Document Isolation via Trusted Memory Segregation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Host computer systems are vulnerable to malware infections, which can lead to security losses, efficiency reductions, and compromised user privacy, as malicious software can be unintentionally downloaded and used to attack other network resources without detection.
Innovation Solution
Implementing document isolation through a host-based firewall and segregation of trusted and untrusted memory spaces, where applications and processes are restricted to operate within sandboxed environments, preventing unauthorized data transfer and communication without explicit user input.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If applications are allowed to run freely on the host computer system, then ease of operation is improved, but security reliability deteriorates due to malware infections
Solution Approach 1:
The patent segments the host computer system into multiple isolated memory spaces (first memory space for trusted applications, second memory space for untrusted applications). This segmentation allows the system to maintain ease of operation by permitting multiple applications to run simultaneously while improving security through spatial isolation that prevents malware from affecting the entire system.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The first memory space is configured with trusted status and full system access, while the second memory space is configured with untrusted status and restricted access. This local quality differentiation enables the system to operate freely with trusted applications while containing potential malware threats in isolated regions.
2Reliability
If memory spaces are segregated into trusted and untrusted environments, then security reliability is improved, but device complexity increases due to additional firewall and isolation mechanisms
Solution Approach 1:
The patent implements self-service mechanisms where the sandbox container process automatically enforces isolation between memory spaces without requiring complex manual firewall configuration. The system self-manages the security boundaries through programmatic isolation mechanisms, reducing the operational complexity despite maintaining strong security isolation.
Solution Approach 2:
The patent introduces a sandbox container process as an intermediary between trusted and untrusted memory spaces. This intermediary manages communication and data transfer between isolated environments, providing a controlled interface that simplifies security management compared to direct firewall rule configurations while maintaining reliable isolation.
3Reliability
If data transfer between memory spaces is restricted without explicit user input, then security reliability is improved, but productivity decreases due to additional user interaction requirements
Solution Approach 1:
The patent implements preliminary action by establishing security boundaries and access control mechanisms before data transfer occurs. The isolation framework is pre-configured to prevent unauthorized data transfer between memory spaces, and legitimate transfers are facilitated through pre-defined user interaction protocols. This approach ensures security reliability while minimizing productivity impact through streamlined user approval processes.
Data Source
AI summary
Methods and systems are disclosed for document isolation. A host computer system may be configured to implement document isolation via one or more of a host-based firewall, an internet isolation firewall, and/or a segregation of a trusted memory space and an untrusted memory space. The host computer system may be configured to access one or more files using a first set of one or more applications and/or processes operating within the trusted memory space and/or a second set of one or more applications and/or processes operating within an untrusted memory space. The host computer system may be configured to open (e.g., always open) the one or more accessed files in the trusted memory space of the host computer system.


