WO2024112057A1 - 보안 데이터를 저장하는 전자 장치 및 그 동작 방법 - Google Patents
보안 데이터를 저장하는 전자 장치 및 그 동작 방법 Download PDFInfo
- Publication number
- WO2024112057A1 WO2024112057A1 PCT/KR2023/018740 KR2023018740W WO2024112057A1 WO 2024112057 A1 WO2024112057 A1 WO 2024112057A1 KR 2023018740 W KR2023018740 W KR 2023018740W WO 2024112057 A1 WO2024112057 A1 WO 2024112057A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- memory
- encrypted
- processor
- electronic device
- arc
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/70—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
- G06F21/78—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data
- G06F21/79—Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure storage of data in semiconductor storage media, e.g. directly-addressable memories
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/52—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow
- G06F21/53—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems during program execution, e.g. stack integrity ; Preventing unwanted data erasure; Buffer overflow by executing in a restricted environment, e.g. sandbox or secure virtual machine
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/602—Providing cryptographic facilities or services
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04W—WIRELESS COMMUNICATION NETWORKS
- H04W12/00—Security arrangements; Authentication; Protecting privacy or anonymity
- H04W12/03—Protecting confidentiality, e.g. by encryption
Definitions
- This disclosure relates to an electronic device that stores secure data and a method of operating the same.
- an electronic device eg, user equipment (UE)
- UE user equipment
- voice communication services or data communication services at a designated location or while moving.
- voice communication services or data communication services services and additional functions provided through electronic devices are gradually increasing.
- an appropriate authentication process is required and data requiring security needs to be safely processed.
- a universal integrated circuit card is inserted into an electronic device, and the electronic device and a mobile network operator (MNO) are connected through a universal subscriber identity module (USIM) installed inside the UICC.
- MNO mobile network operator
- USIM universal subscriber identity module
- Authentication is performed between servers.
- the MNO provides a UICC (eg, a SIM card or USIM card) to the user, and the user can insert the provided UICC into his or her electronic device.
- eUICC embedded UICC
- the eUICC may be manufactured as a UICC chip fixed within the terminal during the terminal manufacturing process.
- An integrated SIM integrated SIM, hereinafter referred to as iSIM
- iSIM integrated SIM
- SOC system on chip
- iSIM has a structure in which it is not easy to physically attach or detach the UICC, such as general wireless terminals such as mobile phones, machine to machine (M2M) or device to device (D2D) terminals, and internet of things (IoT) devices. It can be used in various electronic devices.
- general wireless terminals such as mobile phones, machine to machine (M2M) or device to device (D2D) terminals, and internet of things (IoT) devices. It can be used in various electronic devices.
- M2M machine to machine
- D2D device to device
- IoT internet of things
- An electronic device includes a first processor operating in a general non-secure environment; a second processor operating in a secure environment; a first memory allocated to the general non-secure environment; a second memory allocated to the secure environment; and a third memory shared between the general non-secure environment and the secure environment.
- the second processor encrypts at least some of the secure data to generate an encrypted portion, the secure data is generated by a trusted application executing in the secure environment, and stores the encrypted portion in the third memory. It may be set to store, in the second memory, first information used to encrypt at least part of the secure data and second information generated in the process of encrypting at least part of the secure data.
- the first processor may be set to store the encrypted portion stored in the third memory in the first memory.
- a non-transitory computer-readable storage medium storing one or more programs according to an embodiment
- the one or more programs when executed by at least one processor of the electronic device, cause the electronic device to;
- a first processor operating in a secure environment executing a trusted application in the secure environment and generating secure data
- the first processor at least a portion of the generated secure data to generate an encrypted portion.
- Encrypt store the encrypted portion in a first memory shared between the secure environment and a general non-secure environment, and use the first processor to encrypt at least a portion of the secure data and the security.
- Second information generated in the process of encrypting at least part of the data is stored in a second memory allocated to the secure environment, and stored in the first memory by a second processor operating in the general non-secure environment. It may include instructions for storing the encrypted portion in a third memory allocated to the general non-secure environment.
- FIG. 1 is a block diagram of an electronic device 101 in a network environment, according to one or more embodiments.
- Figure 2 is a block diagram of a program according to one or more embodiments.
- Figure 3 shows a block diagram for explaining a program module according to one or more embodiments.
- FIG. 4 is a diagram illustrating an example of an execution environment according to a program module of an electronic device according to one or more embodiments.
- FIG. 5 is a flowchart illustrating an example of an operation of an electronic device according to one or more embodiments.
- FIG. 6 is a diagram for explaining an example of the operation of the electronic device of FIG. 5 according to one or more embodiments.
- FIG. 7 is a flowchart illustrating an example of an operation of an electronic device according to one or more embodiments.
- FIG. 8 is a diagram for explaining an example of the operation of the electronic device of FIG. 7 according to one or more embodiments.
- FIG. 1 is a block diagram of an electronic device 101 in a network environment 100, according to various embodiments.
- the electronic device 101 communicates with the electronic device 102 through a first network 198 (e.g., a short-range wireless communication network) or a second network 199. It is possible to communicate with the electronic device 104 or the server 108 through (e.g., a long-distance wireless communication network). According to one or more embodiments, the electronic device 101 may communicate with the electronic device 104 through the server 108.
- a first network 198 e.g., a short-range wireless communication network
- a second network 199 e.g., a second network 199.
- the electronic device 101 may communicate with the electronic device 104 through the server 108.
- the electronic device 101 includes a processor 120, a memory 130, an input module 150, an audio output module 155, a display module 160, an audio module 170, Sensor module 176, interface 177, connection terminal 178, haptic module 179, camera module 180, power management module 188, battery 189, communication module 190, subscriber identification module (196), or may include an antenna module (197).
- at least one of these components eg, the connection terminal 178) may be omitted or one or more other components may be added to the electronic device 101.
- some of these components e.g., sensor module 176, camera module 180, or antenna module 197) are integrated into one component (e.g., display module 160). It can be.
- the processor 120 for example, executes software (e.g., program 140) to operate at least one other component (e.g., hardware or software component) of the electronic device 101 connected to the processor 120. It can be controlled and various data processing or calculations can be performed. According to one or more embodiments, as at least part of data processing or computation, processor 120 may store instructions or data received from another component (e.g., sensor module 176 or communication module 190) into volatile memory. The commands or data stored in the volatile memory 132 may be processed and the resulting data may be stored in the non-volatile memory 134 .
- software e.g., program 140
- processor 120 may store instructions or data received from another component (e.g., sensor module 176 or communication module 190) into volatile memory.
- the commands or data stored in the volatile memory 132 may be processed and the resulting data may be stored in the non-volatile memory 134 .
- the processor 120 may include a main processor 121 (e.g., a central processing unit or an application processor) or an auxiliary processor 123 (e.g., a graphics processing unit, a neural network) that can operate independently or together with the main processor 121. It may include a processing unit (NPU: neural processing unit), image signal processor, sensor hub processor, or communication processor. For example, if the electronic device 101 includes a main processor 121 and a secondary processor 123, the secondary processor 123 may be set to use lower power than the main processor 121 or be specialized for a designated function. You can.
- the auxiliary processor 123 may be implemented separately from the main processor 121 or as part of it.
- the auxiliary processor 123 may, for example, act on behalf of the main processor 121 while the main processor 121 is in an inactive (e.g., sleep) state, or while the main processor 121 is in an active (e.g., application execution) state. ), together with the main processor 121, at least one of the components of the electronic device 101 (e.g., the display module 160, the sensor module 176, or the communication module 190) At least some of the functions or states related to can be controlled.
- coprocessor 123 e.g., image signal processor or communication processor
- may be part of another functionally related component e.g., camera module 180 or communication module 190. It can be implemented.
- the auxiliary processor 123 may include a hardware structure specialized for processing artificial intelligence models.
- Artificial intelligence models can be created through machine learning. For example, such learning may be performed in the electronic device 101 itself, where artificial intelligence is performed, or may be performed through a separate server (e.g., server 108).
- Learning algorithms may include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but It is not limited.
- An artificial intelligence model may include multiple artificial neural network layers.
- Artificial neural networks include deep neural network (DNN), convolutional neural network (CNN), recurrent neural network (RNN), restricted boltzmann machine (RBM), belief deep network (DBN), bidirectional recurrent deep neural network (BRDNN), It may be one of deep Q-networks or a combination of two or more of the above, but is not limited to the examples described above.
