Program Verification System for Secure Environment Maliciousness Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing secure execution environments struggle to detect and prevent malicious programs that may appear non-malicious during verification but become malicious upon operation, due to their protection mechanisms making external interference difficult.
Innovation Solution
A program verification system that includes maliciousness verification, program execution function verification, and external input attack defense function verification, along with a signature mechanism to ensure only safe programs are executed within the secure environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a program is placed in the secure environment without comprehensive verification, then the ease of operation is improved, but the reliability deteriorates due to undetected maliciousness
Solution Approach 1:
The patent performs preliminary verification actions before placing a program in the secure environment. The verification unit checks for program execution functions and external input attack defense functions before deployment, ensuring that only verified safe programs are placed in the secure environment, thus preventing malicious programs from being deployed while maintaining ease of operation for legitimate programs.
Solution Approach 2:
The patent applies preliminary anti-action by proactively detecting and preventing malicious program execution functions and external input attack vulnerabilities before they can be exploited. The verification unit identifies potential threats in advance and prevents the program from being placed in the secure environment, countering potential attacks before they occur.
2Reliability
If comprehensive verification functions are added to detect maliciousness, then the reliability is improved, but the device complexity increases
Solution Approach 1:
The patent extracts specific critical verification functions from a comprehensive verification system. Instead of implementing all possible verification checks, the invention focuses on extracting and verifying only the most critical functions: program execution function detection and external input attack defense function detection. This reduces device complexity while maintaining high reliability for the most important security aspects.
Solution Approach 2:
The patent applies local quality by concentrating verification resources on specific critical areas rather than uniformly verifying all program aspects. The verification unit focuses its analysis on detecting program execution functions and external input attack vulnerabilities, applying intensive verification locally to these high-risk areas while avoiding unnecessary verification of other less critical program components.
3Reliability
If the secure environment protection mechanism is strengthened, then the reliability is improved, but the ease of repair deteriorates as external interference becomes difficult
Solution Approach 1:
The patent performs preliminary verification of program update contents before allowing them to be executed in the secure environment. The verification unit checks updated programs for malicious execution functions and external input attack vulnerabilities before deployment, ensuring that program updates maintain security while enabling the secure environment's protection mechanism to remain strong without compromising update capability.
Data Source
AI summary
A program verification system of the invention includes program verification means 51 for verifying whether a verification target program input as a program operating in a secure environment does not include a program execution function which is a function of executing a new program in the same environment by a command in the corresponding program and/or whether the verification target program or a protection mechanism of the secure environment as an operation source of the verification target program includes an external input attack defense function which is a function of defending against an attack caused by an external data input during execution of the program; and signature means 52 for giving a signature to the program based on a result of the verification by the program verification means 51.


