Master Device for Application Security Environment Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems for computing environments, such as UNIX and Windows operating systems, are inadequate in preventing malicious users from exploiting security weaknesses to gain privileged access, leading to risks for users' data and identity, especially when laptops are stolen or when privileged users act maliciously, and existing solutions require cumbersome manual actions for protection and are not suitable for mass memories.

Innovation Solution

A Slave Application Security Environment Protection Device (SASEPDevice) is introduced, which supports multiple states for each Application Security Environment, requiring manual authentication and authorization through a master device to ensure secure operation, dividing mass-memories into regions and enforcing fine-grained protection based on user privileges, with only authorized users able to perform operations like creating or deleting users, user groups, and Application Security Environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual protection mechanisms are implemented in existing operating systems, then security against malicious programs is improved, but device complexity and ease of operation deteriorate due to cumbersome manual actions required for each machine

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system automatically manages protection states for multiple machines without requiring manual intervention for each device. The master device autonomously controls and synchronizes security states across the network, eliminating the need for administrators to manually configure each machine individually.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The master device serves multiple functions by simultaneously managing security protection across numerous machines through a single centralized interface. This universal control mechanism allows one device to perform what would traditionally require multiple individual configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If fine-grained protection for each Application Security Environment is implemented, then security against privileged user attacks is improved, but device complexity worsens due to the need for granular control mechanisms

Engineering Contradiction:
Improvesecurity protectionVSAvoidcontrol mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system divides protection into distinct states for different Application Security Environments. Each ASE can be independently configured with specific protection levels, allowing fine-grained control without requiring complex customization for each individual environment. The master device manages these segmented states through standardized operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system controls security by changing parameters (protection states) rather than restructuring the entire control mechanism. The master device can switch between predefined protection states (e.g., protected, unprotected, update mode) which simplifies the control complexity while maintaining fine-grained security management.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If protection is enabled for all machines simultaneously, then security is improved, but ease of operation worsens when system administrators need to perform maintenance tasks like software updates

Engineering Contradiction:
Improvesecurity protectionVSAvoidmaintenance operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The security protection state is dynamic rather than static. The master device can temporarily modify protection states for specific machines or groups of machines based on operational needs, such as enabling update modes during maintenance windows while maintaining protection elsewhere. This dynamic adjustment maintains both security and operational flexibility.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system allows preliminary configuration of protection states and update schedules before maintenance operations are needed. Administrators can pre-configure which machines should be updated and when, so that during actual maintenance, the system is already prepared and requires minimal intervention, balancing security with operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10372924B2Master device for controlling application security environments
Publication Date: 2019.08.06 MADATHILPARAMBIL GEORGE GEORGE
  • US10372924B2 patent drawing
  • US10372924B2 patent drawing
  • US10372924B2 patent drawing

AI summary

Computer protection is weak with the methods currently available and there are risks of malicious users getting access to computers, corrupting important data, including system data. We are proposing a method for improving access protection, more particularly, by using a slave device that will enable or disable protection for applications as required. The device supports one or more users, none or more user groups, none or one or more Application Security Environments for each user or user group and one or more states for each Application Security Environment. The state of the hardware is manually controlled by the users. Depending on the configuration, each hardware state corresponding to an Application Security Environment corresponds to a set of privileges the processes running in that Application Security Environment have while that Application Security Environment is in that state.