Trusted App Security for Appliance Financing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for remote management of user devices require multiple hardware units and software-only lock solutions that can be easily defeated, making them inefficient and insecure for ensuring timely payments and controlling device usage.
Innovation Solution
A system that uses a hardware-based appliance management subsystem embedded in devices, running a Trusted App in the Trustzone below the operating system, to enforce security and control device access, combined with a software app for communication and payment verification, ensuring secure and remote management without relying on device communication capabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If software-only lock solutions are used for device control, then ease of manufacture is improved, but security is worsened because they can be easily defeated
Solution Approach 1:
The patent introduces a mobile communication network as an intermediary between the seller and buyer to verify payments and control device access. The network operator's infrastructure acts as a trusted mediator that neither party can easily compromise, resolving the security weakness of software-only solutions while maintaining ease of manufacture.
Solution Approach 2:
The patent replaces physical hardware locking mechanisms with a communication-based control system. Instead of mechanical locks or hardware security modules, the system uses mobile network communication to verify payments and control device functionality, achieving enhanced security without increasing manufacturing complexity.
2Reliability
If multiple hardware units are required for device control and payment management, then security is improved, but device complexity is worsened
Solution Approach 1:
The patent extracts the security and payment verification functions from the device itself and places them in the mobile communication network. This separation allows the device to remain simple while the network handles the complex security verification, resolving the contradiction between security and device complexity.
Solution Approach 2:
The patent leverages the mobile communication network's existing infrastructure to perform multiple functions: payment verification, device access control, and usage monitoring. This multi-functionality approach achieves enhanced security without requiring multiple separate hardware units, as the network handles all these tasks through its universal communication platform.
3Ease of operation
If device mobile communication capability is required for remote control, then ease of operation is improved, but device complexity is worsened
Solution Approach 1:
The patent enables the device to use its existing mobile communication capability to automatically receive control commands and verification signals from the network. The device serves itself by leveraging its inherent communication functions rather than requiring additional dedicated control hardware, achieving ease of operation without increasing complexity.
Data Source
AI summary
Embodiments described herein include methods and systems for remotely managing appliances, including enabling communication between a user of the appliance and third party systems. The third party systems can include any entity that has a relationship with the user of the appliance, such as a payment infrastructure handling incremental payments for the appliance, and managing access to the appliance accordingly. In some embodiments, the appliance being controlled is a mobile phone that also includes third party operating system software. Various methods for preventing alteration or replacement of the third party operating system are also described.


