Resource Transfer Verification Using TEE Identity Matching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
When a user's terminal device is lost or stolen, there is a risk of resource theft due to stolen verification information, such as a payment password, allowing thieves to perform unauthorized transactions or data access.
Innovation Solution
Implement a resource transfer method that includes verifying identity feature information using a local device management rule within a trusted execution environment (TEE) to ensure that only authorized users can perform resource transfers, protecting privacy data and preventing unauthorized access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If verification information such as payment passwords is stored locally on the terminal device for quick access, then resource transfer operations become faster and more convenient, but the security risk increases significantly when the device is lost or stolen
Solution Approach 1:
The patent segments verification information into multiple components: identity feature information (stored in TEE), device binding information (stored on server), and dynamic verification codes. This segmentation ensures that no single component contains all verification power, and all components are required together for successful verification, thus maintaining both speed and security
Solution Approach 2:
The patent introduces a trusted execution environment (TEE) as an intermediary component that securely stores and manages verification information on the terminal device. The TEE acts as a secure enclave that protects identity feature information from being accessed by unauthorized applications or processes, enabling fast local verification while maintaining high security standards
2Reliability
If all verification information is stored on the server, then security is improved, but resource transfer operations require more time and network communication
Solution Approach 1:
The patent implements preliminary binding between device information and user identity information during device registration or account setup. This pre-established binding relationship is stored both on the server and in the TEE, enabling rapid local verification without requiring real-time server communication for every transaction, thus reducing operation time while maintaining security
Solution Approach 2:
The terminal device with TEE performs self-verification of identity feature information against device binding information stored locally. This self-service capability allows the device to verify user identity without constant server intervention, significantly reducing operation time while the server maintains the master binding records for periodic synchronization and security oversight
Data Source
AI summary
A resource transfer method includes obtaining, by using a target application, a resource transfer request triggered by a target user, where the resource transfer request includes verification information used to perform resource transfer processing and identity feature information of the target user. By using the target application, verifying the verification information, and invoking, if the verification succeeds by using the target application, a local device management rule, and determining, by using the local device management rule, whether the identity feature information of the target user matches identity feature information of a pre-registered user. If the identity feature information of the target user matches the identity feature information of the pre-registered user, sending the resource transfer request to a first server corresponding to the target application to trigger, based on the resource transfer request, the first server to perform resource transfer processing.


