A physically isolated single-system smartphone

By employing a physically isolated single-system design within smartphones, combined with authentication and data encryption, the problem of insufficient smartphone data security is solved, enabling efficient and secure closed and open operations on the same device, while reducing costs and complexity.

CN117097830BActive Publication Date: 2026-02-17JINGSHU TECH (SHANGHAI) CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202310978934.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-04
Publication Date
2026-02-17
Estimated Expiration
2043-08-04

AI Technical Summary

Technical Problem

Existing smartphones suffer from insufficient physical isolation in terms of data security, and existing solutions often require secondary development, the addition of external devices, or are costly and inconvenient to use.

Method used

The smartphone adopts a physically isolated single-system design, with application and communication modules running on the same operating system. It utilizes the physically isolated module for authentication and data processing, including data encapsulation and encryption, supports both closed and open operating modes, and integrates firewalls and VPNs to ensure security.

Benefits of technology

It achieves the goal of reducing the complexity and cost of using smartphones while ensuring data security, making it suitable for mobile office and communication in high-security situations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117097830B_ABST
    Figure CN117097830B_ABST
Patent Text Reader

Abstract

The application provides a physically isolated single-system smart phone, comprising an application module and a communication module, the application module and the communication module are isolated and information is transmitted through a physical isolation module; the application module, the communication module and the physical isolation module adopt the same running system; the physical isolation module comprises an identity authentication unit and a controllable data channel, so as to perform identity authentication and data processing on the information transmission process between the application module and the communication module, the data processing comprises data encapsulation, data filtering and data encryption; the smart phone is initialized and system configured, so that the smart phone enters a closed operation mode or an open operation mode. The application can guarantee the data security of the smart phone by isolating the application module from the communication module; the same running system is adopted, so that the user can use more conveniently, and the cost of the smart phone can be reduced.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of smart phones, in particular to a physically isolated single-system smart phone. BACKGROUND

[0002] Smart phones are essential electronic devices for modern people's life and work, and their security is increasingly important, especially in places involving important finance and important work.

[0003] CN102045449A "A multi-operating system smart phone" gives a soft mode, at least containing an open operating system and a closed operating system, which does not isolate data processing physically and cannot essentially solve the data security problem.

[0004] CN109167777A "A smart terminal firewall device for mobile phone", which is a calling firewall access, must be developed twice for general smart phones, modified from the system bottom, and has an external device, which is not convenient to use.

[0005] CN105848143A "A dual-system integrated smart phone and a private information processing method", the physically isolated "private system" and "open system" share the "display unit" through "safe switching".

[0006] CN106549934B "Network equipment security system", the physically isolated two systems are in master-slave relationship, and the data exchange and the use of peripherals between the two systems are transmitted through special isolation hardware. These two ways essentially run two sets of software and hardware platforms, and the data exchange is safely realized through physical isolation circuit. These two ways realize the separation of life system and work system on the same mobile phone, but are not convenient to use and have high terminal cost. SUMMARY

[0007] In order to overcome the above technical defects, the purpose of the present application is to provide a smart phone which is physically isolated and only runs one set of application system.

[0008] The application discloses a physically isolated single-system intelligent mobile phone, which comprises an application module and a communication module, and the application module and the communication module are isolated and information is transmitted through a physical isolation module; the application module, the communication module and the physical isolation module adopt a same running system; the physical isolation module comprises an identity authentication unit and a controllable data channel, so as to perform identity authentication and data processing on the information transmission process between the application module and the communication module, and the data processing comprises data encapsulation, data filtering and data encryption; the intelligent mobile phone is initialized and system configured, so that the intelligent mobile phone enters a closed operation mode, and in the closed operation mode, the intelligent mobile phone only runs a mobile phone basic function; in the closed operation mode of the intelligent mobile phone, the intelligent mobile phone is initialized and system configured, so that the intelligent mobile phone enters an open operation mode, and in the open operation mode, the intelligent mobile phone also runs intelligent functions except the mobile phone basic function.

[0009] Preferably, the application module comprises a processor, a VPN and a firewall; when the application module and the communication module are connected, the firewall and the VPN need to be set together.

[0010] Preferably, the running system is configured with a trusted secure boot mechanism, and the secure boot mechanism makes the start of the hardware and software of the intelligent mobile phone must pass through integrity verification.

[0011] Preferably, the application module encrypts stored user data and a kind of application data, and the security level of the kind of application data is the highest among all application data.

