Hardware Abstract Layer Authentication Bypassing Framework

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing methods for authentication information transmission in terminal devices are complex and costly due to frequent system updates, requiring frequent definition of application framework layer interfaces and leading to inefficient path establishment and potential tampering of authentication data.

Innovation Solution

A key management client and server are defined within a hardware abstract layer, allowing authentication information to be transmitted directly from an application client to a trusted execution environment for signing, then back to the application server through a preset hardware abstract layer interface, bypassing the application framework layer and reducing the complexity and cost of path establishment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If authentication information is transmitted through the application framework layer interface, then the authentication process can be implemented, but the system complexity increases and the path establishment becomes costly due to frequent system updates

Engineering Contradiction:
Improveauthentication processVSAvoidapplication framework layer interface
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the authentication information transmission path from the application framework layer and relocates it to the hardware abstract layer. By removing the dependency on the application framework layer interfaces, the system eliminates the complexity and cost associated with frequent interface redefinitions during system updates, while maintaining the authentication functionality through the hardware abstract layer interface

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent segments the authentication transmission path into distinct layers: the application layer for authentication requests, the hardware abstract layer for secure transmission, and the trusted execution environment for verification. This segmentation isolates the authentication mechanism from the application framework layer, enabling independent updates and reducing overall system complexity

Inventive Principle:
Principle #1Segmentation

2Reliability

If authentication information is transmitted through multiple layers including application framework layer, then the authentication can be achieved, but the transmission time increases due to path establishment overhead

Engineering Contradiction:
ImproveauthenticationVSAvoidtransmission time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent removes the authentication information transmission from the application framework layer and places it directly in the hardware abstract layer. This extraction eliminates the intermediate path establishment steps and reduces transmission time by creating a more direct communication path between the authentication client and the trusted execution environment

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent establishes the hardware abstract layer interface and trusted execution environment in advance, before authentication is needed. This preliminary setup eliminates the need for time-consuming path establishment during each authentication transaction, as the infrastructure is already in place and ready for immediate use

Inventive Principle:
Principle #10Preliminary action

3Reliability

If authentication information is transmitted through the application framework layer, then the authentication process can be completed, but the data may be tampered with during transmission

Engineering Contradiction:
Improveauthentication processVSAvoiddata tampering
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces the hardware abstract layer as an intermediary between the authentication client and the trusted execution environment. This intermediary layer provides a secure, isolated channel that prevents unauthorized access and tampering with authentication information, while still enabling the necessary authentication communication to proceed

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the transmission path into distinct secure zones: the authentication client, the hardware abstract layer interface, and the trusted execution environment. Each segment is isolated from the others, preventing tampering while maintaining the authentication flow. The segmentation creates clear boundaries that protect data integrity throughout the transmission process

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12184777B2Authentication information transmission method, apparatus, and storage medium
Publication Date: 2024.12.31 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • US12184777B2 patent drawing
  • US12184777B2 patent drawing
  • US12184777B2 patent drawing

AI summary

Embodiments of this disclosure provide an authentication information transmission method and system, a key management client, and a computer device. Performed by a device hosting a key management client and comprising a hardware abstract layer, the method includes receiving, through a path via a preset hardware abstract layer interface of the hardware abstract layer, authentication information from an application client associated with an application server; transmitting the authentication information to a key management server, so that the key management server transmits the authentication information to a trusted application in the device; obtaining authentication information signed by the trusted application and forwarded by the key management server; and transmitting, through the preset hardware abstract layer interface, the signed authentication information to the application server, so that the application server performs a validity check on the authentication information.