- artificial intelligence models may additionally or alternatively include software structures.
- the memory 130 may store various data used by at least one component (eg, the processor 120 or the sensor module 176) of the electronic device 101. Data may include, for example, input data or output data for software (e.g., program 140) and instructions related thereto.
- Memory 130 may include volatile memory 132 or non-volatile memory 134.
- the program 140 may be stored as software in the memory 130 and may include, for example, an operating system 142, middleware 144, or application 146.
- the input module 150 may receive commands or data to be used in a component of the electronic device 101 (e.g., the processor 120) from outside the electronic device 101 (e.g., a user).
- the input module 150 may include, for example, a microphone, mouse, keyboard, keys (eg, buttons), or digital pen (eg, stylus pen).
- the sound output module 155 may output sound signals to the outside of the electronic device 101.
- the sound output module 155 may include, for example, a speaker or a receiver. Speakers can be used for general purposes such as multimedia playback or recording playback.
- the receiver can be used to receive incoming calls. According to one or more embodiments, the receiver may be implemented separately from the speaker or as part of it.
- the display module 160 can visually provide information to the outside of the electronic device 101 (eg, a user).
- the display module 160 may include, for example, a display, a hologram device, or a projector, and a control circuit for controlling the device.
- the display module 160 may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of force generated by the touch.
- the audio module 170 can convert sound into an electrical signal or, conversely, convert an electrical signal into sound. According to one or more embodiments, the audio module 170 acquires sound through the input module 150, the sound output module 155, or an external electronic device connected directly or wirelessly to the electronic device 101. Sound may be output through (e.g., electronic device 102) (e.g., speaker or headphone).
- electronic device 102 e.g., speaker or headphone
- the sensor module 176 detects the operating state (e.g., power or temperature) of the electronic device 101 or the external environmental state (e.g., user state) and generates an electrical signal or data value corresponding to the detected state. can do.
- the sensor module 176 may include, for example, a gesture sensor, a gyro sensor, an air pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, It may include a biometric sensor, temperature sensor, humidity sensor, or illuminance sensor.
- the interface 177 may support one or more designated protocols that can be used to connect the electronic device 101 directly or wirelessly with an external electronic device (eg, the electronic device 102).
- the interface 177 may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
- HDMI high definition multimedia interface
- USB universal serial bus
- SD card interface Secure Digital Card
- connection terminal 178 may include a connector through which the electronic device 101 can be physically connected to an external electronic device (eg, the electronic device 102).
- the connection terminal 178 may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (eg, a headphone connector).
- the haptic module 179 can convert electrical signals into mechanical stimulation (e.g., vibration or movement) or electrical stimulation that the user can perceive through tactile or kinesthetic senses.
- the haptic module 179 may include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
- the camera module 180 can capture still images and moving images. According to one or more embodiments, the camera module 180 may include one or more lenses, image sensors, image signal processors, or flashes.
- the power management module 188 can manage power supplied to the electronic device 101.
- the power management module 188 may be implemented as at least a part of, for example, a power management integrated circuit (PMIC).
- PMIC power management integrated circuit
- the battery 189 may supply power to at least one component of the electronic device 101.
- the battery 189 may include, for example, a non-rechargeable primary cell, a rechargeable secondary cell, or a fuel cell.
- Communication module 190 is configured to provide a direct (e.g., wired) communication channel or wireless communication channel between electronic device 101 and an external electronic device (e.g., electronic device 102, electronic device 104, or server 108). It can support establishment and communication through established communication channels. Communication module 190 operates independently of processor 120 (e.g., an application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one or more embodiments, the communication module 190 may be a wireless communication module 192 (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194.
- GNSS global navigation satellite system
- the corresponding communication module is a first network 198 (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network 199 (e.g., legacy It may communicate with an external electronic device 104 through a telecommunication network such as a cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., LAN or WAN).
- a first network 198 e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)
- a second network 199 e.g., legacy It may communicate with an external electronic device 104 through a telecommunication network such as a cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., LAN or WAN).
- a telecommunication network
- the wireless communication module 192 uses subscriber information (e.g., International Mobile Subscriber Identifier (IMSI)) stored in the subscriber identification module 196 to communicate within a communication network such as the first network 198 or the second network 199.
- subscriber information e.g., International Mobile Subscriber Identifier (IMSI)
- IMSI International Mobile Subscriber Identifier
- the wireless communication module 192 may support 5G networks after 4G networks and next-generation communication technologies, for example, NR access technology (new radio access technology).
- NR access technology provides high-speed transmission of high-capacity data (enhanced mobile broadband (eMBB)), minimization of terminal power and access to multiple terminals (massive machine type communications (mMTC)), or ultra-reliable and low-latency (URLLC). -latency communications)) can be supported.
- the wireless communication module 192 may support high frequency bands (eg, mmWave bands), for example, to achieve high data rates.
- the wireless communication module 192 uses various technologies to secure performance in high frequency bands, for example, beamforming, massive array multiple-input and multiple-output (MIMO), and full-dimensional multiplexing.
- MIMO massive array multiple-input and multiple-output
- the wireless communication module 192 may support various requirements specified in the electronic device 101, an external electronic device (e.g., electronic device 104), or a network system (e.g., second network 199). According to one or more embodiments, the wireless communication module 192 may provide peak data rate (e.g., 20 Gbps or more) for realizing eMBB, loss coverage (e.g., 164 dB or less) for realizing mmTC, or U- Can support plane latency (e.g., downlink (DL) and uplink (UL) of 0.5 ms or less each, or round trip of 1 ms or less).
- peak data rate e.g., 20 Gbps or more
- loss coverage e.g., 164 dB or less
- U- Can support plane latency e.g., downlink (DL) and uplink (UL) of 0.5 ms or less each, or round trip of 1 ms or less.
- the antenna module 197 may transmit or receive signals or power to or from the outside (eg, an external electronic device).
- the antenna module 197 may include an antenna including a radiator made of a conductor or a conductive pattern formed on a substrate (eg, PCB).
- the antenna module 197 may include a plurality of antennas (eg, an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network such as the first network 198 or the second network 199 is, for example, connected to the plurality of antennas by the communication module 190. can be selected. Signals or power may be transmitted or received between the communication module 190 and an external electronic device through the at least one selected antenna.
- other components eg, radio frequency integrated circuit (RFIC) in addition to the radiator may be additionally formed as part of the antenna module 197.
- RFIC radio frequency integrated circuit
- peripheral devices e.g., bus, general purpose input and output (GPIO), serial peripheral interface (SPI), or mobile industry processor interface (MIPI)
- signal e.g. commands or data
- commands or data may be transmitted or received between the electronic device 101 and the external electronic device 104 through the server 108 connected to the second network 199.
- Each of the external electronic devices 102 or 104 may be of the same or different type as the electronic device 101.
- all or part of the operations performed in the electronic device 101 may be executed in one or more of the external electronic devices 102, 104, or 108.
- the electronic device 101 may perform the function or service instead of executing the function or service on its own.
- one or more external electronic devices may be requested to perform at least part of the function or service.
- One or more external electronic devices that have received the request may execute at least part of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device 101.
- the electronic device 101 may process the result as is or additionally and provide it as at least part of a response to the request.
- cloud computing distributed computing, mobile edge computing (MEC), or client-server computing technology can be used.
- the electronic device 101 may provide an ultra-low latency service using, for example, distributed computing or mobile edge computing.
- the external electronic device 104 may include an Internet of Things (IoT) device.
- Server 108 may be an intelligent server using machine learning and/or neural networks.
- the external electronic device 104 or server 108 may be included in the second network 199.
- the electronic device 101 may be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
- Figure 2 is a block diagram 200 of a program 140 according to one or more embodiments.
- the program 140 is an operating system 142, middleware 144, or an application executable on the operating system 142 for controlling one or more resources of the electronic device 101. It may include (146).
- Operating system 142 may include, for example, Android TM , iOS TM , Windows TM , Symbian TM , Tizen TM , or Bada TM .
- At least some of the programs 140 are preloaded into the electronic device 101, for example, during manufacturing, or are stored in an external electronic device (e.g., the electronic device 102 or 104) in an environment in which a user uses the electronic device. , or can be downloaded or updated from the server 108).
- the operating system 142 may control (e.g., allocate or reclaim) system resources (e.g., processes, memory, or power) of the electronic device 101.
