Electronic Device Data Isolation via Trusted User Identifier

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data security measures, such as secure elements and encryption, face limitations in versatility and storage capacity, and may become disabled when encrypted files are deleted, failing to adequately protect data in-transit, at-rest, and in-use.

Innovation Solution

An electronic device with a processor and storage device that generates a user identifier based on trusted application and device information to manage data in a secure area, ensuring data integrity and access control through a trusted execution environment and secure area authentication, independent of the normal operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure element is used for confidential computing, then data security is improved, but storage space and versatility are limited

Engineering Contradiction:
Improvedata securityVSAvoidstorage capacity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The storage device is divided into a secure area and a normal area. The secure area is specifically assigned to store data for trusted applications, while the normal area handles general storage operations. This segmentation allows the system to provide enhanced security for sensitive data without compromising the overall storage capacity and versatility of the device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A processor acts as an intermediary between the trusted application and the storage device. The processor generates a user identifier based on device information and manages data access to the secure area based on this identifier. This intermediary mechanism enables secure data management while maintaining system versatility and storage capacity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is used to protect data, then data security is improved, but data becomes inaccessible when encrypted files are deleted

Engineering Contradiction:
Improvedata securityVSAvoiddata accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system uses self-service mechanisms where the processor automatically generates user identifiers and manages encryption/decryption operations based on device information and trusted application credentials. This automated approach ensures that data remains accessible to authorized applications even without manual intervention, while maintaining strong encryption protection.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where the processor continuously verifies user identifiers and manages data access based on authentication status. This feedback loop ensures that encrypted data remains accessible to authorized trusted applications while preventing unauthorized access, resolving the contradiction between security and accessibility.

Inventive Principle:
Principle #23Feedback

3Reliability

If a secure area is assigned to a trusted application, then data integrity is improved, but device complexity increases

Engineering Contradiction:
Improvedata integrityVSAvoidsystem structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The secure area and user identifier mechanism serve multiple functions: they provide data integrity protection, enable access control, and support trusted application execution. This multi-functionality approach allows the system to achieve high data integrity without proportionally increasing device complexity, as the same structural elements serve multiple security and operational purposes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20240275588A1Electronic device for data isolation and method of operating the same
Publication Date: 2024.08.15 SAMSUNG ELECTRONICS CO LTD
  • US20240275588A1 patent drawing
  • US20240275588A1 patent drawing
  • US20240275588A1 patent drawing

AI summary

An electronic device includes a storage device, including a secure area assigned to a trusted application and a normal area, and a processor configured to generate a user identifier, assigned to the trusted application, based on the trusted application and device information and to manage data requested for the secure area from the trusted application based on the user identifier. The device information includes at least one of information associated with the storage device and information associated with the processor.