Data-Driven Secure Computing With Real-Time DAP Policy Enforcement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure processing techniques for computer hardware and software are constrained by limited functionality and memory access, leading to vulnerabilities that cannot be adaptively addressed in real time, making them susceptible to Zero-Day exploits.

Innovation Solution

A data-driven secure computing paradigm is introduced, where each datum is associated with supplemental data fields (DAPs) that evaluate security policies in real time, ensuring secure data processing by enforcing policies based on inherent data properties and operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter-based security models are used with constrained capabilities and hard limits on memory space access, then security can be made more credible through exhaustive evaluation of the solution space, but the system becomes vulnerable to Zero-Day exploits and cannot adapt to compromises in real time

Engineering Contradiction:
Improvesecurity credibilityVSAvoidreal-time adaptation capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security boundaries that can adapt in real-time based on data properties and policy evaluations. Instead of fixed perimeters, the system uses configurable security policies that are evaluated at runtime based on data-associated properties (DAPs), allowing the security model to dynamically adjust to new threats and compromises without requiring exhaustive re-evaluation of the entire solution space.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes security parameters dynamically by evaluating data-associated properties (DAPs) and adjusting security policies based on these properties. Each data element carries properties that determine its security requirements, and the system modifies security boundaries and access controls based on these parameter changes, enabling real-time adaptation while maintaining security credibility through property-based enforcement.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If arbitrary code execution and segmented memory spaces are implemented, then system versatility and functionality are improved, but the security model becomes more complex and harder to exhaustively evaluate

Engineering Contradiction:
Improvecode execution capabilityVSAvoidsecurity model complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by associating specific security properties with individual data elements rather than applying uniform security rules across the entire system. Each data element has its own data-associated properties (DAPs) that define its security requirements, allowing arbitrary code to execute with differentiated security boundaries at the data level, thereby managing complexity through localized property-based control.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces data-associated properties (DAPs) as intermediaries between arbitrary code execution and security enforcement. These DAPs serve as a mediating layer that translates complex security requirements into evaluable properties attached to data elements, simplifying the security model while supporting versatile code execution through property-based policy evaluation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If fixed perimeter security barriers are used to control data flow, then security can be guaranteed by controlling data crossing the barrier, but the system cannot adapt to undiscovered vulnerabilities over time

Engineering Contradiction:
Improvesecurity guaranteeVSAvoidresponse time to vulnerabilities
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements feedback mechanisms where data-associated properties (DAPs) provide continuous information about data security requirements to the policy evaluation system. This feedback loop enables real-time detection and response to potential security issues, allowing the system to adapt to newly discovered vulnerabilities immediately rather than waiting for periodic security updates or exhaustive re-evaluation.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary security evaluations by attaching data-associated properties (DAPs) to data elements before they cross security boundaries. Security policies are evaluated in advance based on these properties, allowing the system to prepare appropriate security measures before actual data flow occurs, thereby reducing response time to vulnerabilities while maintaining security guarantees.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3994597B1Systems and methods for data-driven secure and safe computing
Publication Date: 2025.09.10 BEYOND SEMICON D O O
  • EP3994597B1 patent drawingFigure 1A~1B
  • EP3994597B1 patent drawingFigure 2
  • EP3994597B1 patent drawingFigure 3

AI summary

System and methods for the processing of data in a secure and safe manner are disclosed. Embodiments of such system and methods may ensure the operation of policies in a manner that is dependent on the inherent properties of the data being operated on as well as the operations that are performed on that data.