Modular Software Security Evaluation via Logical Module Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security evaluation frameworks for software applications on commercial-off-the-shelf devices require extensive computing resources and time due to their end-to-end nature, necessitating complete re-evaluation with every change, which is inefficient for frequent updates and enhancements.

Innovation Solution

A method involving a network processing computer that determines logical modules based on software information, provides them to a testing computer for evaluation, and generates a security evaluation report, allowing for targeted security testing and summarization, thereby enabling efficient security approval without full re-evaluation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing end-to-end security evaluation framework is used, then comprehensive security coverage is achieved, but computing resources and time required increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidevaluation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the monolithic end-to-end security evaluation into modular functional component evaluations. Each functional component (e.g., data entry, data storage, data transmission) is evaluated independently using standardized security criteria. This segmentation allows partial re-evaluation when only specific components are modified, rather than requiring complete re-evaluation of the entire software system, thus improving evaluation efficiency while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Reliability

If complete re-evaluation is performed for every software change, then security reliability is maintained, but time consumption increases

Engineering Contradiction:
Improvesecurity assuranceVSAvoidevaluation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent establishes preliminary security requirements and evaluation criteria for each functional component before the software development process begins. These pre-defined security standards allow for targeted re-evaluation of only the affected components when changes occur, rather than performing complete re-evaluation. This preliminary preparation maintains security assurance while significantly reducing the time required for iterative evaluations during frequent software updates.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive security evaluation is conducted, then security quality is ensured, but computing resources consumed increase

Engineering Contradiction:
Improvesecurity qualityVSAvoidcomputing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent divides the comprehensive security evaluation into segmented assessments of individual functional components. Each component is evaluated against specific security criteria relevant to its function (e.g., encryption for data transmission, access control for data storage). This segmentation reduces computing resource consumption by evaluating only the necessary security aspects of modified components rather than performing exhaustive full-system analysis, while still ensuring overall security quality through systematic coverage of all functional areas.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240143788A1Modular security evaluation of software on devices
Publication Date: 2024.05.02 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US20240143788A1 patent drawing
  • US20240143788A1 patent drawing
  • US20240143788A1 patent drawing

AI summary

A method includes receiving, by a network processing computer, software information from a development computer. The network processing computer can determine one or more logical modules of a plurality of logical modules based on the software information. The network processing computer can provide the one or more logical modules to a testing computer. The testing computer evaluates one or more software modules corresponding to the software information using the one or more logical modules. The network processing computer receives a security evaluation report from the testing computer based on the evaluation of the one or more software modules using the one or more logical modules. The network processing computer creates a security evaluation summary based on the security evaluation report.