How to respond safely to violations of security policies

The method employs a security agent and device to authenticate and monitor compliance with security policies, effectively addressing the challenge of securely responding to policy violations and enhancing overall system security and safety.

JP7679561B2Active Publication Date: 2025-05-19FORT ROBOTICS INC
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
JP2024560835
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2022-04-19
Filing Date
2023-04-19
Publication Date
2025-05-19
Estimated Expiration
2043-04-19

AI Technical Summary

Technical Problem

Existing computer security systems lack an efficient method for securely responding to security policy violations, which can lead to system downtime, data breaches, and potential harm.

Method used

A method involving a security agent running on a computing platform that authenticates with a security device, accesses a configuration profile defining security policies, and monitors resource access to execute predefined actions upon detecting policy violations.

Benefits of technology

This solution enables secure and timely responses to security policy violations, reducing the risk of system compromise, data loss, and ensuring the safety of both the system and its users.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007679561000001
    Figure 0007679561000001
  • Figure 0007679561000002
    Figure 0007679561000002
  • Figure 0007679561000003
    Figure 0007679561000003
Patent Text Reader

Abstract

The method includes, in a security agent executing on a computing platform including a set of resources and a first application, steps of authenticating the security agent with a security device; accessing a configuration profile from the security device, the configuration profile defining identity information associated with the first application and a first security policy defining a subset of resources in the set of resources to which the first application is authorized to access; authenticating the first application based on the identity information; monitoring the set of resources corresponding to execution of the first application on the computing platform; and in response to detecting access by the first application to a first resource in the set of resources that is excluded from the subset of resources, issuing a command to transition the computing platform to a secure state.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention generally relates to the field of computer security, and more specifically, to a novel and useful method for secure response to security policy violations in the field of computer security.

[0002] Cross - Reference to Related Applications This application claims the benefit of U.S. Provisional Application No. 63 / 332,680, filed on April 19, 2022, which is hereby incorporated by reference in its entirety.

[0003] This application is related to U.S. Patent Application No. 16 / 937,299, filed on July 23, 2020, U.S. Patent Application No. 17 / 856,661, filed on July 1, 2022, and U.S. Patent Application No. 18 / 081,833, filed on December 15, 2022, and each of those applications is hereby incorporated by reference in its entirety.

Brief Description of the Drawings

[0004]

Figure 1

Figure 2

Figure 3

Figure 4

Best Mode for Carrying Out the Invention

[0005] The following description of embodiments of the present invention is not intended to limit the present invention to those embodiments, but is intended to enable those skilled in the art to manufacture and use the present invention. The aspects, configurations, embodiments, exemplary aspects, and examples described herein are optional and are not limited to the aspects, configurations, embodiments, exemplary aspects, and examples they describe. The present invention described herein can include any combination of those aspects, configurations, embodiments, exemplary aspects, and examples.

[0006] 1. Method As shown in FIGS. 1 and 2, method S100 is performed by a security agent running on a computing platform including a set of resources, an operating system, and a first application during a first period. In block S110, based on first identity information associated with the security agent, where the first identity information is stored in the security device, the security device authenticates the security agent. In block S112, in response to authenticating the security agent, the security device accesses a configuration profile from the security device. The first configuration profile can define second identity information associated with the operating system, third identity information associated with the first application, and a first security policy. The first security policy can define a subset of resources within the set of resources that the first application is permitted to access and a first action corresponding to a first violation of the first security policy.

[0007] Method S100 further includes, in block S116, authenticating the operating system based on the second identity information and, in block S120, authenticating the first application based on the third identity information.

[0008] Method S100 further includes, during a second period following the first period, in block S130, monitoring a set of resources corresponding to the execution of a first application on a computing platform; and in block S136, in response to detecting access to a first resource within the set of resources by the first application, executing a first action, where the first resource is excluded from a subset of the resources.

[0009] 1.1 Variation: Violation of Network Communication Channel Access As shown in FIGS. 1 and 2, one variation of method S100 includes, during the first period, in a security device including a first set of resources including a hardware security module, in block S104, authenticating the first set of resources based on first identity information associated with the first set of resources, where the first identity information is stored in the hardware security module; and in block S108, authenticating a configuration profile based on the first identity information, where the configuration profile is associated with a computing platform communicatively coupled to the security device and includes a second set of resources, an operating system, and a first application.

[0010] A variation of this method S100 is, during a second period following the first period, with a security agent running on a computing platform, in block S110, authenticating the security agent with a security device based on second identity information associated with the security agent, where the second identity information is shown in a configuration profile; and in block S112, accessing the configuration profile from the security device in response to authentication of the security agent. The configuration profile can define third identity information associated with an operating system, fourth identity information associated with a first application, and a first security policy, where the first security policy can define a subset of network communication channels within a set of network communication channels that the first application is permitted to access, and a first action corresponding to a first violation of the first security policy.

[0011] A variation of this method S100 further includes, in block S116, authenticating the operating system based on the third identity information, and in block S120, authenticating the first application based on the fourth identity information.

[0012] A variation of this method S100 is, during a third period following the second period, with a security agent, in block S130, monitoring a second set of resources corresponding to execution of a first application on a computing platform; and in block S136, executing the first action in response to detecting access by the first application to a first network communication channel within a set of network communication channels, where the first communication channel is excluded from a subset of network communication channels.

[0013] 1.2 Variation: Secure Response to Violation of Security Policy As shown in FIGS. 1 and 2, one variation of method S100 is that, during a first period, in block S110, in a security agent running on a computing platform including a set of resources and a first application, based on first identity information associated with the security agent, authenticating the security agent at a security device; and in block S112, in response to authentication of the security agent, accessing a configuration profile from the security device, the configuration profile being generated based on second identity information associated with the security device, the first configuration profile defining third identity information associated with the first application and a first security policy, the first security policy defining a subset of resources within the set of resources that the first application is permitted to access; and in block S120, authenticating the first application based on the third identity information.

[0014] This variation of method S100 further includes, during a second period following the first period, in block S130, monitoring a set of resources corresponding to execution of the first application on the computing platform; and in block S148, issuing a command to transition the computing platform to a secure state in response to detecting access by the first application to a first resource within the set of resources, where the first resource is excluded from the subset of resources.

[0015] 2. Application Generally, by being executed by a computer system (hereinafter referred to as "the system"), the blocks of method S100 associate a computing platform (e.g., a machine, a robot, a vehicle) with a security device capable of performing a functionally safe operation, and instantiate a security agent (on the computing platform) that manages security and safety on the computing platform in cooperation with the security device.

[0016] More specifically, by being executed by the system, the blocks of method S100 authenticate the security device based on pre-provided information stored in the security device, access a configuration profile that defines identity information associated with a set of a security agent, an operating system, and applications executed on the computing platform, authenticate the configuration profile based on the pre-provided information, and authenticate the set of the security agent, the operating system, and the applications (based on the identity information) before executing them on the computing platform.

[0017] Therefore, by being executed by the system, the blocks of method S100 can verify that the configuration profile corresponds to the computing platform and the security device, whereby the system can verify, based on the configuration profile, that the set of the security agent, the operating system, and the applications executed on the computing platform are genuine, unmodified, and permitted to be executed on the computing platform.

[0018] 2.1 Violation and Response of Security Policy Furthermore, by being executed by the system, the blocks of method S100 establish a chain of trust (starting from the security device) that extends through the security agent to the operating system and a set of applications, whereby the security agent and the security device can perform security and / or safety actions associated with the computing platform.

[0019] Furthermore, by being executed by the system, the blocks of method S100 access a configuration profile that defines security policies associated with the application, monitor the execution of the application on the computing platform, and, in response to detecting a violation of the security policy, perform actions such as issuing a command to transition the computing platform to a preset state (e.g., a secure state).

[0020] Thus, by combining a computing platform (which does not meet the functional safety standard and does not include security functions) with a security device, the system can extend the functional safety and security functions of the security device to the computing platform via the security agent, thereby reducing security vulnerabilities that could lead to system downtime, intellectual property theft, destruction of work products, human harm, and / or death due to attempted or successful intrusion.

