Electronic device for controlling access to device resources and method of operating the same

By configuring multiple operation permission areas and permission determination modules in the processor of the electronic device, the problem of using device resources in malicious situations is solved, and the security and credibility of device resources are achieved.

CN114287002BActive Publication Date: 2025-06-17SAMSUNG ELECTRONICS CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080059991.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-08-29
Filing Date
2020-08-26
Publication Date
2025-06-17
Estimated Expiration
2040-08-26

AI Technical Summary

Technical Problem

Device resources of electronic devices may be used in malicious situations, such as when the device is lost or stolen, the database is easily accessed or forged, resulting in the security of device resources being compromised.

Method used

By configuring multiple operation permission areas in the processor, the operating system and application are allowed to run at different permission levels, and the permission determination module is used to configure the application's permission to access device resources to prevent malicious use and database forgery.

Benefits of technology

It effectively prevents malicious use of device resources and database forgery, and ensures the security and credibility of device resources.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114287002B_ABST
    Figure CN114287002B_ABST
Patent Text Reader

Abstract

The present disclosure relates to an electronic device for controlling access to device resources and an operation method thereof. The electronic device may include a memory; and a processor configured to execute at least one operating system executed in a first area that permits operations based on a first privilege; execute at least one application executed in a second area that permits operations based on a second privilege; and determine an access privilege to at least one device resource by using a privilege determination module executed in a third area that permits operations based on a third privilege in response to detecting access by at least one application to at least one device resource.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various embodiments of the present disclosure relate to an electronic device for controlling access to device resources and an operating method thereof. Background Art

[0002] An electronic device includes various types of device resources. For example, the device resources may include at least one camera module, at least one sensor module, at least one speaker module, at least one microphone module, and / or at least one display module. By using at least one device resource, the above-described electronic device may be implemented in a type of comprehensive multimedia device (player) that provides various functions such as taking photos or videos, reproducing music or video files, executing games, receiving broadcasts, and supporting wireless Internet. Summary of the Invention

[0003] Technical Problem

[0004] Generally, an electronic device may manage access rights to device resources on a framework through a database. However, the database is easily accessed or forged (tampered with) by malicious use of the electronic device (e.g., rooting, framework change, etc.). Accordingly, there is a problem that device resources of the electronic device may be used in a malicious situation such as when the electronic device is lost or stolen.

[0005] Technical Solution

[0006] Accordingly, various aspects provide a method and a device for preventing forgery (or tampering) of a database related to device resources of an electronic device (e.g., an input / output database of device resources) and preventing malicious use of the device resources of the electronic device. According to one aspect, an electronic device includes a memory; and a processor, wherein the processor is configured to execute at least one operating system executed in a first region that permits an operation based on a first privilege; execute at least one application executed in a second region that permits an operation based on a second privilege; and configure a privilege for the at least one application to access the at least one device resource by using a privilege determination module executed in a third region that permits an operation based on a third privilege in response to detecting access of the at least one application to the at least one device resource.

[0007] According to one aspect, a method of operating an electronic device includes: executing at least one operating system executed in a first region that permits operations based on a first privilege; executing at least one application executed in a second region that permits operations based on a second privilege; and in response to detecting access by the at least one application to at least one device resource, configuring a privilege for the at least one application to access the at least one device resource by using a privilege determination module executed in a third region that permits operations based on a third privilege.

[0008] Advantageous Effects

[0009] According to various embodiments, in a region where a hypervisor (EL2), a secure EL2, and a virtual machine manager (VMM) are executed, it is possible to determine a privilege for an application to access at least one device resource, to prevent forgery (or tampering) of a privilege related to a configuration of a device resource of an electronic device, and to prevent malicious use of a device resource of the electronic device. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] From the following description with reference to the accompanying drawings, the above and other aspects, features, and advantages of certain embodiments of the present disclosure will become more apparent, in which:

[0011] Figure 1 is a block diagram of an electronic device in a network environment according to an embodiment;

[0012] Figure 2 is a block diagram showing an example of a program according to an embodiment;

[0013] Figure 3 is a diagram showing an architecture of a processor according to an embodiment;

[0014] Figure 4A is a flowchart for determining an access privilege to a device resource in an electronic device according to an embodiment;

[0015] Figure 4B is a flowchart for determining an access privilege to a device resource in an electronic device according to an embodiment;

[0016] Figure 5 is a flowchart for configuring a privilege policy in an electronic device according to an embodiment;

[0017] Figure 6 is a diagram showing additional policy privileges according to an embodiment;

[0018] Figure 7 is a flowchart for configuring a resource privilege in an electronic device according to an embodiment;

[0019] Figure 8A FIG. Figure 8A is a diagram showing a process of providing a privilege policy to an area allowing an operation based on a third privilege according to an embodiment; Figure 8B FIG. Figure 8B is a diagram showing a process of providing a privilege policy to an area allowing an operation based on a third privilege according to an embodiment; and Figure 8C FIG. Figure 8C is a diagram showing a process of providing a privilege policy to an area allowing an operation based on a third privilege according to an embodiment;

[0020] Figure 9 FIG. Figure 9 is a flowchart for processing access to device resources in an electronic device according to an embodiment;

[0021] Figure 10 FIG. Figure 10 is a flowchart for processing access to device resources in an electronic device according to an embodiment;

[0022] Figure 11A FIG. Figure 11A is a diagram showing operations of accessing device resources in a general electronic device; and

[0023] Figure 11B FIG. Figure 11B is a diagram showing operations of accessing device resources in an electronic device according to an embodiment. DETAILED DESCRIPTION

[0024] Hereinafter, various embodiments will be described in detail with reference to the accompanying drawings. In addition, when describing the embodiments, detailed descriptions of known related functions or configurations incorporated herein will be omitted when they may obscure the subject matter of the present disclosure. Terms defined below are considered in view of the functions of the present disclosure, and the meanings of these terms may vary according to the intention, convention, etc. of a user or an operator. Therefore, the definitions of the terms should be based on the entire contents of the specification.

[0025] Figure 1 FIG. Figure 1 is a block diagram of an electronic device 101 in a network environment 100 according to an embodiment. Refer to Figure 1, the electronic device 101 in the network environment 100 can communicate with the electronic device 102 via the first network 198 (e.g., a short-range wireless communication network), or communicate with the electronic device 104 or the server 108 via the second network 199 (e.g., a long-range wireless communication network). According to an embodiment, the electronic device 101 can communicate with the electronic device 104 via the server 108. According to an embodiment, the electronic device 101 may include a processor 120, a memory 130, an input device 150, a sound output device 155, a display device 160, an audio module 170, a sensor module 176, an interface 177, a haptic module 179, a camera module 180, a power management module 188, a battery 189, a communication module 190, a subscriber identity module (SIM) 196, or an antenna module 197. In some embodiments, at least one of the components (e.g., the display device 160 or the camera module 180) may be omitted from the electronic device 101, or one or more other components may be added to the electronic device 101. In some embodiments, some of the components may be implemented as a single integrated circuit. For example, the sensor module 176 (e.g., a fingerprint sensor, an iris sensor, or a luminance sensor) may be implemented as being embedded in the display device 160 (e.g., a display).

