Shim Application for Enclave Communication Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile communication devices and personal computers often mix personal and business or educational data, leading to unauthorized access between applications associated with different entities, compromising security and data integrity.
Innovation Solution
Implementing isolation enclaves with dedicated hardware and software resources for each entity, managed by an enclave application, and using a shim application to monitor and filter communications based on policies to enforce security and restrict access between enclaves.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple applications from different entities are installed on a single mobile device, then the device can serve multiple purposes (personal, business, educational), but data security and privacy are compromised due to unauthorized access between applications
Solution Approach 1:
The patent divides the mobile device into separate isolation enclaves, each dedicated to a specific entity (personal, business, educational). Each enclave contains its own applications and data, physically separating them from other entities' data. This segmentation allows the device to serve multiple purposes while maintaining data security through enforced isolation boundaries.
2Productivity
If applications share common hardware resources for efficiency, then device productivity increases, but unauthorized access between applications occurs compromising data integrity
Solution Approach 1:
The patent introduces a shim layer as an intermediary component that sits between applications and the radio interface. This shim monitors and controls all communications, acting as a gatekeeper that permits or blocks data flow based on security policies. It enables controlled sharing of hardware resources while preventing unauthorized access through active monitoring and filtering of communications.
3Device complexity
If a single operating system manages all applications, then system complexity is reduced, but the ability to enforce strict isolation between entities is weakened
Solution Approach 1:
The patent implements a nested architecture where isolation enclaves are created within the existing operating system structure. Each enclave is a nested container that holds applications and data for a specific entity, while the host operating system provides common management functions. This nested approach maintains operational simplicity at the system level while enforcing strict isolation boundaries within each enclave.
Data Source
AI summary
A method comprises receiving, by a shim application of a user equipment (UE), an outbound communication from a first application destined for an external device, prior to transmitting the outbound communication to the external device, determining, by the shim application, whether to forward the outbound communication to the external device, via a radio interface of the UE, based on a first policy, receiving, by the shim application, an inbound communication destined for a second application from the external device, via the radio interface, determining, by the shim application, whether to forward the inbound communication to the second application based on a second policy, receiving, by the shim application, an inter-enclave communication from the first application destined for the second application, and determining, by the shim application, whether to forward the inter-enclave communication to the second application based on the second policy.


