Trusted Mobile Platform for Data Exfiltration Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices are vulnerable to data exfiltration due to defects and vulnerabilities in their platforms, which can render security features like remote wipe, location tracking, and encryption ineffective, especially with the increasing trend of BYOD, where sensitive corporate data is accessed through personal devices.

Innovation Solution

A data exfiltration prevention system that migrates applications from mobile devices to a secure computing platform within a distributed processing environment, using a Trusted Mobile Platform (TMP) with Trusted Mobile Instances (TMI) and Trusted Mobile Runtime (TMR) to execute applications within a secure perimeter, providing a tightly controlled environment with restricted network access and encrypted remote display technology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If mobile devices implement security features like remote wipe, location tracking, and encryption, then data protection is improved, but these features can be rendered ineffective by vulnerabilities in the mobile platform that allow arbitrary code execution

Engineering Contradiction:
Improvedata protectionVSAvoidplatform vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the application execution environment from the mobile operating system by introducing a trusted computing platform that runs applications in isolated containers. This segmentation prevents malicious code from compromising the entire device while maintaining security features like encryption and remote wipe in the trusted environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted computing platform acts as an intermediary between the mobile device and external resources. This intermediary layer enforces security policies and controls access to sensitive operations, preventing direct exploitation of mobile platform vulnerabilities while maintaining the functionality of security features.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If applications are allowed to access sensitive data and resources on mobile devices, then application functionality is improved, but data exfiltration risk increases due to platform vulnerabilities

Engineering Contradiction:
Improveapplication functionalityVSAvoiddata exfiltration
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system divides the computing environment into untrusted mobile device components and trusted computing platform components. Applications run in isolated containers on the trusted platform with controlled access to resources, enabling full functionality while preventing data exfiltration through the mobile device's vulnerable software stack.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Different security properties are applied to different parts of the system. The trusted computing platform provides strong security guarantees for data processing, while the mobile device provides convenient user interface and sensor access. This local differentiation of security qualities allows functionality while preventing exfiltration.

Inventive Principle:
Principle #3Local quality

3Reliability

If mobile devices use software-based security solutions like containers and wrappers, then access control is improved, but these solutions can be attacked through the software stack and cannot protect data while being processed

Engineering Contradiction:
Improveaccess controlVSAvoidsecurity architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A trusted computing platform serves as an intermediary that implements hardware-backed security for data processing. This intermediary provides strong access control through hardware-enforced isolation, protecting data while being processed without requiring complex software-based containers and wrappers.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces software-based security mechanisms (containers, wrappers) with hardware-based security features in the trusted computing platform. This substitution provides more reliable access control with less complexity, as hardware enforcement cannot be compromised through software vulnerabilities.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

4Reliability

If network layer solutions are used to intercept and enforce policies on mobile traffic, then known application traffic protection is improved, but data transferred over unknown methods or systems cannot be protected

Engineering Contradiction:
Improvenetwork traffic protectionVSAvoidprotection coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Security policies are established and enforced in advance within the trusted computing platform before data leaves the secure environment. This preliminary action ensures that all data, regardless of the transmission method or destination, is protected by the time it exits the controlled environment, covering both known and unknown communication channels.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted computing platform acts as an intermediary that controls all data exfiltration paths. By positioning this intermediary at the source of data flow rather than intercepting traffic on the network, the system can enforce security policies on all communication methods, including previously unknown channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9483646B2Data exfiltration prevention from mobile platforms
Publication Date: 2016.11.01 GEN DIGITAL INC
  • US9483646B2 patent drawing
  • US9483646B2 patent drawing
  • US9483646B2 patent drawing

AI summary

Technology is disclosed for preventing an exfiltration of a data associated with an application executing on a mobile device. The technology can migrate the application from a computing platform of the mobile device to a secure computing platform, where the secure computing platform is independent of the computing platform of the mobile device. The technology can further receive a request to access the application through the mobile device, execute the requested application on the secure computing platform, and provide an access to the requested application executing on the secure computing platform through the mobile device. The access provided through the mobile device includes displaying information on the mobile device, where the displayed information includes data generated by the execution of requested application on the secure platform.