- Operating system 142 may additionally or alternatively operate on other hardware devices of electronic device 101, such as input device 150, audio output device 155, display device 160, audio module 170. , sensor module 176, interface 177, haptic module 179, camera module 180, power management module 188, battery 189, communication module 190, subscriber identification module 196, or It may include one or more driver programs for driving the antenna module 197.
- the middleware 144 may provide various functions to the application 146 so that the application 146 can use functions or information provided by one or more resources of the electronic device 101.
- the middleware 144 includes, for example, an application manager 201, a window manager 203, a multimedia manager 205, a resource manager 207, a power manager 209, a database manager 211, and a package manager ( 213), connectivity manager (215), notification manager (217), location manager (219), graphics manager (221), security manager (223), call manager (225), or voice recognition manager (227). can do.
- the application manager 201 may, for example, manage the life cycle of the application 146.
- the window manager 203 can, for example, manage GUI resources used on the screen.
- the multimedia manager 205 may determine the format required for playing media files and encode or decode the media file using a codec suitable for the format.
- the resource manager 207 may, for example, manage the source code or memory space of the application 146.
- the power manager 209 manages, for example, battery capacity, temperature, or power, and can use this information to determine or provide power information necessary for the operation of the electronic device 101.
- the power manager 209 may interface with a basic input/output system (BIOS).
- BIOS basic input/output system
- the database manager 211 may create, search, or change a database to be used in the application 146, for example.
- the package manager 213 may, for example, manage the installation or update of applications distributed in the form of package files.
- the connectivity manager 215 may manage, for example, a wireless or wired connection between the electronic device 101 and an external electronic device.
- the notification manager 217 may provide a function for notifying the user of an event that has occurred (eg, a call, a message, or an alarm).
- the location manager 219 may, for example, manage location information of the electronic device 101.
- the graphics manager 221 may, for example, manage graphic effects to be provided to users or user interfaces related thereto.
- Security manager 223 may provide, for example, system security or user authentication.
- the telephony manager 225 may, for example, manage the voice call or video call function of the electronic device 101.
- the voice recognition manager 227 transmits the user's voice data to the server 108 and generates a command or corresponding voice corresponding to a function to be performed in the electronic device 101 based on the voice data. You can receive converted text data based on the data.
- the middleware 244 may dynamically delete some existing components or add new components.
- at least a portion of the middleware 144 may be included as part of the operating system 142 or may be implemented as software separate from the operating system 142.
- the application 146 includes, for example, home 251, dialer 253, SMS/MMS (255), instant message (IM) 257, browser 259, camera 261, and alarm 263. , Contacts (265), Voice Recognition (267), Email (269), Calendar (271), Media Player (273), Album (275), Watch (277), Health (279) (e.g. exercise amount or blood sugar level, etc. measurement), or environmental information 281 (e.g., barometric pressure, humidity, or temperature information) applications. According to one or more embodiments, the application 146 may further include an information exchange application configured to support information exchange between the electronic device 101 and an external electronic device.
- an information exchange application configured to support information exchange between the electronic device 101 and an external electronic device.
- the information exchange application may include, for example, a notification relay application for delivering designated information (e.g., a call, message, or alarm) to an external electronic device, or a device management application for managing the external electronic device.
- the notification relay application transmits notification information corresponding to an event (e.g., email reception) generated in another application (e.g., email application 269) of the electronic device 101 to an external electronic device.
- notification information may be received from an external electronic device and provided to the user of the electronic device 101.
- the device management application may, for example, control the power (e.g., turn-on or turn-on) of an external electronic device or some component thereof (e.g., display device 160 or camera module 180) that communicates with the electronic device 101. -off) or functions (e.g., brightness, resolution, or focus of the display device 160 or the camera module 180) can be controlled.
- a device management application may additionally or alternatively support installation, deletion, or update of applications running on external electronic devices.
- an electronic device eg, the electronic device 101 of FIG. 1
- the electronic device described below may be implemented like the electronic device 101 described above in FIG. 1, redundant description will be omitted.
- FIG. 3 is a diagram for explaining an example of the configuration of the electronic device 101 according to one or more embodiments.
- the electronic device 101 may be implemented to include more or fewer components than those shown in FIG. 3 .
- FIG. 3 will be described with reference to FIG. 4 .
- FIG. 4 is a diagram illustrating an example of an execution environment according to a program module of an electronic device (eg, the electronic device 101 of FIG. 1 ) according to one or more embodiments.
- the program module 400 may include a rich execution environment (REE) 410 and a trusted execution environment (TEE) 420.
- the REE 410 and TEE 420 may be distinguished, for example, in hardware or in software. In one or more examples, REE 410 and TEE 420 may be physically separated and/or software separated.
- the REE 410 may be an environment in which a general operating system (eg, the operating system 242 of FIG. 2) operates. For example, Android operating system, Windows operating system, Linux operating system, etc. can operate on REE 410.
- TEE 420 may be an environment running a securely secured operating system, for example a secured operating system, or any other working system well known to those skilled in the art.
- a secure operating system such as Qualcomm's QSee, Trustonic's Kinibi, etc. may operate on the TEE 420.
- applications supporting iSIM functionality may operate on TEE 420.
- Data processing based on a secure operating system may be performed securely and safely within the TEE 420.
- TEE 420 includes a trust zone, a secure execution environment, a platform security processor, trusted execution technology, software guard extensions, Alternatively, it may be implemented in various ways, such as any other implementation configuration known to those skilled in the art, and a person skilled in the art will easily understand that there is no limitation to the implemented configuration.
- the REE 410 may include an application layer 411, a framework layer 412, and a kernel layer 413.
- various applications eg, application 246 in FIG. 2
- the framework layer 412 may operate functions that support the operation of applications and services provided by the operating system.
- the kernel layer 413 may be a layer in which core functions of the operating system operate.
- the kernel layer 413 for example, may be configured to control or manage system resources used to execute operations or functions implemented in other programs. Additionally, the kernel layer 413 may provide an interface for controlling or managing system resources by accessing individual components of the electronic device 101.
- TEE 420 includes a trusted application layer 421, a trusted framework layer 422, and a secured operating system kernel layer. (423) may be included.
- a trusted application can operate.
- the electronic device 101 may execute an application that performs the iSIM function in the trusted application layer 421.
- a trusted application can create, transmit, receive, and store data requiring security during the execution of the application, which will be described in more detail later.
- Trusted framework layer 422 may run an operating system running on TEE 420, such as a security operating system.
- the security OS kernel layer 423 may be a layer in which the core functions of the security operating system operate.
- the secure OS kernel layer 423 may control or manage system resources used to execute, for example, trusted applications or operations or functions implemented in the secure operating system.
- various hardware eg, memory 330 and processor 320 of the electronic device 101 may operate.
- the processor 320 may include a first processor 321 and a second processor 322.
- the first processor 321 and the second processor 322 perform operations executed in a plurality of execution environments (e.g., REE 410 and TEE 420) isolated from each other. can do.
- the plurality of execution environments may be implemented as software-isolated execution environments, hardware-isolated execution environments, or a combination thereof.
- each of the first processor 321 and the second processor 322 operates in at least one of a plurality of execution environments to perform a designated operation, and/or the electronic device 101 It is possible to control at least one hardware component included in .
- the first processor 321 may include an application processor (AP) and may perform operations executed in the REE (410).
- the second processor 322 may include a secure processor (SP) and may perform operations executed in the TEE 420.
- Operations of the processor 320 eg, the first processor 321 and the second processor 322) described below may be performed according to the execution of modules stored in the memory 330.
- the modules may be implemented (eg, executed) in software, firmware, or a combination of at least two or more thereof.
- the modules are in the form of applications, programs, computer code, instructions, routines, or processes that can be executed by the processor 320.
- each module may be implemented as hardware (e.g., processor, control circuit) separate from the processor 320.
- the memory 330 may include a first memory 331, a second memory 332, a third memory 333, and a fourth memory 334.
- the first memory 331 (eg, at least a portion of the non-volatile memory 138 of FIG. 1) is a non-secure memory and may be a non-volatile memory.
- the first memory 332 may store data output from an application running on the application layer 311 of the REE (410).
- an application is executed in the application layer 411 by the first processor 321, and the first processor 321 transmits data generated during application execution to the first processor 321 through the kernel layer 413. It can be stored in memory 332.
