MOBILE DEVICE WITH SECURE PRIVATE MEMORY
A mobile device can detect an idle state and, in response, initiate an access monitoring function to covertly monitor activity involving a human interaction with the mobile device. The covert monitoring is undetectable by a user of the mobile device. The mobile device can then detect a human interaction with the mobile device and, in response, cause the mobile device to covertly capture and log one or more human interactions with the mobile device. An authorized user of the mobile device is enabled to review the log of human interactions with the mobile device.
1 . A mobile device comprising:
a non-private memory in which is stored:
a first mobile application, and
a driver program that controls operations of a radio access technology (RAT) device, a positioning, navigation, or timing (PNT) device, an input/output (I/O) device, or a communications port of the mobile device;
a private memory in which is stored:
a copy of the first mobile application,
a copy of the driver program, and
a second mobile application that is stored in the private memory only; and
a processor that is configured to enable switching between a private mode, in which access to the second mobile application is permitted, and a non-private mode, in which access to the second mobile application is forbidden, based on an outcome of a multifactor authentication (MFA) procedure.
2 . The mobile device of claim 1 , wherein the processor is able to switch between the private mode and the non-private mode as part of, or in response to, a reboot procedure.
3 . The mobile device of claim 1 , wherein the processor is further configured to:
cause display of an interface on which are presented a first graphical element for rebooting in the private mode and a second graphical element for rebooting in the non-private mode;
receiving input that is indicative of an interaction with the first graphical element;
initiate the MFA procedure; and
initiate a reboot procedure, with the mobile device rebooting in the private mode, in response to a determination that the MFA procedure was successfully completed.
4 . The mobile device of claim 1 , wherein the processor is further configured to:
cause display of an interface on which are presented a first graphical element for rebooting in the private mode and a second graphical element for rebooting in the non-private mode;
receiving input that is indicative of an interaction with the second graphical element; and
initiate a reboot procedure, with the mobile device rebooting in the non-private mode.
5 . The mobile device of claim 1 , wherein as part of the MFA procedure, a passcode entered by a user is verified.
6 . The mobile device of claim 1 , wherein as part of the MFA procedure, a biometric of a user is verified.
7 . The mobile device of claim 1 , wherein as part of the MFA procedure, a near-field communication (NFC) identifier that is detected by the mobile device and emitted by an NFC chip located proximate to the mobile device is verified.
8 . A computing device comprising:
a non-private memory that is configured to store at least one computer program;
a private memory that is configured to store copies of the at least one computer program and a given computer program that is only stored in the private memory; and
a processor that is configured to:
cause display of an interface on which are presented
(i) a first graphical element that corresponds to a private mode, in which access to the given computer program is permitted, and
(ii) a second graphical element that corresponds to a non-private mode, in which access to the given computer program is forbidden,
receive input that is indicative of a selection of either the first graphical element or the second graphical element, and
initiate a reboot procedure, with the computing device rebooting in either the private mode or the non-private mode based on the input.
9 . The computing device of claim 8 , further comprising:
a communications channel that is configured to copy data between the private memory and the non-private memory,
wherein the communications channel is disabled when the computing device is in the non-private mode, and
wherein the communications channel is enabled when the computing device is in the private mode.
10 . The computing device of claim 8 , wherein the processor is further configured to:
initiate a multifactor authentication (MFA) procedure in response to a determination that the input is indicative of a selection of the first graphical element.
11 . The computing device of claim 8 , wherein the processor is further configured to:
receive second input that is indicative of a selection of one of the at least one computer program stored in the non-private memory, and
remove the selected computer program from the non-private memory.
12 . The computing device of claim 11 , wherein as part of the reboot procedure, the selected computer program is restored in the non-private memory from a copy stored in the private memory.
13 . The computing device of claim 8 ,
wherein the at least one computer program is stored in the non-private memory in accordance with a first encryption protocol, and
wherein the copies of the at least one computer program and the given computer program are stored in the private memory in accordance with a second encryption protocol that is different than the first encryption protocol.
14 . The computing device of claim 8 ,
wherein the copies of the at least one computer program and the given computer program stored in the private memory are encrypted when the computing device is in the non-private mode, and
wherein the copies of the at least one computer program and the given computer program stored in the private memory are decrypted when the computing device is in the private mode.
15 . The computing device of claim 8 , wherein the non-private memory and the private memory are different partitions of a common memory device.
16 . A non-transitory medium with instructions stored thereon that, when executed by a processor of a computing device, cause the computing device to perform operations comprising:
causing display of an interface that includes a plurality of graphical controls, while the computing device is executing in a non-private mode in which access to a computer program stored in a private memory is forbidden;
receiving input that is indicative of an interaction with a first one of the plurality of graphical controls that corresponds to a private mode, in which access to the computer program stored in the private memory is permitted;
initiating a multifactor authentication (MFA) procedure in response to receiving the input; and
initiating a reboot procedure, with the computing device rebooting in the private mode, in response to the MFA procedure being successfully completed.
17 . The non-transitory medium of claim 16 , wherein the operations further comprise:
causing display of a second interface that includes the plurality of graphical controls, while the computing device is executing in the private mode;
receiving second input that is indicative of an interaction with a second one of the plurality of graphical controls that corresponds to the non-private mode; and
initiating a second reboot procedure, with the computing device rebooting in the non-private mode.
18 . The non-transitory medium of claim 16 , wherein the plurality of graphical controls includes
(i) the first graphical control that, when engaged, causes the computing device to be rebooted in the private mode,
(ii) a second graphical control that, when engaged, causes the computing device to be rebooted in the non-private mode, and
(iii) a third graphical control that, when engaged, causes a power state of the computing device to be changed.
19 . The non-transitory medium of claim 16 , wherein the operations further comprise:
copying data from the private memory to a non-private memory that is accessible while the computing device is in the non-private mode, while the computing device is in the private mode.
20 . The non-transitory medium of claim 16 ,
wherein while the computing device is in the non-private mode, the computing device is able to access a non-private memory in which one or more computer programs are stored, and
wherein either:
(i) the non-private memory is local to the computing device and the private memory is accessible to the computing device via a network, or
(ii) the private memory is local to the computing device and the non-private memory is accessible to the computing device via the network.