Terminal Data Sharing via Secure Channel and Security Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing terminal technologies face challenges in enabling secure communication between security and standard systems while maintaining data security, as direct communication compromises the security of the security system.

Innovation Solution

A data sharing method that sets a secure data channel between systems, performs security detection on shared data, and only allows secure data to be shared through this channel, using public storage areas or system broadcasts, and optionally encrypts data to ensure security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the security system and standard system are isolated from each other, then data security in the security system is improved, but user convenience deteriorates

Engineering Contradiction:
Improvedata securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the terminal into two isolated systems (security system and standard system) and creates a controlled interface between them. Data is segmented into security data and non-security data, with only non-security data allowed to pass through the shared memory area, maintaining isolation while enabling necessary communication.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A shared memory area acts as an intermediary between the security system and standard system. This intermediary enables data sharing while maintaining security boundaries, as it is configured to accept only non-security data from the standard system and make it available to the security system without compromising security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If communication between security system and standard system is implemented, then user convenience is improved, but data security in the security system deteriorates

Engineering Contradiction:
Improvedata sharing capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The shared memory area has different access qualities for different systems. The standard system can write non-security data to the shared memory, while the security system can read from it. Security data is excluded from this shared area, creating local quality differences that maintain security while enabling communication.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The shared memory serves as a secure intermediary that filters data types. It accepts non-security data from the standard system and provides it to the security system, while preventing security data from being exposed to the standard system, thus maintaining security boundaries during communication.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If simple communication permission is granted to standard system accessing security system, then ease of operation is improved, but data security deteriorates

Engineering Contradiction:
Improvecommunication easeVSAvoiddata leakage risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary classification of data into security and non-security categories before sharing. The shared memory is pre-configured to only accept non-security data from the standard system, preventing security data from being accidentally or maliciously exposed before the sharing operation occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The shared memory acts as a security intermediary that enforces data type restrictions. It mediates between the standard system and security system by accepting only non-security data for sharing, thereby preventing data leakage while maintaining ease of operation for legitimate data sharing needs.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3239849B1Data sharing method for terminal, data sharing apparatus and terminal
Publication Date: 2020.12.23 YULONG COMPUTER TELECOMM SCI (SHENZHEN) CO LTD
  • EP3239849B1 patent drawingFigure 1
  • EP3239849B1 patent drawingFigure 2
  • EP3239849B1 patent drawingFigure 3

AI summary

The present disclosure provides a data sharing method for a terminal, a data sharing apparatus and the terminal including a plurality of systems. The data sharing method includes: setting a data channel for communication between each two systems among the plurality of systems; when data needs to be shared between any two systems among the plurality of systems, performing a security detection on data to be shared through a data channel between the any two systems, to determine whether the data to be shared is security data; sharing the data to be shared through the data channel if the data to be shared is detected to be the security data, otherwise prohibiting sharing the data to be shared through the data channel. The present disclosure can realize communication between a security system and an ordinary system under the premise of ensuring that data in the security system has higher security.