Thursday, October 1, 2026

2 - IDENTITY-AWARE DEVICE PRIVACY II: Threat Modeling and Operating-System Architecture for Handoff, Owner, and Emergency Access; A Secretary Suite Project

IDENTITY-AWARE DEVICE PRIVACY II

Threat Modeling and Operating-System Architecture
for Handoff, Owner, and Emergency Access

A Secretary Suite Project

John Swygert

Ivory Tower Publishing

October 1, 2026

Abstract

The first Secretary Suite paper proposed an identity-aware device architecture organized around Owner Mode, Handoff Mode, and Emergency Mode. Its governing principle was: “Possession permits utility. Identity determines access. Emergency permits assistance. None implies ownership.” This second paper develops that concept into a technical threat model and operating-system architecture. It identifies the security boundaries that must exist beneath the user interface; maps major attack surfaces to required mitigations and failure behavior; defines ephemeral session, notification, credential, sensor, network, and inter-process communication controls; and proposes an implementation path for an Android Open Source Project-class prototype. The central claim is that a trustworthy Handoff or Emergency environment cannot be merely a visual overlay or application lock. It must be a system-enforced identity context whose permissions, data flows, credentials, notifications, and transitions are constrained by the operating system and, where appropriate, hardware-backed security.

1. Relationship to the First Paper

Paper I established the conceptual distinction among possession, identity, temporary utility, emergency assistance, and ownership. Paper II preserves that model and asks a narrower engineering question: what must the operating system enforce so that those distinctions remain true under adversarial or accidental conditions?

The three states remain:

  • Owner Mode — the authenticated owner environment.

  • Handoff Mode — an owner-authorized, temporary non-owner session exposing only explicitly permitted capabilities.

  • Emergency Mode — a minimal unauthenticated environment that permits emergency assistance without exposing owner data.

This paper does not replace platform encryption, secure boot, hardware roots of trust, or biometric authentication. It specifies the additional policy and isolation layer required to make the three-state model enforceable.

2. Security Objectives

A conforming implementation should satisfy six primary objectives.

  • Identity separation: physical possession must not silently inherit the owner’s identity, credentials, application state, or private data.

  • Capability minimization: Handoff and Emergency Modes expose only the capabilities necessary for the authorized task.

  • Information-flow control: data must not leak through notifications, clipboards, autofill, recent items, share sheets, IPC, cached sessions, account pickers, voice assistants, or other secondary channels.

  • Transition integrity: movement into Owner Mode or broader permissions requires genuine owner authorization.

  • Fail-safe privacy: timeout, restart, crash, abnormal termination, or uncertain state returns the device toward the locked owner boundary rather than broader disclosure.

  • Emergency continuity: privacy failure or authentication failure must not disable the narrow emergency functions the platform is designed to preserve.

3. Trust Boundaries and Adversary Classes

3.1 Trust Boundaries

The architecture requires explicit boundaries among the owner profile, restricted-session profile, emergency surface, system services, hardware-backed authentication, persistent storage, volatile session state, sensors, radios, and external services. The restricted user interface is therefore not itself the security boundary; it is only the visible expression of deeper enforcement.

3.2 Adversary Classes

  • Curious borrower — a legitimate temporary user who explores beyond the intended task.

  • Opportunistic non-owner — a person who obtains temporary physical access and attempts to discover private information.

  • Lost-or-stolen-device user — a person with possession but no owner authorization.

  • Malicious application — software attempting to cross the restricted-session boundary through IPC, intents, accessibility services, overlays, notifications, shared storage, or account services.

  • Peripheral attacker — a person or device attempting access through USB, debugging, paired accessories, casting, external displays, or previously trusted connections.

  • Local forensic attacker — an attacker attempting to recover remnants from storage or memory after a restricted session.

  • Privileged compromise — malicious firmware, kernel compromise, defeated secure boot, or a broken hardware root of trust. This remains outside the guarantees of the proposed layer and must be stated explicitly.

4. System Architecture

A robust implementation is best modeled as a policy-enforced restricted identity context integrated with the operating system. On an Android/AOSP-class platform, the architecture would require framework-level cooperation rather than relying solely on a launcher or third-party application.

4.1 Mode Policy Controller

A privileged Mode Policy Controller maintains the authoritative state: OWNER, HANDOFF, or EMERGENCY. It validates transitions, loads the applicable policy profile, requests reauthentication when required, and exposes only narrowly scoped state information to other services. Applications must not be able to promote their own mode or widen their own permissions.

4.2 Restricted Session Container

Handoff Mode creates an ephemeral or strongly isolated user/session context. The session receives its own application state, temporary storage, clipboard, browser profile, recent-items database, share targets, and permitted accounts or synthetic account handles. Owner cookies, tokens, saved passwords, private contacts, media libraries, and application databases remain outside the session namespace.

4.3 Emergency Surface

Emergency Mode should be smaller than Handoff Mode. It is a system surface with a fixed capability set: emergency calling, supported emergency messaging, owner-authorized emergency contacts, and explicitly approved medical information. It should not become a general guest profile and should not inherit arbitrary applications.

4.4 Policy Enforcement Points

The policy must be enforced where information crosses boundaries. Relevant enforcement points include activity/task launching, package visibility, content providers, binder/IPC calls, intents, account and credential services, notification delivery, clipboard access, media providers, file pickers, share sheets, autofill, accessibility services, voice assistants, sensors, USB/debug interfaces, Bluetooth and casting, network configuration, and security settings.

5. Notification and Interruption Firewall

Incoming information is a major disclosure channel because the borrower need not actively seek it. A Notification Firewall therefore evaluates every notification against the active mode before presentation. In Handoff or Emergency Mode, private sender names, message bodies, email subjects, calendar details, authentication codes, health information, financial alerts, and other protected content are withheld unless the owner has explicitly authorized the category.

