Secure Software Agent for Dynamic Platform Security in Open Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing platform security methods for electronic devices are inadequate in preventing unauthorized use, malware, application piracy, and content piracy, particularly in open devices with open source operating systems, as they can be circumvented and lack comprehensive verification and recovery mechanisms.

Innovation Solution

A dynamic platform security system is implemented, featuring a secure software agent embedded within an abstraction layer between device hardware and application software, along with a secure store for continuous runtime security information, ensuring ongoing integrity and access control, and enabling the deployment of diverse and updated agents to counter attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional platform security methods are used in open devices, then device openness and third-party application support are maintained, but security against unauthorized use, malware, and piracy is compromised

Engineering Contradiction:
Improvedevice opennessVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security system is segmented into multiple independent components: a secure software agent embedded in the OS kernel, a separate secure store for security information, and an abstraction layer between hardware and applications. This segmentation allows the security mechanisms to be updated and replaced independently without affecting the open device architecture or third-party applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure software agent is introduced as an intermediary component between the hardware and third-party applications. This agent acts as a security gatekeeper that verifies application integrity, controls access to digital assets, and detects malware without preventing the device from supporting open third-party applications. The agent mediates all security-critical operations while maintaining system openness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If static security measures are implemented, then initial security verification is provided, but the ability to recover from attacks and adapt to new threats is lost

Engineering Contradiction:
Improveinitial security verificationVSAvoidrecovery and update capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The security system transitions from static to dynamic through the secure software agent that can be updated in the field. The agent receives security information updates from a remote server, allowing the system to adapt to new threats and recover from attacks without requiring device replacement. The security properties of the agent can change over time while maintaining continuous protection.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements feedback mechanisms where the secure software agent continuously monitors system integrity, detects security breaches, and communicates with a remote server to receive updates. This feedback loop enables the system to learn from attacks and improve its security posture dynamically, allowing recovery from compromised states through agent updates.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive security verification is performed on all applications and system components, then security against malware and piracy is improved, but system performance and user experience deteriorate

Engineering Contradiction:
Improvesecurity verificationVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Security verification is performed in advance during the application installation and provisioning process. The secure software agent verifies application integrity, checks digital signatures, and establishes security policies before applications are executed. This preliminary security checking prevents malware and piracy without impacting runtime performance of legitimate applications.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The secure software agent implements self-verification mechanisms to validate its own integrity and the integrity of security-critical system components. By performing self-checks and using cryptographic verification, the system achieves comprehensive security without requiring continuous external validation that would degrade performance. The agent autonomously maintains security without constant user intervention or system-wide performance overhead.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2684152B1Method and system for dynamic platform security in a device operating system
Publication Date: 2020.07.22 IRDETO BV
  • EP2684152B1 patent drawingFigure 1
  • EP2684152B1 patent drawingFigure 2A
  • EP2684152B1 patent drawingFigure 2B

AI summary

A system and method is provided for implementing platform security on a consumer electronic device having an open development platform. The device is of the type which includes an abstraction layer operable between device hardware and application software. A secure software agent is provided for embedding within the abstraction layer forming the operating system. A secure store is provided for storing security information unique to one or more instances of the application software. The secure software agent uses the security information for continuous runtime assurance of ongoing operational integrity of the operating system and application software and thus operational integrity of the device.