Centralized OS Security Assessor Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security mechanisms for computer systems lack a consistent and comprehensive method for authenticating and verifying the identity and integrity of programs, leading to potential security breaches and system performance issues due to the hodge-podge nature of existing security programs.

Innovation Solution

A novel security framework integrated into the operating system that includes a security assessor and a rules database to evaluate the authenticity of applications and data files based on security policies, using signature verification and priority rules to ensure only trusted operations are executed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple separate security programs are used to address different security needs, then security coverage is improved, but system complexity and performance overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple separate security programs into a single integrated security architecture within the operating system. The security assessor module consolidates functions of anti-virus applications, firewalls, malware detection programs, and signature checking mechanisms into one unified system that comprehensively checks all operations running in the operating system through a centralized security policy framework.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The security assessor is designed as a universal security mechanism that performs multiple security functions through a single component. It can assess different types of operations (application installation, execution, file operations) and enforce various security policies (signature verification, code requirements, publisher authentication) through one integrated system rather than requiring separate specialized programs for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If comprehensive security checks are performed on all operations, then security reliability is improved, but system performance and speed deteriorate

Engineering Contradiction:
Improvesecurity assessment thoroughnessVSAvoidsystem speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security assessor performs preliminary security assessments of applications and data objects before they are executed or operate within the system. By evaluating security policies, verifying signatures, and checking code requirements in advance during installation or initial loading, the system prevents potentially harmful operations from running, thereby maintaining high system speed without compromising security thoroughness.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If uniform security interface programming is introduced for software developers, then ease of operation is improved, but device complexity increases

Engineering Contradiction:
Improvesoftware development uniformityVSAvoidsecurity framework complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The security assessor automatically evaluates whether applications meet security policies without requiring manual configuration or complex interface programming by developers. The system self-services by autonomously verifying signatures, checking code requirements, and enforcing security rules through a standardized internal framework that provides uniform security assessment while maintaining ease of operation for software developers.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS10122759B2Centralized operation management
Publication Date: 2018.11.06 APPLE INC
  • US10122759B2 patent drawing
  • US10122759B2 patent drawing
  • US10122759B2 patent drawing

AI summary

A novel security framework that is part of an operating system of a device is provided. The framework includes a security assessor that performs security policy assessments for different operations that need to be performed with respect to an application executing on the device. Examples of such operations include the installation of the application, execution of the application, and the opening of content files (e.g., opening of documents) by the application.