Dynamic Software Execution Control for Security Patch Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In information processing apparatuses like PCs, POS terminals, and IoT devices, security patches often go unapplied due to communication issues or lack of operator knowledge, leading to increased vulnerability to computer virus infections and potential damage.

Innovation Solution

An information processing apparatus with a memory unit storing first and second software, where the control unit enables execution of both software sets when a security patch is recently applied, but disables the second software if a predetermined time elapses since the patch, ensuring only the basic software operates if security is compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If the information processing apparatus operates with full functionality (first software and second software enabled), then productivity and ease of operation are improved, but security reliability deteriorates when security patches are not applied timely

Engineering Contradiction:
Improveoperational functionalityVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements dynamic functionality adjustment by enabling the control unit to switch between different software execution states based on security patch application status and time elapsed. The system transitions from a static security model to a dynamic one where the second software is conditionally enabled or disabled, allowing the apparatus to adapt its operational capabilities to current security conditions while maintaining productivity when secure and limiting exposure when vulnerable.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies beforehand cushioning by implementing a time-based safety mechanism that proactively disables the second software after a predetermined period following security patch application. This preemptive measure cushions against potential security vulnerabilities by automatically reducing functionality before a breach can occur, rather than waiting for a security incident to trigger protective actions.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

2Reliability

If the second software is disabled to improve security, then security reliability is improved, but productivity and operational capability deteriorate

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system dynamically adjusts its operational state based on security conditions, transitioning between full functionality and restricted functionality modes. This dynamic approach allows the apparatus to maintain high productivity when security is assured while automatically limiting functionality only when security vulnerabilities are detected, avoiding permanent or excessive restrictions on operational capability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the operational parameter of software execution status based on security patch timing. By monitoring the time elapsed since security patch application and comparing it against a predetermined threshold, the system adjusts the execution parameter of the second software from enabled to disabled state, creating a time-based security gate that balances productivity and security without permanently sacrificing functionality.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If security patch application is made mandatory to improve security, then security reliability is improved, but ease of operation deteriorates due to operational restrictions

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service security management by enabling the system to automatically monitor security patch status, calculate elapsed time, and autonomously disable the second software when security thresholds are exceeded. This automated self-service approach eliminates the need for manual security monitoring and enforcement, reducing the operational burden on users while maintaining strict security compliance through automatic functionality restriction.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms by continuously monitoring the time elapsed since security patch application and using this information to automatically adjust software execution permissions. This closed-loop feedback system ensures that security requirements are automatically enforced based on real-time status information, creating a self-regulating security mechanism that adapts to current conditions without requiring continuous user intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11861992B2Information processing apparatus and control program therefor
Publication Date: 2024.01.02 TOSHIBA TEC KK
  • US11861992B2 patent drawing
  • US11861992B2 patent drawing
  • US11861992B2 patent drawing

AI summary

An information processing apparatus includes a memory and a controller. The memory is configured to store first software and second software different from the first software. The controller is configured to enable execution of the first software and the second software when an elapsed time since an application of a program on security was last successfully performed is less than a predetermined time, and enable execution of the first software and disable execution of the second software when the elapsed time is greater than or equal to the predetermined time.