Secure Computing System With Segmented Processing And Interface Unit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer systems lack robust security measures, particularly in personal computers, which are vulnerable to malware and other security threats due to inadequate implementation of formal security models like Bell-LaPadula and Biba. This leads to reactive defense mechanisms and high costs associated with developing secure systems.

Innovation Solution

A computer system with multiple security levels is proposed, comprising a high-power processing device and a low-power processing device, along with an interface unit that manages classified information according to formal rules for confidentiality and integrity. The low-power device operates at the highest possible integrity level, with secure data and code stored in firmware or hardware that cannot be altered by normal software routines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If antivirus software and reactive security measures are used, then malware detection capability is improved, but security reliability is worsened because the protection is applied after infection occurs

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidsecurity reliability
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent implements security measures at the hardware and firmware level before the operating system and software can be infected. The low-power processing device stores security-critical data and code in protected memory that cannot be accessed or modified by normal software operations, preventing malware infection before it can occur. This preliminary security architecture ensures that even if the operating system is compromised, the core security functions remain intact.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If security measures are built into system architecture from the start, then security reliability is improved, but device complexity is worsened

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the processing system into two distinct segments: a high-power processing device for running the operating system and applications, and a low-power processing device for executing security-critical functions. This segmentation isolates security functions from the main system, allowing robust security architecture without significantly complicating the overall device design. Each segment has dedicated memory and processing capabilities optimized for its specific function.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an interface unit as an intermediary between the high-power and low-power processing devices. This interface unit manages all data transfers and communications between the two segments, enforcing security policies and preventing unauthorized access. The intermediary simplifies the architecture by providing a standardized, controlled interface rather than requiring direct complex interactions between the security subsystem and main system.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If formal security models like Bell-LaPadula and Biba are implemented, then confidentiality and integrity are improved, but ease of operation is worsened due to restricted access controls

Engineering Contradiction:
Improveconfidentiality and integrityVSAvoiduser access convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent creates a virtualized environment where multiple operating systems can run simultaneously on the low-power processing device, each with its own isolated memory space and access controls. This allows different security levels and access policies to coexist without interfering with user operations. Users can access their data and applications through virtualized interfaces that enforce security policies transparently, maintaining ease of operation while ensuring formal security model compliance.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS12299147B2Secure computing system
Publication Date: 2025.05.13 CUPP COMPUTING
  • US12299147B2 patent drawing
  • US12299147B2 patent drawing
  • US12299147B2 patent drawing

AI summary

A computer system with multiple security levels, the system comprising a high-power processing device (130), a low-power processing device (110), and an interface unit (120) comprising functions for moving classified information between the high-power device (130) and the low-power device (110) according to formal rules for confidentiality and/or integrity. Additional security aspects, e.g. availability, may readily be accommodated. A method for implementing multiple levels of security along a number of independent security axes on the system is also disclosed.