Suppression should occur before rendering on the restricted display surface. The system may queue the notification for later owner delivery or expose a content-free indication such as “private activity received.” Notification actions, inline replies, deep links, and app-opening affordances must be filtered with the same policy so that a hidden notification cannot become an escape route.

6. IPC, Intent, and Application Boundary

A restricted session can fail even when its visible applications appear isolated if those applications can invoke owner-context services. The operating system must therefore apply mode-aware filtering to inter-process communication.

  • Block or mediate Binder/IPC calls that would reveal owner-only data or invoke owner-context actions.

  • Filter implicit and explicit intents so permitted applications cannot launch protected activities through deep links or exported components.

  • Restrict content-provider queries to the restricted session’s namespace.

  • Present a mode-specific package and account view so applications cannot enumerate private applications or owner accounts unnecessarily.

  • Disable or constrain accessibility, overlay, screen-capture, notification-listener, VPN, device-administration, and other high-leverage privileges unless explicitly required by the profile.

  • Ensure the share sheet and file picker expose only session-authorized destinations and content.

7. Credentials, Autofill, Browser State, and Clipboard

The restricted session must not inherit owner secrets merely because a permitted application is the same executable used in Owner Mode. Password managers, passkeys, saved cards, autofill datasets, browser cookies, authenticated web sessions, form history, predictive text history, clipboard contents, and account-selection dialogs require mode-specific state.

A temporary browser should begin with a fresh profile unless the owner deliberately grants a particular session. When Handoff ends, the implementation should destroy the restricted profile’s ephemeral encryption keys and remove temporary state according to platform capabilities. This paper deliberately avoids claiming that arbitrary RAM can always be cryptographically “purged”; the defensible goal is strong isolation, minimized persistence, key destruction, lifecycle cleanup, and hardware-backed protection where available.

8. Network and Metadata Isolation

Even a clean browser session can reveal information through network configuration and metadata. Handoff profiles should therefore define whether the borrower may view or modify Wi-Fi networks, VPN state, hotspot settings, saved SSIDs, private DNS configuration, nearby-device identities, paired Bluetooth devices, or local-network discovery.

Some metadata cannot be hidden while still providing ordinary network access. For example, an external service can observe the public IP address used by the device. The architecture should distinguish information the operating system can conceal from the temporary user from information necessarily exposed to a remote service by use of the network. Security claims must follow that boundary rather than promise a fictional “zero-leak” environment.

9. Sensors, Media, and Temporary Capture

Camera and microphone access in Handoff Mode should be capability-specific. A temporary camera can write to a session gallery without exposing the owner’s existing media. A permitted microphone session should not grant access to stored recordings. Location can be denied, approximated, or granted according to the profile and application need.

Sensor permissions should expire with the session. Background sensor use, camera roll traversal, EXIF access, media indexing, and cross-profile media providers require explicit controls so that a seemingly harmless camera or map task does not become an indirect owner-data channel.

10. Security-Event Evidence Layer

Paper I proposed an optional evidence layer for suspicious access. Paper II treats it as a separate subsystem rather than a default property of legitimate Handoff Mode. When an owner-defined suspicious condition occurs, the system may create an integrity-protected event record containing time, active mode, failed authentication status, attempted protected action, relevant device state, and—where lawful, configured, and technically permitted—a front-camera image.

Biometric hardware should remain inside its secure subsystem. The architecture must not assume access to raw fingerprint images or templates. A production implementation may record the secure subsystem’s permitted match/non-match/error result and associated event metadata without extracting biometric secrets.

Evidence should be encrypted, integrity-protected, unavailable to restricted sessions, and subject to owner-defined retention. Jurisdiction-specific rules governing covert imaging, biometrics, consent, retention, and disclosure require legal review before deployment.

11. Formal Threat Matrix

Attack Surface

Owner Mode

Handoff / Emergency Control

Primary Mitigation

Failure Behavior

Notifications

Normal owner policy

Private content withheld

Notification firewall; action/deep-link filtering

Queue privately; do not reveal

Clipboard / autofill

Owner state available

Separate/empty state

Mode-scoped clipboard and credential services

Return empty/denied

Browser cookies

Owner profile

Fresh restricted profile

Separate storage namespace; no token inheritance

Unauthenticated session

Gallery / files

Owner libraries

Session-only or explicit grants

Profile-scoped media/file providers

Deny access

IPC / intents

Normal platform rules

Mode-aware mediation

System-service and component filtering

Block transition/action

Accounts / passkeys

Owner accounts

Hidden unless explicitly granted

Credential/account namespace isolation

No account presented

Share sheet / picker

Owner destinations

Restricted destinations

Mode-aware resolver and picker

No protected target

Voice assistant

Owner policy

Disabled or restricted

Mode-scoped assistant capabilities

No owner-context action

USB / debugging

Owner policy

No privilege expansion

Disable debugging/config changes; restrict data roles

Charge-only / deny

Bluetooth / casting

Owner devices visible

Profile-defined visibility

Hide/manage paired-device surfaces

No new pairing/control

Security settings

Owner authenticated

Unavailable

Privileged transition gate

Require owner authentication

Restart / crash

Normal boot policy

Restricted state cannot broaden access

Persistent mode marker + locked boot boundary

Return locked/private

Failed biometrics

Normal retry policy

Never promotes identity

Secure subsystem result only

Remain restricted

Evidence records

Owner access

No access

Encrypted integrity-protected store

Preserve; deny modification

Emergency call

Available

Always available

Dedicated emergency surface

Preserve assistance

12. State-Transition Rules

The mode controller should implement explicit transition rules rather than infer broad authorization from continued possession.

  • LOCKED → OWNER requires valid owner authentication.

