Fingerprint Verification Interface Selection in Dual-OS Mobile Terminals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing fingerprint recognition technologies on mobile terminals are limited to a single secure runtime environment for verification, leading to a monotonous and inflexible verification process, which does not cater to varying security levels and speed requirements.
Innovation Solution
A mobile terminal with two operating systems, one for standard and one for secure environments, allowing the selection of either a first-type or second-type fingerprint interface based on verification information such as security level, speed, or threshold, enabling flexible fingerprint verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If fingerprint verification is performed only in a secure runtime environment (TEE), then security of fingerprint information is ensured, but flexibility and adaptability of verification process deteriorates
Solution Approach 1:
The patent divides the fingerprint verification system into two independent execution environments: a secure runtime environment (TEE) for security-critical verification and a rich runtime environment (REE) for general applications. Each environment has its own fingerprint interface, allowing the system to segment verification tasks based on security requirements while maintaining flexibility in selection.
Solution Approach 2:
The patent implements multi-functionality by providing both a first fingerprint interface in the REE and a second fingerprint interface in the TEE. The system can universally handle different verification scenarios by selecting the appropriate interface based on security level requirements, thus achieving both security and flexibility.
2Device complexity
If only a single fingerprint interface is provided, then device complexity is reduced, but adaptability to different verification requirements deteriorates
Solution Approach 1:
The patent segments the fingerprint interface into two distinct interfaces: a first fingerprint interface in the rich runtime environment and a second fingerprint interface in the trusted runtime environment. This segmentation allows each interface to be optimized for specific verification requirements while maintaining overall system manageability.
Solution Approach 2:
The patent introduces dynamic selection capability where the system can choose which fingerprint interface to invoke based on the verification requirements. This dynamic behavior allows the system to adapt to different security levels and verification scenarios without requiring complex static architecture.
3Reliability
If fingerprint verification requires switchover to TEE, then security level is improved, but verification speed and efficiency deteriorates
Solution Approach 1:
The patent segments verification tasks into two categories: those requiring high security (invoking TEE interface) and those requiring speed (invoking REE interface). By segmenting based on security requirements, the system can optimize verification speed for non-critical tasks while maintaining security for critical tasks.
Solution Approach 2:
The patent changes the execution environment parameter based on security requirements. For high-security verification, the system switches to TEE environment; for speed-critical verification, it remains in REE environment. This parameter change allows optimization of verification speed when security requirements are reduced.
Data Source
AI summary
A fingerprint recognition method includes obtaining, by the mobile terminal, verification information and to-be-verified fingerprint information in a first operating system. The method includes, if the mobile terminal determines, in the first operating system according to the verification information, to perform first-type verification on the to-be-verified fingerprint information, directly invoking, by the mobile terminal, the first fingerprint interface in the first operating system to verify the to-be-verified fingerprint information. The method additionally includes, if the mobile terminal determines, in the first operating system according to the verification information, to perform second-type verification on the to-be-verified fingerprint information, switching, by the mobile terminal, from the first operating system to the second operating system, and invoking the second fingerprint interface in the second operating system to verify the to-be-verified fingerprint information.


