Shim Application for Enclave Communication Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices and personal computers often mix personal and business or educational data, leading to unauthorized access between applications associated with different entities, compromising security and data integrity.

Innovation Solution

Implementing isolation enclaves with dedicated hardware and software resources for each entity, managed by an enclave application, and using a shim application to monitor and filter communications based on policies to enforce security and restrict access between enclaves.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple applications from different entities are installed on a single mobile device, then the device can serve multiple purposes (personal, business, educational), but data security and privacy are compromised due to unauthorized access between applications

Engineering Contradiction:
Improvemulti-purpose usageVSAvoiddata security
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent divides the mobile device into separate isolation enclaves, each dedicated to a specific entity (personal, business, educational). Each enclave contains its own applications and data, physically separating them from other entities' data. This segmentation allows the device to serve multiple purposes while maintaining data security through enforced isolation boundaries.

Inventive Principle:
Principle #1Segmentation

2Productivity

If applications share common hardware resources for efficiency, then device productivity increases, but unauthorized access between applications occurs compromising data integrity

Engineering Contradiction:
Improvedevice efficiencyVSAvoiddata integrity
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent introduces a shim layer as an intermediary component that sits between applications and the radio interface. This shim monitors and controls all communications, acting as a gatekeeper that permits or blocks data flow based on security policies. It enables controlled sharing of hardware resources while preventing unauthorized access through active monitoring and filtering of communications.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If a single operating system manages all applications, then system complexity is reduced, but the ability to enforce strict isolation between entities is weakened

Engineering Contradiction:
Improvesystem structureVSAvoidisolation enforcement
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent implements a nested architecture where isolation enclaves are created within the existing operating system structure. Each enclave is a nested container that holds applications and data for a specific entity, while the host operating system provides common management functions. This nested approach maintains operational simplicity at the system level while enforcing strict isolation boundaries within each enclave.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS12052656B2Shim application for enclave separation
Publication Date: 2024.07.30 T MOBILE INNOVATIONS LLC
  • US12052656B2 patent drawing
  • US12052656B2 patent drawing
  • US12052656B2 patent drawing

AI summary

A method comprises receiving, by a shim application of a user equipment (UE), an outbound communication from a first application destined for an external device, prior to transmitting the outbound communication to the external device, determining, by the shim application, whether to forward the outbound communication to the external device, via a radio interface of the UE, based on a first policy, receiving, by the shim application, an inbound communication destined for a second application from the external device, via the radio interface, determining, by the shim application, whether to forward the inbound communication to the second application based on a second policy, receiving, by the shim application, an inter-enclave communication from the first application destined for the second application, and determining, by the shim application, whether to forward the inter-enclave communication to the second application based on the second policy.