Hosted Execution Runtime Environment for Secure Application Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Designers face challenges in balancing security and functionality in modern computing devices, as existing software platforms struggle to adapt to new applications while maintaining compatibility and security, often leading to increased vulnerabilities and high development costs.

Innovation Solution

A method and system for executing applications using a hosted execution runtime environment (HERE) connected to a secure storage element, which includes a persistent memory image that can be updated, allowing for secure execution and synchronization of applications while maintaining security features like data encryption and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security features are enhanced using specialized hardware architecture, then security is improved, but design and development costs increase substantially

Engineering Contradiction:
ImprovesecurityVSAvoiddesign and development costs
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secure runtime environment (SRE) as an intermediary software layer that provides security services without requiring specialized hardware architecture. The SRE acts as a mediator between the host operating system and applications, implementing security features such as secure boot, code signing, and runtime protection through software mechanisms rather than expensive hardware modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security features are implemented, then security is improved, but functionality and efficiency are limited

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The secure runtime environment implements dynamic security policies that can be adjusted based on application requirements and threat levels. The system dynamically loads security modules, adjusts protection levels, and adapts security behavior during runtime, allowing functionality to expand while maintaining appropriate security measures without static limitations.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments security functions into modular components within the secure runtime environment, allowing different security features to be selectively activated based on application needs. This segmentation enables partial security implementation for specific applications while maintaining overall system functionality and efficiency.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If openness and functionality are increased in device design, then adaptability is improved, but vulnerability to malware and exploits increases

Engineering Contradiction:
ImprovefunctionalityVSAvoidvulnerability to malware
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The secure runtime environment performs preliminary security actions including code signing verification, secure boot validation, and vulnerability assessment before applications are executed. By establishing security checks in advance, the system enables open and functional device design while preventing malware execution through pre-validated security measures.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback mechanisms that monitor application behavior, system integrity, and security events in real-time. When potential threats are detected, the feedback loop triggers automated responses such as application isolation, security policy updates, or system lockdown, allowing high functionality while rapidly responding to vulnerability exploitation attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2727040B1A secure hosted execution architecture
Publication Date: 2018.11.28 ORACLE INT CORP
  • EP2727040B1 patent drawingFigure 1
  • EP2727040B1 patent drawingFigure 2
  • EP2727040B1 patent drawingFigure 3

AI summary

In general, in one aspect, the invention relates to a method for executing applications. The method includes accessing a secure storage element via a host device including a computer processor; executing, by the computer processor, a hosted execution runtime environment (HERE) on the host device; identifying a persistent memory image of the HERE within the secure storage element; executing, by the computer processor, an application using the HERE; and applying, based on executing the application, a first set of changes to the persistent memory image.