Improving Mobile Device Security Using A Secure Execution Context
Abstract
A device includes a secure execution context that is segregated from an operating system of the device. A security application executing in the operating system interfaces with the secure execution context to obtain verified data. The secure execution context may verify that operating system files are free of malware, obtain sensor readings that may be cryptographically signed, verify functioning of a baseband processor, and verify other aspects of the function and security of the device. The verified data may be used for various purposes such as verifying location of the device, training a machine learning model, and the like.
Claims
exact text as granted — not AI-modified1 . A method comprising:
providing, via a processor, a secure execution context representing an isolated and secure operating system on a device, the device including one or more sensors; providing an operating system representing a software supporting device functions and excluding the secure execution context; and receiving, by the secure execution context, first data representing information about a state of the device, the state of the device including the physical environment of the device, the first data being a first reading from the one or more sensors obtained within the secure execution context.
2 . The method of claim 1 , further comprising:
providing a security application executing within the operating system, the security application defining an interface to the secure execution context; and requesting, by the security application, the first data.
3 . The method of claim 1 , further comprising cryptographically signing, by the secure execution context, the first reading using a hardware key of the device.
4 . The method of claim 1 , wherein the one or more sensors include a camera and the first reading is pixel data obtained from the camera.
5 . The method of claim 1 , wherein the one or more sensors include a global positioning system (GPS) receiver and the first reading is a location obtained from the GPS receiver.
6 . The method of claim 5 , further comprising:
receiving, by the processor, a region definition; evaluating, by the processor, whether the location is within the region definition; and returning, by the processor, a result of the evaluating.
7 . The method of claim 1 , wherein the one or more sensors include an accelerometer and the first reading is an accelerometer reading obtained from the accelerometer.
8 . The method of claim 1 , further comprising:
performing, by the processor, a biometric assessment of a user of the device using the first reading; authenticating the user based on the biometric assessment; and in response to authenticating the user based on the biometric assessment, granting access to the user to an application on the device.
9 . The method of claim 8 , wherein one or more sensors include an accelerometer and the biometric assessment include assessing one or more of a gait of the user, tremors of the device, and orientation of the device.
10 . The method of claim 8 , wherein the one or more sensors include a touch screen and the biometric assessment includes assessing touch behavior of the user including one or more of placement, finger size, location, trajectory, and typing behavior.
11 . The method of claim 8 , wherein the one or more sensors include a radio frequency (RF) sensor and the biometric assessment includes assessing non-touching behaviors around the device.
12 . The method of claim 11 , wherein the biometric assessment includes assessing signals received from one or more other devices adjacent the device using the RF sensor.
13 . The method of claim 12 , wherein the signals received from the one or more other devices comprise signals indicating one or more of speech, tapping, and sensor readings detected by the one or more other devices.
14 . The method of claim 8 , wherein authenticating the user based on the biometric assessment comprises determining that the biometric assessment corresponds to an authenticated behavior model.
15 . A mobile device comprising:
one or more processing devices defining a secure execution context representing an isolated and secure operating system on a device, the device including one or more sensors; and one or more memory devices coupled to the one or more processing devices, the one or more memory devices storing executable code that, when executed by the one or more processing devices, causes the one or more processing devices to: execute an operating system representing a software supporting device functions and excluding the secure execution context; receive, by the secure execution context, first data representing information about behavior of a user of the device, the first data being a first reading from the one or more sensors obtained within the secure execution context; obtain biometric data from the first data; evaluate the biometric data with respect to an authenticated behavior model in the secure execution context; and if the biometric data corresponds to the authenticated behavior model, grant the user access to a resource on the mobile device.
16 . The mobile device of claim 15 , wherein the one or more sensors include one or more of an accelerometer, a camera, a microphone, radio frequency (RF) receiver, and a touch screen.
17 . The mobile device of claim 16 , wherein one or more sensors include the accelerometer and the biometric data includes one or more of a gait of the user, tremors of the device, and orientation of the device.
18 . The mobile device of claim 16 , wherein one or more sensors include the touch screen and the biometric data includes touch behavior of the user including one or more of placement, finger size, location, trajectory, and typing behavior.
19 . The mobile device of claim 16 , wherein the one or more sensors include the RF sensor and the biometric data includes one or both of (a) non-touching behaviors around the mobile device and (b) signals received from one or more other devices adjacent the mobile device using the RF sensor.
20 . The mobile device of claim 19 , wherein the signals received from the one or more other devices comprise signals indicating one or more of speech, tapping, and sensor readings detected by the one or more other devices.Join the waitlist — get patent alerts
Track US2022239692A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.