Security Management Processor Isolating Application Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional computer systems are vulnerable to viruses and spyware due to their open operating systems, which can lead to data corruption and increased complexity, making them susceptible to attacks and slowing down operations as they attempt to support multiple incompatible applications.
Innovation Solution
A computer system with multiple microprocessors and a security management processor that isolates application execution, manages access to storage and peripherals, and encrypts OS/application pairs to control information flow and enhance security, ensuring only authorized access to data and preventing unauthorized data sharing.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a conventional open operating system is used to support multiple applications concurrently, then application versatility is improved, but security vulnerability increases due to viruses and spyware spreading easily
Solution Approach 1:
The patent divides the computer system into multiple isolated execution environments, each capable of running applications independently. This segmentation prevents viruses and spyware from spreading between applications while maintaining the ability to run multiple applications concurrently. Each isolated environment has its own memory space and access controls, creating security boundaries without sacrificing application versatility.
2Adaptability or versatility
If the operating system contains the superset of support services required by all applications to operate concurrently, then application compatibility is improved, but system operation speed decreases due to increased OS size
Solution Approach 1:
Instead of having a single large operating system containing all possible services, the patent segments the system into multiple smaller isolated execution environments. Each environment loads only the necessary services and applications required for its specific task. This eliminates the need for a monolithic OS that must contain every possible application service, thereby reducing overall system complexity and improving operation speed while maintaining application compatibility through standardized interfaces.
Solution Approach 2:
The patent implements a dynamic system where execution environments can be created, modified, and destroyed on demand. The operating system dynamically loads only the necessary services and applications into active execution environments rather than maintaining all services in memory simultaneously. This dynamic approach allows the system to adapt to different application requirements while minimizing the active OS footprint, thereby improving system speed without sacrificing compatibility.
3Adaptability or versatility
If applications have access to the entirety of the hard disk and system inputs/outputs, then application functionality is improved, but security risk increases allowing viruses and spyware to spread easily
Solution Approach 1:
The patent segments the file system and peripheral access into isolated execution environments. Each application runs in its own sandboxed environment with controlled access to storage devices and peripherals. Applications can access data and resources through defined interfaces and permissions rather than having unrestricted access to the entire hard disk and system inputs/outputs. This segmentation maintains application functionality while preventing viruses and spyware from spreading between applications or accessing unauthorized data.
Solution Approach 2:
The patent introduces a security management processor as an intermediary layer between applications and the underlying system resources. This mediator controls and monitors all access requests from applications to storage devices, peripherals, and other system resources. The security management processor acts as a gatekeeper that allows applications to access necessary resources through authorized channels while blocking unauthorized access, thereby preventing virus and spyware spread while maintaining application functionality.
4Productivity
If multiple applications are executed concurrently on a conventional system, then productivity is improved, but system complexity increases making installation more difficult
Solution Approach 1:
The patent segments the system into multiple independent execution environments that can run applications concurrently without interfering with each other. Each execution environment is a self-contained unit with its own memory space, file system view, and peripheral access controls. This segmentation enables multiple applications to execute simultaneously while isolating their complexity within individual environments, thereby improving productivity without proportionally increasing overall system complexity. The standardized interfaces between environments simplify installation and management.
Data Source
AI summary
A method for enhancing security of a computer system is provided. The computer system may include a plurality of microprocessors and a security management processor for managing execution of applications in isolation on the plurality of microprocessors. Each of the plurality of microprocessors is communicatively coupled to the security management processor. An operating system is installed on one of the plurality of microprocessors. An application is installed on the same microprocessors. The application and the operating system are combined into an OS/application pair (or pair). The pair is encrypted. The encrypted pair is then stored in a mass storage of the computer system. The mass storage is communicatively coupled to the security management processor. A graphic user interface of the security management processor may be used to launch the application on any of the plurality of microprocessors by loading the stored pair to that microprocessor. Data produced by the application may be encrypted and stored in the mass storage when saved. The stored data produced by the application may be not accessible by other applications without authorization.


