Unified Display Combining for Secure Computing Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computing systems, especially network-connected devices, are vulnerable to attacks, with Virtual Machines and process isolation not being foolproof, leading to potential side channel attacks, particularly in mission-critical applications.

Innovation Solution

A system and method for separating computing systems while allowing them to work together by combining and monitoring their displays, enabling one-way communication and protecting user displays from unwanted data by identifying and blocking malicious content, using secure boot mechanisms and other security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If Virtual Machines or process isolation are used to separate computing systems, then system security is improved, but side channel attacks can still penetrate the isolation

Engineering Contradiction:
Improvesystem securityVSAvoidside channel attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system is divided into separate computing units with distinct display outputs. Each unit maintains independent processing while their displays are combined through a display combiner, creating physical segmentation that prevents side channel attacks between units while allowing coordinated display output.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A display combiner acts as an intermediary component that receives display outputs from multiple separated computing units and combines them into a single unified display. This intermediary enables secure separation of computing systems while maintaining display unity and preventing direct communication channels that could be exploited.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If computing systems are separated for security, then attack protection is improved, but the systems cannot work together seamlessly

Engineering Contradiction:
Improveattack protectionVSAvoidseamless operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The display outputs from multiple separated computing units are merged into a single unified display through the display combiner. This merging occurs at the display level rather than at the computing level, allowing the systems to remain separated for security while presenting a seamless unified interface to the user.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If display monitoring is implemented to detect attacks, then attack identification is improved, but system complexity increases

Engineering Contradiction:
Improveattack identificationVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The attack detection functionality is extracted from the individual computing units and implemented as a separate display monitoring system. This separate monitoring unit observes the combined display output without interfering with the core computing functions, thereby improving attack identification while minimizing added complexity to the computing systems themselves.

Inventive Principle:
Principle #2Taking out (Extraction)

4Reliability

If one-way communication is established between separated systems, then security is improved, but communication capability is limited

Engineering Contradiction:
ImprovesecurityVSAvoidcommunication capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of allowing direct communication between computing units, the system inverts the approach by having units communicate through their display outputs. Computing units send information to be displayed, and other units can observe this information through the combined display, creating a one-way communication channel that is secure yet functional.

Inventive Principle:
Principle #13The other way round (Inversion)

Data Source

PatentUS11108741B2System and method for the separation of systems that work together
Publication Date: 2021.08.31 CAMIEL NOAM
  • US11108741B2 patent drawing
  • US11108741B2 patent drawing
  • US11108741B2 patent drawing

AI summary

A system and method is introduced for separating computing devices that work together. The computing devices appear to the user as a single device such as through using a single display and other I/O means. The output of computing devices such as the display output, may be monitored for unwanted display output to the user which may be filtered from the user. The device displaying unwanted content may then be reverted to a known state. Computing devices may communicate among themselves using display data while remaining separated. Secure services from the cloud to a user device may be offered through the separated computing devices that work together, services that utilizes separating and securing the user I/O from internet connected devices, while allowing to monitor and filter the internet connected devices. These services preferably use a key that is non-extractable for communicating with the secure cloud. Such services from the cloud server may include a secure remote desktop for VDI/DaaS and a secure web browser There is also provided implementation of the system on different architectures using SW only or using some HW additions. Usage examples for vehicles, enterprises and others are described.