Temporary Trust Enablement for Secure App Execution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices without a trusted security zone hardware partition cannot perform secure execution of applications or data exchange, particularly when interacting with server computers maintained by non-home carriers, posing security concerns in cloud computing systems for premium content services.

Innovation Solution

A method is introduced to install a temporary trust enablement application on electronic devices, which generates and compares encrypted keys or tokens to determine trustworthiness, allowing secure execution of trusted applications by restricting processor access and APIs, even without a trusted security zone hardware partition.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a trusted security zone hardware partition is used, then security of application execution is improved, but device complexity and cost increase

Engineering Contradiction:
Improvesecurity of application executionVSAvoidhardware partition structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtual copy of trusted security zone functionality through software-based temporary trust enablement. Instead of requiring physical hardware partitions, the system generates virtual trusted environments that replicate security zone behaviors, allowing secure application execution on devices without dedicated security hardware.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements temporary trust enablement that is created on-demand and discarded after use. Rather than permanently allocating hardware security resources, the system generates ephemeral trusted environments for specific applications and removes them after execution, reducing overall device complexity while maintaining security during critical operations.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

2Reliability

If trusted security zone is implemented, then security is improved, but ease of manufacture deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoiddevice manufacturing process
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent replaces mechanical/hardware-based security zone implementation with software-based temporary trust enablement. By substituting physical hardware partitions with virtualized security mechanisms, the system maintains security functionality while dramatically simplifying the manufacturing process, as no specialized hardware components are required.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If processor access is restricted for security, then security is improved, but productivity deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidapplication execution efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic processor access control where restrictions are applied only when and where needed for secure application execution. The temporary trust enablement mechanism dynamically adjusts processor accessibility based on the security requirements of the running application, rather than maintaining static restrictions that would continuously impact performance.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent segments processor access control into application-specific isolated environments. By creating separate temporary trust enablement spaces for individual secure applications, the system restricts processor access only for the specific application needing security, while other applications continue to execute without restriction, thereby maintaining overall system productivity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9230085B1Network based temporary trust extension to a remote or mobile device enabled via specialized cloud services
Publication Date: 2016.01.05 T MOBILE INNOVATIONS LLC
  • US9230085B1 patent drawing
  • US9230085B1 patent drawing
  • US9230085B1 patent drawing

AI summary

A method of executing a trusted application on a trusted security zone enabled electronic device. The method comprises responsive to a trusted security subzone not being provisioned on the electronic device, generating, by a server, a temporary trust token, transmitting the temporary trust token to the electronic device, and comparing the temporary trust token with a plurality of trust tokens stored in the electronic device to determine the trustworthiness of the temporary trust token. The method further comprises responsive to the temporary trust token being determined to be trustworthy, provisioning the non-provisioned trusted security subzone on the electronic device to be a temporary trust enablement, transmitting the trusted application through an encrypted channel to the temporary trust enablement, executing the trusted application in the temporary trust enablement, and removing the trusted application, the temporary trust enablement, and the temporary trust token when the trusted application is completed.