Secure Processing Module Isolating Sensitive Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The increasing functionality of cellular devices poses a risk to sensitive information as they can be compromised by malicious software, unauthorized access, or exposure to private networks, necessitating secure processing and encryption methods.
Innovation Solution
A processing module physically connected to a host device but executing code independently, using encryption and secure communication protocols to isolate and protect sensitive information, allowing it to execute applications like online transactions and access credentials without exposing them to the host device or network.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If cellular devices are given additional functionality (email, media player, camera, etc.), then device versatility is improved, but security risk increases due to exposure to malicious software and unauthorized access
Solution Approach 1:
The patent divides the device into two separate processing modules: a host device that handles general functions and a secure processing module that handles sensitive operations. This segmentation isolates sensitive information processing from the potentially compromised host device, allowing the secure module to operate independently with its own code execution environment, thus maintaining security while preserving device versatility.
Solution Approach 2:
The patent extracts sensitive information processing capabilities from the host device and places them in a separate secure processing module. This extraction removes the vulnerability of sensitive data being stored on or accessed by the host device, while still allowing the host device to provide necessary services like display and communication interfaces.
2Ease of operation
If sensitive information is stored on the host device, then ease of operation is improved, but reliability deteriorates due to potential compromise by malicious software
Solution Approach 1:
The secure processing module acts as an intermediary between the host device and the sensitive information. It receives access requests from the host device, validates them against security policies, and only grants access to authorized operations. This intermediary layer maintains ease of operation for authorized users while protecting reliability by blocking malicious access attempts.
Solution Approach 2:
By segmenting storage and processing functions, the patent ensures that sensitive information is processed in an isolated environment that is independent of the host device's file system and application layer, preventing malicious software on the host from accessing or corrupting sensitive data.
3Productivity
If code is executed on the host device, then productivity is improved, but security risk increases due to potential execution of malicious code
Solution Approach 1:
The patent segments code execution into two separate environments: the host device executes general applications, while the secure processing module executes code that handles sensitive information. Each module has its own isolated execution environment with separate memory spaces and system calls, preventing malicious code in one module from affecting the other.
Solution Approach 2:
The patent extracts the code execution capability for sensitive operations from the host device and implements it in the secure processing module. This extraction ensures that even if the host device is compromised, malicious code cannot execute sensitive operations, as those functions are isolated in the secure module.
4Ease of operation
If access credentials are stored on the host device, then ease of operation is improved, but reliability deteriorates due to exposure to unauthorized access
Solution Approach 1:
The patent extracts credential storage from the host device and places it in the secure processing module. The secure module maintains a private database of access credentials that is isolated from the host device's file system, ensuring that even if the host is compromised, credentials remain protected and inaccessible to unauthorized entities.
Solution Approach 2:
The secure processing module serves as an intermediary credential vault that authenticates users and authorizes access to sensitive resources. It receives authentication requests from the host device, verifies credentials in its isolated storage, and issues authorization tokens, thereby maintaining both ease of operation and reliability.
Data Source
AI summary
A processing module operating method includes using a processing module physically connected to a wireless communications device, requesting that the wireless communications device retrieve encrypted code from a web site and receiving the encrypted code from the wireless communications device. The wireless communications device is unable to decrypt the encrypted code. The method further includes using the processing module, decrypting the encrypted code, executing the decrypted code, and preventing the wireless communications device from accessing the decrypted code. Another processing module operating method includes using a processing module physically connected to a host device, executing an application within the processing module, allowing the application to exchange user interaction data communicated using a user interface of the host device with the host device, and allowing the application to use the host device as a communications device for exchanging information with a remote device distinct from the host device.


