Trusted Execution Environment Service Processing for Private Risk Scoring
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing data collection methods in risk prevention and control applications face challenges due to low user authorization for black market data, impacting the accuracy and security of risk prediction and control.
Innovation Solution
Implementing a service processing method using a trusted execution environment (TEE) to securely process service data within a terminal device, ensuring data integrity and privacy by isolating data processing from unauthorized access, and providing processed results to applications for display.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If data collection satisfies principles of minimum and necessary with user authorization, then user privacy is protected, but risk prevention and control accuracy deteriorates due to low authorization willingness
Solution Approach 1:
The system segments data processing into two distinct environments: trusted execution environment (TEE) for processing authorized data and untrusted environment for handling unauthorized data. This segmentation allows the system to maintain privacy protection while expanding data utilization scope for risk prediction.
Solution Approach 2:
The TEE acts as an intermediary between the application and the data processing system. It provides a secure sandbox that allows untrusted data to be processed without exposing it to the application, thereby enabling broader data collection while maintaining privacy protection.
2Measurement precision
If service data including unauthorized data is processed to improve risk prediction accuracy, then service processing accuracy improves, but data security deteriorates due to potential exposure
Solution Approach 1:
The system establishes TEE protection mechanisms before data processing occurs. By pre-configuring secure execution environments and access controls, the system cushions against potential security breaches before they can affect the data or system.
Solution Approach 2:
The TEE serves as a secure intermediary layer that isolates untrusted data processing from the application. This mediator enables accurate risk prediction using broad data sources while preventing direct access to sensitive data, thus eliminating the security risk.
3Object-affected harmful factors
If TEE is used to securely process untrusted data, then data security improves, but device complexity increases
Solution Approach 1:
The TEE implementation leverages existing hardware security features and operating system capabilities already present in modern devices. By utilizing these self-service mechanisms rather than building complete security infrastructure from scratch, the system achieves enhanced security with minimal additional complexity.
Data Source
AI summary
Embodiments of this specification disclose a service processing method, apparatus, and device. The method is applied to a terminal device, the terminal device includes a trusted execution environment, and the method includes: A service processing instruction initiated by a target user for a target service by using a target application is obtained. Service data of the target service are obtained by using a trusted application in the trusted execution environment. Then, the service data are processed in the trusted execution environment based on a prestored service processing policy of the target service, to obtain a corresponding processing result. Service data restored based on the processing result are different from the obtained service data. Finally, the processing result can be provided to the target application. The target application can display a processing result of the target service to the target user based on the processing result.


