Secure Execution Enclave for Mobile Device Privacy Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Smartphones lack effective mechanisms to alert users of data collection and dissemination by third-party software applications, allowing unauthorized access to sensitive information, which compromises user privacy and security.

Innovation Solution

The introduction of a secure enclave, known as the 'safe case,' which monitors and restricts third-party software access to private information by executing applications in a controlled environment, using code signing and digital keys to ensure safe execution and limit access to sensitive data such as voice, video, and location information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party software applications are allowed to access hardware and software elements on a mobile device, then functionality and user experience are improved, but security and user privacy are compromised

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the mobile device into two distinct execution environments: a secure enclave with full hardware access for legitimate applications, and a restricted sandbox environment for third-party software. This segmentation allows third-party applications to function while preventing them from accessing sensitive hardware elements, thus resolving the contradiction between functionality and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a mediator layer (secure execution environment) that sits between third-party software and hardware resources. This intermediary controls and filters all access requests, allowing necessary functionality while blocking unauthorized access to sensitive data, thereby maintaining both versatility and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If third-party software applications are restricted from accessing private information, then user privacy and security are improved, but functionality and user experience deteriorate

Engineering Contradiction:
Improveuser privacyVSAvoidfunctionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies different access permissions to different data types and resources within the system. Third-party applications are granted local quality restrictions that allow them to access only specific non-sensitive resources while being blocked from sensitive private information, thus maintaining privacy without completely sacrificing functionality.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates a copied or simulated version of the hardware environment within the secure enclave that provides third-party applications with the functionality they need without granting actual access to sensitive hardware resources. This allows functionality to be maintained while privacy is protected.

Inventive Principle:
Principle #26Copying

3Reliability

If a secure execution enclave is implemented to monitor and restrict third-party software, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the secure execution enclave functionality into the existing mobile device processor and memory structure, rather than requiring a completely separate physical system. This integration approach provides enhanced security while minimizing the increase in device complexity by utilizing existing hardware resources in a new security architecture.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS11303639B2Secure execution enclave for user equipment (UE)
Publication Date: 2022.04.12 PPIP LLC
  • US11303639B2 patent drawing
  • US11303639B2 patent drawing
  • US11303639B2 patent drawing

AI summary

In some embodiments, an apparatus (e.g., a first device) for secure execution of software is provided. The apparatus includes a housing arranged to hold a second device. The apparatus includes a memory configured to store a set of instructions of an application, a local communications device, and a processor. The apparatus is configured to execute the application and transmit a first set of data via the local communication device to be processed by the second device. The apparatus may receive, input data from the second device, interpret the input data using the set of instructions of the application, and transmit a second set of data via the local communication device to be processed by the second device, the second set of data may reflect an updated active state of the application.