Program Verification System for Secure Environment Maliciousness Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing secure execution environments struggle to detect and prevent malicious programs that may appear non-malicious during verification but become malicious upon operation, due to their protection mechanisms making external interference difficult.

Innovation Solution

A program verification system that includes maliciousness verification, program execution function verification, and external input attack defense function verification, along with a signature mechanism to ensure only safe programs are executed within the secure environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a program is placed in the secure environment without comprehensive verification, then the ease of operation is improved, but the reliability deteriorates due to undetected maliciousness

Engineering Contradiction:
Improveease of program deploymentVSAvoidprogram safety
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent performs preliminary verification actions before placing a program in the secure environment. The verification unit checks for program execution functions and external input attack defense functions before deployment, ensuring that only verified safe programs are placed in the secure environment, thus preventing malicious programs from being deployed while maintaining ease of operation for legitimate programs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by proactively detecting and preventing malicious program execution functions and external input attack vulnerabilities before they can be exploited. The verification unit identifies potential threats in advance and prevents the program from being placed in the secure environment, countering potential attacks before they occur.

Inventive Principle:
Principle #9Preliminary anti-action

2Reliability

If comprehensive verification functions are added to detect maliciousness, then the reliability is improved, but the device complexity increases

Engineering Contradiction:
Improveprogram safetyVSAvoidverification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts specific critical verification functions from a comprehensive verification system. Instead of implementing all possible verification checks, the invention focuses on extracting and verifying only the most critical functions: program execution function detection and external input attack defense function detection. This reduces device complexity while maintaining high reliability for the most important security aspects.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent applies local quality by concentrating verification resources on specific critical areas rather than uniformly verifying all program aspects. The verification unit focuses its analysis on detecting program execution functions and external input attack vulnerabilities, applying intensive verification locally to these high-risk areas while avoiding unnecessary verification of other less critical program components.

Inventive Principle:
Principle #3Local quality

3Reliability

If the secure environment protection mechanism is strengthened, then the reliability is improved, but the ease of repair deteriorates as external interference becomes difficult

Engineering Contradiction:
Improvesecure environment protectionVSAvoidprogram update ability
Core Design Contradiction:
ReliabilityVSEase of repair

Solution Approach 1:

The patent performs preliminary verification of program update contents before allowing them to be executed in the secure environment. The verification unit checks updated programs for malicious execution functions and external input attack vulnerabilities before deployment, ensuring that program updates maintain security while enabling the secure environment's protection mechanism to remain strong without compromising update capability.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11409886B2Program verification system, method, and program
Publication Date: 2022.08.09 NEC CORP
  • US11409886B2 patent drawing
  • US11409886B2 patent drawing
  • US11409886B2 patent drawing

AI summary

A program verification system of the invention includes program verification means 51 for verifying whether a verification target program input as a program operating in a secure environment does not include a program execution function which is a function of executing a new program in the same environment by a command in the corresponding program and/or whether the verification target program or a protection mechanism of the secure environment as an operation source of the verification target program includes an external input attack defense function which is a function of defending against an attack caused by an external data input during execution of the program; and signature means 52 for giving a signature to the program based on a result of the verification by the program verification means 51.