[0021] 2.2 Example In one exemplary application, the blocks of method S100 are executed by a system including a first robot (within a set of robots operating in a work zone) and a first security device mounted on the first robot, thereby authenticating the first security device based on encrypted information pre - provided to the hardware security module of the first security device, accessing a configuration profile that defines identity information associated with a security agent, an operating system, and an object - detection application executed by the first robot, authenticating the configuration profile based on the encrypted information, and initializing a security agent on the first robot.

[0022] In this example, the blocks of method S100 are executed by a security agent on the first robot, thereby authenticating at the first security device, accessing the configuration profile, and authenticating the operating system and the object - detection application based on the identity information defined in the configuration profile.

[0023] Furthermore, the blocks of method S100 are executed by a security agent on the first robot, thereby accessing a configuration profile (associated with the object - detection application) that further defines a security policy defining a subset of memory addresses to which the object - detection application is permitted access, and monitoring the execution of the object - detection application. In response to detecting an access (by the object - detection application) to a memory address excluded from the subset of memory addresses, the security agent issues a command to the first security device to transition the first robot to a safe state. Thereafter, the first security device sends a signal to an emergency stop device (coupled to the first robot) to transition the first robot to a safe state.

[0024] Accordingly, the blocks of method S100, when executed by the first robot and the first security device, verify and monitor the execution of the object detection application on the first robot, and in response to detecting an unexpected execution behavior of the object detection application (which may indicate a cyber attack), transfer the first robot to a safe state. Thus, the system enables each robot (within the set of robots) to detect a security violation and locally trigger a safety-critical response, thereby preventing or reducing damage to work products, human injury, and / or death in the set of robots or the work area.

[0025] 2.2 Violation and Response of Operating System Security Policy The method S100 described herein, when executed by a security agent running on a computing platform, monitors the execution of applications on the computing platform and executes an action in response to detecting a violation of the security policy associated with the application. However, the security agent can similarly execute the blocks of method S100 to monitor the execution of the operating system on the computing platform and execute an action in response to detecting a violation of the security policy associated with the operating system.

[0026] 3. Terms In general, the "private key" referred to herein is a key associated with a specific entity (e.g., a controller, a device) in a set of devices, and is a key known only to that specific entity and the key server.

[0027] In general, the "symmetric key" referred to herein is a cryptographic key used for encryption and decryption.

[0028] Generally, as used herein, an "asymmetric key pair" is a pair of cryptographic keys (associated with a particular entity) that includes a public key and a private key.

[0029] 4. System Overall, as shown in FIG. 1, the system can include a computing platform, a security device communicatively coupled to the computing platform, and an administrative server (e.g., the computing platform). The computing platform and the security device can be communicatively coupled to the administrative server via a communication network (e.g., a local area network, a wide area network, the Internet).

[0030] Furthermore, the system can include a user device (e.g., a status indicator, a control panel, a terminal, a mobile device, a smartphone) communicatively coupled to the security device, the computing platform, and / or the administrative server. In one example, the user device can be communicatively coupled to the security device and / or the computing platform via a direct communication channel over the communication network. In another example, the user device can be communicatively coupled to the security device and / or the computing platform via the administrative server. In yet another example, the user device can be coupled (e.g., directly coupled) to the security device and / or the computing platform.

[0031] The system can include additional computing platforms and / or security devices communicatively connected to a management server via a communication network. More specifically, the system can include a set of computing platforms and a set of security devices, with each security device (within the set of security devices) corresponding to a computing platform within the set of computing platforms. For example, each security device (within the set of security devices) can be mounted on the corresponding computing platform within the set of computing platforms.

[0032] The system can include one or more security devices, one or more computing platforms and / or additional user devices communicatively connected to a management server.

[0033] 5. Computing Platform Generally, computing platforms can include sensors (e.g., radar sensors, LiDAR sensors, ultrasonic sensors, infrared cameras), machines, robots, vehicles (e.g., autonomous vehicles, semi-autonomous vehicles), control systems, emergency stop systems (e.g., line break sensors, emergency stop buttons) and / or industrial systems (e.g., manufacturing systems, agricultural systems, construction systems, power systems, transportation systems), etc.

[0034] In one embodiment, a computing platform can include a set of resources, such as a set of processors, volatile memory (e.g., random access memory or "RAM"), non-volatile memory (e.g., flash storage), input / output interfaces, a set of network interfaces (e.g., wireless local area network interface, wired local area network interface, Bluetooth network interface), input devices (e.g., sensors, user interfaces), output devices (e.g., motors, actuators, hydraulic arms), and the like.

[0035] Furthermore, the computing platform can further include an operating system (or kernel) and a set of applications (e.g., stored in non-volatile memory). The computing platform can utilize the set of resources to execute the operating system and / or the set of applications, such as an object detection application and a path planning application.

[0036] In another embodiment, the computing platform can include a security agent that manages the security of the computing platform in cooperation with a security device and / or a management server, as described below.

[0037] 5.1 Machine Identity Generally, a computing platform can indicate a machine identity that uniquely identifies the computing platform within a set of computing platforms. For example, the computing platform can indicate the machine identity based on a serial number that uniquely identifies the computing platform.

[0038] In one embodiment, a computing platform can present a machine identity based on a set of hardware-specific elements of the computing platform. In one example, the computing platform can present a machine identity based on a unique identifier embedded in a chip (such as a unique identifier of a processor) associated with a processor of the computing platform. In another example, the computing platform can present a machine identity based on a network interface hardware address (such as a media access controller address or "MAC address") associated with a network interface of the computing platform.

[0039] Additionally or alternatively, the computing platform can present a machine identity based on cryptographic information (such as a private key, a symmetric key, an asymmetric key pair) correlated with a set of hardware-specific elements of the computing platform.

[0040] Thus, a particular computing platform (within a set of computing platforms that may be mass-produced with the same build) can be uniquely identified based on its unique machine identity. As such, the system can ensure that this particular computing platform includes appropriate firmware, software, configuration information, licenses, and other information corresponding to its machine identity.

[0041] 6. Security Device Generally, a security device can perform security-critical diagnostic and control functions. For example, the security device can include hardware and / or software that meets functional safety standards (such as IEC61508, ISO13849, ISO26262).

[0042] In one embodiment, the security device can include a security subsystem configured to perform functionally safe operations, such as output of commands, input validation, command verification, system health monitoring, encapsulation of communication integrity, and / or output control, to transition a corresponding computing platform (or group of computing platforms) to a secure state, as described in U.S. Patent Application No. 16 / 937,299, U.S. Patent Application No. 17 / 856,661, and U.S. Patent Application No. 18 / 081,833.

[0043] Furthermore, the security agent can cooperate with the security device to perform security-critical diagnostic and control functions as well (on the computing platform).

[0044] In one embodiment, the security device, in cooperation with a security agent running on the computing platform, can authenticate software (e.g., a set of security agents, operating systems, applications) running on the computing platform according to a configuration profile associated with the computing platform, monitor the execution of software on the computing platform, detect violations of security policies (defined by the configuration profile) based on the execution of software on the computing platform, and perform actions corresponding to such violations according to actions specified by the security policies.

[0045] Accordingly, by combining a computing platform (which may not meet functional safety standards and may not include security functions) with a security device, the system can extend the functional safety and security functions of the security device to the computing platform via a security agent, thereby reducing security vulnerabilities that could lead to system downtime, intellectual property theft, destruction of work products, personal injury, and / or death due to attempted or successful intrusion.

[0046] 6.1 Architecture of Security Device Generally, a security device can include a set of resources, such as a set of controllers, volatile memory (e.g., RAM), non-volatile memory (e.g., flash storage), a set of network interfaces (e.g., wireless local area network interface, wired local area network interface, Bluetooth network interface), input / output interfaces, and / or a hardware security module, etc. Further, the security device can further include firmware, an operating system (or kernel), a set of applications, and / or logic.

[0047] In one embodiment, the security device can include a set of resources, which includes a first controller (e.g., a first safety controller), a second controller (e.g., a second safety controller), a third controller (e.g., a security controller), and a communication bus. The communication bus can support bidirectional communication between the first controller and the second controller, bidirectional communication between the first controller and the third controller, and bidirectional communication between the second controller and the third controller.

