Mobile Trusted Execution Environment Using Hypervisor Watchpoints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing commercial security technologies, such as ARM TrustZone, are difficult to implement in low-end mobile devices, necessitating a solution to create a trusted execution environment without relying on these technologies.

Innovation Solution

An apparatus is provided that includes a hypervisor to separate regions into privileged and non-privileged areas, utilizing debugging watchpoints and write area execution prevention, with a mode switch unit to ensure secure execution by trapping exceptions and managing region switches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If ARM TrustZone technology is used to create a trusted execution environment, then security is improved, but device compatibility deteriorates because it cannot be implemented in low-end devices

Engineering Contradiction:
ImprovesecurityVSAvoiddevice compatibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent copies the essential security functionality of TrustZone by implementing a hypervisor-based trusted execution environment that replicates the secure isolation capabilities without requiring proprietary hardware features. The hypervisor creates a virtual trusted environment that mimics TrustZone's security model using standard virtualization mechanisms.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent makes the trusted execution environment universal by designing it to work across different device types and architectures. The hypervisor implementation provides multi-functional security support that can operate on various hardware platforms without requiring device-specific proprietary features, thus achieving both high security and broad compatibility.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If commercial security technologies are used, then security functionality is improved, but device complexity increases due to proprietary requirements

Engineering Contradiction:
Improvesecurity functionalityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent enables the system to provide its own security services through the hypervisor implementation. Instead of relying on external proprietary security modules, the hypervisor itself creates and manages the trusted execution environment using standard virtualization features already present in the hardware, thereby reducing overall system complexity while maintaining security functionality.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent extracts the essential security functionality from proprietary commercial solutions and implements it through a standalone hypervisor. By separating the core security mechanisms from device-specific proprietary features, the solution reduces system complexity while preserving the fundamental security capabilities needed for trusted execution.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS12585756B2Apparatus for reinforcing security of mobile trusted execution environment
Publication Date: 2026.03.24 THE IND & ACADEMIC COOP IN CHUNGNAM NAT UNIV (IAC)
  • US12585756B2 patent drawing
  • US12585756B2 patent drawing
  • US12585756B2 patent drawing

AI summary

The present invention relates to an apparatus for reinforcing security of a mobile trusted execution environment, and relates to an apparatus for reinforcing security of a mobile trusted execution environment for constructing a general-purpose trusted execution environment. According to an embodiment of the present invention, a technology available for a general purpose in a mobile device operating on the basis of an ARM architecture has effects of configuring a trusted execution environment for guaranteeing safe execution of an application without depending on an existing commercial security technology, and of configuring a mobile trusted execution environment by using a write area execution prevention function and a debugging watchpoint, which are general-purpose hardware functions.