[0012] Preferably, the application module comprises a tamper-proof detection module, the tamper-proof detection module monitors the encrypted stored user data and the kind of application data in real time through a key, and when the tamper-proof detection module detects data tampering, all the encrypted stored user data and the kind of application data are cleared.

[0013] Preferably, the application module comprises a data interface, and before data is transmitted through the data interface, identity authentication is needed; the data transmitted into the application module needs to be placed in a honeypot after being filtered and analyzed and then decrypted for acquisition after being decrypted; the data transmitted from the application module needs to be outputted after being authenticated, registered, encrypted and added with digital watermark.

[0014] Preferably, the application module comprises an encryption chip, and the encryption chip adopts a national secret algorithm to perform data encryption, signature verification, private key encryption storage of an asymmetric algorithm, key encryption storage of a symmetric algorithm and generation of pseudo-random numbers.

[0015] Preferably, the isolation module comprises an isolation circuit, the application module is connected with the isolation circuit through a first control interface, and the communication module is connected with the isolation circuit through a second control interface; the first control interface and the second control interface are used for transmitting GPIO / UART / I2C / SPI signals.

[0016] Preferably, data input by the communication module to the application module is transmitted to a firewall for processing and then enters a normal operation of data; data output by the application module is processed by a VPN calling encryption chip in cooperation and then transmitted to the firewall for processing and output.

[0017] Preferably, the communication module comprises 5G, 4G, BLE, WIFI, GPS and Beidou.

[0018] After the above technical scheme is adopted, compared with the prior art, the following beneficial effects are achieved:

[0019] 1. By isolating the application module and the communication module, the data security of the smart phone can be ensured; by using the same operating system for the application module, the communication module and the physical isolation module, the user can use more conveniently, and the cost of the smart phone can be reduced. BRIEF DESCRIPTION OF DRAWINGS

[0020] Figure 1 The module structure schematic diagram of the smart phone is provided in the present application. DETAILED DESCRIPTION

[0021] The advantages of the present application will be further described below in combination with the accompanying drawings and specific embodiments.

[0022] The exemplary embodiments will be described in detail herein below with reference to the accompanying drawings. When the following description refers to the drawings, same numbers in different drawings represent the same or similar elements unless otherwise indicated. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present disclosure. Instead, they are merely examples of apparatuses and methods consistent with some aspects of the present disclosure as detailed in the appended claims.

[0023] The terminology used in this disclosure is for the purpose of describing particular embodiments only and is not intended to be limiting of the present disclosure. As used in this disclosure and the appended claims, the singular forms "a," "an" and "the" are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that the term "and / or" as used herein refers to and encompasses any and all possible combinations of one or more of the associated listed items.

[0024] It should be understood that, although the terms first, second, third, etc. can be employed in this disclosure to describe various information, the information is not to be limited to these terms. These terms are only used to distinguish one category of information from another. For example, without departing from the scope of the present disclosure, the first information can also be referred to as the second information, and similarly, the second information can also be referred to as the first information. Depending on the context, the word "if" as used herein can be interpreted as "when" or "upon" or "in response to determining."

[0025] In the description of the present application, it should be understood that the orientation or positional relationship indicated by the terms "longitudinal", "lateral", "upper", "lower", "front", "back", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer" and the like is based on the orientation or positional relationship shown in the drawings, and is only for the convenience of describing the present application and simplifying the description, and does not indicate or imply that the device or element referred to must have a particular orientation, be constructed and operated in a particular orientation, and therefore cannot be understood as a limitation of the present application.

[0026] In the description of the present application, unless otherwise specified and limited, it should be noted that the terms "mounting", "connection", "connection" should be understood broadly, for example, it can be mechanical connection or electrical connection, it can be the communication between two elements, it can be direct connection or indirect connection through intermediate medium, and the specific meaning of the above terms can be understood by those skilled in the art according to the specific circumstances.

[0027] In the subsequent description, the suffix such as "module", "component" or "unit" used to represent elements is only for the convenience of the description of the present application, and has no specific meaning in itself. Therefore, "module" and "component" can be used interchangeably.

[0028] Referring to the accompanying Figure 1 The application discloses a physically isolated single-system smart phone, which comprises an application module and a communication module, the application module and the communication module are isolated in some use scenarios and transmit information in other use scenarios through a physical isolation module, so that the data security of the smart phone can be ensured.