[0048] In one embodiment, the first controller can include an arithmetic logic unit (hereinafter, "ALU"), a volatile memory (e.g., RAM), and a non-volatile memory (e.g., flash storage). The ALU can execute arithmetic and logical operations based on computer instructions executed by the first controller. The RAM can temporarily store data retrieved from storage for performing calculations. The flash storage can store data and / or instructions programmed into the first controller. The first controller can further include an input / output interface, an internal bus, and / or an internal oscillator. The first controller can include fewer components or additional components.

[0049] The second controller can include components similar (e.g., similar, identical) to those of the first controller. For example, the first controller and the second controller may each be redundant controllers that include the same components.

[0050] Furthermore, the third controller can include components similar (e.g., similar, identical) to those of the first controller. The third controller can further include a network interface (or a set of network interfaces) for communication via a communication network.

[0051] 6.2 Identity of Security Device Generally, a security device can indicate a machine identity that uniquely identifies the security device within a set of security devices. For example, the security device can indicate the machine identity based on a serial number that uniquely identifies the security device.

[0052] In one embodiment, a security device can indicate a machine identity based on a set of elements specific to the security device's hardware. In one example, a computing platform can indicate a machine identity based on a unique identifier embedded in a chip of the security platform, such as a unique identifier associated with a controller of the security device and / or a unique identifier associated with a hardware security module. In another example, a security device can indicate a machine identity based on a network interface hardware address (e.g., a MAC address) associated with a network interface of the security device.

[0053] Accordingly, a particular security device (within a set of security devices) can be uniquely identified based on this unique machine identity. Thus, the system can ensure that this particular security device includes appropriate firmware, software, configuration information, licenses, and other information corresponding to its machine identity.

[0054] 6.3 Hardware Security Module Generally, a security device can include identity information associated with the security device and the computing platform. The security device can use the identity information to authenticate elements (e.g., hardware, software) of the security device and / or the computing platform.

[0055] In one embodiment, a security device can store identity information including encryption information such as a private key, a symmetric key, an asymmetric key pair for device identification, and / or an asymmetric key pair for communication.

[0056] In another embodiment, the security device can store identity information including the machine identity of the security device and / or the machine identity of the computing platform (e.g., the machine identity of the computing platform corresponding to the security device).

[0057] In another embodiment, the security device can store identity information associated with a first set of resources included in the security device. More specifically, the security device can store identity information including encryption information correlated with a set of hardware-specific elements of the security device. For example, the security device can store identity information including encryption information correlated with a unique identifier embedded in the chip of the security device (e.g., a unique identifier associated with the controller of the security device, a unique identifier associated with the hardware security module) and / or a network interface hardware address (e.g., MAC address) associated with the network interface of the security device.

[0058] In one embodiment, the security device can store identity information associated with the firmware, operating system (or kernel), set of applications, and / or logic of the security device. In one example, the security device can store identity information including identifiers (e.g., unique identifiers, version numbers) of each application and / or logic within the firmware, operating system, and set of applications. In another example, the security device can store identity information including encryption information (e.g., private key, asymmetric key pair) correlated with the identifier.

[0059] In another embodiment, the security device can store identity information associated with a second set of resources included in the computing platform. More specifically, the security device can store identity information that includes encrypted information correlated with a set of hardware-specific elements of the computing platform. For example, the security device can store identity information that includes encrypted information correlated with a unique identifier embedded in a chip of the computing platform (e.g., a unique identifier associated with a processor of the computing platform) and / or a network interface hardware address (e.g., a MAC address) associated with a network interface of the computing platform.

[0060] In one embodiment, the security device can store identity information within the hardware security module of the security device. More specifically, the hardware security module can provide (or "pre-provide") identity information (or a portion of the identity information) before deployment and / or at runtime of the security device.

[0061] 7. Security Agent In one embodiment, the computing platform can include a security agent that cooperates with a corresponding security device and / or management platform.

[0062] In one example, a security agent (running on the computing platform) can cooperate with the security device to authenticate a set of the security agent, the operating system, and / or applications on the computing platform according to a configuration profile, as described below.

[0063] In another example, a security agent can monitor the execution of a set of applications on a computing platform to generate runtime execution metrics, detect violations of security policies (defined by a configuration profile) during the execution of the set of applications, and respond to such violations according to actions specified by the security policies. In this example, the security agent can send (to a management server) alerts indicating runtime execution metrics and / or violations.

[0064] 8. Management Server Generally, a management server can generate a set of configuration profiles, where each configuration profile defines identity information associated with security agents, operating systems, and / or applications included in a computing platform, and a set of security policies associated with the security agents, operating systems, and / or applications.

[0065] In one embodiment, the management server can generate a configuration profile based on identity information associated with a security device corresponding to the computing platform. More specifically, the management server can generate a configuration profile based on encrypted information that correlates with a unique identifier associated with the security device (e.g., a unique identifier of a controller, a unique identifier of a hardware security module, a MAC address), thereby uniquely mapping the configuration profile to the security device.

[0066] Accordingly, in order for the management server to generate each configuration profile uniquely mapped to a security device and the corresponding computing platform, the security agent running on the security device and / or the computing platform can authenticate applications on the computing platform based on the configuration profile securely stored in the security device and the corresponding identity information. For this reason, the system can uniquely identify applications running on the computing platform and impose specific security policies applicable to those applications during execution on the computing platform.

[0067] 8.1 Registration of Security Device Generally, for each security device within a set of security devices, the management server can store identity information associated with the security device. For example, the management server can store identity information including a machine identity associated with the security device.

[0068] In one embodiment, the management server can receive registration information that links a security device (within a set of security devices) to a user identity associated with a user (e.g., an operator, a group of operators, an organization), thereby linking the security device to a group of computing platforms associated with the user identity.

[0069] In one example, the management server can receive registration information that specifies a first serial number of a first security device (within a set of security devices) and a first user identity within a set of user identities. Thereafter, the management server can link the first security device to a group of computing platforms associated with the first user identity.

[0070] In another example, the management server can receive registration information that specifies the first serial number of the first security device and the second serial number of the first computing platform within a group of computing platforms associated with the first user identity. The management server can then link the first security device to the first computing platform.

[0071] In response to linking a security device to a user identity and / or a computing platform, the management server can generate a configuration profile that defines a set of valid software for the computing platform. More specifically, the management server can generate a configuration profile that defines identity information for a set of security agents, operating systems, and / or applications on the computing platform, as described below.

[0072] 8.2 Registration of Software In general, the management server can store verification information associated with software (e.g., security agents, operating systems, applications) deployed on a computing platform.

[0073] In one embodiment, the management server can store verification information associated with a set of valid instructions that represent a security agent, a set of valid instructions that represent an operating system, and / or a set of valid instructions that represent each application within a set of applications. For example, the management server can receive verification information and / or those sets of valid instructions from one or more software developers (associated with the set of security agents, operating systems, and / or applications) during a software registration process.

[0074] Therefore, based on the verification information, the system can authenticate the software executed on the computing platform, thereby verifying that the software executed on the computing platform is genuine and has not been modified.

[0075] 9. Configuration Profile Generally, the management server can generate a configuration profile that defines the identity information associated with a set of security agents, operating systems, and / or applications included in the computing platform, and a set of security policies associated with the security agents, operating systems, and applications.

[0076] 9.1 Computing Platform Configuration In one embodiment, the management server can receive the configuration of the computing platform associated with the user identity and generate a configuration profile based on that configuration. More specifically, the management server can receive a configuration that defines the operating system (or kernel) and applications deployed and executed on the computing platform. Thereafter, the management server can generate a configuration profile that defines the first identity information associated with the security agent, the second identity information associated with the operating system, and the third identity information associated with the application. Further, the management server can generate a configuration profile based on the fourth identity information associated with the security device linked to the computing platform.

[0077] For example, the management server can receive, from a user device associated with the user identity, a first configuration for a first computing platform within a group of computing platforms associated with the user identity, the configuration defining a first operating system within a set of operating systems (e.g., a first operating system indicating an identifier of a first version) and a subset of applications within a set of applications, the subset of applications including a first application (e.g., an object detection application indicating an identifier of a second version) and a second application (e.g., a path planning application indicating an identifier of a third version).

