Open Architecture Security via Component Trust Levels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Open architecture platforms used in devices like controllers are vulnerable to cyber security threats due to the inability to restrict actions of installed components and authenticate the source of input during runtime, posing challenges in providing security for multiple users with varying levels of trust.
Innovation Solution
Implementing a method that identifies the source of computing components, assigns a trust value based on the source, and designates them into security levels, restricting interactions between components of different security levels to prevent cyber threats.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an open architecture platform utilizes products from multiple entities to enhance adaptability and versatility, then the platform's functionality and flexibility improve, but the system becomes vulnerable to cyber security threats due to inability to authenticate sources and restrict component actions
Solution Approach 1:
The patent segments the open architecture platform into multiple security levels (e.g., system level, application level, data level) and assigns computing components to appropriate levels based on their trustworthiness. This segmentation allows the platform to maintain versatility by accepting components from multiple sources while improving security by isolating components at different security levels and restricting interactions between levels.
Solution Approach 2:
The patent introduces an intermediary security management mechanism that acts as a mediator between computing components and the platform core. This intermediary authenticates component sources, assigns security levels, and enforces access control policies, thereby enabling the platform to utilize diverse components while protecting against cyber threats through controlled interactions.
2Ease of operation
If the platform allows unrestricted installation and execution of computing components to maintain ease of operation, then system flexibility improves, but security control deteriorates due to inability to restrict component actions
Solution Approach 1:
The patent applies preliminary action by authenticating computing components and assigning security levels before they are installed and executed on the platform. The security management mechanism pre-evaluates component sources, verifies digital signatures or certificates, and determines appropriate security classifications in advance, thereby enabling easy installation while preventing harmful actions through pre-established security constraints.
Solution Approach 2:
The patent applies local quality by assigning different security attributes and access permissions to different computing components based on their specific characteristics and trustworthiness. Each component is evaluated individually and assigned to appropriate security levels with specific permitted actions, rather than applying uniform restrictions, thereby maintaining operational flexibility while preventing unauthorized actions through targeted security controls.
Data Source
AI summary
Devices, methods, systems, and computer-readable media for open architecture security are described herein. One or more embodiments include a method for open architecture security, comprising: identifying a source of a received computing component, assigning a value to the received computing component based on the source, and designating the received computing component into a security level based on the assigned value.


