Secure Behavior Analysis in Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile device solutions fail to efficiently identify and correct the complex factors contributing to performance and power degradation over time, often consuming excessive resources and lacking comprehensive detection of malicious behaviors beyond known viruses and malware.

Innovation Solution

Implementing a secure behavior observation and analysis system within a trusted execution environment, utilizing multiple privilege/protection domains to intelligently monitor and analyze mobile device behaviors, generating concise behavior vectors, and performing adaptive observations to classify behaviors as benign, suspicious, malicious, or performance-degrading, while communicating securely with the user and network servers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive behavior monitoring and analysis is implemented to detect malicious behaviors and performance degradation, then detection capability and security are improved, but device resources (power, processing) are consumed excessively

Engineering Contradiction:
Improvedetection capabilityVSAvoidpower consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system segments behavior monitoring into multiple privilege domains (privileged-normal, unprivileged-secure, unprivileged-normal) with specialized observer modules in each domain. This segmentation allows distributed monitoring responsibilities, enabling comprehensive detection while distributing power consumption across different system layers rather than concentrating it in a single resource-intensive module.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces secure buffers and protected communication channels as intermediaries between observer modules and analyzer modules. These intermediaries enable efficient data transfer with minimal processing overhead, reducing the power consumption associated with continuous inter-module communication while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multiple privilege domains and secure buffers are implemented for secure behavior analysis, then security and tamper-proof monitoring are improved, but system complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides the monitoring architecture into distinct privilege domains (privileged-normal, unprivileged-secure, unprivileged-normal), with each domain having specific responsibilities. This segmentation provides security through isolation while managing complexity by assigning focused functions to each domain rather than implementing a monolithic secure system.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure buffers implemented in the patent serve multiple functions: they act as protected storage for behavior data, provide secure communication channels between modules, and enable tamper-proof data retention. This multi-functionality reduces system complexity by consolidating multiple security mechanisms into a single versatile component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If continuous behavior observation and analysis is performed to identify performance-degrading behaviors, then performance optimization is improved, but processing resources are consumed excessively

Engineering Contradiction:
Improveperformance optimizationVSAvoidprocessing resources
Core Design Contradiction:
ProductivityVSPower

Solution Approach 1:

The observer modules implement selective monitoring by focusing on specific behavior vectors relevant to performance degradation rather than continuously analyzing all possible behaviors. This partial action approach maintains performance optimization capability while significantly reducing processing resource consumption by monitoring only the most indicative behaviors.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system enables self-service performance optimization by automatically analyzing behavior patterns and identifying performance-degrading activities without requiring intensive external intervention. The localized analysis capabilities in each privilege domain allow the system to self-optimize performance while consuming minimal processing resources compared to centralized continuous analysis.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9756066B2Secure behavior analysis over trusted execution environment
Publication Date: 2017.09.05 QUALCOMM INC
  • US9756066B2 patent drawing
  • US9756066B2 patent drawing
  • US9756066B2 patent drawing

AI summary

Systems and methods for recognizing and reacting to malicious or performance-degrading behaviors in a mobile computing device include observing mobile device behaviors in an observer module within a privileged-normal portion of a secure operating environment to identify a suspicious mobile device behavior. The observer module may generate a behavior vector based on the observations, and provide the vector to an analyzer module in an unprivileged-secure portion of the secure operating environment. The vector may be analyzed in the unprivileged-secure portion to determine whether the mobile device behavior is benign, suspicious, malicious, or performance-degrading. If the behavior is found to be suspicious, operations of the observer module may be adjusted, such as to perform deeper observations. If the behavior is found to be malicious or performance-degrading behavior the user and/or a client module may be alerted in a secure, tamper-proof manner.