[0078] In this example, in response to receiving the first configuration from the user device, the management server can generate a first configuration profile based on the first configuration. More specifically, the management server can generate a first configuration profile defining first identity information associated with a security agent, second identity information associated with the first operating system, third identity information associated with the first application, and fourth identity information associated with the second application.

[0079] Furthermore, in this example, the management server can generate a first configuration profile based on fifth identity information associated with a first security device linked to a first computing platform. More specifically, the management server can generate a first configuration profile based on fifth identity information including encryption information correlated with a unique identifier of a hardware security module associated with the first security device, for example, encryption information correlated with a unique identifier incorporated in a chip of the security platform (e.g., a unique identifier associated with a controller of the first security device, a unique identifier associated with the hardware security module), and / or encryption information correlated with a network interface hardware address (e.g., a MAC address) associated with a network interface of the first security device.

[0080] Therefore, since the management server generates a first configuration profile based on fifth identity information associated with the first security device, the first security device can authenticate the first configuration profile based on pre-provided identity information (matching the fifth identity information) within the hardware security module of the first security device. Thus, the first security device can ensure that the first configuration profile corresponds to the first security device and the first computing platform.

[0081] In one embodiment, the management server can generate a configuration profile that further defines encryption information associated with secure communication. For example, the management server can generate a configuration profile that further defines a set of symmetric keys and / or a set of asymmetric key pairs, and use them to enable a security device and / or a computing platform (e.g., a security agent running on the computing platform) to participate in secure communication with other devices.

[0082] 9.2 Identity Information Generally, the management server can generate a configuration profile that defines identity information for a set of security agents, operating systems (or kernels), and / or applications deployed and / or executed on a computing platform. Additionally, the management server can generate a configuration profile based on the identity information of a security device corresponding to (e.g., linked to) the computing platform.

[0083] 9.2.1 Identity Information of Security Agent In one embodiment, the management server can generate a configuration profile that defines first identity information associated with a security agent. In one example, the management server can generate a configuration profile that defines first identity information including an identifier of the security agent (e.g., a unique identifier, a version number). Additionally or alternatively, the management server can generate a configuration profile that defines first identity information including encryption information (e.g., a private key, an asymmetric key pair) correlated with the identifier of the security agent. In another example, the management server can generate a configuration profile that defines first identity information including verification information associated with a valid set of instructions indicating the security agent. The management server can generate a configuration profile that defines first identity information including other information associated with the security agent.

[0084] 9.2.2 Identity Information of Operating System and Application In one embodiment, the management server can execute similar methods and techniques to generate a configuration profile that defines respective identity information associated with each application within a set of operating systems (or kernels) and / or applications. For example, the management server can generate a configuration profile that defines respective identity information defining an identifier of a software element (e.g., an operating system, an application) (e.g., a unique identifier, a version number), encryption information (e.g., a private key, an asymmetric key pair) correlated with the identifier of the software element, and / or verification information associated with a valid set of instructions indicating the software element.

[0085] 9.3 Security Policy Generally, the management server can generate a configuration profile that further defines a set of security policies. More specifically, the management server can generate a configuration profile that further defines a set of security policies, and each security policy (within the set of security policies) is associated with a security device and / or a computing platform associated with the configuration profile.

[0086] In one embodiment, the management server can generate a configuration profile that further defines a set of security policies, and each security policy (within the set of security policies) defines a rule and a first action corresponding to a violation of the rule. Additionally or alternatively, the management server can generate a configuration profile that further defines each security policy (within the set of security policies), and each security policy defines a rule and a second action corresponding to compliance with the rule. The management server can generate a configuration profile that defines a security policy, and the security policy defines a set of rules and a set of actions corresponding to a violation (or compliance) of each rule within the set of rules.

[0087] 9.3.1 Security Policy: Authentication Generally, the management server can generate a configuration profile that further defines a security policy associated with authentication. More specifically, the management server can generate a configuration profile that defines a security policy associated with the authentication of a set of security devices, configuration profiles, security agents, operating systems, and / or applications.

[0088] In one embodiment, the management server can generate a configuration profile that defines security policies associated with authentication during the initialization period (e.g., boot, startup) of a set of security devices, configuration profiles, security agents, operating systems, and / or applications.

[0089] For example, the management server can generate a configuration profile that defines a first security policy, where the first security policy defines rules for authenticating an application (e.g., during the initialization period of the application, prior to the runtime execution period) based on identity information associated with the application, and actions corresponding to violations of the first security policy (i.e., the rules). More specifically, the management server can generate a configuration profile that defines a security policy that defines actions corresponding to the detection of authentication failure of an application (during the initialization period of the application) based on identity information associated with the application.

[0090] Additionally or alternatively, the management server can similarly generate a configuration profile that defines a second security policy associated with authentication during the runtime execution period (e.g., following the initialization period) of a set of security devices, configuration profiles, security agents, operating systems, and / or applications.

[0091] 9.3.2 Security Policy: Access and Use of Resources Generally, the management server can further generate a configuration profile that defines security policies associated with access to a set of resources of a computing platform. More specifically, the management server can generate a configuration profile that defines security policies associated with access to a set of resources of a computing platform by a set of security agents, operating systems, and / or applications.

[0092] In one embodiment, the management server can generate a configuration profile that defines a security policy that defines a subset of resources (e.g., processor resources, memory resources, network interface resources, input / output device resources) within a set of resources of a computing platform that a set of security agents, operating systems, and / or applications are permitted to access (e.g., during execution), and an action corresponding to the detection of a security policy violation (e.g., access to a resource excluded from the subset of resources).

[0093] In one example, the management server can generate a configuration profile that defines a third security policy that defines a subset of memory addresses within a set of resources of a computing platform that a first application is permitted to access during execution, and a third action corresponding to the detection of access (or an attempt to access) by the first application to a first memory address excluded from the subset of memory addresses.

[0094] In another example, the management server can generate a configuration profile that defines a fourth security policy that defines a subset of network interfaces within a set of resources of a computing platform that a first application is permitted to access during execution, and a fourth action corresponding to the detection of access (or an attempt to access) by the first application to a first network interface excluded from the subset of network interfaces.

[0095] In another embodiment, the management server can generate a configuration profile that defines a fifth security policy that defines a model characterizing the expected usage patterns (e.g., execution time, memory footprint, data rate of network messages) of a subset of the resources in execution, and a fifth action corresponding to detecting that the difference between the usage pattern and the first model exceeds a threshold (e.g., 10%, 25%).

[0096] Accordingly, the system can define a subset of the resources of the computing platform (to which the application has access permission) based on the expected execution behavior of the application, and enforce access to the subset of resources during execution, thereby enabling the system to detect abnormal execution behavior of the application and mitigate security vulnerabilities associated with the abnormal execution behavior.

[0097] 9.3.3 Security Policy: Access to Network Communication Channel In general, the management server can generate a configuration profile that further defines security policies associated with access to a set of network communication channels by a set of security agents, operating systems, and / or applications.

[0098] In one embodiment, the management server can generate a configuration profile that defines a security policy that defines a subset of network communication channels (within the set of network communication channels) to which a set of security agents, operating systems, and / or applications are permitted access (e.g., during execution), and an action corresponding to detecting a violation of the security policy (e.g., access to a network communication channel excluded from the subset of network communication channels).

[0099] 9.3.4 Security Policy: Timing of Network Messages Generally, the management server can generate a configuration profile that further defines security policies associated with network messages generated and / or sent by a set of security agents, operating systems, and / or applications.

[0100] In one embodiment, the management server can generate a configuration profile that defines a security policy that defines periodic network messages at preset time intervals (e.g., 200 milliseconds, 5 minutes, 1 hour) and actions corresponding to the detection of security policy violations (e.g., detection of the absence of network messages during a time interval that exceeds a preset time interval).

[0101] 9.3.5 Security Policy: Action Generally, the management server can generate a configuration profile that defines a security policy that defines one or more actions corresponding to security policy violations, such as recording events associated with the violation, sending a notification indicating the violation to a user device and / or the management server, prompting the user device for confirmation of the violation, isolating the application associated with the violation, and / or sending a command to migrate the computing platform to a secure state, as described below.