  • OWNER → HANDOFF requires deliberate owner activation and a selected or default Handoff profile.

  • HANDOFF → OWNER requires valid owner authentication; knowledge of the Handoff task or continued possession is insufficient.

  • LOCKED/HANDOFF → EMERGENCY may occur without owner authentication.

  • EMERGENCY → OWNER requires valid owner authentication.

  • EMERGENCY → HANDOFF should not occur unless the owner has previously defined a safe transition or authenticates.

  • HANDOFF/EMERGENCY timeout, restart, crash, or policy uncertainty must never widen access.

  • A restricted application requesting a protected capability triggers denial or owner reauthentication, not silent privilege escalation.

13. Fast Handoff as a Security Requirement

A secure feature that is too slow to invoke will be bypassed in ordinary life. Handoff activation should therefore be treated as part of the threat model rather than cosmetic user experience. The design target should be a routine transition achievable in approximately two seconds once configured: for example, a dedicated lock-screen gesture, quick-action control followed by owner biometric confirmation, or a secondary authenticated gesture that launches a default Handoff profile.

Speed must not weaken intentionality. The interface should make clear what the borrower can use, while avoiding a configuration ceremony every time the phone changes hands. Reusable profiles—Passenger, Family, Browser/Phone, Repair, and similar owner-defined contexts—reduce friction without converting Handoff into an unrestricted guest account.

14. AOSP-Class Prototype Architecture

A research prototype on an Android Open Source Project-class platform would likely require modifications or privileged integrations across multiple framework services. The following is an architectural map rather than a claim that each named component can be modified identically across all Android versions or vendor builds.

  • System UI / lock screen: mode selection, restricted status display, emergency surface, and owner reauthentication.

  • Activity/task management: prevent restricted tasks from launching owner-only activities and control cross-profile task transitions.

  • Package management / resolver: present only authorized applications, components, and share targets.

  • Notification service: apply the Notification Firewall before restricted rendering or action exposure.

  • Account, credential, keystore, and autofill services: prevent owner-secret inheritance and expose only profile-authorized credentials.

  • Content/media/file providers: enforce profile-scoped namespaces and explicit grants.

  • Clipboard and input-method services: prevent owner clipboard and learned/private text state from crossing into restricted sessions.

  • Connectivity services: restrict configuration visibility and modification of Wi-Fi, VPN, hotspot, Bluetooth, casting, and nearby-device state.

  • Sensor/privacy services: apply mode-specific camera, microphone, location, and background-sensor policy.

  • Biometric/KeyMint/TEE-facing services: preserve hardware-backed owner authentication while exposing only permitted result status to the mode controller.

  • Persistent policy store: retain mode configuration and fail-safe state without making evidence or owner secrets available to the restricted user.

15. Verification and Acceptance Tests

The architecture should be tested as a set of falsifiable guarantees. A prototype succeeds only when a temporary user can complete authorized tasks while repeated attempts to cross the identity boundary fail.

  • Activation test: configured Handoff Mode can be entered quickly and reliably without exposing owner content during transition.

  • Notification test: protected notifications arriving during restricted use reveal neither content nor actionable escape paths.

  • Credential test: permitted browsers and applications cannot obtain owner cookies, passkeys, autofill secrets, or account tokens unless explicitly granted.

  • IPC escape test: deep links, exported activities, intents, providers, accessibility services, overlays, and share targets cannot cross into owner-only resources.

  • Media test: a temporary camera can capture and use session media without enumerating the owner gallery.

  • Restart/crash test: forced process death, UI crash, reboot, and timeout never broaden privileges.

  • Emergency test: emergency calling and authorized emergency information remain available despite failed owner authentication.

  • Evidence-integrity test: a restricted user cannot view, alter, or delete protected security-event records.

  • Usability test: ordinary users can understand the active mode, complete permitted tasks, and return the device without accidental disclosure.

16. Residual Risks and Limits

No restricted-session architecture can guarantee privacy if the operating system, kernel, secure boot chain, or hardware root of trust is already compromised. Nor can it prevent a borrower from observing information the owner deliberately exposes for the permitted task. Network use necessarily reveals some information to external services, and legal requirements for emergency access, covert imaging, biometrics, and data retention differ by jurisdiction.

The objective is therefore not absolute secrecy. It is a defensible reduction of unnecessary disclosure by making possession, identity, authorization, and emergency capability separate enforceable relationships.

17. Research Program

Paper II turns the Secretary Suite concept into a prototype-ready research agenda. The next phase should combine a reference implementation with adversarial testing. Useful work packages include: a minimal AOSP mode controller; a restricted-session container; notification filtering; credential and clipboard isolation; mode-aware intent/IPC enforcement; emergency-surface hardening; protected event logging; and a usability study measuring activation time, task completion, accidental disclosure, and escape attempts.

The architecture should be evaluated against existing platform mechanisms not by asking whether they offer a guest mode or application pinning, but by testing whether they preserve the governing relationship: can another person use the physical device for a defined purpose without inheriting the owner’s digital identity?

18. Conclusion

Identity-aware device privacy requires more than hiding applications. It requires the operating system to treat identity as a security context that governs information flows across the entire device. Handoff Mode must therefore isolate sessions, credentials, notifications, storage, IPC, sensors, network configuration, and transitions. Emergency Mode must remain smaller still, preserving assistance without becoming an authentication bypass.

The resulting architecture retains the principle established in Paper I: possession can permit utility without conferring identity, and emergency need can permit assistance without conferring ownership. Paper II translates that principle into enforceable trust boundaries, threat controls, failure rules, and acceptance tests suitable for an operating-system prototype.

Possession permits utility. Identity determines access. Emergency permits assistance. None implies ownership.

