Dynamic Platform Resource Access Control via Integrity Monitoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computer systems connected to networks are vulnerable to malware attacks, which can compromise their integrity and operation, and existing technologies lack effective methods to anticipate or respond to these threats, especially as network connectivity and accessibility increase.
Innovation Solution
A system that dynamically monitors and adjusts the accessibility of platform resources based on integrity levels, using a trusted platform module (TPM) or other trusted computing platform logic to detect and mitigate malware attacks by transitioning to a lower functionality level and re-establishing a high integrity level, thereby maintaining runtime operation and reducing the risk of compromise.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If network connectivity and accessibility are increased to support more users and services, then platform versatility and utility are improved, but vulnerability to malware attacks and integrity compromise increases
Solution Approach 1:
The system dynamically adjusts resource accessibility based on real-time integrity assessments. The enforcement domain continuously monitors the functional domain's integrity level and modifies access permissions accordingly, transitioning between different accessibility states to balance utility and security
Solution Approach 2:
An enforcement domain is introduced as an intermediary between the functional domain and platform resources. This mediator enforces accessibility rules based on integrity levels, allowing the system to maintain high accessibility when intact while automatically restricting access when compromise is detected
2Productivity
If the system maintains high functionality and resource accessibility, then productivity and user experience are improved, but the system becomes more vulnerable to malware compromise
Solution Approach 1:
The system implements dynamic functionality adjustment by transitioning between different operational states. When integrity is high, full functionality is available; when integrity drops below thresholds, the system automatically reduces functionality to maintain security while preserving critical operations
Solution Approach 2:
The system establishes predefined integrity thresholds and corresponding accessibility rules in advance. These pre-configured security policies enable the system to respond automatically to compromise attempts before they can cause significant damage, cushioning against potential harm
3Reliability
If the system restricts resource accessibility to maintain security, then system integrity is protected, but productivity and functionality are reduced
Solution Approach 1:
The accessibility control system dynamically adjusts resource permissions based on real-time integrity assessments. Rather than maintaining constant restrictions, the system grants full access when integrity is verified and only imposes restrictions when compromise is detected, minimizing productivity impact
4Reliability
If the system implements comprehensive integrity monitoring and dynamic accessibility control, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The system is divided into distinct domains: a functional domain that executes user applications and an enforcement domain that monitors integrity and enforces accessibility rules. This segmentation allows security functions to be separated from application execution, managing complexity through modular architecture
Data Source
AI summary
Techniques and mechanism to selectively provide resource access to a functional domain of a platform. In an embodiment, the platform includes both a report domain to monitor the functional domain and a policy domain to identify, based on such monitoring, a transition of the functional domain from a first integrity level to a second integrity level. In response to a change in integrity level, the policy domain may configure the enforcement domain to enforce against the functional domain one or more resource accessibility rules corresponding to the second integrity level. In another embodiment, the policy domain automatically initiates operations in aid of transitioning the platform from the second integrity level to a higher integrity level.


