Computer device having a divided security module and security module update method
The split security module with a non-updatable and updatable part, along with an update manager, addresses the challenge of updating kernel-level security modules, enabling rapid and secure updates that enhance the device's resistance to malware.
Patent Information
- Application Number
- JP2023221108
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2020-11-17
- Filing Date
- 2023-12-27
- Publication Date
- 2025-05-30
- Estimated Expiration
- 2040-12-30
AI Technical Summary
Existing security modules installed at the kernel level of computer devices are difficult to update, making them vulnerable to malware attacks, as updating these modules often requires modifying the OS kernel, which is not easily flexible in rapidly changing cybersecurity environments.
A split security module is introduced, comprising a non-updatable part that directly interfaces with the OS kernel and an updatable part that indirectly interfaces with the OS kernel via the non-updatable part, along with an update manager to control updates to the updatable part, allowing for independent updates without affecting the OS kernel.
This solution enables quick and easy updates to the security module, enhancing security by allowing updates to be made independently of the OS kernel, thereby reducing the vulnerability of the computer device to malware attacks.
Smart Images

Figure 0007686058000001 
Figure 0007686058000002 
Figure 0007686058000003
Abstract
Description
Technical Field
[0001] The present invention relates to a security module for a computer device and a method for updating the same.
Background Art
[0002] Malware is a general term for all malicious software that can have an adverse effect on a computer device. Known types of malware include computer viruses, worms, Trojan horses, spyware, adware, rootkits, ransomware, and the like.
[0003] Some of the security modules designed to counter the threat of malware are installed at the kernel level of a computer device and interface with the operating system (OS) kernel to take responsibility for the security of the hardware and processes of the computer device. Such a security module installed at the kernel level is created with code that can hook into the OS kernel in order to monitor the activities of the computer device.
[0004] However, once such a security module is installed on a computer device, it may be difficult to update the security module in some OS environments. That is, in order to upgrade to other code to update the security function of the security module, modification of the OS kernel itself may be required, such as further compiling the OS kernel. Therefore, developers and suppliers of security modules may sometimes have to wait until the next upgrade to the OS kernel itself without quickly updating the security module.
[0005] In some types of operating systems, it is not easy to update the security module, making the computer device vulnerable to malicious attacks. Such inflexibility is not desirable in the rapidly changing cyber security environment these days. One of the elements that can effectively counter malware attacks is the speed and flexibility to quickly and easily update the functions of the security module at a speed that exceeds the rate of change of malware attack strategies.
Summary of the Invention
Problems to be Solved by the Invention
[0006] One object of the present invention is to enable quick and easy updating of a security module installed at the kernel level.
[0007] Another object of the present invention is to enhance the security function of a computer device equipped with a security module installed at the kernel level.
Means for Solving the Problems
[0008] The present invention provides a computer device comprising a split security module and a security module update method.
[0009] A computer device according to an embodiment of the present invention can include an OS kernel and a divided security module. The OS kernel is installed and operates at the kernel level and includes a security callback function. The divided security module is installed and operates at the kernel level and is divided into a non-updatable part and an updatable part. Further, the divided security module includes the non-updatable part that directly interfaces with the OS kernel and is connected to the security callback function, the updatable part that indirectly interfaces with the OS kernel via the non-updatable part, and an update manager that controls the update of the updatable part.
[0010] According to an embodiment of the present invention, the security callback function of the OS kernel is called in response to a specific activity of the computer device, transmits an inquiry to the updatable part via the non-updatable part, and can receive a response to the inquiry from the updatable part via the non-updatable part.
[0011] According to an embodiment of the present invention, the non-updatable part of the security module can be configured by hooking the security callback function so that the security callback function of the OS kernel has code pointing to the non-updatable part.
[0012] According to an embodiment of the present invention, the computer device can further include security software installed and operating at the user level, and the updatable part can interface with the security software.
