Electronic device for updating firmware using a secure integrated circuit and method of operating the same

By using a security integrated circuit in an electronic device, performing user authentication and generating authentication information, the problem of personal information leakage caused by internal attacks during firmware update is solved, and the secure firmware update of the electronic device is realized.

CN114450663BActive Publication Date: 2025-06-13SAMSUNG ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202080068520.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-09-27
Filing Date
2020-09-09
Publication Date
2025-06-13
Estimated Expiration
2040-09-09

AI Technical Summary

Technical Problem

Personal information stored in electronic devices may be leaked due to internal attacks, especially during firmware updates, where firmware obtained from unreliable sources can pose a security threat and users may not be aware of these attacks.

Method used

It adopts a security integrated circuit, which includes the main processor and the security processor, performs user authentication through the security processor, generates authentication information and stores it in a secure memory, ensuring that only certified firmware is installed.

Benefits of technology

Through the storage and use of user authentication and authentication information, electronic devices remain safe during firmware updates and prevent personal information leakage caused by internal attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114450663B_ABST
    Figure CN114450663B_ABST
Patent Text Reader

Abstract

Devices and methods for updating firmware by using a secure integrated circuit in an electronic device. The electronic device may include a secure integrated circuit (IC) that provides a general execution environment and a secure execution environment. The secure integrated circuit includes a main processor operating in the general execution environment and a secure processor operating in the secure execution environment. The secure processor is configured to perform user authentication based on firmware update information received from a server through the main processor. If the user authentication is successful, authentication information corresponding to the firmware update information is generated and stored in at least a portion of a secure memory. If the firmware is installed, authentication of the firmware is performed based on the authentication information stored in the secure memory, and if the authentication of the firmware is successful, the firmware is installed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Various embodiments relate to an apparatus and method for updating firmware by using a secure integrated circuit in an electronic device. Background Art

[0002] With the development of information and communication technology and semiconductor technology, various types of electronic devices have evolved into multimedia devices that provide various multimedia services. For example, the multimedia services may include at least one of a voice call service, a messaging service, a broadcast service, a wireless Internet service, a camera service, an electronic payment service, or a music playback service.

[0003] As the services provided by the electronic device become more diverse, the amount of personal information stored in the electronic device is increasing. For example, the personal information stored in the electronic device may include information that requires security configuration (such as payment information) and information related to certificates and credentials. Summary of the Invention

[0004] Technical Problem

[0005] Due to various types of attacks, personal information stored in an electronic device may be leaked to the outside. For example, the various types of attacks may include internal attacks. For example, an internal attack may include an attack method in which, when a binary including a personal information publishing function is signed with a valid signature key without the user's consent and installed in the electronic device (as if the binary is a normal binary), the personal information stored in the electronic device is leaked to the outside by the personal information publishing function included in the binary.

[0006] Internal attacks may occur due to error codes or malicious codes (such as a personal information publishing function), where an insider having permissions related to personal information includes these codes in a normal binary and publishes them in the normal binary. Therefore, the electronic device needs a method for preventing internal attacks caused by updating firmware from an unreliable source without the user being aware of the attack.

[0007] Various embodiments provide an apparatus and method for updating firmware by using a secure integrated circuit in an electronic device.

[0008] Solution to the Problem

[0009] According to various embodiments, an electronic device may include: a secure integrated circuit (IC) that provides a general execution environment and a secure execution environment, where the secure integrated circuit includes a main processor operating in the general execution environment and a secure processor operating in the secure execution environment, and where the secure processor is configured to: perform user authentication based on firmware update information received from a server by the main processor; generate authentication information corresponding to the firmware update information if the user authentication is successful; store the authentication information in at least a portion of a secure memory; perform authentication of the firmware based on the authentication information stored in the secure memory if the firmware is installed; and install the firmware if the firmware authentication is successful.

[0010] According to various embodiments, a method of operating an electronic device may include: in a secure integrated circuit (IC) including a main processor operating in a general execution environment and a secure processor operating in a secure execution environment, performing user authentication by the secure processor based on firmware update information received from a server by the main processor; generating authentication information corresponding to the firmware update information if the user authentication is successful; storing the authentication information in at least a portion of a secure memory; performing authentication of the firmware based on the authentication information stored in the secure memory if the corresponding firmware is installed; and installing the firmware if the firmware authentication is successful.

[0011] Before presenting the following "Detailed Description", it may be advantageous to set forth definitions of certain words and phrases used throughout this patent document: The term "comprising" and its derivatives mean including but not limited to; the term "or" is inclusive and means and / or; the phrases "associated with" and "associated therewith" and their derivatives may mean including, included within, interconnected with, containing, contained in, connected to or coupled with, capable of communicating with, cooperating with, interlacing, juxtaposed, proximate to, bound to or coupled with, having, having the property of, etc.; and the term "controller" means any device, system, or part thereof that controls at least one operation, and such device may be implemented in hardware, firmware, software, or some combination of at least two of them. It should be noted that the functions associated with any particular controller may be centralized or distributed, whether local or remote.

[0012] In addition, the various functions described below can be implemented or supported by one or more computer programs, each of which is formed of computer-readable program code and embodied in a computer-readable medium. The terms "application" and "program" refer to one or more computer programs, software components, instruction sets, procedures, functions, objects, classes, instances, related data, or a portion thereof that are adapted to be implemented with appropriate computer-readable program code. The phrase "computer-readable program code" includes any type of computer code, including source code, object code, and executable code. The phrase "computer-readable medium" includes any type of medium that can be accessed by a computer, such as read-only memory (ROM), random access memory (RAM), hard disk drives, optical discs (CDs), digital video discs (DVDs), or any other type of memory. A "non-transitory" computer-readable medium excludes wired, wireless, optical, or other communication links that transmit transitory electrical signals or other signals. Non-transitory computer-readable media include media that can permanently store data, as well as media that can store data and then rewrite the data, such as rewritable optical discs or erasable memory devices.

[0013] Throughout this patent document, definitions of certain words and phrases are provided. Those of ordinary skill in the art should understand that, in many, if not most, instances, such definitions apply to the prior as well as future use of such defined words and phrases.

