Trusted Execution Environment Audio Verification for Mobile Payment Forgery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing mobile payment security methods are vulnerable to attacks, as attackers can forge password input screens and security prompt information, compromising user data and lacking trustworthiness for special users like the blind.

Innovation Solution

A transaction security processing method that loads a trusted application in a trusted execution environment, plays a unique audio file to verify the trusted environment, and controls the audio output device to prevent unauthorized access, making it difficult for attackers to forge the audio file and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security prompt information is displayed on the password input screen, then user awareness of trusted environment is improved, but the system becomes vulnerable to forgery attacks

Engineering Contradiction:
Improveuser awareness of trusted environmentVSAvoidvulnerability to forgery attacks
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces visual security prompts (mechanical/display-based system) with audio prompts based on voiceprint recognition (acoustic system). The terminal device plays a pre-recorded audio file with the user's voiceprint when the password input screen is displayed in a trusted environment. Since voiceprints are biometrically unique and difficult to forge, this substitution maintains security awareness while significantly increasing resistance to forgery attacks.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Object-affected harmful factors

If audio files are played to verify trusted environment, then attack difficulty is increased, but device complexity increases

Engineering Contradiction:
Improveattack difficultyVSAvoidsystem complexity
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-recording the user's voiceprint and storing it as an audio file in the trusted execution environment before actual payment operations. When the password input screen is displayed, the system simply plays this pre-prepared audio file rather than performing complex real-time voiceprint analysis. This approach increases attack difficulty while minimizing added system complexity during critical operations.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If audio output device mode is controlled by trusted application, then security is improved, but ease of operation is reduced

Engineering Contradiction:
ImprovesecurityVSAvoidaudio device accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements dynamic control of the audio output device mode. The trusted application temporarily switches the audio device to a secure mode where only authorized applications can access it during password input operations. After the password input is complete, the system dynamically switches back to the normal mode, allowing other applications to use the audio device. This dynamic approach maintains high security during critical operations while preserving ease of operation for other tasks.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12001596B2Transaction security processing method and apparatus, and terminal device for using a trusted application in association with an audio file
Publication Date: 2024.06.04 HUAWEI TECH CO LTD
  • US12001596B2 patent drawing
  • US12001596B2 patent drawing
  • US12001596B2 patent drawing

AI summary

The technology of this application relates to a transaction security processing method and apparatus, and a terminal device. The method includes receiving, in a rich execution environment (REE), a screen jump instruction triggered by a user in a first screen, where the screen jump instruction is used for jumping to a second screen, and the second screen can be displayed in a trusted execution environment (TEE), and entering the TEE and loading a trusted application (TA) in the TEE. The method further includes obtaining a first audio file from storage space on an REE side and playing the first audio file by using the TA, where the first audio file is used to represent that the terminal device is currently running in a trusted environment, and displaying the second screen generated by using the TA.