Dual-Kernel Mobile Terminal Secure Communication Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication security is compromised due to the increasing complexity of operating systems in mobile terminals, leading to security vulnerabilities that allow eavesdropping on communication content.
Innovation Solution
Implementing a secure communication method that uses a dual-kernel architecture in mobile terminals, where a secure virtual kernel and a common virtual kernel share resources but are isolated, with the secure kernel performing policy-based processing and encryption on communication content to prevent unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single operating system kernel is used in mobile terminals, then the device complexity is reduced and ease of operation is improved, but communication security deteriorates due to vulnerabilities allowing eavesdropping
Solution Approach 1:
The patent divides the operating system kernel into two separate virtual kernels: a secure virtual kernel and a common virtual kernel. Each kernel operates independently with isolated memory spaces and permission systems. The secure virtual kernel handles sensitive communication operations while the common virtual kernel manages general applications, preventing unauthorized access between domains and thus improving communication security without requiring complete system redesign.
Solution Approach 2:
The patent introduces a permission management mechanism as an intermediary between the secure and common virtual kernels. This mediator controls and regulates access requests from the common kernel to secure kernel resources, enforcing security policies and preventing direct unauthorized access. The intermediary layer maintains security boundaries while enabling necessary controlled interactions between the two kernels.
2Adaptability or versatility
If the operating system has full access to communication content for processing, then system functionality is improved, but security deteriorates as the OS becomes vulnerable to eavesdropping
Solution Approach 1:
The patent implements different security qualities in different parts of the system. The secure virtual kernel and its associated memory space are assigned high security quality with restricted access, while the common virtual kernel operates with standard functionality. This local differentiation allows the system to maintain full functionality in the common domain while protecting sensitive operations in the secure domain from eavesdropping.
Solution Approach 2:
The patent extracts sensitive communication processing functions from the common operating system environment and places them in a separate secure virtual kernel. By taking out these critical functions into an isolated security domain, the system maintains necessary processing capabilities while removing the vulnerability vector that would allow the general OS to access and potentially compromise communication content.
3Use of energy by moving object
If memory and peripherals are shared between kernel domains, then resource utilization is improved, but security deteriorates due to potential unauthorized access
Solution Approach 1:
The patent implements dynamic access control mechanisms that adjust permission levels based on the operational context. The permission management system dynamically grants or revokes access rights to shared memory and peripherals depending on which virtual kernel requires the resource and what security policies are currently active. This dynamic approach allows efficient resource sharing when needed while maintaining security boundaries when required.
Solution Approach 2:
The patent incorporates feedback mechanisms in the permission management system that monitor access requests to shared resources. When the common virtual kernel attempts to access secure kernel resources, the system provides feedback through the permission management mechanism that enforces security policies. This feedback loop ensures that resource sharing occurs only under controlled conditions that maintain both efficiency and security.
Data Source
AI summary
Embodiments of the present disclosure disclose a secure communication method for a mobile terminal and a mobile terminal. The secure communication method may include: when a wireless communication connection is established between the mobile terminal and another mobile terminal, and the wireless communication connection meets a preset security processing trigger condition, prohibiting, by means of setting, a program in a common virtual kernel from accessing a shared memory between a secure virtual kernel and the common virtual kernel and accessing a peripheral that needs to be called for the wireless communication connection; performing, by using the secure virtual kernel, preset policy-based processing on communication content corresponding to the wireless communication connection; and outputting, by using the secure virtual kernel, communication content obtained by performing the preset policy-based processing.