- the first processor 321 may read data required during application execution from the first memory 331 through the kernel layer 413.
- the second memory 332 is a volatile memory and may be a shared memory shared between the REE 410 and the TEE 420.
- the second memory 332 may be dynamic random access memory (DRAM).
- the second memory 332 may temporarily store at least some of the security data output from a trusted application operating in the trusted application layer 421 under the control of the first processor 321 and the second processor 322. there is.
- the trusted application is executed in the trusted application layer 421 by the second processor 322, and the second processor 322 transfers data to the secure OS kernel as the trusted application is executed.
- a request is made to the first processor 321 through the mailbox of the layer 423, and the first processor 321 sends a currently running daemon to the second processor 322 through the mailbox of the kernel layer 413.
- the data stored in the first memory 331 can be read through the daemon and temporarily stored in the second memory 332.
- the second processor 322 may read data temporarily stored in the second memory 332 through the secure OS kernel layer 423 and transmit it to the trusted application layer 421.
- the trusted application is executed in the trusted application layer 421 by the second processor 322, and the second processor 322 collects the security data generated as the trusted application is executed. It may be stored in the second memory 332, and storage of the security data temporarily stored in the second memory 332 may be requested from the first processor 321 through the mail box of the security OS kernel layer 423.
- the first processor 321 temporarily stores the request in the second memory 332 through the daemon.
- Security data can be read and stored in the first memory 331.
- the request from the second processor 322 may include the address of the second memory 332 where the security data is stored.
- the third memory 333 may be a volatile memory (eg, volatile memory 132 of FIG. 1) and may have a lower capacity than the first memory 331.
- the third memory 333 may be static random access memory (SRAM).
- the third memory 333 may temporarily store at least some of the security data output from a trusted application running in the trusted application layer 421.
- a trusted application is executed in the trusted application layer 421 by the second processor 322, and the second processor 322 selects the security data generated as the trusted application is executed. At least part of it can be temporarily stored in the third memory 333 through the security OS kernel layer 423.
- data stored in the third memory 333 may be encrypted and copied (e.g., swapped out) to the second memory 332.
- Data stored in the second memory 332 may be decrypted and copied (eg, swapped in) to the third memory 333.
- the fourth memory 334 (eg, at least a portion of the non-volatile memory 138 of FIG. 1) is a non-volatile memory and may be a secure memory.
- the fourth memory 334 may store at least some of the security data output from a trusted application running in the trusted application layer 421.
- a trusted application is executed in the trusted application layer 421 by the second processor 322, and the second processor 322 selects the security data generated as the trusted application is executed. At least part of it can be stored in the fourth memory 334 through the security OS kernel layer 423.
- the fourth memory 334 may be a storage space where data read, modify, or delete functions are rarely performed.
- the electronic device 101 may be set to allow access to the fourth memory 334 only for a specific command set. For example, according to a command from a trusted application, data in the fourth memory 334 may be read, modified, or deleted. In addition, data in the fourth memory 334 may not be read, modified, or deleted depending on a command from a general application rather than a trusted application. According to one or more embodiments, information used in the process of encrypting secure data may be stored in the fourth memory 334. Information stored in the fourth memory 334 can be used to decrypt encrypted security data at a later time. This will be described in more detail later.
- the electronic device 101 performs a plurality of execution functions based on hardware (e.g., memories 331 to 334 and/or processors 321 and 322) implemented independently from each other. It may be implemented to perform an operation (or function) in environments.
- different pieces of hardware associated with different permissions may be allocated to a plurality of execution environments (e.g., REE 410 and TEE 420). For example, referring to FIG. 4, hardware devices located to the left of the dotted line are assigned to the REE (410) (or run in the REE (410)), and hardware devices located to the right are assigned to the TEE (420). It may be assigned to (or driven in the TEE 420). For example, referring to FIG.
- different memories 331 to 334 may be allocated to a plurality of execution environments (eg, REE 410 and TEE 420).
- the first processor 321 executes the first operating system on the REE 410 to perform at least one operation, and reads and writes data to the first memory 331 allocated to the REE 410. there is.
- the second processor 322 executes a second operating system separate and independent from the first operating system of the REE 410 in the TEE 420 to perform at least one operation, and performs at least one operation in the TEE 420. Data can be read and written to the third memory 323 and the fourth memory 334.
- the authority and/or security for the TEE 420 may be higher than the authority and/or security for the REE 410.
- the second processor 322 may access the first memory 331 allocated to the REE 410 in the TEE 420 to read and write data, but the first processor 321 may Access from the REE 410 to the fourth memory 334 allocated to the TEE 420 may be restricted. For example, the first processor 321 may not be able to write data to the fourth memory 334 or read data stored in the fourth memory 334. According to one or more embodiments, access to the second memory 332 by the REE 410 and the TEE 420 may be permitted. For example, the first processor 321 may write data to the second memory 332 in the REE 410 or read data stored in the second memory 332. For example, the second processor 322 may write data to the second memory 332 in the TEE 420 or read data stored in the second memory 332.
- the electronic device 101 encrypts the security data generated by the execution of the trusted application in the TEE 420 and stores the first memory allocated to the REE 410 through the second memory 332. It can be stored in the memory 331 in the form of a file, and information used to encrypt and/or decrypt security data can be stored in the fourth memory 334.
- the electronic device 101 stores the first memory 331 allocated to the REE 410 through a daemon currently running in the REE 410.
- FIG. 5 is a flowchart 500 illustrating an example of an operation of the electronic device 101 according to one or more embodiments.
- the operations shown in FIG. 5 are not limited to the order shown and may be performed in a variety of orders. Additionally, according to one or more embodiments, more operations may be performed, or at least one operation less than the operations shown in FIG. 5 may be performed. Below, FIG. 5 will be described with reference to FIG. 6 .
- the electronic device 101 executes a trusted application in the trusted application layer 421 of the TEE 420 in operation 501 to collect secure data.
- a trusted application in the trusted application layer 421 of the TEE 420 in operation 501 to collect secure data.
- the data generated includes information that requires security, such as subscriber identification information, authentication key, subscriber phone number, local area ID, personal identification number (PIN), and service provider information. It may include at least one of:
- security data may vary depending on the application being executed and may include information specified by the developer of the application.
- the electronic device 101 e.g., the second processor 322) stores security data (e.g., 631 in FIG. 6) generated by execution of a trusted application in the third memory 333 through the secure OS kernel layer 423. ) can be temporarily stored in .
- the electronic device 101 encrypts the security data or a portion thereof in use in the trusted application in operation 503 (e.g., 601 in FIG. 6) and secures the security OS kernel layer 423. It can be copied (e.g., swap out) to the second memory 332 (e.g., 621 in FIG. 6).
- advanced encryption standard (AES)-galois/counter mode (GCM) may be used to encrypt data.
- AES advanced encryption standard
- GCM Galois/counter mode
- the encryption method is not limited to this, and other encryption methods known to those skilled in the art that ensure confidentiality and integrity may be used.
- data encryption may be performed in blocks by dividing data into predetermined sizes.
- rolling back encrypted data may include changing the encrypted data to a previous form, such as unencrypted data.
- an anti-replay counter (ARC) may be used to prevent rollback.
- different ARC values may be used for each data block. Different ARC values used for each data block may be temporarily stored in the third memory 333 in table form. In one or more embodiments, different ARC values used for each data block may be temporarily stored in the third memory 333 in the form of a table (eg, 632 in FIG. 6).
- the ARC table may be a linear array composed of ARC values.
- the number of ARC values may be determined according to the size of the security data copied (eg, swapped out) to the second memory 332. For example, 256 ARC values can be used to encrypt 2MB of secure data and copy (e.g., swap out) it to the second memory 332. Each ARC value may be increased by 1 from a predetermined initial value.
- secure data is copied (e.g., swap out) to the second memory 332 or copied (e.g., swap in) from the second memory 332
- the corresponding ARC value is used to encrypt the secure data.
- it can be used as an initial vector (IV) of a decoding operation.
- IV may be calculated by the following equation:
- the device specific value is a value unique to the electronic device and may consist of 4 bytes.
- ARC can be composed of 8 bytes, and IV can be composed of 16 bytes including 4 bytes of zero padding.
- the electronic device 101 encrypts the parameter values generated in the process of encrypting data in block units and stores them in the second memory 332 through the security OS kernel layer 423 ( Example: swap out).
