Remote Kernel Space Execution for Secure Device Maintenance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Communication systems face challenges in achieving good performance and efficient communication between devices, particularly in scenarios where service providers need to remotely access and control customer-premises equipment while ensuring privacy and security.
Innovation Solution
The implementation of a method and system that allows service providers to remotely execute computer instructions in the kernel space of communication devices, using an application server to send encrypted packages with instructions to the kernel space for execution, thereby enabling non-intrusive access and control.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a service provider representative visually inspects and gains operative control of the communication device, then the service provider can verify device usage and software version, but the customer loses full access to the communication device
Solution Approach 1:
The system segments access control by creating distinct user space and kernel space environments. The customer operates in the user space with full access to applications, while the service provider gains controlled access only to the kernel space for monitoring and verification purposes. This segmentation allows both parties to have appropriate levels of access without conflict.
Solution Approach 2:
The patent introduces a remote execution environment that acts as an intermediary between the service provider and the communication device. This intermediary enables the service provider to execute verification instructions remotely in the kernel space without requiring physical presence or disrupting customer operations in the user space.
2Ease of operation
If the service provider remotely executes instructions in the kernel space, then non-intrusive access is enabled, but system security and privacy concerns arise
Solution Approach 1:
The system divides the communication device into user space and kernel space with clearly defined boundaries. The service provider's remote execution is confined to the kernel space, which is isolated from the customer's user space applications. This segmentation ensures that remote access for maintenance does not compromise user data security or privacy.
Solution Approach 2:
The patent implements preliminary verification mechanisms where the service provider obtains and verifies cryptographic signatures of the remote execution instructions before execution. This preliminary validation ensures that only authorized and integrity-checked instructions are executed in the kernel space, preventing malicious code execution.
3Ease of operation
If the customer has full access to the communication device, then privacy and security are maintained, but the service provider cannot perform monitoring and maintenance
Solution Approach 1:
The system segments functionality by allowing the customer to maintain full access to user space applications while the service provider executes maintenance and monitoring instructions in the isolated kernel space. This segmentation enables both customer control and service provider productivity without mutual interference.
Solution Approach 2:
The remote execution environment serves as an intermediary that enables the service provider to perform maintenance operations without directly accessing or disrupting the customer's user space. The intermediary translates service provider maintenance requests into safe kernel space operations that do not interfere with customer applications.
4Reliability
If physical inspection is performed by service provider representative, then device control is verified, but customer operations are interrupted
Solution Approach 1:
The patent replaces the mechanical approach of physical inspection by service provider representatives with a remote execution system. The service provider can verify device status and execute maintenance instructions remotely through the kernel space, eliminating the need for physical presence and avoiding interruption of customer operations.
Solution Approach 2:
The remote execution environment acts as an intermediary that enables verification and maintenance operations to be performed remotely without physical intervention. This intermediary allows the service provider to maintain device reliability through remote monitoring and updates while keeping customer operations uninterrupted.
Data Source
AI summary
There is provided mechanisms for remote execution of computer instructions in a kernel space of a communication device. A method is performed by an application server for the communication device. The method comprises obtaining computer instructions for handling interaction between the application server and the kernel space. The computer instructions are to be remotely executed in the kernel space of the communication device. The method comprises sending an encrypted package comprises the computer instructions towards the kernel space of the communication device.


