Segmented Data Zone Indexing for Secure Multi-Consumer Service Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for providing multiple electronic services on mobile terminals are costly and resource-intensive, as they require multiple security domains and keys for each consumer, leading to increased resource usage and performance reduction.

Innovation Solution

A method for partitioned provision of electronic services on an electronic terminal, where a security domain is implemented to index data zones into sub-zones, allowing only specific sub-zones to be accessed by consumers through a data access key, reducing the need for multiple security domains and keys.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a separate security domain is installed for each consumer, then data confidentiality is guaranteed, but terminal resources are multiplied and costs increase

Engineering Contradiction:
Improvedata confidentialityVSAvoidterminal resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The data zone within the security domain is segmented into multiple sub-zones, each associated with a specific consumer. The indexing mechanism divides the data zone into identifiable sub-zones that can be selectively accessed, allowing one security domain to serve multiple consumers without requiring separate security domains for each consumer.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A single security domain is designed to serve multiple consumers simultaneously by implementing an indexing mechanism that routes access requests to appropriate sub-zones. This makes the security domain universal, capable of handling data for multiple consumers without requiring separate instances for each consumer.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple security domains are installed to serve multiple consumers, then consumer data segregation is improved, but device complexity increases

Engineering Contradiction:
Improvedata segregationVSAvoidsecurity domain management
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The data zone is segmented into sub-zones with indexing information stored in a table. Each sub-zone corresponds to a specific consumer, and the indexing table provides a mapping mechanism that simplifies access control without requiring multiple separate security domains.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

An indexing mechanism acts as an intermediary between access requests and the actual data sub-zones. The index table serves as a mediator that translates consumer identifiers into appropriate sub-zone access permissions, simplifying the management of data segregation.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate security domains are provisioned for each service and consumer, then service partitioning is improved, but manufacturing cost increases

Engineering Contradiction:
Improveservice partitioningVSAvoidterminal manufacturing cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

Multiple consumer data spaces are merged into a single security domain's data zone, organized through sub-zones and an indexing table. This consolidation reduces the number of security domains needed, thereby reducing manufacturing costs while maintaining service partitioning through the indexing mechanism.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

A single security domain is designed to be multi-functional, serving multiple consumers and services simultaneously through its indexing mechanism. This universality eliminates the need to manufacture separate security domains for each service-consumer combination, reducing overall manufacturing costs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP1909462B1Method of compartmentalised provision of an electronic service
Publication Date: 2010.08.11 SOC FR DU RADIOTELEPHONE SFR
  • EP1909462B1 patent drawingFigure 1
  • EP1909462B1 patent drawingFigure 2
  • EP1909462B1 patent drawingFigure 3~4

AI summary

The method involves indexing, in a security domain, a data area which reaches an electronic service on an electronic terminal in a subarea to guarantee that a request (302) of a customer such as baker, from a set of customers reads/writes/modifies only one preset subarea associated to the customer who transmits the request either directly or via the service. The data area is indexed by using a third party server, and the security domain is implemented via a Java platform.