computing platform to a secure state.
[0135] Additionally, the security agent can perform similar methods and techniques to authenticate other applications within the computing platform based on identity information associated with those applications defined in the configuration profile.
[0136] 10.4.1 Verifying Application Verification Information Additionally or alternatively, the security agent may authenticate an application in the set of applications based on validation information associated with a valid instruction set representing the application.
[0137] In one embodiment, a security agent can access a configuration profile that defines identity information (associated with an application), including validation information (e.g., a cyclic redundancy check value, a checksum value, a cryptographic hash value, or other error detection code) associated with a valid instruction set representing the application, and the security agent can authenticate the application based on the validation information.
[0138] In one example, a security agent can authenticate an application based on a cyclic redundancy check and verification information for the application, in response to accessing verification information including a cyclic redundancy check value associated with a valid instruction set representing the application, calculating a first value based on the cyclic redundancy check of the application, and verifying a match between the first value and the cyclic redundancy check value.
[0139] In another example, a security agent can authenticate an application based on a validation of the application and a cryptographic hash value included in the validation information. More specifically, the security agent can authenticate the application in response to accessing validation information including a cryptographic hash value associated with a valid instruction set representing the application, calculating a second value based on a cryptographic hash (e.g., MD5, SHA-1, SHA-256) of the application, and verifying a match between the second value and the cryptographic hash value.
[0140] In other embodiments, a security agent may perform similar methods and techniques to authenticate a security agent and / or an operating system based on verification information (such as a cyclic redundancy check value, a checksum value, a cryptographic hash value, other error detection code, etc.). In one example, a security agent may authenticate a security agent based on a cyclic redundancy check of the security agent and verification information associated with a valid instruction set indicative of the security agent. In another example, a security agent may authenticate an operating system based on a cyclic redundancy check of the operating system and verification information associated with a valid instruction set indicative of the operating system.
[0141] Thus, the system can authenticate software executed on the computing platform based on the verification information, thereby verifying that the software executed on the computing platform is authentic and unaltered.
[0142] 10.4.2 Application Wrappers In general, a computing platform may initialize an application within an application container (e.g., an application wrapper). For example, a security agent may cooperate with the application wrapper (which contains the application) to manage security of the application running within the application wrapper on the computing platform.
[0143] In one embodiment, in block S118, the security agent may initialize the application within an application wrapper on the computing platform.
[0144] In another embodiment, in block S120, the security agent can authenticate the application based on the application wrapper and identity information associated with the application. For example, the security agent can authenticate the application in response to verifying the contents of the application wrapper and detecting a match between an identifier of the application and identity information (associated with the application) defined in the configuration profile. More specifically, the security agent can verify the contents of the application wrapper based on verification information (associated with the application wrapper) defined in a security policy of the configuration profile.
[0145] Thus, the system can implement a lightweight application wrapper to initialize and authenticate each application on the computing platform, thereby enabling the system to isolate each application on the computing platform and protect the computing platform from security vulnerabilities associated with each application.
[0146] 10.5 Runtime Authentication In general, a security agent may perform similar methods and techniques described above to periodically authenticate an application during run-time execution following an initialization period.
[0147] In one embodiment, a security agent can access a configuration profile that defines a security policy that defines periodic cyclic redundancy checking of an application (based on validation information associated with the application) at pre-configured time intervals (e.g., 5 minutes, 60 minutes) during runtime execution of the application.
[0148] In another embodiment, in block S122, the security agent can periodically perform a cyclic redundancy check of the application and the validation information associated with the application at a preset time interval, and the security device can perform an action (e.g., an action specified in a security policy) in response to detecting a failure of the cyclic redundancy check.
[0149] Additionally or alternatively, the security agent may access a configuration profile that defines a security policy that defines periodic validation of the application (based on other validation information, such as a cryptographic hash value associated with a valid instruction set representing the application) at pre-configured time intervals (or another time interval) during runtime execution of the application. The security agent may periodically calculate a value based on the cryptographic hash value of the application and perform an action in response to detecting a discrepancy between that value and the cryptographic hash value.
[0150] Thus, the security agent can verify that applications running on a computing platform are authentic and have not been tampered with during execution.
[0151] Additionally, the system may implement similar methods and techniques to periodically authenticate security devices, configuration profiles, security agents, and / or operating systems during runtime execution of the computing platform.
[0152] 11. Runtime Execution Monitoring Block S130 of method S100 illustrates monitoring a set of resources corresponding to execution of a first application on a computing platform.