- a tag (TAG) (e.g., 651 in FIG. 6) is generated for each data block, and the electronic device 101 (e.g., the second The processor 322) encrypts the tags generated during the encryption process in table form (e.g., 603 in FIG. 6) and stores them (e.g., swap out) in the second memory 332 through the security OS kernel layer 423. (e.g. 623 in FIG. 6).
- AES-ECB electronic code block
- the encryption method is not limited to this, and other encryption methods known to those skilled in the art that ensure confidentiality may be used.
- the electronic device 101 encrypts the information generated during the data encryption process and stored in the third memory 333 to establish the secure OS kernel layer 423. It can be copied (eg, swapped out) to the second memory 332.
- the electronic device 101 e.g., the second processor 322 encrypts the ARC table stored in the third memory 333 (e.g., 605 in FIG. 6) to create a secure OS kernel layer ( 423) can be copied (e.g., swap out) to the second memory 332 (e.g., 622 in FIG. 6).
- AES-GCM may be used to encrypt the ARC table.
- the encryption method is not limited to this, and other encryption methods known to those skilled in the art that ensure confidentiality and integrity may be used.
- the electronic device 101 e.g., the second processor 322 is used when encrypting information generated in the encryption process and stores the generated parameters in the fourth memory through the secure OS kernel 423. It can be saved at (334).
- the electronic device 101 e.g., the second processor 322 may use the master ARC as an initial vector (IV) when encrypting the ARC table. Master ARC can be generated as a random value each time secure data generated from a trusted application is stored.
- a master ARC may be used when decrypting an encrypted ARC table.
- the electronic device 101 may store the master ARC in the fourth memory 334 through the secure OS kernel layer 423 (e.g., 641 in FIG. 6). .
- a master tag may be created in the process of encrypting the ARC table. The master tag can be used when decrypting an encrypted ARC table.
- the electronic device 101 e.g., the second processor 322 may store the master tag in the fourth memory 334 through the secure OS kernel layer 423 (e.g., 642 in FIG. 6). .
- the electronic device 101 may store the encrypted data stored in the second memory 332 in the first memory 331 allocated to the REE 410.
- the second processor 322 of the electronic device 101 sends secure data assigned to the REE 410 to the first processor 321 through the mailbox of the secure OS kernel layer 423. It may be requested to store it in the first memory 331.
- the first processor 321 of the electronic device 101 may receive a request for security data from the second processor 322 through the mail box of the kernel layer 413 while running a daemon in the REE 410. .
- the request transmitted from the second processor 322 to the first processor 321 may include the address of the second memory 332 where the security data is stored.
- the first processor 321 of the electronic device 101 reads the encrypted data stored in the second memory 332 through a daemon running in the REE 410 and encrypted data read through the kernel layer 413. may be stored in the first memory 331 (e.g., 607 in FIG. 6).
- the encrypted data stored in the second memory 332 includes encrypted security data (e.g., 611 in FIG. 6), an encrypted ARC table (e.g., 612 in FIG. 6), and an encrypted tag. It may include a table (e.g., 613 in FIG. 6), and the encrypted data may be stored in the first memory 331 in the form of a single file (e.g., 610 in FIG. 6).
- FIG. 7 is a flowchart 700 illustrating an example of an operation of the electronic device 101 according to one or more embodiments.
- the operations shown in FIG. 7 are not limited to the order shown and can be performed in a variety of orders. Additionally, according to one or more embodiments, more operations may be performed, or at least one operation less than the operations shown in FIG. 7 may be performed. Below, FIG. 7 will be described with reference to FIG. 8 .
- the electronic device 101 may execute a trusted application in the trusted application layer 421 of the TEE 420 in operation 701.
- the second processor 322 sends the security information stored in the first memory 331 to the first processor 321 via the mailbox of the secure OS kernel 423. You can request data.
- the electronic device 101 may read the encrypted data file (e.g., 610 in FIG. 8) stored in the first memory 331 in operation 703 (e.g., 801).
- the encrypted data file e.g., 610 in FIG. 8 stored in the second memory 332 can be read (e.g., 801 in FIG. 8).
- the first memory 331 contains encrypted data (e.g., 611 in FIG. 8), encryption An encrypted ARC table (e.g., 612 in FIG. 8) and an encrypted tag table (e.g., 613 in FIG. 8) may be stored.
- the electronic device 101 e.g., the first processor 321 encodes the encrypted data included in the file read from the first memory 331 (e.g., 611 in FIG. 8) and the encrypted ARC table (e.g. : 612 in FIG. 8), and the encrypted tag table (e.g., 613 in FIG. 8) can be copied to the second memory 332.
- the first processor 321 encodes data included in a file read from the first memory 331 through a daemon running in the REE 410 (e.g., 611 in FIG. 8),
- the encrypted ARC table e.g., 612 in FIG. 8
- the encrypted tag table e.g., 613 in FIG. 8
- the electronic device 101 can decrypt the encrypted data (e.g., 611 in FIG. 8) copied to the second memory 332 in operation 705 for use in a trusted application. there is.
- the electronic device 101 e.g., the second processor 322 may store encrypted data (e.g., 411 in FIG. 6), an encrypted ARC table (e.g., 612 in FIG. 8), and encryption. Each tag table (e.g., 613 in FIG. 8) can be decrypted.
- the electronic device 101 e.g., the second processor 322) may verify and decrypt the encrypted data generated during the encryption process using encryption information stored in the fourth memory 334. .
- the electronic device 101 may decrypt (e.g., 803 of FIG. 8) the encrypted ARC table (e.g., 622 of FIG. 8).
- the fourth memory 334 includes a master ARC created and used in the encryption process (e.g., 641 in FIG. 8). and master tag (e.g., 642 in FIG. 8) are stored.
- the second processor 322 stores the master ARC (e.g., 641 in FIG. 8) and the master tag (e.g., 641 in FIG.
- a master tag may be used for verification of an encrypted ARC table.
- the electronic device 101 e.g., the second processor 322 may store (swap in) the decrypted ARC table in the third memory 333 through the secure OS kernel layer 423 (e.g., FIG. 8 632).
- the electronic device 101 may decrypt the encrypted security data using the decrypted information.
- the electronic device 101 e.g., the second processor 322 stores the ARC values of the decrypted ARC table (e.g., 632 in FIG. 8) and the decrypted ARC values copied to the second memory 332.
- the encrypted security data e.g., 621 in FIG. 8 copied to the second memory 332 can be decrypted in block units (e.g., in FIG. 8 of 805). For example, data may be split into one or more blocks, where the data is encrypted block by block and then decrypted block by block.
- the electronic device 101 (e.g., the second processor 322) stores the decrypted security data in the third memory 333 through the secure OS kernel layer 423 (e.g., swap in) can be done (e.g., 631 in FIG. 8). Thereafter, the electronic device 101 (e.g., the second processor 322) uses the decrypted security data stored in the third memory 333 through a trusted application running in the trusted application layer 421 of the TEE 420. You can use it.
- the secure OS kernel layer 423 e.g., swap in
- the electronic device 101 e.g., the second processor 322 uses the decrypted security data stored in the third memory 333 through a trusted application running in the trusted application layer 421 of the TEE 420. You can use it.
- FIG. 9 is a diagram illustrating an example of the format of security data stored in the fourth memory 334 of the electronic device 101 according to one or more embodiments.
- At least some of the security data output from a trusted application running on the trusted application layer 421 may be stored in the fourth memory 334 .
- a trusted application is executed in the trusted application layer 421 by the second processor 322, and the second processor 322 selects the security data generated as the trusted application is executed. At least part of it can be stored in the fourth memory 334 through the security OS kernel layer 423. According to one or more embodiments, information used in the process of encrypting secure data may be stored in the fourth memory 334.
- data 910 generated by execution of trusted application number 1 may be stored in slot A (slot A) 920 of the fourth memory 334.
- Data including 916 may be stored in the fourth memory 334.
- Data stored in the fourth memory 334 includes a magic field 911, a version field 912, and an active set, in addition to the master ARC field 915 and the master tag field 916. It may further include a field 913, a data size field 914, and a Reserved field 917.
- the magic field 911 may consist of 4 bytes and may be an integer used to confirm a command.
- the version field 912 may consist of 4 bytes and may be a value representing version information of the corresponding data.
- the active set field 913 may consist of 4 bytes and may be a flag value indicating a set in which correct information is stored.
