Secure System Configuration Branching With Early Security Evaluation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing automatic design technologies for secure system configurations face inefficiencies and security gaps, requiring repeated generation and evaluation of system proposals to find secure configurations, leading to prolonged processing times.
Innovation Solution
A secure system automatic design apparatus and method that integrates an input/output unit, configuration information concretization unit, and security evaluation unit to generate and evaluate multiple configuration drafts in a stepwise manner, branching options based on security evaluations to efficiently derive secure system configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If security evaluation is performed only on concrete system configuration proposals, then security assessment accuracy is improved, but processing time increases significantly due to repeated generation and evaluation cycles
Solution Approach 1:
The patent applies preliminary action by performing security evaluation on configuration drafts (intermediate designs) before final concrete system configuration proposals are generated. The security evaluation unit evaluates configuration drafts at multiple concretization steps, allowing early identification and rejection of insecure design paths before substantial processing resources are wasted on generating complete concrete proposals from insecure drafts.
Solution Approach 2:
The patent segments the design process into multiple concretization steps, with configuration drafts generated at each step. Security evaluation is applied at each segment rather than only at the final stage. This segmentation allows the system to evaluate and prune insecure paths incrementally, reducing the total number of complete proposals that need to be generated and evaluated.
2Productivity
If the search range is narrowed by evaluating configuration drafts early in the concretization process, then processing efficiency is improved, but security evaluation becomes inapplicable since draft evaluation means are not available
Solution Approach 1:
The patent makes the security evaluation unit universal by enabling it to evaluate both configuration drafts (intermediate designs) and concrete system configuration proposals. The security evaluation means is designed to handle multiple types of input data at different stages of the concretization process, allowing early security assessment without requiring separate evaluation mechanisms for drafts versus final proposals.
3Reliability
If multiple configuration drafts are generated and evaluated at each concretization step, then secure system configurations are ensured, but the complexity of the design process increases
Solution Approach 1:
The patent applies dynamics by making the concretization process adaptive based on security evaluation results. The configuration information concretization unit dynamically adjusts which concretization paths to pursue based on security assessment outcomes. Insecure drafts are rejected and their branches pruned, while secure drafts are continued. This dynamic adaptation reduces the effective complexity by eliminating unnecessary evaluation paths while maintaining comprehensive security coverage.
Data Source
AI summary
A secure system automatic design apparatus includes: an input/output unit that receives an input of a system requirement and output a system configuration; a configuration information concretization unit that converts the system requirement into the system configuration through a plurality of concretization procedures; and a security evaluation unit that evaluates security of the system configuration. In each of the concretization procedures, the configuration information concretization unit generates a plurality of configuration drafts, each of the configuration drafts being configuration information that is being converted and each of the configuration drafts being branched to a plurality of options of a concretization method. The security evaluation unit also evaluates security of each of the configuration drafts generated through the respective procedures. The configuration information concretization unit determines the option to be branched based on a result of the evaluation of each of the configuration drafts by the security evaluation unit.