SIGNAL: Symbolic Persistence Under Coercion:How Brief Human Acts Outlive Systems of Power

SIGNAL

Symbolic Persistence Under Coercion:
How Brief Human Acts Outlive Systems of Power

John Swygert

Ivory Tower Publishing

October 1, 2026

Abstract

Some of history’s most durable human signals are physically tiny: a person standing before a line of tanks, a kiss beside a wall, a recovered object carried through a hostile world, a flower held where violence has attempted to dictate meaning. Their material force is negligible compared with the institutions, weapons, architecture, or coercive systems surrounding them. Yet these brief acts can become the informational event that survives.

This paper proposes symbolic persistence under coercion as a framework for examining that asymmetry. The central claim is not that symbolic acts physically defeat power. Rather, physical magnitude, duration, and coercive capacity do not reliably predict cultural, informational, or moral persistence. A short act may become a high-density signal whose meaning propagates long after the immediate coercive system has changed or disappeared. The paper develops the concepts of signal compression, boundary contrast, receiver-dependent meaning, temporal asymmetry, pathway multiplication, paradox, and artistic retransmission. It examines the 1989 Tank Man image, David Bowie’s “Heroes,” anti-war imagery associated with “War Pigs,” and the widely reproduced photograph of Donald Trump raising a fist after the July 13, 2024 assassination attempt as distinct examples of how an event can become an image-sign whose interpretation exceeds the event’s physical duration.

1. Signal

An act and a second of Love and kindness can overcome a lifetime of oppression and inspire beyond the lives that set the example.

The proposition requires a precise meaning of “overcome.” A brief act does not necessarily overthrow a government, stop a weapon, remove a wall, reverse a death, or erase suffering. It can nevertheless defeat a narrower objective of coercion: the attempt to determine what a person may value, remember, love, express, or choose.

A signal is therefore not measured here primarily by physical energy. It is an event that becomes transmissible meaning. The person acts once; observers receive the act; photographs, songs, films, memories, stories, and later artworks retransmit it. Each new receiver can become a new transmitter. The original event ends while its informational consequences continue.

The duration of an event does not determine the duration of its meaning.

2. Physical Magnitude and Semantic Magnitude

Ordinary measurements favor the large system. A tank has more mass than a pedestrian. A state has more coercive resources than an individual. A concrete wall has more physical permanence than a kiss. An industrial or military apparatus can occupy nearly an entire visual field while a human being occupies only a few pixels.

Yet semantic magnitude can reverse that ordering. The eye may go first to the lone person. The remembered element may be the kiss rather than the wall, the flower rather than the factory, the raised fist rather than the stage, or the human body rather than the armored column.

This suggests two distinct scales: physical magnitude and semantic magnitude. They can correlate, but they need not. A central hypothesis of this paper is that extreme physical asymmetry can intensify symbolic meaning because the contrast itself becomes part of the information.

3. Boundary, Pathway, and Paradox

Power and resistance meet at boundaries: body/tank, lover/wall, individual/system, life/death, private meaning/public force. The boundary is not merely where two objects touch. It is where incompatible relational claims become visible.

A pathway is the route by which the act reaches receivers. An event witnessed by ten people may disappear; the same event captured in a photograph can reach millions; a photograph incorporated into education, journalism, music, painting, film, or political memory can generate new pathways decades later.

The paradox is that the weaker physical participant can become the stronger informational object. Coercive power may dominate the event while the resisting signal dominates its memory.

Power can determine what is done to a person without necessarily determining what the person’s act will mean.

4. Signal Compression

Powerful symbolic images are often radically compressed narratives. They remove explanatory connective tissue and force the receiver to reconstruct relationships. This is analogous to a sharded artistic method: instead of presenting the entire causal story, the work presents selected high-density fragments whose relations must be completed by the observer.

A wall, guns, two lovers, a kiss, dolphins, a king and queen, and “one day” do not constitute a conventional linear synopsis. Yet in “Heroes” they form a coherent emotional system. Likewise, a photograph of one person and a line of tanks contains no essay explaining state power, vulnerability, fear, refusal, consequence, or courage. The geometry carries much of the argument.

Compression can strengthen a signal because the receiver participates in reconstruction. Meaning is not merely delivered; it is completed.

5. Case Study: Tank Man, Beijing, June 5, 1989

SUGGESTED IMAGE TO LOOK UP (not reproduced here): Jeff Widener, “Tank Man,” Associated Press, Beijing, June 5, 1989 — the elevated photograph showing the lone man standing before a column of tanks. Out of respect for the photographer, publisher, copyright, licensing, trademark, and other applicable intellectual-property rights, please locate and view the properly credited image through an authorized source rather than reproducing it from this paper.

The photographs and video commonly known as “Tank Man” show an unidentified man standing in the path of a column of tanks in Beijing on June 5, 1989, following the military crackdown associated with the Tiananmen Square protests. In the most famous compositions, the man is physically minute relative to the armored vehicles. He carries no comparable weapon and commands no visible force.

The visual relationship is what makes the image extraordinary: one human body interrupts the forward path of multiple armored machines. The event’s symbolic force does not require us to know the man’s internal thoughts. Those remain unknown. The observable fact is enough: a lone person occupied the tanks’ path, and the tanks had to respond to his presence.

The image demonstrates asymmetry in nearly pure form. If two tanks confronted one another, the image would depict competing physical forces. Because the confrontation is between armored vehicles and a human body, the physical imbalance itself becomes information.

The tanks possess the force. The human figure possesses the signal.

6. Case Study: David Bowie’s “Heroes”

SUGGESTED ARTWORK / IMAGERY TO LOOK UP (not reproduced here): David Bowie, “Heroes” (1977), including authorized “Heroes” artwork and historically documented Berlin Wall-era imagery associated with the song. Out of respect for the artists, photographers, record label, publishers, copyright, trademark, licensing, and other applicable rights, please view properly credited material through authorized sources.

