Mobile Trusted Execution Environment Credential Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity management systems impose friction on users and are potentially vulnerable to attacks, especially when multiple authentication sessions are required within a short duration, and there is a risk of malicious code capturing user credentials from system memory.

Innovation Solution

A process executed by a mobile device with a trusted execution environment, where a set of credentials is established within a secure memory, and a key-pair is used to authenticate the user to access a web-service from another computing device, without revealing the actual credential values.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional identity management systems require multiple authentication sessions within a short duration, then security verification is performed, but user friction increases and productivity decreases

Engineering Contradiction:
Improvesecurity verificationVSAvoidauthentication speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The mobile device performs preliminary authentication actions by establishing a secure channel with the trusted execution environment and pre-storing credentials. When authentication is needed, the system can quickly retrieve and transmit credentials without requiring the user to re-enter information, thus reducing authentication time while maintaining security verification

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A trusted execution environment acts as an intermediary between the user's mobile device and the web-service authentication system. This intermediary securely stores credentials and facilitates quick authentication by transmitting only necessary authentication data, reducing the time required for multiple authentication sessions

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If credentials are stored in system memory for quick access, then authentication speed improves, but vulnerability to malicious code increases

Engineering Contradiction:
Improveauthentication speedVSAvoidmalware vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts credentials from the vulnerable system memory and stores them instead in a trusted execution environment. This extraction removes the harmful factor (malware vulnerability) while maintaining the ability for quick credential access, as the trusted environment provides secure storage that can rapidly provide authentication data when needed

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of storing actual credential values in accessible memory, the system uses representations or copies of credentials within the trusted execution environment. These copies can be quickly accessed for authentication purposes but cannot be read by malicious code outside the trusted environment, thus maintaining both speed and security

Inventive Principle:
Principle #26Copying

3Reliability

If a trusted execution environment is implemented to secure credentials, then security improves, but device complexity increases

Engineering Contradiction:
Improvecredential securityVSAvoidsystem architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution environment is designed to serve multiple functions: storing credentials securely, establishing secure channels, and facilitating quick authentication. By making this component multi-functional, the patent reduces the need for separate dedicated security modules, thereby limiting the increase in device complexity while maintaining strong credential security

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS20250048098A1Secure mobile initiated authentications to web-services
Publication Date: 2025.02.06 HYPR CORP
  • US20250048098A1 patent drawing
  • US20250048098A1 patent drawing
  • US20250048098A1 patent drawing

AI summary

Provided is a process for mobile-initiated authentications to web services. Credential values of the user are established within a trusted execution environment of the mobile device and representations are transmitted to a server. The user of the mobile device may authenticate with the mobile device to the server, which may convey access to a web-based service from a relying device. The server may pass credentials corresponding to the web-service received from the mobile device and verified to permit user access to the web-service to the relying device. The relying device presents credentials to the web-service to login, authenticate, or otherwise obtain user-level permission for the user on the relying device. The user of the mobile device may authenticate with the mobile device to the server, and may initiate the authentication process from the mobile device, without inputting credentials corresponding to the web-service on the relying device.