Application Trust Level Determination via Location Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Executing applications from remote sources can pose risks due to inappropriate trust levels, leading to potential damage or misuse of a user's computer and information, as existing systems often grant too high or too low trust levels when applications are loaded from local machines, regardless of their origin.

Innovation Solution

Systems and methods that determine and embed requested trust levels into applications, comparing execution locations with published locations to execute them at appropriate trust levels, ensuring safe and robust operation by prohibiting harmful operations and allowing execution at restricted trust levels when necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If applications are executed from local machine, then execution convenience is improved, but trust level accuracy deteriorates

Engineering Contradiction:
Improveexecution convenienceVSAvoidtrust level accuracy
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a trust level determination system as an intermediary between the application execution environment and the trust level assignment. This system analyzes the application's published location, execution location, and other attributes to determine the appropriate trust level, mediating between the convenience of local execution and the need for accurate trust assessment.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If applications are granted high trust level, then application functionality is improved, but system security deteriorates

Engineering Contradiction:
Improveapplication functionalityVSAvoidsystem security
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent changes the trust level parameter dynamically based on the application's attributes, published location, and execution context. Instead of using fixed high trust levels for all local applications, the system adjusts the trust level parameter to match the actual risk profile, allowing full functionality for trusted applications while limiting permissions for untrusted ones.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent applies different trust levels to different applications based on their specific characteristics and origins. Each application receives a customized trust level appropriate to its published location and execution context, rather than a uniform high trust level, thereby providing both functionality and security where appropriate.

Inventive Principle:
Principle #3Local quality

3Object-affected harmful factors

If applications are executed at low trust level, then system security is improved, but application performance deteriorates

Engineering Contradiction:
Improvesystem securityVSAvoidapplication performance
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system dynamically adjusts the trust level parameter based on the application's attributes and execution context. For applications that can be safely executed at lower trust levels, the system maintains security while allowing sufficient functionality for proper operation, avoiding both over-trust and under-trust scenarios.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS7676843B1Executing applications at appropriate trust levels
Publication Date: 2010.03.09 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7676843B1 patent drawing
  • US7676843B1 patent drawing
  • US7676843B1 patent drawing

AI summary

Systems and methods that enable execution of applications at appropriate trust levels are described. These systems and methods can determine appropriate trust levels by comparing applications' permitted trust levels with their requested trust levels. These systems and method can determine applications' permitted trust levels by comparing applications' execution locations with their published locations. Applications can also be executed at a restricted trust level at which potentially dangerous operations are prohibited.