[0153] Block S132 of the method S100 illustrates generating a first usage pattern of the subset of resources by a first application while executing on the computing platform.
[0154] Block S134 of the method S100 depicts monitoring a set of network messages from a first application.
[0155] In general, as shown in Figures 2 and 3, a security agent can monitor the runtime execution of an operating system and / or a set of applications on a computing platform in response to authenticating the operating system and a set of applications.
[0156] In one embodiment, in block S130, a security agent may monitor a set of resources of a computing platform corresponding to the execution of an application on the computing platform. More specifically, the security agent may detect access (or attempts to access) the set of resources by the application during execution. In one example, a security monitor may detect a set of memory addresses accessed by the application during execution. In another example, the security agent may detect network interfaces and / or input / output devices accessed by the application during execution. In yet another example, the security agent may detect a set of software libraries and / or data accessed by the application during execution.
[0157] In another embodiment, in block S132, the security agent can generate a usage pattern of resources utilized by the application during execution. For example, the security agent can generate a usage pattern that characterizes processor usage, memory access, and / or network access by the running application.
[0158] In another embodiment, a security agent can monitor a set of network messages from an application. More specifically, the security agent can monitor a set of network messages sent by the application and generate a set of timing metrics associated with the set of network messages. For example, the security agent can generate a first subset of metrics based on a duration of the network messages (e.g., a difference between a receipt time of a network message and a receipt time of a previous network message), a pre-configured duration of the set of network messages (e.g., a duration defined in a security policy of a configuration profile), and / or an average duration of the network messages in the set of network messages. For example, the set of messages can include a set of heartbeat signals, a set of status messages, and / or other data.
[0159] In one embodiment, a security agent can communicate resource access information and / or usage patterns to a management server and / or user device, thereby enabling remote monitoring of application execution.
[0160] In another embodiment, a security agent may cooperate with an operating system to monitor a set of computing platform resources Additionally or alternatively, a security agent may cooperate with an application wrapper to monitor a set of computing platform resources corresponding to the execution of an application within the application wrapper.
[0161] Additionally or alternatively, the security agent may perform similar methods and techniques to detect access to a set of resources by a running operating system and / or to generate usage patterns of resources utilized by the operating system during execution.
[0162] Thus, a security agent can monitor the runtime execution of an operating system and / or a set of resources of a computing platform, thereby enabling the security agent to detect and respond to violations of security policies, as described below.
[0163] 12. Response to Policy Violations In general, a security agent may access configuration profiles that define security policies associated with applications and monitor the execution of the applications on a computing platform. In response to detecting a violation of the security policy by the application, the security agent may perform actions defined in the security policy, such as logging an event associated with the violation, sending a notification indicating the violation, prompting a user device to acknowledge the violation, quarantining the application, and / or triggering a safety-critical response in the computing platform.
[0164] 12.1 Resource Access Violation Block S112 of method S100 illustrates accessing a configuration profile from the security device in response to authenticating the security agent, the first configuration profile defining a first security policy defining a subset of resources within the set of resources that the first application is permitted to access and a first action corresponding to a first violation of the first security policy.
[0165] Block S136 of method S100 illustrates performing a first action in response to detecting access by a first application to a first resource in the set of resources, where the first resource is excluded from the subset of resources.
[0166] In general, a security agent can access a configuration profile that defines a security policy that defines a subset of resources that an application is permitted to access, and can detect violations associated with access (or attempted access) (by an application) to resources that are excluded from the subset of resources. In response to detecting a violation, the security agent can perform an action defined in the security policy.
[0167] In one embodiment, in block S112, the security agent may access a configuration profile that defines a security policy that defines a subset of resources (within the set of resources of the computing platform) that the application is permitted to access and an action corresponding to a first violation of the security policy. The security agent may monitor the set of resources corresponding to execution of the application on the computing platform in block S130 and may perform an action in response to detecting access by the application to a resource that is excluded from the subset of resources in block S136.
[0168] 12.1.1 Event Recording Example In one example, in block S112, the security agent can access a configuration profile that defines a first security policy that defines a subset of memory addresses that the application is permitted to access and a first action corresponding to a violation of the first security policy, the first action including recording an event associated with the violation. In response to detecting an access by the application to a memory address that is excluded from the subset of memory addresses, the security agent can record an event associated with the violation in block S140, the event identifying first data associated with the violation, e.g., an application identifier, an identifier of the security device, an identifier of the computing platform, a resource accessed by the application, a date and time of the violation, etc. The security agent can further record an event identifying second data associated with a first state of the system (e.g., security device, computing platform) during a first period of time prior to the violation and third data associated with a second state of the system during a second period of time after the violation.
