Operating Environment Partitioning for Group Communication Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious third-parties often gain access to communication hardware and resources of mobile computing devices by breaching LTE and/or WiFi resources, which are typically under the control of a single computer operating environment, posing a risk to input devices like cameras and microphones.
Innovation Solution
The secure and normal operating environments of group communication devices are partitioned via a trust partition, using a System-on-Chip (SoC) or a hypervisor to segregate secure resources from normal resources, ensuring that secure resources, such as microphones and cameras, are maintained separately from LTE and WiFi communication resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single operating environment controls both communication resources (LTE/WiFi) and secure resources (microphone/camera), then device complexity is reduced and ease of operation is improved, but security is compromised as malicious third-parties can breach communication resources to access secure resources
Solution Approach 1:
The patent divides the operating environment into separate secure and normal environments, with each controlling specific resources. The secure operating environment controls secure resources (microphone, camera, speaker) while the normal operating environment controls communication resources (LTE, WiFi). This segmentation prevents malicious access to secure resources through communication resources, resolving the security vulnerability while maintaining manageable complexity through clear environmental boundaries.
2Reliability
If secure resources are segregated from normal resources via trust partition, then security against malicious access is improved, but device complexity increases due to additional partitioning mechanisms
Solution Approach 1:
The patent implements segmentation by creating distinct secure and normal operating environments with separate resource control. The trust partition mechanism enforces boundary enforcement between these environments, ensuring that breaches in the normal environment cannot compromise the secure environment. This segmentation approach directly addresses the security improvement while the modular trust partition design manages the complexity through standardized interface definitions.
Solution Approach 2:
The trust partition acts as an intermediary layer between the secure and normal operating environments. It mediates resource access requests and enforces security policies, allowing the system to maintain security isolation while providing controlled interoperability. This intermediary mechanism resolves the contradiction by adding a managed layer of complexity that enables secure resource protection without requiring complete system redesign.
3Ease of operation
If all resources are controlled by one operating system, then ease of operation and resource management are improved, but vulnerability to malicious attacks increases as attack points like LTE and WiFi can compromise input devices
Solution Approach 1:
The patent segments resource control authority between two operating environments: the normal operating environment manages communication resources (LTE, WiFi) while the secure operating environment manages secure resources (microphone, camera, speaker). This segmentation prevents malicious access to secure resources through communication resources, as each environment is confined to its designated resource set. The segmentation maintains ease of operation within each environment while eliminating the harmful factor of cross-resource vulnerability.
Data Source
AI summary
The present disclosure is directed to systems, methods and devices for securing communication resources of group communication devices. Secure resources of a group communication computing device may be maintained in a secure operating environment of the group communication computing device, which is separate from a normal operating environment of the group communication computing device, via a trust partition comprising one or both of an SoC trust partition and a hypervisor. The secure operating environment may comprise input resources including a microphone, a camera, audio encoding and decoding engines, audio encryption and decryption engines, and a secure operating system. The normal operating environment may comprise resources including LTE and WiFi communication resources, transport layer security layer resources, and an operating system.


