Obfuscated Hardware for Malware Detection in Edge Computing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Edge computer systems deployed in military and critical operations lack effective cybersecurity measures to detect and mitigate malware attacks instantly, as they often lack traditional operating systems and virus scan procedures, making them vulnerable to cyberattacks through wireless connections.

Innovation Solution

The implementation of a computer device with redundant processing cores and a trusted execution environment (TEE) processor that obfuscates instruction codes and monitors for malware by comparing instruction register values across multiple cores, enabling instantaneous detection and mitigation of malware attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional operating systems and virus scan procedures are implemented in edge computer systems, then cybersecurity detection capability is improved, but system execution speed and operational responsiveness deteriorate

Engineering Contradiction:
Improvecybersecurity detection capabilityVSAvoidsystem execution speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent replaces traditional software-based virus scanning mechanisms with hardware-level cybersecurity enforcement through specialized security processors and trusted execution environments. This substitution occurs at the hardware architecture level, where security functions are implemented as dedicated hardware modules rather than software processes, thereby providing malware detection capability without the performance overhead of traditional operating system-based security software.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system performs preliminary security validation through hardware-enforced trusted execution environments and security processors before malicious code can execute. By pre-configuring security policies, cryptographic verification, and malware detection capabilities at hardware initialization, the system establishes security defenses that operate automatically without requiring runtime virus scanning, thus maintaining both security and performance.

Inventive Principle:
Principle #10Preliminary action

2Speed

If edge computer systems operate without traditional operating systems to maintain fast execution, then system speed is improved, but cybersecurity protection capability deteriorates

Engineering Contradiction:
Improvesystem execution speedVSAvoidcybersecurity protection capability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The patent introduces hardware-based security processors and trusted execution environment modules as intermediary components between the bare metal operating system and application workloads. These intermediary hardware modules provide malware detection, cryptographic verification, and security policy enforcement without requiring a traditional operating system, thus maintaining fast execution while adding cybersecurity protection through dedicated security hardware layers.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If wireless connectivity is added to edge computer systems for network operations, then operational capability is improved, but vulnerability to remote malware injection deteriorates

Engineering Contradiction:
Improvewireless network capabilityVSAvoidremote malware injection vulnerability
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system applies preliminary anti-action by implementing hardware-enforced security policies and trusted execution environments that prevent malicious code execution before wireless interfaces can be compromised. The security processors continuously monitor and validate code integrity, establishing a preemptive defense that blocks remote malware injection attempts through wireless connections before they can affect system operations.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS12050688B1Malware-resistant obfuscated computer hardware for reconfigurable hardware devices and methods thereof
Publication Date: 2024.07.30 RESILIENT COMPUTING LLC
  • US12050688B1 patent drawing
  • US12050688B1 patent drawing
  • US12050688B1 patent drawing

AI summary

A computer device including a computing engine having a plurality of processor cores configured to simultaneously execute identical sets of processor-executable instructions, where each of the processor cores includes different instruction code assignments, and a malware monitoring and remediation component that detects presence of malware when instruction register values from a predetermined number of processor cores are identical during an instruction cycle. In various embodiments, the computer device may be an “edge” computer deployed in military or other highly-sensitive environments. The computing engine may be implemented using one or more field programmable gate arrays (FPGAs).