[0014] Advantageous Effects of the Invention

[0015] According to various embodiments, if an electronic device successfully performs user authentication of firmware-related update information by using a secure integrated circuit, the electronic device may generate authentication information and store the generated authentication information in a secure memory, and update the firmware at the time point of updating the firmware based on the authentication information stored in the secure memory. Accordingly, the electronic device may update the firmware safely and effectively. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] To more fully understand the present disclosure and its advantages, reference is now made to the following description taken in conjunction with the accompanying drawings, in which like reference numerals represent like parts:

[0017] Figure 1 A block diagram showing an electronic device in a network environment according to various embodiments;

[0018] Figure 2 A block diagram showing an electronic device for updating firmware according to various embodiments;

[0019] Figure 3 A block diagram showing an electronic device for updating firmware according to various embodiments;

[0020] Figure 4Block diagram of an electronic device for updating firmware according to various embodiments;

[0021] Figure 5 Block diagram of an electronic device for updating firmware according to various embodiments;

[0022] Figure 6 Flowchart for updating firmware in an electronic device according to various embodiments;

[0023] Figure 7 Flowchart for performing user authentication of update information in an electronic device according to various embodiments;

[0024] Figure 8A Screen configuration for user authentication according to various embodiments;

[0025] Figure 8B Screen configuration for configuring firmware update conditions according to various embodiments;

[0026] Figure 9 Flowchart for updating firmware based on authentication information in an electronic device according to various embodiments;

[0027] Figure 10A Screen configuration including firmware download status information according to various embodiments;

[0028] Figure 10B Screen configuration for determining whether to install firmware according to various embodiments; and

[0029] 10C shows a screen configuration including firmware update restriction information according to various embodiments. Detailed Description of the Embodiments

[0030] The following discussion Figures 1 to 10C and the various embodiments for describing the principles of the present disclosure in this patent document are merely for illustrative purposes and should not be construed as limiting the scope of the present disclosure in any way. Those skilled in the art will understand that the principles of the present disclosure can be implemented in any appropriately arranged system or device.

[0031] Hereinafter, various embodiments of the present disclosure will be described in detail with reference to the accompanying drawings.

[0032] Figure 1 is a block diagram of an electronic device 101 in a network environment 100 according to various embodiments. Refer to Figure 1, the electronic device 101 in the network environment 100 may communicate with the electronic device 102 via the first network 198 (e.g., a short-range wireless communication network), or communicate with the electronic device 104 or the server 108 via the second network 199 (e.g., a long-range wireless communication network). According to an embodiment, the electronic device 101 may communicate with the electronic device 104 via the server 108. According to an embodiment, the electronic device 101 may include a processor 120, a memory 130, an input device 150, a sound output device 155, a display device 160, an audio module 170, a sensor module 176, an interface 177, a haptic module 179, a camera module 180, a power management module 188, a battery 189, a communication module 190, a subscriber identification module (SIM) 196, or an antenna module 197. In some embodiments, at least one of the components (e.g., the display device 160 or the camera module 180) may be omitted from the electronic device 101, or one or more other components may be added to the electronic device 101. In some embodiments, some of the components may be implemented as a single integrated circuit. For example, the sensor module 176 (e.g., a fingerprint sensor, an iris sensor, or an illuminance sensor) may be implemented as being embedded in the display device 160 (e.g., a display).

[0033] The processor 120 may run software (e.g., the program 140), for example, to control at least one other component (e.g., a hardware component or a software component) connected to the processor 120 of the electronic device 101, and may perform various data processing or calculations. According to one embodiment, as at least part of the data processing or calculation, the processor 120 may load a command or data received from another component (e.g., the sensor module 176 or the communication module 190) into the volatile memory 132, process the command or data stored in the volatile memory 132, and store the resulting data in the non-volatile memory 134. According to an embodiment, the processor 120 may include a main processor 121 (e.g., a central processing unit (CPU) or an application processor (AP)), and an auxiliary processor 123 (e.g., a graphics processing unit (GPU), an image signal processor (ISP), a sensor hub processor, or a communication processor (CP)) that is operationally independent of or combined with the main processor 121. Additionally or alternatively, the auxiliary processor 123 may be adapted to consume less power than the main processor 121, or be adapted for a specific function. The auxiliary processor 123 may be implemented as being separate from the main processor 121, or as part of the main processor 121.

[0034] When the main processor 121 is in an inactive (e.g., sleep) state, the auxiliary processor 123 may control at least some of the functions or states related to at least one of the components of the electronic device 101 (rather than the main processor 121) (e.g., the display device 160, the sensor module 176, or the communication module 190), or when the main processor 121 is in an active state (e.g., running an application), the auxiliary processor 123 may control, together with the main processor 121, at least some of the functions or states related to at least one of the components of the electronic device 101 (e.g., the display device 160, the sensor module 176, or the communication module 190). According to an embodiment, the auxiliary processor 123 (e.g., an image signal processor or a communication processor) may be implemented as part of another component (e.g., the camera module 180 or the communication module 190) that is functionally related to the auxiliary processor 123.

[0035] The memory 130 may store various data used by at least one component of the electronic device 101 (e.g., the processor 120 or the sensor module 176). The various data may include, for example, software (e.g., the program 140) and input data or output data for commands related thereto. The memory 130 may include a volatile memory 132 or a non-volatile memory 134.

[0036] The program 140 may be stored in the memory 130 as software, and the program 140 may include, for example, an operating system (OS) 142, middleware 144, or an application 146.

[0037] The input device 150 may receive commands or data to be used by other components of the electronic device 101 (e.g., the processor 120) from the outside of the electronic device 101 (e.g., a user). The input device 150 may include, for example, a microphone, a mouse, a keyboard, or a digital pen (e.g., a stylus).

[0038] The sound output device 155 may output a sound signal to the outside of the electronic device 101. The sound output device 155 may include, for example, a speaker or a receiver. The speaker may be used for general purposes such as playing multimedia or playing a record, and the receiver may be used for incoming calls. According to an embodiment, the receiver may be implemented separately from the speaker or as part of the speaker.

[0039] The display device 160 may visually provide information to the outside of the electronic device 101 (e.g., a user). The display device 160 may include, for example, a display, a holographic device, or a projector, and a control circuit for controlling the corresponding one of the display, the holographic device, and the projector. According to an embodiment, the display device 160 may include a touch circuit adapted to detect a touch or a sensor circuit (e.g., a pressure sensor) adapted to measure the intensity of a force caused by the touch.

