Trusted Execution Environment Confirmation via Display Verification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional methods face challenges in reliably confirming whether an input/output screen is occupied by a Trusted Execution Environment (TEE) in mobile or embedded devices, as methods like LED lighting may not be feasible in all devices and storing secret information can be insecure against malicious access.
Innovation Solution
A confirmation system comprising a display device with a first and second execution environment, where the second environment is more secure, and a verification device that generates and verifies certification information to ensure the display device's authenticity and integrity, allowing users to confirm TEE occupation without dedicated hardware.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a LED lamp is embedded to indicate TEE occupation, then visual confirmation is provided, but device complexity increases and retrofitting becomes difficult
Solution Approach 1:
The patent uses software-based copying of the LED indicator function through virtual display elements. Instead of physical LED hardware, the system creates a software replica that appears on the display screen, providing the same visual confirmation function without physical hardware constraints. This allows any device with a display to indicate TEE occupation status.
Solution Approach 2:
The patent replaces the mechanical/optical LED indicator system with a software-based visual indicator system. The physical LED lamp and its control circuitry are substituted with software code that renders visual indicators on the display screen, eliminating hardware complexity while maintaining the confirmation function.
2Reliability
If secret information is stored to confirm TEE occupation, then confirmation is provided, but security is compromised against malicious access
Solution Approach 1:
The patent extracts the confirmation function from secret information storage and replaces it with publicly visible display information. Instead of relying on hidden secret data that could be stolen, the system displays confirmation indicators that are intentionally visible to users, removing the security vulnerability associated with secret information while maintaining confirmation reliability.
Solution Approach 2:
The patent introduces a trusted verification mechanism as an intermediary between the TEE and the user. Rather than directly exposing secret information or relying on it, the system uses a verification process that produces visible confirmation indicators, mediating the security relationship and allowing users to confirm TEE occupation without accessing sensitive data.
3Device complexity
If no dedicated hardware is used for confirmation, then device complexity is reduced, but confirmation reliability may be compromised
Solution Approach 1:
The patent makes the display screen serve multiple functions: it displays normal application content and simultaneously provides TEE occupation confirmation indicators. The display hardware is already present in modern devices, and the patent adds the confirmation function software-based, making the display universal for both information presentation and security confirmation without requiring dedicated hardware.
Solution Approach 2:
The patent creates software-based copies of hardware indicator functions. By rendering visual indicators through software on the existing display screen, the system replicates the confirmation function of dedicated hardware indicators without requiring the physical hardware, maintaining reliability through software-based verification mechanisms.
Data Source
AI summary
A trusted application (TA) operates on a trusted execution environment (TEE) and generates a screen. Further, the TA transmits certification information for certifying validity of the TA to a verification device. The verification device verifies whether the TA is valid on the basis of the certification information. Further, the verification device authenticates a display device when the validity of the TA is certified and when the verification device is capable of confirming the facts that a picture is being output and that a device outputting the picture is the display device. Further, the verification device outputs a random number code when the display device is authenticated. Further, the verification device transmits the random number code to the display device when the display device is authenticated. Further, the display device receives the random number code from the verification device and displays the same.


