Security Agent Safe-State Response to Unauthorized Resource Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computing systems lack effective methods to respond safely and securely to security policy violations, particularly in environments where functional safety standards are not met, leading to potential operational downtime, intellectual property theft, and risk of human injury or death due to cyber-attacks.

Innovation Solution

A method involving a security agent on a computing platform that authenticates with a security device, accesses a configuration profile defining identity information and security policies, monitors resource access, and initiates a safe state upon detecting policy violations, leveraging a security device to extend functional safety and security capabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security agent monitors resource access and enforces security policies, then security policy compliance is improved, but system response time and operational continuity deteriorate when violations are detected

Engineering Contradiction:
Improvesecurity policy complianceVSAvoidoperational downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The security device is pre-configured with configuration profiles containing identity information and security policies before the computing platform operates. This preliminary setup enables the security agent to immediately enforce policies without delay, and the system can transition to a safe state pre-planned responses to violations, minimizing operational downtime while maintaining security compliance.

Inventive Principle:
Principle #10Preliminary action

2Device complexity

If the computing platform operates without functional safety standards, then device complexity and ease of operation are improved, but safety and security capabilities deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidfunctional safety
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

A security device acts as an intermediary between the computing platform and security enforcement requirements. The security device handles the complexity of security policies, identity management, and safe state definitions, while the computing platform maintains its simplicity. This mediator approach enables functional safety without requiring the computing platform itself to become complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If the security device stores configuration profiles with identity information, then authentication capability is improved, but device complexity and storage requirements worsen

Engineering Contradiction:
Improveauthentication capabilityVSAvoidconfiguration management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security device is designed to universally handle multiple authentication scenarios and security policies through configuration profiles. Rather than requiring separate mechanisms for different identity verification needs, the security device uses a unified configuration profile structure that can accommodate various identity information types and security requirements, reducing overall system complexity despite enhanced authentication capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12373543B2Method for safety responses to security policy violations
Publication Date: 2025.07.29 FORT ROBOTICS INC
  • US12373543B2 patent drawing
  • US12373543B2 patent drawing
  • US12373543B2 patent drawing

AI summary

A method includes, at a security agent executing on a computing platform including a set of resources and a first application: authenticating the security agent with a security device; accessing a configuration profile, from the security device, defining identity information associated with the first application and a first security policy defining a subset of resources, in the set of resources, to which the first application is permitted access; authenticating the first application based on the identity information; monitoring the set of resources responsive to execution of the first application on the computing platform; and issuing a command to cause the computing platform to enter a safe state in response to detecting an access by the first application to a first resource in the set of resources, the first resource excluded from the subset of resources.