[0029] The application module, the communication module and the physical isolation module of the present application adopt the same running system, avoiding the use obstacles of two or more sets of running systems, and the same running system is used, so that the user can use more conveniently, and the cost of the smart phone can be reduced. The running system includes but is not limited to Android, VIVO Phone, Harmony, Yuanxin and the like. However, the running system used needs to be deeply customized in cooperation with the processor and the hardware of the smart phone, so as to have a trusted secure boot mechanism, which makes the start of the hardware and software of the smart phone must pass the integrity verification.

[0030] The application module has no external communication capabilities and mainly includes: processor, VPN, firewall, and physical security. Processors for the application module include, but are not limited to, Qualcomm, Samsung, MediaTek, Apple, Huawei HiSilicon, and Spreadtrum.

[0031] The firewall's data interface with the smartphone uses either a serial communication interface or a parallel data interface. The firewall's access control security policy monitors input and output data to control its flow and block some attacks. Based on pre-defined security rules, input and output data are monitored; data that meets the requirements is allowed to pass, while other data packets are blocked. The firewall module's data confidentiality and integrity security policy ensures data confidentiality through encryption, encapsulation, and authentication of transmitted data, preventing unauthorized users from accessing information.

[0032] Communication modules include, but are not limited to, 5G, 4G, BLE, WIFI, GPS, and BeiDou.

[0033] The physical isolation module includes an authentication unit and a controllable data channel to authenticate and process data during information transmission between the application module and the communication module. Authentication ensures that the transmitted data is qualified for transmission, while data processing includes data encapsulation, data filtering, and data encryption to ensure data security. When interfacing with the application module and the communication module, a shared firewall and VPN configuration are required.

[0034] Initializing and configuring a smartphone puts it into a closed operating mode. In this mode, the smartphone only performs basic phone functions, such as making and receiving calls and sending and receiving text messages. In closed mode, the smartphone is considered a secure smartphone. To enter open operating mode, the smartphone needs to be initialized and configured again. In open mode, the smartphone performs additional intelligent functions beyond basic phone functions, such as browsing the internet, chatting, and downloading. In open mode, the smartphone is considered a regular smartphone.

[0035] The smartphone provided by this invention is physically isolated and runs only one application system, mainly for mobile office and communication in high-security situations.

[0036] Furthermore, the application module encrypts and stores user data and a type of application data. The security level of this type of application data is the highest among all application data. This can be understood as the application module encrypting and storing user data and important application data.

[0037] Further, the application module includes a tamper detection module, which monitors the encrypted user data and the application data in real time through the key, and when the tamper detection module detects data tampering, all the encrypted user data and the application data are cleared.

[0038] Further, the tamper detection module is a tamper detection sensing circuit arranged on the shell of the smart device, and in cooperation, the shell of the smart device is provided with a physical button for manually clearing the key information of the smart phone.

[0039] Further, after the data is cleared, the device is locked, so that it (the smart phone) cannot be normally used, and only the system can be reinstalled.

[0040] Further, the application module further includes a data interface, and before data is transmitted through the data interface, identity authentication is required, and: the data transmitted to the application module needs to be placed in a honeypot after being disinfected, analyzed, processed, filtered and decrypted; the data transmitted from the application module needs to be encrypted after being authenticated, registered and having digital watermark, and then output. The data interface is preferably a type-c interface.

[0041] Further, the application module further includes a secure VOIP APP to support the smart phone to make a VOIP call, a secure chat APP to support the smart phone to make an instant chat, and a secure mailbox APP to support the smart phone to send and receive emails, and of course, other secure applications can also be included to support more functions of the smart phone. The above-mentioned secure applications are customized software specially customized for the smart phone, which need to be registered and authenticated on the background server, and the data transmission thereof adopts point-to-point encryption to ensure the security of data transmission.

[0042] As a basic application, the application module further includes a camera, a microphone, a sensor, an NFC, etc. Moreover, the camera and the microphone are in a default closed state, and can be used only after the user manually confirms to turn on the camera and the microphone.

[0043] Further, the application module further includes an encryption chip, which adopts a national secret algorithm to encrypt data, sign and verify, store a private key of an asymmetric algorithm, store a key of a symmetric algorithm, and generate a pseudo-random number. The encryption chip realizes a cryptography function from a hardware layer.

[0044] Further, the isolation module comprises an isolation circuit, the application module is connected with the isolation circuit through a first control interface, the communication module is connected with the isolation circuit through a second control interface, and the first control interface and the second control interface are used for transmitting signals such as GPIO / UART / I2C / SPI.

