Embedded Stub for Secured VMM Client Access
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face security threats due to malicious applications and the need for secure access to privileged processes, especially for Virtual Mobile Management (VMM) clients, which require 'root' privileges but pose risks if not managed properly, and existing methods are inefficient for remote application management and secure key exchange.
Innovation Solution
An embedded stub with 'root' privilege is integrated into the mobile device's OS to authorize VMM clients and tools, enabling secure access to network interfaces through a Communication Endpoint Gateway (CEG) server using a secured key exchange algorithm, allowing communication via a secure link between the embedded stub and session mediation server.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If VMM client is given root privilege to access privileged processes, then access capability is improved, but security risk increases
Solution Approach 1:
The patent introduces an embedded stub as an intermediary component that mediates between the VMM client and the privileged processes. The stub is integrated into the mobile device OS and provides a controlled interface, allowing the VMM client to access privileged functions without obtaining full root privileges. This mediator approach enables the system to grant necessary access capabilities while maintaining security by preventing direct access to root-level processes.
Solution Approach 2:
The patent segments the privileged access mechanism by separating the VMM client from direct root access. Instead of giving the client full root privileges, the system divides the access right into two parts: the embedded stub that holds the root privilege and the VMM client that uses the stub's interface. This segmentation allows privileged access to be granted selectively and controlledly, reducing the security risk associated with full root access.
2Object-affected harmful factors
If key exchange procedure is implemented for securing access, then security is improved, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-integrating the embedded stub into the mobile device operating system during the device manufacturing process. The stub is pre-configured with the necessary security credentials and communication protocols, eliminating the need for complex runtime key exchange procedures. This preliminary setup simplifies the overall system complexity while maintaining strong security, as the authentication mechanisms are already in place before the VMM client needs to access privileged functions.
Data Source
AI summary
Disclosed is an apparatus and method to access privileges of Virtual Mobile Management (VMM) client in mobile device. A disclosed example method contains an assigning embedded stub to raise the access privilege of the tool on a mobile device, the embedded stub is integrated by an operating system of the mobile device with “root” privilege, determining via a secured key exchange algorithm that the VMM client and tools is authorized to be installed on the mobile device then, the VMM client and tools of a mobile device are authorized to access a network interface of the Communication Endpoint Gateway (CEG) server, configuring the embedded stub to install the key exchange procedure for the shared certification between the embedded stub, VMM client and the session mediation server, enabling the embedded stub to communicate through a secure link via VMM client.