[0040] The audio module 170 can convert sound into an electrical signal and vice versa. According to an embodiment, the audio module 170 can obtain sound via the input device 150, or output sound via the sound output device 155 or headphones of an external electronic device (e.g., electronic device 102) directly (e.g., wired) or wirelessly connected to the electronic device 101.

[0041] The sensor module 176 can detect the operating state of the electronic device 101 (e.g., power or temperature) or the environmental state outside the electronic device 101 (e.g., the state of the user), and then generate an electrical signal or data value corresponding to the detected state. According to an embodiment, the sensor module 176 can include, for example, a gesture sensor, a gyro sensor, an atmospheric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an infrared (IR) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0042] The interface 177 can support one or more specific protocols for directly (e.g., wired) or wirelessly connecting the electronic device 101 to an external electronic device (e.g., electronic device 102). According to an embodiment, the interface 177 can include, for example, a high-definition multimedia interface (HDMI), a universal serial bus (USB) interface, a secure digital (SD) card interface, or an audio interface.

[0043] The connection end 178 can include a connector through which the electronic device 101 can be physically connected to an external electronic device (e.g., electronic device 102). According to an embodiment, the connection end 178 can include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0044] The haptic module 179 can convert an electrical signal into a mechanical stimulus (e.g., vibration or movement) or an electrical stimulus that can be recognized by the user via his sense of touch or kinesthesia. According to an embodiment, the haptic module 179 can include, for example, a motor, a piezoelectric element, or an electrical stimulator.

[0045] The camera module 180 can capture still images or moving images. According to an embodiment, the camera module 180 can include one or more lenses, an image sensor, an image signal processor, or a flash. The power management module 188 can manage the power supply to the electronic device 101. According to an embodiment, the power management module 188 can be implemented as at least part of, for example, a power management integrated circuit (PMIC).

[0046] The battery 189 can supply power to at least one component of the electronic device 101. According to an embodiment, the battery 189 can include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0047] The communication module 190 may support establishing a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device 101 and an external electronic device (e.g., the electronic device 102, the electronic device 104, or the server 108), and perform communication via the established communication channel. The communication module 190 may include one or more communication processors capable of operating independently of the processor 120 (e.g., an application processor (AP)), and support direct (e.g., wired) communication or wireless communication. According to an embodiment, the communication module 190 may include a wireless communication module 192 (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194 (e.g., a local area network (LAN) communication module or a power line communication (PLC) module). Each of these communication modules may communicate with an external electronic device via a first network 198 (e.g., a short-range communication network such as Bluetooth, Wi-Fi Direct, or Infrared Data Association (IrDA)) or a second network 199 (e.g., a long-range communication network such as a cellular network, the Internet, or a computer network (e.g., LAN or wide area network (WAN))). These various types of communication modules may be implemented as a single component (e.g., a single chip), or these various types of communication modules may be implemented as multiple separate components (e.g., multiple chips). The wireless communication module 192 may use the subscriber information (e.g., international mobile subscriber identity (IMSI)) stored in the subscriber identification module 196 to identify and authenticate the electronic device 101 in a communication network (such as the first network 198 or the second network 199).

[0048] The antenna module 197 may transmit a signal or power to the outside of the electronic device 101 (e.g., an external electronic device) or receive a signal or power from the outside of the electronic device 101 (e.g., an external electronic device). According to one embodiment, the antenna module 197 may include an antenna, which includes a radiation element composed of a conductive material or a conductive pattern formed in or on a substrate (e.g., a PCB). According to one embodiment, the antenna module 197 may include multiple antennas. In this case, for example, the communication module 190 (e.g., the wireless communication module 192) may select at least one antenna suitable for the communication scheme used in a communication network (such as the first network 198 or the second network 199) from the multiple antennas. Then, a signal or power is transmitted or received between the communication module 190 and an external electronic device via the selected at least one antenna. According to an embodiment, another component (e.g., a radio frequency integrated circuit (RFIC)) other than the radiation element may be additionally formed as part of the antenna module 197.

[0049] At least some of the above components may be interconnected via an inter-peripheral communication scheme (e.g., a bus, General-Purpose Input / Output (GPIO), Serial Peripheral Interface (SPI), or Mobile Industry Processor Interface (MIPI)) and communicatively transmit signals (e.g., commands or data) therebetween.

[0050] According to an embodiment, commands or data may be sent or received between the electronic device 101 and the external electronic device 104 via the server 108 connected to the second network 199. Each of the electronic devices 102 and 104 may be a device of the same type as the electronic device 101 or a device of a different type from the electronic device 101. According to an embodiment, all or some of the operations running on the electronic device 101 may be run on one or more of the external electronic device 102, the external electronic device 104, or the server 108. For example, if the electronic device 101 is to automatically perform a function or service or is to perform a function or service in response to a request from a user or another device, the electronic device 101 may request one or more of the external electronic devices to perform at least part of the function or service, rather than running the function or service, or in addition to running the function or service, the electronic device 101 may also request one or more of the external electronic devices to perform at least part of the function or service. The one or more external electronic devices that receive the request may perform the requested at least part of the function or service, or perform additional functions or additional services related to the request, and transmit the result of the execution to the electronic device 101. The electronic device 101 may provide the result as at least part of a reply to the request, with or without further processing of the result. To this end, for example, cloud computing technology, distributed computing technology, or client-server computing technology may be used.

[0051] An electronic device according to various embodiments may be one of various types of electronic devices. The electronic device may include, for example, a portable communication device (e.g., a smart phone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a household appliance. According to an embodiment of the present disclosure, the electronic device is not limited to those described above.

[0052] It should be understood that the various embodiments of the present disclosure and the terms used therein are not intended to limit the technical features set forth herein to specific embodiments, but include various changes, equivalent forms or alternative forms for the corresponding embodiments. For the description of the drawings, like reference numerals may be used to refer to like or related elements. It will be understood that a singular noun corresponding to a term may include one or more things, unless the relevant context clearly indicates otherwise. As used herein, each of the phrases such as "A or B", "at least one of A and B", "at least one of A or B", "A, B or C", "at least one of A, B and C", and "at least one of A, B or C" may include all possible combinations of the items listed together in the corresponding one of the plurality of phrases. As used herein, terms such as "first" and "second" or "1st" and "2nd" may be used to simply distinguish the corresponding components from another component, and do not limit the components in other respects (e.g., importance or order). It will be understood that, in the case where the term "operably" or "communicatively" is used or where the term "operably" or "communicatively" is not used, if an element (e.g., a first element) is referred to as "coupled with another element (e.g., a second element)", "coupled to another element (e.g., a second element)", "connected with another element (e.g., a second element)", or "connected to another element (e.g., a second element)", it means that the one element can be directly (e.g., wired) connected to the other element, wirelessly connected to the other element, or connected to the other element via a third element.

