Mobile Device Trusted Execution Environment Encryption
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile communication security solutions are vulnerable to malware, as they often store plaintext information or decrypt ciphertext information for extended periods, compromising user privacy and convenience.
Innovation Solution
Implementing an advanced execution environment in mobile devices for both encryption and decryption processes, where plaintext information is encrypted and decrypted, and then presented to the user, with the plaintext being destroyed under predetermined conditions, thereby enhancing security and trust levels.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If plaintext information is stored or decrypted for extended periods to ensure accessibility, then user convenience is improved, but security is compromised due to malware access risks
Solution Approach 1:
The system performs encryption and decryption operations in advance within the secure environment before data is transmitted or accessed. By pre-processing data in the trusted execution environment, the patent ensures data is protected during storage and transmission while maintaining accessibility when needed, resolving the contradiction between security and convenience
Solution Approach 2:
The trusted execution environment acts as an intermediary layer between the user applications and the actual data processing. This intermediate secure environment handles sensitive operations while isolating them from potential malware in the regular execution environment, allowing convenient access without compromising security
2Device complexity
If encryption and decryption operations are performed in a regular execution environment, then device complexity is reduced, but security is compromised as malware can access plaintext information
Solution Approach 1:
The system divides the execution environment into two distinct segments: a regular execution environment for general operations and a trusted execution environment for sensitive cryptographic operations. This segmentation isolates security-critical functions from potential malware while maintaining overall system functionality, addressing the contradiction between complexity and security
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The trusted execution environment provides enhanced security properties specifically for encryption and decryption operations, while the rest of the system maintains standard operation. This localized security enhancement protects critical functions without making the entire system unnecessarily complex
Data Source
Figure 1~2
Figure 3
Figure 4
AI summary
The present invention discloses an information transmission method and a mobile device. The method includes the following steps: After receiving, in a first execution environment, plaintext information of a user, a first mobile device performs encryption processing in an advanced execution environment, and sends ciphertext information to a second mobile device. After receiving the ciphertext information, the second mobile device performs decryption in an advanced execution environment, and then presents the plaintext information to a user. The plaintext information is destroyed under a predetermined condition instead of being permanently stored, and a security and trust level of an advanced execution environment is higher than a security and trust level of the first execution environment. In this way, security of communications information can be improved.