Secure Access Interface for Untrusted Framework Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Integrating untrusted software frameworks and applications with a secure operating system environment in devices like set top boxes is challenging due to certification complexities and security risks, as existing methods often require rigid hardware separation and distinct certification processes, which can lead to security breaches and instability.

Innovation Solution

Implementing a secure software abstraction layer with secure access clients and servers, along with container-based virtualization, to isolate untrusted frameworks and applications from secure components, allowing them to interact safely while preventing unauthorized access and system breaches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If untrusted software frameworks and applications are integrated with a secure operating system environment, then functionality and adaptability are improved, but security risks and certification complexity increase

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system is divided into distinct security zones: a secure operating system environment and an untrusted framework environment. Each zone operates independently with defined boundaries, allowing untrusted applications to run in the framework zone while the secure OS remains protected in its own zone, thus maintaining security while enabling functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure access interface acts as an intermediary between the untrusted framework and the secure operating system. This interface controls and monitors all interactions, allowing necessary communication while preventing unauthorized access. The intermediary enforces security policies and validates access requests, resolving the contradiction by enabling functionality through controlled access while maintaining security through verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware boundaries are used to separate secure and untrusted processing modules, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidcomplexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides processing into separate modules: a secure processing module for critical operations and an untrusted processing module for framework applications. This segmentation allows each module to be optimized for its specific security requirements while working together through defined interfaces, achieving security through functional separation without requiring complete hardware isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure access interface provides multi-functional capabilities, handling authentication, authorization, and communication protocols through a single unified mechanism. This universal interface reduces overall system complexity by consolidating security functions rather than requiring separate hardware components for each security operation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If complete isolation is used between secure pathway and untrusted components, then security is improved, but ease of operation deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The secure access interface serves as a mediator that simplifies interaction between isolated environments. Applications in the untrusted framework can access secure resources through standardized interface calls, eliminating the need for complex integration logic. The intermediary abstracts the isolation complexity, making the system easy to operate while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements feedback mechanisms where the secure access interface monitors and controls access requests in real-time. This feedback loop allows dynamic adjustment of access permissions based on security policies, enabling smooth operation within security constraints without requiring manual configuration or complex user intervention.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9344762B2Integration of untrusted applications and frameworks with a secure operating system environment
Publication Date: 2016.05.17 AVAGO TECHNOLOGIES INTERNATIONAL SALES PTE LTD

AI summary

A set top box or like device utilizing trusted applications in conjunction with an untrusted software framework. In one implementation, trusted or certified applications are received from a service provider for execution by a software framework of the device. Certification of a trusted application may entail, for example, verifying that the application is executable by the device in a manner consist with the industry standard certification process. The software framework may comprise, for example, an Android framework supported by an underlying. Linux operating system environment and isolated in a Linux resource container. A secure access client/server interface may also be provided to support interactions between the software framework and trusted portions of the device. In further embodiments, both trusted applications and a set top box application utilized by the device to perform traditional set top box operations are implemented in at least one version of an Android or like framework.