Multi-mode Data Isolation for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security solutions for mobile devices, such as VMware, OS division, and application duplication schemes, consume excessive CPU and memory resources, leading to performance degradation and inefficiencies when used for Bring Your Own Device (BYOD) scenarios, where personal devices are used for both personal and business purposes.

Innovation Solution

A device and method that utilize multiple operating modes, with a multi-mode application processing data in a normal mode data area during normal usage and in a security mode data area during security mode, isolating sensitive business data and reducing resource consumption by encrypting and decrypting data as needed.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If VMware scheme is applied to provide security separation, then security isolation is improved, but CPU resources and memory resources are excessively consumed leading to performance degradation

Engineering Contradiction:
Improvesecurity isolationVSAvoidCPU resources and memory resources consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the security-critical data processing functions from the main application and places them in a separate security mode data area. This extraction allows security isolation without requiring full virtualization overhead, as only the essential security functions are separated rather than entire application processes.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The storage area is segmented into a normal mode data area and a security mode data area. This segmentation provides logical separation of data based on security requirements, allowing the system to maintain security isolation while using a unified memory space that reduces overall resource consumption compared to full virtualization.

Inventive Principle:
Principle #1Segmentation

2Reliability

If OS division scheme is applied to separate general and business applications, then security separation is improved, but memory resources are excessively consumed and interworking between OSs becomes difficult

Engineering Contradiction:
Improvesecurity separationVSAvoidmemory resources consumption
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent implements a multi-mode application that can operate in both normal mode and security mode. This multi-functionality allows a single application to serve both personal and business purposes while maintaining security separation through mode-specific data area access, eliminating the need for separate OS instances.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the functionality of multiple OSs into a single unified OS that supports multiple operating modes. The normal mode and security mode share the same underlying OS infrastructure, memory space, and hardware resources, while maintaining logical separation through mode-specific data areas and access control mechanisms.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If application duplication scheme is applied to install general and business applications, then security separation is improved, but memory resources are excessively consumed and application management becomes inconvenient

Engineering Contradiction:
Improvesecurity separationVSAvoidapplication management convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic mode switching that allows the application to transition between normal mode and security mode based on the user's needs. This dynamic adaptability provides security separation when required while maintaining ease of use, as users can switch modes without managing separate application installations or configurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9911009B2Device and method for providing safety of data by using multiple modes in device
Publication Date: 2018.03.06 SAMSUNG ELECTRONICS CO LTD
  • US9911009B2 patent drawing
  • US9911009B2 patent drawing
  • US9911009B2 patent drawing

AI summary

A device and method for providing the security of data by using multiple modes in the device are provided. The device includes a storage unit that includes a normal mode data area and a security mode data area which is isolated from the normal mode data area and access to which is allowed only in a security mode; and a controller that processes data in the normal mode data area during a normal mode, and processes data in the security mode data area during the security mode.