Resource Transfer Verification Using TEE Identity Matching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

When a user's terminal device is lost or stolen, there is a risk of resource theft due to stolen verification information, such as a payment password, allowing thieves to perform unauthorized transactions or data access.

Innovation Solution

Implement a resource transfer method that includes verifying identity feature information using a local device management rule within a trusted execution environment (TEE) to ensure that only authorized users can perform resource transfers, protecting privacy data and preventing unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If verification information such as payment passwords is stored locally on the terminal device for quick access, then resource transfer operations become faster and more convenient, but the security risk increases significantly when the device is lost or stolen

Engineering Contradiction:
Improveresource transfer operation speedVSAvoidsecurity of verification information
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments verification information into multiple components: identity feature information (stored in TEE), device binding information (stored on server), and dynamic verification codes. This segmentation ensures that no single component contains all verification power, and all components are required together for successful verification, thus maintaining both speed and security

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a trusted execution environment (TEE) as an intermediary component that securely stores and manages verification information on the terminal device. The TEE acts as a secure enclave that protects identity feature information from being accessed by unauthorized applications or processes, enabling fast local verification while maintaining high security standards

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If all verification information is stored on the server, then security is improved, but resource transfer operations require more time and network communication

Engineering Contradiction:
Improvesecurity of verification informationVSAvoidresource transfer operation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary binding between device information and user identity information during device registration or account setup. This pre-established binding relationship is stored both on the server and in the TEE, enabling rapid local verification without requiring real-time server communication for every transaction, thus reducing operation time while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The terminal device with TEE performs self-verification of identity feature information against device binding information stored locally. This self-service capability allows the device to verify user identity without constant server intervention, significantly reducing operation time while the server maintains the master binding records for periodic synchronization and security oversight

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12614178B2Resource transfer methods, apparatuses, and devices
Publication Date: 2026.04.28 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • US12614178B2 patent drawing
  • US12614178B2 patent drawing
  • US12614178B2 patent drawing

AI summary

A resource transfer method includes obtaining, by using a target application, a resource transfer request triggered by a target user, where the resource transfer request includes verification information used to perform resource transfer processing and identity feature information of the target user. By using the target application, verifying the verification information, and invoking, if the verification succeeds by using the target application, a local device management rule, and determining, by using the local device management rule, whether the identity feature information of the target user matches identity feature information of a pre-registered user. If the identity feature information of the target user matches the identity feature information of the pre-registered user, sending the resource transfer request to a first server corresponding to the target application to trigger, based on the resource transfer request, the first server to perform resource transfer processing.