Mobile Trusted Execution Environment Credential Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity management systems impose friction on users and are potentially vulnerable to attacks, especially when multiple authentication sessions are required within a short duration, and there is a risk of malicious code capturing user credentials from system memory.
Innovation Solution
A process executed by a mobile device with a trusted execution environment, where a set of credentials is established within a secure memory, and a key-pair is used to authenticate the user to access a web-service from another computing device, without revealing the actual credential values.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional identity management systems require multiple authentication sessions within a short duration, then security verification is performed, but user friction increases and productivity decreases
Solution Approach 1:
The mobile device performs preliminary authentication actions by establishing a secure channel with the trusted execution environment and pre-storing credentials. When authentication is needed, the system can quickly retrieve and transmit credentials without requiring the user to re-enter information, thus reducing authentication time while maintaining security verification
Solution Approach 2:
A trusted execution environment acts as an intermediary between the user's mobile device and the web-service authentication system. This intermediary securely stores credentials and facilitates quick authentication by transmitting only necessary authentication data, reducing the time required for multiple authentication sessions
2Productivity
If credentials are stored in system memory for quick access, then authentication speed improves, but vulnerability to malicious code increases
Solution Approach 1:
The patent extracts credentials from the vulnerable system memory and stores them instead in a trusted execution environment. This extraction removes the harmful factor (malware vulnerability) while maintaining the ability for quick credential access, as the trusted environment provides secure storage that can rapidly provide authentication data when needed
Solution Approach 2:
Instead of storing actual credential values in accessible memory, the system uses representations or copies of credentials within the trusted execution environment. These copies can be quickly accessed for authentication purposes but cannot be read by malicious code outside the trusted environment, thus maintaining both speed and security
3Reliability
If a trusted execution environment is implemented to secure credentials, then security improves, but device complexity increases
Solution Approach 1:
The trusted execution environment is designed to serve multiple functions: storing credentials securely, establishing secure channels, and facilitating quick authentication. By making this component multi-functional, the patent reduces the need for separate dedicated security modules, thereby limiting the increase in device complexity while maintaining strong credential security
Data Source
AI summary
Provided is a process for mobile-initiated authentications to web services. Credential values of the user are established within a trusted execution environment of the mobile device and representations are transmitted to a server. The user of the mobile device may authenticate with the mobile device to the server, which may convey access to a web-based service from a relying device. The server may pass credentials corresponding to the web-service received from the mobile device and verified to permit user access to the web-service to the relying device. The relying device presents credentials to the web-service to login, authenticate, or otherwise obtain user-level permission for the user on the relying device. The user of the mobile device may authenticate with the mobile device to the server, and may initiate the authentication process from the mobile device, without inputting credentials corresponding to the web-service on the relying device.


