Secure Data Storage in Wireless Devices via Dual OS Architecture
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Wireless communication devices with open operating systems are vulnerable to malicious applications exploiting the open source code, which can compromise the security of protected data, and existing solutions do not adequately safeguard sensitive information.
Innovation Solution
A dual-processing circuitry architecture where the RF operating system manages protected data in a secure memory inaccessible to the open operating system, encrypting and decrypting data as needed to prevent unauthorized access, ensuring that only genuine applications can decrypt protected data for legitimate purposes.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If an open operating system is used to facilitate third-party application development, then application development capability is improved, but security of protected data deteriorates due to potential malicious applications
Solution Approach 1:
The system is divided into two separate operating systems: an open operating system for application execution and a closed RF operating system for secure data management. This segmentation allows the open system to maintain development flexibility while the closed system ensures data security through physical and logical isolation.
Solution Approach 2:
The closed RF operating system acts as an intermediary between the open operating system and the protected data. It receives requests from applications, verifies their legitimacy, and mediates data access by returning encrypted or decrypted data as appropriate, preventing direct access to the data storage.
2Reliability
If protected data is stored in a secure memory inaccessible to the open operating system, then security is improved, but data access capability deteriorates
Solution Approach 1:
The closed RF operating system serves as an intermediary that manages data access requests. It receives requests from the open operating system, retrieves data from secure storage, and returns it in appropriate formats (encrypted or decrypted), thereby maintaining security while enabling necessary data access functionality.
Solution Approach 2:
The closed RF operating system autonomously manages the encryption and decryption processes without requiring direct intervention from the open operating system or applications. It self-manages the secure data lifecycle including storage, retrieval, encryption, and decryption operations.
3Reliability
If the RF operating system encrypts protected data before transfer to the open operating system, then security is improved, but processing efficiency deteriorates due to additional encryption/decryption operations
Solution Approach 1:
Different data elements are treated differently based on their security requirements. Unprotected data is transferred without encryption for efficient processing, while only protected data undergoes encryption/decryption operations. This selective approach maintains security for sensitive information while preserving processing efficiency for non-sensitive data.
Data Source
AI summary
A wireless communication device comprises first processing circuitry configured to execute an RF operating system and second processing circuitry configured to execute an open operating system, wherein the first processing circuitry is linked to a secure memory device inaccessible to the second processing circuitry. The RF operating system is configured to receive protected data and store the protected data in the secure memory device. The open operating system is configured to receive a request for the protected data from one of a plurality of user applications and transfer the request to the RF operating system. In response to the request for the protected data, the RF operating system is configured to retrieve the protected data from the secure memory device, encrypt the protected data, and transfer the encrypted protected data to the open operating system for delivery to the one of the user applications associated with the request.


