Sealed CPU for Real-Time Object Code Integrity Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security solutions are inadequate in preventing cyber attacks as they primarily focus on detecting and mitigating known hacking techniques, failing to effectively block unauthorized cyber interventions, especially new or future variants, and do not address internal or external infiltrations proactively.

Innovation Solution

An artificial intelligence system securely stores executable binary object code in a Sealed-off Central Processing Unit (SCPU) with no external communication interfaces, constantly reads and compares the object code, blocks unmatched sections, and notifies IT security authorities for review, ensuring immediate and proactive blocking of unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing security programs focus on detecting known hacking techniques, then detection capability for existing threats is improved, but the ability to block new or future cyber attack variants deteriorates

Engineering Contradiction:
Improvedetection capabilityVSAvoidability to block new attack variants
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a sealed copy of the original application code before execution and stores it in an isolated SCPU environment. This preliminary action establishes a reference baseline that enables detection of any code modifications or injections during runtime, regardless of whether the attack method is known or novel.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system separates the code protection functionality into a distinct SCPU component that is isolated from the main application environment. This segmentation allows the security mechanism to operate independently and compare code integrity without interfering with application execution, enabling universal protection against diverse attack vectors.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security systems use complex system engineering approaches, then detection of specific hacking techniques is improved, but the ability to prevent all unauthorized interventions deteriorates

Engineering Contradiction:
Improvedetection reliabilityVSAvoidunauthorized cyber interventions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary SCPU that acts as a mediator between the original application code and the execution environment. This SCPU receives the application code, creates a sealed copy for comparison purposes, and monitors code integrity during execution, thereby preventing unauthorized interventions without requiring complex analysis of potential threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If security programs focus on post-detection malware removal, then response to known threats is improved, but proactive prevention of cyber attacks deteriorates

Engineering Contradiction:
Improveresponse efficiencyVSAvoidproactive prevention capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary code sealing and integrity baseline establishment before the application executes. This proactive measure ensures that any code modifications, whether from known malware or novel attacks, are detected immediately upon occurrence rather than requiring post-detection response actions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10762198B1Artificial intelligence system and method for instantly identifying and blocking unauthorized cyber intervention into computer application object code
Publication Date: 2020.09.01 DEA RICHARD
  • US10762198B1 patent drawing

AI summary

An artificial intelligence system and method securely stores all executable binary object code of a client/user's computer-based software applications in a separate and impenetrable Sealed-off Central Processing Unit (SCPU). The SCPU is shielded from any external communication interface by having no input ports or devices able to receive external transmissions. The SCPU executes four primary functions: 1. constantly reads all the primary object code in the client/user's application system; 2. simultaneously compares and matches the application system executable object code to the shielded executable object code copy stored in the SCPU; 3. permanently blocks the unmatched object code section(s) pending internal IT security team review of the unmatched object code; and, 4. notifies the client/user's authorized IT security authority of the blocked object code section(s) and submits to them a copy of the potentially invalid object code.