TEE Biometric Signature Processing for Secure Service Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current service processing systems rely fully on verification success results from terminals, which can be compromised by hackers, leading to security vulnerabilities, especially when terminals are cracked, allowing unauthorized transactions without biometric verification.
Innovation Solution
Implementing a method where terminals use a Trusted Execution Environment (TEE) to verify biometric information and perform signature processing on signature information using pre-stored private keys, and then transmit this information to a service server for verification, ensuring that only successful biometric matches trigger service processing, thereby enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the terminal fully trusts verification success results from the terminal, then the service processing is simple and fast, but the security is compromised when the terminal is cracked
Solution Approach 1:
The patent introduces a TEE (Trusted Execution Environment) as an intermediary component within the terminal. The TEE acts as a secure mediator that independently verifies biometric information and generates signature information, separating the trust verification function from the main terminal system. This allows the service server to trust the TEE-generated signatures without fully trusting the terminal's general verification results, thus improving security while maintaining a relatively simple verification process.
Solution Approach 2:
The patent segments the terminal system into two distinct parts: the general terminal system and the secure TEE environment. The TEE is isolated from the main system and handles only the critical biometric verification and signature generation functions. This segmentation ensures that even if the main terminal system is compromised, the TEE remains secure and can still provide reliable verification, thus improving overall system security.
2Reliability
If the service private key is stored in the terminal for signature processing, then the verification security is enhanced, but the terminal becomes more vulnerable to key extraction attacks
Solution Approach 1:
The TEE serves as a secure intermediary that stores and manages the service private key. Instead of storing the key in the general terminal system where it could be extracted by hackers, the key is kept within the isolated TEE environment. The TEE processes the signature information using the private key and returns only the signature result to the main system, never exposing the key itself. This intermediary approach enhances verification security while protecting against key extraction attacks.
Solution Approach 2:
The patent applies local quality by creating a specially secured environment (TEE) with different security properties than the rest of the terminal. Within this local secure zone, the private key is stored and processed under strict security controls. The TEE has isolated memory spaces and execution environments that prevent unauthorized access, thus protecting the key from extraction while allowing signature processing to occur.
3Reliability
If biometric verification is performed through the TEE system with signature processing, then unauthorized transactions are prevented, but the processing time and complexity increase
Solution Approach 1:
The TEE performs biometric verification and signature generation as preliminary actions before the main service processing occurs. The biometric data is verified and the signature is generated in advance within the secure environment, so that when the service server receives the signature information, the verification is already complete. This preliminary action within the TEE prevents unauthorized transactions while minimizing the time impact on the overall service flow, as the security-critical operations are handled efficiently in the isolated environment.
Data Source
Figure 1A
Figure 1B~2
Figure 3
AI summary
The present disclosure relates to a service processing method, a service processing device and a service processing system, which belong to computer technologies. The method includes: a service execution request is transmitted to a service server; a verification notification carrying signature information is received from the service server; currently inputted biometric feature information is verified through a Trusted Execution Environment (TEE) system, when biometric feature information is consistent with pre-stored reference biometric feature information, a signature processing is performed on signature information, by using a pre-stored service private key, first to-be-checked signature information is obtained; and a verification request carrying first to-be-checked signature information is transmitted to the service server. By adopting the present disclosure, security may be enhanced.