[0026] The processor 120 may run software (e.g., the program 140) to control at least one other component (e.g., a hardware component or a software component) connected to the processor 120 of the electronic device 101, and may perform various data processing or calculations. According to an embodiment, as at least part of the data processing or calculation, the processor 120 may load a command or data received from another component (e.g., the sensor module 176 or the communication module 190) into the volatile memory 132, process the command or data stored in the volatile memory 132, and store the resulting data in the non-volatile memory 134. According to an embodiment, the processor 120 may include a main processor 121 (e.g., a central processing unit (CPU) or an application processor (AP)) and an auxiliary processor 123 (e.g., a graphics processing unit (GPU), an image signal processor (ISP), a sensor hub processor, or a communication processor (CP)) that is operationally independent of or combined with the main processor 121. Additionally or alternatively, the auxiliary processor 123 may be adapted to consume less power than the main processor 121, or may be adapted for a specific function. The auxiliary processor 123 may be implemented as being separate from the main processor 121, or as a part of the main processor 121.

[0027] When the main processor 121 is in an inactive (e.g., sleep) state, the auxiliary processor 123 (instead of the main processor 121) may control at least some of the functions or states related to at least one of the components of the electronic device 101 (e.g., the display device 160, the sensor module 176, or the communication module 190). Or when the main processor 121 is in an active state (e.g., running an application), the auxiliary processor 123 may control at least some of the functions or states related to at least one of the components of the electronic device 101 (e.g., the display device 160, the sensor module 176, or the communication module 190) together with the main processor 121. According to an embodiment, the auxiliary processor 123 (e.g., an image signal processor or a communication processor) may be implemented as part of another component (e.g., the camera module 180 or the communication module 190) that is functionally related to the auxiliary processor 123.

[0028] The memory 130 may store various data used by at least one component of the electronic device 101 (e.g., the processor 120 or the sensor module 176). The various data may include, for example, software (e.g., the program 140) and input data or output data for commands related thereto. The memory 130 may include a volatile memory 132 or a non-volatile memory 134.

[0029] The program 140 may be stored in the memory 130 as software, and the program 140 may include, for example, an operating system (OS) 142, middleware 144, or an application 146.

[0030] The input device 150 may receive commands or data to be used by other components of the electronic device 101 (e.g., the processor 120) from the outside of the electronic device 101 (e.g., a user). The input device 150 may include, for example, a microphone, a mouse, a keyboard, or a digital pen (e.g., a stylus).

[0031] The sound output device 155 may output a sound signal to the outside of the electronic device 101. The sound output device 155 may include, for example, a speaker or a receiver. The speaker may be used for general purposes such as playing multimedia or playing a record, and the receiver may be used for incoming calls. According to an embodiment, the receiver may be implemented separately from the speaker or as part of the speaker.

[0032] The display device 160 may visually provide information to the outside of the electronic device 101 (e.g., a user). The display device 160 may include, for example, a display, a holographic device, or a projector, and a control circuit for controlling the corresponding one of the display, the holographic device, and the projector. According to an embodiment, the display device 160 may include a touch circuit adapted to detect a touch or a sensor circuit (e.g., a pressure sensor) adapted to measure the intensity of the force caused by the touch.

[0033] The audio module 170 can convert sound into an electrical signal and vice versa. According to an embodiment, the audio module 170 can obtain sound via the input device 150, or output sound via the sound output device 155 or headphones of an external electronic device (e.g., electronic device 102) directly (e.g., wired) or wirelessly connected to the electronic device 101.

[0034] The sensor module 176 can detect the operating state of the electronic device 101 (e.g., power or temperature) or the environmental state outside the electronic device 101 (e.g., the state of the user), and then generate an electrical signal or data value corresponding to the detected state. According to an embodiment, the sensor module 176 can include, for example, a gesture sensor, a gyro sensor, an atmospheric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an infrared (IR) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or a brightness sensor.

[0035] The interface 177 can support one or more specific protocols for directly (e.g., wired) or wirelessly connecting the electronic device 101 to an external electronic device (e.g., electronic device 102). According to an embodiment, the interface 177 can include, for example, a high-definition multimedia interface (HDMI), a universal serial bus (USB) interface, a secure digital (SD) card interface, or an audio interface.

[0036] The connection terminal 178 can include a connector through which the electronic device 101 can be physically connected to an external electronic device (e.g., electronic device 102). According to an embodiment, the connection terminal 178 can include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0037] The haptic module 179 can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that can be recognized by the user through his sense of touch or kinesthesia. According to an embodiment, the haptic module 179 can include, for example, a motor, a piezoelectric element, or an electrical stimulator.

[0038] The camera module 180 can capture still images or moving images. According to an embodiment, the camera module 180 can include one or more lenses, an image sensor, an image signal processor, or a flash.

[0039] The power management module 188 can manage the power supply to the electronic device 101. According to an embodiment, the power management module 188 can be implemented as at least part of, for example, a power management integrated circuit (PMIC).

[0040] The battery 189 may supply power to at least one component of the electronic device 101. According to an embodiment, the battery 189 may include, for example, a primary non-rechargeable battery, a rechargeable storage battery, or a fuel cell.

[0041] The communication module 190 may support establishing a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device 101 and an external electronic device (e.g., the electronic device 102, the electronic device 104, or the server 108), and perform communication via the established communication channel. The communication module 190 may include one or more communication processors capable of operating independently of the processor 120 (e.g., an application processor (AP)), and support direct (e.g., wired) communication or wireless communication. According to an embodiment, the communication module 190 may include a wireless communication module 192 (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194 (e.g., a local area network (LAN) communication module or a power line communication (PLC) module). A corresponding one of these communication modules may communicate with an external electronic device via a first network 198 (e.g., a short-range communication network, such as Bluetooth TM , Wi-Fi Direct, or Infrared Data Association (IrDA)) or a second network 199 (e.g., a long-range communication network, such as a cellular network, the Internet, or a computer network (e.g., LAN or wide area network (WAN))). These various types of communication modules may be implemented as a single component (e.g., a single chip), or these various types of communication modules may be implemented as multiple separate components (e.g., multiple chips). The wireless communication module 192 may identify and authenticate the electronic device 101 in a communication network (such as the first network 198 or the second network 199) using user information (e.g., an international mobile subscriber identity (IMSI)) stored in the user identification module 196.

