Dual Security Module System for Application Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security methods for mobile devices, such as hypervisor-based and trust zone-based systems, face performance degradation and complexity in protecting new security applications, particularly due to authentication challenges.

Innovation Solution

Implementing a dual security module system where the hypervisor is deactivated when not in use and activated only during security application execution, with one module generating and managing encryption keys for secure data storage and transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hypervisor-based security method is used to protect security applications, then security protection is improved, but device performance deteriorates due to continuous hypervisor operation

Engineering Contradiction:
Improvesecurity protectionVSAvoiddevice performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent applies dynamics by making the hypervisor state changeable - it can be activated when security applications need protection and deactivated when not needed. This dynamic switching resolves the contradiction by allowing the system to have strong security protection only when required, rather than continuously, thus maintaining device performance while providing security when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by providing security protection only to specific security applications in the secure storage area rather than the entire system. The hypervisor is activated locally only when these specific applications are executed, allowing other parts of the system to operate at full performance without hypervisor overhead.

Inventive Principle:
Principle #3Local quality

2Reliability

If trust zone based security method is used to protect security applications, then security protection is improved, but adaptability deteriorates due to complexity in protecting new security applications

Engineering Contradiction:
Improvesecurity protectionVSAvoidprotection of new security applications
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies segmentation by dividing the storage area into a secure storage area and a non-secure storage area, and further dividing security applications into authenticated applications and unauthenticated applications. This segmentation allows new security applications to be added to the authenticated group through registration, improving adaptability while maintaining security protection through the structured segmentation approach.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies universality by creating a registration mechanism that allows any new security application to be authenticated and added to the secure storage area. The hypervisor and security management system work universally with different security applications, not just pre-authenticated ones, enabling the system to protect various types of security applications including new ones.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If hypervisor is continuously activated to ensure security, then security protection is improved, but execution speed deteriorates due to hypervisor overhead

Engineering Contradiction:
Improvesecurity protectionVSAvoidapplication execution speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

The patent applies periodic action by activating the hypervisor only during specific periods when security applications are being executed, and deactivating it during other periods. This periodic activation pattern ensures security protection when needed while minimizing performance overhead during normal operation, directly resolving the speed-protection contradiction.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS10642983B2Method and apparatus for protecting application
Publication Date: 2020.05.05 SAMSUNG ELECTRONICS CO LTD
  • US10642983B2 patent drawing
  • US10642983B2 patent drawing
  • US10642983B2 patent drawing

AI summary

The present invention relates to a method for protecting content of an electronic device, comprising the steps of: enabling a first security module to transmit a data encryption request to a second security module when data requiring security is generated according to the execution of a security application by the first security module in a security storage region of a memory; enabling the second security module to generate an encryption key by using the authentication information included in the data encryption request and to encrypt the data included in the data encryption request by using the encryption key; enabling the second security module to transfer the encrypted data to the first security module; and enabling the first security module to store the encrypted data in the security application.