Smartphone Identity Verification Using Trusted Execution Environment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing identity verification and transaction systems on smartphones are vulnerable to malware attacks and identity theft, particularly concerning Personal Identifiable Information (PII) and dynamic information like Credit Card Numbers, which can lead to financial fraud and compromised transaction security.
Innovation Solution
A 3-step verification process that separates user authentication from service-centric authorization, utilizing a Trusted Execution Environment (TEE) for secure data transfer and obfuscated code execution, along with context-sensitive identification and dynamic binding of identity attributes to proprietary smartphone identifiers, ensuring secure transactions without relying on the smartphone's OS environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If user authentication is performed using traditional smartphone applications, then ease of operation is improved, but security against malware attacks deteriorates
Solution Approach 1:
The authentication system is segmented into two independent parts: a trusted component stored in the secure element (immutable authentication logic) and a service application layer (variable service logic). This segmentation isolates the critical security functions from malware-prone environments, allowing ease of operation through service apps while maintaining security through the protected secure element.
Solution Approach 2:
The secure element acts as an intermediary between the user and the service application. It mediates authentication by holding the trusted authentication logic and verifying user identity without exposing the authentication mechanism to the potentially compromised service application layer, thus resolving the contradiction between operational ease and security.
2Ease of operation
If Personal Identifiable Information is stored on smartphone for transactions, then ease of operation is improved, but vulnerability to identity theft increases
Solution Approach 1:
The critical authentication data is extracted from the vulnerable smartphone application environment and placed into the protected secure element. This extraction removes the vulnerability to identity theft while preserving ease of operation, as the secure element automatically handles authentication without requiring users to manage sensitive information.
Solution Approach 2:
The system uses disposable session tokens and temporary authentication credentials generated by the secure element for each transaction. These short-living objects replace persistent storage of sensitive PII, reducing identity theft risk while maintaining operational convenience through automatic token management.
3Adaptability or versatility
If dynamic identity information is used for transactions, then adaptability is improved, but risk of data modification by malware increases
Solution Approach 1:
The system segments identity information into static authentication credentials (stored securely and immutable) and dynamic service parameters (handled by the service application). This allows adaptability through dynamic service parameters while protecting against malware modification by isolating the critical authentication portion in the secure element.
4Measurement precision
If imaging device is used for identity verification, then measurement precision is improved, but device complexity increases
Solution Approach 1:
The secure element performs self-service authentication by automatically capturing and verifying biometric data without requiring complex external imaging devices. The secure element's integrated sensors and processing provide sufficient measurement precision while minimizing device complexity, as the authentication function is built into the trusted hardware module.
Data Source
AI summary
The present invention enables secure identification, transactions or access using smartphones. The present invention presents a method and a system for secure identification, transaction and access, comprising an interaction between a user; a smartphone of the user; a software application, enabling the user to communicate with a Relying-Party-Service-Provider and; an Identity-Management-as-a-Service, performing identity verification of the user, using software application; and a Relying-Party-Service-Provider, performing transaction and access of the user. Relying-Party-Service-Provider may be one of the group consisting of Banks, Financial Services, Online Shops, Online Voting, Enterprise Websites, Smart Home, Mobile and Web applications.


