Independent Witness Verification for Source Code Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security functions in computer systems are inadequate in preventing harmful activities, such as unauthorized access and phishing attacks, particularly in source code control systems, where privileged users can compromise sensitive information, and conventional security measures are insufficient to detect malicious code changes or breaches.

Innovation Solution

A method that utilizes an independent witness system, where keystrokes and mouse movements are logged on a trusted device like a smartphone, and compared with source code changes in a repository, generating a risk score to validate the integrity of input data and detect potential security breaches, leveraging multipoint Bluetooth communication to ensure independent verification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security functions (password authentication, access control) are used, then basic user identity protection is provided, but they are insufficient to prevent harmful activities such as phishing attacks and unauthorized actions by privileged users

Engineering Contradiction:
Improvesecurity protection capabilityVSAvoidsecurity system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary verification mechanism that compares input data from multiple independent sources (different logical objects receiving input from the same origin) to detect potential security breaches. This intermediary layer validates whether inputs are legitimate without requiring complex security infrastructure, thereby improving reliability while maintaining manageable complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If privileged users are granted greater access to system operational functions, then system operational capability is improved, but the risk of harmful and unethical activities increases

Engineering Contradiction:
Improvesystem operational capabilityVSAvoidrisk of harmful activities
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary verification of input data before executing operations, especially for privileged users. By validating inputs through comparison across multiple logical objects before the actual operation occurs, the system maintains high operational capability for privileged users while preventing harmful activities through pre-execution validation.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If source code control systems store and manage source code assets centrally, then collaboration and historical tracking are improved, but vulnerability to coordinated attacks on both the trusted device and repository increases

Engineering Contradiction:
Improvecollaboration efficiencyVSAvoidvulnerability to coordinated attacks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent segments the verification process across multiple independent logical objects that each receive input from the same origin. This segmentation ensures that a coordinated attack would need to compromise multiple independent verification points simultaneously, significantly reducing vulnerability while maintaining central source code control functionality for collaboration and historical tracking.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8914895B1Managing verification of input data
Publication Date: 2014.12.16 EMC IP HLDG CO LLC
  • US8914895B1 patent drawing
  • US8914895B1 patent drawing

AI summary

A method is used in managing verification of input data. A first set of input information is received at a first logical object, and a second set of input information is received at a second logical object. The first and second sets of input information are indicated as having a same origin. Based on the first and second sets of input information, it is determined whether the first set of input information is valid.