[0102] 10. Authentication Generally, the system can execute a series of authentication processes to establish the trust of security devices and computing platforms. More specifically, during the initialization period (e.g., before the runtime execution period), the system can authenticate the security device based on the identity information stored in the hardware security module of the security device, and can authenticate the configuration profile generated by the management server based on the identity information stored in the hardware security module of the security device. In response to the authentication of the configuration profile, the system can authenticate the software elements (e.g., security agents, operating systems, application sets) of the computing platform based on the configuration profile.

[0103] 10.1 Authentication of Security Device Block S104 of method S100 indicates authenticating the first set of resources based on the first identity information (stored in the hardware security module) associated with the first set of resources.

[0104] Generally, during the initialization period, a security device (including the first set of resources (e.g., controller, memory, network interface, hardware security module)) can execute an authentication process based on the first identity information (e.g., pre-provided) stored in the hardware security module associated with the security device.

[0105] In one embodiment, in block S102, the security device can execute a secure boot.

[0106] In response to the execution of secure boot, the security device can access the first identity information stored in the hardware security module at block S104 and authenticate the first set of resources based on the first identity information. In one example, the security device can authenticate the first controller (within the first set of resources) based on the first identity information that includes encrypted information correlated with the unique identifier of the first controller. In another example, the security device can authenticate the first network interface (within the first set of resources) based on the first identity information that includes encrypted information correlated with the unique identifier of the first network interface.

[0107] Similarly, the security device can authenticate the firmware, operating system (or kernel), software application, and / or the logic of the security device based on the first identity information.

[0108] Therefore, since the security device can authenticate the elements of the security device based on the trusted identity information stored in the hardware security module, the system can establish the security device as a trust anchor for authenticating the configuration profile, security agent, operating system of the computing platform, and the set of applications on the computing platform. For this reason, the system can extend the chain of trust from the security device to the set of applications based on the trusted identity information within the hardware security module.

[0109] 10.2 Authentication of Configuration Profile Block S106 of method S100 indicates accessing a configuration profile from a management server, and the configuration profile is generated by the management server based on encrypted information correlated with the first identity information.

[0110] Block S108 of method S100 indicates authenticating a configuration profile based on the first identity information.

[0111] Generally, in response to authenticating the resources of a security device, the security device can access the configuration profile and authenticate the authentication profile based on the identity information stored in the hardware security module.

[0112] In one embodiment, in block S106, the security device can access (from the management server) a configuration profile associated with the security device and the corresponding computing platform. More specifically, the security device can receive the configuration profile from the management server via a secure communication channel based on the encrypted information (e.g., the first asymmetric key pair) stored in the hardware security module.

[0113] In another embodiment, in block S108, the security device can authenticate the configuration profile based on the identity information stored in the hardware security module. More specifically, since the management server generates the configuration profile based on the identity information associated with the security device, the security device can authenticate the configuration profile based on the identity information stored in the hardware security module.

[0114] For example, a security device can access a configuration profile from a management server (where the configuration profile is based on first encrypted information correlated with a unique identifier of the hardware security module of the security device), and can access identity information (stored in the hardware security module) that includes second encrypted information correlated with the unique identifier of the hardware security module. In this example, the security device can authenticate the configuration profile in response to detecting a match between the first encrypted information and the second encrypted information. However, if a difference between the first encrypted information and the second encrypted information is detected, the security device can detect a failure to authenticate the configuration profile. In response to detecting a failed authentication, the security device can perform actions such as recording an event, sending a notification to a user device, and / or sending a command to transition the computing platform to a secure state.

[0115] 10.3 Authentication of Security Agent Block S110 of method S100 indicates authenticating a security agent at a security device based on first identity information stored at the security device and associated with the security agent.

[0116] Generally, a computing platform can execute a boot procedure and initialize (e.g., start up) a security agent on the computing platform. The security agent can authenticate at the security device based on a configuration profile that defines identity information associated with the security agent.

[0117] In one embodiment, in block S110, the security agent can perform authentication on the security device based on identity information associated with the security agent, and the identity information (associated with the security agent) is specified in the configuration profile and / or stored in the security device.

[0118] For example, the security agent can perform authentication on the security device based on the identity information associated with the security agent by sending the first identity information (e.g., an identifier, encrypted information correlated with the identifier) associated with the security agent to the security device. In response to receiving the first identity information, the security device can access the configuration profile that defines the second identity information associated with the security agent, and in response to detecting a match between the first identity information and the second identity information, the security device can authenticate the security agent. However, in response to a difference between the first identity information and the second identity information, the system (e.g., the security agent, the security device) can detect a failed authentication of the security agent and perform actions such as recording an event, sending a notification to the user device, and / or sending a command to transition the computing platform to a secure state.

[0119] Therefore, the security agent can cooperate with the security device to authenticate the security agent on the computing platform. Thus, the system can extend trust from the security device to the security agent, thereby enabling the security agent to manage security on the computing platform and perform security-critical responses to security violations.

[0120] 10.4 Authentication of Operating System and Application Block S112 of method S100 indicates accessing a configuration profile from a security device in response to authentication of a security agent, where a first configuration profile defines second identity information associated with an operating system and third identity information associated with a first application.

[0121] Block S114 of method S100 indicates authenticating a configuration profile based on encrypted information correlated with a unique identifier associated with a hardware security module of a security device in response to accessing the configuration profile from the security device, where the encrypted information is stored in the hardware security module.

[0122] The block of method S100 shows authenticating the operating system based on the second identity information in block S116 and authenticating the first application based on the third identity information in block S120.

[0123] Generally, a security agent can access a configuration profile that defines the configuration (e.g., software configuration) of a computing platform. More specifically, a security agent can access a configuration profile that defines identity information associated with an operating system (or kernel) and identity information associated with a first application. A security agent can access a configuration profile that defines additional information (e.g., identity information associated with additional applications).

[0124] In one embodiment, in block S112, the security agent can access the configuration profile from the security device. For example, in response to the security agent being authenticated at the security device, the security agent can receive the configuration profile from the security device via a secure communication channel based on encrypted information (e.g., a second asymmetric key pair) stored in the hardware security module.

[0125] In block S114, in response to accessing the configuration profile, the security agent can authenticate the configuration profile based on the identity information associated with the security device. For example, the security agent can authenticate the configuration profile based on encrypted information that correlates with a unique identifier associated with the hardware security module of the security device.

[0126] Generally, in response to accessing and / or authenticating the configuration profile, the security agent can authenticate a set of the operating system (or kernel) and applications of the computing platform. For example, the security agent can authenticate the set of the operating system (or kernel) and applications during an initialization period prior to the runtime execution period of the set of the operating system and applications.

[0127] In one embodiment, in block S116, the security agent can authenticate the operating system (or kernel) based on the identity information defined in the configuration profile (associated with the operating system).

[0128] For example, a security agent can access an identifier (e.g., a version number) associated with an operating system and can access identity information associated with the operating system defined in a configuration profile. In this example, in response to the security agent detecting a match between the identifier and the identity information associated with the operating system, the security agent can authenticate the operating system.

[0129] Thus, by authenticating the operating system of a computing system, the security agent can extend trust to the operating system including core resources for process management and network communication, whereby the security agent can trust and utilize those core resources.

[0130] However, in response to detecting a difference between the identifier associated with the operating system and the identity information, the security agent can detect a failure to authenticate the operating system and can perform actions such as recording an event, sending a notification to a user device, and / or sending a command to transition the computing platform to a secure state (e.g., an action defined in a security policy of a configuration profile).

[0131] In another embodiment, in block S120, the security agent can perform similar methods and techniques to authenticate a first application. More specifically, in response to authenticating the operating system, the security agent can authenticate the first application based on identity information defined in the configuration profile (associated with the first application).

[0132] For example, a security agent can access an identifier (e.g., a version number) associated with a first application and can access identity information associated with the first application defined in a configuration profile. In this example, the security agent can authenticate the first application in response to detecting a match between the identifier and the identity information associated with the first application.

[0133] Thus, by authenticating the first application of the computing system, the security agent can complete a chain of trust from the security device to the first application.

