Onboard Data Access Control Using Application Permission Mapping
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing onboard information processing devices face high computational loads and potential security risks due to complex rules required to determine legitimate data access by applications, necessitating expensive hardware configurations.
Innovation Solution
An onboard information processing device with a hypervisor and independent operating systems, utilizing a correspondence relationship list to permit or deny data access based on simpler rules, and implementing middleware APIs to monitor and control data-access activity, thereby reducing computational load and preventing high-risk attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If complex rules are used to determine whether application processes constitute attacks, then security monitoring capability is improved, but computational load increases and hardware cost increases
Solution Approach 1:
The patent segments the monitoring approach by separating simple data access permission checks from complex process behavior analysis. The correspondence relationship list records only essential permission mappings between applications and data, avoiding the need to analyze complex attack patterns while maintaining security monitoring capability.
Solution Approach 2:
The patent extracts only the essential permission verification function from complex security monitoring. By recording correspondence relationships between applications and permitted data in a simplified format, it removes unnecessary computational complexity while retaining the core security checking capability.
2Reliability
If complex rules are used to determine whether application processes constitute attacks, then security monitoring capability is improved, but hardware configuration cost increases
Solution Approach 1:
The patent uses a lightweight correspondence relationship list that can be easily stored and updated, replacing the need for expensive hardware configurations. This simple data structure provides sufficient security monitoring capability without requiring high-performance processors or specialized security hardware.
3Device complexity
If simple rules are used to monitor data access, then computational load is reduced, but security monitoring effectiveness decreases
Solution Approach 1:
The patent performs preliminary action by pre-recording correspondence relationships between applications and their permitted data in the correspondence relationship list. This allows the system to make quick permission decisions based on pre-established rules without needing to perform complex real-time analysis, maintaining both simplicity and effectiveness.
Data Source
AI summary
A processor is configured to determine whether or not target data, this being data that a first application is attempting to access, is permitted data based on a correspondence relationship list, and to permit the first application to access the target data in cases in which the processor has determined the target data to be the permitted data, and not to permit the first application to access the target data in cases in which the processor has determined the target data not to be the permitted data.


