Data-Driven Secure Computing With Real-Time DAP Policy Enforcement
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure processing techniques for computer hardware and software are constrained by limited functionality and memory access, leading to vulnerabilities that cannot be adaptively addressed in real time, making them susceptible to Zero-Day exploits.
Innovation Solution
A data-driven secure computing paradigm is introduced, where each datum is associated with supplemental data fields (DAPs) that evaluate security policies in real time, ensuring secure data processing by enforcing policies based on inherent data properties and operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional perimeter-based security models are used with constrained capabilities and hard limits on memory space access, then security can be made more credible through exhaustive evaluation of the solution space, but the system becomes vulnerable to Zero-Day exploits and cannot adapt to compromises in real time
Solution Approach 1:
The patent implements dynamic security boundaries that can adapt in real-time based on data properties and policy evaluations. Instead of fixed perimeters, the system uses configurable security policies that are evaluated at runtime based on data-associated properties (DAPs), allowing the security model to dynamically adjust to new threats and compromises without requiring exhaustive re-evaluation of the entire solution space.
Solution Approach 2:
The system changes security parameters dynamically by evaluating data-associated properties (DAPs) and adjusting security policies based on these properties. Each data element carries properties that determine its security requirements, and the system modifies security boundaries and access controls based on these parameter changes, enabling real-time adaptation while maintaining security credibility through property-based enforcement.
2Adaptability or versatility
If arbitrary code execution and segmented memory spaces are implemented, then system versatility and functionality are improved, but the security model becomes more complex and harder to exhaustively evaluate
Solution Approach 1:
The patent applies local quality by associating specific security properties with individual data elements rather than applying uniform security rules across the entire system. Each data element has its own data-associated properties (DAPs) that define its security requirements, allowing arbitrary code to execute with differentiated security boundaries at the data level, thereby managing complexity through localized property-based control.
Solution Approach 2:
The system introduces data-associated properties (DAPs) as intermediaries between arbitrary code execution and security enforcement. These DAPs serve as a mediating layer that translates complex security requirements into evaluable properties attached to data elements, simplifying the security model while supporting versatile code execution through property-based policy evaluation.
3Reliability
If fixed perimeter security barriers are used to control data flow, then security can be guaranteed by controlling data crossing the barrier, but the system cannot adapt to undiscovered vulnerabilities over time
Solution Approach 1:
The patent implements feedback mechanisms where data-associated properties (DAPs) provide continuous information about data security requirements to the policy evaluation system. This feedback loop enables real-time detection and response to potential security issues, allowing the system to adapt to newly discovered vulnerabilities immediately rather than waiting for periodic security updates or exhaustive re-evaluation.
Solution Approach 2:
The system performs preliminary security evaluations by attaching data-associated properties (DAPs) to data elements before they cross security boundaries. Security policies are evaluated in advance based on these properties, allowing the system to prepare appropriate security measures before actual data flow occurs, thereby reducing response time to vulnerabilities while maintaining security guarantees.
Data Source
Figure 1A~1B
Figure 2
Figure 3
AI summary
System and methods for the processing of data in a secure and safe manner are disclosed. Embodiments of such system and methods may ensure the operation of policies in a manner that is dependent on the inherent properties of the data being operated on as well as the operations that are performed on that data.