Trusted Security Zone Extension for Cellular Modem Input Forwarding

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Confidential communications over networks are vulnerable to security threats due to infiltration by malware, which can capture sensitive information and transmit it without being detected, as existing technologies do not effectively establish a trusted security zone on untrusted computers.

Innovation Solution

A cellular wireless modem with a trusted security zone is coupled to an intelligent appliance, installing a trusted security zone extension application that executes at a privileged level, blocking access to input devices and forwarding inputs to the modem for secure transmission, thereby creating a trusted communication path.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a cellular wireless modem with trusted security zone is coupled to an intelligent appliance and executes a trusted security zone extension application at ring 0 level, then security and confidentiality of communications are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments the communication path into a trusted security zone extension application running at ring 0 level on the intelligent appliance and a cellular wireless modem with trusted security zone. This segmentation isolates security-critical functions in a protected environment while allowing the rest of the system to operate normally, resolving the contradiction by improving security through structural division rather than complicating the entire device.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted security zone extension application acts as an intermediary between the user interface input device and the cellular wireless modem. It mediates input capture at the privileged ring 0 level, blocking access by untrusted applications while forwarding inputs securely to the modem. This intermediary approach improves security without requiring complete redesign of the device architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If the trusted security zone extension application blocks access to the user interface input device by applications executing above ring 0 level, then protection from malware is improved, but ease of operation deteriorates

Engineering Contradiction:
Improveprotection from malwareVSAvoidease of operation
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted security zone extension application serves as an intermediary that sits between malicious applications and the user interface input device. It blocks malware from capturing inputs while maintaining legitimate functionality by forwarding authorized inputs to the cellular wireless modem. This resolves the contradiction by providing protection without completely blocking user interaction.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies different access qualities to different applications: untrusted applications above ring 0 level are blocked from accessing the input device, while the trusted security zone extension application at ring 0 level maintains full access. This local differentiation of access rights improves protection from malware while preserving ease of operation for authorized functions.

Inventive Principle:
Principle #3Local quality

3Reliability

If input forwarding application is provisioned on the intelligent appliance to forward inputs to the cellular wireless modem, then confidentiality of information transmission is improved, but device complexity increases

Engineering Contradiction:
ImproveconfidentialityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The input forwarding function is segmented into a separate trusted security zone extension application running at ring 0 level, distinct from untrusted applications. This segmentation ensures that input forwarding operates in a protected environment, improving confidentiality while managing device complexity through functional separation rather than monolithic design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted security zone extension application automatically provisions itself on the intelligent appliance and self-manages the input forwarding operation. By making the security-critical components self-provisioning and self-managing, the system improves confidentiality without requiring complex external configuration or management infrastructure.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9210576B1Extended trusted security zone radio modem
Publication Date: 2015.12.08 T MOBILE INNOVATIONS LLC
  • US9210576B1 patent drawing
  • US9210576B1 patent drawing
  • US9210576B1 patent drawing

AI summary

A cellular wireless modem. The cellular wireless modem comprises a cellular radio transceiver, a short range communication interface, a processor, wherein the processor comprises a trusted security zone, a memory, wherein the memory stores an input forwarding application, and a trusted security zone extension application stored in the memory. When executed by the processor, the extension application provisions the input forwarding application to an intelligent appliance via the short range communication interface, receives input from the input forwarding application executing on the intelligent appliance via the short range communication interface, and transmits a message based on the input via the cellular radio transceiver.