Document Isolation via Trusted Memory Segregation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Host computer systems are vulnerable to malware infections, which can lead to security losses, efficiency reductions, and compromised user privacy, as malicious software can be unintentionally downloaded and used to attack other network resources without detection.

Innovation Solution

Implementing document isolation through a host-based firewall and segregation of trusted and untrusted memory spaces, where applications and processes are restricted to operate within sandboxed environments, preventing unauthorized data transfer and communication without explicit user input.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are allowed to run freely on the host computer system, then ease of operation is improved, but security reliability deteriorates due to malware infections

Engineering Contradiction:
Improveapplication execution freedomVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the host computer system into multiple isolated memory spaces (first memory space for trusted applications, second memory space for untrusted applications). This segmentation allows the system to maintain ease of operation by permitting multiple applications to run simultaneously while improving security through spatial isolation that prevents malware from affecting the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the system. The first memory space is configured with trusted status and full system access, while the second memory space is configured with untrusted status and restricted access. This local quality differentiation enables the system to operate freely with trusted applications while containing potential malware threats in isolated regions.

Inventive Principle:
Principle #3Local quality

2Reliability

If memory spaces are segregated into trusted and untrusted environments, then security reliability is improved, but device complexity increases due to additional firewall and isolation mechanisms

Engineering Contradiction:
Improvesecurity isolationVSAvoidfirewall configuration
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service mechanisms where the sandbox container process automatically enforces isolation between memory spaces without requiring complex manual firewall configuration. The system self-manages the security boundaries through programmatic isolation mechanisms, reducing the operational complexity despite maintaining strong security isolation.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces a sandbox container process as an intermediary between trusted and untrusted memory spaces. This intermediary manages communication and data transfer between isolated environments, providing a controlled interface that simplifies security management compared to direct firewall rule configurations while maintaining reliable isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If data transfer between memory spaces is restricted without explicit user input, then security reliability is improved, but productivity decreases due to additional user interaction requirements

Engineering Contradiction:
Improvedata transfer controlVSAvoidfile access efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary action by establishing security boundaries and access control mechanisms before data transfer occurs. The isolation framework is pre-configured to prevent unauthorized data transfer between memory spaces, and legitimate transfers are facilitated through pre-defined user interaction protocols. This approach ensures security reliability while minimizing productivity impact through streamlined user approval processes.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10992642B2Document isolation
Publication Date: 2021.04.27 CROGA INNOVATIONS LTD
  • US10992642B2 patent drawing
  • US10992642B2 patent drawing
  • US10992642B2 patent drawing

AI summary

Methods and systems are disclosed for document isolation. A host computer system may be configured to implement document isolation via one or more of a host-based firewall, an internet isolation firewall, and/or a segregation of a trusted memory space and an untrusted memory space. The host computer system may be configured to access one or more files using a first set of one or more applications and/or processes operating within the trusted memory space and/or a second set of one or more applications and/or processes operating within an untrusted memory space. The host computer system may be configured to open (e.g., always open) the one or more accessed files in the trusted memory space of the host computer system.