[0013] According to an embodiment of the present invention, the OS kernel may further include a security function that provides an access control security policy at the kernel level, and at least one of the non-updateable part and the updateable part can interact with the security function of the OS kernel.
[0014] A method for updating a security module of a computer device according to an embodiment of the present invention is a method for updating a security module of a computer device including an OS kernel installed and operating at the kernel level and a divided security module installed and operating at the kernel level. The divided security module may include a non-updateable part that directly interfaces with the OS kernel, an updateable part that indirectly interfaces with the OS kernel via the non-updateable part, and an update manager that controls the update of the updateable part. The method may include: S1, installing the divided security module at the kernel level; S2, receiving a request for updating the divided security module; S3, verifying an update request object that sent the update request; S4, receiving a security module update version corresponding to the updateable part of the divided security module; S5, verifying the received security module update version; and S6, installing the security module update version.
[0015] According to an embodiment of the present invention, the S2 step may be to (a) receive the update request from a user directly connected to the computer device, (b) receive the update request via the server from a user connected to a server linked to the computer device through an internal communication network, (c) receive the update request via the terminal or server and the network from a user connected to a terminal or server linked to the computer device through a network, or (d) receive the update request via the user terminal and the cloud from a user connected to a cloud linked to the computer device through a network.
[0016] According to an embodiment of the present invention, the S3 step can perform at least one of user authentication, server authentication, network authentication, and terminal authentication.
Effect of the Invention
[0017] According to the present invention, a security module installed at the kernel level of a computer device is embodied as a security module divided into a non-updateable part and an updateable part. The non-updateable part directly interfaces with the OS kernel, and the updateable part indirectly interfaces with the OS kernel via the non-updateable part. In this way, it is possible to update only the updateable part of the security module independently of the OS kernel. Therefore, the present invention has the effect of being able to quickly and easily update the security module installed at the kernel level.
[0018] Further, according to the present invention, since the security module can be updated by changing or modifying only the code of the updatable part without changing the non-updatable part directly connected to the OS kernel, it is possible to update the security module without further compiling the OS kernel. Therefore, the present invention has the effect of being immediately updatable without the need to reboot the computer device.
[0019] Also, according to the present invention, when a security module update request is received, the update request object is verified, and when a security module update version is received, the received security module update version is verified. Therefore, security can be further enhanced through double verification of the update request object and the update version.
Brief Description of the Drawings
[0020]
Figure 1
Figure 2
Figure 3
Embodiments for Carrying Out the Invention
[0021] Hereinafter, embodiments of the present invention will be described in detail with reference to the accompanying drawings.
[0022] The present invention can be implemented in various forms and should not be construed as being limited to the embodiments disclosed herein. The disclosed embodiments are provided to fully convey the scope of the present invention to those with ordinary knowledge in the technical field to which the present invention pertains. The principles and features of the present invention can be applied in a very wide variety of embodiments without departing from the scope of the present invention.
[0023] In addition, when describing the embodiments, matters that are well known in the technical field to which the present invention pertains or that are not directly related to the present invention can be omitted from the description in order to clearly convey without obscuring the core of the present invention. In the accompanying drawings, some components are exaggerated, omitted, or illustrated schematically, and the sizes of the components do not fully reflect the actual sizes. Throughout the accompanying drawings, the same or corresponding components are given the same reference numerals.
[0024] All terms used herein, including technical and scientific terms, have the same meaning as those understood by a person having ordinary knowledge in the technical field to which the present invention pertains, unless otherwise defined. On the other hand, even if described in the singular form, it includes plural forms unless clearly indicated otherwise in the context.
[0025] FIG. 1 is a diagram showing various usage environments of a computer device according to an embodiment of the present invention.
[0026] Referring to FIG. 1, the computer device 10 according to an embodiment of the present invention can be used in various environments. For example, user A can directly connect to the computer device 10 and use the computer device 10. As another example, user B can connect to the computer device 10 by connecting to a server 20 connected to the computer device 10 via an internal communication network. As yet another example, user C can connect to the computer device 10 by connecting to a terminal 40 (or server) connected to the computer device 10 via a network 30 such as the Internet. As yet another example, user D can connect a user terminal (not shown) to a cloud 50 connected to the computer device 10 via the network 30 and use the computer device 10.