- the data size field 914 may consist of 4 bytes and may be a value indicating the size of security data generated by the corresponding trusted application.
- the master ARC field 915 may consist of 8 bytes, and the master ARC may be a random value generated each time secure data generated from a trusted application is stored. Master ARC can be used as an IV (initial vector) when encrypting an ARC table or decrypting an encrypted ARC table.
- the master tag field 916 may consist of 16 bytes, and the master tag may be an authentication tag created as a result of an encryption operation when the ARC table is encrypted and copied (e.g., swapped out) to the second memory 332.
- the master tag can be used as an authentication tag when decrypting an encrypted ARC table.
- An electronic device includes a first processor 321 operating in a general environment 410; a second processor 322 operating in a secure environment 420; a first memory 331 allocated to the general environment; a second memory 334 allocated to the secure environment; and a third memory 332 shared between the general environment and the secure environment.
- the second processor encrypts at least some of the secure data generated by a trusted application running in the secure environment and stores it in the third memory, and encodes first information used to encrypt at least some of the secure data. and may be set to store second information generated in the process of encrypting at least part of the secure data in the second memory.
- the first processor may be set to store at least some of the encrypted secure data stored in the third memory in the first memory.
- the second processor encrypts the at least some of the secure data in blocks, using different anti-replay counter (ARC) values for each block, and the ARC values are
- the stored ARC table 432 can be encrypted, and the tag values 651 generated in the process of encrypting at least some of the security data in block units can be set to encrypt the stored tag table.
- the first processor stores at least some of the encrypted secure data 611, the encrypted ARC table 612, and the encrypted tag table 613 in a file format 610. It can be set to be stored in the first memory.
- the first information may be a master ARC (641), and the second information may be a master tag (642).
- the first processor copies at least some of the encrypted security data stored in the first memory and stores it in the third memory.
- the second processor may be set to decrypt at least some of the encrypted secure data stored in the third memory using the first information and the second information.
- At least some of the encrypted secure data stored in the third memory is an encryption device in which ARC (anti-replay counter) values used in the process of encrypting the at least some secure data in block units are stored. It includes an ARC table 622 and an encrypted tag table 623 in which tag values generated in the process of encrypting at least some of the secure data in blocks are stored, and the second processor is configured to store the first information and the Decrypt the encrypted ARC table using second information, decrypt the tag table, and decrypt at least some of the secure data encrypted in blocks using the decrypted ARC table and the decrypted tag table. It can be set to do so.
- ARC anti-replay counter
- the first processor reads a file 610 containing the encrypted secure data, the encrypted ARC table, and the encrypted tag table from the first memory, and performs the encryption
- the encrypted security data, the encrypted ARC table, and the encrypted tag table may be set to be separated and stored in the third memory.
- the second processor is configured to encrypt at least some of the secure data and the ARC table using an advanced encryption standard (AES)-galois/counter mode (GCM) method. You can.
- AES advanced encryption standard
- GCM Galois/counter mode
- the second processor may be configured to decrypt at least some of the encrypted secure data using an advanced encryption standard (AES)-galois/counter mode (GCM) method.
- AES advanced encryption standard
- GCM Galois/counter mode
- the second processor may be configured to encrypt the tag table using an advanced encryption standard (AES)-electronic code block (ECB) method.
- AES advanced encryption standard
- EBC electronic code block
- a method of operating an electronic device includes an operation (501) of executing a trusted application in a secure environment and generating secure data by a first processor 322 operating in a secure environment 420. ) may include.
- the method includes an operation 503 of encrypting at least some of the generated security data by the first processor and storing it in a first memory 332 shared between the secure environment and the general environment 410. can do.
- the method allocates, by the first processor, first information used to encrypt at least part of the secure data and second information generated in the process of encrypting at least part of the secure data to the security area. It may include an operation 503 of storing the data in the second memory 334.
- the method includes storing at least some of the encrypted security data stored in the first memory in a third memory 331 allocated to the general environment by a second processor 321 operating in the general environment. Operation 505 may be included.
- the encryption operation 503 encrypts the at least some secure data in blocks by the first processor, and uses different anti-replay counter (ARC) values for each block.
- the operation 505 of storing in the third memory includes, by the second processor, the encrypted at least some secure data, the encrypted ARC table, and the encrypted tag table. It may include an operation of storing (607) in the first memory in a file format (610).
- the first information may be a master ARC (641), and the second information may be a master tag (642).
- At least some of the encrypted secure data stored in the first memory is copied by the second processor to the second processor.
- An operation of storing in a memory (703), an operation of decrypting at least some of the encrypted security data stored in the first memory by the first processor using the first information and the second information (705) ) may further be included.
- At least some of the encrypted secure data stored in the first memory is an encryption device in which ARC (anti-replay counter) values used in the process of encrypting the at least some secure data in block units are stored. It includes an ARC table 621 and an encrypted tag table 623 in which tag values generated in the process of encrypting at least some of the secure data in block units are stored, and the decryption operation 705 includes the first By a processor, an operation of decrypting the encrypted ARC table using the first information and the second information (803), an operation of decrypting the tag table (805), and the decrypted ARC table and the decrypted An operation 805 of decrypting at least some of the secure data encrypted in blocks using a tag table may be included.
- ARC anti-replay counter
- a file 610 containing the encrypted secure data, the encrypted ARC table, and the encrypted tag table is read, by the second processor, from the third memory (801). ), separating the encrypted security data 621, the encrypted ARC table 622, and the encrypted tag table 623 and storing them in the first memory.
- the encryption operations 601 and 605 include encryption using an advanced encryption standard (AES)-galois/counter mode (GCM) method when encrypting at least some of the secure data and the ARC table. can do.
- AES advanced encryption standard
- GCM Galois/counter mode
- the decryption operation 705 may decrypt at least some of the encrypted secure data using an advanced encryption standard (AES)-galois/counter mode (GCM) method.
- AES advanced encryption standard
- GCM Galois/counter mode
- the operation 603 of encrypting the tag table may be performed using an advanced encryption standard (AES)-electronic code block (ECB) method.
- AES advanced encryption standard
- EBC electronic code block
- An electronic device may be of various types.
- Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances.
- Electronic devices according to one or more embodiments of this document are not limited to the above-described devices.
- first, second, or first or second may be used simply to distinguish one component from another, and to refer to those components in other respects (e.g., importance or order) is not limited.
- One (e.g., first) component is said to be “coupled” or “connected” to another (e.g., second) component, with or without the terms “functionally” or “communicatively.”
- module used in one embodiment of this document may include a unit implemented in hardware, software, or firmware, and is interchangeable with terms such as logic, logic block, component, or circuit, for example. can be used
- a module may be an integrated part or a minimum unit of the parts or a part thereof that performs one or more functions.
- the module may be implemented in the form of an application-specific integrated circuit (ASIC).
- ASIC application-specific integrated circuit
- One or more embodiments of this document are stored in a storage medium (e.g., built-in memory 136 or external memory 138) that can be read by a machine (e.g., electronic device 101). It may be implemented as software (e.g., program 140) including one or more instructions.
- a processor e.g., processor 120
- the one or more instructions may include code generated by a compiler or code that can be executed by an interpreter.
- a storage medium that can be read by a device may be provided in the form of a non-transitory storage medium.
- 'non-transitory' only means that the storage medium is a tangible device and does not contain signals (e.g. electromagnetic waves).
- This term refers to cases where data is stored semi-permanently in the storage medium. There is no distinction between cases where it is temporarily stored.
- a method according to one or more embodiments disclosed in this document may be provided and included in a computer program product.
- Computer program products are commodities and can be traded between sellers and buyers.
- the computer program product may be distributed in the form of a machine-readable storage medium (e.g. compact disc read only memory (CD-ROM)) or through an application store (e.g. Play StoreTM) or on two user devices (e.g. It can be distributed (e.g. downloaded or uploaded) directly between smart phones) or online.
- a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or a relay server.
- each component e.g., module or program of the above-described components may include a single or plural entity, and some of the plurality of entities may be separately arranged in other components. It could be. According to one or more embodiments, one or more of the components or operations described above may be omitted, or one or more other components or operations may be added. Alternatively or additionally, multiple components (eg, modules or programs) may be integrated into a single component. In this case, the integrated component may perform one or more functions of each component of the plurality of components identically or similarly to those performed by the corresponding component of the plurality of components prior to the integration. .
- operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or , or one or more other operations may be added.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Theoretical Computer Science (AREA)
- Software Systems (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- General Engineering & Computer Science (AREA)
- Physics & Mathematics (AREA)
- Signal Processing (AREA)
- General Health & Medical Sciences (AREA)
- Bioethics (AREA)
- Health & Medical Sciences (AREA)
- Computer Networks & Wireless Communication (AREA)
- Telephone Function (AREA)
Abstract
Description
Claims (15)
- 전자 장치(101)에 있어서,일반 비보안 환경(410)에서 동작하는 제1 프로세서(321);보안 환경(420)에서 동작하는 제2 프로세서(322);상기 일반 비보안 환경에 할당된 제1 메모리(331);상기 보안 환경에 할당된 제2 메모리(334); 및상기 일반 비보안 환경과 상기 보안 환경에서 공유되는 제3 메모리(332)를 포함하며,상기 제2 프로세서는,암호화 된 부분을 생성하기 위해 보안 데이터 중 적어도 일부를 암호화 하고, 상기 보안 데이터는 상기 보안 환경에서 실행되는 신뢰된 어플리케이션에 의해 생성되고,상기 암호화 된 부분을 상기 제3 메모리에 저장하고,상기 보안 데이터 중 적어도 일부를 암호화 하기 위하여 사용되는 제1 정보 및 상기 보안 데이터 중 적어도 일부를 암호화 하는 과정에서 생성되는 제2 정보를 상기 제2 메모리에 저장하고,상기 제1 프로세서는,상기 제3 메모리에 저장된, 상기 암호화 된 부분을 상기 제1 메모리에 저장하도록 설정된 전자 장치.
- 제1항에 있어서,상기 제2 프로세서는,상기 적어도 일부의 보안 데이터를 블록 단위로 암호화 하되, 상기 블록 별로 서로 다른 ARC(anti-replay counter) 값들을 사용하여 암호화 하고,상기 블록 별로 상기 ARC 값들이 저장된 ARC 테이블(432)을 암호화 하며,상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 생성되는 태그값들(651)이 저장된 태그 테이블을 암호화 하도록 설정되는 것을 특징으로 하는 전자 장치.
- 제2항에 있어서,상기 제1 프로세서는,상기 암호화 된 적어도 일부의 보안 데이터(611), 상기 암호화 된 ARC 테이블(612), 및 상기 암호화 된 태그 테이블(613)을 파일 형태(610)로 상기 제1 메모리에 저장하도록 설정되는 것을 특징으로 하는 전자 장치.
- 제2항 또는 제3항에 있어서,상기 제1 정보는 마스터 ARC(641)이고, 상기 제2 정보는 마스터 태그(642)임을 특징으로 하는 전자 장치.
- 제1항 내지 제4항 중 어느 한 항에 있어서,상기 제1 프로세서는,상기 보안 환경에서 상기 신뢰된 어플리케이션이 실행됨에 따라, 상기 제1 메모리에 저장된 상기 암호화 된 부분을 복사된 부분으로서 복사하고, 상기 복사된 부분을 상기 제3 메모리에 저장하며,상기 제2 프로세서는,상기 제1 정보 및 상기 제2 정보를 이용하여, 상기 제3 메모리에 저장된 상기 암호화 된 부분을 복호화 하도록 설정되는 전자 장치.
- 제5항에 있어서,상기 제3 메모리에 저장된 상기 암호화 된 부분은,상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 사용된 ARC(anti-replay counter)값들이 저장된 암호화 된 ARC 테이블(622), 상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 생성된 태그 값들이 저장된 암호화 된 태그 테이블(623)을 포함하며,상기 제2 프로세서는,상기 제1 정보 및 상기 제2 정보를 이용하여 상기 암호화 된 ARC 테이블을 복호화 하고,상기 암호화 된 태그 테이블을 복호화 하고,상기 복호화 된 ARC 테이블 및 상기 복호화 된 태그 테이블을 이용하여 상기 암호화 된 부분을 복호화 하도록 설정되는 전자 장치.
- 제5항 또는 제6항에 있어서,상기 제1 프로세서는,상기 제1 메모리로부터 상기 암호화 된 부분, 상기 암호화 된 ARC 테이블, 및 상기 암호화 된 태그 테이블을 포함하는 파일(610)을 독출하고, 상기 암호화 된 부분, 상기 암호화 된 ARC 테이블, 및 상기 암호화 된 태그 테이블을 각각 상기 제3 메모리에 저장하도록 설정된 전자 장치.
- 제2항 내지 제7항 중 어느 한 항에 있어서,상기 제2 프로세서는,상기 보안 데이터 중 적어도 일부와, 상기 ARC 테이블을 암호화 할 때, AES(advanced encryption standard)-GCM(galois/counter mode) 방식으로 암호화 하도록 설정된 전자 장치.
- 제5항 내지 제8항 중 어느 한 항에 있어서,상기 제2 프로세서는,상기 암호화 된 부분을 AES(advanced encryption standard)-GCM(galois/counter mode) 방식으로 복호화 하도록 설정된 전자 장치.
- 제2항 내지 제9항 중 어느 한 항에 있어서,상기 제2 프로세서는,상기 태그 테이블을 암호화 할 때, AES(advanced encryption standard)- ECB(electronic code block) 방식으로 암호화 하도록 설정된 전자 장치.
- 전자 장치(101)의 동작 방법에 있어서,보안 환경(420)에서 동작하는 제1 프로세서(322)에 의해, 상기 보안 환경에서 신뢰된 어플리케이션을 실행하고 보안 데이터를 생성하는 동작(501),상기 제1 프로세서에 의해, 암호화 된 부분을 생성하기 위해 상기 생성된 보안 데이터 중 적어도 일부를 암호화 하고, 상기 암호화된 부분을 상기 보안 환경과 일반 비보안 환경(410)에서 공유되는 제1 메모리(332)에 저장하는 동작(503),상기 제1 프로세서에 의해, 상기 보안 데이터 중 적어도 일부를 암호화 하기 위하여 사용되는 제1 정보 및 상기 보안 데이터 중 적어도 일부를 암호화 하는 과정에서 생성되는 제2 정보를, 상기 보안 환경에 할당된 제2 메모리(334)에 저장하는 동작(503), 및상기 일반 비보안 환경에서 동작하는 제2 프로세서(321)에 의해, 상기 제1 메모리에 저장된, 상기 암호화 된 부분을 상기 일반 비보안 환경에 할당된 제3 메모리(331)에 저장하는 동작(505)을 포함하는 방법.
- 제11항에 있어서,상기 제1 프로세서에 의해 상기 암호화 하는 동작(503)은,상기 적어도 일부의 보안 데이터를 블록 단위로 암호화 하되, 상기 블록 별로 서로 다른 ARC(anti-replay counter) 값들을 사용하여 암호화 하는 동작(601),상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 생성되는 태그값들이 저장된 태그 테이블을 암호화 하는 동작(603), 및상기 블록 별로 상기 ARC 값들이 저장된 ARC 테이블을 암호화 하는 동작(605)을 포함하고,상기 제2 프로세서에 의해 상기 제3 메모리에 저장하는 동작(505)은,상기 암호화 된 부분, 상기 암호화 된 ARC 테이블, 및 상기 암호화 된 태그 테이블을 파일 형태(610)로 상기 제1 메모리에 저장(607)하는 동작을 포함하고,상기 제1 정보는 마스터 ARC(641)이고, 상기 제2 정보는 마스터 태그(642)임을 특징으로 하는 방법.
- 제11항 또는 제12항에 있어서,상기 보안 환경에서 상기 신뢰된 어플리케이션이 실행됨에 따라(701), 상기 제2 프로세서에 의해, 상기 제1 메모리에 저장된 상기 암호화 된 부분을 복사하고, 상기 복사된 부분을 상기 제1 메모리에 저장하는 동작(703),상기 제1 프로세서에 의해, 상기 제1 정보 및 상기 제2 정보를 이용하여, 상기 제1 메모리에 저장된 상기 암호화 된 부분을 복호화 하는 동작(705)을 더 포함하고,상기 제1 메모리에 저장된 암호화 된 부분은,상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 사용된 ARC(anti-replay counter)값들이 저장된 암호화 된 ARC 테이블(621), 상기 적어도 일부의 보안 데이터를 상기 블록 단위로 암호화 하는 과정에서 생성된 태그 값들이 저장된 암호화 된 태그 테이블(623)을 포함하며,상기 제1 프로세서에 의해 상기 복호화 하는 동작(705)은,상기 제1 정보 및 상기 제2 정보를 이용하여 상기 암호화 된 ARC 테이블을 복호화 하는 동작(803),상기 태그 테이블을 복호화 하는 동작(805), 및상기 복호화 된 ARC 테이블 및 상기 복호화 된 태그 테이블을 이용하여 상기 암호화 된 부분을 복호화 하는 동작(805)을 포함하는 방법.