David Bowie’s “Heroes,” recorded at Hansa in West Berlin in 1977, transforms a small human relationship into an image of temporary victory against division. Bowie later identified producer Tony Visconti and Antonia Maaß as the lovers whose meeting near the Berlin Wall helped motivate the song. The song’s imagery nevertheless exceeds a single biographical anecdote: movement, separation, sovereignty, danger, intimacy, shame, endurance, and a deliberately temporary interval are compressed into fragments.

The crucial temporal structure is that the victory need not last forever to be meaningful. The surrounding conditions can remain. The wall can remain. Danger can remain. Yet a human relationship can create an interval in which the surrounding system fails to define the entirety of lived experience.

This is symbolic persistence before the fact: the participants may possess only a moment, while the artistic representation of that moment can persist for generations. The work converts a transient human act into a repeatable signal.

7. Case Study: “War Pigs” and Visual Anti-War Narrative

SUGGESTED VISUAL SEQUENCE TO LOOK UP (not reproduced here): the specific anti-war video sequence discussed in this section — the woman in red, the fallen figure, the red personal object/scarf-like element, industrial workers and surveillance imagery, the flower, and the monumental institutional setting. Before publication, identify the exact video title, artist/performer, director, production company, release date, and rights holder. Out of respect for copyright, trademark, licensing, and other applicable intellectual-property rights, please locate and view the authorized version rather than reproducing frames here.

Black Sabbath’s “War Pigs” is explicitly anti-war in its lyrical attack on leaders who initiate wars while others bear their physical consequences. Visual works associated with or inspired by such anti-war themes can intensify that argument by placing vulnerable individuals, personal objects, flowers, industrial environments, surveillance, regimentation, and monumental architecture in direct visual opposition.

The image sequence considered in developing this paper is especially useful as an artistic example: human figures are physically overwhelmed by a severe built environment; a red personal element persists across scenes; intimate grief and remembrance are contrasted with machinery and institutional order; and a small living flower becomes visually disproportionate in meaning to the architecture around it.

The analytical point does not depend on treating every detail as literal history. Art can construct a synthetic event whose relational structure is historically recognizable: overwhelming system, vulnerable person, meaningful object, refusal, memory, and continuation. Fictional or stylized art can therefore carry the same class of signal as documentary photography while remaining clearly distinguishable from documentary evidence.

8. Case Study: Donald Trump, Butler, Pennsylvania, July 13, 2024

SUGGESTED IMAGE TO LOOK UP (not reproduced here): Evan Vucci / Associated Press, July 13, 2024, Butler, Pennsylvania — Donald Trump, blood visible on his face, surrounded by U.S. Secret Service agents, raising his fist with the American flag in the composition. Out of respect for the photographer and Associated Press copyright and licensing rights, as well as applicable trademark and other intellectual-property rights, please view the properly credited image through an authorized source rather than reproducing it here.

After being wounded during an assassination attempt at a campaign rally in Butler, Pennsylvania, on July 13, 2024, Donald Trump was photographed with blood visible on his face, surrounded by Secret Service agents, raising a fist as he was moved from the stage. The photographs became immediately recognizable political images.

This paper does not require agreement about Trump, his politics, or the later uses of the image. Indeed, its analytic usefulness lies partly in receiver dependence. Supporters may perceive defiance, survival, courage, or solidarity. Opponents may attach different political meanings or reject the heroic framing entirely. The physical event is shared; the semantic reception diverges.

That divergence reveals an essential property of signal: meaning is relational. It is produced by an event interacting with a receiver’s history, values, affiliations, fears, expectations, and interpretive frame. The same raised fist can therefore be intensely attractive to one observer and intensely repellent to another while remaining an unusually powerful visual signal to both.

9. Are These Snapshots of Martyrdom?

They are better described as martyrdom-adjacent images than as a single category of martyrdom. Classical martyrdom ordinarily involves suffering or death because a person refuses to renounce a belief, identity, cause, or commitment. Some symbolic images capture actual death; others capture anticipated sacrifice, survived violence, willingness to accept consequence, remembrance of another’s sacrifice, or public refusal under threat.

The broader category needed here is the sacrificial signal: an act whose meaning is amplified because the actor appears willing to accept a cost greater than the immediate material benefit of the act. The observer perceives that the person may lose safety, freedom, status, bodily integrity, or life and acts anyway.

This explains why a person standing before tanks can resemble martyr imagery without requiring that the person die, and why a wounded political figure raising a fist can acquire martyr-like visual characteristics without being a martyr. The image captures vulnerability plus persistence. Actual martyrdom is one possible endpoint, not the necessary definition.

10. Receiver Dependence

No symbolic signal carries a single guaranteed meaning. A receiver participates in its interpretation. Political imagery makes this obvious, but the principle is universal. A flag can evoke belonging or exclusion. A wall can mean protection or imprisonment. A fist can mean resistance or aggression. A uniform can mean safety or threat.

Receiver dependence does not imply that interpretation is arbitrary. The observable event constrains plausible interpretations, as do historical context, authorship, sequence, and corroborating evidence. But the same evidence can still produce sharply different emotional and moral responses.

A useful model is therefore:

EVENT → REPRESENTATION → RECEIVER → INTERPRETATION → RETRANSMISSION

Each retransmission can preserve, compress, distort, expand, reverse, or mythologize the original signal.

11. Temporal Asymmetry

Coercive systems often require continuous maintenance: personnel, weapons, bureaucracy, architecture, surveillance, money, ideology, enforcement, and repetition. A symbolic act may require seconds.

Once successfully encoded into cultural memory, however, the maintenance requirements can reverse. The original coercive apparatus may disappear while a photograph, song, story, or gesture continues to be copied at negligible cost.

