Secure Behavior Analysis in Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile device solutions fail to efficiently identify and correct the complex factors contributing to performance and power degradation over time, often consuming excessive resources and lacking comprehensive detection of malicious behaviors beyond known viruses and malware.
Innovation Solution
Implementing a secure behavior observation and analysis system within a trusted execution environment, utilizing multiple privilege/protection domains to intelligently monitor and analyze mobile device behaviors, generating concise behavior vectors, and performing adaptive observations to classify behaviors as benign, suspicious, malicious, or performance-degrading, while communicating securely with the user and network servers.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If comprehensive behavior monitoring and analysis is implemented to detect malicious behaviors and performance degradation, then detection capability and security are improved, but device resources (power, processing) are consumed excessively
Solution Approach 1:
The system segments behavior monitoring into multiple privilege domains (privileged-normal, unprivileged-secure, unprivileged-normal) with specialized observer modules in each domain. This segmentation allows distributed monitoring responsibilities, enabling comprehensive detection while distributing power consumption across different system layers rather than concentrating it in a single resource-intensive module.
Solution Approach 2:
The patent introduces secure buffers and protected communication channels as intermediaries between observer modules and analyzer modules. These intermediaries enable efficient data transfer with minimal processing overhead, reducing the power consumption associated with continuous inter-module communication while maintaining comprehensive monitoring capabilities.
2Reliability
If multiple privilege domains and secure buffers are implemented for secure behavior analysis, then security and tamper-proof monitoring are improved, but system complexity increases
Solution Approach 1:
The system divides the monitoring architecture into distinct privilege domains (privileged-normal, unprivileged-secure, unprivileged-normal), with each domain having specific responsibilities. This segmentation provides security through isolation while managing complexity by assigning focused functions to each domain rather than implementing a monolithic secure system.
Solution Approach 2:
The secure buffers implemented in the patent serve multiple functions: they act as protected storage for behavior data, provide secure communication channels between modules, and enable tamper-proof data retention. This multi-functionality reduces system complexity by consolidating multiple security mechanisms into a single versatile component.
3Productivity
If continuous behavior observation and analysis is performed to identify performance-degrading behaviors, then performance optimization is improved, but processing resources are consumed excessively
Solution Approach 1:
The observer modules implement selective monitoring by focusing on specific behavior vectors relevant to performance degradation rather than continuously analyzing all possible behaviors. This partial action approach maintains performance optimization capability while significantly reducing processing resource consumption by monitoring only the most indicative behaviors.
Solution Approach 2:
The system enables self-service performance optimization by automatically analyzing behavior patterns and identifying performance-degrading activities without requiring intensive external intervention. The localized analysis capabilities in each privilege domain allow the system to self-optimize performance while consuming minimal processing resources compared to centralized continuous analysis.
Data Source
AI summary
Systems and methods for recognizing and reacting to malicious or performance-degrading behaviors in a mobile computing device include observing mobile device behaviors in an observer module within a privileged-normal portion of a secure operating environment to identify a suspicious mobile device behavior. The observer module may generate a behavior vector based on the observations, and provide the vector to an analyzer module in an unprivileged-secure portion of the secure operating environment. The vector may be analyzed in the unprivileged-secure portion to determine whether the mobile device behavior is benign, suspicious, malicious, or performance-degrading. If the behavior is found to be suspicious, operations of the observer module may be adjusted, such as to perform deeper observations. If the behavior is found to be malicious or performance-degrading behavior the user and/or a client module may be alerted in a secure, tamper-proof manner.


