Security Verification Device for Omission-Free System Component Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security verification technologies fail to ensure that all necessary elements for implementing security measures in a system are prepared without omission, as they do not verify the integrity between implementation means and system components.
Innovation Solution
A security verification device and method that include a verification item storage, function item storage, requirement model generation, possessed function model generation, and verification unit to compare and verify the security requirements and implemented functions of system components, ensuring that all necessary security measures are properly implemented.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security verification is performed using existing technologies, then security assessment can be conducted, but it cannot verify that all necessary elements for implementing security measures are prepared without omission
Solution Approach 1:
The patent applies preliminary action by generating a requirement model that specifies all necessary security elements before verification. The system creates a comprehensive list of required security functions and implementation means in advance, then verifies whether each element is properly implemented in the target system. This prevents omission of security elements by establishing the complete requirement set beforehand.
Solution Approach 2:
The patent implements feedback by comparing the requirement model with the actual security implementation in the target system. The verification unit checks whether each security element specified in the requirement model is present and correctly implemented, providing feedback on compliance status. This feedback mechanism ensures that all necessary security elements are verified and identifies any omissions.
2Measurement precision
If comprehensive security verification is implemented to ensure all elements are prepared, then verification accuracy improves, but system complexity increases
Solution Approach 1:
The patent applies segmentation by dividing the security verification process into distinct components: a requirement model generation unit that creates security requirements, a verification unit that checks implementation, and separate storage for security functions and implementation means. This segmentation allows comprehensive verification while managing system complexity through modular architecture, where each component has a specific function.
Solution Approach 2:
The patent introduces an intermediary element - the requirement model - that serves as a bridge between security specifications and verification. The requirement model contains structured information about security functions and implementation means, acting as an intermediary representation that simplifies the verification process by providing a clear, organized framework for checking security implementation without requiring direct complex analysis of the target system.
Data Source
AI summary
The present invention provides a security verification device and a security verification method which are capable of verifying that elements for implementing security measures necessary for a system can be prepared without omission. The security verification device and the security verification method select a verification item on the basis of security requirement information, generate security requirement information of parts specified by the verification item on the basis of a security target model, generate information which indicates a possessed function of security of the parts included in the security target model on the basis of a function item which is extracted on the basis of an implementation method included in the verification item and output a comparison and verification result of the security requirement information of the parts and the information which indicates the possessed function.


