Mobile Security Matrix with Trust Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile device security systems are vulnerable to various attacks, including identity theft, software piracy, and digital rights management violations, leading to significant financial losses and potential liability for manufacturers, with existing solutions often introducing new security holes and being difficult to validate.

Innovation Solution

Implementing a security matrix model with trust zones and layered memory schemes to control accessibility by trusted and non-trusted entities, incorporating modules such as memory protection, secure debug, secure file system, trusted time source, and security mode control to secure hardware and software components.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software solutions are used to address security issues, then security coverage is improved, but new security holes are introduced and validation becomes difficult

Engineering Contradiction:
Improvesecurity coverageVSAvoidvalidation difficulty
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the system into trusted and non-trusted execution environments, creating distinct security zones. The trusted environment runs security-critical code while the non-trusted environment runs applications, preventing applications from compromising security functions and eliminating the need to validate security logic within application code.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment as an intermediary layer between applications and security-sensitive operations. This mediator verifies application requests and enforces security policies, isolating validation complexity to the trusted environment while providing comprehensive security coverage to the entire system.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If manufacturers embed immutable security modules in hardware, then security protection is improved, but adaptability for different vendors and customization is reduced

Engineering Contradiction:
Improvesecurity protectionVSAvoidvendor customization
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic security configurations within the trusted execution environment, allowing security policies and access controls to be modified based on vendor requirements and application needs. This dynamic approach maintains strong security protection while enabling adaptability for different vendors and use cases without requiring hardware changes.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS7921303B2Mobile security system and method
Publication Date: 2011.04.05 QUALCOMM INC
  • US7921303B2 patent drawing
  • US7921303B2 patent drawing
  • US7921303B2 patent drawing

AI summary

A system and method for providing a secure environment for mobile telephones and other devices are disclosed. The system and method may utilize trust zoning, layered memory, and a secure matrix model having, for example, a memory protection module for protecting memory; a secure debug module for ensuring security of the debug module; a secure file system module for protecting the secure file system; and a trusted time source module for protecting components. Embodiments of the present invention may protect against security attacks on a variety of hardware and software components while permitting suitable levels of accessibility for developmental and maintenance purposes.