Dual Security Module System for Application Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security methods for mobile devices, such as hypervisor-based and trust zone-based systems, face performance degradation and complexity in protecting new security applications, particularly due to authentication challenges.
Innovation Solution
Implementing a dual security module system where the hypervisor is deactivated when not in use and activated only during security application execution, with one module generating and managing encryption keys for secure data storage and transmission.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If hypervisor-based security method is used to protect security applications, then security protection is improved, but device performance deteriorates due to continuous hypervisor operation
Solution Approach 1:
The patent applies dynamics by making the hypervisor state changeable - it can be activated when security applications need protection and deactivated when not needed. This dynamic switching resolves the contradiction by allowing the system to have strong security protection only when required, rather than continuously, thus maintaining device performance while providing security when needed.
Solution Approach 2:
The patent applies local quality by providing security protection only to specific security applications in the secure storage area rather than the entire system. The hypervisor is activated locally only when these specific applications are executed, allowing other parts of the system to operate at full performance without hypervisor overhead.
2Reliability
If trust zone based security method is used to protect security applications, then security protection is improved, but adaptability deteriorates due to complexity in protecting new security applications
Solution Approach 1:
The patent applies segmentation by dividing the storage area into a secure storage area and a non-secure storage area, and further dividing security applications into authenticated applications and unauthenticated applications. This segmentation allows new security applications to be added to the authenticated group through registration, improving adaptability while maintaining security protection through the structured segmentation approach.
Solution Approach 2:
The patent applies universality by creating a registration mechanism that allows any new security application to be authenticated and added to the secure storage area. The hypervisor and security management system work universally with different security applications, not just pre-authenticated ones, enabling the system to protect various types of security applications including new ones.
3Reliability
If hypervisor is continuously activated to ensure security, then security protection is improved, but execution speed deteriorates due to hypervisor overhead
Solution Approach 1:
The patent applies periodic action by activating the hypervisor only during specific periods when security applications are being executed, and deactivating it during other periods. This periodic activation pattern ensures security protection when needed while minimizing performance overhead during normal operation, directly resolving the speed-protection contradiction.
Data Source
AI summary
The present invention relates to a method for protecting content of an electronic device, comprising the steps of: enabling a first security module to transmit a data encryption request to a second security module when data requiring security is generated according to the execution of a security application by the first security module in a security storage region of a memory; enabling the second security module to generate an encryption key by using the authentication information included in the data encryption request and to encrypt the data included in the data encryption request by using the encryption key; enabling the second security module to transfer the encrypted data to the first security module; and enabling the first security module to store the encrypted data in the security application.


