Trusted Execution Environment for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing authentication services in electronic devices often operate in software environments with low security, which can compromise the integrity and reliability of identity verification processes such as face recognition and electronic payments.

Innovation Solution

Implementing a security control method that determines whether an application meets preset security conditions, enabling it to run in a trusted execution environment, where authentication services are executed, enhancing security and reliability through dedicated hardware and image sensors for living body detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If authentication services run in software environment, then ease of operation is improved, but security and reliability deteriorate

Engineering Contradiction:
Improveease of operationVSAvoidsecurity and reliability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the execution environment into two distinct segments: a general software environment for normal application execution and a trusted execution environment (TEE) for authentication services. The TEE is isolated from the main software environment, creating separate security domains. This segmentation allows authentication to occur in a secure, isolated space while maintaining ease of operation in the general software environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The trusted execution environment acts as an intermediary between the application and the authentication process. Instead of applications directly performing authentication in the software environment, they communicate through the TEE which mediates the authentication service execution. This intermediary provides security isolation while maintaining operational convenience for applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If dedicated hardware is introduced for trusted execution environment, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvesecurity and reliabilityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the trusted execution environment capabilities into the existing processor architecture. Rather than adding completely separate dedicated hardware for TEE, the system integrates TEE functions within the processor itself, combining security features with general-purpose computing resources. This reduces overall device complexity while maintaining security improvements.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The processor is designed to serve multiple functions: general computation in the software environment and secure authentication in the trusted execution environment. This multi-functionality eliminates the need for entirely separate dedicated hardware, as the processor dynamically switches between roles based on execution context, thereby reducing device complexity while providing enhanced security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11157605B2Security control method and device of application, and electronic device
Publication Date: 2021.10.26 GUANGDONG OPPO MOBILE TELECOMMUNICATIONS CORP LTD
  • US11157605B2 patent drawing
  • US11157605B2 patent drawing
  • US11157605B2 patent drawing

AI summary

The present disclosure provides a security control method and device of an application, and an electronic device. The method includes: determining whether running information of the application meets a preset security control condition; calling a preset service if the running information of the application meets the preset security control condition, the preset service being configured to enable the application to run in a trusted execution environment; and executing an authentication service corresponding to the running information of the application in the trusted execution environment.