TEE Peripheral Access Control via Whitelist Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current mobile terminal systems face challenges in managing application permissions for peripherals, leading to potential side-channel attacks, and existing solutions either restrict peripheral access too severely or require cumbersome user intervention, impacting terminal functionality.

Innovation Solution

A data processing method that determines if an application is on a whitelist before accessing peripherals, allowing the Trusted Execution Environment (TEE) management module to take over conflicting peripherals and send data to authorized applications, ensuring secure information exchange while minimizing functional limitations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the terminal prohibits external entities from accessing peripherals when displaying TUI, then information security is improved, but terminal functionality is restricted

Engineering Contradiction:
Improveinformation securityVSAvoidterminal functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent implements differential permission management where different applications receive different levels of peripheral access rights. The whitelist mechanism allows specific authorized applications to access peripherals while other applications remain restricted, achieving local quality control rather than universal restriction.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically adjusts peripheral access permissions based on the running state of applications. When a whitelisted application is detected to be running, the system automatically grants it peripheral access rights, and revokes them when the application stops, making the permission control dynamic rather than static.

Inventive Principle:
Principle #15Dynamics

2Reliability

If the system requires user intervention to manage peripheral permissions, then security control is improved, but ease of operation deteriorates

Engineering Contradiction:
Improvesecurity controlVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system implements automatic permission management that operates without user intervention. The permission management module automatically detects running applications, checks them against the whitelist, and adjusts peripheral permissions accordingly, making the security system self-service rather than user-dependent.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The whitelist of authorized applications is pre-configured before runtime. The system performs preliminary validation by checking running applications against this pre-established whitelist, enabling automatic permission decisions without requiring users to make real-time security judgments.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If static permission restriction is applied during TUI display, then side-channel attack prevention is improved, but adaptability to complex application environments deteriorates

Engineering Contradiction:
Improveside-channel attack preventionVSAvoidadaptation to application environment
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The patent transforms static permission restrictions into dynamic control by continuously monitoring application runtime states. Permission decisions are made based on real-time detection of which whitelisted applications are currently running, allowing the system to adapt to changing application environments while maintaining security.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system implements a feedback mechanism where the permission management module continuously monitors application execution states and adjusts peripheral permissions based on this feedback. When a whitelisted application starts or stops, the system receives feedback and automatically adjusts permissions, creating a closed-loop adaptive security system.

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3537291B1Data processing method and terminal thereof
Publication Date: 2022.08.24 HUAWEI TECH CO LTD
  • EP3537291B1 patent drawingFigure 1
  • EP3537291B1 patent drawingFigure 2
  • EP3537291B1 patent drawingFigure 3A

AI summary

Embodiments of the present invention provide a data processing method and a terminal. The method includes: determining whether a first conflicting application related to a first conflicting peripheral is in a whitelist; when it is determined that the first conflicting application is in the whitelist, independently taking over the first conflicting peripheral, where the first conflicting application is an application that is running in a rich execution environment REE; and when the TUI is displayed, sending data generated by the first conflicting peripheral to the first conflicting application. The embodiments of the present invention provide a method for processing peripheral data, so that not only information security of the terminal can be ensured, but also an access restriction on a terminal peripheral in a trusted execution environment TEE can be minimized, thereby less limiting and affecting a terminal function.