Universal Trusted Application for Multi-App Mobile Payment Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Mobile terminals supporting multiple third-party payment applications face increased costs due to multiple digital signature fees and have high security risks from malicious applications accessing confidential information stored in the Trusted Execution Environment (TEE).
Innovation Solution
A general payment Trusted Application (TA) operating in the TEE is designed to be shared by multiple third-party payment applications, generating and encrypting application and user keys, and returning encrypted content for secure payment operations, reducing the need for multiple TAs and enhancing security by preventing malicious installations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple TAs are installed in the TEE to support multiple third-party payment applications, then each application can operate independently, but signature fees increase and security risks increase
Solution Approach 1:
The patent implements a universal TA architecture where a single TA in the TEE can serve multiple third-party payment applications. The TA receives payment requests from different applications, performs unified authentication and encryption operations, and returns results to the respective applications. This multi-functional design eliminates the need for separate TAs for each application, reducing signature fees and minimizing security risks while maintaining support for multiple payment services.
2Reliability
If multiple TAs are installed in the TEE, then each application has dedicated security processing, but digital signature fees increase
Solution Approach 1:
The patent merges the security processing functions of multiple TAs into a single unified TA. This consolidated TA handles authentication, encryption, and decryption operations for all third-party payment applications centrally. By combining these functions, the system maintains reliable security processing while reducing the number of digital signatures required from multiple to one, thereby lowering signature fees.
3Reliability
If multiple TAs are installed in the TEE, then each application can operate securely, but security risks from malicious applications increase
Solution Approach 1:
The patent introduces a unified TA as an intermediary between third-party payment applications and the TEE. This intermediary TA acts as a gatekeeper, validating payment requests, performing authentication and encryption operations, and controlling access to confidential information stored in the TEE. By centralizing security control through this intermediary, the system maintains secure operation while preventing malicious applications from directly accessing sensitive data, thereby reducing security risks.
Data Source
AI summary
The present disclosure is related to a biological recognition technology-based mobile payment device, method and apparatus, and a storage medium. The method includes receiving, by a payment Trusted Application (TA) that operates in a Trusted Execution Environment (TEE) on a device, a call request from one of a plurality of third party payment applications that are installed on the device and operate with the payment TA, determining content to be encrypted and an encryption parameter for performing encryption based on the call request, acquiring a result of biometric recognition from a biometric recognition application, encrypting the content according to the encryption parameter and the result of biometric recognition and returning the encrypted content to the third party payment application that generates the call request, for the third party payment application to perform a pay tent-related operation based on the encrypted content.