[0053] As used herein, the term "module" may include a unit implemented in hardware, software or firmware, and may be used interchangeably with other terms (e.g., "logic", "logic block", "portion" or "circuit"). A module may be a single integrated component adapted to perform one or more functions or the smallest unit or portion of the single integrated component. For example, according to an embodiment, a module may be implemented in the form of an application specific integrated circuit (ASIC).

[0054] The various embodiments described herein can be implemented as software (e.g., program 140) including one or more instructions readable by a machine (e.g., electronic device 101) stored in a storage medium (e.g., internal memory 136 or external memory 138). For example, under the control of a processor, a processor (e.g., processor 120) of the machine (e.g., electronic device 101) can call at least one of the one or more instructions stored in the storage medium and run the at least one instruction with or without using one or more other components. This enables the machine to operate to perform at least one function according to the at least one instruction called. The one or more instructions can include code generated by a compiler or code that can be run by an interpreter. The machine-readable storage medium can be provided in the form of a non-transitory storage medium. Herein, the term "non-transitory" only means that the storage medium is a tangible device and does not include signals (e.g., electromagnetic waves), but this term does not distinguish between data being stored semi-permanently in the storage medium and data being stored temporarily in the storage medium.

[0055] According to an embodiment, a method according to various embodiments of the present disclosure can be included and provided in a computer program product. The computer program product can be traded between a seller and a purchaser as a product. The computer program product can be distributed (e.g., downloaded or uploaded) online via an application store (e.g., PlayStore TM ) in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or can be directly distributed (e.g., downloaded or uploaded) between two user devices (e.g., smart phones). If it is distributed online, at least part of the computer program product can be generated temporarily, or at least part of the computer program product can be stored at least temporarily in a machine-readable storage medium (such as the memory of a manufacturer's server, an application store's server, or a forwarding server).

[0056] According to various embodiments, each of the above components (e.g., a module or a program) may include a single entity or multiple entities. According to various embodiments, one or more of the above components may be omitted, or one or more other components may be added. Optionally or additionally, multiple components (e.g., modules or programs) may be integrated into a single component. In this case, according to various embodiments, the integrated component may still perform the one or more functions of each of the multiple components in the same or similar manner as the corresponding one of the multiple components performed one or more functions before integration. According to various embodiments, the operations performed by a module, a program, or another component may be performed sequentially, in parallel, repeatedly, or in a heuristic manner, or one or more of the operations may be run in a different order or omitted, or one or more other operations may be added.

[0057] Figure 2 FIG. is a block diagram illustrating an electronic device 200 for updating firmware according to various embodiments. In the following description, the electronic device 200 may include Figure 1 at least a portion of the electronic device 101 in

[0058] Referring to Figure 2 , the electronic device 200 may include a secure integrated circuit (IC) 210 that supports a general environment (general execution environment) and a secure environment (secure execution environment).

[0059] According to various embodiments, the secure integrated circuit 210 may employ a system-on-chip (SoC) that includes a main processor 220, a secure processor 230, and a secure memory 240. According to an embodiment, the main processor 220 may be substantially the same as or may be included in the main processor 121 in Figure 1 . The secure processor 230 may be substantially the same as or may be included in the auxiliary processor 123 in Figure 1 . The secure memory 240 may be substantially the same as or may be included in the non-volatile memory 134 in Figure 1 .

[0060] According to various embodiments, the main processor 220 may control the processing and calculation of data in the general execution environment. According to an embodiment, if the usage environment of the electronic device 200 satisfies the firmware update condition, the main processor 220 may transmit a request signal for updating the firmware to the secure processor 230. For example, the firmware update condition may include at least one of "install immediately", "install at night", "install when connected to a wireless LAN", or "install at a specific time". The firmware update condition may be configured by a user. For example, the main processor 220 may include an application processor (AP).

[0061] According to various embodiments, the security processor 230 may be operably connected to the main processor 220 to communicate with the main processor 220. The security processor 230 may receive a request for operating or initializing a secure execution environment from the main processor 220, and control data processing and computing in the secure execution environment. For example, the security processor 230 may include at least one of a processing module, an encryption module, a secure memory controller, a secure cache, a read-only memory (ROM), a random access memory (RAM), a memory controller (MEM controller), or a security sensor.

[0062] According to an embodiment, if the security processor 230 determines that the firmware-related update information received from the main processor 220 is valid, the security processor may perform user authentication of the firmware-related update information. If the security processor 230 successfully performs user authentication of the firmware-related update information, the security processor may generate authentication information related to the firmware, and may store the generated authentication information in the secure memory 240. For example, the firmware-related update information may include at least one of firmware version information, patch content, hash information related to the firmware, or a signature of an external device (e.g., a server). For example, the validity of the firmware-related update information may be determined based on the signature of the external device, through which it is possible to identify whether the update information has been forged or tampered with and to identify the source of the update information. For example, the authentication information related to the firmware may include at least one of the version information of the firmware, hash information, and the hash-based message authentication code (HMAC) value of the security processor 230 or information related to the permission of the authentication information. For example, the version information of the firmware may include identification information of the firmware binary and / or version information of the firmware binary (e.g., a rollback prevention version (RP)). The version information of the firmware binary may be signed with the manufacturer's signature key, and thus the integrity of the version information can be ensured. For example, the hash information may include the hash value of the firmware binary. For example, the information related to the permission of the authentication information may include information about the permission time point of the authentication information and / or information about the expiration time point of the permission of the authentication information. For example, the expiration time point of the permission of the authentication information may be configured based on the permission time point of the authentication information, or may be randomly configured based on user input.

