Operating Environment Partitioning for Group Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Malicious third-parties often gain access to communication hardware and resources of mobile computing devices by breaching LTE and/or WiFi resources, which are typically under the control of a single computer operating environment, posing a risk to input devices like cameras and microphones.

Innovation Solution

The secure and normal operating environments of group communication devices are partitioned via a trust partition, using a System-on-Chip (SoC) or a hypervisor to segregate secure resources from normal resources, ensuring that secure resources, such as microphones and cameras, are maintained separately from LTE and WiFi communication resources.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single operating environment controls both communication resources (LTE/WiFi) and secure resources (microphone/camera), then device complexity is reduced and ease of operation is improved, but security is compromised as malicious third-parties can breach communication resources to access secure resources

Engineering Contradiction:
ImprovesecurityVSAvoidoperating environment structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the operating environment into separate secure and normal environments, with each controlling specific resources. The secure operating environment controls secure resources (microphone, camera, speaker) while the normal operating environment controls communication resources (LTE, WiFi). This segmentation prevents malicious access to secure resources through communication resources, resolving the security vulnerability while maintaining manageable complexity through clear environmental boundaries.

Inventive Principle:
Principle #1Segmentation

2Reliability

If secure resources are segregated from normal resources via trust partition, then security against malicious access is improved, but device complexity increases due to additional partitioning mechanisms

Engineering Contradiction:
ImprovesecurityVSAvoidpartitioning structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements segmentation by creating distinct secure and normal operating environments with separate resource control. The trust partition mechanism enforces boundary enforcement between these environments, ensuring that breaches in the normal environment cannot compromise the secure environment. This segmentation approach directly addresses the security improvement while the modular trust partition design manages the complexity through standardized interface definitions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trust partition acts as an intermediary layer between the secure and normal operating environments. It mediates resource access requests and enforces security policies, allowing the system to maintain security isolation while providing controlled interoperability. This intermediary mechanism resolves the contradiction by adding a managed layer of complexity that enables secure resource protection without requiring complete system redesign.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If all resources are controlled by one operating system, then ease of operation and resource management are improved, but vulnerability to malicious attacks increases as attack points like LTE and WiFi can compromise input devices

Engineering Contradiction:
Improveresource managementVSAvoidmalicious access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments resource control authority between two operating environments: the normal operating environment manages communication resources (LTE, WiFi) while the secure operating environment manages secure resources (microphone, camera, speaker). This segmentation prevents malicious access to secure resources through communication resources, as each environment is confined to its designated resource set. The segmentation maintains ease of operation within each environment while eliminating the harmful factor of cross-resource vulnerability.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10887290B2Operating environment partitioning for securing group communication device resources
Publication Date: 2021.01.05 ORION LABS TECH LLC
  • US10887290B2 patent drawing
  • US10887290B2 patent drawing
  • US10887290B2 patent drawing

AI summary

The present disclosure is directed to systems, methods and devices for securing communication resources of group communication devices. Secure resources of a group communication computing device may be maintained in a secure operating environment of the group communication computing device, which is separate from a normal operating environment of the group communication computing device, via a trust partition comprising one or both of an SoC trust partition and a hypervisor. The secure operating environment may comprise input resources including a microphone, a camera, audio encoding and decoding engines, audio encryption and decryption engines, and a secure operating system. The normal operating environment may comprise resources including LTE and WiFi communication resources, transport layer security layer resources, and an operating system.