Secure Domain Controller Persona Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile stations lack effective mechanisms to securely store sensitive data and limit access to it, allowing personal data to be accessible by work-related applications and vice versa, compromising security.
Innovation Solution
Implementing a virtualization layer with a secure domain controller and user identity module (UIM) that creates separate personas and authentication key pairs for applications, ensuring only authenticated applications can access secure data associated with their designated persona.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If sensitive data is stored on the mobile station for multiple contexts, then data accessibility and convenience are improved, but data security deteriorates because applications can access data outside their authorized context
Solution Approach 1:
The patent segments the mobile station into multiple isolated secure domains, each associated with a specific context (work, personal, etc.). Each domain has its own authentication credentials and access controls, preventing applications from accessing data outside their authorized context while maintaining convenient access within the authorized context.
Solution Approach 2:
The patent introduces an identity module as an intermediary between applications and sensitive data. This module authenticates applications and enforces context-based access policies, allowing legitimate access for authenticated applications while blocking unauthorized cross-context access, thus resolving the security concern.
2Reliability
If separate storage mechanisms are implemented for different contexts, then data security is improved, but device complexity increases
Solution Approach 1:
The patent implements a universal identity module that handles authentication and access control for multiple contexts and data types. This single multi-functional component manages work data, personal data, and other sensitive information across different contexts, avoiding the need for separate complex storage systems for each context while maintaining strong security.
Data Source
AI summary
A mobile station is configured to authenticate applications running thereon in order to control access by the authenticated applications to secure data stored in a subscriber identity module of the mobile station. Sensitive data securely stored in the subscriber identity module is associated with one of multiple personas implemented on the mobile station. When an application running on the mobile station requests access to the secure data, a secure domain controller processes the request and authenticates the application, for example based on an application authentication key. The secure domain controller further determines whether the application is associated with the same persona as the secure data identified in the request. If the application is authenticated, the secure domain controller then allows the application to access secure data associated with the same persona, but prevents the application from accessing secure data associated with other personas.


