Mobile Device Domain Isolation via Software Provisioning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication devices lack the ability to operate in multiple isolated domains with differing levels of security and reliability without requiring hardware modifications, posing challenges in government, business, and personal settings.

Innovation Solution

A commercial off-the-shelf smartphone is adapted through software modifications to provide multiple operating modes or domains with varying security and reliability levels, using a provisioning process that clears existing software, installs trusted software, and employs a communication control module to enforce memory isolation and communication restrictions, along with integrity verification techniques using hash functions and cryptographic techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple isolated domains with differing security levels are implemented, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the mobile device into multiple isolated domains (secure domain and non-secure domain), each with its own operating system and security context. This segmentation allows different security levels to coexist without requiring complete system redesign, thereby improving reliability while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A single mobile device is designed to perform multiple functions across different domains - handling both secure communications (government/business use) and general personal use. The unified hardware platform supports multiple operating modes through software configuration, avoiding the need for separate devices and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If hardware modifications are made to achieve multiple domains, then security is improved, but ease of manufacture deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of manufacture
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The invention replaces hardware-based security modifications with software-based solutions. Instead of modifying physical device architecture to create isolated domains, the system uses software virtualization and domain isolation techniques that can be deployed through firmware or operating system-level changes, significantly improving ease of manufacture while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system achieves different security levels by changing software parameters and configuration settings rather than hardware characteristics. The mobile device can be provisioned with different security profiles, domain configurations, and access control policies through software, allowing flexible security implementation without re manufacturing the hardware.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If commercial off-the-shelf smartphone is used, then ease of manufacture is improved, but adaptability deteriorates

Engineering Contradiction:
Improveease of manufactureVSAvoidadaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system transforms a static commercial smartphone into a dynamic multi-domain platform through software configuration. The device can adapt its security context, domain isolation level, and access control policies based on provisioning information and usage requirements, enabling the same hardware to serve multiple security-critical applications while maintaining ease of manufacture.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8498619B2Method and apparatus for validating integrity of a mobile communication
Publication Date: 2013.07.30 VIASAT INC
  • US8498619B2 patent drawing
  • US8498619B2 patent drawing
  • US8498619B2 patent drawing

AI summary

A method for validating integrity of a mobile communication device includes provisioning the mobile communication device by deleting existing software and installing an integrity verification application. The method also includes establishing a first pass indicator and a second pass indicator including receiving a first instance of the first pass indicator. The method also includes receiving a second instance of the first pass indicator as a challenge for verification. In response to receiving the second instance of the first pass indicator, the second pass indicator may be displayed as an indication of the integrity.