Virtual Device Access Control via Authentication Codes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtual device protection systems lack effective methods to restrict access to virtual devices and data even if the regular system is compromised by external hacking, leading to potential unauthorized access and control.

Innovation Solution

An electronic apparatus that includes a storage for an operating system and a virtual device program, with a processor to determine access authority based on an authentication code, selectively permitting or denying access to virtual device data and monitoring for OS alterations to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the regular system assigns administration authority to programs, then system operation flexibility is improved, but security against external hacking attacks deteriorates

Engineering Contradiction:
Improvesystem operation flexibilityVSAvoidsecurity against external hacking
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments administration authority into two distinct types: general administration authority for system operation and specific access authority to virtual device data. This segmentation allows programs to have operational flexibility while restricting access to sensitive virtual device data, thereby resolving the contradiction between ease of operation and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies local quality by differentiating access permissions for different data regions. Virtual device data is protected with restricted access authority, while other system data remains accessible to programs with administration authority. This localized permission control enables flexible operation in unprotected areas while maintaining security in critical areas.

Inventive Principle:
Principle #3Local quality

2Reliability

If virtual devices are isolated from the regular system, then security is improved, but access control capability deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidaccess control capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent introduces an intermediary authentication mechanism that mediates between the isolated virtual device and the regular system. The authentication code embedded in programs acts as an intermediary credential, allowing controlled access to virtual device data without breaking the isolation barrier. This enables selective access control while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If authentication codes are embedded in programs, then access control precision is improved, but device complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidprogram structure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by embedding authentication codes during the program compilation or building phase. This preliminary incorporation of security credentials eliminates the need for complex runtime authentication mechanisms, reducing operational complexity while maintaining precise access control. The authentication code is prepared in advance and integrated into the program structure.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10846376B2Electronic apparatus and control method thereof
Publication Date: 2020.11.24 SAMSUNG ELECTRONICS CO LTD
  • US10846376B2 patent drawing
  • US10846376B2 patent drawing
  • US10846376B2 patent drawing

AI summary

An electronic apparatus operated based on an OS is provided. The electronic apparatus includes a storage to store the OS, a virtual device program capable of generating a virtual device executed based on the OS, and at least one program; and at least one processor to execute the virtual device program to generate the virtual device, and to execute the OS to determine whether a first program having an administration authority assigned by the OS from among the at least one program has access authority to data about the virtual device in response to an attempt to access the data from the first program and to selectively permit the access to the data based on the determined access authority. With this, the electronic apparatus may restrain the access to the virtual device or the data thereabout according to a presence of the access authority, thereby safely protecting the virtual device or the data.