OP-TEE Trusted Application Chain for Secure Cross-OS Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing OP-TEE systems face issues with secure data accessibility being exploited by malicious software applications and the difficulty in preloading securely encrypted files due to new keys being created at boot up, compromising the integrity of trusted data and file storage.

Innovation Solution

A chain of trust is established between software applications and the OP-TEE OS, leveraging OP-TEE for secure key management and inter-process communication, with keys injected into the OS to authenticate applications and preload secure storage with encrypted files, using cryptographic signatures and secure boot processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If OP-TEE APIs are made accessible to all software applications, then data accessibility is improved, but security is worsened due to exploitation by malicious applications

Engineering Contradiction:
Improvedata accessibilityVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces a Trusted Application (TA) as an intermediary layer between untrusted Linux applications and the OP-TEE secure storage. The TA acts as a mediator that authenticates applications and manages secure access to encrypted files, preventing direct access by malicious applications while maintaining ease of use for authenticated applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication and authorization actions before allowing access to secure data. Applications must be authenticated and authorized by the TA before they can access OP-TEE storage, ensuring that only trusted applications can access secure data while maintaining operational ease.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If keys are created at boot up, then secure storage is established, but file preloading is difficult

Engineering Contradiction:
Improvesecure storageVSAvoidfile preloading
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent uses preliminary action by creating a default Trusted Application at boot time that automatically handles file preloading. This TA is pre-configured to decrypt and load encrypted files into secure storage before they are needed, eliminating the manual preloading difficulty while maintaining secure storage reliability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service by enabling the system to automatically manage key creation, authentication, and file preloading without manual intervention. The default TA at boot time automatically sets up secure storage and preloads files, making the process seamless and eliminating the need for manual configuration.

Inventive Principle:
Principle #25Self-service

3Adaptability or versatility

If unauthenticated applications can access OP-TEE APIs, then system versatility is improved, but trust integrity is worsened

Engineering Contradiction:
Improveapplication compatibilityVSAvoidtrust integrity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a Trusted Application as an intermediary layer that all applications must pass through to access secure storage. This mediator maintains versatility by allowing any application to attempt access while protecting trust integrity by authenticating each application before allowing access to secure data.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication action before allowing any access to OP-TEE storage. Unauthenticated applications are blocked at this preliminary stage, while authenticated applications can proceed to access secure data, thus maintaining both versatility and trust integrity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12423431B2Establishing trust between applications in a computing environment
Publication Date: 2025.09.23 THE ADT SECURITY CORPORATION
  • US12423431B2 patent drawing
  • US12423431B2 patent drawing
  • US12423431B2 patent drawing

AI summary

A method, system and device are disclosed. A premises device comprising a first operating system and a second operating system is described. The premises device comprises processing circuitry configured to establish a chain of trust at least between the first operating system and at least one software application associated with the second operating system. The processing circuitry is further configured to perform at least one action based at least in part on the established chain of trust.