Terminal Data Sharing via Secure Channel and Security Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing terminal technologies face challenges in enabling secure communication between security and standard systems while maintaining data security, as direct communication compromises the security of the security system.
Innovation Solution
A data sharing method that sets a secure data channel between systems, performs security detection on shared data, and only allows secure data to be shared through this channel, using public storage areas or system broadcasts, and optionally encrypts data to ensure security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the security system and standard system are isolated from each other, then data security in the security system is improved, but user convenience deteriorates
Solution Approach 1:
The patent divides the terminal into two isolated systems (security system and standard system) and creates a controlled interface between them. Data is segmented into security data and non-security data, with only non-security data allowed to pass through the shared memory area, maintaining isolation while enabling necessary communication.
Solution Approach 2:
A shared memory area acts as an intermediary between the security system and standard system. This intermediary enables data sharing while maintaining security boundaries, as it is configured to accept only non-security data from the standard system and make it available to the security system without compromising security.
2Ease of operation
If communication between security system and standard system is implemented, then user convenience is improved, but data security in the security system deteriorates
Solution Approach 1:
The shared memory area has different access qualities for different systems. The standard system can write non-security data to the shared memory, while the security system can read from it. Security data is excluded from this shared area, creating local quality differences that maintain security while enabling communication.
Solution Approach 2:
The shared memory serves as a secure intermediary that filters data types. It accepts non-security data from the standard system and provides it to the security system, while preventing security data from being exposed to the standard system, thus maintaining security boundaries during communication.
3Ease of operation
If simple communication permission is granted to standard system accessing security system, then ease of operation is improved, but data security deteriorates
Solution Approach 1:
The system performs preliminary classification of data into security and non-security categories before sharing. The shared memory is pre-configured to only accept non-security data from the standard system, preventing security data from being accidentally or maliciously exposed before the sharing operation occurs.
Solution Approach 2:
The shared memory acts as a security intermediary that enforces data type restrictions. It mediates between the standard system and security system by accepting only non-security data for sharing, thereby preventing data leakage while maintaining ease of operation for legitimate data sharing needs.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure provides a data sharing method for a terminal, a data sharing apparatus and the terminal including a plurality of systems. The data sharing method includes: setting a data channel for communication between each two systems among the plurality of systems; when data needs to be shared between any two systems among the plurality of systems, performing a security detection on data to be shared through a data channel between the any two systems, to determine whether the data to be shared is security data; sharing the data to be shared through the data channel if the data to be shared is detected to be the security data, otherwise prohibiting sharing the data to be shared through the data channel. The present disclosure can realize communication between a security system and an ordinary system under the premise of ensuring that data in the security system has higher security.