[0045] Further, the data input by the communication module to the application module is transmitted to the firewall through the first control interface for processing, and then enters the normal operation of the data. The data output by the application module is processed by the VPN calling encryption chip in cooperation, and then transmitted to the firewall for processing and output.

[0046] It should be noted that the embodiments of the present application have better implementation, and do not limit the present application in any form, and any skilled person in the art can change or modify the above disclosed technical content into equivalent effective embodiments, as long as the content of the technical scheme of the present application is not deviated, and any modification or equivalent change and modification of the above embodiments according to the technical essence of the present application still belongs to the scope of the technical scheme of the present application.

Claims

1. A physically isolated single system smartphone, characterized in that, The application module and the communication module are isolated and information is transmitted between them through a physical isolation module; the application module, the communication module and the physical isolation module adopt the same operating system; The physical isolation module includes an identity authentication unit and a controllable data channel to perform identity authentication and data processing on the information transmission process between the application module and the communication module, and the data processing includes data packaging, data filtering and data encryption; The smart phone is initialized and system configured so that the smart phone enters a closed operation mode in which the smart phone only runs basic functions of the phone; in the closed operation mode of the smart phone, the smart phone is initialized and system configured so that the smart phone enters an open operation mode in which the smart phone also runs smart functions in addition to the basic functions of the phone; The application module encrypts stored user data and a type of application data, and the security level of the type of application data is the highest among all application data; The application module includes a tamper-proof detection module which monitors the encrypted stored user data and the type of application data in real time through a key, and when the tamper-proof detection module detects data tampering, all the encrypted stored user data and the type of application data are cleared; The tamper-proof detection module is a tamper-proof sensing circuit arranged on the shell of the smart device, and the shell of the smart device is provided with a physical button for manually clearing critical information of the smart phone; when the tamper-proof detection module detects tampering of the shell or data, the physical button is pressed to clear the critical information of the smart phone, and after the data is cleared, the smart phone is locked so that it cannot be normally used and can only be reinstalled; The application module further includes a secure VOIP APP to support the smart phone to make VOIP calls, and a secure chat APP to support the smart phone to make instant chat; The application module further includes a secure mailbox APP to support the smart phone to send and receive emails, and a camera, a microphone, a sensor and NFC; and the camera and the microphone are in a default off state and can be used only after the user manually confirms to turn them on.

2. The physically isolated single-system smartphone of claim 1, wherein, The application module includes a processor, a VPN and a firewall; When the application module and the communication module are connected, a firewall and a VPN need to be set up together.

3. The physically isolated single-system intelligent phone of claim 1, wherein, The operating system is configured with a trusted secure boot mechanism which makes the start of the hardware and software of the smart phone pass integrity verification.

4. The physically isolated single-system intelligent phone of claim 1, wherein, The application module includes a data interface, and before data is transmitted through the data interface, identity authentication is required; Data transmitted to the application module needs to be analyzed, processed, filtered and decrypted after being placed in a honeypot after being disinfected; Data transmitted from the application module needs to be authenticated, registered, encrypted and outputted with digital watermark.

5. The physically isolated single-system intelligent phone of claim 1, wherein, The application module comprises an encryption chip, which is used for data encryption, signature verification, private key encryption storage of an asymmetric algorithm, key encryption storage of a symmetric algorithm, and generation of pseudo-random numbers.

6. The physically isolated single-system intelligent phone of claim 1, wherein, The isolation module comprises an isolation circuit, the application module is connected with the isolation circuit through a first control interface, and the communication module is connected with the isolation circuit through a second control interface. The first control interface and the second control interface are used for transmitting GPIO / UART / I2C / SPI signals.

7. The physically isolated single-system intelligent phone of claim 6, wherein, Data input by the communication module to the application module is transmitted to a firewall for processing and then enters the regular operation of data. Data output by the application module is processed by a VPN in cooperation with an encryption chip and then transmitted to the firewall for processing and output.

8. The physically isolated single-system intelligent phone of claim 1, wherein, The communication module comprises 5G, 4G, BLE, WIFI, GPS and Beidou.

Citation Information

Patent Citations

  • Multi-operating system smart phone

    CN102045449A

  • Dual-system integrated smart mobile phone and private information processing method thereof

    CN105848143A

  • Network device security system

    CN106549934B

  • Mobile phone mode switching method and mobile phone

    CN102970431A

  • Firewall device of an intelligent terminal of a mobile phone

    CN109167777A