Hardware Abstract Layer Authentication Bypassing Framework
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for authentication information transmission in terminal devices are complex and costly due to frequent system updates, requiring frequent definition of application framework layer interfaces and leading to inefficient path establishment and potential tampering of authentication data.
Innovation Solution
A key management client and server are defined within a hardware abstract layer, allowing authentication information to be transmitted directly from an application client to a trusted execution environment for signing, then back to the application server through a preset hardware abstract layer interface, bypassing the application framework layer and reducing the complexity and cost of path establishment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If authentication information is transmitted through the application framework layer interface, then the authentication process can be implemented, but the system complexity increases and the path establishment becomes costly due to frequent system updates
Solution Approach 1:
The patent extracts the authentication information transmission path from the application framework layer and relocates it to the hardware abstract layer. By removing the dependency on the application framework layer interfaces, the system eliminates the complexity and cost associated with frequent interface redefinitions during system updates, while maintaining the authentication functionality through the hardware abstract layer interface
Solution Approach 2:
The patent segments the authentication transmission path into distinct layers: the application layer for authentication requests, the hardware abstract layer for secure transmission, and the trusted execution environment for verification. This segmentation isolates the authentication mechanism from the application framework layer, enabling independent updates and reducing overall system complexity
2Reliability
If authentication information is transmitted through multiple layers including application framework layer, then the authentication can be achieved, but the transmission time increases due to path establishment overhead
Solution Approach 1:
The patent removes the authentication information transmission from the application framework layer and places it directly in the hardware abstract layer. This extraction eliminates the intermediate path establishment steps and reduces transmission time by creating a more direct communication path between the authentication client and the trusted execution environment
Solution Approach 2:
The patent establishes the hardware abstract layer interface and trusted execution environment in advance, before authentication is needed. This preliminary setup eliminates the need for time-consuming path establishment during each authentication transaction, as the infrastructure is already in place and ready for immediate use
3Reliability
If authentication information is transmitted through the application framework layer, then the authentication process can be completed, but the data may be tampered with during transmission
Solution Approach 1:
The patent introduces the hardware abstract layer as an intermediary between the authentication client and the trusted execution environment. This intermediary layer provides a secure, isolated channel that prevents unauthorized access and tampering with authentication information, while still enabling the necessary authentication communication to proceed
Solution Approach 2:
The patent segments the transmission path into distinct secure zones: the authentication client, the hardware abstract layer interface, and the trusted execution environment. Each segment is isolated from the others, preventing tampering while maintaining the authentication flow. The segmentation creates clear boundaries that protect data integrity throughout the transmission process
Data Source
AI summary
Embodiments of this disclosure provide an authentication information transmission method and system, a key management client, and a computer device. Performed by a device hosting a key management client and comprising a hardware abstract layer, the method includes receiving, through a path via a preset hardware abstract layer interface of the hardware abstract layer, authentication information from an application client associated with an application server; transmitting the authentication information to a key management server, so that the key management server transmits the authentication information to a trusted application in the device; obtaining authentication information signed by the trusted application and forwarded by the key management server; and transmitting, through the preset hardware abstract layer interface, the signed authentication information to the application server, so that the application server performs a validity check on the authentication information.