- 제13항에 있어서,상기 제2 프로세서에 의해,상기 제3 메모리로부터 상기 암호화 된 보안 데이터, 상기 암호화 된 ARC 테이블, 및 상기 암호화 된 태그 테이블을 포함하는 파일(610)을 독출하고(801), 상기 암호화 된 부분(621), 상기 암호화 된 ARC 테이블(622), 및 상기 암호화 된 태그 테이블(623)을 각각 상기 제1 메모리에 저장하는 동작을 더 포함하는 방법.
- 제12항 내지 제14항 중 어느 한 항에 있어서,상기 암호화 하는 동작(601,605)은,상기 보안 데이터 중 적어도 일부와, 상기 ARC 테이블을 암호화 할 때, AES(advanced encryption standard)-GCM(galois/counter mode) 방식으로 암호화 하고,상기 복호화 하는 동작(705)은,상기 암호화 된 부분을 AES(advanced encryption standard)-GCM(galois/counter mode) 방식으로 복호화 하고,상기 태그 테이블을 암호화 하는 동작(603)은,AES(advanced encryption standard)- ECB(electronic code block) 방식으로 암호화 하는 방법.
Priority Applications (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP23894985.3A EP4575871A4 (en) | 2022-11-25 | 2023-11-21 | Electronic device for storing secure data and its operating method |
| CN202380078175.1A CN120202471A (zh) | 2022-11-25 | 2023-11-21 | 用于存储安全数据的电子装置及其操作方法 |
| US18/520,023 US12627469B2 (en) | 2022-11-25 | 2023-11-27 | Electronic device for storing secure data and method for operating the same |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| KR10-2022-0160173 | 2022-11-25 | ||
| KR1020220160173A KR20240077842A (ko) | 2022-11-25 | 2022-11-25 | 보안 데이터를 저장하는 전자 장치 및 그 동작 방법 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US18/520,023 Continuation US12627469B2 (en) | 2022-11-25 | 2023-11-27 | Electronic device for storing secure data and method for operating the same |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024112057A1 true WO2024112057A1 (ko) | 2024-05-30 |
Family
ID=91196214
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/KR2023/018740 Ceased WO2024112057A1 (ko) | 2022-11-25 | 2023-11-21 | 보안 데이터를 저장하는 전자 장치 및 그 동작 방법 |
Country Status (2)
| Country | Link |
|---|---|
| KR (1) | KR20240077842A (ko) |
| WO (1) | WO2024112057A1 (ko) |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080320263A1 (en) * | 2007-06-20 | 2008-12-25 | Daniel Nemiroff | Method, system, and apparatus for encrypting, integrity, and anti-replay protecting data in non-volatile memory in a fault tolerant manner |
| KR20170124360A (ko) * | 2016-05-02 | 2017-11-10 | 삼성전자주식회사 | 가상 sim 운용 방법 및 그 장치 |
| US20200304295A1 (en) * | 2019-03-22 | 2020-09-24 | Jpmorgan Chase Bank, N.A. | Systems and methods for manipulation of private information on untrusted environments |
| CN113553204A (zh) * | 2021-09-16 | 2021-10-26 | 支付宝(杭州)信息技术有限公司 | 一种数据传输方法及装置 |
| KR20220062866A (ko) * | 2020-11-09 | 2022-05-17 | 한화테크윈 주식회사 | 네트워크 카메라 및 그의 보안 서비스 제공 방법 |
-
2022
- 2022-11-25 KR KR1020220160173A patent/KR20240077842A/ko active Pending
-
2023
- 2023-11-21 WO PCT/KR2023/018740 patent/WO2024112057A1/ko not_active Ceased
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20080320263A1 (en) * | 2007-06-20 | 2008-12-25 | Daniel Nemiroff | Method, system, and apparatus for encrypting, integrity, and anti-replay protecting data in non-volatile memory in a fault tolerant manner |
| KR20170124360A (ko) * | 2016-05-02 | 2017-11-10 | 삼성전자주식회사 | 가상 sim 운용 방법 및 그 장치 |
| US20200304295A1 (en) * | 2019-03-22 | 2020-09-24 | Jpmorgan Chase Bank, N.A. | Systems and methods for manipulation of private information on untrusted environments |
| KR20220062866A (ko) * | 2020-11-09 | 2022-05-17 | 한화테크윈 주식회사 | 네트워크 카메라 및 그의 보안 서비스 제공 방법 |
| CN113553204A (zh) * | 2021-09-16 | 2021-10-26 | 支付宝(杭州)信息技术有限公司 | 一种数据传输方法及装置 |
Also Published As
| Publication number | Publication date |
|---|---|
| KR20240077842A (ko) | 2024-06-03 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| WO2022030893A1 (ko) | 오디오 공유를 지원하는 전자 장치 | |
| WO2022010134A1 (ko) | 메시지의 암호화 방법 및 전자 장치 | |
| WO2022092869A1 (ko) | 전자 장치 및 이를 이용한 메모리 보호 방법 | |
| WO2021006574A1 (en) | Method and apparatus for managing application | |
| WO2022030891A1 (ko) | 백업 데이터 복원 방법 및 이를 위한 전자 장치 | |
| WO2024071582A1 (ko) | 블록체인 기반 데이터 전송 방법 및 장치 | |
| US12627469B2 (en) | Electronic device for storing secure data and method for operating the same | |
| WO2024075929A1 (ko) | 신뢰 실행 환경을 제공하기 위한 전자 장치 | |
| WO2024039235A1 (ko) | 전자 장치 및 전자 장치에서 사용자 인증을 수행하는 방법 | |
| WO2025089665A1 (ko) | 전자 장치 및 개인화 컨텐츠 생성 방법 | |
| WO2020149555A1 (ko) | 암호화될 데이터의 정보량에 기반하여 암호화에 사용될 키를 선택하는 전자 장치 및 전자 장치의 동작 방법 | |
| WO2024096639A1 (ko) | 전자 장치 및 전자 장치에서 데이터를 검증하는 방법 | |
| WO2023038222A1 (ko) | 사용자의 생체 정보를 보호하기 위한 전자 장치 | |
| WO2022154273A1 (ko) | 데이터 백업을 지원하는 전자 장치 및 그 운용 방법 | |
| KR20240077842A (ko) | 보안 데이터를 저장하는 전자 장치 및 그 동작 방법 | |
| WO2023058860A1 (ko) | 멀티 서명된 apk 파일을 처리하는 전자 장치 및 그 동작 방법 | |
| WO2022124646A1 (ko) | 프라이버시 서비스를 제공하기 위한 전자 장치 | |
| WO2021256720A1 (ko) | 외부 장치로 요청을 전송하는 방법 및 이를 지원하는 전자 장치 | |
| WO2024071861A1 (ko) | 업데이트 방법 및 이를 위한 전자 장치 | |
| WO2023013886A1 (ko) | 분리 권한을 이용하는 전자 장치 및 그 동작 방법 | |
| WO2024072117A1 (ko) | 전자 장치 및 어플리케이션 간의 통신 방법 | |
| WO2024205383A1 (ko) | 가상 머신을 이용하여 인증을 수행하는 전자 장치 및 이의 동작 방법 | |
| KR20240026069A (ko) | 전자 장치 및 전자 장치에서 사용자 인증을 수행하는 방법 | |
| WO2024039233A1 (ko) | 전자 장치 및 전자 장치에서 프라이버시 강화 모드를 실행하는 방법 | |
| WO2025154939A1 (ko) | 데이터 전송을 위한 방법 및 이를 수행하는 전자 장치 |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 23894985 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2023894985 Country of ref document: EP |
|
| ENP | Entry into the national phase |
Ref document number: 2023894985 Country of ref document: EP Effective date: 20250318 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 202380078175.1 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 202380078175.1 Country of ref document: CN |
|
| WWP | Wipo information: published in national office |
Ref document number: 2023894985 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |