Smartphone Identity Verification Using Trusted Execution Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing identity verification and transaction systems on smartphones are vulnerable to malware attacks and identity theft, particularly concerning Personal Identifiable Information (PII) and dynamic information like Credit Card Numbers, which can lead to financial fraud and compromised transaction security.

Innovation Solution

A 3-step verification process that separates user authentication from service-centric authorization, utilizing a Trusted Execution Environment (TEE) for secure data transfer and obfuscated code execution, along with context-sensitive identification and dynamic binding of identity attributes to proprietary smartphone identifiers, ensuring secure transactions without relying on the smartphone's OS environment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If user authentication is performed using traditional smartphone applications, then ease of operation is improved, but security against malware attacks deteriorates

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication system is segmented into two independent parts: a trusted component stored in the secure element (immutable authentication logic) and a service application layer (variable service logic). This segmentation isolates the critical security functions from malware-prone environments, allowing ease of operation through service apps while maintaining security through the protected secure element.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The secure element acts as an intermediary between the user and the service application. It mediates authentication by holding the trusted authentication logic and verifying user identity without exposing the authentication mechanism to the potentially compromised service application layer, thus resolving the contradiction between operational ease and security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If Personal Identifiable Information is stored on smartphone for transactions, then ease of operation is improved, but vulnerability to identity theft increases

Engineering Contradiction:
Improveease of operationVSAvoididentity theft
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The critical authentication data is extracted from the vulnerable smartphone application environment and placed into the protected secure element. This extraction removes the vulnerability to identity theft while preserving ease of operation, as the secure element automatically handles authentication without requiring users to manage sensitive information.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system uses disposable session tokens and temporary authentication credentials generated by the secure element for each transaction. These short-living objects replace persistent storage of sensitive PII, reducing identity theft risk while maintaining operational convenience through automatic token management.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Adaptability or versatility

If dynamic identity information is used for transactions, then adaptability is improved, but risk of data modification by malware increases

Engineering Contradiction:
ImproveadaptabilityVSAvoiddata modification
Core Design Contradiction:
Adaptability or versatilityVSObject-generated harmful factors

Solution Approach 1:

The system segments identity information into static authentication credentials (stored securely and immutable) and dynamic service parameters (handled by the service application). This allows adaptability through dynamic service parameters while protecting against malware modification by isolating the critical authentication portion in the secure element.

Inventive Principle:
Principle #1Segmentation

4Measurement precision

If imaging device is used for identity verification, then measurement precision is improved, but device complexity increases

Engineering Contradiction:
Improveidentity verification accuracyVSAvoiddevice complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The secure element performs self-service authentication by automatically capturing and verifying biometric data without requiring complex external imaging devices. The secure element's integrated sensors and processing provide sufficient measurement precision while minimizing device complexity, as the authentication function is built into the trusted hardware module.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11044604B2Method and system for protecting and utilizing internet identity, using smartphone
Publication Date: 2021.06.22 TALMOR ELI
  • US11044604B2 patent drawing
  • US11044604B2 patent drawing
  • US11044604B2 patent drawing

AI summary

The present invention enables secure identification, transactions or access using smartphones. The present invention presents a method and a system for secure identification, transaction and access, comprising an interaction between a user; a smartphone of the user; a software application, enabling the user to communicate with a Relying-Party-Service-Provider and; an Identity-Management-as-a-Service, performing identity verification of the user, using software application; and a Relying-Party-Service-Provider, performing transaction and access of the user. Relying-Party-Service-Provider may be one of the group consisting of Banks, Financial Services, Online Shops, Online Voting, Enterprise Websites, Smart Home, Mobile and Web applications.