Automated Hardware Software Design Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing system architectures for hardware and software systems fail to ensure information security while considering the interests of authorized users and requirements of functional safety, potentially affecting the realization of user interests and observance of safety requirements during system use.

Innovation Solution

An automated design system that uses a threat model compared to a use model to select hardware and software elements, limiting unauthorized access and ensuring the realization of authorized user interests by constraining threat vectors and methods of configuration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If additional elements are used to ensure information security, then information security is improved, but device complexity increases and may conflict with authorized user interests and functional safety requirements

Engineering Contradiction:
Improveinformation securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by constructing threat models and use models during the design phase before the system is implemented. The automated design system performs model comparison and selects hardware/software elements that inherently limit threat vectors, rather than adding security elements after the system is built. This preliminary security integration avoids later complexity additions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent changes the parameter of security consideration from an afterthought to a fundamental design parameter. By formalizing threat models with specific parameters (threat vectors, methods of realization) and comparing them against use models, the system selects components whose parameters inherently limit threats while satisfying authorized user interests and functional safety requirements.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If system architecture is designed to meet authorized user interests and functional safety requirements, then user interests and safety are improved, but information security may be compromised

Engineering Contradiction:
Improveability to realize authorized user interestsVSAvoidinformation security vulnerabilities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the security analysis into distinct model components: threat models (containing threat vectors and methods) and use models (containing authorized user interests and functional safety requirements). This segmentation allows the automated system to systematically compare each segment and select hardware/software elements that satisfy both sides without compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces model comparison as an intermediary process between threat analysis and system design. The automated design system uses this intermediary to translate security requirements into concrete hardware/software selections that inherently limit threat vectors while enabling authorized uses, rather than directly adding security constraints to the architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If threat vectors are limited through automated design, then information security is improved, but device complexity increases

Engineering Contradiction:
Improveinformation securityVSAvoiddesign process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by creating an automated design system that performs threat model construction, use model construction, model comparison, and hardware/software selection automatically. The system serves itself by using formalized models to make design decisions without manual intervention, reducing the complexity burden on human designers while achieving comprehensive security.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual security analysis and component selection (mechanical process) with an automated computational system. The automated design system uses algorithmic model comparison to select elements that limit threat vectors, substituting human expertise with a systematic computational approach that handles complexity more efficiently.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10867051B2System and method of automated design of hardware and software systems and complexes
Publication Date: 2020.12.15 AO KASPERSKY LAB
  • US10867051B2 patent drawing
  • US10867051B2 patent drawing
  • US10867051B2 patent drawing

AI summary

The present disclosure is directed to methods and systems for automated design of a system of hardware and software. In an exemplary embodiment, such a method comprises constructing, by a hardware processor, a model of use based on an architecture description of the system, constructing, by the hardware processor, threat model based on a threat description indicating known threats to the system, determining use of the system based on a comparison between the model of use and the threat model and selecting a configuration for realizing the system based on a result of the comparison.