Trusted Execution Environment for Mobile Security Migration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current mobile device security solutions are inadequate in providing a trusted execution environment, especially for security-sensitive applications, due to high costs, implementation complexity, and limited resources, and they lack robust mechanisms for detecting compromised devices and migrating secure user data.
Innovation Solution
The system securely installs, executes, and migrates security-sensitive applications within a trusted execution environment on mobile devices by verifying the operating environment, discovering supported trusted execution environments, and using cloud synchronization to ensure data integrity and security, even in cases of device compromise, loss, or upgrade.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security solutions are implemented on mobile devices, then security protection is improved, but device complexity and cost increase
Solution Approach 1:
The patent introduces a cloud-based security service as an intermediary between the mobile device and security-sensitive applications. The cloud service provides security verification, environment validation, and application hosting, allowing the device to offload complex security functions while maintaining strong protection. This resolves the contradiction by providing enterprise-grade security without requiring complex local implementation.
Solution Approach 2:
The patent extracts security-critical functions from the mobile device and relocates them to a cloud-based trusted execution environment. By separating security verification, application execution, and data storage from the device, the solution provides robust security protection while keeping the device itself simple and cost-effective.
2Reliability
If cloud-based security verification is implemented, then detection of compromised devices is improved, but communication overhead increases
Solution Approach 1:
The patent performs security verification and environment validation in advance before allowing application execution. The cloud service pre- verifies device integrity, validates security environments, and prepares trusted execution contexts beforehand. This preliminary action ensures rapid detection of compromised devices while minimizing communication overhead during actual application operations.
3Reliability
If security verification is performed before application installation, then security protection is improved, but installation time increases
Solution Approach 1:
The cloud-based service performs comprehensive security verification, device validation, and environment assessment before application installation is initiated. By completing these security checks in advance and caching verification results, the system ensures strong security protection while minimizing the perceived installation time for users.
Solution Approach 2:
The patent establishes continuous security verification and cloud-device communication that maintains security context across installation and execution phases. Once security is verified during installation, the trusted relationship continues through application execution, reducing redundant verification steps and minimizing total time while maintaining protection.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Systems, methods, apparatuses, and computer-readable media are described for securely installing, executing and/or migrating a security sensitive application in a trusted execution environment on a mobile device. For example, techniques described herein allow a mobile device to verify the operating environment of the mobile device, the security sensitive application itself and discover a trusted execution environment on the device to install the security sensitive application. Furthermore, techniques are disclosed for verifying the state of one or more applications on the mobile device against a synchronized copy of the trusted execution environment operating in the cloud and also migrating the state of one or more applications from a trusted execution environment from a first mobile device to a second mobile device in the event that the mobile device is compromised, lost, stolen or being upgraded.