Trusted Execution Environment Identity Registration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing data transmission methods are burdensome for data providers and lack full trustworthiness, as they rely on digital signatures and can be vulnerable to tampering during data transmission, especially when using untrusted applications.

Innovation Solution

Implementing an identity registration method that restricts applications to trusted sources by installing secure applications in a trusted execution environment, ensuring data acquisition and transmission occur within a secure and trusted framework, utilizing a blockchain network to verify and store identity information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If data providers digitally sign data to ensure authenticity, then data source trustworthiness is improved, but operational burden on data providers increases greatly

Engineering Contradiction:
Improvedata source trustworthinessVSAvoiddata provider operational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces a trusted execution environment (TEE) as an intermediary component that resides on the data provider's device but operates independently. This TEE performs cryptographic operations and data signing without requiring the main application to do so, thereby maintaining data authenticity while relieving the application of operational burden. The TEE acts as a mediator between the data and the signing process.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The trusted execution environment provides self-service capabilities by automatically performing cryptographic operations, data integrity verification, and authentication processes. The TEE manages its own keys, certificates, and security policies without requiring manual intervention from data providers, thus improving operational efficiency while maintaining reliability.

Inventive Principle:
Principle #25Self-service

2Ease of operation

If data is transmitted through untrusted applications, then ease of data access is improved, but data integrity deteriorates due to potential tampering

Engineering Contradiction:
Improvedata accessibilityVSAvoiddata integrity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by creating a specialized trusted execution environment with distinct security properties for specific cryptographic operations. Instead of making the entire system trusted or untrusted, only the specific TEE components handling data signing and verification are trusted, while the rest of the system can remain untrusted. This localized trust approach maintains data integrity without restricting overall system accessibility.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system is segmented into trusted and untrusted components. The trusted execution environment is isolated from the untrusted application layer, allowing data to be accessed through untrusted applications while the critical cryptographic operations occur within the segmented, protected TEE boundary. This segmentation enables data accessibility through multiple applications while preserving integrity through isolated trusted operations.

Inventive Principle:
Principle #1Segmentation

3Reliability

If secure applications are restricted to trusted execution environments, then data security is improved, but system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution environment is designed as a universal platform that can host multiple secure applications and perform various cryptographic operations (signing, verification, key management) through a standardized interface. This multi-functionality reduces the need for separate trusted components for each operation, thereby improving security without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses cryptographic copying mechanisms where the TEE creates verified copies of data and digital signatures that can be transmitted and verified elsewhere. Instead of requiring the entire system to be trusted, only the copied cryptographic artifacts need to be verified, simplifying the trust model while maintaining security. The TEE produces copyable verification data that proves integrity without requiring continuous trusted connection.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3961450B1Identity registration methods, apparatuses, and devices
Publication Date: 2023.05.24 ALIPAY (HANGZHOU) INFORMATION TECH CO LTD
  • EP3961450B1 patent drawingFigure 1~2
  • EP3961450B1 patent drawingFigure 3
  • EP3961450B1 patent drawingFigure 4~5

AI summary

Embodiments of the present specification disclose an identity registration method, apparatus, and device. The solutions include the following: description information submitted by a user for a secure application to be installed is obtained, where the secure application is a program used to obtain trusted data; installation package data corresponding to the secure application is retrieved based on the description information; the secure application is installed in a trusted execution environment based on the installation package data; and the description information is added to a digital identity document of the user in a blockchain network.