[0169] In this example, the security agent may record the event on a storage device of the computing platform (e.g., a protected area of the storage device). Additionally or alternatively, the security agent may record the event on a storage device of the security platform and / or record the event at a management server.
[0170] 12.1.2 Notification Examples In another example, in block S112, the security agent can access a configuration profile that defines a second security policy that defines a subset of network interfaces the application is permitted to access and a second action responsive to a violation of the second security policy, the second action including sending a notification to a user device (e.g., a user device associated with the computing platform) indicative of the first violation. In response to detecting access by the application to a network interface that is excluded from the subset of network interfaces, the security agent can send a notification (indicative of the violation) to the user device in block S142. Additionally, the security agent can also send the notification to a management server.
[0171] In this example, the security agent can access a configuration profile that further defines encryption information associated with the secure communication (e.g., a third asymmetric key pair), encrypt messages (including notifications) based on the encryption information, and send the messages to the user device and / or the management server.
[0172] 12.1.3 Confirmation prompt example In another example, in response to detecting a violation of a security policy by an application executing on a computing platform, a security agent may perform similar methods and techniques to prompt a user device to confirm the violation. More specifically, in response to detecting access by an application to a resource that is excluded from a subset of resources that the application is permitted to access, the security agent may prompt the user device to confirm access to the resource in block S144.
[0173] Upon receiving confirmation (from the user device) of the application's access to the resource, the security agent can allow the application to access the resource (e.g., via the application wrapper). More specifically, the security agent can allow the application to access the resource upon receiving confirmation (from the user device) within a preset time period (e.g., within 15 minutes) indicating multi-factor authentication.
[0174] In this example, the security agent may prompt user devices associated with a particular operator of the computing platform, user devices associated with an administrator of the computing platform, and / or user devices associated with a user identity corresponding to the computing platform.
[0175] 12.1.4 Application Isolation Examples In another example, in response to detecting a violation of a security policy by an application on a computing platform, a security agent may perform similar methods and techniques to quarantine the application. More specifically, in response to detecting access by an application (e.g., an application running in an application wrapper) to a resource that is excluded from the subset of resources that the application is permitted to access, the security agent may quarantine the application in block S146.
[0176] 12.1.6 Examples of Safety Responses In another example, in response to detecting a violation of a security policy by an application executing on the computing platform, a security agent may perform similar methods and techniques to trigger the computing platform to take a safety-critical response, such as outputting a command to transition the computing platform to a safe state (e.g., turn off power, cut off fuel supply, etc.) More specifically, in response to detecting access by an application to a resource that is excluded from the subset of resources that the application is permitted to access, the security agent may issue a command (or signal) in block S148 to transition the computing platform to a safe state.
[0177] In this example, a security agent may issue commands (e.g., a first command) to a security device, a computing platform, a local emergency stop device connected to the computing platform, a remote emergency stop device (or field bus) communicatively connected to the computing platform, and / or other controllers. The security agent may issue the first command (in a set of commands) that exhibits a minimum Hamming distance (e.g., 4, 8) from other commands in the set of commands.
[0178] 12.2 Unusual Resource Usage Patterns In one embodiment, in block S112, the security agent may access a configuration profile that defines a security policy that defines a model characterizing an expected usage pattern of a subset of resources (that are permitted to be accessed) by an application executing on the computing platform and an action responsive to a difference between the application's actual (e.g., running) usage pattern and the model (e.g., expected usage pattern) exceeding a preset threshold (e.g., 5%, 15%). The security agent may monitor a set of resources corresponding to the application's execution on the computing platform in block S130, generate a first usage pattern of resources utilized by the application during execution in block S132, and perform an action in response to detecting a difference between the first usage pattern and the model exceeding a preset threshold in block S136.
[0179] Thus, the security agent may detect unexpected behavior by a running application, thereby mitigating security and / or safety vulnerabilities of the computing platform resulting from that behavior.
[0180] 12.3 Network Message Violations In another embodiment, in block S112, the security agent can access a configuration profile that defines a security policy that defines periodic network messages sent from the application at preset time intervals and actions corresponding to violations of the security policy. The security agent can monitor a set of network messages sent by the application in block S134 and perform an action in block S136 in response to detecting an absence of network messages from the application during a first time interval that exceeds the preset time interval.