[0063] According to an embodiment, if the security processor 230 receives a request signal for updating the firmware from the main processor 220, the security processor may determine whether the authentication information stored in the secure memory 240 is valid. For example, the validity of the authentication information stored in the secure memory 240 may be determined based on at least one of the permission time point information, the expiration time point information of the permission, or the HMAC value of the authentication information (which is included in the authentication information).

[0064] According to an embodiment, if the security processor 230 has determined that the authentication information stored in the secure memory 240 is valid, the security processor 230 may authenticate the firmware requested to be updated by the main processor 220 based on the authentication information stored in the secure memory 240. If the security processor 230 successfully authenticates the firmware requested to be updated by the main processor 220, the security processor may update the firmware of the electronic device 200. For example, if the hash information of the authentication information and the hash information of the firmware requested to be updated by the main processor 220 are the same as each other, the security processor 230 may determine that the authentication of the firmware is successful.

[0065] According to various embodiments, the secure memory 240 may be operably connected to the security processor 230. For example, the secure memory 240 may perform encrypted communication with the security processor 230 by using a key previously shared with the security processor 230 (e.g., a subscriber management key (SMK)). According to an embodiment, the secure memory 240 may store authentication information related to the firmware received from the security processor 230 and / or store the firmware. For example, the firmware stored in the secure memory 240 may include the firmware currently running in the electronic device 200. For example, when the firmware of the electronic device 200 is updated, the secure memory 240 may store the updated firmware of the electronic device 200 under the control of the security processor 230.

[0066] Figure 3 A block diagram of an electronic device 300 for updating firmware according to various embodiments is shown. In the following description, the electronic device 300 may include Figure 1 at least a part of the electronic device 101 in

[0067] Refer to Figure 3 , the electronic device 300 may include a secure integrated circuit 310 and a non-secure memory 350. According to an embodiment, the non-secure memory 350 may be substantially the same as or may include the non-volatile memory 134 in Figure 1

[0068] According to various embodiments, the secure integrated circuit 310 may employ a system-on-chip that includes a main processor 320, a security processor 330, and a secure memory 340, wherein the main processor 320 operates in a general execution environment and the security processor 330 operates in a secure execution environment. The secure integrated circuit 310 of the electronic device 300 may operate in a manner similar to Figure 2 the secure integrated circuit 210 of the electronic device 200 in Figure 3 For example, Figure 2 ​operates in the manner of the main processor 220, the security processor 230, and the security memory 240 in []. Therefore, to avoid duplicate descriptions, detailed descriptions of the components of the security integrated circuit 310 of the electronic device 300 are omitted. Figure 2 duplicate descriptions, a detailed description of the components of the security integrated circuit 310 of the electronic device 300 is omitted.

[0069] According to various embodiments, if the security processor 330 has updated the firmware of the electronic device 300, the main processor 320 may store the updated firmware in the non-secure memory 350. According to an embodiment, if the security processor 330 has updated the firmware of the electronic device 300, the main processor 320 may store the firmware received from the security processor 330 and the signature information of the security processor 330 in the non-secure memory 350. For example, the signature information of the security processor 330 may include a security key (e.g., a rights encryption key (REK), or a fused bit) to secure the communication of the security processor 330.

[0070] According to various embodiments, the non-secure memory 350 may store various data used by at least one component (e.g., the main processor 320) of the electronic device 300 in a general execution environment. According to an embodiment, the non-secure memory 350 may include a first area 352 and a second area 354 for storing firmware. For example, the first area 352 may be designated as an inactive area where new firmware downloaded from an external device to update the firmware is stored. The second area 354 may be designated as an active area where the firmware currently running in the electronic device 300 is stored. According to an embodiment, if the security processor 330 has updated the firmware of the electronic device 300 based on the firmware stored in the first area 352, the first area 352 of the non-secure memory 350 may be changed to an active area under the control of the main processor 320. That is, the firmware stored in the first area 352 may be configured as the firmware currently running in the electronic device 300 through a firmware update. The signature information of the security processor 330 may be stored together with the firmware of the electronic device 300 in the first area 352. According to an embodiment, if the security processor 330 has updated the firmware of the electronic device 300, the second area 354 of the non-secure memory 350 may be changed to an inactive area under the control of the main processor 320. The signature information related to the previously stored firmware may be removed from the second area 354.

[0071] Figure 4 A block diagram of an electronic device 400 for updating firmware according to various embodiments is shown. In the following description, the electronic device 400 may include Figure 1 at least a part of the electronic device 101 in [].

[0072] Referring toFigure 4 , the electronic device 400 may include a secure integrated circuit 410, a secure memory 440, and a non-secure memory 450.

[0073] According to various embodiments, the secure integrated circuit 410 may employ a system-on-chip that includes a main processor 420 operating in a general execution environment and a secure processor 430 operating in a secure execution environment. The secure integrated circuit 410 of the electronic device 400 may operate in a manner similar to Figure 2 the secure integrated circuit 210 of the electronic device 200 in Figure 4 , except that the secure memory 440 is separated from the secure integrated circuit 410. For example, Figure 2 the main processor 420 and the secure processor 430 in Figure 2 may operate in a manner similar to the main processor 220 and the secure processor 230 in

[0074] Accordingly, to avoid redundant descriptions, detailed descriptions of the elements of the secure integrated circuit 410 of the electronic device 400 are omitted.

[0074] According to various embodiments, the secure processor 430 may encrypt data transmitted to the secure memory 440 to prevent the data from being exposed to the outside due to the secure memory 440 being external to the secure integrated circuit 410. According to an embodiment, if the secure processor 430 successfully performs user authentication of firmware-related update information, the secure processor may generate an authentication key (AK) and an encryption key (EK). The authentication key may be used to generate an HMAC value included in the authentication information. The encryption key may be used to encrypt the information included in the authentication information. For example, the authentication key may be generated through a key derivation function (KDF), where a key previously shared between the secure processor 430 and the secure memory 440 (e.g., SMK) and a security key defined for secure communication of the secure processor 430 (e.g., a fused REK or a fused bit) are applied to the function. For example, the encryption key may be generated through a KDF to which a security key is applied to secure the communication of the secure processor 430. According to an embodiment, the main processor 420 may store the data (e.g., authentication information) encrypted by the secure processor 430 in the secure memory 440.