[0042] The antenna module 197 may transmit signals or power to the outside of the electronic device 101 (e.g., an external electronic device) or receive signals or power from the outside of the electronic device 101 (e.g., an external electronic device). According to an embodiment, the antenna module 197 may include an antenna including a radiation element formed of a conductive material or a conductive pattern formed in a substrate (e.g., a PCB) or formed on the substrate. According to an embodiment, the antenna module 197 may include a plurality of antennas. In this case, at least one antenna suitable for a communication scheme to be used in a communication network (such as the first network 198 or the second network 199) may be selected from the plurality of antennas by, for example, the communication module 190 (e.g., the wireless communication module 192). Subsequently, signals or power may be transmitted or received between the communication module 190 and an external electronic device via the at least one selected antenna. According to an embodiment, additional components (e.g., a radio frequency integrated circuit (RFIC)) other than the radiation element may be additionally formed as part of the antenna module 197.

[0043] At least some of the above components may be interconnected via an inter-peripheral communication scheme (e.g., a bus, a general-purpose input / output (GPIO), a serial peripheral interface (SPI), or a mobile industry processor interface (MIPI)) and communicatively transmit signals (e.g., commands or data) therebetween.

[0044] According to an embodiment, commands or data may be transmitted or received between the electronic device 101 and an external electronic device 104 via a server 108 connected to a second network 199. Each of the electronic devices 102 and 104 may be a device of the same type as the electronic device 101 or a device of a different type from the electronic device 101. According to an embodiment, all or some of the operations running on the electronic device 101 may be run on one or more of the external electronic device 102, the external electronic device 104, or the server 108. For example, if the electronic device 101 is to automatically perform a function or service or is to perform a function or service in response to a request from a user or another device, the electronic device 101 may request one or more of the external electronic devices to perform at least part of the function or service instead of running the function or service, or in addition to running the function or service, the electronic device 101 may also request one or more of the external electronic devices to perform at least part of the function or service. The one or more external electronic devices that receive the request may perform the requested at least part of the function or service, or perform additional functions or additional services related to the request, and transmit the result of the performance to the electronic device 101. The electronic device 101 may provide the result as at least part of a reply to the request with or without further processing of the result. For this purpose, for example, cloud computing technology, distributed computing technology, or client-server computing technology may be used.

[0045] Figure 2 FIG. 200 is a block diagram showing an example of a program 140 according to various embodiments. According to an embodiment, the program 140 may include an operating system (OS) 142 for controlling at least one resource of the electronic device 101, middleware 144, or an application 146 executable in the operating system 142. The operating system 142 may include, for example, Android TM , iOS TM , Windows TM , Symbian TM , Tizen TM , or Bada TM . At least a part of the program 140 may be pre-loaded onto the electronic device 101, for example, at the time of manufacture, or downloaded or updated from an external electronic device (e.g., the electronic device 102 or 104, or the server 108) when the user uses it.

[0046] The operating system 142 may control the management (e.g., allocation or deallocation) of at least one system resource (e.g., a process, memory, or power) of the electronic device 101. Additionally or alternatively, the operating system 142 may include at least one driver for operating other hardware devices (e.g., device resources) of the electronic device 101, such as an input device 150, a sound output device 155, a display device 160, an audio module 170, a sensor module 176, an interface 177, a haptic module 179, a camera module 180, a power management module 188, a battery 189, a communication module 190, a SIM 196, or an antenna module 197.

[0047] The middleware 144 may provide various functions to the application 146 so that the application 146 can use the functions or information provided from at least one resource of the electronic device 101. The middleware 144 includes, for example, an application manager 201, a window manager 203, a multimedia manager 205, a resource manager 207, a power manager 209, a database manager 211, a package manager 213, a connection manager 215, a notification manager 217, a location manager 219, a graphics manager 221, a security manager 223, a telephone manager 225, or a voice recognition manager 227.

[0048] The application manager 201 may manage, for example, the life cycle of the application 146. The window manager 203 may manage, for example, at least one GUI resource used in the screen. The multimedia manager 205 may, for example, identify one or more formats required to reproduce a media file and encode or decode the corresponding media file in the media file by using a codec that matches the corresponding format selected in the format. The resource manager 207 may manage, for example, the source code of the application 146 or the storage space of the memory 130. The power manager 209 may, for example, manage the capacity, temperature, or power of the battery 189 and determine or provide relevant information required for the operation of the electronic device 101 by using the corresponding information in the capacity, temperature, or power. According to an embodiment, the power manager 209 may be linked to the basic input / output system (BIOS) of the electronic device 101.

[0049] The database manager 211 can, for example, generate, search, or change a database to be used by the application 146. The package manager 213 can manage the installation or update of applications distributed, for example, in the form of package files. The connection manager 215 can manage a wireless connection or a direct connection, for example, between the electronic device 101 and an external electronic device. The notification manager 217 can provide a function for notifying a user of the occurrence of a specified event (e.g., an incoming call, a message, or an alert), for example. The location manager 219 can manage the location information of the electronic device 101, for example. The graphics manager 221 can manage at least one graphics effect to be provided to the user or a related user interface, for example.

[0050] The security manager 223 can provide system security or user authentication, for example. The phone manager 225 can manage the voice call function or the video call function provided by the electronic device 101, for example. The voice recognition manager 227 can, for example, send the user's voice data to the server 108 and receive, from the server 108, an instruction corresponding to a function to be executed in the electronic device 101, at least partially based on the voice data or character data converted from the voice data. According to an embodiment, the middleware 244 can dynamically remove a part of an existing component or add a new component. According to an embodiment, at least a part of the middleware 144 can be included as a part thereof in the operating system 142, or can be implemented as independent software different from the operating system 142.

[0051] The application 146 can include a home 251, a dialer 253, SMS / MMS 255, instant messaging (IM) 257, a browser 259, a camera 261, an alarm 263, contacts 265, voice recognition 267, email 269, a calendar 271, a media player 273, an album 275, a clock 277, health 279 (e.g., measuring biometric information such as exercise amount or blood sugar), or environmental information 281 (e.g., measuring atmospheric pressure, humidity, or temperature information). According to an embodiment, the application 146 can further include an information exchange application for supporting information exchange between the electronic device 101 and an external electronic device. The information exchange application can include, for example, a notification relay application configured to transmit specified information (e.g., a call, a message, or an alert) to an external electronic device, or a device management application configured to manage an external electronic device. The notification relay application can, for example, transmit notification information corresponding to a specified event (e.g., mail reception) that has occurred in another application (e.g., the email application 269) of the electronic device 101 to an external electronic device. Additionally or alternatively, the notification relay application can receive notification information from an external electronic device and provide the notification information to a user of the electronic device 101.

