Secure Integration of Isolated Execution Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to effectively identify and secure isolated execution environments, leading to potential data compromise in authorized user systems, especially with the increasing number of mobile computing tasks and diverse user activities.

Innovation Solution

A method and system that identify authorized computer systems, form isolated execution environments for security applications, detect and integrate multiple execution environments, and apply restrictions based on predefined rules to prevent unauthorized data access, enhancing the security of isolated execution environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If isolated execution environments are used to run applications, then application security and data protection are improved, but the ability to detect and secure all execution environments deteriorates

Engineering Contradiction:
Improvedata protectionVSAvoidexecution environment detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The security application performs self-installation and self-detection within the isolated execution environment. The system automatically detects other execution environments without requiring external intervention, using the environment's own resources to monitor and secure itself and others.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors and detects other isolated execution environments, then integrates them into a secure framework based on detected characteristics. This feedback loop enables the system to adapt to new execution environments and maintain security across dynamic environments.

Inventive Principle:
Principle #23Feedback

2Adaptability or versatility

If multiple isolated execution environments are deployed, then user authorization and access control are improved, but the complexity of managing and integrating these environments increases

Engineering Contradiction:
Improveuser access controlVSAvoidenvironment integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system segments the management of multiple execution environments by creating a dedicated security application that handles detection and integration separately from the environments themselves. Each environment maintains its isolation while the security layer provides unified management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The security application serves multiple functions: it installs itself, detects other environments, integrates them securely, and maintains authorization controls. This multi-functional approach reduces overall system complexity by consolidating management tasks into a single universal component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If security applications are provided with maximum permissions, then the security application can detect and secure all environments, but the risk of data access transit and unauthorized access increases

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata access transit
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The security application is installed and configured before other applications are executed. It proactively detects and integrates other execution environments into the secure framework before they can potentially access data unauthorizedly, preventing data access transit issues before they occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The security application acts as an intermediary between the maximum permission model and the need to prevent data access transit. It receives broad permissions to detect and secure environments, then mediates by implementing specific integration rules that control and monitor data access between environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP4455913A1Systems and methods for enhancing the security of isolated execution environments of an authorized user
Publication Date: 2024.10.30 AO KASPERSKY LAB
  • EP4455913A1 patent drawingFigure 1
  • EP4455913A1 patent drawingFigure 2
  • EP4455913A1 patent drawingFigure 3

AI summary

Disclosed herein are systems and methods for enhancing the security of isolated execution environments of an authorized user. An exemplary method comprises: identifying at least one computer system on which a user is authorized, forming an isolated execution environment for execution of a security application, detecting at least two isolated execution environments using an isolated execution environment of the installed security application on the identified computer system, and forming a secure integration of the identified isolated execution environments using integration rules. The forming of the secured integration is performed by: creating an integration of the identified isolated execution environments, and checking for presence of a data access transit in the created integration. When the data access transit is identified, the method further comprises applying restrictions based on identified options for the identified data access transit using integration rules.