Cross Domain Notification for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication devices lack the ability to operate in multiple isolated domains with differing levels of security and reliability without hardware modification, posing challenges in government, business, and personal settings.

Innovation Solution

A commercial off-the-shelf smartphone is adapted through software modifications to provide multiple operating modes or domains, with a provisioning process that clears existing software, installs trusted software, and includes cross-domain activity notification and user authentication mechanisms to ensure secure switching between domains.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple isolated domains with differing security levels are implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the mobile device into multiple isolated domains (first domain and second domain), each with different security levels. The first domain operates with higher security restrictions while the second domain allows more freedom. This segmentation enables simultaneous operation of secure and unrestricted applications without compromising overall system security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A domain manager acts as an intermediary component that controls switching between domains and manages domain isolation. The domain manager handles domain switching requests, enforces security policies, and ensures that applications cannot unauthorizedly access other domains, thereby managing the complexity of multi-domain operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If domain switching capability is added, then adaptability is improved, but ease of operation deteriorates due to authentication requirements

Engineering Contradiction:
Improvedomain switching capabilityVSAvoiduser operation simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system performs preliminary authentication and domain establishment actions before actual domain switching is needed. User credentials are verified in advance, and domain contexts are pre-configured, so that when switching is required, the process is streamlined and does not require repeated complex authentication sequences.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system provides feedback to users about their current domain status and the security implications of switching domains. This feedback mechanism helps users make informed decisions about domain switching and understand when authentication is required, making the overall operation more intuitive despite the added complexity.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If cross-domain activity notification is implemented, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improveactivity tracking accuracyVSAvoidnotification system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The domain manager serves as an intermediary that monitors and tracks activities across domains. It detects when applications attempt to access resources in other domains and generates appropriate notifications. This centralized mediation approach enables precise activity tracking without requiring complex monitoring logic in each individual application or domain.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8594652B2Cross domain notification
Publication Date: 2013.11.26 VIASAT INC
  • US8594652B2 patent drawing
  • US8594652B2 patent drawing
  • US8594652B2 patent drawing

AI summary

A method for a mobile communication device to indicate activity associated with an operating domain includes establishing a plurality of operating domains for the mobile communication device each operating as an independent virtual machine. The method also includes providing a trusted indicator at the mobile communication device for indicating activity associated with a high-side domain. The method also includes providing an input on the mobile communication device for switching from a low-side domain to the high-side domain. The method also includes providing a trusted element for the mobile communication device that is independent of either the high-side domain or the low-side domain. The trusted element may be configured to receive a signal from the input for switching from the low-side domain to the high-side domain and to perform user authentication for switching from the low-side domain to the high-side domain.