Trusted Execution Environment Identity Registration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data transmission methods are burdensome for data providers and lack full trustworthiness, as they rely on digital signatures and can be vulnerable to tampering during data transmission, especially when using untrusted applications.
Innovation Solution
Implementing an identity registration method that restricts applications to trusted sources by installing secure applications in a trusted execution environment, ensuring data acquisition and transmission occur within a secure and trusted framework, utilizing a blockchain network to verify and store identity information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data providers digitally sign data to ensure authenticity, then data source trustworthiness is improved, but operational burden on data providers increases greatly
Solution Approach 1:
The patent introduces a trusted execution environment (TEE) as an intermediary component that resides on the data provider's device but operates independently. This TEE performs cryptographic operations and data signing without requiring the main application to do so, thereby maintaining data authenticity while relieving the application of operational burden. The TEE acts as a mediator between the data and the signing process.
Solution Approach 2:
The trusted execution environment provides self-service capabilities by automatically performing cryptographic operations, data integrity verification, and authentication processes. The TEE manages its own keys, certificates, and security policies without requiring manual intervention from data providers, thus improving operational efficiency while maintaining reliability.
2Ease of operation
If data is transmitted through untrusted applications, then ease of data access is improved, but data integrity deteriorates due to potential tampering
Solution Approach 1:
The patent applies local quality by creating a specialized trusted execution environment with distinct security properties for specific cryptographic operations. Instead of making the entire system trusted or untrusted, only the specific TEE components handling data signing and verification are trusted, while the rest of the system can remain untrusted. This localized trust approach maintains data integrity without restricting overall system accessibility.
Solution Approach 2:
The system is segmented into trusted and untrusted components. The trusted execution environment is isolated from the untrusted application layer, allowing data to be accessed through untrusted applications while the critical cryptographic operations occur within the segmented, protected TEE boundary. This segmentation enables data accessibility through multiple applications while preserving integrity through isolated trusted operations.
3Reliability
If secure applications are restricted to trusted execution environments, then data security is improved, but system complexity increases
Solution Approach 1:
The trusted execution environment is designed as a universal platform that can host multiple secure applications and perform various cryptographic operations (signing, verification, key management) through a standardized interface. This multi-functionality reduces the need for separate trusted components for each operation, thereby improving security without proportionally increasing system complexity.
Solution Approach 2:
The patent uses cryptographic copying mechanisms where the TEE creates verified copies of data and digital signatures that can be transmitted and verified elsewhere. Instead of requiring the entire system to be trusted, only the copied cryptographic artifacts need to be verified, simplifying the trust model while maintaining security. The TEE produces copyable verification data that proves integrity without requiring continuous trusted connection.
Data Source
Figure 1~2
Figure 3
Figure 4~5
AI summary
Embodiments of the present specification disclose an identity registration method, apparatus, and device. The solutions include the following: description information submitted by a user for a secure application to be installed is obtained, where the secure application is a program used to obtain trusted data; installation package data corresponding to the secure application is retrieved based on the description information; the secure application is installed in a trusted execution environment based on the installation package data; and the description information is added to a digital identity document of the user in a blockchain network.