This produces temporal asymmetry: a brief event can acquire a cultural half-life far exceeding the institution that gave the event its meaning. The system unintentionally supplies the contrast that makes the resisting signal memorable.

12. Art as Signal Amplifier

Art does not merely illustrate these events. It can change their transmission characteristics. Music adds rhythm, repetition, voice, and emotional memory. Photography freezes relational geometry. Film adds sequence and consequence. Painting can remove incidental detail and exaggerate the essential relation. Literature can restore interiority that a photograph cannot provide.

The strongest companion images for this paper should therefore not be decorative. Each should perform analytical work. A photograph of Tank Man demonstrates physical/semantic asymmetry. “Heroes” demonstrates narrative sharding and temporary victory. Anti-war visual imagery demonstrates artistic recomposition of grief, memory, industrial power, and refusal. The Butler photograph demonstrates receiver-dependent political meaning and the rapid formation of an icon.

The image and the paper should interrogate one another. The text explains relationships that the image compresses; the image makes visible relationships that prose can over-explain.

13. Proposed Analytical Tests

The framework can be made empirically useful by asking measurable questions. How rapidly does an image become recognizable without captioning? Which visual elements are retained in memory? Does recognition persist when contextual detail is removed? How does perceived physical asymmetry correlate with reported symbolic power? How strongly do political or cultural priors alter interpretation? Which events generate derivative art, slogans, reenactments, references, and visual quotations? How long does the signal persist relative to the institution or event that produced it?

Experimental work could compare documentary photographs, fictionalized artworks, musical narratives, and reconstructed scenes. Participants could be shown full context, fragmented context, or image alone. Researchers could measure recall, emotional intensity, inferred narrative, moral interpretation, and persistence over time. Network analysis could examine retransmission pathways across journalism, education, social media, music, film, and visual art.

14. The Border of Art and Theory

The framework reaches a productive border between artistic intuition and formal analysis. Artists have long understood that the smallest object can dominate a composition, that silence can outweigh noise, that a single repeated phrase can carry an entire narrative, and that what is omitted can force the audience to build the missing structure.

The theoretical opportunity is to ask why. Boundary contrast, receiver dependence, pathway structure, compression, invariance, and paradox provide a vocabulary for examining how meaning survives transformations in medium and perspective.

The same underlying relation can appear as a photograph, a lyric, a fictional scene, a remembered event, or a political image while its surface form changes. The research question becomes not merely what the artwork depicts, but what relation survives the transformation and continues to produce meaning.

15. Conclusion

A signal can be physically small and historically enormous. Tank Man does not need to overpower a tank. Lovers do not need to demolish a wall. A flower does not need to defeat an industrial system. A raised fist does not need to produce the same interpretation in every observer. Their power as images arises from relationships made visible under pressure.

The deepest asymmetry is temporal. Oppression can consume years and still fail to monopolize memory. A moment of Love, dignity, refusal, courage, grief, mercy, or solidarity can become the fragment that survives.

A second can outlive a lifetime.

That is the signal.

References and Artwork Documentation

ARTWORK RESPECT NOTICE: This paper intentionally does not reproduce the suggested photographs, album/video imagery, film frames, logos, or other protected visual works. Readers are respectfully asked to look up the identified works through properly credited, authorized sources. Any later illustrated edition should obtain permission or a suitable license where required and provide the creator, publisher/agency, source, date, and rights information appropriate to that work.

Bowie, David. “Heroes.” Lyrics by David Bowie; music by David Bowie and Brian Eno. Recorded at Hansa by the Wall, Berlin, 1977. Produced by David Bowie and Tony Visconti.

David Bowie Official Website. “'Heroes' Single Is Forty Years Old Today.” September 23, 2017. Includes Bowie’s and Tony Visconti’s accounts of the lovers near the Berlin Wall.

Black Sabbath. “War Pigs.” Written by Tony Iommi, Ozzy Osbourne, Geezer Butler, and Bill Ward. Released on Paranoid, 1970. Official Black Sabbath materials identify the song’s anti-war lyrical narrative.

Tank Man photographs, Beijing, June 5, 1989. Multiple photographers recorded the encounter from different vantage points. Any image reproduced with publication of this paper should be credited to its specific photographer and licensed from the relevant rights holder rather than treated as a generic public-domain image.

Trump assassination-attempt photographs, Butler, Pennsylvania, July 13, 2024. The widely circulated raised-fist sequence includes photographs by Associated Press photographer Evan Vucci. Any reproduced image should carry the photographer/agency credit and appropriate publication license.

Artwork note: the visual sequence discussed in Section 7 should be identified by exact video/film title, director, production source, date, and rights holder before publication. The present paper analyzes the user-supplied frames as visual material but does not infer provenance that has not yet been verified.

IDENTITY-AWARE DEVICE PRIVACY AND EMERGENCY ACCESS: A Secretary Suite Project

IDENTITY-AWARE DEVICE PRIVACY
AND EMERGENCY ACCESS

A Secretary Suite Project

John Swygert

Ivory Tower Publishing

October 1, 2026

Abstract

Personal smartphones increasingly function as extensions of identity: they contain private communications, photographs, files, financial access, health information, authentication tokens, location histories, cloud accounts, and records of daily life. Yet the physical device is also an extraordinarily useful object that an owner may reasonably need to hand to another person, and in an emergency it may be the nearest available communications instrument. Conventional lock-screen design treats these situations too coarsely: either the device is locked, or a person who has authenticated may enter a much larger private environment.