[0027] The computer device 10 is a computer device including the OS kernel and the divided security modules of the present invention described below, and its type is not particularly limited. The terminal 40 is a term including portable user electronic devices. In some embodiments, the terminal 40 may be a server. The fact that a user uses the computer device 10 includes updating the security module provided in the computer device 10 to a new version.
[0028] FIG. 2 is a diagram showing the OS kernel and security module related configuration of the computer device according to an embodiment of the present invention.
[0029] Referring to FIG. 2, the computer device 10 according to an embodiment of the present invention includes an OS kernel 110 and a security module 120 that are installed and operate at the kernel level. Although FIG. 2 illustrates the computer device 10 focusing on the OS kernel 110 and the security module 120 that are directly related to the present invention, various other known configurations (for example, a processor, a memory, an input / output device, a communication module, etc.) can be provided in the computer device 10.
[0030] The OS kernel 110 includes a security call-back function 112 and a security function 114, and the security module 120 includes a non-updatable part 122, an updatable part 124, and an update manager 126. The OS kernel 110 means the kernel of any OS type, and the OS includes all commercial OSs such as Unix, Linux (registered trademark), Mac, Windows, etc. Since the security module 120 of the present invention is divided into the non-updatable part 122 and the updatable part 124, the security module 120 of the present invention can be referred to as a "split security module".
[0031] The non-updatable part 122 of the security module 120 can be directly interfaced with the OS kernel 110 and connected to the security call-back function 112 of the OS kernel 110. In contrast, the updatable part 124 of the security module 120 indirectly interfaces with the OS kernel 110 via the non-updatable part 122. In this specification, the meaning of interfacing does not refer to a physical interface, but means sending and receiving data and interacting with each other.
[0032] The non-updatable part 122 is not updatable in that the code of the non-updatable part 122 cannot be easily changed or modified without complex procedures such as recompiling the OS kernel 110 itself.
[0033] The updatable part 124 is updatable in that it is easier to change or modify the code compared to the non-updatable part 122. That is, the updatable part 124 can be easily changed or modified without further recompiling the OS kernel 110. Also, the updatable part 124 can be updated immediately without the need to reboot the computer device 10.
[0034] When the security module 120 is installed in the computer device 10, the non-updateable part 122 interfaces directly with the OS kernel 110, and the updateable part 124 interfaces indirectly with the OS kernel 110 via the non-updateable part 122. Such a divided security module 120 provides an appropriate separation between the updateable part 124 and the OS kernel 110. This enables the developer or supplier company of the security module 120 to update the security module 120 independently of the OS kernel 110. That is, the developer or supplier company of the security module 120 can update the security module 120 by changing or modifying only the code of the updateable part 124 without changing the non-updateable part 122 directly connected to the OS kernel 110.
[0035] The security callback function 112 of the OS kernel 110 can be called in response to specific activities of the computer device 10 such as opening a file, opening a network connection, and running an application.
[0036] In the absence of the security module 120, the security callback function 112 of the OS kernel 110 refers to the specific security function 114 of the OS kernel 110. The security function 114 provides access control security policies at the kernel level.
[0037] In the case where there is no security module 120, when the security callback function 112 is called (for example, in response to opening a file), the security callback function 112 queries the security function 114 to request permission to open the file, and the security function 114 returns a response to the query. The response indicates whether the process (e.g., opening and executing the file) is permitted. In the case where there is no security module 120, since such a security mechanism of the OS kernel 110 is fixed, a malicious attacker can easily determine how the security function operates within the OS kernel 110 and can easily decide how to disable the security mechanism. That is, since the fixed security mechanism cannot be easily changed, the attacker has time to develop an attack strategy to avoid the security mechanism of the OS kernel 110. Therefore, the fact that the security module 120, particularly the updatable part 124 of the security module 120, can be dynamically updated can make it difficult for the attacker to disable or avoid the security mechanism.
