Secure Integration of Isolated Execution Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current technologies fail to effectively identify and secure isolated execution environments, leading to potential data compromise in authorized user systems, especially with the increasing number of mobile computing tasks and diverse user activities.
Innovation Solution
A method and system that identifies authorized computer systems, forms an isolated execution environment for a security application, detects and integrates multiple execution environments using integration rules, and applies restrictions to prevent unauthorized data access, enhancing the security of isolated execution environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the number of programs and user activities increases, then the functionality and versatility of the system improves, but the security risk and complexity of isolated execution environments worsens
Solution Approach 1:
The system segments execution environments into isolated containers, each with its own memory space and system calls. This allows multiple programs to run simultaneously without interfering with each other, maintaining versatility while containing security risks within isolated segments rather than propagating system-wide.
Solution Approach 2:
A security monitor acts as an intermediary between execution environments and the operating system. It intercepts system calls, validates permissions, and mediates resource access, thereby managing the complexity of security control as a separate layer that simplifies the overall system architecture.
2Reliability
If isolated execution environments are created for each program, then data protection against malicious code improves, but the difficulty of detecting and measuring vulnerable environments worsens
Solution Approach 1:
The security monitor continuously monitors system calls and execution environment behavior, providing feedback about potential vulnerabilities and security incidents. This enables real-time detection of compromised environments without requiring complex manual analysis, as the feedback mechanism automatically identifies anomalies in program behavior.
Solution Approach 2:
The security monitor serves multiple functions: it monitors security events, detects vulnerabilities, measures execution environment characteristics, and provides protection. This multi-functionality consolidates detection and measurement capabilities into a single system component, reducing the difficulty of identifying vulnerable environments.
3Object-affected harmful factors
If known security technologies are used, then basic security protection is provided, but the ability to identify vulnerable execution environments remains insufficient
Solution Approach 1:
The patent replaces traditional mechanical security checks with a software-based security monitor that operates at the system call level. This substitution enables more precise detection of vulnerable execution environments by monitoring actual program behavior and system interactions rather than relying on static configuration checks.
Solution Approach 2:
The security monitor dynamically changes monitoring parameters based on execution environment characteristics and detected behavior patterns. By adjusting detection thresholds and monitoring focus in real-time, the system improves vulnerability identification precision without requiring exhaustive static analysis of all possible execution scenarios.
Data Source
AI summary
Disclosed herein are systems and methods for enhancing the security of isolated execution environments of an authorized user. In one aspect, an exemplary method comprises: identifying at least one computer system on which a user is authorized, forming an isolated execution environment for execution of a security application, detecting at least two isolated execution environments using an isolated execution environment of the installed security application on the identified computer system, and forming a secure integration of the identified isolated execution environments using integration rules. In one aspect, the forming of the secured integration is performed by: creating an integration of the identified isolated execution environments, and checking for presence of a data access transit in the created integration. In one aspect, when the data access transit is identified, the method further comprises applying restrictions based on identified options for the identified data access transit using integration rules.


