Mobile Device Trusted Execution Environment Encryption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile communication security solutions are vulnerable to malware, as they often store plaintext information or decrypt ciphertext information for extended periods, compromising user privacy and convenience.

Innovation Solution

Implementing an advanced execution environment in mobile devices for both encryption and decryption processes, where plaintext information is encrypted and decrypted, and then presented to the user, with the plaintext being destroyed under predetermined conditions, thereby enhancing security and trust levels.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If plaintext information is stored or decrypted for extended periods to ensure accessibility, then user convenience is improved, but security is compromised due to malware access risks

Engineering Contradiction:
Improveuser convenienceVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system performs encryption and decryption operations in advance within the secure environment before data is transmitted or accessed. By pre-processing data in the trusted execution environment, the patent ensures data is protected during storage and transmission while maintaining accessibility when needed, resolving the contradiction between security and convenience

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The trusted execution environment acts as an intermediary layer between the user applications and the actual data processing. This intermediate secure environment handles sensitive operations while isolating them from potential malware in the regular execution environment, allowing convenient access without compromising security

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If encryption and decryption operations are performed in a regular execution environment, then device complexity is reduced, but security is compromised as malware can access plaintext information

Engineering Contradiction:
Improvesystem complexityVSAvoidsecurity
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The system divides the execution environment into two distinct segments: a regular execution environment for general operations and a trusted execution environment for sensitive cryptographic operations. This segmentation isolates security-critical functions from potential malware while maintaining overall system functionality, addressing the contradiction between complexity and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the system. The trusted execution environment provides enhanced security properties specifically for encryption and decryption operations, while the rest of the system maintains standard operation. This localized security enhancement protects critical functions without making the entire system unnecessarily complex

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3324572B1Information transmission method and mobile device
Publication Date: 2021.05.12 HUAWEI TECH CO LTD
  • EP3324572B1 patent drawingFigure 1~2
  • EP3324572B1 patent drawingFigure 3
  • EP3324572B1 patent drawingFigure 4

AI summary

The present invention discloses an information transmission method and a mobile device. The method includes the following steps: After receiving, in a first execution environment, plaintext information of a user, a first mobile device performs encryption processing in an advanced execution environment, and sends ciphertext information to a second mobile device. After receiving the ciphertext information, the second mobile device performs decryption in an advanced execution environment, and then presents the plaintext information to a user. The plaintext information is destroyed under a predetermined condition instead of being permanently stored, and a security and trust level of an advanced execution environment is higher than a security and trust level of the first execution environment. In this way, security of communications information can be improved.