[0052] The device management application can control the power (e.g., turn on or off) or functions (e.g., brightness, resolution, or focus of the display device 160 or the camera module 180) of an external electronic device that communicates with, for example, a part of the components of the electronic device 101 or an external electronic device (e.g., the display device 160 or the camera module 180). Additionally or alternatively, the device management application can support the installation, removal, or update of applications running on the external electronic device.

[0053] According to various embodiments, the program 140 as described above can include additional elements 220 for managing access to device resources, as shown in the figure. The additional elements 220 can include a management program 291, a management (hyper, HYP) module 293, an operating system (OS) module 295, and a privilege management manager 297.

[0054] According to an embodiment, the privilege management manager 297 can access the input / output of at least one device resource in response to requests from at least one application 146 and the operating system 142. According to an embodiment, the operating system module 295 can support the exchange of information between the privilege management manager 297 and the HYP module 293. For example, if the operating system module 295 detects a change in the access restriction privilege configuration of a device resource, which is made by the privilege management manager 297, the operating system module can provide the access restriction privilege configuration information related to the device resource to the HYP module 293. In addition, the operating system module 295 can obtain the result of the access privilege restriction configuration executed by the HYP module 293 and provide the obtained restriction configuration result to the privilege management manager 297.

[0055] According to an embodiment, the management program 291 can be in an area where the operating system 142 and at least one application 146 cannot access. For example, the management program 291 or the HYP module 293 operating in the area of the management program 291 can manage at least one virtual machine. Alternatively or additionally, according to various embodiments, the management program 291 or the HYP module 293 can manage the access privileges to device resources. For example, the management program 291 or the HYP module 293 can determine whether a device resource to be accessed by the operating system 142 or at least one application 146 is a restricted resource and can provide the determination result to the operating system module 295.

[0056] The electronic device according to various embodiments can be one of various types of electronic devices. The electronic device can include, for example, a portable communication device (e.g., a smart phone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a household appliance. According to an embodiment of the present disclosure, the electronic device is not limited to the electronic devices described above.

[0057] It should be understood that the various embodiments of the present disclosure and the terms used therein are not intended to limit the technical features set forth herein to specific embodiments, but include various changes, equivalent forms or alternative forms for the corresponding embodiments. For the description of the drawings, like reference numerals may be used to refer to like or related elements. It will be understood that a singular noun corresponding to a term may include one or more things, unless the relevant context clearly indicates otherwise. As used herein, each of the phrases such as "A or B", "at least one of A and B", "at least one of A or B", "A, B or C", "at least one of A, B and C", and "at least one of A, B or C" may include any one or all possible combinations of the items listed together in the corresponding one of the plurality of phrases. As used herein, terms such as "first" and "second" or "1st" and "2nd" may be used to simply distinguish the corresponding components from another component, and do not limit the components in other respects (e.g., importance or order). It will be understood that, in the case where the term "operably" or "communicatively" is used or where the term "operably" or "communicatively" is not used, if an element (e.g., a first element) is referred to as "coupled with another element (e.g., a second element)", "coupled to another element (e.g., a second element)", "connected with another element (e.g., a second element)", or "connected to another element (e.g., a second element)", it means that the one element can be directly (e.g., wired) connected to the other element, wirelessly connected to the other element, or connected to the other element via a third element.

[0058] As used herein, the term "module" may include a unit implemented in hardware, software or firmware and may be used interchangeably with other terms (e.g., "logic", "logic block", "portion" or "circuit"). A module may be a single integrated component adapted to perform one or more functions or the smallest unit or portion of the single integrated component. For example, according to an embodiment, a module may be implemented in the form of an application specific integrated circuit (ASIC).

[0059] The various embodiments described herein can be implemented as software (e.g., program 140) including one or more instructions readable by a machine (e.g., electronic device 101) stored in a storage medium (e.g., internal memory 136 or external memory 138). For example, under the control of a processor, a processor (e.g., processor 120) of the machine (e.g., electronic device 101) can invoke at least one of the one or more instructions stored in the storage medium and run the at least one instruction with or without using one or more other components. This enables the machine to operate to perform at least one function in accordance with the at least one instruction invoked. The one or more instructions can include code generated by a compiler or code that can be run by an interpreter. The machine-readable storage medium can be provided in the form of a non-transitory storage medium. Herein, the term "non-transitory storage medium" is a tangible device and does not include signals (e.g., electromagnetic waves), but this term does not distinguish between data being stored semi-permanently in the storage medium and data being stored temporarily in the storage medium. For example, a "non-transitory storage medium" can include a buffer that stores data temporarily.

[0060] According to an embodiment, a method according to various embodiments of the present disclosure can be included and provided in a computer program product. The computer program product can be traded between a seller and a purchaser as a product. The computer program product can be distributed (e.g., downloaded or uploaded) online via an application store (e.g., Play Store TM ) in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or can be directly distributed (e.g., downloaded or uploaded) between two user devices (e.g., smart phones). If it is distributed online, at least a part of the computer program product (e.g., a downloadable application) can be generated temporarily, or at least a part of the computer program product can be stored at least temporarily in a machine-readable storage medium (such as the memory of a manufacturer's server, an application store's server, or a forwarding server).

[0061] According to various embodiments, each of the above components (e.g., a module or a program) may include a single entity or multiple entities. According to various embodiments, one or more of the above components may be omitted, or one or more other components may be added. Optionally or additionally, multiple components (e.g., modules or programs) may be integrated into a single component. In this case, according to various embodiments, the integrated component may still perform the one or more functions of each of the multiple components in the same or similar manner as the corresponding one of the multiple components performed one or more functions before integration. According to various embodiments, the operations performed by a module, a program, or another component may be performed sequentially, in parallel, repeatedly, or in a heuristic manner, or one or more of the operations may be run in a different order or omitted, or one or more other operations may be added.

[0062] Figure 3 FIG. 300 is a diagram showing the architecture of a processor 120 according to various embodiments.

[0063] Referring Figure 3 , the processor 120 may operate at multiple exception levels. The exception levels may be related to the processing privilege levels processed by the processor 120. For example, the exception levels may include EL0, EL1, EL2, and EL3, and more privileges may be assigned to higher-numbered exception levels (e.g., EL3) compared to the lower-numbered exception level (EL0). As Figure 3 shown, at least one application 312 may be executed at EL0 310, and at least one operating system 322 may be executed at EL1 320. In addition, a hypervisor 332 may be executed at EL2 330. At least one application 312, at least one operating system 322, and the hypervisor 332 may operate in a first region 350 called a non-secure state. In addition, the processor 120 may support a second region 360 called a secure state, which is separated from the first region 350 to prevent access by processes executed in the first region 350. Accordingly, a secure application 314, a secure operating system (OS) 324, trusted firmware 334, and a security monitor 344 may be executed in the second region 360.

