Dual Execution Space Telecommunication Terminal Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security policies in telecommunications terminals, such as MIDP 2.0, face issues with lack of security due to potential 'leaks' between applications and the inability to formally prove the validity of programs, while STIP profiles are not suited for open systems allowing user downloads, leading to security and validation challenges.

Innovation Solution

Implementing a computing device with two virtual machine execution spaces, one for user applications (MIDP profile) and another for operator applications (STIP profile), where the latter is inaccessible to users and ensures high security, using a single physical processing device that cannot be separated without being destroyed, allowing secure access to user interfaces and communication channels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a single execution space is used for all applications, then ease of operation is improved, but security is worsened due to potential leaks between applications

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system is divided into two separate execution spaces: a first execution space for user applications and a second execution space for operator applications. This segmentation isolates user applications from critical operator functions, preventing security leaks while maintaining ease of use for user applications.

Inventive Principle:
Principle #1Segmentation

2Ease of operation

If MIDP profile is used for user applications, then ease of operation is improved, but security is worsened due to inability to formally prove program validity

Engineering Contradiction:
Improveease of operationVSAvoidformal verification capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The execution environment is segmented into two distinct spaces with different security characteristics. The first execution space uses MIDP profile for ease of operation, while the second execution space uses STIP profile for formal verification capability, allowing each to operate in its optimal security context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A security boundary acts as an intermediary between the two execution spaces, allowing controlled interaction while maintaining security isolation. This boundary enables the system to leverage both MIDP's ease of operation and STIP's formal verification capabilities without compromising either.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If STIP profile is used for operator applications, then security is improved, but adaptability is worsened due to closed system requirements

Engineering Contradiction:
ImprovesecurityVSAvoidadaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system segments applications into user applications (first execution space) and operator applications (second execution space). This allows STIP profile to be used for security-critical operator applications while MIDP profile handles user applications, maintaining both security and adaptability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The terminal is designed to host multiple execution spaces with different profiles, making it universally capable of running both user applications and operator applications. This multi-functionality allows the system to adapt to different application requirements while maintaining security through isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If two separate physical processors are used for user and operator applications, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of separating applications physically across two processors, the system creates separation in the logical dimension through virtual execution spaces. This allows security isolation without the complexity of dual physical processors, as both execution spaces share the same physical hardware resources.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

A virtualization layer acts as an intermediary between the physical processor and applications, creating isolated execution spaces. This intermediary provides security isolation similar to separate processors while avoiding the complexity of actual multi-processor architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS7865724B2Telecommunication terminal comprising two execution spaces
Publication Date: 2011.01.04 THALES DIS FRANCE SA
  • US7865724B2 patent drawing
  • US7865724B2 patent drawing
  • US7865724B2 patent drawing

AI summary

The invention relates to a user interface-equipped computing device comprising means for implementing a series of applications, said means including two execution spaces. According to the invention, the applications of the second execution space (100, P1, 200, P2) have a level of security specifically higher than that of the applications of the first execution space (100, P1, 200, P2), said two execution spaces being hosted by a physical processing means which is designed such that it cannot be separated into two parts without destroying the physical processing means.