Selective Feature Deprivation for Zero-Day Threat Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for addressing vulnerabilities in computing systems are inadequate, as patches are often unavailable when vulnerabilities are discovered, and compensating controls are complex and ineffective, especially when attacks occur over encrypted protocols.

Innovation Solution

Implementing a feature deprivation system where computing systems are pre-configured to temporarily disable vulnerable features via deprivation tokens, enabling quick threat prevention until a permanent solution is available, without relying on detection or analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If patches are applied to address vulnerabilities, then system security is improved, but time loss occurs due to patch development, certification and distribution cycles

Engineering Contradiction:
Improvesystem securityVSAvoidtime for patch development and distribution
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary action by proactively disabling vulnerable features before patches are available. When a vulnerability is discovered, the feature controller immediately deactivates the affected feature, preventing exploits before they can occur. This eliminates the time loss associated with patch development and distribution while maintaining security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by preemptively disabling the vulnerable feature rather than waiting for an exploit to occur or a patch to be ready. The feature controller receives vulnerability information and immediately counteracts the potential threat by deactivating the feature, creating a preventive measure that exists before the harmful action can take place.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If compensating controls are implemented to limit exploit reach, then system security is improved, but device complexity increases due to pattern matching and heuristics requirements

Engineering Contradiction:
Improvesystem securityVSAvoidcomplexity of compensating controls
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the security function from complex network-based compensating controls and relocates it to the device itself through feature deactivation. Instead of relying on complex pattern matching and heuristics in network security infrastructure, the system directly removes the vulnerable feature at its source, simplifying the overall security architecture.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The feature controller acts as an intermediary between the vulnerable feature and the exploit. It receives vulnerability information and mediates by deactivating the feature, providing a simple and direct security mechanism without requiring complex pattern matching or heuristics that would increase device complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If network security infrastructure is used to prevent exploits, then system security is improved, but loss of information occurs when attacks occur over encrypted protocols like TLS

Engineering Contradiction:
Improvesystem securityVSAvoidvisibility into encrypted traffic
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The feature controller serves as an intermediary that operates independently of network security infrastructure. It receives vulnerability information and deactivates features directly on the device, eliminating the need for network-based security measures that cannot inspect encrypted TLS traffic. This approach maintains security without requiring decryption operations that would result in information loss.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4020283B1Threat prevention by selective feature deprivation
Publication Date: 2025.11.26 INTEL CORP
  • EP4020283B1 patent drawingFigure 1
  • EP4020283B1 patent drawingFigure 2
  • EP4020283B1 patent drawingFigure 3

AI summary

A method of preventing exploitation of a vulnerability of a computing system includes generating a deprivation token to cause disabling of a selected one or more features of a component of the computing system to prevent an exploit of a vulnerability affecting the selected one or more features; and publishing the derivation token to at least one of a computing system manufacturer computing system and an enterprise information technology (IT) computing system for distribution to affected computing systems.