Security State Watcher for High-Assurance Computer Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems with shared resources between secure and insecure execution environments are vulnerable to attacks such as focus shifting and spoofing, where users cannot distinguish between legitimate and fake user interfaces, compromising the high-assurance nature of secure components.

Innovation Solution

A security device connected to the computer system that independently monitors and alerts the user to the security state by querying the secure functionality, providing independent power, clock, computation, and memory, and challenging the secure functionality with cryptographic queries to ensure its satisfactory operation, and alerts the user through visual, auditory, or tactile signals if compromised.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a virtual machine monitor is used to provide complete separation between execution environments, then security assurance is improved, but device complexity and adaptability to open architecture machines deteriorate

Engineering Contradiction:
Improvesecurity assuranceVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into a host operating system and a guest operating system (nexus) with distinct security responsibilities. The nexus provides high-assurance security functions while the host provides general-purpose infrastructure, allowing security-critical operations to be isolated without requiring full virtualization of all system components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security device acts as an intermediary between the user and the computer system, independently monitoring the security state by querying the nexus and providing direct feedback to the user. This intermediary validates security claims without requiring complete virtualization or complex VMM infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a virtual machine monitor is used to provide complete separation between execution environments, then security assurance is improved, but adaptability to open architecture machines deteriorates

Engineering Contradiction:
Improvesecurity assuranceVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system separates security-critical functions (nexus) from general-purpose functions (host), allowing the secure component to remain small and highly assured while the host adapts to various devices and applications. This segmentation enables the secure nexus to focus only on security validation without needing to virtualize all machine components.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host operating system provides universal infrastructure services (device drivers, memory management, scheduling) that support a wide variety of devices and applications, while the specialized nexus provides focused security assurance. This multi-functionality arrangement allows the system to adapt to open architecture machines without compromising security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If the nexus is made small and limited-purpose to increase confidence in assurance, then security assurance is improved, but functionality deteriorates

Engineering Contradiction:
Improvesecurity assuranceVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system divides functionality between the small, focused nexus (security validation) and the full-featured host (general-purpose operations). The nexus remains small and simple to maintain high assurance, while the host provides complete functionality for device support and applications.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The host operating system provides self-service infrastructure support to the nexus, including device drivers, memory management, and scheduling. This allows the small nexus to access full system functionality through the host's infrastructure without needing to implement these complex functions itself, maintaining both small size and high functionality.

Inventive Principle:
Principle #25Self-service

4Ease of operation

If the windowing system is run by the host operating system to provide user interface functionality, then ease of operation is improved, but security vulnerability increases

Engineering Contradiction:
Improveease of operationVSAvoidsecurity vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The security device provides continuous feedback to the user about the actual security state by independently querying the nexus and comparing it against expected security conditions. This feedback mechanism allows the user to distinguish between legitimate and spoofed interface elements, enabling safe use of the host's windowing system.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The security device acts as an intermediary validation layer between the user and the host operating system's windowing system. It independently verifies security claims and provides direct feedback to the user, allowing the user to safely interact with the convenient host interface while protected from spoofing attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

5Productivity

If shared resources are provided between host and guest operating systems, then productivity is improved, but security vulnerability increases

Engineering Contradiction:
ImproveproductivityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The security device provides continuous feedback about the security state of shared resources by querying the nexus and validating security conditions. This feedback mechanism allows the system to safely share resources between host and guest by monitoring and alerting users to any security violations or spoofing attempts.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS7574610B2Security state watcher
Publication Date: 2009.08.11 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7574610B2 patent drawing
  • US7574610B2 patent drawing
  • US7574610B2 patent drawing

AI summary

A security device watches over the secure functionality in a computer system. This “watcher” security device may be integrated within the computer system or may be separate from it. The security device queries the secure functionality to determine whether the state of the secure functionality is acceptable. If no satisfactory state exists, or if no response is received, then a signal is transmitted. The signal may be auditory (a buzzer) or visual (a flashing light) in order to signal to any user that the secure functionality has been compromised. Optionally, human input devices may be disabled, or a monitoring service notified, in conjunction with or in lieu of the signal. If the secure functionality includes a secret shared between the secure functionality and the user, then the security device may signal the secret. For example, where the secret is visual, the security device may display the secret. Where there is more than one element of secure functionality in the computer system, the security device may separately watch and report on more than one element of secure functionality. The security device may also display status information regarding the computer system. Some or all of the security device may be distributed via a trusted distribution infrastructure.