[0064] As described above, the processor 120 may provide the first region 350 and the second region 360. However, this is merely an example, and the embodiments are not limited thereto. For example, the processor 120 may provide only the first region 350 or the second region 360.

[0065] According to an embodiment, the above-mentioned hypervisor 332 may manage at least one virtual machine. Alternatively or additionally, the hypervisor 332 may manage access rights to device resources. For example, the hypervisor 332 may manage a permission policy for device resources at EL2 330 where the operating system 322 and at least one application 312 cannot access. The permission policy may be data that defines device resources restricted (or permitted) for access by the operating system 322 and at least one application 312. In addition, the hypervisor 332 is capable of configuring the processor 120 to determine whether at least one application 312 and / or the operating system 322 has the right to access at least one device resource. For example, the hypervisor 332 is capable of configuring the processor 120 to: if access to a device resource by at least one application 312 and / or the operating system 322 is detected, determine whether the device resource to be accessed by at least one application 312 and / or the operating system 322 is a restricted resource based on the configured permission policy. For example, if the device resource is determined to be a resource with restricted access, the hypervisor 332 may receive information notifying of the access restriction from the processor 120 and notify such information.

[0066] According to an embodiment, an electronic device may include a memory; and a processor, where the processor is configured to execute at least one operating system that executes in a first region allowing operations based on a first permission; execute at least one application that executes in a second region allowing operations based on a second permission; and in response to detecting access by the at least one application to at least one device resource, configure access rights to the at least one device resource by using a permission determination module that executes in a third region allowing operations based on a third permission. The permission determination module may include a hypervisor.

[0067] The third permission may include a permission higher than the first permission.

[0068] The third region allowing operations based on the third permission may include a region in which at least one of a hypervisor, a secure region, and a virtual machine manager (VMM) executes.

[0069] The processor may be configured to store a permission policy in the third region allowing operations based on the third permission, where the permission policy defines device resources restricted by the at least one application.

[0070] The processor may be configured to obtain the permission policy in the electronic device or from an external device.

[0071] The processor may be configured to provide the permission policy to a non-secure region allowing operations based on the third permission through a non-secure region of the processor.

[0072] The processor may be configured to provide the permission policy to a secure region allowing operations based on the third permission through a secure region of the processor.

[0073] The processor may be configured to provide a privilege policy to a non-secure area that allows operations based on a third privilege through a secure area of the processor.

[0074] The processor may be configured to determine access privileges for the at least one application based on the configured access privileges for the at least one device resource; and provide information indicating a restriction on access to the at least one device resource if the configured privilege is determined to be a privilege that restricts access to the at least one device resource.

[0075] The processor may be configured to obtain a specified first privilege policy during a boot-on operation and, after the boot operation is completed, obtain a second privilege policy. For example, the first privilege policy may be stored in the electronic device. In addition, the second privilege policy may be obtained from outside the electronic device.

[0076] Figure 4A FIG. 400 is a flowchart for determining access privileges to device resources in an electronic device 101 according to an embodiment. In the embodiments described below, the operations may be performed sequentially, but the present disclosure is not limited to sequential operations. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0077] Reference Figure 4A , in step 410, the electronic device 101 (or the processor 120) may execute at least one operating system. The processor 120 may process at least one operating system to be executed in an area that allows operations based on a first privilege. For example, the area that allows operations based on a first privilege may correspond to an exception level (e.g., EL1 320), and more privileges are assigned to this exception level compared to a lower-numbered exception level (EL0 310).

[0078] In step 420, the processor 120 may execute at least one application. The processor 120 may process the execution of at least one application executed in an area that allows operations based on a second privilege. For example, the area that allows operations based on a second privilege may correspond to an exception level (EL0), and fewer privileges are assigned to this exception level compared to the area that allows operations based on a first privilege.

[0079] In step 430, the processor 120 may determine the access rights of at least one application to the device resources. In a state where access to the device resources by at least one application is restricted, in terms of hardware, access to the device resources is restricted, and the processor 120 may be requested to determine the access rights to the device resources by using a rights determination module executed in an area that permits operations based on a third right. For example, the area that permits operations based on a third right may be an area in which a hypervisor, a virtual machine, and secure EL2 are executed. For example, the area that permits operations based on a third right may correspond to an exception level (EL2 330), and more rights are assigned to this exception level compared to the area that permits operations based on a first right. In addition, the rights determination module may include a hypervisor.

[0080] Figure 4B FIG. 440 is a flowchart for determining access rights to device resources in an electronic device according to an embodiment. In the embodiments described below, the operations may be performed sequentially, but the present disclosure is not limited to sequential operations. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.

[0081] Refer to Figure 4B , in step 450, the electronic device 101 (or the processor 120) may receive a request for determining access rights to the device resources from a rights determination module executed in an area that permits operations based on a third right (e.g., EL2 330). For example, as described above, the area that permits operations based on a third right may correspond to an exception level, and more rights are assigned to this exception level compared to the area that permits operations based on a first right (e.g., EL1 320). In addition, the rights determination module may include a hypervisor 332. The rights determination module may be configured to configure access rights to the device resources. For example, the rights determination module may provide the configured access rights to the processor 120 to request determination of access rights to the device resources.

[0082] In step 460, the processor 120 may execute at least one operating system. The processor 120 may process at least one operating system to be executed in an area that permits operations based on a first right. For example, the area that permits operations based on a first right may correspond to an exception level, and more rights are assigned to this exception level compared to the area that permits operations based on a second right (e.g., EL0 310).

[0083] In step 470, the processor 120 may execute at least one application. The processor 120 may process the execution of at least one application executed in an area that permits operations based on a second right. For example, the area that permits operations based on a second right may correspond to an exception level, and fewer rights are assigned to this exception level compared to the area that permits operations based on a first right.

[0084] In step 480, the processor 120 may determine the permissions for at least one executed application to access device resources. The processor 120 may determine the access permissions for at least one application accessing specific hardware based on the access permissions received from the permission determination module.

[0085] In step 490, the processor 120 may perform processing such that access to device resources by at least one application is restricted. In response to detecting that access restrictions for at least one application to access device resources are configured, the processor 120 may perform processing such that access to the device resources is restricted. In addition, the processor 120 may notify the permission management module that the access restriction is configured. For example, in a state where access to device resources by at least one application is restricted, in terms of hardware, access to the device resources is restricted, and the permission management module operating in an area where operations based on a third permission are allowed may be notified of information indicating the restriction of access to the device resources.

