Virtual OS Administrator Permission Simulation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security approaches for computing environments either limit user productivity by requiring administrative privileges for application installations or struggle to effectively monitor and prevent harmful operations, even when running applications with administrator permissions.
Innovation Solution
A method that allows software applications to execute with administrator permissions in a secured environment by simulating administrator permissions for user accounts with guest access, using a virtual operating system with components like a virtual security permission manager and virtual service manager to handle security system calls and service requests, thereby preventing harmful operations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If applications are run with administrator permissions, then user productivity is improved, but security risk increases
Solution Approach 1:
The system segments the permission model by introducing multiple administrator permission levels (full administrator, limited administrator, and simulated administrator). This allows applications to run with appropriate permission levels - full administrator for system operations, limited administrator for specific tasks, and simulated administrator for user-level operations - thereby maintaining productivity while reducing security risks through granular permission control.
Solution Approach 2:
The patent introduces an intermediary permission simulation layer that mediates between user applications and the actual system resources. This simulated administrator permission system acts as a safe intermediary, allowing users to operate applications with administrator-like capabilities without directly exposing system vulnerabilities, thus improving productivity while maintaining security through the mediating layer.
2Reliability
If locked-down computer approach is used, then security is improved, but user productivity deteriorates
Solution Approach 1:
The patent implements a dynamic permission system where administrator permissions are not statically assigned but dynamically simulated based on application requirements and user context. The simulated administrator permission level can be activated when needed for specific operations and deactivated otherwise, allowing the system to adapt between secure locked-down state and productive administrator-access state, thus resolving the contradiction between security and productivity.
Solution Approach 2:
The system changes the parameter of permission simulation rather than actual permission assignment. By simulating administrator permissions through a virtual permission layer rather than actual system privilege elevation, the system maintains the security parameters of a locked-down computer while providing the functional parameters of administrator access, thereby improving productivity without compromising security.
3Reliability
If protected environment approach is used, then security is improved, but monitoring complexity increases
Solution Approach 1:
The patent creates a copied permission system - a simulated administrator permission layer that mirrors the functionality of actual administrator permissions without requiring complex monitoring of every system operation. This permission copy allows applications to operate with administrator-like capabilities in a protected environment while simplifying monitoring, as the simulation layer inherently controls and logs permissions without needing to analyze infinite operation combinations.
Data Source
AI summary
Techniques for securing a computing environment are disclosed. Specifically, the invention allows the execution of any software application with administrator permissions on any computing device. This is done while preventing any of the software applications executed by the users, to perform harmful operations on the device. To this end, a user having only guest access permissions is allowed to perform operations as if the user has administrator permissions.


