Secure Execution Environment for Mobile Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current Trusted Platform Modules (TPMs) and Mobile Trusted Modules (MTMs) face challenges in managing security functions, particularly in updating and migrating sensitive data, supporting multiple service protection methods, and ensuring security properties are maintained during upgrades, which limits their functionality and efficiency in cellular telecommunications networks.
Innovation Solution
Implementing an upgradeable software MTM with a secure execution environment that allows for over-the-air software updates, key management, and secure data migration, enabling the terminal to support multiple service protection methods and maintain security properties during upgrades, while also allowing for background operations without user intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a stand-alone TPM chip is used, then security functions are provided, but device complexity increases and ease of operation deteriorates due to physical presence requirements
Solution Approach 1:
The patent merges the TPM security functions with the mobile terminal's existing processor and memory resources, eliminating the need for a separate stand-alone chip. The security module is integrated into the terminal's system architecture, sharing computational resources while maintaining security isolation through virtualization techniques.
Solution Approach 2:
The patent introduces a security manager component that acts as an intermediary between the security module and other system components. This manager handles key management, secure operations, and coordination with the SIM card, simplifying the interface and reducing the complexity of direct chip-to-component interactions.
2Reliability
If TPM is implemented as additional stand-alone chip, then security functions are provided, but ease of operation worsens due to physical presence state requirements
Solution Approach 1:
The security module is designed to operate autonomously within the terminal without requiring external physical presence or intervention. It self-manages key storage, cryptographic operations, and security policies, eliminating the need for users to physically access or configure the security chip.
Solution Approach 2:
The security manager serves as an intermediary that abstracts away the physical presence requirements from user interactions. It handles authentication, authorization, and secure operations through software interfaces, making security functions as accessible as any other terminal function without requiring physical chip access.
3Reliability
If TPM hardware module is used, then security functions are provided, but adaptability deteriorates due to difficulty in updating and migrating
Solution Approach 1:
The security module is implemented as a dynamic software-based system rather than static hardware. This allows the security functions, algorithms, and key management policies to be updated, upgraded, or migrated through software updates without requiring physical hardware replacement or complex reconfiguration.
Solution Approach 2:
The integrated security module is designed to support multiple service protection methods and cryptographic standards simultaneously. It can adapt to different security requirements and protocols, providing universal security functionality across various applications and services rather than being limited to a single fixed function.
4Adaptability or versatility
If multiple service protection methods are supported, then adaptability improves, but device complexity increases
Solution Approach 1:
The security module is segmented into independent functional components, each handling specific service protection methods or cryptographic algorithms. This modular architecture allows multiple protection methods to be supported through separate, manageable modules rather than a monolithic complex system, reducing overall complexity while maintaining versatility.
Solution Approach 2:
The security module implements a universal interface and common key management infrastructure that works across multiple service protection methods. By providing a unified framework that can accommodate different algorithms and protocols through standardized interfaces, the system achieves multi-functionality without proportionally increasing complexity.
Data Source
AI summary
A mobile terminal for use with a cellular or mobile telecommunications network includes a normal execution environment and a secure execution environment The mobile terminal enables the software of the terminal in the secure execution environment to be updated. The terminal may be provided with minimal software initially in the secure execution environment, and is operable to subsequently update the software by over the air transmission of software. Also disclosed is a method for managing rights in respect of broadcast, multicast and/or unicast (downloaded) data. The method defines a service protection platform implemented on mobile terminals having both normal execution environment and secure execution environment. Service protection is provided by separating the operation of service protection application components into those that operate in the normal environment and those that are adapted to execute only in the secure execution environment.


