Hosted Execution Runtime Environment for Secure Application Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Designers face challenges in balancing security and functionality in modern computing devices, as existing software platforms struggle to adapt to new applications while maintaining compatibility and security, often leading to increased vulnerabilities and high development costs.
Innovation Solution
A method and system for executing applications using a hosted execution runtime environment (HERE) connected to a secure storage element, which includes a persistent memory image that can be updated, allowing for secure execution and synchronization of applications while maintaining security features like data encryption and access control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security features are enhanced using specialized hardware architecture, then security is improved, but design and development costs increase substantially
Solution Approach 1:
The patent introduces a secure runtime environment (SRE) as an intermediary software layer that provides security services without requiring specialized hardware architecture. The SRE acts as a mediator between the host operating system and applications, implementing security features such as secure boot, code signing, and runtime protection through software mechanisms rather than expensive hardware modifications.
2Reliability
If security features are implemented, then security is improved, but functionality and efficiency are limited
Solution Approach 1:
The secure runtime environment implements dynamic security policies that can be adjusted based on application requirements and threat levels. The system dynamically loads security modules, adjusts protection levels, and adapts security behavior during runtime, allowing functionality to expand while maintaining appropriate security measures without static limitations.
Solution Approach 2:
The patent segments security functions into modular components within the secure runtime environment, allowing different security features to be selectively activated based on application needs. This segmentation enables partial security implementation for specific applications while maintaining overall system functionality and efficiency.
3Adaptability or versatility
If openness and functionality are increased in device design, then adaptability is improved, but vulnerability to malware and exploits increases
Solution Approach 1:
The secure runtime environment performs preliminary security actions including code signing verification, secure boot validation, and vulnerability assessment before applications are executed. By establishing security checks in advance, the system enables open and functional device design while preventing malware execution through pre-validated security measures.
Solution Approach 2:
The system implements continuous feedback mechanisms that monitor application behavior, system integrity, and security events in real-time. When potential threats are detected, the feedback loop triggers automated responses such as application isolation, security policy updates, or system lockdown, allowing high functionality while rapidly responding to vulnerability exploitation attempts.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
In general, in one aspect, the invention relates to a method for executing applications. The method includes accessing a secure storage element via a host device including a computer processor; executing, by the computer processor, a hosted execution runtime environment (HERE) on the host device; identifying a persistent memory image of the HERE within the secure storage element; executing, by the computer processor, an application using the HERE; and applying, based on executing the application, a first set of changes to the persistent memory image.