[0134] The security device can perform similar methods and techniques to execute an action in response to detecting a failed authentication of the first application. For example, in response to detecting a difference between the identifier and the identity information associated with the first application, the security agent can detect a failed authentication of the first application and can perform actions such as recording an event, sending a notification to a user device, isolating the first application, and / or sending a command to transition the computing platform to a secure state (e.g., an action defined in the security policy of the configuration profile).

[0135] Furthermore, the security agent can perform similar methods and techniques to authenticate other applications within the computing platform based on the identity information associated with those applications defined in the configuration profile.

[0136] 10.4.1 Verification of Application Verification Information Additionally or alternatively, the security agent can authenticate an application within a set of applications based on verification information associated with a valid set of instructions that represent the application.

[0137] In one embodiment, the security agent can access a configuration profile that defines identity information (associated with the application), and the identity information includes verification information (such as a cyclic redundancy check value, a checksum value, a cryptographic hash value, other error detection codes) associated with a valid set of instructions that represent the application. The security agent can authenticate the application based on the verification information.

[0138] In one example, the security agent can authenticate an application based on a cyclic redundancy check and verification information of the application. In this example, the security agent accesses verification information that includes a cyclic redundancy check value associated with a valid set of instructions that represent the application, calculates a first value based on the cyclic redundancy check of the application, and authenticates the application in response to verifying a match between the first value and the cyclic redundancy check value.

[0139] In another example, the security agent can authenticate an application based on a verification and a cryptographic hash value included in the verification information of the application. More specifically, the security agent accesses verification information that includes a cryptographic hash value associated with a valid set of instructions that represent the application, calculates a second value based on a cryptographic hash (such as MD5, SHA-1, SHA-256) of the application, and authenticates the application in response to verifying a match between the second value and the cryptographic hash value.

[0140] In another embodiment, the security agent can perform similar methods and techniques to authenticate the security agent and / or the operating system based on verification information (such as cyclic redundancy check values, checksum values, cryptographic hash values, other error detection codes, etc.). In one example, the security agent can authenticate the security agent based on a cyclic redundancy check of the security agent and verification information associated with a valid instruction set representing the security agent. In another example, the security agent can authenticate the operating system based on a cyclic redundancy check of the operating system and verification information associated with a valid instruction set representing the operating system.

[0141] Accordingly, the system can authenticate software executed on the computing platform based on the verification information, thereby verifying that the software executed on the computing platform is genuine and has not been modified.

[0142] 10.4.2 Application Wrapper Generally, the computing platform can initialize an application within an application container (e.g., an application wrapper). For example, the security agent can cooperate with the application wrapper (including the application) to manage the security of the application executed within the application wrapper on the computing platform.

[0143] In one embodiment, at block S118, the security agent can initialize an application within an application wrapper on the computing platform.

[0144] In another embodiment, in block S120, the security agent can authenticate an application based on the application wrapper and the identity information associated with the application. For example, the security agent can verify the content of the application wrapper and, in response to detecting a match between the identifier of the application and the identity information (associated with the application) defined in the configuration profile, authenticate the application. More specifically, the security agent can verify the content of the application wrapper based on the verification information (associated with the application wrapper) defined in the security policy of the configuration profile.

[0145] Accordingly, the system can implement lightweight application wrappers to initialize and authenticate each application on the computing platform, thereby enabling the system to isolate each application on the computing platform and protect the computing platform from security vulnerabilities associated with each application.

[0146] 10.5 Runtime Authentication Generally, the security agent can execute similar methods and techniques as described above during the runtime execution period following the initialization period to periodically authenticate the application.

[0147] In one embodiment, during the runtime execution of the application, the security agent can access a configuration profile that defines a security policy that defines periodic cyclic redundancy checks of the application (based on verification information associated with the application) at preset time intervals (e.g., 5 minutes, 60 minutes).

[0148] In another embodiment, in block S122, the security agent can periodically perform a cyclic redundancy check on the application and the verification information associated with the application at a preset time interval. In response to detecting a failure of the cyclic redundancy check, the security device can perform an action (e.g., the action specified in the security policy).

[0149] Additionally or alternatively, during the runtime execution of the application, the security agent can access a configuration profile that defines a security policy for periodically verifying the application (e.g., based on other verification information such as a cryptographic hash value associated with a valid instruction set indicating the application) at a preset time interval (or another time interval). The security agent can periodically calculate a value based on the cryptographic hash value of the application and perform an action in response to detecting a difference between that value and the cryptographic hash value.

[0150] Thus, the security agent can verify that the application running on the computing platform is genuine and has not been modified during execution.

[0151] Furthermore, the system can perform similar methods and techniques to periodically authenticate the security device, the configuration profile, the security agent, and / or the operating system during the runtime execution of the computing platform.

[0152] 11. Runtime Execution Monitoring Block S130 of method S100 shows monitoring a set of resources corresponding to the execution of a first application on a computing platform.

[0153] Block S132 of method S100 shows generating a first usage pattern of a subset of resources by a first application during execution on a computing platform.

[0154] Block S134 of method S100 shows monitoring a set of network messages from the first application.

[0155] Generally, as shown in FIGS. 2 and 3, in response to authenticating a set of an operating system and applications, a security agent can monitor the runtime execution of the set of the operating system and / or applications on a computing platform.

[0156] In one embodiment, at block S130, a security agent can monitor a set of resources of a computing platform corresponding to the execution of an application on the computing platform. More specifically, the security agent can detect access (or an attempt to access) to a set of resources by an application during execution. In one example, a security monitor can detect a set of memory addresses accessed by an application during execution. In another example, the security agent can detect a network interface and / or an input / output device accessed by an application during execution. In yet another example, the security agent can detect a set of software libraries and / or data accessed by an application during execution.

[0157] In another embodiment, in block S132, the security agent can generate a usage pattern of the resources utilized by the application during execution. For example, the security agent can generate a usage pattern characterizing the use of the processor, memory access, and / or network access by the running application.

[0158] In another embodiment, the security agent can monitor a set of network messages from the application. More specifically, the security agent can monitor a set of network messages transmitted by the application and generate a set of timing metrics associated with the set of network messages. For example, the security agent can generate a first subset of metrics based on the period of the network messages (e.g., the difference between the reception time of a network message and the reception time of the previous network message), a preset period of the set of network messages (e.g., the period defined in the security policy of the configuration profile), and / or the average period of the network messages within the set of network messages. For example, the set of messages can include a set of heartbeat signals, a set of status messages, and / or other data.

[0159] In one embodiment, the security agent can communicate the resource access information and / or usage pattern to a management server and / or a user device, thereby enabling remote monitoring of application execution.

[0160] In another embodiment, a security agent can monitor a set of resources of a computing platform in cooperation with an operating system. Additionally or alternatively, the security agent can monitor a set of resources of the computing platform corresponding to the execution of an application within an application wrapper in cooperation with the application wrapper.

[0161] Additionally or alternatively, the security agent can perform similar methods and techniques to detect access by the running operating system to a set of resources and / or to generate usage patterns of resources utilized by the operating system during execution.

[0162] Thus, the security agent can monitor the runtime execution of the operating system and / or a set of resources of the computing platform, thereby enabling the security agent to detect and respond to security policy violations, as described below.

[0163] 12. Response to Policy Violation Generally, a security agent can access a configuration profile that defines a security policy associated with an application and monitor the execution of the application on the computing platform. In response to detecting a violation of the security policy by the application, the security agent can perform actions defined in the security policy, such as recording events associated with the violation, sending a notification indicating the violation, prompting the user device to confirm the violation, isolating the application, and / or triggering a security-critical response in the computing platform.

[0164] 12.1 Resource Access Violation Block S112 of method S100 indicates accessing a configuration profile from a security device in response to authentication of a security agent, where a first configuration profile defines a first security policy that defines a subset of resources within a set of resources that a first application is permitted to access, and a first action corresponding to a first violation of the first security policy.

[0165] Block S136 of method S100 indicates executing a first action in response to detecting access by a first application to a first resource within a set of resources, where the first resource is excluded from a subset of resources.

[0166] Generally, a security agent can access a configuration profile that defines a security policy that defines a subset of resources that an application is permitted to access, and can detect a violation associated with an access (or attempted access) by the application to a resource that is excluded from the subset of resources. The security agent can execute an action defined by the security policy in response to detecting the violation.

