Trusted Execution Enclave for Local Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for protecting devices and applications from malware and theft are inadequate, as local security techniques are ineffective against advanced threats, and cloud-based processing is complex, costly, and prone to network attacks.
Innovation Solution
A system and method for trusted execution of sensitive operations on a local device using an enclave, which provides a secure environment for data processing and authentication without external communication, reducing latency and cloud costs, and protecting against malware by executing algorithms and data within a trusted execution environment (TEE).
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If cloud-based processing is used for authentication and data processing, then security against local malware is improved, but system complexity and cost increase
Solution Approach 1:
The patent extracts the authentication and sensitive data processing functions from the cloud and places them within a Trusted Execution Environment (TEE) on the local device. The TEE creates an isolated secure enclave that performs authentication operations locally, eliminating the need for complex cloud-based processing while maintaining security. This extraction of critical functions to the local device reduces system complexity and cost while preserving security benefits.
Solution Approach 2:
The patent introduces a Trusted Execution Environment (TEE) as an intermediary between the untrusted operating system and the authentication processes. This TEE acts as a secure mediator that isolates sensitive operations from potential malware and unauthorized access. The TEE provides a protected space where authentication can occur without requiring complex cloud infrastructure, thereby reducing overall system complexity while maintaining high security standards.
2Reliability
If cloud-based processing is used for authentication, then centralized security management is improved, but network latency and vulnerabilities increase
Solution Approach 1:
The patent extracts authentication operations from the network-dependent cloud environment and executes them locally within a Trusted Execution Environment on the device. This extraction eliminates network latency by performing authentication directly on the device without requiring communication with remote servers. The TEE maintains centralized security management capabilities while executing operations locally, thereby eliminating network-related delays and vulnerabilities.
3Device complexity
If local security techniques are used, then device simplicity is maintained, but effectiveness against advanced malware is reduced
Solution Approach 1:
The patent implements a nested security architecture where a Trusted Execution Environment (TEE) is embedded within the existing operating system. The TEE creates a nested secure enclave that contains authentication operations and sensitive data, isolating them from potential malware in the outer untrusted environment. This nesting approach allows simple local security techniques to be enhanced with advanced protection capabilities without significantly increasing overall device complexity. The TEE provides hardware-enforced isolation that effectively protects against advanced malware while maintaining device simplicity.
Solution Approach 2:
The patent applies local quality by implementing a Trusted Execution Environment that provides enhanced security properties specifically for authentication operations, while the rest of the system maintains its original simplicity. The TEE creates a localized secure space with specialized protection mechanisms (such as hardware-enforced memory isolation and execution control) that are applied only where needed for authentication, rather than complicating the entire device architecture. This localized enhancement effectively protects against advanced malware without unnecessarily increasing overall device complexity.
4Adaptability or versatility
If cloud components are used for authentication, then service provider functionality is improved, but costs increase
Solution Approach 1:
The patent extracts authentication functionality from cloud-based services and implements it locally within a Trusted Execution Environment on the device. This extraction eliminates the need for paid cloud computing resources, reducing operational costs for service providers. The TEE provides the necessary authentication capabilities natively on the device, replacing expensive cloud infrastructure with cost-effective local hardware support for the trusted execution environment.
Data Source
AI summary
In one example embodiment, an electronic device is provided and configured to: acquire authentication data for an authorized user; store the authentication data in an enclave; acquire identification data for a potential user, and compare, in the enclave, the identification data to the authentication data for recognizing if the potential user is the authorized user. In another embodiment, a server is provided and includes at least one processor; at least one memory; at least one driver, where the server is configured to: receive assertion data from an electronic device, where the assertion includes an authentication signing key and results from a comparison of acquired data and reference data; and determine it the assertion data is valid by: comparing the results to a threshold; and comparing the authentication signing key to an authentication signing key assigned to the electronic device.


