Secure Device Parallel World Isolation for Data Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are inadequate in protecting data from cyber attacks and inside breaches, as they can be bypassed, and there is an asymmetry between defenders and attackers, making it difficult to ensure the security of machines connected to networks.

Innovation Solution

A 'parallel world' of security is created, where secure data is handled in an isolated environment that never intersects with non-secure environments, using a secure device that authenticates itself to the user, allowing seamless use and sharing of sensitive data while keeping it protected from breaches and unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If data is handled in a non-secure user machine environment, then ease of operation and accessibility are improved, but security and protection from cyber attacks deteriorate

Engineering Contradiction:
Improveease of data accessVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the computing environment into two distinct segments: a non-secure user machine environment for general operations and a secure parallel world environment for handling sensitive data. This segmentation allows users to access data easily through the user machine while the secure environment maintains isolated protection, resolving the contradiction between ease of access and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure device acts as an intermediary between the user machine and the secure data environment. The secure device receives commands from the user machine, executes them in the isolated secure environment, and returns results without exposing the secure data to the untrusted user machine environment, thus maintaining both accessibility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption and physical security measures are implemented, then data protection is improved, but these measures can still be bypassed by attackers and device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure environment is extracted as a completely isolated parallel world separate from the user machine environment. By taking out the secure data handling operations from the compromised user environment and placing them in an independent secure device, the system achieves strong data protection without requiring complex security infrastructure within the user machine itself.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If a secure isolated environment is created for data handling, then security is improved, but the user experience and transparency of operation may deteriorate

Engineering Contradiction:
Improvedata securityVSAvoiduser experience transparency
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure device serves as an transparent intermediary that users interact with through the familiar user machine interface. Users can access and manipulate secure data through the user machine as if it were a normal environment, while the secure device mediates all operations in the isolated secure environment, maintaining both security and user experience transparency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9177164B2System and method for a parallel world of security for non secure environments
Publication Date: 2015.11.03 CAMIEL NOAM
  • US9177164B2 patent drawing
  • US9177164B2 patent drawing
  • US9177164B2 patent drawing

AI summary

A system and method is introduced for combining a secure device with a non secure user machine for using and sharing secure data seamlessly through the non secure user machine. The secure device runs in a separate, “parallel world” to the user machine so that the user machine cannot access secure data while it is being used. Even if the user machine is already compromised, the secure data and its usage remain protected from the likes of key logging and screen captures. The secure device authenticates secure data handling to the user so that the user is able to differentiate between a secure and a non secure data usage, as well as identify false imitations of the secure environment.