[0167] In one embodiment, in block S112, a security agent can access a configuration profile that defines a security policy that defines a subset of resources (within a set of resources of a computing platform) that an application is permitted to access, and an action corresponding to a first violation of the security policy. The security agent can monitor, in block S130, a set of resources corresponding to the execution of an application on the computing platform, and can execute an action in response to detecting access by the application to a resource that is excluded from the subset of resources in block S136.

[0168] 12.1.1 Example of Event Recording In one example, in block S112, the security agent can access a configuration profile that defines a first security policy that defines a subset of memory addresses to which the application is permitted access and a first action corresponding to a violation of the first security policy, the first action including recording an event associated with the violation. In response to detecting an access by the application to a memory address excluded from the subset of memory addresses, the security agent can, in block S140, record an event associated with the violation, the event identifying first data associated with the violation, such as an application identifier, an identifier of a security device, an identifier of a computing platform, a resource accessed by the application, a date and time of the violation, and the like. The security agent can further record an event that identifies second data associated with a first state of the system (e.g., a security device, a computing platform) during a first period prior to the violation and third data associated with a second state of the system during a second period after the violation.

[0169] In this example, the security agent can record the event on a storage device of the computing platform (e.g., a protected area of the storage device). Additionally or alternatively, the security agent can record the event on a storage device of the security platform and / or record the event on a management server.

[0170] 12.1.2 Example of Notification In another example, in block S112, the security agent can access a configuration profile that defines a second security policy that defines a subset of network interfaces that the application is permitted to access and a second action corresponding to a violation of the second security policy, where the second action includes sending a notification indicating the first violation to a user device (e.g., a user device associated with the computing platform). In response to detecting an application's access to a network interface that is excluded from the subset of network interfaces, the security agent can, in block S142, send a notification (indicating the violation) to the user device. Further, the security agent can also send the notification to a management server.

[0171] In this example, the security agent can access a configuration profile that further defines encryption information (e.g., a third pair of asymmetric keys) associated with secure communication, encrypt a message (including the notification) based on the encryption information, and send the message to the user device and / or the management server.

[0172] 12.1.3 Example of Prompting for Confirmation In another example, in response to detecting a violation of a security policy by an application running on a computing platform, the security agent can perform similar methods and techniques to prompt the user device to confirm the violation. More specifically, in response to detecting an application's access to a resource that is excluded from a subset of resources that the application is permitted to access, the security agent can, in block S144, prompt the user device to confirm the access to the resource.

[0173] Upon receiving (from a user device) a confirmation of access to a resource by an application, the security agent can permit the access to the resource by the application (e.g., via an application wrapper). More specifically, the security agent can permit the access to the source by the application when it receives the confirmation within a preset time period (e.g., within 15 minutes) from (a user device indicating multi-factor authentication).

[0174] In this example, the security agent can prompt a user device associated with a particular operator of the computing platform, a user device associated with an administrator of the computing platform, and / or a user device associated with a user identity corresponding to the computing platform.

[0175] 12.1.4 Example of Application Isolation In another example, in response to detecting a security policy violation by an application on a computing platform, the security agent can perform similar methods and techniques to isolate the application. More specifically, in response to detecting an access by an application (e.g., an application running in an application wrapper) to a resource that is excluded from a subset of resources to which the application is permitted access, the security agent can isolate the application at block S146.

[0176] 12.1.6 Example of Security Response In another example, in response to detecting a security policy violation by an application running on a computing platform, a security agent can execute similar methods and techniques to trigger outputs of commands for security-critical actions on the computing platform, such as transitioning the computing platform to a secure state (e.g., powering off, cutting off the fuel supply). More specifically, in response to detecting an application's access to a resource that is excluded from a subset of resources that the application is permitted to access, the security agent can, at block S148, issue a command (or signal) to transition the computing platform to a secure state.

[0177] In this example, the security agent can issue commands (e.g., a first command) to a security device, a computing platform, a local emergency stop device connected to the computing platform, a remote emergency stop device (or field bus) communicatively connected to the computing platform, and / or other controllers. The security agent can issue a first command (within the set of commands) that exhibits a minimum Hamming distance (e.g., 4, 8) from other commands within the set of commands.

[0178] 12.2 Abnormal Resource Usage Pattern In one embodiment, in block S112, the security agent accesses a configuration profile that defines a security policy that defines a model that characterizes an expected usage pattern of a subset of resources (permitted access) by an application running on a computing platform, and an action corresponding to a difference between the actual (e.g., running) usage pattern of the application and the model (e.g., the expected usage pattern) exceeding a preset threshold (e.g., 5%, 15%). In block S130, the security agent monitors a set of resources corresponding to the execution of an application on the computing platform, generates a first usage pattern of the resources utilized by the application during execution in block S132, and can execute an action in response to detecting that a difference between the first usage pattern and the model exceeds a preset threshold in block S136.

[0179] Accordingly, the security agent can detect unexpected behavior by a running application, thereby making it possible to mitigate security and / or safety vulnerabilities of the computing platform resulting from that behavior.

[0180] 12.3 Violation of Network Messages In another embodiment, in block S112, the security agent accesses a configuration profile that defines a security policy that defines periodic network messages sent from an application at preset time intervals and an action corresponding to a violation of the security policy. In block S134, the security agent monitors a set of network messages sent by the application, and can execute an action in response to detecting that there are no network messages from the application during a first time interval exceeding a preset time interval in block S136.

[0181] Additionally or alternatively, the security agent can monitor the payloads of messages within a set of messages from an application. In response to detecting an impaired state of the application based on the payload, the security agent can perform actions as described above.

[0182] Accordingly, the security agent can detect an impaired state of a running application, thereby reducing security and / or safety vulnerabilities on the computing platform resulting from that state.

[0183] 12.4 Violation of Network Communication Channel In one embodiment, at block S112, the security agent can access a configuration profile that defines a security policy that defines a subset of network communication channels that the application is permitted to access and actions corresponding to security policy violations. At block S130, the security agent can monitor a set of resources corresponding to the execution of the application on the computing platform. More specifically, the security agent can monitor a set of network interfaces within a set of resources of the computing platform and detect a group of network communication channels accessed by the application during execution.

[0184] In block S136, in response to detecting an application's access to a network communication channel that is excluded from a subset of network communication channels, the security agent can execute an action. In one example, the security agent can send a notification to the user device via the management server. In another example, the security agent can issue (to the security device) a command to transition the computing platform to a secure state. In this example, when the security device receives a command to transition the computing platform to a secure state, in block S150, it can send an emergency stop signal to the computing platform.

[0185] 13. Monitoring and Security Response of Security Device Block S160 of method S100 indicates that a status message is periodically sent to the security device at a preset time interval, the status message includes a status indicator within a set of status indicators, and each status indicator within the set of status indicators indicates that the minimum Hamming distance from another status indicator within the set of status indicators is 4.

[0186] Block S162 of method S100 indicates that when it detects the absence of a status message from the security agent during a first time interval that exceeds a preset time interval, it sends a signal to transition the computing platform to a secure state.

[0187] Generally, as shown in FIG. 4, the security device can execute the same methods and techniques as described above in block S106 to access a configuration profile that defines the security policy, monitor the computing platform (and / or the security device) during execution, and execute one or more actions (defined in the security policy) in response to detecting a violation of the security policy.

[0188] In one embodiment, the security device can access a configuration profile that defines a security policy that defines periodic status messages sent from the security agent at preset time intervals (e.g., every 200 milliseconds, 10 seconds, 5 minutes) and actions corresponding to violations of the security policy.

[0189] The security agent can periodically send status messages to the security device at preset time intervals in block S160. More specifically, the security agent can periodically send a status message that includes status indicators within a set of status indicators, where each status indicator within the set of status indicators indicates the minimum Hamming distance (e.g., 4, 8) from another status indicator within the set of status indicators.

[0190] In this embodiment, the security device can monitor a set of status messages sent by the security agent in block S162 and execute an action in response to detecting the absence of a status message from the security agent during a first time interval that exceeds the preset time interval.

