Dual-CPU Computer Architecture for Malware Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems are vulnerable to malicious code and hacking attempts, as they rely solely on software solutions to handle malfunctions, lacking hardware-based structural complementarity to prevent or mitigate system seizures and malfunctions.

Innovation Solution

A computer architecture with a security management computing unit and a user computing unit, where the security management unit is hardware-connected to I/O devices and auxiliary storage, managing system monitoring and restoration, while the user computing unit runs user programs and OS in isolation, using a separate CPU and memory, and communicates through a dedicated interface, allowing for isolation and protection from malicious code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single CPU structure is used in general personal computers, then device complexity is reduced and cost is minimized, but the system becomes vulnerable to complete failure when malware or hardware issues occur, as there is no isolated backup processing unit

Engineering Contradiction:
Improvesystem reliability against malwareVSAvoidcomputer structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The computer system is divided into two independent processing units: a first CPU for running the operating system and user applications, and a second CPU specifically dedicated to security monitoring and malware detection. This segmentation allows the security functions to operate independently without interfering with normal system operations, while providing a structural defense against complete system compromise.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security monitoring program acts as an intermediary between the two CPUs, receiving data from the first CPU, analyzing it for malicious behavior, and coordinating the response actions. This intermediary layer enables the second CPU to detect and respond to malware threats while maintaining system operational continuity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple CPUs are implemented for security monitoring, then the ability to detect and respond to malware is improved, but additional cost and structural complexity are incurred

Engineering Contradiction:
Improvemalware detection capabilityVSAvoiddual CPU architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The second CPU is specialized exclusively for security monitoring functions, creating a local quality difference between the two processing units. This specialization allows the security CPU to focus its resources on detecting malicious behavior patterns without being burdened by general system operations, improving detection effectiveness while maintaining a relatively simple overall architecture.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If the security monitoring program has full system access to monitor all operations, then malware detection accuracy is improved, but the system becomes vulnerable to privilege escalation attacks where malware could seize administrator rights and compromise the entire system

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidprivilege escalation vulnerability
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

System privileges are segmented and distributed differently to the two CPUs: the first CPU runs with standard user privileges for normal operations, while the second CPU operates with elevated privileges specifically for security monitoring. This segmentation prevents malware running on the first CPU from gaining system-wide administrator access, as the security monitoring functions are isolated to the second CPU's protected environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security monitoring program on the second CPU acts as an intermediary that observes and analyzes system operations without requiring the first CPU to run with full administrator privileges. This intermediary approach enables accurate malware detection while maintaining the principle of least privilege on the main system processor.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If the first CPU runs with administrator privileges for full system control, then system management capability is improved, but malware could exploit these privileges to seize system control and cause damage

Engineering Contradiction:
Improvesystem management capabilityVSAvoidmalware system seizure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

System management functions are segmented between two CPUs: the first CPU handles user-level operations with limited privileges, while the second CPU maintains security-critical administrator functions. This segmentation allows legitimate system management to continue through the secured second CPU even if the first CPU is compromised by malware.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Administrator privileges are applied locally and selectively to the second CPU's security monitoring functions rather than being universally applied to the entire system. This localized privilege assignment enables the security monitoring program to perform necessary administrative tasks while preventing malware on the first CPU from exploiting broad administrator access.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3623978B1Computer having isolated user computing unit
Publication Date: 2024.03.20 KIM E E
  • EP3623978B1 patent drawingFigure 1~2
  • EP3623978B1 patent drawingFigure 3
  • EP3623978B1 patent drawingFigure 4

AI summary

The present invention relates to a computer having an isolated user computing unit for responding to a system seizing attempt by a malicious code and minimizing damage to a system. A computer according to a feature proposed by the present invention comprises: a security management computing unit for managing connected I/O devices and auxiliary storage device unit; and a user computing unit which is isolated from the I/O devices, communicates with the I/O devices via an intercommunication unit responsible for communication between the security management computing unit and the user computing unit, has a separate CPU and memory, and is connected to the security management computing unit. The security management computing unit manages the I/O devices, monitors and restores a system, and monitors and controls the user computing unit, and the user computing unit is isolated from the security management computing unit and executes a user program and a user OS.