Dual Computing Environment for Malware Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computing devices, such as personal computers and smartphones, are vulnerable to malware attacks due to their single CPU and OS architecture, which exposes sensitive user information to fraudsters and makes it difficult to protect against threats like phishing and man-in-the-browser attacks.
Innovation Solution
Implementing a dual computing environment system with a trusted environment that physically separates security-critical functions from a legacy computing environment, where the trusted environment manages and monitors operations, preventing malware from accessing sensitive information and executing malicious attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single CPU and OS architecture is used in existing computing devices, then the device complexity is reduced and ease of operation is improved, but security and reliability deteriorate due to vulnerability against malware attacks
Solution Approach 1:
The computing device is divided into two separate processing environments: a trusted processing environment with a first processor for executing trusted applications, and a legacy processing environment with a second processor for executing untrusted applications. This segmentation isolates security-critical operations from potentially malicious code, preventing malware from compromising the trusted environment while maintaining the benefits of a unified system architecture.
2Reliability
If a trusted environment physically separates security functions from legacy environment, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The trusted processing environment is implemented as a nested architecture within the legacy computing device, where the first processor and its associated security functions are embedded within the broader system. This nesting approach allows the trusted environment to provide enhanced security isolation while sharing physical hardware resources, thereby limiting the increase in overall device complexity.
3Reliability
If a dual computing environment system is implemented, then protection against malware attacks is improved, but ease of operation may deteriorate due to the need for environment management
Solution Approach 1:
A trusted platform module serves as an intermediary between the trusted and legacy processing environments, managing the interaction and data exchange between the two environments. This mediator abstracts the complexity of environment switching and communication from the user, allowing seamless operation while maintaining security boundaries, thus preserving ease of use.
Data Source
AI summary
Secure computer architectures, systems, and applications are provided herein. An exemplary system includes a legacy environment which is an off-the-shelf computing system, a trusted environment device that communicates with a network, and at least one peripheral that is communicatively coupled with the trusted environment device or having an authentication module.


