Trusted Execution Environment for Secure Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing authentication services in electronic devices often operate in software environments with low security, which can compromise the integrity and reliability of identity verification processes such as face recognition and electronic payments.
Innovation Solution
Implementing a security control method that determines whether an application meets preset security conditions, enabling it to run in a trusted execution environment, where authentication services are executed, enhancing security and reliability through dedicated hardware and image sensors for living body detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If authentication services run in software environment, then ease of operation is improved, but security and reliability deteriorate
Solution Approach 1:
The system divides the execution environment into two distinct segments: a general software environment for normal application execution and a trusted execution environment (TEE) for authentication services. The TEE is isolated from the main software environment, creating separate security domains. This segmentation allows authentication to occur in a secure, isolated space while maintaining ease of operation in the general software environment.
Solution Approach 2:
The trusted execution environment acts as an intermediary between the application and the authentication process. Instead of applications directly performing authentication in the software environment, they communicate through the TEE which mediates the authentication service execution. This intermediary provides security isolation while maintaining operational convenience for applications.
2Reliability
If dedicated hardware is introduced for trusted execution environment, then security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent merges the trusted execution environment capabilities into the existing processor architecture. Rather than adding completely separate dedicated hardware for TEE, the system integrates TEE functions within the processor itself, combining security features with general-purpose computing resources. This reduces overall device complexity while maintaining security improvements.
Solution Approach 2:
The processor is designed to serve multiple functions: general computation in the software environment and secure authentication in the trusted execution environment. This multi-functionality eliminates the need for entirely separate dedicated hardware, as the processor dynamically switches between roles based on execution context, thereby reducing device complexity while providing enhanced security.
Data Source
AI summary
The present disclosure provides a security control method and device of an application, and an electronic device. The method includes: determining whether running information of the application meets a preset security control condition; calling a preset service if the running information of the application meets the preset security control condition, the preset service being configured to enable the application to run in a trusted execution environment; and executing an authentication service corresponding to the running information of the application in the trusted execution environment.


