Dynamic Security Module for Software Loading Units

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Confidentiality Control Systems lack flexibility in implementing and providing coherence for dynamic security policies that originate from applications, failing to match the confidentiality level of security policies fixed by the operating system.

Innovation Solution

A method and system that associate each software loading unit with security data structures for identification, installation restrictions, and security policy rules, using a dynamic data structure to represent the current security status of the data-processing unit, validated by an autonomous security module to authorize loading, installation, or execution based on security requirements and features.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Confidentiality Control Systems are used to standardize security policies, then security coherence is improved, but flexibility in implementing dynamic security policies from applications deteriorates

Engineering Contradiction:
Improvesecurity coherenceVSAvoidflexibility in implementing dynamic security policies
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments security policies into two distinct types: mandatory security policies (fixed by the operating system) and discretionary security policies (dynamic, originating from applications). This segmentation allows each type to be handled differently, with mandatory policies ensuring security coherence and discretionary policies providing flexibility for application-specific needs.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic security policies that can be modified and updated by applications during runtime, while mandatory security policies remain fixed. This dynamic approach allows the system to adapt to changing security requirements without compromising the overall security framework.

Inventive Principle:
Principle #15Dynamics

2Reliability

If authentication of applications is performed before downloading, then integrity of software is improved, but loss of time in the loading process deteriorates

Engineering Contradiction:
Improveintegrity of softwareVSAvoidtime in the loading process
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs authentication and validation of applications before they are downloaded or executed. Security policies are established in advance, and the system pre-validates application security requirements, ensuring integrity is maintained while minimizing runtime overhead.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Once authentication is completed during the preliminary phase, the system skips repeated validation checks during execution, rushing through the loading process with already-verified security credentials, thus reducing time loss during actual operation.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS8543997B2Secure dynamic loading
Publication Date: 2013.09.24 TRUSTONIC SAS
  • US8543997B2 patent drawing
  • US8543997B2 patent drawing
  • US8543997B2 patent drawing

AI summary

A method for loading, installing and running software, called loading units, having different levels of confidence by a data processing unit (1). The method includes at least associating at least one structure of information data concerning security requirements and characteristics of this loading unit with each loading unit (2, 3, 7); associating a dynamic data structure (10) representative of the state of security in the data processing unit (1) to the data processing unit (1); validating the security requirements and characteristics of each loading unit (2, 3, 7) with regard to the state in the data processing unit (1) contained in the dynamic data structure (10via an autonomous security module (9), and; if the validation is positive, authorizing, via the security module (9), the loading, installation or running of the loading unit (2, 3, 7).