Dual-Unit Secure Execution Environment for Mobile Cloud Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile cloud services face security threats such as information leakage, unauthorized access, and service instability due to terminal vulnerabilities and limitations in computing performance and storage, necessitating a secure execution environment for user terminals.

Innovation Solution

A secure execution environment is provided through a dual-unit system, where a general execution unit generates authentication information and receives a security key from a cloud server for secure communication, while a secure execution unit verifies the key and manages data encryption and decryption, allowing secure operation even when the network is blocked.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Power

If mobile cloud service is implemented to overcome terminal limitations, then computing performance and storage capacity are improved, but security vulnerabilities and information leakage risks increase

Engineering Contradiction:
Improvecomputing performanceVSAvoidsecurity vulnerabilities
Core Design Contradiction:
PowerVSObject-affected harmful factors

Solution Approach 1:

The system divides the execution environment into two separate domains: a general execution environment for running applications and a secure execution environment for protecting sensitive data and operations. This segmentation isolates security-critical functions from potential attacks while maintaining overall system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A secure execution environment acts as an intermediary between the general execution environment and the cloud server. It verifies security keys, manages authentication information, and controls data transmission, thereby mediating security risks while enabling cloud service functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Object-affected harmful factors

If security verification is performed for cloud service access, then information leakage is prevented, but service access time and complexity increase

Engineering Contradiction:
Improveinformation leakage preventionVSAvoidservice access time
Core Design Contradiction:
Object-affected harmful factorsVSLoss of time

Solution Approach 1:

The secure execution environment performs security key verification and authentication information management before cloud service access is initiated. By preparing security credentials in advance and verifying them proactively, the system prevents information leakage while minimizing the time impact during actual service operations.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If dual execution units are implemented for security, then data protection is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidexecution environment complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The secure execution environment is designed to perform multiple functions including security key verification, authentication information management, encrypted data storage, and controlled data transmission. By consolidating these security functions into a unified secure domain, the system achieves comprehensive data protection while managing complexity through functional integration.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10771249B2Apparatus and method for providing secure execution environment for mobile cloud
Publication Date: 2020.09.08 ELECTRONICS & TELECOMM RES INST
  • US10771249B2 patent drawing
  • US10771249B2 patent drawing
  • US10771249B2 patent drawing

AI summary

Disclosed herein are an apparatus and method for providing a secure execution environment for a mobile cloud. The apparatus for providing a secure execution environment includes a general execution unit for, when a request for service execution is received, generating authentication information, transmitting the authentication information to a cloud server, and receiving a security key required for secure communication from the cloud server, and a secure execution unit for verifying the security key received from the general execution unit and performing secure communication with the cloud server by running a service execution monitor when verification succeeds, wherein the general execution unit is configured to transmit the authentication information, including general authentication information corresponding to the general execution unit and secure authentication information received from the secure execution unit, to the cloud server, thus allowing the cloud server to verify the general execution unit and the secure execution unit.