Dual Execution Space Telecommunication Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security policies in telecommunications terminals, such as MIDP 2.0, face issues with lack of security due to potential 'leaks' between applications and the inability to formally prove the validity of programs, while STIP profiles are not suited for open systems allowing user downloads, leading to security and validation challenges.
Innovation Solution
Implementing a computing device with two virtual machine execution spaces, one for user applications (MIDP profile) and another for operator applications (STIP profile), where the latter is inaccessible to users and ensures high security, using a single physical processing device that cannot be separated without being destroyed, allowing secure access to user interfaces and communication channels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a single execution space is used for all applications, then ease of operation is improved, but security is worsened due to potential leaks between applications
Solution Approach 1:
The system is divided into two separate execution spaces: a first execution space for user applications and a second execution space for operator applications. This segmentation isolates user applications from critical operator functions, preventing security leaks while maintaining ease of use for user applications.
2Ease of operation
If MIDP profile is used for user applications, then ease of operation is improved, but security is worsened due to inability to formally prove program validity
Solution Approach 1:
The execution environment is segmented into two distinct spaces with different security characteristics. The first execution space uses MIDP profile for ease of operation, while the second execution space uses STIP profile for formal verification capability, allowing each to operate in its optimal security context.
Solution Approach 2:
A security boundary acts as an intermediary between the two execution spaces, allowing controlled interaction while maintaining security isolation. This boundary enables the system to leverage both MIDP's ease of operation and STIP's formal verification capabilities without compromising either.
3Reliability
If STIP profile is used for operator applications, then security is improved, but adaptability is worsened due to closed system requirements
Solution Approach 1:
The system segments applications into user applications (first execution space) and operator applications (second execution space). This allows STIP profile to be used for security-critical operator applications while MIDP profile handles user applications, maintaining both security and adaptability.
Solution Approach 2:
The terminal is designed to host multiple execution spaces with different profiles, making it universally capable of running both user applications and operator applications. This multi-functionality allows the system to adapt to different application requirements while maintaining security through isolation.
4Reliability
If two separate physical processors are used for user and operator applications, then security is improved, but device complexity is worsened
Solution Approach 1:
Instead of separating applications physically across two processors, the system creates separation in the logical dimension through virtual execution spaces. This allows security isolation without the complexity of dual physical processors, as both execution spaces share the same physical hardware resources.
Solution Approach 2:
A virtualization layer acts as an intermediary between the physical processor and applications, creating isolated execution spaces. This intermediary provides security isolation similar to separate processors while avoiding the complexity of actual multi-processor architecture.
Data Source
AI summary
The invention relates to a user interface-equipped computing device comprising means for implementing a series of applications, said means including two execution spaces. According to the invention, the applications of the second execution space (100, P1, 200, P2) have a level of security specifically higher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces being hosted by a physical processing means which is designed such that it cannot be separated into two parts without destroying the physical processing means.


