Virtualized Trusted Storage via Reputation-Based Access Control
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current solutions for virtualized trusted storage are inadequate in protecting data from malicious software and hackers, as they often require custom coding and are not effective against threats like ransomware and password stealers, failing to secure sensitive information effectively.
Innovation Solution
A communication system for virtualized trusted storage is configured to dynamically virtualize a file system using a security module, redirecting input/output operations to secure or unsecured storage based on the reputation of processes, ensuring that only trusted processes access secured storage, while untrusted processes are restricted from it.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If custom coding solutions are used for virtualized trusted storage, then implementation flexibility is improved, but security effectiveness against malware and hackers deteriorates
Solution Approach 1:
The patent introduces a security module as an intermediary component that mediates between the file system and storage devices. This security module dynamically virtualizes the file system and controls access based on process reputation, providing both flexibility in implementation and effectiveness against security threats without requiring custom coding for each scenario.
Solution Approach 2:
The security module provides universal protection against multiple types of threats including ransomware, password stealers, and other malware through a single integrated system. It handles diverse access control scenarios through reputation-based mechanisms, making the solution broadly effective without requiring custom specialized coding for each threat type.
2Reliability
If dynamic virtualization of file system is implemented, then data protection capability is improved, but system complexity increases
Solution Approach 1:
The security module performs self-service by automatically determining process reputation and making access control decisions without requiring manual configuration or complex administrative intervention. The system self-manages the virtualization process and access permissions, reducing the operational complexity burden on users while maintaining strong data protection.
Solution Approach 2:
The system changes the state of storage access through parameter modifications based on process reputation. Instead of complex structural changes, the security module dynamically adjusts access parameters (allowed/disallowed access) to secured storage based on the reputation score, simplifying the implementation of data protection while maintaining effectiveness.
3Reliability
If access control based on process reputation is used, then security against unauthorized access is improved, but performance of legitimate processes may deteriorate
Solution Approach 1:
The system implements feedback mechanisms where process reputation is continuously evaluated and updated based on behavior patterns. This feedback loop allows the system to distinguish between legitimate processes that may temporarily be untrusted and actual malicious processes, enabling selective access control that maintains security while minimizing impact on legitimate operations.
Solution Approach 2:
The access control system is dynamic rather than static, adjusting permissions in real-time based on process reputation changes. Legitimate processes can dynamically gain or lose access rights as their reputation changes, allowing the system to adapt to changing conditions and maintain both security and productivity without rigid permanent restrictions.
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Particular embodiments described herein provide for an electronic device that can be configured to receive a request from a process to access data is a system, determine if the data is in a virtualized protected area of memory in the system, and allow access to the data if the data is in the virtualized protected area of memory and the process is a trusted process. The electronic device can also be configured to determine if new data should be protected, store the new data in the virtualized protected area of memory in the system if the new data should be protected, and store the new data in an unprotected area of memory in the system if the new data should not be protected.