Isolated Secure Environments for Flexible Asset Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional layered security systems are limited in their ability to provide flexible and secure access to assets across multiple computer devices, often restricting operations and failing to secure asset usage between devices.

Innovation Solution

A method and apparatus for providing isolated asset access in a layered security system, where a server device configures secure environments, such as virtual machines, on client devices to manage asset access with specified security restrictions, allowing for reduced restrictions based on user requests.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional network security measures are implemented, then security protection is improved, but the flexibility and operation of computer devices are unduly restricted

Engineering Contradiction:
Improvesecurity protectionVSAvoidflexibility of computer device operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments the computing environment into multiple isolated secure environments (virtual machines) with different security levels. Each environment can have customized security restrictions, allowing sensitive assets to be protected while non-sensitive operations maintain flexibility. This resolves the contradiction by providing both security and flexibility in separate, isolated contexts rather than applying uniform restrictions across the entire system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security restriction levels to different local environments rather than imposing uniform restrictions system-wide. Each secure environment can be configured with appropriate security controls matched to the sensitivity of assets it contains, allowing high-security zones for sensitive data and low-restriction zones for general operations, thus maintaining both security and operational flexibility.

Inventive Principle:
Principle #3Local quality

2Reliability

If layered security systems divide computer systems into separate environments, then security control is improved, but the ability to securely share assets between devices is limited

Engineering Contradiction:
Improvesecurity controlVSAvoidsecure asset sharing between devices
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary mechanism that enables secure asset sharing between isolated secure environments. This intermediary allows controlled interaction and asset transfer between devices while maintaining the security boundaries of each environment, thus resolving the contradiction by providing both isolation and controlled connectivity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If uniform security restrictions are applied across all environments, then security consistency is improved, but the productivity and user experience are reduced

Engineering Contradiction:
Improvesecurity consistencyVSAvoiduser productivity and efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic security restrictions where each secure environment can have customized security policies based on its specific requirements. This allows security consistency within each environment while adapting restrictions to match the actual risk level and operational needs of different assets, thereby maintaining security without unnecessarily impacting productivity in lower-risk environments.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12341822B2Method and apparatus for providing isolated asset access in a layered security system
Publication Date: 2025.06.24 WORCESTER POLYTECHNIC INSTITUTE
  • US12341822B2 patent drawing
  • US12341822B2 patent drawing
  • US12341822B2 patent drawing

AI summary

Embodiments of the innovation relate to a server device, comprising a controller having a memory and a processor, the controller configured to establish a first secure environment with a client device, the first secure environment having an associated server asset policy; provide the asset to the client device via the first secure environment; receive a request from the client device, via the first secure environment, to utilize the asset with a user-selected application according to a user-selected asset policy; establish a second secure environment with the client device, the second secure environment having the user-selected application and the associated user-selected asset policy and the second secure environment isolated from the first secure environment; and provide the asset to the client device via the second secure environment.