Execution Environment Isolation for Security-Hardened Information Processing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing information processing apparatuses in autonomous control systems are vulnerable to security attacks, with existing technologies failing to effectively reduce security intrusion risk and harden the system against such attacks.
Innovation Solution
Implementing an information processing apparatus with execution-environment separating/setting units, configuration-risk evaluation, and activation-setting units to deploy application software in isolated environments, along with secure communication and logging functions to manage and control hardware resources, thereby reducing security intrusion risk and enhancing defensiveness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the information processing apparatus is connected with diverse external systems and performs collaborative processing, then the functionality and adaptability of the system is improved, but the security risk increases
Solution Approach 1:
The patent divides the information processing apparatus into multiple isolated execution environments (first execution environment and second execution environment). Each environment has its own security boundaries and access controls. The first execution environment handles external connections and collaborative processing, while the second execution environment handles critical functions. This segmentation allows the system to maintain high adaptability for external collaborations while protecting critical functions from security risks through environmental isolation.
2Reliability
If intrusion detection devices are added to detect security attacks, then the security monitoring capability is improved, but the system complexity increases
Solution Approach 1:
The patent introduces a configuration management device as an intermediary between the external systems and the information processing apparatus. This intermediary device manages the configuration information of execution environments, controls the activation and deactivation of environments based on security requirements, and coordinates the isolation mechanisms. By using this intermediary, the system achieves effective security monitoring and intrusion prevention without directly adding complex detection devices within the core processing apparatus.
3Object-affected harmful factors
If execution environments are isolated to reduce security intrusion risk, then the security defensiveness is improved, but the system complexity increases
Solution Approach 1:
The patent designs the execution environment isolation mechanism with multi-functional capabilities. The same isolation infrastructure supports multiple execution environments, configuration management, security control, and resource allocation simultaneously. The configuration management device can manage different types of execution environments (first and second types) using unified principles and methods. This universality reduces the overall system complexity compared to implementing separate isolation mechanisms for each security requirement.
Data Source
AI summary
An information processing apparatus includes computer hardware, system software that manages and controls the computer hardware, and two or more application software items to be executed on the system software. Further, there is an execution-environment separating/setting unit including an execution-environment-separation definition table, a configuration-risk definition table, a configuration-risk evaluation unit, and an activation-setting unit, and an execution-environment separating/deploying unit that deploys execution environments on the computer hardware in accordance with an instruction of the activation-setting unit; the application software items are executed in the respective execution environments deployed by the execution-environment separating/deploying unit.


