Protected Mode Service Integrity Verification for COTS Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computing systems restrict devices using commercial off-the-shelf (COTS) hardware and software from connecting to protected mode systems, as they are not trusted, limiting the ability to securely communicate with services running in protected mode environments.
Innovation Solution
A method and apparatus that utilize COTS hardware and software components to securely communicate with protected mode services by initiating a protected mode service, verifying the integrity of unprotected mode services through unique digital signatures, and registering them as child processes, allowing secure boot and expanded functionality within protected mode environments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional computing systems restrict access to protected mode services, then system security is improved, but device functionality and adaptability deteriorate
Solution Approach 1:
The patent introduces an intermediary component that acts as a bridge between COTS devices and protected mode services. This intermediary verifies the integrity of COTS components and facilitates their secure access to protected mode services, resolving the contradiction by allowing functionality expansion while maintaining security through verification mechanisms.
Solution Approach 2:
The system is segmented into distinct components: protected mode services, verification mechanisms, and COTS device interfaces. This segmentation allows each component to operate with appropriate security levels while enabling controlled interaction, thus improving both security and adaptability simultaneously.
2Adaptability or versatility
If COTS hardware and software components are allowed to connect to protected mode systems, then device versatility is improved, but system security deteriorates
Solution Approach 1:
The system performs preliminary verification actions before allowing COTS components to access protected mode services. Integrity verification is conducted in advance, and only components that pass verification are granted access, thus enabling versatility while preventing security compromises.
Solution Approach 2:
An intermediary verification mechanism is introduced between COTS components and protected mode services. This intermediary checks the integrity of COTS components and mediates their access requests, allowing versatile connectivity while maintaining security through the verification layer.
3Reliability
If integrity verification of unprotected mode services is implemented, then system security is improved, but processing time and complexity increase
Solution Approach 1:
Integrity verification is performed as a preliminary action before service execution. By verifying integrity in advance and caching verification results, the system avoids repeated verification overhead during service execution, thus improving security while minimizing time loss.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed herein is a method for executing unprotected mode services in a protected mode computing environment includes initiating a protected mode service that is configured to execute in a protected mode. Further, the method includes verifying an integrity of one or more unprotected mode services configured to execute in an unprotected mode. The one or more unprotected mode services is registered with the protected mode service. The method also includes initiating an unprotected mode service of the one or more unprotected mode services in response to the integrity of the unprotected mode service being verified.