Trusted Execution Environment Confirmation via Display Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional methods face challenges in reliably confirming whether an input/output screen is occupied by a Trusted Execution Environment (TEE) in mobile or embedded devices, as methods like LED lighting may not be feasible in all devices and storing secret information can be insecure against malicious access.

Innovation Solution

A confirmation system comprising a display device with a first and second execution environment, where the second environment is more secure, and a verification device that generates and verifies certification information to ensure the display device's authenticity and integrity, allowing users to confirm TEE occupation without dedicated hardware.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a LED lamp is embedded to indicate TEE occupation, then visual confirmation is provided, but device complexity increases and retrofitting becomes difficult

Engineering Contradiction:
Improveconfirmation reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent uses software-based copying of the LED indicator function through virtual display elements. Instead of physical LED hardware, the system creates a software replica that appears on the display screen, providing the same visual confirmation function without physical hardware constraints. This allows any device with a display to indicate TEE occupation status.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces the mechanical/optical LED indicator system with a software-based visual indicator system. The physical LED lamp and its control circuitry are substituted with software code that renders visual indicators on the display screen, eliminating hardware complexity while maintaining the confirmation function.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If secret information is stored to confirm TEE occupation, then confirmation is provided, but security is compromised against malicious access

Engineering Contradiction:
Improveconfirmation reliabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the confirmation function from secret information storage and replaces it with publicly visible display information. Instead of relying on hidden secret data that could be stolen, the system displays confirmation indicators that are intentionally visible to users, removing the security vulnerability associated with secret information while maintaining confirmation reliability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a trusted verification mechanism as an intermediary between the TEE and the user. Rather than directly exposing secret information or relying on it, the system uses a verification process that produces visible confirmation indicators, mediating the security relationship and allowing users to confirm TEE occupation without accessing sensitive data.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Device complexity

If no dedicated hardware is used for confirmation, then device complexity is reduced, but confirmation reliability may be compromised

Engineering Contradiction:
Improvedevice complexityVSAvoidconfirmation reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent makes the display screen serve multiple functions: it displays normal application content and simultaneously provides TEE occupation confirmation indicators. The display hardware is already present in modern devices, and the patent adds the confirmation function software-based, making the display universal for both information presentation and security confirmation without requiring dedicated hardware.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent creates software-based copies of hardware indicator functions. By rendering visual indicators through software on the existing display screen, the system replicates the confirmation function of dedicated hardware indicators without requiring the physical hardware, maintaining reliability through software-based verification mechanisms.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11550894B2Confirmation system and confirmation method
Publication Date: 2023.01.10 NIPPON TELEGRAPH & TELEPHONE CORP
  • US11550894B2 patent drawing
  • US11550894B2 patent drawing
  • US11550894B2 patent drawing

AI summary

A trusted application (TA) operates on a trusted execution environment (TEE) and generates a screen. Further, the TA transmits certification information for certifying validity of the TA to a verification device. The verification device verifies whether the TA is valid on the basis of the certification information. Further, the verification device authenticates a display device when the validity of the TA is certified and when the verification device is capable of confirming the facts that a picture is being output and that a device outputting the picture is the display device. Further, the verification device outputs a random number code when the display device is authenticated. Further, the verification device transmits the random number code to the display device when the display device is authenticated. Further, the display device receives the random number code from the verification device and displays the same.