Payment App Isolation via Segmentation and Local Quality

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Payment applications on mobile terminals face security risks due to potential access by malicious applications, and existing security measures can inconvenience users by isolating frequently used applications within the same independent space.

Innovation Solution

A method and apparatus for isolating payment applications into different security levels, allowing trusted applications to invoke payment applications in a first isolation area while keeping financial asset applications completely isolated from other applications in a second area, enhancing security without hindering user convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the payment application is installed in an independent space to prevent asset theft, then security is improved, but user convenience deteriorates because frequently used applications cannot invoke the payment application

Engineering Contradiction:
Improvepayment application securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the independent space into two isolation areas: a first isolation area that allows invocation by trusted applications and a second isolation area that provides complete isolation. This segmentation resolves the contradiction by allowing different security levels for different payment applications based on their invocation requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security attributes to different regions within the independent space. The first isolation area has the quality of being invocable by trusted applications, while the second isolation area has the quality of complete isolation. This local differentiation allows the system to optimize for both security and convenience in appropriate regions.

Inventive Principle:
Principle #3Local quality

2Reliability

If the payment application is completely isolated from other applications, then security is improved, but resource consumption increases due to maintaining unnecessary processes

Engineering Contradiction:
Improvepayment application securityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the isolation mechanism into two types: first isolation area that allows controlled access and second isolation area that provides complete isolation. This enables the system to avoid maintaining processes for applications that don't require complete isolation, thereby reducing resource consumption while maintaining security where needed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent changes the isolation parameter from a single binary state (isolated/not isolated) to a spectrum with at least two levels (first isolation area with invocation permission, second isolation area with complete isolation). This parameter change allows optimization of resource usage by selecting the appropriate isolation level for each payment application.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11762983B2Payment application isolation method and apparatus, and terminal
Publication Date: 2023.09.19 HUAWEI TECH CO LTD
  • US11762983B2 patent drawing
  • US11762983B2 patent drawing
  • US11762983B2 patent drawing

AI summary

A payment application isolation method and apparatus, and a terminal are provided. In the payment application isolation method, a payment application that is selected by a user and that is to be added to an isolation area is obtained; and if the to-be-added payment application has an attribute of being addable to a first isolation area, the to-be-added payment application is added to the first isolation area; or if the to-be-added payment application has an attribute of being addable to a second isolation area, the to-be-added payment application is added to the second isolation area. A payment application added to the first isolation area has an attribute of being invocable by a trusted application installed outside the first isolation area, and a payment application added to the second isolation area has an attribute of being completely isolated from an application installed outside the second isolation area.