Payment-Based Security for Computing Resources

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional systems are ineffective in preventing malicious computing actions, especially from authorized users who become disgruntled or attackers who have breached security layers, as they lack defense mechanisms against insider threats and unauthorized access.

Innovation Solution

Implementing a system that requires a payment for each action on a computing resource, using a transfer scheme where authorized agents pay the owner, and unauthorized agents pay the owner directly, with payments processed via cryptocurrencies, to deter malicious actions and provide reimbursement for victims.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems (firewalls, anti-malware, authentication) are used to protect computing resources, then security barriers are established, but they do little or nothing to hinder attackers who have breached these layers or insider threats from authorized users

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidmalicious actions from unauthorized or authorized agents
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent converts the harmful factor of malicious actions into a beneficial economic deterrent by requiring payment for each action. Instead of trying to prevent all malicious actions through complex security measures, the system allows actions to proceed but charges a fee that malicious actors cannot or will not pay, thereby converting the security problem into an economic barrier that protects the system.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

2Object-affected harmful factors

If a payment system is implemented to deter malicious actions, then malicious users are hindered by financial compensation requirements, but the system complexity increases

Engineering Contradiction:
Improvemalicious computing actionsVSAvoidsystem architecture
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent introduces a payment intermediary layer between the agent and the computing resource. This intermediary handles the payment verification and action authorization, simplifying the overall system by centralizing the security check in a single payment verification step rather than requiring complex multi-layered security infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Object-affected harmful factors

If payment verification is performed for each action, then malicious actions are prevented, but the speed of legitimate operations may be reduced

Engineering Contradiction:
Improveunauthorized actionsVSAvoidoperation speed
Core Design Contradiction:
Object-affected harmful factorsVSSpeed

Solution Approach 1:

The patent performs payment verification as a preliminary action before allowing the computing action to proceed. By checking payment status in advance and caching the verification result, the system ensures that malicious actions are blocked while minimizing the impact on legitimate operations, as the payment check is performed once before the actual computing task.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11394741B1Systems and methods for hindering malicious computing actions
Publication Date: 2022.07.19 GEN DIGITAL INC
  • US11394741B1 patent drawing
  • US11394741B1 patent drawing
  • US11394741B1 patent drawing

AI summary

The disclosed computer-implemented method for hindering malicious computing actions may include (i) identifying an attempt by an agent to perform an action on a computing resource that is vulnerable to attempted actions performed by unauthorized agents, (ii) requesting from the agent, in response to identifying the attempt to perform the action on the computing resource, a payment to an owner of the computing resource equal to a monetary value assigned to performing the action on the computing resource, (iii) receiving, by the owner of the computing resource, the payment of the monetary value from the agent, and (iv) allowing, in response to receiving the payment of the monetary value from the agent, the attempt by the agent to perform the action on the computing resource. Various other methods, systems, and computer-readable media are also disclosed.