[0086] Figure 5 is a flowchart 500 for configuring a permission policy in the electronic device 101 according to an embodiment. In addition, Figure 6 is a diagram 600 showing additional policy permissions according to an embodiment. The steps described below Figure 5 may correspond to various embodiments of step 410 in Figure 4A In addition, in the following embodiments, the operations may be performed sequentially, but the present disclosure is not limited to sequential operations. For example, the order of operations may be changed, and at least two operations may be performed in parallel.

[0087] Referring to Figure 5 , according to various embodiments, in step 510, the electronic device 101 (or the processor 120) may perform a boot operation. The processor 120 may perform the boot operation in response to receiving an input indicating the boot operation. For example, the input indicating the boot operation may include a power key input. As another example, the input indicating the boot operation may be related to the power supply of the electronic device 101.

[0088] In step 520, the processor 120 may obtain a specified permission policy. As described above, the permission policy may be data defining the device resources restricted (or allowed) for the operating system 322 and / or at least one application 312 to access. For example, the permission policy may be encrypted and stored in a pre-specified storage space (e.g., a storage space with a predetermined level of security). For example, the permission policy may be obtained by an architecture module operating in an area where operations based on a first permission are allowed, as described below with reference to Figure 7 and FIG. 8.

[0089] In step 530, the processor 120 may configure resource permissions based on the obtained permission policy. The processor 120 may configure resource permissions by storing the obtained permission policy in an area that allows operations based on a third permission (e.g., EL2), as described below with reference to Figure 7 and FIG. 8. In addition, the processor 120 may perform resource permission operations before the boot operation is completed.

[0090] In step 540, the processor 120 may determine whether an additional permission policy is obtained. The additional permission policy may be obtained in a state where the boot operation has been completed. For example, the additional permission policy may be received through an external electronic device (e.g., electronic device 102, electronic device 104, or server 108). The processor 120 may obtain an additional permission policy that defines restrictions or allows at least one device resource based on a user's input. As Figure 6 shown, the user may select a target (e.g., a control target) for controlling access to a device resource through an external electronic device (as shown by reference numeral 610). The user may select at least one device resource from the device resources of the selected control target and restrict or allow access to the device resource (as shown by reference numeral 620). For example, the user may control access to all sensors in the device resources. In addition, the user may control access to a part of the sensors in the device resources. For example, the additional permission policy may be defined by a user who has lost the electronic device 101. As another example, the additional permission policy may be defined by an external company (e.g., a financial institution) for asserting (or securing) the ownership of the electronic device 101.

[0091] If the additional permission policy is not obtained, the processor 120 may execute at least one operating system. For example, the processor 120 may perform operations related to Figure 4A step 401 in

[0092] If the additional permission policy is obtained, then in step 550, the processor 120 may update the resource permissions based on the additional permission policy. The processor 120 may update the resource permissions by updating the policy permissions stored in the area that allows operations based on a third permission based on the obtained additional policy permissions. In addition, after updating the resource permissions, the processor 120 may execute at least one operating system. For example, the processor 120 may perform operations related to Figure 4A step 401 in

[0093] Figure 7 is a flowchart 700 for configuring resource permissions in the electronic device 101 according to an embodiment. In addition, Figure 8A is a diagram 800 showing a process of providing a permission policy to an area that allows operations based on a third permission according to an embodiment, Figure 8BFIG. 820 illustrates a process of providing a privilege policy to an area allowing an operation based on a third privilege according to an embodiment, and Figure 8C FIG. 840 illustrates a process of providing a privilege policy to an area allowing an operation based on a third privilege according to an embodiment. The steps described below Figure 7 may correspond to various embodiments of step 530 in Figure 5 . In addition, in the following embodiments, operations may be performed in sequence, but the present disclosure is not limited to sequential operations. For example, the order of operations may be changed, and at least two operations may be performed in parallel.

[0094] Referring to Figure 7 , in step 710, the electronic device 101 (or the processor 120) may provide a specified privilege policy to an area allowing an operation based on a third privilege. For example, the privilege policy may be obtained by an architecture module operating in an area allowing an operation based on a first privilege (e.g., EL0), and the processor 120 may provide the obtained privilege policy to an area allowing an operation based on a third privilege (e.g., EL2). For example, the privilege policy may be provided to an area allowing an operation based on a third privilege (e.g., EL2) through an area allowing an operation based on a second privilege (e.g., EL1).

[0095] The processor 120 may provide a privilege policy to a non-secure area allowing an operation based on a third privilege through a first area 810 called a non-secure state (or normal world), as Figure 8A shown. The non-secure area may include an architecture module 812, an operating system module 814, and a HYP module 816. For example, the processor 120 may provide a privilege policy obtained through the architecture module 812 to the HYP module 816 through the operating system module 814.

[0096] For example, the architecture module 812 may operate at the lowest privileged assigned low-numbered exception level (EL0), and may obtain (or receive) a permission policy from an external electronic device (e.g., electronic device 102, electronic device 104, or server 108). Additionally, the architecture module 812 may provide the permission policy obtained from the external electronic device to the operating system module. As described above, the operating system module 814 may support the exchange of information between the architecture module 812 and the HYP module 816, and provide the permission policy received from the architecture module 812 to the HYP module 816. The permission policy may be data that defines the device resources restricted (or permitted) for access by the operating system and at least one application. As described above, the HYP module 816 may manage the access permissions to the device resources. For example, the HYP module 816 (or hypervisor) may store the permission policy received from the operating system module 814. Additionally, the HYP module 816 may determine whether the device resources to be accessed by the operating system or at least one application are restricted resources, and may provide the determination result to the operating system module 814.

[0097] According to another embodiment, the processor 120 may provide a permission policy to a secure region that permits operations based on a third privilege through a second region 830, which is referred to as a secure state (or secure world) and is separated from the first region 810, as Figure 8B shown. The secure region may include a trusted application 832, a secure operating system module 834, and a secure EL2 836. For example, the processor 120 may store, through the secure operating system module 834, the permission policy obtained through the trusted application 832 in the secure EL2 836. For example, the trusted application 832, the secure operating system module 834, and the secure EL2 836 may be similar to the architecture module 812, the operating system module 814, and the hypervisor 816 executed in the first region 810, except that the trusted application, the secure operating system module, and the secure EL2 are executed in a second region 830 separated from the first region 810.

