Trusted Secure Desktop for Network Data Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer security software is reactive and requires regular updates, making it inadequate in addressing the increasing complexity of threats, particularly in protecting data communicated between computers via networks, and fails to provide comprehensive protection against hackers, viruses, spyware, and malware.
Innovation Solution
The system involves transferring security software from an external memory device to an internal memory device of a client computer, establishing secure communications links with network sites, and providing keylogger prevention, code injection prevention, and screen scraper protection services through a trusted secure desktop environment, which includes user mode and kernel mode software to safeguard data communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional reactive security software is used, then the system can detect known threats, but it cannot prevent new or unknown threats and requires frequent updates
Solution Approach 1:
The patent implements a proactive security model by establishing secure desktop environments and security services before threats occur. The secure desktop is created in advance with protected processes and services that prevent malware execution, code injection, and screen scraping before these attacks can compromise the system.
Solution Approach 2:
The patent introduces a secure desktop as an intermediary layer between the user and the underlying operating system. This secure desktop acts as a mediator that intercepts and blocks malicious activities such as keyboard hooks, screen captures, and code injections, preventing them from reaching vulnerable applications.
2Reliability
If comprehensive security services are implemented, then protection against multiple threat types is achieved, but system complexity increases
Solution Approach 1:
The patent combines multiple security functions (keylogger prevention, code injection prevention, screen scraper protection, process protection) into a unified secure desktop environment. These diverse security services are merged into a single integrated system that manages all protections through a common architecture, reducing overall system complexity.
Solution Approach 2:
The secure desktop is designed as a universal security platform that provides multiple protection capabilities through a single system. The same secure desktop infrastructure handles keyboard protection, screen protection, process protection, and network security, eliminating the need for separate specialized security tools.
3Reliability
If secure desktop environment is created, then protection against keyboard hooks and screen scrapers is improved, but performance overhead increases
Solution Approach 1:
The secure desktop processes are designed to be self-protecting, with built-in mechanisms that automatically prevent keyboard hooks and screen scrapers without requiring continuous external monitoring. The security services run within the secure desktop and protect themselves, reducing the computational overhead of external security software.
Data Source
AI summary
Systems (100) and methods (400) for protecting data accessed through a network connection. The methods involve transferring security software (150) from an external memory device of a client computer (102) to an internal memory device of the client computer. The security software is operative to protect data communicated to and from the client computer via communication links. The security software is also operative to provide a web browser (1101, 1102, . . . , 110p) which executes in user mode on a trusted secured desktop (904) configured to run simultaneously with an unsecured desktop (902) of the client computer. The security software is further operative to provide a security service to the web browser. The security service includes at least one service selected from the group consisting of a keylogger prevention service, a code injection prevention service, and a screen scraper protection service.