[0181] Additionally or alternatively, the security agent can monitor the payloads of messages in a set of messages from the application, and in response to detecting a fault condition of the application based on the payloads, the security agent can take action as described above.
[0182] Thus, the security agent can detect fault conditions in a running application, thereby mitigating security and / or safety vulnerabilities on the computing platform that result from those conditions.
[0183] 12.4 Violation of Network Communication Channels In one embodiment, in block S112, the security agent can access a configuration profile that defines a security policy that defines a subset of network communication channels that the application is permitted to access and an action corresponding to a violation of the security policy. The security agent can monitor a set of resources corresponding to the execution of the application on the computing platform in block S130. More specifically, the security agent can monitor a set of network interfaces within the set of resources of the computing platform to detect a group of network communication channels accessed by the application during execution.
[0184] In block S136, the security agent can perform an action in response to detecting access by the application to a network communication channel that is excluded from the subset of network communication channels. In one example, the security agent can send a notification to the user device via a management server. In another example, the security agent can issue a command (to the security device) to transition the computing platform to a secure state. In this example, once the security device receives the command to transition the computing platform to a secure state, an emergency stop signal can be sent to the computing platform in block S150.
[0185] 13.Security device monitoring and safety response Block S160 of method S100 illustrates periodically sending a status message to the security device at a preset time interval, the status message including a status indicator in a set of status indicators, each status indicator in the set of status indicators having a minimum Hamming distance of four from another status indicator in the set of status indicators.
[0186] Block S162 of method S100 depicts sending a signal to transition the computing platform to a secure state upon detecting an absence of a status message from the security agent during a first time interval that exceeds a pre-set time interval.
[0187] In general, as shown in FIG. 4, the security device may perform similar methods and techniques described above to access a configuration profile that defines a security policy, monitor the computing platform (and / or security device) during execution, and perform one or more actions (defined in the security policy) in response to detecting a violation of the security policy, in block S106.
[0188] In one embodiment, a security device can access a configuration profile that defines a security policy that defines periodic status messages to be sent from the security agent at pre-set intervals (e.g., every 200 milliseconds, 10 seconds, 5 minutes) and actions to be taken in response to violations of the security policy.
[0189] The security agent may periodically transmit a status message to the security device at a preset time interval, block S160. More specifically, the security agent may periodically transmit a status message that includes a status indicator in a set of status indicators, where each status indicator in the set of status indicators exhibits a minimum Hamming distance (e.g., 4, 8) from another status indicator in the set of status indicators.
[0190] In this embodiment, the security device can monitor a set of status messages sent by the security agent in block S162 and can perform an action in response to detecting the absence of a status message from the security agent during a first time interval that exceeds a pre-set time interval.
[0191] Additionally or alternatively, the security agent can monitor the payload of a status message in a set of status messages from the security agent, and the security device can perform an action as described above in response to detecting a fault condition of the security agent based on the payload.
[0192] Thus, the security agent may detect a fault condition in the security agent while it is running, which may enable the security device to mitigate security and / or safety vulnerabilities on the computing platform caused by that condition.
[0193] 14. Conclusion The systems and methods described herein may be embodied and / or realized at least in part as a machine configured to receive a computer-readable medium storing computer-readable instructions. The instructions may be executed by a computer-executable component integrated with an application, an applet, a host, a server, a network, a website, a communication service, a communication interface, a hardware / firmware / software element of a user computer or mobile device, a wristband, a smartphone, or any suitable combination thereof. Other systems and methods of the embodiments may be embodied and / or realized at least in part as a machine configured to receive a computer-readable medium storing computer-readable instructions. The instructions may be executed by a computer-executable component integrated with the above-mentioned types of devices and networks. The computer-readable medium may be stored in any suitable computer-readable medium, such as a RAM, a ROM, a flash memory, an EEPROM, an optical device (CD or DVD), a hard drive, a floppy drive, or any suitable device. The computer-executable component may be a processor, although any suitable dedicated hardware device may (alternatively or additionally) execute the instructions.
[0194] As can be understood from the foregoing detailed description, drawings and claims, those skilled in the art may make modifications and variations to the embodiments of the present invention without departing from the scope of the invention as defined in the following claims.