This paper proposes an identity-aware device architecture for Secretary Suite that separates physical possession, temporary utility, emergency assistance, and owner identity. The architecture is organized around three operating states—Owner Mode, Handoff Mode, and Emergency Mode—and a policy principle: possession may permit narrowly defined utility without conferring access to the owner's digital identity. The proposal further introduces privacy-preserving notification controls, temporary-session isolation, automatic re-locking, emergency communications, and an optional security-event evidence layer for documenting suspicious or unauthorized interaction. The goal is not merely to lock individual applications, but to make the device itself change what it is permitted to reveal according to the identity and authorization state of the current user.

1. Problem Definition

A modern smartphone is simultaneously a telephone, camera, wallet, key ring, correspondence archive, identity token, medical-information carrier, navigation device, cloud terminal, and personal computer. Handing the device to another person can therefore expose information wholly unrelated to the reason it was handed over. A person borrowing a phone to place a call should not thereby gain access to photographs. A friend using navigation should not see incoming private-message previews. A repair technician testing a speaker should not inherit access to email. A stranger using a found or borrowed phone during an emergency should not need the owner's passcode merely to contact emergency services.

The architectural mistake is to treat device possession and owner authorization as nearly synonymous. They are different relationships. A device can be physically useful to a non-owner while remaining informationally private.

2. Governing Principle

Possession permits utility. Identity determines access.
Emergency permits assistance. None implies ownership.

The proposed system treats authorization as a continuously enforced boundary rather than a single unlock event. The relevant question is not simply whether the screen is unlocked, but which identity context is active and which information flows are permitted within that context.

3. Three-State Architecture

3.1 Owner Mode

Owner Mode is the normal authenticated environment. Successful owner authentication—using the device's configured credentials and secure biometric mechanisms—restores the owner's authorized applications, files, accounts, notifications, settings, cloud connections, credentials, and personalized services. Existing operating-system security remains foundational; Secretary Suite adds a higher-level identity and disclosure policy rather than replacing secure hardware, encryption, or platform authentication.

3.2 Handoff Mode

Handoff Mode is intentionally activated when the owner wants another person to use the device without entering the owner's private environment. The owner selects or predefines the capabilities that remain available. Examples can include a telephone dialer, a particular browser session, maps, a calculator, a camera with a temporary gallery, a music player, or one specifically authorized application.

Private content remains inaccessible even while permitted functions operate. Owner photographs, messages, email, files, browser history, saved passwords, financial applications, cloud drives, private contacts, account-switching controls, notification contents, authentication tokens, and other designated resources remain sealed. The temporary user receives a session, not the owner's identity.

3.3 Emergency Mode

Emergency Mode is available without the owner's passcode or fingerprint, but exposes only a deliberately minimal emergency environment. Its core purpose is to allow a person with physical possession of the device to request help without gaining access to private data.

Permitted functions can include emergency voice calls, emergency text or equivalent emergency messaging where supported, access to owner-designated emergency contacts, and explicitly authorized emergency medical information. The interface must prevent lateral movement into ordinary messaging histories, contact databases, photographs, files, account settings, cloud services, or other owner resources.

4. Handoff Session Isolation

Handoff Mode should behave as a temporary, isolated identity context. Applications opened within it receive only the data and permissions assigned to that session. A temporary browser should not inherit the owner's authenticated cookies. A camera session should not expose the owner's existing gallery. A telephone interface may allow dialing without exposing an unrestricted contact history. Clipboard contents, autofill data, password managers, recent-document lists, notification histories, and cross-application sharing should be filtered or replaced with temporary-session equivalents.

When Handoff Mode ends, temporary state can be discarded according to owner policy. The system should automatically return to a locked owner boundary after a configurable timeout, device restart, explicit return command, or security event.

5. Notification Firewall

One of the easiest ways to violate privacy after a phone is handed to someone is through information that arrives rather than information the borrower actively seeks. Handoff and Emergency Modes therefore require a notification firewall. Private message text, sender names, email subjects, calendar details, financial alerts, authentication codes, health notifications, and similar content should not appear unless the owner has explicitly authorized that category.

The device may indicate that private activity occurred without revealing its substance—for example, by recording notifications for later presentation when Owner Mode is restored.

6. Emergency Utility Without Identity Disclosure

Emergency accessibility should be designed as a capability boundary rather than an authentication bypass. A non-owner may be able to initiate an emergency call or compose a new emergency message while remaining unable to inspect prior communications. Emergency contacts can be exposed selectively, with the owner deciding which names, relationships, medical facts, or instructions are appropriate to reveal.

The emergency environment should be visually unmistakable and technically constrained. No action performed within it should silently convert the session into Owner Mode. Authentication remains necessary for owner data even after emergency communication succeeds.

7. Security-Event Evidence Layer

Secretary Suite can optionally treat entry into designated non-owner or suspicious-access states as a security event. With the owner's prior configuration and subject to applicable law, the device may create a protected event record containing a timestamp, mode entered, failed authentication attempts, relevant device state, and other security telemetry.

One proposed feature is an unannounced front-camera capture when a defined suspicious-access condition is triggered. The purpose is evidentiary: to document who was interacting with a lost, stolen, or protected device without advertising the evidence-collection event to that person. Because laws governing image capture, biometrics, consent, retention, and disclosure vary by jurisdiction, this feature must be configurable, legally reviewed, and designed with strict retention and access controls.

7.1 Biometric Prompt as Evidence Event

A non-owner may also be prompted to present a fingerprint or other biometric while still being allowed to use the narrow functions that do not require owner authentication. The crucial distinction is that the prompt does not falsely authenticate the person and does not unlock owner information. A failed or non-owner biometric interaction can instead be recorded as a security event.

The architecture should not assume that ordinary mobile biometric hardware exposes a raw fingerprint image. In a production implementation, Secretary Suite should use only evidence and status information legitimately available from the platform's secure biometric subsystem. Raw biometric templates should not be copied out of secure hardware merely to create an evidentiary record. The design goal is documentation of the interaction, not creation of an insecure biometric database.