[0038] Note that when implementing the security module 120 of the present invention, the non-updatable part 122 of the security module 120 may be configured to hook the security callback function 112 of the OS kernel 110. Such hooking means replacing the code in the OS kernel 110 where the security callback function 112 points to the security function 114 with other code where the security callback function 112 points to the non-updatable part 122 of the security module 120 instead of the security function 114. Therefore, when the security callback function 112 is called, it can transmit a query to the non-updatable part 122, and the non-updatable part 122 can transmit the query to the updatable part 124. This provides the security module 120 with the ability to monitor events and / or related data of the computer device 10.
[0039] The updatable part 124 that receives an inquiry can be configured to generate and return a response indicating whether the execution of the process is permitted. That is, the updatable part 124 determines the characteristics of the inquiry (e.g., the type of callback), searches for relevant parameters related to this determination, analyzes the events and / or data related to the inquiry, and can determine whether the analyzed events and / or data are associated with malicious code. Based on such a determination, the updatable part 124 can generate a response to the inquiry and provide the response to the OS kernel 110 via the non-updatable part 122. For example, when the inquiry is related to a request to open a specific file, the updatable part 124 can determine that the request to open the specific file is associated with malicious code and generate a response instructing the interruption of the process of opening the specific file and return it to the OS kernel 110.
[0040] In addition, in some embodiments, the updatable part 124 that receives an inquiry from the OS kernel 110 via the non-updatable part 122 can also interface with the security software 140 installed at the user level of the computer device 10 and operating, and request an analysis of the events and / or data related to the inquiry, a determination of whether there is an association with malicious code, etc.
[0041] Also, in some embodiments, the non-updateable part 122 and / or the updateable part 124 can also be additionally configured to interact with the security function 114 of the OS kernel 110. Such interaction with the security function 114 can occur after the non-updateable part 122 receives an inquiry from the security callback function 112. As an example, the non-updateable part 122 can directly query the security function 114 about the access control security policy of the OS kernel 110. As another example, the updateable part 124 can indirectly query the security function 114 via the non-updateable part 122. Such security policies can be considered when the updateable part 124 generates a response to the query.
[0042] The non-updateable part 122 can be installed to occupy a minimum memory capacity and executed to consume minimum resources. That is, the non-updateable part 122 consists of much less code compared to the updateable part 124, and most of the functions of the security module 120 can be provided by the code of the updateable part 124. The non-updateable part 122 mainly serves as a passage for transmitting inquiries / responses between the OS kernel 110 and the updateable part 124 while providing separation between the OS kernel 110 and the updateable part 124.
[0043] Note that when the update manager 126 of the security module 120 receives a request for an update to the security module 120, it can verify the update request object, and when it receives the security module update version 130, it can verify the received security module update version 130. In this way, security can be further enhanced through double verification of the update request object and the update version. Specific explanations regarding this will be described later with reference to FIG. 3 below.
[0044] FIG. 3 is a diagram showing a method for updating a security module of a computer device according to an embodiment of the present invention. The following description refers to FIGS. 1 to 3.
[0045] First, in step S1, the computer device 10 installs the divided security module 120 as shown in FIG. 2 at the kernel level. The computer device 10 includes an OS kernel 110 that operates installed at the kernel level, and the OS kernel 110 includes a security callback function 112. The divided security module 120 installed in step S1 operates at the kernel level and includes a non-updateable part 122, an updateable part 124, and an update manager 126. The non-updateable part 122 directly interfaces with the OS kernel 110 and is connected to the security callback function 112. The updateable part 124 indirectly interfaces with the OS kernel 110 via the non-updateable part 122, and the update manager 126 controls the update of the updateable part 124. In particular, the non-updateable part 122 of the security module 120 is configured by hooking the security callback function 112 such that the security callback function 112 of the OS kernel 110 has code pointing to the non-updateable part 122.