[0098] According to another embodiment, the processor 120 may provide a permission policy to a non-secure region that permits operations based on a third privilege through a different second region 850, which is referred to as a secure state (or secure world) and is separated from the first region 810, as Figure 8C shown. The secure region 850 may include a trusted application 852, a secure operating system module 854, and a monitor module 856. For example, the permission policy may be obtained by the trusted application 852, and the obtained permission policy may be stored in a non-secure region 858 in the first region that permits operations based on a third privilege, as Figure 8CAs shown. The permission policy obtained in the secure area 850 (e.g., obtained by the trusted application 852 and the secure operating system module 854) can be transmitted to the non-secure area 858 through the monitor module 856.

[0099] In step 720, the processor 120 can decode the permission policy through the area that allows operations based on the third permission. The processor 120 can decode the encrypted permission policy by using the hypervisor executed in the area that allows operations based on the third permission.

[0100] In step 730, the processor 120 can store the decoded permission policy in the area that allows operations based on the third permission. The processor 120 can store the decoded permission policy in the non-secure area that allows operations based on the third permission or the secure area that allows operations based on the third permission.

[0101] The processor 120 can store the decoded permission policy in the area that allows operations based on the third permission to complete the resource permission configuration operation. After storing the decoded permission policy, the processor 120 can determine whether an additional permission policy is obtained. For example, the processor 120 can perform operations related to Figure 5 step 540 in

[0102] Figure 9 is a flowchart 900 for processing access to device resources in the electronic device 101 according to an embodiment. The steps described below Figure 9 can correspond to various embodiments of step 430 in Figure 4A In addition, in the following embodiments, the operations can be performed sequentially, but the present disclosure is not limited to sequential operations. For example, the order of operations can be changed, and at least two operations can be performed in parallel.

[0103] Refer to Figure 9 , in step 910, the electronic device 101 (or the processor 120) can determine whether an access to the device resources is detected. The input / output of the device resources can be managed through a database. The processor 120 can determine whether the operating system or at least one application accesses the memory address area corresponding to at least one device resource. However, this determination is only an example, and the embodiments are not limited thereto. For example, the processor 120 can detect whether the operating system or at least one application accesses at least one device resource based on various known methods.

[0104] If no access to the device resources is detected, the processor 120 can repeatedly perform the operation of determining whether an access to the device resources is detected. For example, the processor 120 can perform operations related to step 910. Step 910 can occur repeatedly under normal circumstances where the program 140 uses the device resources.

[0105] If an access to a device resource is detected, then at step 920, the processor 120 may determine whether the device resource to be accessed that has been detected is a device resource with restricted access rights. For example, based on this determination, the processor 120 may determine whether an event for determining the access rights to the device resource has occurred. In terms of hardware, step 920 may be determined in the processor 120. The access rights determination event may be a specified event that allows the permission management module to perform subsequent processing operations when restricting access to the device resource. The processor 120 may determine that an access rights determination event has occurred in response to detecting an access to a device resource with restricted access rights. For example, in response to detecting a flash operation with the highest privilege in the operating system running in the electronic device 101, the processor 120 may determine that a device resource with restricted access rights has been accessed. As another example, in response to obtaining an additional permission policy that defines at least one device resource with restricted or permitted access from an external electronic device (e.g., the electronic device 102, the electronic device 104, or the server 108), the processor 120 may determine that a device resource with restricted access rights has been accessed. As another example, in response to detecting the installation of an unauthenticated custom binary, the processor 120 may determine that a device resource with restricted access rights has been accessed. As another example, in response to detecting entry into a pre-specified area (or region, zone) where access is not permitted, the processor 120 may determine that a device resource with restricted access rights has been accessed.

[0106] In the case where a device resource with restricted access rights is accessed, if the access rights to the corresponding device resource area are pre-configured in an area that allows operations based on the third privilege, then at step 920, in terms of hardware, the processor 120 may determine whether the resource is a resource with restricted access rights.

[0107] If it is detected that the device resource to be accessed is a device resource with restricted access rights, then at step 930, the processor 120 may request a module in a different area to perform subsequent processing on the access rights restriction of the device resource in the area that allows operations based on the third privilege. For example, the subsequent processing request may be a notification (permission failure) informing of the access to the restricted device resource. As described above, the area that allows operations based on the third privilege is the area where the hypervisor, virtual machine, and secure EL2 are executed, and may correspond to the exception level (EL2 330), and more privileges are assigned to this exception level compared to the exception level (EL0) of the area that allows operations based on the first privilege. In addition, the permission determination module may include the hypervisor.

[0108] If the device resource is a device resource with unrestricted access permissions, then at step 940, the processor 120 may allow access to the device resource. The processor 120 may perform processing such that the device resource accessed by the operating system or at least one application is executed.

[0109] Figure 10 is a flowchart 1000 for processing access to a device resource in an electronic device according to an embodiment. The steps described below Figure 10 may correspond to various embodiments of step 430 in Figure 4A or step 920 in Figure 9 In addition, in the following embodiments, operations may be performed sequentially, but the present disclosure is not limited to sequential operations. For example, the order of operations may be changed, and at least two operations may be performed in parallel.

[0110] Referring to Figure 10 , at step 1010, the processor 120 may identify whether access to a device resource restricted from execution is recognized. The processor 120 may determine whether the operating system or at least one application accesses the restricted device resource by using a permission determination module executed in an area that permits operations based on a third permission. For example, the permission determination module may identify the restricted device resource based on a pre-specified permission policy.

[0111] If access to the restricted device resource is recognized, then at step 1020, the processor 120 may determine that access to the device resource needs to be restricted.

[0112] If it is determined that access to the device resource needs to be restricted, then at step 1030, the processor 120 may provide a notification informing of the access restriction. The processor 120 may provide the notification informing of the access restriction to at least one of the architecture module or the operating system module. Accordingly, the processor may perform processing such that a message informing of the execution of the restricted device resource is output through the display device 160 of the electronic device 101. As another example, the processor 120 may process the execution of an application to be stopped according to the notification. However, this processing only corresponds to an example, and the embodiment is not limited thereto. For example, the notification may be provided in various forms, such as in an audio form, a vibration form, etc. After providing the notification informing of the access restriction, the processor 120 may store a record (e.g., a log) indicating that an abnormal (or malicious) operation has occurred in the electronic device 101 (such as in the memory 130) or outside the electronic device 101 (e.g., an external electronic device (e.g., the electronic device 102, the electronic device 104, or the server 108)).

[0113] If access to the restricted device resource is not recognized, then at step 1040, the processor 120 may determine to allow access to the device resource.

[0114] If it is determined that access to the device resources is permitted, at step 1050, the processor 120 may perform processing such that the device resources accessed by the operating system or at least one application are executed.

[0115] Figure 11A FIG. 1100 is a diagram showing operations of accessing device resources in a general electronic device. In addition, Figure 11B FIG. 1120 is a diagram showing operations of accessing device resources in the electronic device 101 according to an embodiment.

