Trusted Execution Environment Audio Verification for Mobile Payment Forgery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing mobile payment security methods are vulnerable to attacks, as attackers can forge password input screens and security prompt information, compromising user data and lacking trustworthiness for special users like the blind.
Innovation Solution
A transaction security processing method that loads a trusted application in a trusted execution environment, plays a unique audio file to verify the trusted environment, and controls the audio output device to prevent unauthorized access, making it difficult for attackers to forge the audio file and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security prompt information is displayed on the password input screen, then user awareness of trusted environment is improved, but the system becomes vulnerable to forgery attacks
Solution Approach 1:
The patent replaces visual security prompts (mechanical/display-based system) with audio prompts based on voiceprint recognition (acoustic system). The terminal device plays a pre-recorded audio file with the user's voiceprint when the password input screen is displayed in a trusted environment. Since voiceprints are biometrically unique and difficult to forge, this substitution maintains security awareness while significantly increasing resistance to forgery attacks.
2Object-affected harmful factors
If audio files are played to verify trusted environment, then attack difficulty is increased, but device complexity increases
Solution Approach 1:
The patent implements preliminary action by pre-recording the user's voiceprint and storing it as an audio file in the trusted execution environment before actual payment operations. When the password input screen is displayed, the system simply plays this pre-prepared audio file rather than performing complex real-time voiceprint analysis. This approach increases attack difficulty while minimizing added system complexity during critical operations.
3Reliability
If audio output device mode is controlled by trusted application, then security is improved, but ease of operation is reduced
Solution Approach 1:
The patent implements dynamic control of the audio output device mode. The trusted application temporarily switches the audio device to a secure mode where only authorized applications can access it during password input operations. After the password input is complete, the system dynamically switches back to the normal mode, allowing other applications to use the audio device. This dynamic approach maintains high security during critical operations while preserving ease of operation for other tasks.
Data Source
AI summary
The technology of this application relates to a transaction security processing method and apparatus, and a terminal device. The method includes receiving, in a rich execution environment (REE), a screen jump instruction triggered by a user in a first screen, where the screen jump instruction is used for jumping to a second screen, and the second screen can be displayed in a trusted execution environment (TEE), and entering the TEE and loading a trusted application (TA) in the TEE. The method further includes obtaining a first audio file from storage space on an REE side and playing the first audio file by using the TA, where the first audio file is used to represent that the terminal device is currently running in a trusted environment, and displaying the second screen generated by using the TA.