[0046] Next, in step S2, the computer device 10 receives a request for updating the security module 120 from the user. For example, in various environments as shown in FIG. 1, the computer device 10 can receive an update request. Specifically, the computer device 10 can receive an update request from the directly connected user A via the input device, and can receive an update request from the user B connected to the server 20 via the internal communication network and the server 20, and can receive an update request from the user C connected to the terminal 40 (or server) connected to the computer device 10 via the network 30 via the terminal 40 (or server) and the network 30, and can also receive an update request from the user D connected to the cloud 50 connected to the computer device 10 via the network 30 via the user terminal (not shown) and the cloud 50.
[0047] Next, in step S3, the computer device 10 verifies the update request object. As used herein, the update request object refers to the entity or medium that sends the update request for the security module 120 to the computer device 10, that is, the user, server, network, or terminal. Therefore, step S3 determines the update request object according to the situation where the update request is received in step S2 described above and performs verification, and can include user authentication, server authentication, network authentication, and terminal authentication.
[0048] User authentication is to authenticate whether the user A has the right to request an update when the computer device 10 directly receives an update request from the user A. For this purpose, various known user authentication methods can be applied.
[0049] Server authentication is to authenticate whether the server 20 is a server with a permitted connection, a server with update request permission, etc. when the computer device 10 receives an update request from user B via the server 20. For this purpose, various known server authentication methods can be applied. Also, user authentication can be performed in parallel with server authentication.
[0050] Network authentication is to authenticate whether the network 30 is a reliable network, a network with a permitted connection, etc. when the computer device 10 receives an update request from user C via the network 30 and the terminal 40 (or server), or receives an update request from user D via the network 30 and the cloud 50. For this purpose, various known network authentication methods can be applied. Also, user authentication can be performed in parallel with network authentication.
[0051] Terminal authentication is to authenticate whether the terminal 40 (or server) or the user terminal (not shown) is a terminal with a permitted connection, a terminal with update request permission, etc. when the computer device 10 receives an update request from user C via the network 30 and the terminal 40 (or server), or receives an update request from user D via the cloud 50 and the user terminal (not shown). For this purpose, various known terminal authentication methods can be applied. Also, user authentication and / or network authentication can be performed in parallel with terminal authentication.
[0052] Next, when the verification of the update request object in the above-described S3 stage is successfully performed, in the S4 stage, the computer device 10 receives a security module update version 130. The security module update version 130 corresponds to the updatable part 124 of the security module 120 installed in the computer device 10. At this time, the security module update version 130 can be provided in a state stored in a storage medium or downloaded from an update providing server.
[0053] Next, in the S5 stage, the computer device 10 verifies the received security module update version 130. The verification of the security module update version 130 is to diagnose malware in the security module update version 130 corresponding to the updatable part 124 of the security module 120. For this purpose, various known malware diagnosis methods can be applied.
[0054] Next, in the S6 stage, the computer device 10 installs the security module update version 130 that has passed the verification. That is, the computer device 10 replaces the updatable part 124 of the security module 120 installed at the kernel level with the security module update version 130 to complete the update of the security module 120.
[0055] Note that at least some of the above-described S2 to S6 stages can be performed by the update manager 126 of the security module 120.
[0056] The embodiments of the present invention disclosed in this specification and the drawings are merely specific examples presented to easily explain the technical content of the present invention and assist in understanding the present invention, and are not intended to limit the scope of the present invention. It is obvious to those with ordinary knowledge in the technical field to which the present invention pertains that other variations based on the technical idea of the present invention are also feasible besides the embodiments disclosed herein.
