Hardware Security Module for Process Authorization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern operating systems face security gaps due to incomplete control over process calls, which can be circumvented by inappropriate programming, and existing access control mechanisms like Linux Security Modules (LSM) can be misconfigured, leading to insufficient security levels despite isolation and virtualization efforts.

Innovation Solution

A method and device utilizing a security module for secure monitoring of processes, where access control is configured and managed through a hardware-side security module, ensuring that only authorized access to hardware resources and process calls is allowed, preventing incorrect user configurations by integrating a trusted third-party entity for secure authorization and encryption.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If access control mechanisms like Linux Security Modules (LSM) are used to monitor process calls, then process monitoring capability is improved, but security reliability deteriorates due to potential misconfiguration by users with appropriate rights

Engineering Contradiction:
Improveprocess monitoring capabilityVSAvoidsecurity reliability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent introduces a trusted third-party entity as an intermediary between the user and the access control mechanism. This mediator verifies and approves configuration changes before they take effect, preventing unauthorized or erroneous configurations while maintaining the monitoring capabilities of LSM. The intermediary layer ensures that only validated security configurations are applied, resolving the contradiction between monitoring capability and security reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If isolation and virtualization approaches are used to secure processes, then security isolation is improved, but device complexity increases due to requiring standalone operating systems in virtual machines

Engineering Contradiction:
Improvesecurity isolationVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trusted third-party verification function from the complex virtualization infrastructure and implements it as a separate approval mechanism within the existing operating system. This allows security isolation to be enhanced through verified access control without requiring full virtual machine isolation, thereby reducing overall system complexity while maintaining improved security.

Inventive Principle:
Principle #2Taking out (Extraction)

3Productivity

If containers or jails are used for process isolation on a common operating system, then computational efficiency is improved, but security reliability deteriorates due to targeted incorrect configuration

Engineering Contradiction:
Improvecomputational efficiencyVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary verification of configuration parameters before they are applied to container or jail setups. The trusted third-party entity pre-approves valid configuration schemes, ensuring that only security-valid configurations can be deployed. This preliminary approval mechanism prevents targeted incorrect configurations while maintaining the computational efficiency benefits of containerization.

Inventive Principle:
Principle #10Preliminary action

4Ease of operation

If user-configurable access control is allowed, then ease of operation is improved, but manufacturing precision deteriorates due to incorrect configuration leading to insufficient security

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidconfiguration accuracy
Core Design Contradiction:
Ease of operationVSManufacturing precision

Solution Approach 1:

The patent implements a feedback loop where the trusted third-party entity continuously monitors and verifies configuration changes. When users attempt to configure access control parameters, the system provides feedback indicating whether the configuration is valid or would compromise security. This feedback mechanism guides users toward correct configurations while maintaining operational flexibility, resolving the contradiction between ease of operation and configuration accuracy.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3167400B1Method and device for making processes secure
Publication Date: 2019.01.02 BUNDESDRUCKEREI GMBH
  • EP3167400B1 patent drawingFigure 1
  • EP3167400B1 patent drawingFigure 2
  • EP3167400B1 patent drawingFigure 3

AI summary

The application relates to a device comprising a processor designed to execute an operating system and perform at least one process (25a, 25b) on the operating system, and an interface designed to be coupled to a security module (11); the operating system includes an access control module designed to monitor, on the basis of one or more authorizations, initiations of the at least one process (25a, 25b); and the operating system is designed to configure the one or more authorizations by means of the security module (11). The invention further relates to a method for monitoring processes in a secured manner.