Secure Software Agent for Dynamic Platform Security in Open Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing platform security methods for electronic devices are inadequate in preventing unauthorized use, malware, application piracy, and content piracy, particularly in open devices with open source operating systems, as they can be circumvented and lack comprehensive verification and recovery mechanisms.
Innovation Solution
A dynamic platform security system is implemented, featuring a secure software agent embedded within an abstraction layer between device hardware and application software, along with a secure store for continuous runtime security information, ensuring ongoing integrity and access control, and enabling the deployment of diverse and updated agents to counter attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional platform security methods are used in open devices, then device openness and third-party application support are maintained, but security against unauthorized use, malware, and piracy is compromised
Solution Approach 1:
The security system is segmented into multiple independent components: a secure software agent embedded in the OS kernel, a separate secure store for security information, and an abstraction layer between hardware and applications. This segmentation allows the security mechanisms to be updated and replaced independently without affecting the open device architecture or third-party applications.
Solution Approach 2:
A secure software agent is introduced as an intermediary component between the hardware and third-party applications. This agent acts as a security gatekeeper that verifies application integrity, controls access to digital assets, and detects malware without preventing the device from supporting open third-party applications. The agent mediates all security-critical operations while maintaining system openness.
2Reliability
If static security measures are implemented, then initial security verification is provided, but the ability to recover from attacks and adapt to new threats is lost
Solution Approach 1:
The security system transitions from static to dynamic through the secure software agent that can be updated in the field. The agent receives security information updates from a remote server, allowing the system to adapt to new threats and recover from attacks without requiring device replacement. The security properties of the agent can change over time while maintaining continuous protection.
Solution Approach 2:
The system implements feedback mechanisms where the secure software agent continuously monitors system integrity, detects security breaches, and communicates with a remote server to receive updates. This feedback loop enables the system to learn from attacks and improve its security posture dynamically, allowing recovery from compromised states through agent updates.
3Reliability
If comprehensive security verification is performed on all applications and system components, then security against malware and piracy is improved, but system performance and user experience deteriorate
Solution Approach 1:
Security verification is performed in advance during the application installation and provisioning process. The secure software agent verifies application integrity, checks digital signatures, and establishes security policies before applications are executed. This preliminary security checking prevents malware and piracy without impacting runtime performance of legitimate applications.
Solution Approach 2:
The secure software agent implements self-verification mechanisms to validate its own integrity and the integrity of security-critical system components. By performing self-checks and using cryptographic verification, the system achieves comprehensive security without requiring continuous external validation that would degrade performance. The agent autonomously maintains security without constant user intervention or system-wide performance overhead.
Data Source
Figure 1
Figure 2A
Figure 2B
AI summary
A system and method is provided for implementing platform security on a consumer electronic device having an open development platform. The device is of the type which includes an abstraction layer operable between device hardware and application software. A secure software agent is provided for embedding within the abstraction layer forming the operating system. A secure store is provided for storing security information unique to one or more instances of the application software. The secure software agent uses the security information for continuous runtime assurance of ongoing operational integrity of the operating system and application software and thus operational integrity of the device.