Secure Peripheral Interface Disablement via Hardware Enclave

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current technologies fail to securely disable and re-enable peripheral interfaces on computing devices without user intervention, making them vulnerable to malicious use and unable to prevent unauthorized access to sensitive data in secure facilities.

Innovation Solution

Implementing methods and computing devices that allow for secure disablement and re-enablement of peripheral interfaces, which cannot be thwarted by software or users, using a combination of hardware and software mechanisms such as secure memory translation tables and trusted execution environments to control access to peripheral devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If Mobile Device Management software is used to control peripheral access, then enterprise control capability is improved, but security against malicious use is worsened because software controls can be thwarted

Engineering Contradiction:
Improveenterprise control capabilityVSAvoidsecurity against malicious use
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a hardware-based intermediary (secure enclave processor or trusted execution environment) that mediates between the operating system and peripheral interfaces. This intermediary acts as a security layer that cannot be bypassed by software, providing reliable control while maintaining enterprise management capabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces software-based control mechanisms (MDM) with hardware-based control mechanisms (secure enclave, trusted execution environment). This substitution eliminates the vulnerability of software controls to malicious code while maintaining the ability to enforce peripheral access policies.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If peripheral interfaces are completely disabled for security, then security against malicious use is improved, but device usability is worsened because users cannot use legitimate functions

Engineering Contradiction:
Improvesecurity against malicious useVSAvoiddevice usability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic control of peripheral interfaces through hardware mechanisms. The secure enclave or trusted execution environment can selectively enable or disable specific peripheral interfaces based on security policies, allowing legitimate uses while preventing malicious access. This dynamic control maintains both security and usability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies different security controls to different peripheral interfaces individually. Rather than uniformly disabling all peripherals, the hardware security mechanism can grant access to specific interfaces (camera, microphone) while blocking others, providing localized security control that preserves necessary functionality.

Inventive Principle:
Principle #3Local quality

3Productivity

If MDM software controls are implemented, then enterprise monitoring capability is improved, but ability to prevent unauthorized access in secure facilities is worsened because users can bypass software controls

Engineering Contradiction:
Improveenterprise monitoring capabilityVSAvoidunauthorized access in secure facilities
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security measures by establishing hardware-based trust before the operating system or applications can interfere. The secure enclave or trusted execution environment pre-configures security policies and controls peripheral access at the hardware level, preventing unauthorized access before software can bypass controls.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies preliminary anti-action by using hardware mechanisms to preemptively block malicious software from gaining control of peripheral interfaces. The trusted execution environment establishes security boundaries that prevent malicious code from interfering with peripheral access control before the threat can manifest.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentEP3776221B1Secure interface disablement
Publication Date: 2024.01.17 QUALCOMM INC
  • EP3776221B1 patent drawingFigure 1
  • EP3776221B1 patent drawingFigure 2
  • EP3776221B1 patent drawingFigure 3

AI summary

Various embodiments include methods and devices for implementing secure peripheral interface disablement on a computing device. Various embodiments may include receiving a trigger to disable a peripheral interface associated with a peripheral device of the computing device, identifying a physical address of the peripheral interface, and securely removing a mapping of an intermediate physical address of the peripheral interface to the physical address of the peripheral interface.