Claims
1. A security agent executing on a computing platform including a set of resources, an operating system, and a first application, During the first period, o authenticating the security agent at a security device based on first identity information associated with the security agent, the first identity information being stored on the security device; o accessing a configuration profile from the security device in response to authentication of the security agent, the first configuration profile comprising: - second identity information associated with the operating system; and - third identity information associated with the first application; and A first security policy is defined, the first security policy being a subset of resources in the set of resources to which the first application is permitted to access; and - defining a first action corresponding to a first violation of the first security policy; o authenticating the operating system based on the second identity information; o authenticating the first application based on the third identity information; During a second period following the first period, o monitoring a set of resources corresponding to the execution of the first application on the computing platform; o performing the first action in response to detecting access by the first application to a first resource in the set of resources that is excluded from the subset of resources.
2. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of memory addresses within the set of resources that the first application is permitted to access; and a first action responsive to a first violation of the first security policy, the first action including recording an event associated with the first violation; accessing a configuration profile defining the first security policy; - A method characterized in that performing the first action includes, in response to detecting an access by the first application to a first memory address in the set of resources that is excluded from the subset of memory addresses, recording an event associated with an access by the first application to the first memory address.
3. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of network interfaces in the set of resources to which the first application is permitted to access; and a first action responsive to a first violation of the first security policy, the first action including sending a notification to a user device indicating the first violation; accessing a configuration profile defining the first security policy; - A method, characterized in that performing the first action includes sending the notification to a user device in response to detecting access by the first application to a first network interface in the set of resources that is excluded from the subset of network interfaces.
4. 4. The method of claim 3, accessing the configuration profile includes accessing a configuration profile that further defines cryptographic information associated with the secure communication; sending the notification to the user device; o encrypting a message including said notification based on said encryption information; o transmitting the message to the user device.
5. 10. The method of claim 1 , Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: a first model characterizing an expected usage pattern of the subset of resources by the first application executing on the computing platform; and a second action corresponding to a second violation of the second security policy, the second violation being characterized by a difference between a usage pattern and the first model exceeding a threshold; the method comprising, during the second period: generating a first usage pattern of the subset of resources by the first application while executing on the computing platform; and o performing the second action in response to detecting that a difference between the first usage pattern and the first model exceeds a threshold.
6. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of resources in the set of resources to which the first application is authorized to access; and a first action responsive to a first violation of the first security policy, the first action including issuing a first command in a set of commands to the security device to transition the computing platform to a secure state, the first command exhibiting a minimum Hamming distance from other commands in the set of commands; accessing a configuration profile defining a first security policy, - A method, characterized in that performing the first action includes issuing the first command to the security device to transition the computing platform to a secure state in response to detecting access to the first resource by the first application.
7. 10. The method of claim 1 , authenticating the first application based on the third identity information; Initializing the first application within an application wrapper on the computing platform; - authenticating the first application based on the application wrapper and the third identity information.
8. 8. The method of claim 7, Accessing a configuration profile defining the first security policy includes: a subset of resources in the set of resources to which the first application is authorized to access; and a first action in response to a violation of the first security policy, the first action including quarantining the first application; and accessing a configuration profile defining a first security policy, monitoring a set of resources corresponding to execution of the first application on the computing platform includes monitoring a set of resources corresponding to execution of the first application within the application wrapper on the computing platform; - A method, wherein performing the first action includes quarantining the first application in response to detecting access to the first resource by the first application.
9. 10. The method of claim 1 , accessing a configuration profile defining the third identity information includes accessing a configuration profile defining third identity information including validation information associated with a valid instruction set indicative of the first application; - A method, wherein authenticating the first application based on the third identity information includes authenticating the first application based on a cyclic redundancy check of the first application and the verification information.
10. 10. The method of claim 9, Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: o a periodic cyclic redundancy check of the first application at a preset time interval; a second action corresponding to a violation of the second security policy; the method comprising, during the second period: o periodically performing a cyclic redundancy check of the first application and the verification information at the preset time interval; and performing the second action in response to detecting a cyclic redundancy check failure of the first application and the validation information.
11. 10. The method of claim 1 , Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: o periodic network messages from the first application at pre-defined time intervals; and a second action corresponding to a violation of the second security policy; the method comprising, during the second period: o monitoring a set of network messages from the first application; and performing the second action in response to detecting an absence of network messages from the first application for a first time interval that exceeds the preset time interval.
12. 10. The method of claim 1 , During the first period, by the security agent: - In response to accessing a configuration profile from the security device, the method further includes a step of authenticating the configuration profile based on cryptographic information that correlates with a unique identifier associated with a hardware security module of the security device, the cryptographic information being stored in the hardware security module.
13. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: A first security policy, a subset of resources that the first application is authorized to access; and a first action in response to a first violation of the first security policy, the first action including sending a notification to a management server indicating the first violation; accessing a configuration profile that defines the first security policy; o accessing a configuration profile defining the first security policy, the configuration profile being generated by the management server based on cryptographic information that correlates with a unique identifier associated with the security device; - A method, wherein performing the first action includes sending the notification to the management server in response to detecting access to the first resource by the first application.
14. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of resources that the first application is authorized to access; and a first action corresponding to the first violation of the first security policy, the first action including prompting a user device to acknowledge the first violation; and accessing a configuration profile defining a first security policy, - A method, characterized in that performing the first action includes, in response to detecting access to the first resource by the first application, prompting the operator device to confirm access to the first resource by the first application.
15. 10. The method of claim 1 , During the second period of time, by the security agent: - The method further comprising the step of periodically sending a status message to the security device at a preset time interval, the status message including a status indicator in a set of status indicators, each status indicator in the set of status indicators indicating a minimum Hamming distance from another status indicator in the set of status indicators of four.
16. During a first period of time, in a security device including a first set of resources including a hardware security module, o authenticating the first set of resources based on first identity information associated with the first set of resources, the first identity information being stored in the hardware security module; o authenticating a configuration profile associated with a computing platform based on the first identity information, the computing platform comprising: - communicatively coupled to said security device; and o a second set of resources; and an operating system; and o a first application; during a second period of time subsequent to the first period of time, in a security agent executing on the computing platform, o authenticating the security agent at the security device based on second identity information associated with the security agent, the second identity information being specified in the configuration profile; o accessing the configuration profile from the security device in response to authentication of the security agent, the configuration profile comprising: - third identity information associated with the operating system; and - fourth identity information associated with the first application; and A first security policy is defined, the first security policy being a subset of network communication channels within the set of network communication channels that the first application is permitted to access; and - defining a first action corresponding to a first violation of the first security policy; o authenticating the operating system based on the second identity information; o authenticating the first application based on the third identity information; during a third period following the second period, in the security agent: o monitoring a second set of resources corresponding to execution of the first application on the computing platform; o performing the first action in response to detecting access by the first application to a first network communication channel in the set of network communication channels that is excluded from the subset of network communication channels.
17. 17. The method of claim 16, - during the first period, at the security device, accessing the configuration profile from a management server, the configuration profile being generated by the management server based on encrypted information that correlates with the first identity information; accessing from the security device a configuration profile defining the first security policy; o the first security policy, a subset of the network communication channels that the first application is permitted to access; and accessing a configuration profile defining a first security policy that defines a first action responsive to a first violation of the first security policy, the first action including sending a notification to a user device indicating the first violation; - A method, characterized in that performing the first action includes sending the notification to an operator device via the management server in response to detecting access to the first network communication channel by the first application.
18. 17. The method of claim 16, Accessing a configuration profile defining the first security policy includes: a subset of network communication channels that the first application is authorized to access; and a first action responsive to a first violation of the first security policy, the first action including issuing a first command in a set of commands to the security device to transition the computing platform to a secure state; accessing a configuration profile defining a first security policy, performing the first action includes issuing the first command to the security device to transition the computing platform to a secure state in response to detecting access to the first resource by the first application; The method further comprising the step of transmitting, by the security device, an emergency stop signal to the computing platform in response to receiving the first command during the third period of time.
19. 17. The method of claim 16, The method of claim 1, further comprising: during the third period of time, in response to detecting, by the security agent, an absence of a status message from the security agent during a first time interval that exceeds a predetermined time interval, transmitting a signal to transition the computing platform to a secure state.
20. A security agent executing on a computing platform including a set of resources and a first application, During the first period, o authenticating the security agent at a security device based on first identity information associated with the security agent; o in response to authenticating the security agent, accessing a configuration profile from the security device, the configuration profile being generated based on second identity information associated with the security device, the first configuration profile comprising: - third identity information associated with the first application; and - defining a first security policy defining a subset of resources within the set of resources that the first application is permitted to access; o authenticating the first application based on the third identity information; During a second period following the first period, o monitoring a set of resources corresponding to the execution of the first application on the computing platform; and in response to detecting access by the first application to a first resource in the set of resources that is excluded from the subset of resources, issuing a command to transition the computing platform to a secure state.
Citation Information
Patent Citations
Permission multiplexing method, resource access method based on permission multiplexing and related device
CN113326498A
Systems and methods for safety-enabled control
US20210026320A1