Software Solidification via External Integrity Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems lack a method to solidify the software and configuration data available for execution, allowing unauthorized modifications or installations even with administrative privileges, necessitating a solution to restrict software changes to a granular policy managed externally.

Innovation Solution

Implementing a system that translates and freezes software interfaces, with an integrity server managing the execution permissions, ensuring that any additional software installed after the solidification process cannot execute, and allowing controlled execution through a mapping table and authentication mechanisms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If passwords or administrative privileges are used to control software installation, then users can install and remove software freely, but system security and software integrity are compromised

Engineering Contradiction:
Improvesoftware installation freedomVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent extracts the software execution approval authority from the local computer system and places it in an external integrity server. This separation removes the ability of local administrators to execute unauthorized software, as all execution requests must be approved by the external server, thus resolving the contradiction between operational freedom and system security

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The integrity server acts as an intermediary between software installation requests and execution. It mediates by receiving installation requests, evaluating them against security policies, and either permitting or blocking execution. This intermediary mechanism prevents direct software execution by unauthorized programs while maintaining controlled access

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If software modification is allowed for flexibility, then system adaptability improves, but system integrity and security are compromised

Engineering Contradiction:
Improvesoftware modification flexibilityVSAvoidsystem integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent implements preliminary action by requiring software to be registered and approved for execution before it can run on the solidified computer. The integrity server pre-evaluates software against security policies and maintains a whitelist of approved applications, preventing unauthorized or modified software from executing while allowing legitimate software updates through controlled processes

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If administrative passwords are used to enforce software policies, then policy enforcement capability exists, but excessive access rights are granted to password possessors

Engineering Contradiction:
Improvepolicy enforcement capabilityVSAvoidexcessive access rights
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the policy enforcement mechanism from local administrative accounts and relocates it to an external integrity server. This removes the excessive access rights that come with local administrative passwords, as the server handles all security decisions remotely without requiring local administrators to possess sensitive credentials

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The integrity server serves as an intermediary that enforces software policies without requiring local administrative passwords. It receives execution requests, checks them against enforced policies, and makes authorization decisions, thereby providing policy enforcement capability while eliminating the security risk of excessive local access rights

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7873955B1Solidifying the executable software set of a computer
Publication Date: 2011.01.18 MCAFEE LLC
  • US7873955B1 patent drawing
  • US7873955B1 patent drawing
  • US7873955B1 patent drawing

AI summary

System and method for solidifying (or “freezing”) the set of software and configuration data available for execution on a computer. Any additional software installed on the computer after the solidification process will not execute, regardless of whether the installation is initiated or otherwise performed by a person with administrative privilege. The ability to allow new or modified software to execute on the computer rests with an integrity server separate from and outside of the solidified computer. The solidification of software and configuration data proceeds on a level of granularity selectable by the integrity server and any operators thereof.