Secure Hardware Access via Trusted Zone for Third-Party Payments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile devices restrict third-party applications from accessing secure hardware features like fingerprint scanners or retina scanners due to trust issues, limiting the functionality of native wallet applications and preventing seamless integration with third-party payment tools.

Innovation Solution

Integrate third-party payment applications with native applications, allowing them to access secure hardware features through a trusted zone, enabling seamless registration, transactions, and notifications without the need for separate apps, and providing enhanced user interfaces for financial management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If third-party applications are restricted from accessing secure hardware features, then security and trust are maintained, but functionality and versatility of payment applications are limited

Engineering Contradiction:
Improvefunctionality of payment applicationsVSAvoidsecurity of secure hardware access
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system segments the application ecosystem into native applications developed by the device manufacturer and third-party applications, with different access privileges to secure hardware. Native applications are granted full access to secure features, while third-party applications receive controlled access through a trusted zone, allowing functionality expansion while maintaining security boundaries.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A trusted zone acts as an intermediary layer between third-party applications and secure hardware features. This mediator provides controlled access to secure elements like fingerprint scanners and retina scanners for third-party payment applications, enabling functionality while maintaining security through supervised access rather than direct unrestricted access.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If third-party applications are granted access to secure hardware features, then functionality and user experience are enhanced, but security risks and trust issues arise

Engineering Contradiction:
Improveuser experience of payment applicationsVSAvoidsecurity risks of hardware access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

Different security quality levels are applied to different application types. Native applications receive full trust and unrestricted access to secure hardware, while third-party applications receive localized, controlled access through the trusted zone. This differential quality approach enables enhanced user experience for third-party apps without compromising overall system security.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The trusted zone serves as a pre-established security cushion or buffer between third-party applications and critical secure hardware. This protective layer is set up in advance to prevent direct access risks, allowing third-party applications to interact with secure features through controlled interfaces that mitigate security risks before they can affect the core secure elements.

Inventive Principle:
Principle #11Beforehand cushioning (Prior cushioning)

3Reliability

If separate third-party applications are required for secure features, then security control is maintained, but device complexity and user inconvenience increase

Engineering Contradiction:
Improvesecurity control of accessVSAvoidnumber of separate applications
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system merges third-party payment applications with native application interfaces and functionality. Third-party applications can be integrated into the native application ecosystem, allowing users to access secure features through a unified interface rather than requiring separate standalone applications. This combining approach maintains security control while reducing device complexity and improving user convenience.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12548011B2Third-party access to secure hardware
Publication Date: 2026.02.10 BLOCK INC
  • US12548011B2 patent drawing
  • US12548011B2 patent drawing
  • US12548011B2 patent drawing

AI summary

In one aspect, a mobile device includes a secure subsystem configured to provide access to one or more of personal identifying information of a user of the mobile device and secure elements of the mobile device to applications native to an operating system of the mobile device and one or more third-party applications that are not native to the operating system of the mobile device. The mobile device further includes a normal subsystem in which third-party applications other than the one or more third-party applications operate, and a third-party payment processing application configured to operate in one of the secure subsystem or the normal subsystem, receive a request for authenticating a user for processing a transaction, access one or more of the secure elements of the mobile device for authenticating the user, and authenticate the user for processing the transaction using the one or more of the secure elements.