Software Solidification via External Integrity Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer systems lack a method to solidify the software and configuration data available for execution, allowing unauthorized modifications or installations even with administrative privileges, necessitating a solution to restrict software changes to a granular policy managed externally.
Innovation Solution
Implementing a system that translates and freezes software interfaces, with an integrity server managing the execution permissions, ensuring that any additional software installed after the solidification process cannot execute, and allowing controlled execution through a mapping table and authentication mechanisms.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If passwords or administrative privileges are used to control software installation, then users can install and remove software freely, but system security and software integrity are compromised
Solution Approach 1:
The patent extracts the software execution approval authority from the local computer system and places it in an external integrity server. This separation removes the ability of local administrators to execute unauthorized software, as all execution requests must be approved by the external server, thus resolving the contradiction between operational freedom and system security
Solution Approach 2:
The integrity server acts as an intermediary between software installation requests and execution. It mediates by receiving installation requests, evaluating them against security policies, and either permitting or blocking execution. This intermediary mechanism prevents direct software execution by unauthorized programs while maintaining controlled access
2Adaptability or versatility
If software modification is allowed for flexibility, then system adaptability improves, but system integrity and security are compromised
Solution Approach 1:
The patent implements preliminary action by requiring software to be registered and approved for execution before it can run on the solidified computer. The integrity server pre-evaluates software against security policies and maintains a whitelist of approved applications, preventing unauthorized or modified software from executing while allowing legitimate software updates through controlled processes
3Ease of operation
If administrative passwords are used to enforce software policies, then policy enforcement capability exists, but excessive access rights are granted to password possessors
Solution Approach 1:
The patent extracts the policy enforcement mechanism from local administrative accounts and relocates it to an external integrity server. This removes the excessive access rights that come with local administrative passwords, as the server handles all security decisions remotely without requiring local administrators to possess sensitive credentials
Solution Approach 2:
The integrity server serves as an intermediary that enforces software policies without requiring local administrative passwords. It receives execution requests, checks them against enforced policies, and makes authorization decisions, thereby providing policy enforcement capability while eliminating the security risk of excessive local access rights
Data Source
AI summary
System and method for solidifying (or “freezing”) the set of software and configuration data available for execution on a computer. Any additional software installed on the computer after the solidification process will not execute, regardless of whether the installation is initiated or otherwise performed by a person with administrative privilege. The ability to allow new or modified software to execute on the computer rests with an integrity server separate from and outside of the solidified computer. The solidification of software and configuration data proceeds on a level of granularity selectable by the integrity server and any operators thereof.


