TEE Biometric Signature Processing for Secure Service Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current service processing systems rely fully on verification success results from terminals, which can be compromised by hackers, leading to security vulnerabilities, especially when terminals are cracked, allowing unauthorized transactions without biometric verification.

Innovation Solution

Implementing a method where terminals use a Trusted Execution Environment (TEE) to verify biometric information and perform signature processing on signature information using pre-stored private keys, and then transmit this information to a service server for verification, ensuring that only successful biometric matches trigger service processing, thereby enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal fully trusts verification success results from the terminal, then the service processing is simple and fast, but the security is compromised when the terminal is cracked

Engineering Contradiction:
ImprovesecurityVSAvoidverification process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a TEE (Trusted Execution Environment) as an intermediary component within the terminal. The TEE acts as a secure mediator that independently verifies biometric information and generates signature information, separating the trust verification function from the main terminal system. This allows the service server to trust the TEE-generated signatures without fully trusting the terminal's general verification results, thus improving security while maintaining a relatively simple verification process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the terminal system into two distinct parts: the general terminal system and the secure TEE environment. The TEE is isolated from the main system and handles only the critical biometric verification and signature generation functions. This segmentation ensures that even if the main terminal system is compromised, the TEE remains secure and can still provide reliable verification, thus improving overall system security.

Inventive Principle:
Principle #1Segmentation

2Reliability

If the service private key is stored in the terminal for signature processing, then the verification security is enhanced, but the terminal becomes more vulnerable to key extraction attacks

Engineering Contradiction:
Improveverification securityVSAvoidkey extraction risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The TEE serves as a secure intermediary that stores and manages the service private key. Instead of storing the key in the general terminal system where it could be extracted by hackers, the key is kept within the isolated TEE environment. The TEE processes the signature information using the private key and returns only the signature result to the main system, never exposing the key itself. This intermediary approach enhances verification security while protecting against key extraction attacks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies local quality by creating a specially secured environment (TEE) with different security properties than the rest of the terminal. Within this local secure zone, the private key is stored and processed under strict security controls. The TEE has isolated memory spaces and execution environments that prevent unauthorized access, thus protecting the key from extraction while allowing signature processing to occur.

Inventive Principle:
Principle #3Local quality

3Reliability

If biometric verification is performed through the TEE system with signature processing, then unauthorized transactions are prevented, but the processing time and complexity increase

Engineering Contradiction:
Improvetransaction securityVSAvoidverification processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The TEE performs biometric verification and signature generation as preliminary actions before the main service processing occurs. The biometric data is verified and the signature is generated in advance within the secure environment, so that when the service server receives the signature information, the verification is already complete. This preliminary action within the TEE prevents unauthorized transactions while minimizing the time impact on the overall service flow, as the security-critical operations are handled efficiently in the isolated environment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3402154B1Service processing method, device, and system
Publication Date: 2022.07.06 TENCENT TECHNOLOGY (SHENZHEN) CO LTD
  • EP3402154B1 patent drawingFigure 1A
  • EP3402154B1 patent drawingFigure 1B~2
  • EP3402154B1 patent drawingFigure 3

AI summary

The present disclosure relates to a service processing method, a service processing device and a service processing system, which belong to computer technologies. The method includes: a service execution request is transmitted to a service server; a verification notification carrying signature information is received from the service server; currently inputted biometric feature information is verified through a Trusted Execution Environment (TEE) system, when biometric feature information is consistent with pre-stored reference biometric feature information, a signature processing is performed on signature information, by using a pre-stored service private key, first to-be-checked signature information is obtained; and a verification request carrying first to-be-checked signature information is transmitted to the service server. By adopting the present disclosure, security may be enhanced.