OS Object Security via Matrix Register Whitelisting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer operating system security strategies are inadequate in preventing unauthorized access and download of confidential data, as bona fide users and cybercriminals can access and download data with Read authority, and cybercriminals can easily obtain user IDs and passwords, allowing them to exploit both confidential and non-confidential data.

Innovation Solution

A computer operating system with an object security system that utilizes a Matrix register to control access to confidential data objects by determining authorized applications and blocking unauthorized access, incorporating a whitelisting mechanism to ensure only permitted applications can access designated confidential data objects, and an automatic whitelisting wizard to maintain the whitelist.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If Read authority is granted to database users, then users can access and download data, but cyber criminals can also access and download confidential data using stolen user IDs and passwords

Engineering Contradiction:
Improvedata accessibilityVSAvoidunauthorized data access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments database access into two distinct layers: traditional user authentication (User ID/Password) for legitimate users, and a new Application-level authentication layer using the Matrix register to identify authorized applications. This segmentation allows the system to distinguish between legitimate user access and criminal access patterns, enabling selective protection of confidential data while maintaining ease of operation for authorized users.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between the database and the user/application. The Matrix register acts as a mediator that intercepts access requests and determines whether the requesting application is authorized to access specific confidential data objects. This intermediary mechanism prevents direct access by cyber criminals while allowing legitimate applications to access data through proper authentication channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive access controls are implemented to prevent unauthorized access, then security is improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidaccess control system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-establishing the Matrix register before any data access occurs. The Matrix is populated with authorized application-program mappings in advance, allowing the security system to automatically evaluate and approve or deny access requests based on pre-defined rules. This eliminates the need for complex real-time authentication decisions and reduces system complexity while maintaining high security.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The access control system performs self-service by automatically evaluating each access request against the Matrix register without requiring manual intervention or complex decision-making processes. The system autonomously determines authorization status based on the pre-configured Matrix entries, simplifying the architecture while ensuring consistent and reliable security enforcement.

Inventive Principle:
Principle #25Self-service

3Object-affected harmful factors

If application-level authentication is introduced to control data access, then unauthorized access is prevented, but the system requires additional authentication mechanisms

Engineering Contradiction:
Improveunauthorized application accessVSAvoidauthentication mechanism
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent applies universality by designing the Matrix register to serve multiple functions: it authenticates applications, controls data access rights, and maintains security policies. This multi-functional approach consolidates what would otherwise require separate complex systems into a single unified mechanism, reducing overall system complexity while providing robust protection against unauthorized application access.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11151274B2Enhanced computer objects security
Publication Date: 2021.10.19 HADDAD ELIAS
  • US11151274B2 patent drawing
  • US11151274B2 patent drawing
  • US11151274B2 patent drawing

AI summary

A computer-implemented method for providing new data object metadata, and by enhancing the scope of OS functionality, block the exfiltration and corruption of data (including ransomware) by cybercriminals and insiders.