Secure Domain Controller Persona Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile stations lack effective mechanisms to securely store sensitive data and limit access to it, allowing personal data to be accessible by work-related applications and vice versa, compromising security.

Innovation Solution

Implementing a virtualization layer with a secure domain controller and user identity module (UIM) that creates separate personas and authentication key pairs for applications, ensuring only authenticated applications can access secure data associated with their designated persona.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If sensitive data is stored on the mobile station for multiple contexts, then data accessibility and convenience are improved, but data security deteriorates because applications can access data outside their authorized context

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the mobile station into multiple isolated secure domains, each associated with a specific context (work, personal, etc.). Each domain has its own authentication credentials and access controls, preventing applications from accessing data outside their authorized context while maintaining convenient access within the authorized context.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an identity module as an intermediary between applications and sensitive data. This module authenticates applications and enforces context-based access policies, allowing legitimate access for authenticated applications while blocking unauthorized cross-context access, thus resolving the security concern.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If separate storage mechanisms are implemented for different contexts, then data security is improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal identity module that handles authentication and access control for multiple contexts and data types. This single multi-functional component manages work data, personal data, and other sensitive information across different contexts, avoiding the need for separate complex storage systems for each context while maintaining strong security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8600355B1Systems and methods for authenticating applications for access to secure data using identity modules
Publication Date: 2013.12.03 CELLCO PARTNERSHIP INC
  • US8600355B1 patent drawing
  • US8600355B1 patent drawing
  • US8600355B1 patent drawing

AI summary

A mobile station is configured to authenticate applications running thereon in order to control access by the authenticated applications to secure data stored in a subscriber identity module of the mobile station. Sensitive data securely stored in the subscriber identity module is associated with one of multiple personas implemented on the mobile station. When an application running on the mobile station requests access to the secure data, a secure domain controller processes the request and authenticates the application, for example based on an application authentication key. The secure domain controller further determines whether the application is associated with the same persona as the secure data identified in the request. If the application is authenticated, the secure domain controller then allows the application to access secure data associated with the same persona, but prevents the application from accessing secure data associated with other personas.