Verified Privacy Mode Sensors Using Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing electronic devices lack secure and verified methods to disable sensors such as microphones and cameras, which can lead to unauthorized activation, compromising privacy and security.

Innovation Solution

A privacy mode control system utilizing a trusted execution environment with hardware interfaces exclusively accessible to it, allowing secure disabling of sensors through a physical switch or privacy devices like plugs and sensor control devices, ensuring verified feedback and protection against unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional sensor disabling facilities are used, then sensors can be disabled, but they are subject to unauthorized circumvention

Engineering Contradiction:
Improvesensor disabling reliabilityVSAvoidprivacy mode control system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the control system into a trusted execution environment (TEE) and a regular operating system. The TEE is isolated and secured, containing the privacy mode control logic, while the regular OS handles normal operations. This segmentation ensures that sensor disabling controls in the TEE cannot be circumvented by unauthorized software in the regular OS, thereby improving reliability without excessively complicating the overall device architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary trusted execution environment that acts as a mediator between the user/privacy controls and the sensor hardware. The TEE verifies and enforces privacy mode settings before allowing sensor access, serving as a security intermediary that prevents unauthorized circumvention while maintaining a manageable system structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If hardware interfaces are made exclusively accessible to trusted execution environment, then security is enhanced, but access control complexity increases

Engineering Contradiction:
Improveprivacy mode securityVSAvoidhardware interface accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent segments hardware interface access into two distinct paths: one exclusively accessible to the trusted execution environment for security-critical operations, and another accessible to the regular operating system for normal operations. This segmentation enhances privacy mode security by isolating critical controls while maintaining ease of operation for non-critical functions.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent creates separate access pathways or interfaces for the TEE and regular OS. Instead of modifying the existing hardware interface to support dual access modes, the system creates a dedicated TEE interface that copies necessary control functions, allowing the TEE to securely manage privacy modes without interfering with normal OS operations.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3333753B1Verified privacy mode devices
Publication Date: 2021.03.24 BLACKBERRY LTD
  • EP3333753B1 patent drawingFigure 1
  • EP3333753B1 patent drawingFigure 2
  • EP3333753B1 patent drawingFigure 3

AI summary

A system and method for a privacy mode are disclosed. A trusted execution environment and general operating system that has restricted access to the trusted execution environment are maintained on a processor. A privacy mode command indicating either one of a first value and a second value is received. A peripheral control interface, which is communicatively coupled to the trusted execution environment and otherwise communicatively isolated from the general operating system, is disabled when the privacy mode enable indicator has the first value and is enabled when the privacy mode enable indicator has the second value. An associated peripheral is disabled from providing signals to processing circuits when the peripheral control interface is in the disabled state and enabled to provide signals to processing circuits when the peripheral control interface is in the enabled state.