Trusted Execution Environment Secure Data Transmission

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current secure communication methods between devices via trusted execution environments do not effectively prevent external access to sensitive information during data transmission, lacking a comprehensive solution for secure data encryption and authentication.

Innovation Solution

The method involves controlling hardware components from a trusted execution environment, encrypting user inputs within this environment, and transmitting encrypted data through a connectivity application to a rich environment, where it is decrypted only upon successful authentication, ensuring secure access and preventing external interference.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If data is transmitted through the rich environment, then communication flexibility is improved, but security against external access deteriorates

Engineering Contradiction:
Improvecommunication flexibilityVSAvoidexternal access to sensitive information
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the communication process into two segments: encryption/decryption operations occur in the secure trusted execution environment, while data transmission occurs in the rich environment. This segmentation allows flexible communication in the rich environment while maintaining security through isolation of critical operations in the trusted environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted execution environment acts as an intermediary between the rich environment applications and the sensitive data. All data passing through the rich environment must be encrypted by the trusted environment before transmission and can only be decrypted by the receiving trusted environment, preventing external access while maintaining communication flexibility.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If encryption is applied within the trusted execution environment, then data security is improved, but processing complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidprocessing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The complex encryption and decryption operations are extracted from the general application processing and concentrated in the dedicated trusted execution environment. This extraction isolates the complexity to a specialized component, ensuring data security while allowing the rest of the system to operate with simpler, standard processing.

Inventive Principle:
Principle #2Taking out (Extraction)

3Reliability

If authentication is required before decryption, then access control is improved, but communication speed deteriorates

Engineering Contradiction:
Improveaccess controlVSAvoidcommunication speed
Core Design Contradiction:
ReliabilityVSSpeed

Solution Approach 1:

Authentication is performed as a preliminary action before decryption occurs in the trusted execution environment. By requiring authentication upfront, the system ensures that only authorized parties can access the decrypted data, maintaining strong access control while enabling efficient communication once authentication is established.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11159320B2Method for secure connection
Publication Date: 2021.10.26 HAVELSAN HAVA ELEKTRONIK SANAYI VE TICARET ANONIM SIRKETI
  • US11159320B2 patent drawing
  • US11159320B2 patent drawing

AI summary

The invention relates a method involving calling of hardware components (i.e. memory, keyboard, microphone, user interface, etc.) being controlled by software units from trusted execution environment [102]; and encryption of the input from these elements within the trusted execution environment [102]; and transmission of the said encrypted data preferably normalized methods to the application in the rich environment [103]; transmission of the said encrypted data to the receiver via the application in the rich environment [103] via the methods of the application of the rich environment [103]; transmission of the said encrypted data using protocols/methods of the application running in the rich environment [103]; and at the receiving device being opened at the trusted execution environment [102] and being displayed to the user as such.