Dual-Unit Secure Execution Environment for Mobile Cloud Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile cloud services face security threats such as information leakage, unauthorized access, and service instability due to terminal vulnerabilities and limitations in computing performance and storage, necessitating a secure execution environment for user terminals.
Innovation Solution
A secure execution environment is provided through a dual-unit system, where a general execution unit generates authentication information and receives a security key from a cloud server for secure communication, while a secure execution unit verifies the key and manages data encryption and decryption, allowing secure operation even when the network is blocked.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Power
If mobile cloud service is implemented to overcome terminal limitations, then computing performance and storage capacity are improved, but security vulnerabilities and information leakage risks increase
Solution Approach 1:
The system divides the execution environment into two separate domains: a general execution environment for running applications and a secure execution environment for protecting sensitive data and operations. This segmentation isolates security-critical functions from potential attacks while maintaining overall system functionality.
Solution Approach 2:
A secure execution environment acts as an intermediary between the general execution environment and the cloud server. It verifies security keys, manages authentication information, and controls data transmission, thereby mediating security risks while enabling cloud service functionality.
2Object-affected harmful factors
If security verification is performed for cloud service access, then information leakage is prevented, but service access time and complexity increase
Solution Approach 1:
The secure execution environment performs security key verification and authentication information management before cloud service access is initiated. By preparing security credentials in advance and verifying them proactively, the system prevents information leakage while minimizing the time impact during actual service operations.
3Object-affected harmful factors
If dual execution units are implemented for security, then data protection is improved, but device complexity increases
Solution Approach 1:
The secure execution environment is designed to perform multiple functions including security key verification, authentication information management, encrypted data storage, and controlled data transmission. By consolidating these security functions into a unified secure domain, the system achieves comprehensive data protection while managing complexity through functional integration.
Data Source
AI summary
Disclosed herein are an apparatus and method for providing a secure execution environment for a mobile cloud. The apparatus for providing a secure execution environment includes a general execution unit for, when a request for service execution is received, generating authentication information, transmitting the authentication information to a cloud server, and receiving a security key required for secure communication from the cloud server, and a secure execution unit for verifying the security key received from the general execution unit and performing secure communication with the cloud server by running a service execution monitor when verification succeeds, wherein the general execution unit is configured to transmit the authentication information, including general authentication information corresponding to the general execution unit and secure authentication information received from the secure execution unit, to the cloud server, thus allowing the cloud server to verify the general execution unit and the secure execution unit.


