Secure Runtime Environment Offloading to Server

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The existing secure runtime environments in mobile terminals are difficult to handle and manage due to limited secure resources and the need for individual adaptations for each device type, limiting the execution of complex applications and reducing the acceptance of security operating systems.

Innovation Solution

A terminal system that includes a security server to create a virtual secure runtime environment, connected to the end device via a secure channel, allowing applications to run on the server and appear as if they are running on the device, thus overcoming resource limitations and simplifying adaptations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure runtime environment is implemented in a mobile terminal with limited memory resources, then security functions are provided, but complex applications cannot run due to insufficient memory

Engineering Contradiction:
Improvesecurity function provisionVSAvoidapplication execution capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extends the secure runtime environment from the local mobile terminal to a remote server environment. By creating a virtual secure runtime environment on a server that is accessible via secure channel to the terminal, the system provides another dimensional space for secure application execution, thereby overcoming the terminal's memory limitations while maintaining security guarantees.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces a server as an intermediary between the mobile terminal and the secure runtime environment. The server hosts the virtual secure runtime environment and manages secure applications, acting as a mediator that allows terminals with limited resources to access comprehensive security functions without being constrained by their own hardware limitations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If secure runtime environments are adapted for each terminal device type, then security is guaranteed, but the effort and complexity of adaptation increases significantly

Engineering Contradiction:
Improvesecurity guaranteeVSAvoidadaptation effort
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent creates a universal secure runtime environment on the server that can serve multiple different terminal device types simultaneously. Instead of adapting the secure runtime environment to each specific terminal type, the server-based approach provides a single adaptable platform that works with various terminals through standardized secure communication channels, thereby reducing overall adaptation effort.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent inverts the traditional adaptation approach by not adapting the secure runtime environment to each terminal, but rather adapting the terminal interface to connect to a standardized server-based secure runtime environment. This reversal of the adaptation direction significantly reduces the complexity and effort required.

Inventive Principle:
Principle #13The other way round (Inversion)

3Reliability

If applications are specially developed and certified for the security operating system, then security functions are available, but the number of available applications is limited

Engineering Contradiction:
Improvesecurity function availabilityVSAvoidapplication variety
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent allows applications to be developed once for the server-based secure runtime environment and then made available to multiple terminals. The server acts as a central repository and distribution point, copying and delivering applications to various terminals that need them, thereby increasing application variety without requiring separate development for each terminal type.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent merges the application development and certification process with the server infrastructure. By combining the secure runtime environment with a centralized application management system on the server, the patent creates a unified platform where applications can be developed, certified, stored, and distributed together, increasing versatility while maintaining security standards.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP2863605B1Mobile end device system with safety operation system
Publication Date: 2018.03.28 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • EP2863605B1 patent drawingFigure 1
  • EP2863605B1 patent drawingFigure 2
  • EP2863605B1 patent drawingFigure 3

AI summary

The invention provides an end-device system comprising a mobile end device (A) in which a security operating system (E) is implemented, under whose control a secure runtime environment (E, TEE) can be created in the end device (A). It includes: - a security server (D) on which a server security operating system is implemented, under whose control a virtual secure runtime environment can be created on the security server (D), - a secure channel (F) via which the virtual secure runtime environment of the security server (D) can be transferred to the secure runtime environment of the end device (A), and - an overlay device with which the virtual secure runtime environment of the security server (D) can be overlaid into the secure runtime environment of the end device (A), so that the virtual runtime environment actually created on the security server (D) appears as if it were created on the end device (A).