Third-Party Access to Secure Hardware via Segmented Subsystems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile device manufacturers restrict access to certain APIs and hardware features for third-party apps due to security concerns, limiting their functionality and integration capabilities with native apps, especially in areas like payment processing and user authentication.

Innovation Solution

Allowing trusted third-party apps to access restricted hardware features like fingerprint or retina scanners and integrating them seamlessly with native apps, enabling features such as secure payment processing and loyalty programs without the need for separate applications, through a system architecture that separates secure and normal subsystems for controlled access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If device manufacturers restrict access to secure hardware and APIs for third-party apps, then security is improved, but functionality and integration capabilities deteriorate

Engineering Contradiction:
ImprovesecurityVSAvoidfunctionality and integration capabilities
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system is divided into two distinct subsystems: a secure subsystem with restricted access containing sensitive hardware and APIs, and a normal subsystem with broader access for third-party applications. This segmentation allows selective access control, where the operating system can grant specific permissions to trusted third-party apps while maintaining security boundaries. The secure subsystem remains protected, yet authorized applications can integrate with secure features like payment processing and authentication when needed.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If third-party apps are granted access to secure hardware features, then integration capabilities are improved, but security risks increase

Engineering Contradiction:
Improveintegration capabilitiesVSAvoidsecurity risks
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The operating system acts as an intermediary between third-party applications and the secure subsystem. It mediates access requests by evaluating trust relationships and granting permissions selectively. The OS controls which third-party apps can access secure hardware features like fingerprint scanners or payment processors, allowing integration capabilities while maintaining security through controlled intermediary management of access rights.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If separate third-party applications are required for secure features, then security control is improved, but user experience and convenience deteriorate

Engineering Contradiction:
Improvesecurity controlVSAvoiduser experience and convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges third-party applications with native application functionality by allowing trusted third-party apps to access secure subsystem features directly. This integration enables seamless experiences where third-party payment tools can function within native wallet applications without requiring separate app launches or manual switching. The secure control is maintained through OS-mediated access, while user convenience is improved through unified, integrated interfaces.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS10783517B2Third-party access to secure hardware
Publication Date: 2020.09.22 BLOCK INC
  • US10783517B2 patent drawing
  • US10783517B2 patent drawing
  • US10783517B2 patent drawing

AI summary

In one embodiment, a method includes receiving, at a third-party payment application integrated with a native wallet application executing on a mobile device, a payment request and a near-field communication code received from a payment terminal associated with a merchant. The mobile device includes secure elements accessible by the third-party payment application based on a processor of the mobile device being in a secure mode. The method includes authenticating a user through a secure subsystem executing on the mobile device. The method includes facilitating payment between the user and the merchant through a third-party payment server based on the authenticating the user and identifying a loyalty program status associated with the merchant. The method includes updating the payment request with the loyalty program to generate an updated loyalty program status. The method includes displaying a user computing device, comprising the updated loyalty program status.