Service Authentication Using Server-Relocated Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional offline payment systems require a trusted execution environment on both user and merchant terminals, which hinders the advancement and promotion of mobile payment services due to the need for specialized hardware and additional security modules.

Innovation Solution

A method and apparatus for service authentication that involves a service initiating terminal and a service authorization terminal, where service information is sent and a service authorization code is generated based on user information, allowing the service initiating terminal to generate authentication information and upload it to a server for processing, eliminating the need for a trusted environment on the terminals.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trusted execution environment is simulated on user and merchant terminals to ensure payment security, then security is improved, but device complexity and hardware requirements increase

Engineering Contradiction:
Improvepayment securityVSAvoidterminal hardware requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the trusted execution environment requirement from the terminal devices and relocates it to the server. The server generates authentication codes and verifies service authenticity, while terminals only perform basic communication functions. This extraction eliminates the need for complex hardware security modules on user and merchant terminals, resolving the contradiction between payment security and device complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If specialized security modules are added to terminals to create a trusted environment, then authentication reliability is improved, but ease of operation and service promotion are worsened

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidservice promotion
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent makes the authentication system universal by allowing any standard NFC-enabled terminal to participate in secure payments without requiring specialized security hardware. The server handles all complex authentication logic, making the system accessible to general consumer devices and facilitating widespread service adoption while maintaining high security standards.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a trusted execution environment is implemented on terminals, then service security is improved, but the quantity and type of required components increase

Engineering Contradiction:
Improveservice securityVSAvoidsecurity modules
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the authentication functionality into the server infrastructure, combining security verification, code generation, and service validation into a centralized system. This consolidation eliminates the need for separate security modules on each terminal, reducing the total quantity of security components required while maintaining or enhancing overall service security through centralized control.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentEP3843022A1Method and apparatus for service authentication
Publication Date: 2021.06.30 ADVANCED NEW TECHNOLOGIES CO LTD
  • EP3843022A1 patent drawingFigure 1
  • EP3843022A1 patent drawingFigure 2
  • EP3843022A1 patent drawingFigure 3~4

AI summary

An apparatus and method allowing authentication of a service using a service initiating terminal and a service authorization terminal. The method includes sending, by the service initiating terminal, service information to the service authorization terminal, receiving, by the service initiating terminal, a service authorization code corresponding to the service information sent by the service authorization terminal. The method also includes generating, by the service initiating terminal, service authorization information according to the service information and the service authorization code, and uploading the service authentication information to a server for processing the service after authenticating the service authorization code.