Endpoint Protection via Segmented Memory Spaces

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malware infections in host computer systems compromise security and efficiency, allowing unauthorized access and data loss, as well as potential use for staging attacks on other network resources, often undetected by users or administrators.

Innovation Solution

Implementing endpoint protection and authentication schemes with segregated memory spaces, sandboxed computing environments, and firewalls to isolate untrusted network interactions, prevent unauthorized data transfer, and enforce strict authentication and encryption policies based on network trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a host computer system connects to untrusted network destinations, then network functionality and accessibility are improved, but security and vulnerability to malware attacks deteriorate

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidmalware vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the host computer system into a trusted workspace and an untrusted sandboxed computing environment. The sandbox container process creates separate memory spaces (first memory space for workspace, second memory space for sandbox) that are isolated from each other. This segmentation allows the system to access untrusted networks through the sandbox while protecting the trusted workspace from malware, resolving the contradiction between network accessibility and security.

Inventive Principle:
Principle #1Segmentation

2Productivity

If malware is allowed to execute on the host system, then system functionality and application execution are improved, but system integrity and security deteriorate

Engineering Contradiction:
Improveapplication execution capabilityVSAvoidsystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The sandbox container process acts as an intermediary between untrusted applications and the host operating system. It mediates all interactions by running applications in an isolated second memory space with restricted access to the first memory space containing sensitive data. The container process controls and filters all communication between the sandboxed environment and the trusted workspace, allowing application execution while maintaining system integrity through this intermediary layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If data communication between workspace and sandboxed environment is permitted, then data accessibility and functionality are improved, but data security and confidentiality deteriorate

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata confidentiality
Core Design Contradiction:
Ease of operationVSLoss of information

Solution Approach 1:

The patent implements preliminary action by establishing strict access control policies before any data communication occurs. The sandbox container process is configured in advance to prevent data from being communicated between the sandboxed computing environment and the workspace without explicit user input. This preliminary configuration of security policies ensures that data confidentiality is maintained while still allowing controlled accessibility when users intentionally permit it.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10931669B2Endpoint protection and authentication
Publication Date: 2021.02.23 L3 TECHNOLOGIES INC
  • US10931669B2 patent drawing
  • US10931669B2 patent drawing
  • US10931669B2 patent drawing

AI summary

Methods and systems are disclosed for endpoint protection and authentication schemes for a host computer system having an internet isolation system. A first host computer system may include a first memory space and a second memory space. The first memory space may be configured to enable storage and operation of a workspace configured to execute a first set of one or more applications and processes running on an operating system of the first host computer system. The second memory space may be configured to enable storage and operation of a second set of one or more applications and processes associated with an isolated computing environment (e.g., a sandboxed computing environment) configured to run on the operating system. When the first host computer system is connected to a network that is known or associated with a predetermined security policy, the first host computer system may instantiate a predetermined security policy configuration.