General Trusted Application Sharing in TEE for Mobile Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current Trusted Execution Environment (TEE) standardization is low, leading to high costs and security vulnerabilities in developing and maintaining trusted applications, as service providers need to create separate applications for each service, introducing potential security threats during the development process.

Innovation Solution

A method is introduced where a general trusted application (GTA) is shared across multiple security applications, interacting with secure element applications in a bidirectional manner, with service logic deployed in the applet, reducing the need for individual application development and maintenance, and enhancing security by providing a unified interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If separate trusted applications are developed for each service, then service-specific functionality is achieved, but development cost and security vulnerability risk increase

Engineering Contradiction:
Improveservice-specific functionalityVSAvoiddevelopment cost
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal trusted application framework where a single TEE application provides services to multiple secure element applications across different services. The TEE application acts as a shared resource that can be invoked by multiple client applications (CA) and secure element applications (applet), eliminating the need to develop separate trusted applications for each service while maintaining service-specific functionality through the applet layer

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Adaptability or versatility

If separate trusted applications are developed for each service, then service-specific functionality is achieved, but security vulnerability risk increases

Engineering Contradiction:
Improveservice-specific functionalityVSAvoidsecurity vulnerability risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The universal TEE application reduces security vulnerability risk by minimizing the number of trusted applications that need to be developed and maintained. Since the TEE application framework is standardized and shared across services, it undergoes rigorous security testing and validation once, rather than repeatedly for each service. The service-specific logic resides in the applet layer, which has a smaller attack surface and can be independently secured

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Device complexity

If a general trusted application is shared across multiple security applications, then development cost is reduced, but application of the invention requires standardized interfaces

Engineering Contradiction:
Improvedevelopment costVSAvoidinterface standardization requirement
Core Design Contradiction:
Device complexityVSEase of manufacture

Solution Approach 1:

The patent leverages existing TEE and secure element interface standards to enable the universal TEE application to communicate with multiple secure element applications. By building upon standardized interfaces, the invention achieves shared trusted application functionality without requiring proprietary or service-specific interface definitions, thus reducing development cost while maintaining ease of implementation through standard compliance

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If individual trusted applications are maintained for each service, then service independence is ensured, but maintenance cost and security risk increase

Engineering Contradiction:
Improveservice independenceVSAvoidmaintenance cost
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The universal TEE application enables centralized maintenance of security-critical functionality. Updates, security patches, and improvements to the trusted application framework can be applied once and immediately benefit all services that utilize the TEE application. Service independence is maintained through the modular architecture where each service has its own client application and secure element application, but they all interact with the shared TEE application through standardized interfaces

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11734416B2Construct general trusted application for a plurality of applications
Publication Date: 2023.08.22 HUAWEI TECH CO LTD
  • US11734416B2 patent drawing
  • US11734416B2 patent drawing
  • US11734416B2 patent drawing

AI summary

A security application on the terminal uses a client application in a rich execution environment (REE), a general trusted application in a trusted execution environment (TEE), and a secure element (SE) application in a SE. The general trusted application is shared by a plurality of security applications. A method includes receiving, by the general trusted application, a first request from a first client application, determining a corresponding first SE application, sending the first request to the first SE application, sending, by the first SE application, a first command to the general trusted application, executing, by the general trusted application, the first command, returning a first execution result to the first SE application, sending, by the first SE application, a first response to the general trusted application based on the first execution result, and sending, by the general trusted application, the first response to the first client application.