Security Engine for Secure Operating Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices face challenges in securely managing sensitive data due to variations in hardware and operating system resources, leading to limitations in supporting security-sensitive applications across different devices, and existing secure elements are hindered by computing resources and storage capacity.
Innovation Solution
A secure operating environment is implemented that includes a security engine to determine and provide security services based on the device's capabilities, offering a trusted environment for applications to manage security and integrity through memory management, secure storage, and additional security features, enhancing the ability of sensitive applications to run securely across various devices.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure element is used to protect sensitive data, then security protection is provided, but the computing resources and storage capacity of the secure element limit the amount of data that can be protected
Solution Approach 1:
The patent divides the security architecture into multiple components: a secure element for storing security credentials and a secure operating environment for managing sensitive data. This segmentation allows the secure element to maintain its security functions while the secure operating environment provides extended storage and processing capabilities for larger volumes of sensitive data.
Solution Approach 2:
The patent implements a nested structure where the secure operating environment is contained within the trusted execution environment, which in turn is contained within the mobile device operating system. This nested architecture allows layers of security to be combined, with each layer providing additional capabilities while maintaining the security boundaries of inner layers.
2Adaptability or versatility
If security-sensitive applications are installed to handle more security-sensitive tasks, then security functionality is enhanced, but the variation in hardware and operating system resources across devices makes secure deployment difficult
Solution Approach 1:
The secure operating environment is designed to provide universal security services that can adapt to different device configurations. It implements a standardized interface for security-sensitive applications while automatically detecting and utilizing available device resources, allowing the same application to securely deploy across diverse hardware and operating system environments.
Solution Approach 2:
The secure operating environment dynamically adapts to the device's available resources by detecting hardware capabilities and configuring security services accordingly. This dynamic behavior allows the system to optimize security functionality for each specific device while maintaining consistent security guarantees across different platforms.
3Adaptability or versatility
If the least common denominator of security features is used to ensure compatibility across devices, then broad device support is achieved, but security capabilities are reduced
Solution Approach 1:
The secure operating environment changes its operational parameters based on the device's capabilities. It detects available security features and adjusts its service configuration to utilize the highest level of security supported by the device, rather than defaulting to the lowest common denominator. This allows each device to operate at its optimal security level while maintaining compatibility.
Data Source
AI summary
The presenting invention relates to techniques for implementing a secure operating environment for the execution of applications on a computing devices (e.g., a mobile phone). In The secure operating environment may provide a trusted environment with dedicated computing resources to manage security and integrity of processing and data for the applications. The applications may be provided with a variety of security services and/or functions to meet different levels of security demanded by an application. The secure operating environment may include a security engine that enumerates and/or determines the security capabilities of the secure operating environment and the computing device, e.g., the hardware, the software, and/or the firmware of the computing device. The security engine may provide security services desired by applications by choosing from the security capabilities that are supported by the secure operating environment and the computing device.