[0075] According to various embodiments, the non-secure memory 450 may store various data used by at least one element (e.g., the main processor 420) of the electronic device 400 in a general execution environment. According to an embodiment, the non-secure memory 450 may include a first region 452 (e.g., Figure 3 the first region 352 in Figure 3 ) for storing firmware and a second region 454 (e.g.,

[0076] Figure 5 FIG. is a block diagram of an electronic device 500 for updating firmware according to various embodiments. In the following description, the electronic device 500 may include Figure 1 at least a part of the electronic device 101 in

[0077] Referring to Figure 5 , the electronic device 500 may include a secure integrated circuit 510, a secure memory 540, and a non-secure memory 550.

[0078] According to various embodiments, the secure integrated circuit 510 may employ a system-on-chip including a main processor 520 operating in a general execution environment and a secure processor 530 operating in a secure execution environment. The secure integrated circuit 510 of the electronic device 500 may operate in a manner similar to Figure 2 the secure integrated circuit 210 of the electronic device 200 in Figure 5 , except that the secure memory 540 is separated from the secure integrated circuit 510. For example, Figure 2 the main processor 520 and the secure processor 530 in Figure 2 may operate in a manner similar to the main processor 220 and the secure processor 230 in

[0079] According to various embodiments, the secure processor 530 may encrypt data transmitted to the secure memory 540 to prevent the data from being exposed to the outside due to the secure memory 540 being external to the secure integrated circuit 510. According to an embodiment, the secure processor 530 may encrypt the secure information based on a key (e.g., SMK) previously shared with the secure memory 540. The secure processor 530 may store the secure information encrypted based on the key previously shared in the secure memory 540.

[0080] According to various embodiments, the non-secure memory 550 may store various data used by at least one element (e.g., the main processor 520) of the electronic device 400 in a general execution environment. According to an embodiment, the non-secure memory 550 may include a first area 552 (e.g., Figure 3 the first area 352 in Figure 3 ) and a second area 554 (e.g.,

[0081] According to various embodiments, an electronic device (e.g., Figure 2 the electronic device 200 in Figure 2The secure integrated circuit 210) includes a main processor operating in a general execution environment (e.g., Figure 2 the main processor 220) and a secure processor operating in a secure execution environment (e.g., Figure 2 the secure processor 230), and wherein the secure processor is configured to: perform user authentication based on firmware update information received from a server by the main processor; if the user authentication is successful, generate authentication information corresponding to the firmware update information; store the authentication information in at least a portion of a secure memory (e.g., Figure 2 the secure memory 240); if the firmware is installed, perform authentication of the firmware based on the authentication information stored in the secure memory; and if the authentication of the firmware is successful, install the firmware.

[0082] According to various embodiments, the secure memory may be included in the secure integrated circuit.

[0083] According to various embodiments, the authentication information may include at least one of: version information included in the firmware update information, a hash included in the firmware update information, a hash-based message authentication code (HMAC) associated with the secure processor, a time associated with the authorization of the authentication information, or an expiration time of the authorization of the authentication information.

[0084] According to various embodiments, the secure processor may: determine whether signature information of the server included in the firmware update information satisfies a specified condition; and if the signature information of the server satisfies the specified condition, perform user authentication of the firmware update information.

[0085] According to various embodiments, the secure processor may: determine whether signature information of the server included in the firmware update information satisfies a specified condition; if the signature information of the server satisfies the specified condition, compare the version information included in the firmware update information with the version information of the firmware installed in the electronic device; and if the version included in the firmware update information is later than the version of the firmware installed in the electronic device, perform user authentication of the firmware update information.

[0086] According to various embodiments, if the secure memory is located outside the secure integrated circuit, the secure processor may encrypt the authentication information with a security key associated with the secure processor and store the encrypted authentication information in at least a portion of the secure memory.

[0087] According to various embodiments, if the installation condition of the firmware is satisfied, the main processor may transmit a request signal for installing the firmware to the secure processor, and if the secure processor receives the request signal from the main processor, the secure processor may perform authentication of the firmware based on the authentication information stored in the secure memory.

[0088] According to various embodiments, a security processor may: determine whether authentication information stored in a secure memory is valid; and if the authentication information is determined to be valid, perform authentication of firmware based on the authentication information.

[0089] According to various embodiments, a security processor may determine whether authentication information stored in a secure memory is valid based on at least one of an HMAC value, a validity time interval, or the number of uses of the authentication information.

[0090] According to various embodiments, a security processor may: if authentication of firmware fails, perform user authentication of the firmware; and if user authentication is successful, install the firmware.

[0091] Figure 6 FIG. 600 is a flowchart showing a method for updating firmware in an electronic device according to various embodiments. In the following embodiments, operations may be performed in sequence, but the present disclosure is not limited to sequential operations. For example, the order of operations may be changed, and at least two operations may be performed in parallel. Figure 6 The electronic device in Figure 1 may be the electronic device 101 of Figure 2 or the electronic device 200 of

[0092] Referring to Figure 6 , according to various embodiments, in operation 601, an electronic device (e.g., the processor 120 in Figure 1 or the security processor 230 in Figure 2 ) may receive update information related to firmware. According to an embodiment, the security processor 230 may receive update information related to firmware from an external device (e.g., a server) through the main processor 220. For example, the security processor 230 may receive update information related to firmware from a trusted external device through a Transport Layer Security (TLS) protocol. For example, the update information related to firmware may include at least one of firmware version information, patch content, hash information related to the firmware, or a signature of an external device (e.g., a server).

[0093] According to various embodiments, in operation 603, an electronic device (e.g., the processor 120 or the security processor 230) may identify whether user authentication of update information related to firmware is successful. According to an embodiment, the security processor 230 may, through a display device (e.g., Figure 1The display device 160) outputs the patch content of the firmware-related update information received from a trusted external device to allow the user to identify the patch content. The security processor 230 may determine whether user authentication is successful based on user input related to the patch content displayed on the display device. For example, a trusted external device may be identified based on signature information of the external device included in the firmware-related update information. For example, the firmware version information may include identification information of the firmware binary and firmware binary version information.

