Trusted Execution Complex for Secure Service Interaction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for secure electronic commerce are limited by their vulnerability to malware attacks, as they rely on the operating system or external hardware, which compromises user security and ease-of-use.

Innovation Solution

A system and method that employs a trusted execution complex within an electronic device, separate from the main processor and operating system, to ensure secure service interactions by using a secure dialog box for authentication and communication, preventing malware from accessing sensitive information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing secure solutions are hosted inside the operating system, then security is improved, but vulnerability to malware attacks increases

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to malware
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system is divided into two separate execution environments: a trusted execution complex (TEC) for secure operations and a main processor for general computing. This segmentation isolates security-critical functions from the vulnerable operating system, allowing secure credential storage and authentication while maintaining system functionality.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security-critical authentication functions are extracted from the operating system and placed into a dedicated trusted execution complex. This extraction removes the vulnerability point from the main system while preserving security capabilities in a hardened, isolated environment.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If external hardware devices are used for security, then security is improved, but ease of use deteriorates

Engineering Contradiction:
ImprovesecurityVSAvoidease of use
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The trusted execution complex is integrated within the electronic device itself, merging security functionality into the existing device architecture. This eliminates the need for separate external hardware devices while maintaining security, as the TEC becomes an inherent part of the device's processing capabilities.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The trusted execution complex serves multiple functions: secure credential storage, authentication verification, and encrypted communication. This multi-functionality consolidates what would traditionally require separate external security devices into a single integrated component, improving ease of use.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a trusted execution complex is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The trusted execution complex is implemented as a nested secure environment within the broader device architecture. This nesting allows the TEC to leverage existing device infrastructure while maintaining its own isolated secure space, minimizing the increase in overall device complexity.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

A dialog box interface acts as an intermediary between the trusted execution complex and the user/main system. This mediator simplifies interactions by providing a standardized communication protocol and user interface, reducing the complexity burden of the underlying secure architecture.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP3471043B1Trusted service interaction
Publication Date: 2020.07.01 INTEL CORP
  • EP3471043B1 patent drawingFigure 1
  • EP3471043B1 patent drawingFigure 2
  • EP3471043B1 patent drawingFigure 3

AI summary

In one embodiment a controller comprises logic configured to receive, from an application executing on an untrusted execution complex of the electronic device, a request for a secure communication session with a remote service, verify a security credential received from the remote service, establish a secure communication connection between the secure controller and the remote service, establish a secure user interface, collect one or more authentication credentials from a user via the secure user interface, forward the one or more authentication credentials to the remote service, and conduct a secure communication session with the remote service. Other embodiments may be described.