Temporary Trust Enablement for Secure App Execution
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices without a trusted security zone hardware partition cannot perform secure execution of applications or data exchange, particularly when interacting with server computers maintained by non-home carriers, posing security concerns in cloud computing systems for premium content services.
Innovation Solution
A method is introduced to install a temporary trust enablement application on electronic devices, which generates and compares encrypted keys or tokens to determine trustworthiness, allowing secure execution of trusted applications by restricting processor access and APIs, even without a trusted security zone hardware partition.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a trusted security zone hardware partition is used, then security of application execution is improved, but device complexity and cost increase
Solution Approach 1:
The patent creates a virtual copy of trusted security zone functionality through software-based temporary trust enablement. Instead of requiring physical hardware partitions, the system generates virtual trusted environments that replicate security zone behaviors, allowing secure application execution on devices without dedicated security hardware.
Solution Approach 2:
The patent implements temporary trust enablement that is created on-demand and discarded after use. Rather than permanently allocating hardware security resources, the system generates ephemeral trusted environments for specific applications and removes them after execution, reducing overall device complexity while maintaining security during critical operations.
2Reliability
If trusted security zone is implemented, then security is improved, but ease of manufacture deteriorates
Solution Approach 1:
The patent replaces mechanical/hardware-based security zone implementation with software-based temporary trust enablement. By substituting physical hardware partitions with virtualized security mechanisms, the system maintains security functionality while dramatically simplifying the manufacturing process, as no specialized hardware components are required.
3Reliability
If processor access is restricted for security, then security is improved, but productivity deteriorates
Solution Approach 1:
The patent implements dynamic processor access control where restrictions are applied only when and where needed for secure application execution. The temporary trust enablement mechanism dynamically adjusts processor accessibility based on the security requirements of the running application, rather than maintaining static restrictions that would continuously impact performance.
Solution Approach 2:
The patent segments processor access control into application-specific isolated environments. By creating separate temporary trust enablement spaces for individual secure applications, the system restricts processor access only for the specific application needing security, while other applications continue to execute without restriction, thereby maintaining overall system productivity.
Data Source
AI summary
A method of executing a trusted application on a trusted security zone enabled electronic device. The method comprises responsive to a trusted security subzone not being provisioned on the electronic device, generating, by a server, a temporary trust token, transmitting the temporary trust token to the electronic device, and comparing the temporary trust token with a plurality of trust tokens stored in the electronic device to determine the trustworthiness of the temporary trust token. The method further comprises responsive to the temporary trust token being determined to be trustworthy, provisioning the non-provisioned trusted security subzone on the electronic device to be a temporary trust enablement, transmitting the trusted application through an encrypted channel to the temporary trust enablement, executing the trusted application in the temporary trust enablement, and removing the trusted application, the temporary trust enablement, and the temporary trust token when the trusted application is completed.