[0094] According to various embodiments, if the electronic device (e.g., the processor 120 or the security processor 230) successfully performs user authentication of the firmware update information (e.g., “Yes” related to operation 603), then in operation 605, the electronic device may generate authentication information related to the firmware. According to an embodiment, the security processor 230 may generate authentication information related to the firmware based on at least a part of the firmware-related update information (e.g., firmware version information and firmware hash information). For example, the authentication information related to the firmware may further include an HMAC value of the security processor 230 to indicate that the authentication information has been generated by the security processor 230 or to identify the integrity of the authentication information. For example, the authentication information related to the firmware may further include at least one of the permitted time point information or the permitted expiration time point information of the authentication information. As another example, if as Figure 4 shown, the secure memory 440 is located outside the secure integrated circuit 410, the security processor 430 may generate an authentication key (AK) and an encryption key (EK) based on a security key (e.g., a fused REK or a fused bit) defined for secure communication of the security processor 430. The security processor 430 may generate an HMAC value to be included in the authentication information based on the authentication key, and encrypt the information to be included in the authentication information (e.g., the HMAC value, the firmware version information, the firmware hash information, and the information related to the permission of the authentication information) by using the security key to generate the authentication information.

[0095] According to various embodiments, in operation 607, an electronic device (e.g., processor 120 or security processor 230) may store authentication information related to firmware in a secure memory. According to an embodiment, the security processor 230 may securely store the authentication information related to the firmware in the secure memory 240 through a secure channel generated based on a key (e.g., SMK) previously shared with the secure memory 240. According to another embodiment, the security processor 430 may store the authentication information related to the firmware in a secure memory 440 located outside the secure integrated circuit 410 through the main processor 420. For example, if there is previously stored authentication information in the secure memory 240, the security processor 230 may replace the previously stored authentication information stored in the secure memory 240 with new authentication information.

[0096] According to various embodiments, in operation 609, an electronic device (e.g., processor 120 or security processor 230) may identify whether the authentication of the firmware is successful based on the authentication information stored in the secure memory. According to an embodiment, if the firmware update time point has arrived, the main processor 220 may transmit a request signal for updating the firmware to the security processor 230. If the security processor 230 receives a request signal for updating the firmware from the main processor 220, the security processor may generate a hash value corresponding to the firmware received from the main processor 220. If the hash value corresponding to the firmware received from the main processor 220 and the hash value included in the authentication information stored in the secure memory are the same as each other, the security processor 230 may determine that the authentication of the firmware is successful. Additionally, if the version information of the firmware received from the main processor 220 and the version information included in the authentication information stored in the secure memory are the same as each other, the security processor 230 may determine that the authentication of the firmware is successful. According to an embodiment, if it is determined that the authentication information stored in the secure memory 240 is valid, the security processor 230 may perform the authentication of the firmware based on the authentication information stored in the secure memory 240.

[0097] According to various embodiments, if an electronic device (e.g., processor 120 or security processor 230) successfully authenticates the firmware based on the authentication information stored in the secure memory (e.g., "yes" related to operation 609), in operation 611, the electronic device may update the firmware of the electronic device with the authenticated firmware. According to an embodiment, if the storage space (or capacity) of the secure memory 240 is large enough to accommodate the firmware, the security processor 230 may store the updated firmware in the secure memory 240. According to another embodiment, the security processor 330 may store the updated firmware in the non-secure memory 450. Together with the updated firmware, the non-secure memory 450 may also store the signature of the security processor 330.

[0098] According to various embodiments, if an electronic device (e.g., the processor 120 or the security processor 230) fails in user authentication of update information related to firmware (e.g., "No" related to operation 603) or fails to authenticate the firmware based on the authentication information stored in the secure memory (e.g., "No" related to operation 609), then the firmware update program based on the authentication information may be blocked. According to an embodiment, if the security processor 230 fails in user authentication of update information related to firmware or fails to authenticate the firmware based on the authentication information, the security processor may perform user authentication again. According to another embodiment, if the security processor 230 fails in user authentication of update information related to firmware or fails to authenticate the firmware based on the authentication information, the security processor may output firmware update restriction information.

[0099] Figure 7 FIG. 700 is a flowchart showing user authentication of update information to be performed in an electronic device according to various embodiments. The operations described below Figure 7 may be Figure 6 detailed sub-operations of operation 603 in Figure 7 . In the following embodiments, the operations may be performed in order, but the present disclosure is not limited to sequential operations. For example, the order of the operations may be changed, and at least two operations may be performed in parallel. Figure 7 The electronic device in Figure 1 may be the electronic device 101 of Figure 2 or the electronic device 200 of Figure 8A . Thereafter, at least a part of the operations in Figure 8B will be described with reference to Figure 7 . Figure 8A FIG. shows a screen configuration for user authentication according to various embodiments. Figure 8B FIG. shows a screen configuration for configuring firmware update conditions according to various embodiments.

[0100] Referring to Figure 7 , according to various embodiments, if an electronic device (e.g., Figure 1 the processor 120 in Figure 2 or the security processor 230 in Figure 6In operation 601), in operation 701, the electronic device may determine whether update information related to the firmware is valid. According to an embodiment, if the security processor 230 receives update information related to the firmware from an external device (e.g., a server) through the main processor 220, the security processor may determine whether the external device is reliable based on the signature information of the external device included in the update information. For example, if the signature information of the external device included in the update information is included in the list of authenticated devices stored in the memory (e.g., memory 130 or secure memory 240), the security processor 230 may determine that the external device is reliable. If the security processor 230 has determined that the external device is reliable, the security processor may determine that the update information related to the firmware is valid.

[0101] According to various embodiments, if the electronic device (e.g., processor 120 or security processor 230) determines that the update information related to the firmware is valid (e.g., "yes" related to operation 701), in operation 703, the electronic device may identify the version information of the firmware included in the update information. For example, the version information of the firmware may include identification information of the firmware binary and firmware binary version information.

[0102] According to various embodiments, in operation 705, the electronic device (e.g., processor 120 or security processor 230) may determine whether the firmware can be installed in the electronic device based on the version information of the firmware included in the update information. According to an embodiment, the security processor 230 may compare the version information of the firmware operating in the electronic device 200 with the version information of the firmware included in the update information. If the version of the firmware operating in the electronic device 200 is earlier (or lower) than the version of the firmware included in the update information, the security processor 230 may determine that the firmware related to the update information can be installed in the electronic device. Accordingly, the security processor 230 may prevent the firmware from being updated to a previous version (or a lower version). For example, the version information of the firmware operating in the electronic device 200 may be identified in the authentication information stored in the secure memory 240.

