Trusted Execution Environment for Enterprise App Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in providing a secure execution environment for enterprise applications on personal devices without modifying the operating system, leading to compatibility issues and vulnerabilities due to shared execution environments.
Innovation Solution
A trusted execution environment is implemented on unmodified off-the-shelf operating systems, using a keystore application to manage communication associations and encryption keys, allowing secure execution of enterprise applications alongside other apps, while preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a modified or custom operating system is used to provide a secure execution environment for enterprise applications, then security and isolation are improved, but device complexity and deployment difficulty increase
Solution Approach 1:
The patent segments the execution environment into a trusted application space and untrusted application space within the same operating system. The trusted space is further divided into secure containers for different enterprise applications. This segmentation allows security isolation without requiring a completely custom operating system, resolving the contradiction between security and device complexity.
Solution Approach 2:
The patent introduces an intermediary trusted execution environment that mediates between enterprise applications and the underlying operating system. This intermediary layer provides security and isolation functions without requiring modification of the base operating system, thus improving security while maintaining compatibility with standard OS implementations.
2Reliability
If a custom trusted operating system is deployed to ensure secure execution, then security isolation is improved, but compatibility with standard applications and deployment logistics deteriorate
Solution Approach 1:
The patent creates a universal trusted execution environment that can run multiple enterprise applications simultaneously while maintaining security isolation. The same trusted execution infrastructure supports various application types and operating systems, providing both security isolation and broad compatibility without requiring separate custom OS deployments for each application.
Solution Approach 2:
The patent uses virtualization to create copies of the trusted execution environment for different applications. Each enterprise application receives a isolated copy of the secure execution space, allowing standard applications to run on the underlying OS while enterprise applications enjoy secure isolation. This approach maintains compatibility with standard applications while providing necessary security.
3Ease of operation
If enterprise applications run in a shared execution environment with personal applications, then ease of operation is improved, but security and vulnerability resistance worsen
Solution Approach 1:
The patent applies local quality by providing different execution environments for different application types. Personal applications run in the standard untrusted environment while enterprise applications run in the isolated trusted environment. This allows ease of operation for personal apps while maintaining security for enterprise apps, resolving the contradiction between ease of operation and security.
Data Source
AI summary
A trusted execution environment on a computing device within an enterprise, whether owned by the enterprise or the employee/user, allows invocation of trusted enterprise applications without hindering external or non-enterprise apps from running on the same computing device. Each of the trusted apps can interact with other trusted apps on the same enterprise computing device in a trusted manner such that other apps or untrusted network connections are prevented for access to the trusted apps. The computing device, however, also executes non enterprise applications which operate independently of the enterprise apps in the same address space using the same unmodified operating system as the enterprise apps on the computing device. The trusted execution environment therefore restricts interprocess communication to be only within the set of enterprise apps and also permits unimpeded operation of other apps under the same OTS (off the shelf) operating system.