8. Covert Evidence and User Safety

Covert evidence collection creates a tension between device-owner security and the privacy rights of the temporary user. The architecture therefore separates ordinary Handoff Mode from suspicious-access evidence collection. A person whom the owner intentionally hands the phone to should not automatically be treated as an intruder. The owner can define which transitions or failed-authentication patterns constitute a security event.

Evidence records should be encrypted, integrity-protected, inaccessible from Handoff and Emergency Modes, and subject to configurable retention. Remote synchronization, if used, should occur only through an authenticated owner-controlled service. The system should clearly document its evidence policy to the owner during setup even when a triggered capture itself is intentionally not announced to the person handling the device.

9. Continuous and Event-Triggered Identity Assurance

The three modes need not depend on a single authentication event forever. Secretary Suite can support continuous or event-triggered identity assurance. Sensitive actions can require renewed owner authentication even when Owner Mode is active. Conversely, a device intentionally placed into Handoff Mode should not attempt to infer that the borrower has become the owner merely because the device remains in use.

Useful triggers include attempts to open protected resources, access account settings, reveal notifications, export data, change security configuration, disable Handoff Mode, or cross from an allowed application into an owner-only application. The security model should favor explicit authorization over speculative identity inference.

10. Permission Model

The owner should be able to construct reusable Handoff profiles. One profile might permit maps and music for a passenger. Another might permit a browser and telephone for a family member. A service profile could expose diagnostics needed by a repair technician while withholding personal data. An emergency profile would remain system-defined at its core but allow owner-approved emergency information.

Permissions should be expressed in terms understandable to ordinary users while mapping internally to application, file, sensor, account, notification, network, clipboard, credential, and inter-process communication controls.

11. Threat Model

The architecture addresses several distinct threats: casual privacy exposure when a device is voluntarily handed over; opportunistic exploration by a borrower; access attempts after loss or theft; disclosure through incoming notifications; credential leakage through browsers and autofill; unauthorized movement from an emergency interface into private applications; and attempts to disable the privacy boundary itself.

It does not make a compromised operating system, malicious firmware, or defeated hardware root of trust magically secure. Its strongest implementation therefore requires cooperation from the operating system and secure hardware rather than functioning only as a conventional application layered above them.

12. Fail-Safe Rules

  • Emergency communication must remain available even when owner authentication fails.

  • Emergency access must never imply access to owner data.

  • Handoff permissions must default to the minimum capabilities explicitly granted.

  • A failed biometric attempt must never be treated as owner authentication.

  • Security evidence must not be stored where the temporary user can delete or alter it.

  • Returning from Handoff or Emergency Mode to Owner Mode requires genuine owner authentication.

  • Restart, timeout, or abnormal state should fail toward privacy rather than toward broader disclosure.

  • The owner must be able to disable optional evidence-collection features independently of emergency access.

13. Example Use Cases

13.1 Borrowed Phone

An owner lends the phone to a stranger who needs to call for transportation. Handoff Mode exposes the dialer while messages, photographs, notifications, contacts, files, and accounts remain inaccessible. When the call ends, the session can automatically expire.

13.2 Navigation

A driver hands the phone to a passenger for navigation. Maps remains available, but private notifications are suppressed and the passenger cannot move from the navigation session into the owner's personal applications.

13.3 Emergency

An unconscious person's locked phone is found at an accident scene. Emergency Mode allows a bystander to contact emergency services and, if the owner has authorized it, view a limited emergency contact or medical card. No passcode is required for those emergency functions, and no private application becomes available.

13.4 Suspicious Access

A lost device enters a configured suspicious-access state. The device preserves a protected event record and, where lawful and enabled, captures available security evidence. A biometric prompt may be presented, but non-owner interaction cannot unlock private data. Emergency assistance remains available regardless.

14. Research and Prototype Questions

A prototype should determine which protections can be implemented at application level and which require operating-system privileges. Particular research questions include secure isolation of app data, suppression and deferred delivery of notifications, temporary identities for browsers and applications, emergency messaging interfaces, hardware-backed event logs, lawful camera capture, biometric subsystem limitations, owner-configurable disclosure policies, and resistance to mode escape.

Usability testing is equally important. A privacy architecture that is too difficult to activate will not be used; an emergency interface that is confusing can fail at the moment it matters most. Testing should therefore measure activation time, accidental disclosure, successful completion of permitted tasks, attempts to escape the restricted environment, and successful emergency communication under stress.

15. Distinction from Conventional Guest and Lock Modes

The proposal is broader than an application lock and more purpose-specific than a generic guest account. Its central object is the relationship among possession, identity, authorization, disclosure, and emergency need. Rather than asking only whether a user may enter the device, Secretary Suite asks what the device is permitted to reveal and do for this particular interaction.

That distinction allows the same physical phone to become a private owner environment, a deliberately constrained borrowed tool, or a minimal emergency instrument without treating those three situations as equivalent.

16. Conclusion

A smartphone should be shareable without requiring its owner to share a life. It should also remain useful in an emergency without converting emergency access into a privacy vulnerability. Identity-Aware Device Privacy and Emergency Access separates those requirements by treating physical possession, authorized identity, temporary utility, and emergency assistance as distinct states.

Secretary Suite's proposed Owner, Handoff, and Emergency Modes create a device-wide privacy boundary rather than a collection of unrelated application locks. Temporary-session isolation and notification filtering protect information during legitimate handoff. Minimal emergency capabilities preserve access to help. Optional, protected security-event records can document suspicious interaction without granting broader access.

The resulting principle is simple: a person may be allowed to use a device without being allowed to become its owner. Designing explicitly around that distinction can make personal devices simultaneously more private, more shareable, and more useful when they are needed most.