Explanation of Reference Numerals
[0057] 10 Computer device 20 Server 30 Network 40 Terminal 110 OS kernel 112 Security callback function 114 Security function 120 Security module 122 Non-updateable part 124 Updateable part 126 Update manager 130 Security module update version 140 Security software
Claims
1. An OS kernel that is installed and operates at the kernel level and includes a security callback function, and a split security module that is installed and operates at the kernel level and is divided into a non-updatable part and an updatable part, The split security module includes: The non-updatable part that directly interfaces with the OS kernel and is connected to the security callback function, The updatable part that indirectly interfaces with the OS kernel via the non-updatable part, An update manager that controls the update of the updatable part, The update manager: Receives an update request for the security module, and when the verification of the update request object is successful, receives a security module update version, and verifies the received security module update version, The update manager: When verifying the update request object, determines whether the update request object is any one of a user, a server, a network, and a terminal according to the situation of receiving the update request, When it is determined that the update request object is the user, executes user authentication, When it is determined that the update request object is the server, executes server authentication to authenticate whether the server is granted update request authority, or executes both the server authentication and the user authentication, When it is determined that the update request object is the network, executes network authentication to authenticate whether the network is a reliable network, or executes both the network authentication and the user authentication, When it is determined that the update request object is the terminal, executes terminal authentication, or executes at least one of user authentication and network authentication together with the terminal authentication. A computer device characterized by this.
2. The security callback function of the OS kernel is called in response to a specific activity of the computer device, transmits an inquiry to the updatable part via the non-updatable part, and receives a response to the inquiry from the updatable part via the non-updatable part. The computer device according to claim 1, characterized in that.
3. The non-updatable part of the security module is configured by hooking the security callback function of the OS kernel so that the security callback function of the OS kernel has code pointing to the non-updatable part. The computer device according to claim 1, characterized in that.
4. Further includes security software installed and operating at the user level, The updatable part interfaces with the security software. The computer device according to claim 1, characterized in that.
5. The OS kernel further includes a security function that provides an access control security policy at the kernel level, At least one of the non-updatable part and the updatable part interacts with the security function of the OS kernel. The computer device according to claim 1, characterized in that.
6. In a method for updating a security module of a computer device including an OS kernel installed and operating at the kernel level and a divided security module installed and operating at the kernel level, The divided security module includes a non-updatable part that directly interfaces with the OS kernel, an updatable part that indirectly interfaces with the OS kernel via the non-updatable part, and an update manager that controls the update of the updatable part. The method includes Step S1 of installing the divided security module at the kernel level; Step S2 of receiving an update request for the divided security module; Step S3 of verifying the update request object that sent the update request; Step S4 of receiving a security module update version corresponding to the updatable part of the divided security module; Step S5 of verifying the received security module update version; Step S6 of installing the security module update version, and includes: Step S3 includes: Determining whether the update request object is any one of a user, a server, a network, and a terminal according to the situation of receiving the update request; When it is determined that the update request object is the user, performing user authentication; When it is determined that the update request object is the server, performing server authentication to authenticate whether the server is granted the update request permission, or performing both the server authentication and the user authentication; When it is determined that the update request object is the network, performing network authentication to authenticate whether the network is a reliable network, or performing both the network authentication and the user authentication; When it is determined that the update request object is the terminal, performing terminal authentication, or performing at least one of user authentication and network authentication together with the terminal authentication. A security module update method for a computer device, characterized by including the above.
7. Step S2 includes: (a) Receiving the update request from a user directly connected to the computer device; (b) Receiving the update request via the server from a user connected to a server connected to the computer device via an internal communication network; (c) Receiving the update request via the terminal or the server and the network from a user connected to a terminal or a server connected to the computer device via a network, or (d) Receiving the update request via the user terminal and the cloud from a user connected to a cloud connected to the computer device via a network. The security module update method for a computer device according to claim 6, characterized by the above.
8. The security module update method of the computer device according to claim 7, wherein the S3 stage performs at least one of user authentication, server authentication, network authentication, and terminal authentication.
Citation Information
Patent Citations
Server device, control method, and program
JP2006215795A
System for updating firmware device and method thereof
JP2008243183A
Using indirection to facilitate software upgrades
US20190102551A1