Payment App Isolation via Segmentation and Local Quality
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Payment applications on mobile terminals face security risks due to potential access by malicious applications, and existing security measures can inconvenience users by isolating frequently used applications within the same independent space.
Innovation Solution
A method and apparatus for isolating payment applications into different security levels, allowing trusted applications to invoke payment applications in a first isolation area while keeping financial asset applications completely isolated from other applications in a second area, enhancing security without hindering user convenience.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the payment application is installed in an independent space to prevent asset theft, then security is improved, but user convenience deteriorates because frequently used applications cannot invoke the payment application
Solution Approach 1:
The patent divides the independent space into two isolation areas: a first isolation area that allows invocation by trusted applications and a second isolation area that provides complete isolation. This segmentation resolves the contradiction by allowing different security levels for different payment applications based on their invocation requirements.
Solution Approach 2:
The patent applies different security attributes to different regions within the independent space. The first isolation area has the quality of being invocable by trusted applications, while the second isolation area has the quality of complete isolation. This local differentiation allows the system to optimize for both security and convenience in appropriate regions.
2Reliability
If the payment application is completely isolated from other applications, then security is improved, but resource consumption increases due to maintaining unnecessary processes
Solution Approach 1:
The patent segments the isolation mechanism into two types: first isolation area that allows controlled access and second isolation area that provides complete isolation. This enables the system to avoid maintaining processes for applications that don't require complete isolation, thereby reducing resource consumption while maintaining security where needed.
Solution Approach 2:
The patent changes the isolation parameter from a single binary state (isolated/not isolated) to a spectrum with at least two levels (first isolation area with invocation permission, second isolation area with complete isolation). This parameter change allows optimization of resource usage by selecting the appropriate isolation level for each payment application.
Data Source
AI summary
A payment application isolation method and apparatus, and a terminal are provided. In the payment application isolation method, a payment application that is selected by a user and that is to be added to an isolation area is obtained; and if the to-be-added payment application has an attribute of being addable to a first isolation area, the to-be-added payment application is added to the first isolation area; or if the to-be-added payment application has an attribute of being addable to a second isolation area, the to-be-added payment application is added to the second isolation area. A payment application added to the first isolation area has an attribute of being invocable by a trusted application installed outside the first isolation area, and a payment application added to the second isolation area has an attribute of being completely isolated from an application installed outside the second isolation area.


