Master Device for Application Security Environment Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems for computing environments, such as UNIX and Windows operating systems, are inadequate in preventing malicious users from exploiting security weaknesses to gain privileged access, leading to risks for users' data and identity, especially when laptops are stolen or when privileged users act maliciously, and existing solutions require cumbersome manual actions for protection and are not suitable for mass memories.
Innovation Solution
A Slave Application Security Environment Protection Device (SASEPDevice) is introduced, which supports multiple states for each Application Security Environment, requiring manual authentication and authorization through a master device to ensure secure operation, dividing mass-memories into regions and enforcing fine-grained protection based on user privileges, with only authorized users able to perform operations like creating or deleting users, user groups, and Application Security Environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual protection mechanisms are implemented in existing operating systems, then security against malicious programs is improved, but device complexity and ease of operation deteriorate due to cumbersome manual actions required for each machine
Solution Approach 1:
The security system automatically manages protection states for multiple machines without requiring manual intervention for each device. The master device autonomously controls and synchronizes security states across the network, eliminating the need for administrators to manually configure each machine individually.
Solution Approach 2:
The master device serves multiple functions by simultaneously managing security protection across numerous machines through a single centralized interface. This universal control mechanism allows one device to perform what would traditionally require multiple individual configurations.
2Reliability
If fine-grained protection for each Application Security Environment is implemented, then security against privileged user attacks is improved, but device complexity worsens due to the need for granular control mechanisms
Solution Approach 1:
The security system divides protection into distinct states for different Application Security Environments. Each ASE can be independently configured with specific protection levels, allowing fine-grained control without requiring complex customization for each individual environment. The master device manages these segmented states through standardized operations.
Solution Approach 2:
The system controls security by changing parameters (protection states) rather than restructuring the entire control mechanism. The master device can switch between predefined protection states (e.g., protected, unprotected, update mode) which simplifies the control complexity while maintaining fine-grained security management.
3Reliability
If protection is enabled for all machines simultaneously, then security is improved, but ease of operation worsens when system administrators need to perform maintenance tasks like software updates
Solution Approach 1:
The security protection state is dynamic rather than static. The master device can temporarily modify protection states for specific machines or groups of machines based on operational needs, such as enabling update modes during maintenance windows while maintaining protection elsewhere. This dynamic adjustment maintains both security and operational flexibility.
Solution Approach 2:
The system allows preliminary configuration of protection states and update schedules before maintenance operations are needed. Administrators can pre-configure which machines should be updated and when, so that during actual maintenance, the system is already prepared and requires minimal intervention, balancing security with operational efficiency.
Data Source
AI summary
Computer protection is weak with the methods currently available and there are risks of malicious users getting access to computers, corrupting important data, including system data. We are proposing a method for improving access protection, more particularly, by using a slave device that will enable or disable protection for applications as required. The device supports one or more users, none or more user groups, none or one or more Application Security Environments for each user or user group and one or more states for each Application Security Environment. The state of the hardware is manually controlled by the users. Depending on the configuration, each hardware state corresponding to an Application Security Environment corresponds to a set of privileges the processes running in that Application Security Environment have while that Application Security Environment is in that state.


