Multi-Container Trusted Application Processing Method

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing trusted execution environment (TEE) technology has limitations that lead to complex and inefficient trusted application development and deployment processes, requiring close coupling between TA developers and terminal vendors, which increases security risks and costs.

Innovation Solution

A multi-container-based trusted application processing method is introduced, which includes performing integrity and validity checks on signed security computation units using a security computation container, thereby isolating the main container from the TEE and improving security and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a TEE is used to isolate high-security applications from the REE, then security is improved, but the complexity of trusted application development and deployment increases due to coupling between TA developers and terminal vendors

Engineering Contradiction:
ImprovesecurityVSAvoidtrusted application development and deployment process
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the trusted application development process by introducing a standardized interface layer between the REE and TEE. This segmentation allows TA developers to work independently using standard APIs, while terminal vendors implement the TEE according to standard specifications, thereby reducing coupling and development complexity while maintaining security isolation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent establishes a universal interface standard that enables multiple TEE implementations from different vendors to work with trusted applications developed by any TA developer. This universality allows a single TA to be deployed across different terminal types and TEE implementations, reducing development complexity while preserving the security benefits of TEE isolation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If strict security verification specifications are enforced for TA deployment in TEE/SE, then security is improved, but TA processing efficiency decreases due to complex verification processes

Engineering Contradiction:
ImprovesecurityVSAvoidtrusted application processing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements preliminary security verification by establishing certification mechanisms during the TA development and packaging phase. Security attributes and verification data are prepared in advance, allowing the TEE to perform faster validation checks during deployment rather than conducting complex verification processes in real-time, thus improving processing efficiency while maintaining security.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If TEE distributors and TA developers work in close coupling to ensure security, then security is improved, but costs and time consumption increase

Engineering Contradiction:
ImprovesecurityVSAvoiddevelopment and deployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces standardized interfaces and certification bodies as intermediaries between TEE distributors and TA developers. These intermediaries facilitate secure collaboration by providing standardized communication protocols and verification mechanisms, reducing the need for direct tight coupling between vendors and developers, thereby reducing time consumption and costs while maintaining security.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3686762B1Multi-container-based trusted application processing method, and related device
Publication Date: 2025.01.22 HUAWEI TECH CO LTD
  • EP3686762B1 patent drawingFigure 1
  • EP3686762B1 patent drawingFigure 2
  • EP3686762B1 patent drawingFigure 3

AI summary

This application discloses a multi-container-based trusted application processing method and a related device, to simplify a trusted application development and deployment process, and improve trusted application processing efficiency and security of an access interface of a trusted execution environment. The method of this application includes: performing, by a terminal, an integrity check on a signed security computation unit by using a security computation container; if the signed security computation unit succeeds in the integrity check, performing, by the terminal, a validity check on the signed security computation unit by using the security computation container, and obtaining a check result; and if the check result is valid, loading, by the terminal, the signed security computation unit by using a trusted execution environment TEE or a secure element SE, and obtaining a security computation result of a trusted application.