Universal Trusted Application for Multi-App Mobile Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Mobile terminals supporting multiple third-party payment applications face increased costs due to multiple digital signature fees and have high security risks from malicious applications accessing confidential information stored in the Trusted Execution Environment (TEE).

Innovation Solution

A general payment Trusted Application (TA) operating in the TEE is designed to be shared by multiple third-party payment applications, generating and encrypting application and user keys, and returning encrypted content for secure payment operations, reducing the need for multiple TAs and enhancing security by preventing malicious installations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple TAs are installed in the TEE to support multiple third-party payment applications, then each application can operate independently, but signature fees increase and security risks increase

Engineering Contradiction:
Improvesupport for multiple third-party payment applicationsVSAvoidnumber of TAs installed in TEE
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal TA architecture where a single TA in the TEE can serve multiple third-party payment applications. The TA receives payment requests from different applications, performs unified authentication and encryption operations, and returns results to the respective applications. This multi-functional design eliminates the need for separate TAs for each application, reducing signature fees and minimizing security risks while maintaining support for multiple payment services.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple TAs are installed in the TEE, then each application has dedicated security processing, but digital signature fees increase

Engineering Contradiction:
Improvesecurity processing for payment applicationsVSAvoidnumber of digital signatures required
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges the security processing functions of multiple TAs into a single unified TA. This consolidated TA handles authentication, encryption, and decryption operations for all third-party payment applications centrally. By combining these functions, the system maintains reliable security processing while reducing the number of digital signatures required from multiple to one, thereby lowering signature fees.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If multiple TAs are installed in the TEE, then each application can operate securely, but security risks from malicious applications increase

Engineering Contradiction:
Improvesecure operation of payment applicationsVSAvoidsecurity risks from malicious third-party applications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a unified TA as an intermediary between third-party payment applications and the TEE. This intermediary TA acts as a gatekeeper, validating payment requests, performing authentication and encryption operations, and controlling access to confidential information stored in the TEE. By centralizing security control through this intermediary, the system maintains secure operation while preventing malicious applications from directly accessing sensitive data, thereby reducing security risks.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11367054B2Biological recognition technology-based mobile payment device, method and apparatus, and storage medium
Publication Date: 2022.06.21 XIAOMI INC
  • US11367054B2 patent drawing
  • US11367054B2 patent drawing
  • US11367054B2 patent drawing

AI summary

The present disclosure is related to a biological recognition technology-based mobile payment device, method and apparatus, and a storage medium. The method includes receiving, by a payment Trusted Application (TA) that operates in a Trusted Execution Environment (TEE) on a device, a call request from one of a plurality of third party payment applications that are installed on the device and operate with the payment TA, determining content to be encrypted and an encryption parameter for performing encryption based on the call request, acquiring a result of biometric recognition from a biometric recognition application, encrypting the content according to the encryption parameter and the result of biometric recognition and returning the encrypted content to the third party payment application that generates the call request, for the third party payment application to perform a pay tent-related operation based on the encrypted content.