Secure Module Self-Defense Computing Device
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Computing devices, such as mobile devices, are vulnerable to malicious use due to security flaws in operating systems and hardware, leading to compromised states where sensitive data can be exposed and unauthorized actions executed, with existing security mechanisms being ineffective in detection and prevention.
Innovation Solution
A self-defending computing device equipped with a secure module that includes secure processors and protected memory, which monitors the system for malicious activity, performs health checks, and executes response measures such as inhibiting device use, preventing compromised application execution, and encrypting data to protect against compromised states.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If existing security mechanisms are used to monitor and protect computing devices, then basic security coverage is provided, but they become ineffective when the device is compromised due to software and hardware limitations
Solution Approach 1:
The patent divides the computing device into two distinct operational environments: a secure environment with a secure processor that cannot be compromised, and a non-secure environment with the main processor that may be compromised. This segmentation allows the secure processor to independently monitor and respond to security threats without being affected by compromises in the main system, thereby maintaining security effectiveness even when the device is compromised.
Solution Approach 2:
The secure processor acts as an intermediary between the compromised main processor and the sensitive data/resources. It intercepts and validates all requests from the non-secure environment, performing health checks and enforcing security policies. This intermediary approach allows the system to maintain basic security coverage while adding a layer that remains effective even when the main system is compromised.
2Measurement precision
If the secure module continuously monitors the computing system for malicious activity, then detection capability is improved, but system resources and processing overhead increase
Solution Approach 1:
The secure processor performs health checks at periodic intervals rather than continuously monitoring every operation. This periodic monitoring approach maintains detection accuracy by regularly assessing the security state of the system while significantly reducing power consumption and processing overhead compared to continuous monitoring.
Solution Approach 2:
The secure processor is designed to be self-sufficient, executing its own health check routines and security policies without requiring resources from the potentially compromised main processor. It independently manages its own operation, reducing the burden on system resources and minimizing power consumption while maintaining high detection accuracy.
3Reliability
If response measures such as overwriting data and encrypting information are executed, then data security is enhanced, but device functionality and user access are restricted
Solution Approach 1:
The secure processor is pre-configured with response measures (such as data overwriting and encryption) that are executed automatically when threats are detected, before the compromised state can cause significant damage. This preliminary protective action enhances data security by preventing further compromise while the system remains operational, and user access is only restricted when absolutely necessary to prevent data loss.
Solution Approach 2:
The system implements a feedback mechanism where the secure processor continuously monitors the security state and dynamically adjusts response measures based on the detected threat level. When minor anomalies are detected, less restrictive measures are taken, maintaining device usability. When severe threats are identified, stronger protective actions are implemented, restricting access only when necessary to protect data security.
Data Source
AI summary
A computing device monitors for an event trigger by a secure computing module. Based on identifying an event trigger at the computing device, the secure computing module executes a health check according to a configuration identifying operating anomalies that are indicative of malicious activity at the computing device. The health check includes scanning a filesystem and communications module operation and configuration of the computing device for indications of malicious activity. Based on identified operating anomalies at the computing device, the secure computing module determines response measures to secure the computing device. The secure computing module executes the response measures individually or in combination at the computing device based on a response configuration.


