Trusted Secure Desktop for Network Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional computer security software is reactive and requires regular updates, making it inadequate in addressing the increasing complexity of threats, particularly in protecting data communicated between computers via networks, and fails to provide comprehensive protection against hackers, viruses, spyware, and malware.

Innovation Solution

The system involves transferring security software from an external memory device to an internal memory device of a client computer, establishing secure communications links with network sites, and providing keylogger prevention, code injection prevention, and screen scraper protection services through a trusted secure desktop environment, which includes user mode and kernel mode software to safeguard data communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional reactive security software is used, then the system can detect known threats, but it cannot prevent new or unknown threats and requires frequent updates

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidability to counter new threats
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements a proactive security model by establishing secure desktop environments and security services before threats occur. The secure desktop is created in advance with protected processes and services that prevent malware execution, code injection, and screen scraping before these attacks can compromise the system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces a secure desktop as an intermediary layer between the user and the underlying operating system. This secure desktop acts as a mediator that intercepts and blocks malicious activities such as keyboard hooks, screen captures, and code injections, preventing them from reaching vulnerable applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security services are implemented, then protection against multiple threat types is achieved, but system complexity increases

Engineering Contradiction:
Improvecomprehensive threat protectionVSAvoidsecurity system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple security functions (keylogger prevention, code injection prevention, screen scraper protection, process protection) into a unified secure desktop environment. These diverse security services are merged into a single integrated system that manages all protections through a common architecture, reducing overall system complexity.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The secure desktop is designed as a universal security platform that provides multiple protection capabilities through a single system. The same secure desktop infrastructure handles keyboard protection, screen protection, process protection, and network security, eliminating the need for separate specialized security tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If secure desktop environment is created, then protection against keyboard hooks and screen scrapers is improved, but performance overhead increases

Engineering Contradiction:
Improveprotection against input/output interceptionVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The secure desktop processes are designed to be self-protecting, with built-in mechanisms that automatically prevent keyboard hooks and screen scrapers without requiring continuous external monitoring. The security services run within the secure desktop and protect themselves, reducing the computational overhead of external security software.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS8918865B2System and method for protecting data accessed through a network connection
Publication Date: 2014.12.23 WONTOK
  • US8918865B2 patent drawing
  • US8918865B2 patent drawing
  • US8918865B2 patent drawing

AI summary

Systems (100) and methods (400) for protecting data accessed through a network connection. The methods involve transferring security software (150) from an external memory device of a client computer (102) to an internal memory device of the client computer. The security software is operative to protect data communicated to and from the client computer via communication links. The security software is also operative to provide a web browser (1101, 1102, . . . , 110p) which executes in user mode on a trusted secured desktop (904) configured to run simultaneously with an unsecured desktop (902) of the client computer. The security software is further operative to provide a security service to the web browser. The security service includes at least one service selected from the group consisting of a keylogger prevention service, a code injection prevention service, and a screen scraper protection service.