Trusted Execution Environment Security Indication Configuration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current intelligent mobile terminals lack an overall protection mechanism, making them vulnerable to security risks due to existing security vulnerabilities in their operating systems and software, which can lead to attacks by malicious software and data interception.
Innovation Solution
A security indication information configuration method and device that detects the presence of universal security indication information on a trusted user interface, determines the terminal's running status, and only sets the security indication information when the terminal is in a secure state, ensuring that the information is not compromised by malicious software.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security indication information is configured on the terminal, then user security awareness is improved, but the terminal becomes vulnerable to malicious software interception and forgery
Solution Approach 1:
The patent divides the execution environment into two separate segments: a trusted execution environment (TEE) and a rich execution environment (REE). The security indication information is exclusively configured and managed in the TEE, which is isolated from the REE where malicious software operates. This segmentation ensures that security-critical operations cannot be intercepted or forged by unauthorized applications in the REE.
Solution Approach 2:
The patent introduces an intermediary mechanism - the trusted execution environment - that acts as a mediator between the user interface and the system core. The TEE verifies and authenticates security indication information before it is displayed to the user, preventing direct access by malicious software in the REE. This intermediary layer ensures that only authenticated security information reaches the user interface.
2Adaptability or versatility
If the terminal uses a rich execution environment for flexibility, then adaptability is improved, but security vulnerability increases
Solution Approach 1:
The patent segments the terminal's execution environment into two distinct parts: the REE that provides flexibility for installing third-party applications, and the TEE that provides security for critical operations. This segmentation allows the terminal to maintain both adaptability (through REE) and security (through TEE) simultaneously, resolving the contradiction between flexibility and security.
Solution Approach 2:
The patent applies different quality characteristics to different parts of the system. The REE is designed with high adaptability to support various applications, while the TEE is designed with high security properties for managing security indication information. This local differentiation of qualities allows each part to excel at its intended function without compromising the other.
3Loss of information
If security indication information is displayed on the user interface, then user awareness is improved, but the information may be intercepted or forged
Solution Approach 1:
The patent uses the TEE as an intermediary that authenticates and protects security indication information before it is displayed on the user interface. The TEE verifies the integrity of the information and prevents interception or forgery during transmission to the display layer, ensuring that users receive authentic security information.
Solution Approach 2:
The patent performs preliminary authentication and verification of security indication information in the TEE before the information is displayed to the user. By pre-verifying the authenticity and integrity of the information in the secure environment, the system prevents interception and forgery from occurring during the display process.
Data Source
AI summary
Embodiments of the present invention provide a security indication information configuration method and device, to reduce a risk of attack and interception from malicious software. The method includes: detecting, by a terminal, whether universal security indication information is set in the terminal for a TUI; detecting a running status of the terminal if no universal security indication information is set; when it is detected that the running status of the terminal is a secure state, presenting a first input interface on a display by using a first information presentation interface; and receiving input universal security indication information by using the first input interface, and saving the universal security indication information to a trusted execution environment TEE of the terminal.


