Secure Integration of Isolated Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to effectively identify and secure isolated execution environments, leading to potential data compromise in authorized user systems, especially with the increasing number of mobile computing tasks and diverse user activities.

Innovation Solution

A method and system that identifies authorized computer systems, forms an isolated execution environment for a security application, detects and integrates multiple execution environments using integration rules, and applies restrictions to prevent unauthorized data access, enhancing the security of isolated execution environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the number of programs and user activities increases, then the functionality and versatility of the system improves, but the security risk and complexity of isolated execution environments worsens

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments execution environments into isolated containers, each with its own memory space and system calls. This allows multiple programs to run simultaneously without interfering with each other, maintaining versatility while containing security risks within isolated segments rather than propagating system-wide.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security monitor acts as an intermediary between execution environments and the operating system. It intercepts system calls, validates permissions, and mediates resource access, thereby managing the complexity of security control as a separate layer that simplifies the overall system architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If isolated execution environments are created for each program, then data protection against malicious code improves, but the difficulty of detecting and measuring vulnerable environments worsens

Engineering Contradiction:
Improvedata protectionVSAvoiddetection difficulty
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The security monitor continuously monitors system calls and execution environment behavior, providing feedback about potential vulnerabilities and security incidents. This enables real-time detection of compromised environments without requiring complex manual analysis, as the feedback mechanism automatically identifies anomalies in program behavior.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security monitor serves multiple functions: it monitors security events, detects vulnerabilities, measures execution environment characteristics, and provides protection. This multi-functionality consolidates detection and measurement capabilities into a single system component, reducing the difficulty of identifying vulnerable environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If known security technologies are used, then basic security protection is provided, but the ability to identify vulnerable execution environments remains insufficient

Engineering Contradiction:
Improvesecurity protectionVSAvoidvulnerability identification precision
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

The patent replaces traditional mechanical security checks with a software-based security monitor that operates at the system call level. This substitution enables more precise detection of vulnerable execution environments by monitoring actual program behavior and system interactions rather than relying on static configuration checks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The security monitor dynamically changes monitoring parameters based on execution environment characteristics and detected behavior patterns. By adjusting detection thresholds and monitoring focus in real-time, the system improves vulnerability identification precision without requiring exhaustive static analysis of all possible execution scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240362320A1Systems and methods for enhancing the security of isolated execution environments of an authorized user
Publication Date: 2024.10.31 AO KASPERSKY LAB
  • US20240362320A1 patent drawing
  • US20240362320A1 patent drawing
  • US20240362320A1 patent drawing

AI summary

Disclosed herein are systems and methods for enhancing the security of isolated execution environments of an authorized user. In one aspect, an exemplary method comprises: identifying at least one computer system on which a user is authorized, forming an isolated execution environment for execution of a security application, detecting at least two isolated execution environments using an isolated execution environment of the installed security application on the identified computer system, and forming a secure integration of the identified isolated execution environments using integration rules. In one aspect, the forming of the secured integration is performed by: creating an integration of the identified isolated execution environments, and checking for presence of a data access transit in the created integration. In one aspect, when the data access transit is identified, the method further comprises applying restrictions based on identified options for the identified data access transit using integration rules.