Trusted Execution Environment Security Indication Configuration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current intelligent mobile terminals lack an overall protection mechanism, making them vulnerable to security risks due to existing security vulnerabilities in their operating systems and software, which can lead to attacks by malicious software and data interception.

Innovation Solution

A security indication information configuration method and device that detects the presence of universal security indication information on a trusted user interface, determines the terminal's running status, and only sets the security indication information when the terminal is in a secure state, ensuring that the information is not compromised by malicious software.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security indication information is configured on the terminal, then user security awareness is improved, but the terminal becomes vulnerable to malicious software interception and forgery

Engineering Contradiction:
Improvesecurity of terminalVSAvoidinterception and forgery by malicious software
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the execution environment into two separate segments: a trusted execution environment (TEE) and a rich execution environment (REE). The security indication information is exclusively configured and managed in the TEE, which is isolated from the REE where malicious software operates. This segmentation ensures that security-critical operations cannot be intercepted or forged by unauthorized applications in the REE.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary mechanism - the trusted execution environment - that acts as a mediator between the user interface and the system core. The TEE verifies and authenticates security indication information before it is displayed to the user, preventing direct access by malicious software in the REE. This intermediary layer ensures that only authenticated security information reaches the user interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the terminal uses a rich execution environment for flexibility, then adaptability is improved, but security vulnerability increases

Engineering Contradiction:
Improvesoftware installation capabilityVSAvoidsecurity against malicious software
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the terminal's execution environment into two distinct parts: the REE that provides flexibility for installing third-party applications, and the TEE that provides security for critical operations. This segmentation allows the terminal to maintain both adaptability (through REE) and security (through TEE) simultaneously, resolving the contradiction between flexibility and security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different quality characteristics to different parts of the system. The REE is designed with high adaptability to support various applications, while the TEE is designed with high security properties for managing security indication information. This local differentiation of qualities allows each part to excel at its intended function without compromising the other.

Inventive Principle:
Principle #3Local quality

3Loss of information

If security indication information is displayed on the user interface, then user awareness is improved, but the information may be intercepted or forged

Engineering Contradiction:
Improveintegrity of security informationVSAvoidinterception and forgery
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent uses the TEE as an intermediary that authenticates and protects security indication information before it is displayed on the user interface. The TEE verifies the integrity of the information and prevents interception or forgery during transmission to the display layer, ensuring that users receive authentic security information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary authentication and verification of security indication information in the TEE before the information is displayed to the user. By pre-verifying the authenticity and integrity of the information in the secure environment, the system prevents interception and forgery from occurring during the display process.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11100227B2Security indication information configuration method and device
Publication Date: 2021.08.24 HUAWEI TECH CO LTD
  • US11100227B2 patent drawing
  • US11100227B2 patent drawing
  • US11100227B2 patent drawing

AI summary

Embodiments of the present invention provide a security indication information configuration method and device, to reduce a risk of attack and interception from malicious software. The method includes: detecting, by a terminal, whether universal security indication information is set in the terminal for a TUI; detecting a running status of the terminal if no universal security indication information is set; when it is detected that the running status of the terminal is a secure state, presenting a first input interface on a display by using a first information presentation interface; and receiving input universal security indication information by using the first input interface, and saving the universal security indication information to a trusted execution environment TEE of the terminal.