Dual Computing Environment for Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing devices, such as personal computers and smartphones, are vulnerable to malware attacks due to their single CPU and OS architecture, which exposes sensitive user information to fraudsters and makes it difficult to protect against threats like phishing and man-in-the-browser attacks.

Innovation Solution

Implementing a dual computing environment system with a trusted environment that physically separates security-critical functions from a legacy computing environment, where the trusted environment manages and monitors operations, preventing malware from accessing sensitive information and executing malicious attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single CPU and OS architecture is used in existing computing devices, then the device complexity is reduced and ease of operation is improved, but security and reliability deteriorate due to vulnerability against malware attacks

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computing device is divided into two separate processing environments: a trusted processing environment with a first processor for executing trusted applications, and a legacy processing environment with a second processor for executing untrusted applications. This segmentation isolates security-critical operations from potentially malicious code, preventing malware from compromising the trusted environment while maintaining the benefits of a unified system architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a trusted environment physically separates security functions from legacy environment, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted processing environment is implemented as a nested architecture within the legacy computing device, where the first processor and its associated security functions are embedded within the broader system. This nesting approach allows the trusted environment to provide enhanced security isolation while sharing physical hardware resources, thereby limiting the increase in overall device complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

3Reliability

If a dual computing environment system is implemented, then protection against malware attacks is improved, but ease of operation may deteriorate due to the need for environment management

Engineering Contradiction:
Improveprotection against malwareVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A trusted platform module serves as an intermediary between the trusted and legacy processing environments, managing the interaction and data exchange between the two environments. This mediator abstracts the complexity of environment switching and communication from the user, allowing seamless operation while maintaining security boundaries, thus preserving ease of use.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11188652B2Access management and credential protection
Publication Date: 2021.11.30 BARKAN MORDECAI
  • US11188652B2 patent drawing
  • US11188652B2 patent drawing
  • US11188652B2 patent drawing

AI summary

Secure computer architectures, systems, and applications are provided herein. An exemplary system includes a legacy environment which is an off-the-shelf computing system, a trusted environment device that communicates with a network, and at least one peripheral that is communicatively coupled with the trusted environment device or having an authentication module.