Mobile Device Virtualization Security Architecture

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices with virtualized operating systems are susceptible to security vulnerabilities due to the underlying platform's lack of enhanced security measures, necessitating improved security in device virtualization architectures.

Innovation Solution

The implementation of a hardware and software architecture that utilizes cryptography based on public and private keys to secure multiple virtualized operating systems, enforcing security policies for hardware access and incorporating trusted execution environments, secure elements, and cryptographic processors to ensure trusted operation and secure boot processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If device virtualization is implemented to run multiple operating systems on one device, then device functionality and versatility are improved, but security vulnerabilities increase due to the underlying platform's lack of enhanced security measures

Engineering Contradiction:
Improvedevice functionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the device into multiple isolated virtual machines, each with its own trusted execution environment and security context. This allows multiple operating systems to run simultaneously while maintaining separate security boundaries, thus improving versatility without compromising security. Each VM is isolated through virtualization mechanisms that prevent unauthorized access between environments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a hypervisor as an intermediary layer between the hardware and multiple operating systems. This hypervisor manages security policies, controls access to hardware resources, and enforces isolation between virtual machines. By placing this intermediary in trust, the system can support multiple OSes while maintaining security through centralized policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security measures are enhanced in the underlying platform to protect virtualized operating systems, then system security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidarchitecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges security functions into a unified hypervisor layer that manages all virtual machines. Instead of implementing separate security mechanisms for each OS, the hypervisor provides centralized security policy enforcement, authentication, and access control. This consolidation improves security while managing complexity through a single point of control rather than distributed security implementations.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent creates a universal security framework in the hypervisor that serves multiple functions: enforcing isolation between VMs, managing hardware access policies, controlling I/O operations, and providing authentication services. This multi-functional approach enhances security across all virtualized environments without requiring separate complex security implementations for each OS.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If multiple virtualized operating systems are executed simultaneously on one device, then resource utilization and productivity are improved, but the underlying platform becomes susceptible to security vulnerabilities

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent implements preliminary security actions by establishing trusted execution environments and security policies before virtualized operating systems are loaded or executed. The hypervisor pre-configures security boundaries, authentication mechanisms, and access control rules. This preliminary setup ensures that security is embedded from the start rather than added later, allowing high resource utilization while preventing security vulnerabilities.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent incorporates feedback mechanisms where the hypervisor continuously monitors and enforces security policies across virtual machines. Security states are tracked and verified, and the system provides feedback to maintain security compliance while allowing productive multi-OS operation. This ongoing verification ensures that resource utilization remains high without compromising security.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3044661B1Mobile communication device and method of operating thereof
Publication Date: 2019.09.04 THE BOEING CO
  • EP3044661B1 patent drawingFigure 1~2
  • EP3044661B1 patent drawingFigure 3
  • EP3044661B1 patent drawingFigure 4

AI summary

A mobile communication device is provided. The mobile communication device includes a housing and an input device operable with the housing. Actuating the input device enables a user to at least one of change and verify an operational status of the mobile communication device. The mobile communication device also includes an indicator coupled in communication with said input device and configured to provide feedback to the user based on the operational status of the mobile communication device.