Secure Computational Environment via Component Extraction and Data Slicing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional defense solutions fail to effectively address the underlying issues that allow exploits and threats in software components, such as prolonged exposure and administrative access, leading to difficulty in discovering compromised components and mitigating their negative effects.

Innovation Solution

A system that limits exploitable sub-components, replaces software components with known-good versions without detection of compromise, and secures information by interleaving and encrypting data slices using different cryptographic schemes within data packets with varying headers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional defense solutions (firewalls, anti-malware detection) are used to identify and mitigate threats, then security monitoring capability is improved, but the underlying issues allowing exploits to exist (prolonged exposure, administrative access) are not addressed, leading to continued vulnerability

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoidunderlying vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes exploitable sub-components (such as administrative access interfaces and unnecessary privileges) from software components before deployment. This extraction eliminates the root causes of vulnerability rather than merely detecting threats, directly resolving the contradiction between monitoring capability and underlying vulnerability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary actions by replacing software components with known-good versions before they can be compromised or exploited in the runtime environment. This preventive approach addresses vulnerabilities before exploits can occur, rather than relying solely on post-compromise detection.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If software components are exposed in the runtime environment for long periods to provide administrative access and privileges, then operational functionality is improved, but the risk of compromise and exploitation increases

Engineering Contradiction:
Improveoperational functionalityVSAvoidrisk of compromise
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent implements short-lived software component instances that are automatically replaced after use or after a predetermined period. These temporary components provide necessary administrative access for operations but are discarded before they can be compromised, resolving the contradiction between operational functionality and security risk.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Solution Approach 2:

The system discards potentially compromised components by automatically replacing them with known-good versions from a secure repository. This discarding mechanism ensures that even if components are exposed during operation, they are replaced before exploitation can occur, maintaining both functionality and security.

Inventive Principle:
Principle #34Discarding and recovering

3Adaptability or versatility

If networks are exposed via connections required to maintain components in the runtime environment, then component accessibility is improved, but network exposure creates additional attack vectors

Engineering Contradiction:
Improvecomponent accessibilityVSAvoidnetwork attack vectors
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and removes network exposure risks by isolating the runtime environment from direct network access. Components are replaced through a secure repository interface rather than direct network connections, eliminating attack vectors while maintaining component accessibility through the controlled replacement mechanism.

Inventive Principle:
Principle #2Taking out (Extraction)

4Loss of energy

If software components are replaced only after compromise detection, then resource usage is optimized, but extensive damage may have already been inflicted by the time of discovery

Engineering Contradiction:
Improveresource usageVSAvoiddamage from compromise
Core Design Contradiction:
Loss of energyVSObject-generated harmful factors

Solution Approach 1:

The system implements periodic replacement of software components with known-good versions from a secure repository, regardless of whether compromise is detected. This periodic action occurs at predetermined intervals or after a number of uses, ensuring that components are refreshed before exploitation can occur while optimizing resource usage by not requiring continuous monitoring and detection.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP2885739B1System and method for providing a secure computational environment
Publication Date: 2019.10.02 FUGUE INC
  • EP2885739B1 patent drawingFigure 1
  • EP2885739B1 patent drawingFigure 2
  • EP2885739B1 patent drawingFigure 3

AI summary

Approaches for providing a secure computational environment are disclosed. In certain implementations, a secure computational environment may be provided by: limiting exploitable or potentially exploitable sub-components in software components; replacing software components with corresponding known-good software components without regard to whether the software components have been compromised or potentially compromised; combining different information to be transmitted into different slices of a data packet and/or encrypting the slices using different cryptographic schemes; processing a data packet having data slices associated with different information that are encrypted using different cryptographic schemes; securing information using data packets having headers that start at different positions within a data packet with respect to other data packets; processing data packets having headers that start at different positions within a data packet with respect to other data packets; or utilizing other approaches.