[0116] Referring to Figure 11A , the electronic device may execute at least one application based on a specified input, for example, the camera application 1102. In response to the execution of the camera application 1102, at least one camera driver program 1104 (for example, a camera driver of the operating system) for operating at least one device resource (for example, a camera module) may be executed in a memory area. In addition, the camera driver 1104 may access a register 1106 related to the input / output of the camera module to process the camera module to be operated. The register 1106 of the device resource may be easily accessed by the application, and thus there may be a problem that the device resources of the electronic device may be maliciously used. For example, there may be a problem that a user discovers that a lost electronic device is using or attempting to use the device resources.

[0117] However, the electronic device 101 determines the permission for an application to access at least one device resource in an area where at least one of a hypervisor (EL2), Secure EL2, and a virtual machine monitor (VMM) is executed. Therefore, the electronic device may prevent forgery (or tampering) of a database related to the device resources of the electronic device and prevent malicious or unauthorized use of the device resources of the electronic device.

[0118] Specifically, referring to Figure 11B , if the camera driver 1104 is detected accessing the register 1106 related to the input / output of the device resource (for example, the camera module), the processor 120 determines the permission for the application to access the device resource, which is configured in the hypervisor 1108. Therefore, malicious use of the device resources of the electronic device 101 can be prevented.

[0119] According to an embodiment, a method of operating an electronic device may include: executing at least one operating system executed in a first area that permits an operation based on a first permission; executing at least one application executed in a second area that permits an operation based on a second permission; and in response to detecting access by the at least one application to at least one device resource, configuring an access permission to the at least one device resource by using a permission determination module executed in a third area that permits an operation based on a third permission. The permission determination module may include a hypervisor.

[0120] The third privilege may include a privilege higher than the first privilege.

[0121] The third area that permits operations based on the third privilege may include an area in which at least one of a hypervisor, Secure EL2, and a virtual machine monitor (VMM) is executed.

[0122] The method of the electronic device may further include that the processor is further configured to store a privilege policy in the third area that permits operations based on the third privilege, and the privilege policy defines device resources restricted from access by the at least one application.

[0123] The method of the electronic device may further include obtaining a privilege policy in the electronic device or from an external device.

[0124] The privilege policy may be provided to a non-secure area that permits operations based on the third privilege through a non-secure area of the processor.

[0125] The privilege policy may be provided to a secure area that permits operations based on the third privilege through a secure area of the processor.

[0126] The privilege policy may be provided to a non-secure area that permits operations based on the third privilege through a secure area of the processor.

[0127] The method of the electronic device may further include determining access privileges of the at least one application based on the configured access privileges to the at least one device resource, and providing information indicating restricted access to the at least one device resource if the configured privilege is determined to be a privilege that restricts access to the at least one device resource.

[0128] Obtaining the privilege policy may include obtaining a specified first privilege policy during a boot operation, and after the boot operation is completed, obtaining a second privilege policy. The first privilege policy may be stored in the electronic device, and the second privilege policy may be obtained from outside the electronic device.

[0129] Although various embodiments have been described, various changes may be made therein without departing from the scope of the various embodiments. Therefore, the scope of the various embodiments should not be defined as limited to the illustrated embodiments, but should be defined by the appended claims and their equivalents.

Claims

1. An electronic device, comprising: Memory; and a processor, configured to: execute at least one operating system that executes in a first region of the processor that permits operations based on a first privilege; execute at least one application that executes in a second region of the processor that permits operations based on a second privilege; in response to detecting access by the at least one application to at least one device resource, configure access rights to the at least one device resource by using a privilege determination module that executes in a third region of the processor that permits operations based on a third privilege; store a privilege policy in a third region that permits operations based on the third privilege, the privilege policy defining device resources restricted from access by the at least one application, and provide the privilege policy from a secure region of the processor to a non-secure region of the processor that permits operations based on the third privilege, wherein the third region that permits operations based on the third privilege includes a region in which at least one of a hypervisor for the non-secure region or a security exception level executes.

2. The electronic device according to claim 1, wherein, The third privilege includes a privilege higher than the first privilege.

3. The electronic device according to claim 1, wherein, The processor is further configured to obtain a privilege policy in an electronic device or from an external device.

4. The electronic device according to claim 1, wherein, The processor is further configured to provide the privilege policy from a non-secure region of the processor to a non-secure region of the processor that permits operations based on the third privilege.

5. The electronic device according to claim 1, wherein, The processor is further configured to provide the privilege policy from a secure region of the processor to a secure region of the processor that permits operations based on the third privilege.

6. The electronic device according to claim 1, wherein, The processor is further configured to: determine access rights of the at least one application based on the configured access rights to the at least one device resource; and and if the configured privilege is determined to be a privilege that restricts access to the at least one device resource, provide information indicating the restricted access to the at least one device resource.

7. The electronic device according to claim 1, wherein, The privilege determination module includes a hypervisor.

8. A method for operating an electronic device, the method comprising: execute at least one operating system that executes in a first region of the processor that permits operations based on a first privilege; execute at least one application that executes in a second region of the processor that permits operations based on a second privilege; in response to detecting access by the at least one application to at least one device resource, configure access rights to the at least one device resource by using a privilege determination module that executes in a third region of the processor that permits operations based on a third privilege; store a privilege policy in a third region that permits operations based on the third privilege, the privilege policy defining device resources restricted from access by the at least one application, and provide the privilege policy from a secure region of the processor to a non-secure region of the processor that permits operations based on the third privilege, wherein the third region that permits operations based on the third privilege includes a region in which at least one of a hypervisor for the non-secure region or a security exception level executes.

9. The method according to claim 8, wherein, The third privilege includes a privilege higher than the first privilege.

10. The method according to claim 8, further comprising: Obtain a privilege policy in an electronic device or from an external device.

11. The method according to claim 10, further comprising: Acquire a specified first privilege policy during a boot operation; and and after the boot operation is completed, acquire a second privilege policy.

12. The method according to claim 8, further comprising: Provide the privilege policy from a non-secure region of the processor to a non-secure region of the processor that permits operations based on the third privilege.

13. The method according to claim 8 further comprises: Provide a permission policy from a secure area of the processor to a secure area of the processor that allows operations based on a third privilege.

14. The method according to claim 8 further comprises: Determine access permissions for the at least one application based on the configured access permissions for the at least one device resource; and If the configured permission is determined to be a permission that restricts access to the at least one device resource, provide information indicating the restriction of access to the at least one device resource.

Citation Information

Patent Citations

  • Processing method and processing device of malicious application for electronic device

    KR1020150124757A

  • Method for executing an application in a restricted operating environment

    US20140189852A1

  • Computing system for securely executing a secure application in a rich execution environment

    US20180129525A1