Secure Virtual Card Execution via Segmented Processor Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to malicious attacks when running applications, as the operating system and applications are unprotected, allowing hackers to access and misuse virtual card applications.

Innovation Solution

A security object is used to decrypt and manage a protected application, creating a virtual card that can only be executed within the processor, providing a secure functionality equivalent to a physical electronic card, and is controlled by a public/private key pair for access and management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If the mobile device runs applications with unprotected operating system, then the ease of operation is improved, but the security against malicious attacks deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system segments the application execution environment by creating a protected application instance that is isolated from the unprotected operating system. The protected application receives security objects that enable it to run in a secure manner while other applications continue to use the standard unprotected OS, thus maintaining ease of operation for general use while securing sensitive operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A protection manager acts as an intermediary between the unprotected operating system and the protected application. It receives security objects from a security object manager and distributes them to protected applications, enabling secure execution without requiring the entire operating system to be protected, thus balancing security with ease of operation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the protected application is converted to executable form, then the functionality is improved, but the security exposure is increased

Engineering Contradiction:
ImprovefunctionalityVSAvoidsecurity exposure
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary protection by converting the protected application into an executable form only after it has received and processed security objects. The protection manager prepares the execution environment in advance by obtaining security objects from the security object manager, ensuring that security measures are in place before the application becomes fully functional and exposed to potential attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system applies security measures locally to specific protected applications rather than uniformly to all applications. Each protected application receives security objects that enable its specific secure execution requirements, allowing functionality to be enhanced where needed while minimizing security exposure for applications that do not require protection.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the virtual card is executed on the mobile device, then the convenience is improved, but the vulnerability to attacks is increased

Engineering Contradiction:
ImproveconvenienceVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The virtual card functionality is segmented into a protected application that operates independently from the main operating system. The protected application receives security objects that isolate it from malicious attacks on the unprotected OS, allowing users to enjoy the convenience of mobile virtual card execution while maintaining security through environmental segmentation.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9223965B2Secure generation and management of a virtual card on a mobile device
Publication Date: 2015.12.29 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US9223965B2 patent drawing
  • US9223965B2 patent drawing
  • US9223965B2 patent drawing

AI summary

A method, system, and/or computer program product securely generates and/or manages a virtual card on a mobile device. The mobile device receives a protected application, which initially cannot be accessed by an operating system for execution by a processor. The mobile device also receives a security object, which is used to convert the received protected application into an executable application that can be utilized by the operating system for execution by the processor. The executable application is then executed by the processor to act as a virtual card, which provides a functionality of a predefined physical electronic or magnetic-stripe card.