[0191] Additionally or alternatively, the security agent can monitor the payload of a status message within a set of status messages from the security agent. In response to detecting a failure state of the security agent based on the payload, the security device can perform an action as described above.

[0192] Accordingly, the security agent can detect a failure state of the security agent during execution, whereby the security device can mitigate security and / or safety vulnerabilities on the computing platform resulting from that state.

[0193] 14. Conclusion The systems and methods described herein can be at least partially embodied and / or implemented as a machine configured to receive a computer-readable medium storing computer-readable instructions. The instructions can be executed by a computer-executable component integrated with an application, applet, host, server, network, website, communication service, communication interface, user computer or mobile device hardware / firmware / software elements, list band, smartphone, or a suitable combination thereof. Other systems and methods of embodiments can be at least partially embodied and / or implemented as a machine configured to receive a computer-readable medium storing computer-readable instructions. The instructions can be executed by a computer-executable component integrated with the devices and networks of the type described above. The computer-readable medium can be stored on any suitable computer-readable medium, such as RAM, ROM, flash memory, EEPROM, optical device (CD or DVD), hard drive, floppy drive, or any suitable device. The computer-executable component can be a processor, although any suitable dedicated hardware device can (alternatively or additionally) execute the instructions.

[0194] Those skilled in the art can make modifications and changes to the embodiments of the present invention without departing from the scope of the present invention as defined in the following claims, as can be understood from the foregoing detailed description, drawings, and claims.

Claims

1. A security agent executing on a computing platform including a set of resources, an operating system, and a first application, During the first period, o authenticating the security agent at a security device based on first identity information associated with the security agent, the first identity information being stored on the security device; o accessing a configuration profile from the security device in response to authentication of the security agent, the configuration profile comprising: - second identity information associated with the operating system; and - third identity information associated with the first application; and A first security policy is defined, the first security policy being a subset of resources in the set of resources to which the first application is permitted to access; and - defining a first action corresponding to a first violation of the first security policy; o authenticating the operating system based on the second identity information; o authenticating the first application based on the third identity information; During a second period following the first period, o monitoring a set of resources corresponding to the execution of the first application on the computing platform; o performing the first action in response to detecting access by the first application to a first resource in the set of resources that is excluded from the subset of resources.

2. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of memory addresses within the set of resources that the first application is permitted to access; and a first action responsive to a first violation of the first security policy, the first action including recording an event associated with the first violation; accessing a configuration profile that defines the first security policy; - A method characterized in that performing the first action includes, in response to detecting an access by the first application to a first memory address in the set of resources that is excluded from the subset of memory addresses, recording an event associated with an access by the first application to the first memory address.

3. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of network interfaces in the set of resources to which the first application is permitted to access; and a first action responsive to a first violation of the first security policy, the first action including sending a notification to a user device indicating the first violation; accessing a configuration profile defining the first security policy; - A method, characterized in that performing the first action includes sending the notification to a user device in response to detecting access by the first application to a first network interface in the set of resources that is excluded from the subset of network interfaces.

4. 4. The method of claim 3, accessing the configuration profile includes accessing a configuration profile that further defines cryptographic information associated with the secure communication; sending the notification to the user device; o encrypting a message including said notification based on said encryption information; o transmitting the message to the user device.

5. 10. The method of claim 1 , Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: a first model characterizing an expected usage pattern of the subset of resources by the first application executing on the computing platform; and a second action corresponding to a second violation of the second security policy, the second violation being characterized by a difference between a usage pattern and the first model exceeding a threshold; the method comprising, during the second period: generating a first usage pattern of the subset of resources by the first application while executing on the computing platform; and o performing the second action in response to detecting that a difference between the first usage pattern and the first model exceeds a threshold.

6. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of resources in the set of resources to which the first application is authorized to access; and a first action responsive to a first violation of the first security policy, the first action including issuing a first command in a set of commands to the security device to transition the computing platform to a secure state, the first command exhibiting a minimum Hamming distance from other commands in the set of commands; accessing a configuration profile defining a first security policy, - A method, characterized in that performing the first action includes issuing the first command to the security device to transition the computing platform to a secure state in response to detecting access to the first resource by the first application.

7. 10. The method of claim 1 , authenticating the first application based on the third identity information; Initializing the first application within an application wrapper on the computing platform; - authenticating the first application based on the application wrapper and the third identity information.

8. 8. The method of claim 7, Accessing a configuration profile defining the first security policy includes: a subset of resources in the set of resources to which the first application is authorized to access; and a first action in response to a violation of the first security policy, the first action including quarantining the first application; and accessing a configuration profile defining a first security policy, monitoring a set of resources corresponding to execution of the first application on the computing platform includes monitoring a set of resources corresponding to execution of the first application within the application wrapper on the computing platform; - A method, wherein performing the first action includes quarantining the first application in response to detecting access to the first resource by the first application.

9. 10. The method of claim 1 , accessing a configuration profile defining the third identity information includes accessing a configuration profile defining third identity information including validation information associated with a valid instruction set indicative of the first application; - A method, wherein authenticating the first application based on the third identity information includes authenticating the first application based on a cyclic redundancy check of the first application and the verification information.

10. 10. The method of claim 9, Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: o a periodic cyclic redundancy check of the first application at a preset time interval; a second action corresponding to a violation of the second security policy; the method comprising, during the second period: o periodically performing a cyclic redundancy check of the first application and the verification information at the preset time interval; and performing the second action in response to detecting a cyclic redundancy check failure of the first application and the validation information.

11. 10. The method of claim 1 , Accessing the configuration profile includes accessing a configuration profile that further defines a second security policy, the second security policy being: o periodic network messages from the first application at pre-defined time intervals; and a second action corresponding to a violation of the second security policy; the method comprising, during the second period: o monitoring a set of network messages from the first application; and performing the second action in response to detecting an absence of network messages from the first application for a first time interval that exceeds the preset time interval.

12. 10. The method of claim 1 , During the first period, by the security agent: - In response to accessing a configuration profile from the security device, the method further includes a step of authenticating the configuration profile based on cryptographic information that correlates with a unique identifier associated with a hardware security module of the security device, the cryptographic information being stored in the hardware security module.

13. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: A first security policy, a subset of resources that the first application is authorized to access; and a first action in response to a first violation of the first security policy, the first action including sending a notification to a management server indicating the first violation; accessing a configuration profile that defines the first security policy; o accessing a configuration profile defining the first security policy, the configuration profile being generated by the management server based on cryptographic information that correlates with a unique identifier associated with the security device; - A method, wherein performing the first action includes sending the notification to the management server in response to detecting access to the first resource by the first application.

14. 10. The method of claim 1 , Accessing a configuration profile defining the first security policy includes: a subset of resources that the first application is authorized to access; and a first action corresponding to the first violation of the first security policy, the first action including prompting a user device to acknowledge the first violation; and accessing a configuration profile defining a first security policy, - A method, characterized in that performing the first action includes, in response to detecting access to the first resource by the first application, prompting an operator device to confirm access to the first resource by the first application.

15. 10. The method of claim 1 , During the second period of time, by the security agent: - The method further comprising the step of periodically sending a status message to the security device at a preset time interval, the status message including a status indicator in a set of status indicators, each status indicator in the set of status indicators indicating a minimum Hamming distance from another status indicator in the set of status indicators of four.

16. A security agent executing on a computing platform including a set of resources and a first application, comprising: During the first period, o authenticating the security agent at a security device based on first identity information associated with the security agent; o in response to authenticating the security agent, accessing a configuration profile from the security device, the configuration profile being generated based on second identity information associated with the security device, the configuration profile comprising: - third identity information associated with the first application; and - defining a first security policy defining a subset of resources within the set of resources that the first application is permitted to access; o authenticating the first application based on the third identity information; During a second period following the first period, o monitoring a set of resources corresponding to the execution of the first application on the computing platform; and in response to detecting access by the first application to a first resource in the set of resources that is excluded from the subset of resources, issuing a command to transition the computing platform to a secure state.

Citation Information

Patent Citations

  • Permission multiplexing method, resource access method based on permission multiplexing and related device

    CN113326498A

  • Systems and methods for safety-enabled control

    US20210026320A1