Trusted UI Display Architecture Across Multiple TEEs
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Terminal devices face security threats as hackers can obtain sensitive user information by cracking the system or through methods like malicious text input and screenshot capture, compromising user accounts.
Innovation Solution
Implementing a rich execution environment (REE) and multiple trusted execution environments (TEEs) with integrated TUI display and input drivers, allowing the terminal device to switch to a TEE for secure display processing and input handling, using a TUI server end in a second TEE for enhanced security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If TUI drivers are integrated in all TEEs, then security is improved, but manufacturing cost increases
Solution Approach 1:
The patent applies universality by designing a system where the TUI display driver in the second TEE serves multiple TEEs (first TEE, second TEE, and third TEE) through inter-TEE communication mechanisms. This allows a single driver implementation to provide secure display services across multiple execution environments, improving security coverage without proportionally increasing manufacturing costs.
Solution Approach 2:
The patent uses an intermediary approach by introducing a communication mechanism between TEEs that allows the second TEE's TUI display driver to serve other TEEs. The first TEE and third TEE can request display services from the second TEE through this intermediary communication layer, enabling resource sharing while maintaining security isolation.
2Reliability
If multiple TEEs are deployed, then security is improved, but device complexity increases
Solution Approach 1:
The patent reduces complexity by making the second TEE's TUI display driver universal, serving multiple TEEs through standardized communication interfaces. This approach consolidates functionality rather than duplicating drivers in each TEE, thereby reducing overall system complexity while maintaining multiple secure execution environments.
Solution Approach 2:
The patent merges the TUI display driver functionality into a single second TEE that serves multiple TEEs through communication mechanisms. Instead of having separate drivers in each TEE, the system combines driver functionality in one TEE and distributes it to others through inter-TEE communication, reducing redundancy and simplifying the overall architecture.
Data Source
AI summary
Embodiments of this application provide an information processing method and apparatus. Trusted execution environments (TEEs) that can execute a procedure of processing a display request to obtain a display result are deployed in a terminal device. In this way, when the terminal device obtains a first display request through a first TEE, and the first display request includes display information of a first interface, the terminal device can draw the first interface through a first trusted user interface (TUI) framework in the first TEE. Therefore, a procedure of processing the first display request is implemented. A TUI display driver is integrated in a second TEE, and thus, the terminal device can call the TUI display driver of the second TEE to display the first interface. As a result, security of obtaining a display result by the terminal device is improved.


