Dynamic Platform Resource Access Control via Integrity Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems connected to networks are vulnerable to malware attacks, which can compromise their integrity and operation, and existing technologies lack effective methods to anticipate or respond to these threats, especially as network connectivity and accessibility increase.

Innovation Solution

A system that dynamically monitors and adjusts the accessibility of platform resources based on integrity levels, using a trusted platform module (TPM) or other trusted computing platform logic to detect and mitigate malware attacks by transitioning to a lower functionality level and re-establishing a high integrity level, thereby maintaining runtime operation and reducing the risk of compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If network connectivity and accessibility are increased to support more users and services, then platform versatility and utility are improved, but vulnerability to malware attacks and integrity compromise increases

Engineering Contradiction:
Improveplatform accessibilityVSAvoidmalware attack risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system dynamically adjusts resource accessibility based on real-time integrity assessments. The enforcement domain continuously monitors the functional domain's integrity level and modifies access permissions accordingly, transitioning between different accessibility states to balance utility and security

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

An enforcement domain is introduced as an intermediary between the functional domain and platform resources. This mediator enforces accessibility rules based on integrity levels, allowing the system to maintain high accessibility when intact while automatically restricting access when compromise is detected

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If the system maintains high functionality and resource accessibility, then productivity and user experience are improved, but the system becomes more vulnerable to malware compromise

Engineering Contradiction:
Improvesystem functionalityVSAvoidsystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements dynamic functionality adjustment by transitioning between different operational states. When integrity is high, full functionality is available; when integrity drops below thresholds, the system automatically reduces functionality to maintain security while preserving critical operations

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system establishes predefined integrity thresholds and corresponding accessibility rules in advance. These pre-configured security policies enable the system to respond automatically to compromise attempts before they can cause significant damage, cushioning against potential harm

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If the system restricts resource accessibility to maintain security, then system integrity is protected, but productivity and functionality are reduced

Engineering Contradiction:
Improvesystem integrityVSAvoidsystem functionality
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The accessibility control system dynamically adjusts resource permissions based on real-time integrity assessments. Rather than maintaining constant restrictions, the system grants full access when integrity is verified and only imposes restrictions when compromise is detected, minimizing productivity impact

Inventive Principle:
Principle #15Dynamics

4Reliability

If the system implements comprehensive integrity monitoring and dynamic accessibility control, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into distinct domains: a functional domain that executes user applications and an enforcement domain that monitors integrity and enforces accessibility rules. This segmentation allows security functions to be separated from application execution, managing complexity through modular architecture

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9479513B1Apparatus, method and system to control accessibility of platform resources based on an integrity level
Publication Date: 2016.10.25 NATIONAL TECHNOLOGY & ENGINEERING SOLUTIONS OF SANDIA LLC
  • US9479513B1 patent drawing
  • US9479513B1 patent drawing
  • US9479513B1 patent drawing

AI summary

Techniques and mechanism to selectively provide resource access to a functional domain of a platform. In an embodiment, the platform includes both a report domain to monitor the functional domain and a policy domain to identify, based on such monitoring, a transition of the functional domain from a first integrity level to a second integrity level. In response to a change in integrity level, the policy domain may configure the enforcement domain to enforce against the functional domain one or more resource accessibility rules corresponding to the second integrity level. In another embodiment, the policy domain automatically initiates operations in aid of transitioning the platform from the second integrity level to a higher integrity level.