Trusted Security Zone Provisioning and Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile communication devices face challenges in securely managing and isolating confidential information and applications due to the risk of malware and unauthorized access, as they often lack robust security measures to segregate and manage multiple trusted security zones effectively.

Innovation Solution

The implementation of a processor with multiple trusted security zones, including a master trusted security zone and subordinate trusted security zones, where the master trusted application can invoke and manage subordinate trusted applications without visibility into their memory spaces or processing, and dynamically allocate resources based on usage reports, ensuring secure execution and access control.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a single trusted security zone is used to store confidential information and execute trusted applications, then the device can maintain a simplified security architecture, but the device lacks the ability to effectively isolate and manage multiple trusted applications, making them vulnerable to malware and unauthorized access

Engineering Contradiction:
Improvesecurity isolationVSAvoidsecurity zone architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted security zone is divided into multiple isolated sub-zones, each capable of storing confidential information and executing trusted applications independently. This segmentation allows different trusted applications to be isolated from each other, preventing malware from compromising the entire security zone while maintaining a relatively simple overall architecture.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multiple trusted security zones are implemented to isolate confidential information and applications, then security isolation and integrity are improved, but the device complexity and difficulty of managing security zones increase

Engineering Contradiction:
Improveapplication isolationVSAvoidzone management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A zone management system acts as an intermediary layer between the multiple trusted security zones and the external environment. This mediator handles the complexity of zone creation, deletion, data transfer, and access control, allowing individual zones to remain simple while providing sophisticated management capabilities at the system level.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If trusted applications are allowed to access shared resources in a trusted security zone, then resource utilization is improved, but the risk of unauthorized access and malware infiltration increases

Engineering Contradiction:
Improveresource utilizationVSAvoidmalware access risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

Each trusted security zone is configured with specific access rights and permissions tailored to its particular needs. Instead of allowing universal access across the entire trusted security zone, each zone has localized access controls that permit only authorized applications to access specific resources, thereby maintaining high resource utilization while preventing malware infiltration through granular permission management.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9811672B2Systems and methods for provisioning and using multiple trusted security zones on an electronic device
Publication Date: 2017.11.07 T MOBILE INNOVATIONS LLC
  • US9811672B2 patent drawing
  • US9811672B2 patent drawing
  • US9811672B2 patent drawing

AI summary

A method of provisioning a subordinate trusted security zone in a processor having a trusted security zone. The method comprises receiving by a master trusted application executing in a master trusted security zone of the processor a request to provision a subordinate trusted security zone in the processor, wherein the request comprises a master trusted security zone key, wherein the request designates the subordinate trusted security zone, and wherein the request defines an independent key. The method further comprises provisioning by the master trusted application the subordinate trusted security zone to be accessible based on the independent key.