Mobile Trusted Execution Environment Using Hypervisor Watchpoints
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing commercial security technologies, such as ARM TrustZone, are difficult to implement in low-end mobile devices, necessitating a solution to create a trusted execution environment without relying on these technologies.
Innovation Solution
An apparatus is provided that includes a hypervisor to separate regions into privileged and non-privileged areas, utilizing debugging watchpoints and write area execution prevention, with a mode switch unit to ensure secure execution by trapping exceptions and managing region switches.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If ARM TrustZone technology is used to create a trusted execution environment, then security is improved, but device compatibility deteriorates because it cannot be implemented in low-end devices
Solution Approach 1:
The patent copies the essential security functionality of TrustZone by implementing a hypervisor-based trusted execution environment that replicates the secure isolation capabilities without requiring proprietary hardware features. The hypervisor creates a virtual trusted environment that mimics TrustZone's security model using standard virtualization mechanisms.
Solution Approach 2:
The patent makes the trusted execution environment universal by designing it to work across different device types and architectures. The hypervisor implementation provides multi-functional security support that can operate on various hardware platforms without requiring device-specific proprietary features, thus achieving both high security and broad compatibility.
2Reliability
If commercial security technologies are used, then security functionality is improved, but device complexity increases due to proprietary requirements
Solution Approach 1:
The patent enables the system to provide its own security services through the hypervisor implementation. Instead of relying on external proprietary security modules, the hypervisor itself creates and manages the trusted execution environment using standard virtualization features already present in the hardware, thereby reducing overall system complexity while maintaining security functionality.
Solution Approach 2:
The patent extracts the essential security functionality from proprietary commercial solutions and implements it through a standalone hypervisor. By separating the core security mechanisms from device-specific proprietary features, the solution reduces system complexity while preserving the fundamental security capabilities needed for trusted execution.
Data Source
AI summary
The present invention relates to an apparatus for reinforcing security of a mobile trusted execution environment, and relates to an apparatus for reinforcing security of a mobile trusted execution environment for constructing a general-purpose trusted execution environment. According to an embodiment of the present invention, a technology available for a general purpose in a mobile device operating on the basis of an ARM architecture has effects of configuring a trusted execution environment for guaranteeing safe execution of an application without depending on an existing commercial security technology, and of configuring a mobile trusted execution environment by using a write area execution prevention function and a debugging watchpoint, which are general-purpose hardware functions.


