Trusted Mobile Platform for Data Exfiltration Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile devices are vulnerable to data exfiltration due to defects and vulnerabilities in their platforms, which can render security features like remote wipe, location tracking, and encryption ineffective, especially with the increasing trend of BYOD, where sensitive corporate data is accessed through personal devices.
Innovation Solution
A data exfiltration prevention system that migrates applications from mobile devices to a secure computing platform within a distributed processing environment, using a Trusted Mobile Platform (TMP) with Trusted Mobile Instances (TMI) and Trusted Mobile Runtime (TMR) to execute applications within a secure perimeter, providing a tightly controlled environment with restricted network access and encrypted remote display technology.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If mobile devices implement security features like remote wipe, location tracking, and encryption, then data protection is improved, but these features can be rendered ineffective by vulnerabilities in the mobile platform that allow arbitrary code execution
Solution Approach 1:
The system segments the application execution environment from the mobile operating system by introducing a trusted computing platform that runs applications in isolated containers. This segmentation prevents malicious code from compromising the entire device while maintaining security features like encryption and remote wipe in the trusted environment.
Solution Approach 2:
A trusted computing platform acts as an intermediary between the mobile device and external resources. This intermediary layer enforces security policies and controls access to sensitive operations, preventing direct exploitation of mobile platform vulnerabilities while maintaining the functionality of security features.
2Adaptability or versatility
If applications are allowed to access sensitive data and resources on mobile devices, then application functionality is improved, but data exfiltration risk increases due to platform vulnerabilities
Solution Approach 1:
The system divides the computing environment into untrusted mobile device components and trusted computing platform components. Applications run in isolated containers on the trusted platform with controlled access to resources, enabling full functionality while preventing data exfiltration through the mobile device's vulnerable software stack.
Solution Approach 2:
Different security properties are applied to different parts of the system. The trusted computing platform provides strong security guarantees for data processing, while the mobile device provides convenient user interface and sensor access. This local differentiation of security qualities allows functionality while preventing exfiltration.
3Reliability
If mobile devices use software-based security solutions like containers and wrappers, then access control is improved, but these solutions can be attacked through the software stack and cannot protect data while being processed
Solution Approach 1:
A trusted computing platform serves as an intermediary that implements hardware-backed security for data processing. This intermediary provides strong access control through hardware-enforced isolation, protecting data while being processed without requiring complex software-based containers and wrappers.
Solution Approach 2:
The system replaces software-based security mechanisms (containers, wrappers) with hardware-based security features in the trusted computing platform. This substitution provides more reliable access control with less complexity, as hardware enforcement cannot be compromised through software vulnerabilities.
4Reliability
If network layer solutions are used to intercept and enforce policies on mobile traffic, then known application traffic protection is improved, but data transferred over unknown methods or systems cannot be protected
Solution Approach 1:
Security policies are established and enforced in advance within the trusted computing platform before data leaves the secure environment. This preliminary action ensures that all data, regardless of the transmission method or destination, is protected by the time it exits the controlled environment, covering both known and unknown communication channels.
Solution Approach 2:
The trusted computing platform acts as an intermediary that controls all data exfiltration paths. By positioning this intermediary at the source of data flow rather than intercepting traffic on the network, the system can enforce security policies on all communication methods, including previously unknown channels.
Data Source
AI summary
Technology is disclosed for preventing an exfiltration of a data associated with an application executing on a mobile device. The technology can migrate the application from a computing platform of the mobile device to a secure computing platform, where the secure computing platform is independent of the computing platform of the mobile device. The technology can further receive a request to access the application through the mobile device, execute the requested application on the secure computing platform, and provide an access to the requested application executing on the secure computing platform through the mobile device. The access provided through the mobile device includes displaying information on the mobile device, where the displayed information includes data generated by the execution of requested application on the secure platform.


