Secure Runtime Environment Offloading to Server
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing secure runtime environments in mobile terminals are difficult to handle and manage due to limited secure resources and the need for individual adaptations for each device type, limiting the execution of complex applications and reducing the acceptance of security operating systems.
Innovation Solution
A terminal system that includes a security server to create a virtual secure runtime environment, connected to the end device via a secure channel, allowing applications to run on the server and appear as if they are running on the device, thus overcoming resource limitations and simplifying adaptations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a secure runtime environment is implemented in a mobile terminal with limited memory resources, then security functions are provided, but complex applications cannot run due to insufficient memory
Solution Approach 1:
The patent extends the secure runtime environment from the local mobile terminal to a remote server environment. By creating a virtual secure runtime environment on a server that is accessible via secure channel to the terminal, the system provides another dimensional space for secure application execution, thereby overcoming the terminal's memory limitations while maintaining security guarantees.
Solution Approach 2:
The patent introduces a server as an intermediary between the mobile terminal and the secure runtime environment. The server hosts the virtual secure runtime environment and manages secure applications, acting as a mediator that allows terminals with limited resources to access comprehensive security functions without being constrained by their own hardware limitations.
2Reliability
If secure runtime environments are adapted for each terminal device type, then security is guaranteed, but the effort and complexity of adaptation increases significantly
Solution Approach 1:
The patent creates a universal secure runtime environment on the server that can serve multiple different terminal device types simultaneously. Instead of adapting the secure runtime environment to each specific terminal type, the server-based approach provides a single adaptable platform that works with various terminals through standardized secure communication channels, thereby reducing overall adaptation effort.
Solution Approach 2:
The patent inverts the traditional adaptation approach by not adapting the secure runtime environment to each terminal, but rather adapting the terminal interface to connect to a standardized server-based secure runtime environment. This reversal of the adaptation direction significantly reduces the complexity and effort required.
3Reliability
If applications are specially developed and certified for the security operating system, then security functions are available, but the number of available applications is limited
Solution Approach 1:
The patent allows applications to be developed once for the server-based secure runtime environment and then made available to multiple terminals. The server acts as a central repository and distribution point, copying and delivering applications to various terminals that need them, thereby increasing application variety without requiring separate development for each terminal type.
Solution Approach 2:
The patent merges the application development and certification process with the server infrastructure. By combining the secure runtime environment with a centralized application management system on the server, the patent creates a unified platform where applications can be developed, certified, stored, and distributed together, increasing versatility while maintaining security standards.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The invention provides an end-device system comprising a mobile end device (A) in which a security operating system (E) is implemented, under whose control a secure runtime environment (E, TEE) can be created in the end device (A). It includes: - a security server (D) on which a server security operating system is implemented, under whose control a virtual secure runtime environment can be created on the security server (D), - a secure channel (F) via which the virtual secure runtime environment of the security server (D) can be transferred to the secure runtime environment of the end device (A), and - an overlay device with which the virtual secure runtime environment of the security server (D) can be overlaid into the secure runtime environment of the end device (A), so that the virtual runtime environment actually created on the security server (D) appears as if it were created on the end device (A).