[0103] According to various embodiments, if the electronic device (e.g., processor 120 or security processor 230) has determined that the firmware related to the update information can be installed in the electronic device (e.g., "yes" related to operation 705), in operation 707, the electronic device may display the update information related to the firmware. According to an embodiment, the security processor 230 may control the display device (e.g., Figure 1 the display device 160 in) through the main processor 220 such that the display device displays the patch information included in the update information. For example, as Figure 8A shown, the display device (e.g., Figure 1The display device 160) in can display the patch information 800 included in the update information. The patch information 800 may include information 802 related to functions that have been modified, added, or removed through firmware update.

[0104] According to various embodiments, in operation 709, an electronic device (e.g., the processor 120 or the security processor 230) may identify whether a permission input corresponding to update information related to firmware is detected. According to an embodiment, as Figure 8A shown, the security processor 230 may identify whether an input corresponding to the permission button 810 is detected in the patch information 800 displayed in at least a part of the display device. For example, if the security processor 230 detects an input corresponding to the permission button 810 within a reference time interval, the security processor may determine that the security processor has detected a permission input corresponding to the update information related to firmware. For example, if an input corresponding to the permission button is not detected during the reference time interval, or an input corresponding to the cancel button 820 is detected, the security processor 230 may determine that a permission input corresponding to the update information related to firmware is not detected.

[0105] According to various embodiments, if a permission input corresponding to the update information related to firmware is detected (e.g., "Yes" related to operation 709), then in operation 711, an electronic device (e.g., the processor 120 or the security processor 230) may determine that the user authentication of the update information related to firmware is successful. According to an embodiment, if the security processor 230 successfully performs the user authentication of the update information related to firmware, the security processor may provide the main processor 220 with a firmware installation time point (or installation condition) configured based on the user input. For example, if the security processor 230 detects an input corresponding to the permission button 810 of the patch information 800 displayed in the display device, the security processor may control the display device (e.g., Figure 1 the display device 160) in to display a menu 830 for configuring the firmware installation time point, as Figure 8B shown. The security processor 230 may control the display device by using the main processor 220. For example, the menu 830 for configuring the firmware installation time point may include "Install Immediately" 832, "Install at Night" 834, and "Set Installation Time" 836. The security processor 230 may configure the firmware installation time point based on the selection input made by the user to the menu 830 for configuring the firmware installation time point.

[0106] According to various embodiments, if it is determined that the update information related to the firmware is invalid (e.g., "No" related to operation 701), it is determined that the firmware related to the update information cannot be installed in the electronic device (e.g., "No" related to operation 705), or if an approval input corresponding to the update information related to the firmware is not detected (e.g., "No" related to operation 709), then in operation 713, the electronic device (e.g., processor 120 or security processor 230) may determine that the user authentication of the update information related to the firmware has failed. According to an embodiment, if the security processor 230 fails in the user authentication of the update information related to the firmware, the security processor may provide authentication failure information to the main processor 220. The main processor 220 may control the display device (e.g., Figure 1 the display device 160 in

[0107] Figure 9 FIG. 900 is a flowchart illustrating a method for updating firmware based on authentication information in an electronic device according to various embodiments. Operations described below Figure 9 may be Figure 6 detailed sub-operations of operations 609 to 611 in Figure 7 The electronic device in Figure 1 may be the electronic device 101 of Figure 2 or the electronic device 200 of Figure 10A , Figure 10B and Figure 10C At least a part of the operations in Figure 9 will be described hereinafter with reference to Figure 10A FIG. shows a screen configuration including firmware download status information according to various embodiments. Figure 10B FIG. shows a screen configuration for determining whether to install firmware according to various embodiments. Figure 10C FIG. shows a screen configuration including firmware update restriction information according to various embodiments.

[0108] Referring to Figure 9 , according to various embodiments, in operation 901, the electronic device (e.g., Figure 1 the processor 120 in Figure 2The main processor 220) in can identify whether the usage environment of the electronic device satisfies the firmware installation condition. According to an embodiment, the main processor 220 can identify whether the firmware installation time point configured by the user (e.g., "night installation" or "installation at a specific time point") has arrived. According to another embodiment, if "install when accessing a wireless LAN (e.g., WIFI)" is configured as the firmware installation condition, when the electronic device 200 accesses the wireless LAN, the main processor 220 can download the firmware. When the download of the firmware is completed, the main processor 220 can determine that the firmware installation condition is satisfied. The main processor 220 can control at least one element (e.g., the sound output device 155, the display device 160, or the indicator) to output firmware download information to the outside so as to allow the user to identify the firmware download status. For example, as Figure 10A shown, the display device (e.g., the display device 160) can display the download status information 1000 of the firmware, such as "Downloading firmware". According to another embodiment, if "install immediately" is configured, the main processor 220 can identify whether the download of the firmware is completed. If the download of the firmware is completed, the main processor 220 can determine that the firmware installation condition is satisfied.

[0109] According to various embodiments, if the electronic device (e.g., the processor 120 or the security processor 230) does not satisfy the firmware installation condition (e.g., "no" related to operation 901), the electronic device can identify whether the firmware installation condition is satisfied.

[0110] According to various embodiments, if the electronic device (e.g., the processor 120 or the security processor 230) satisfies the firmware installation condition (e.g., "yes" related to operation 901), then in operation 903, the electronic device can identify the firmware to be installed (or updated) in the electronic device. According to an embodiment, if the main processor 220 satisfies the firmware installation condition, the main processor can transmit a request signal for installing (or updating) the firmware to the security processor 230. If the security processor 230 has received a request signal for installing (or updating) the firmware from the main processor 220, the security processor can identify the firmware downloaded by the main processor 220.

[0111] According to various embodiments, in operation 905, an electronic device (e.g., processor 120 or security processor 230) may identify whether authentication information stored in a secure memory is valid. According to an embodiment, the security processor 230 may determine whether the authentication information is valid based on the HMAC value of the authentication information stored in the secure memory 240 and the validity time interval of the authentication information. For example, the validity time interval of the authentication information may be determined based on at least one of the permitted time point information or the permitted expiration time point information of the authentication information included in the authentication information. According to another embodiment, the security processor 230 may determine whether the authentication information is valid based on the HMAC value of the authentication information stored in the secure memory 240 and the number of times the authentication information has been used. For example, if the number of times the authentication information stored in the secure memory 240 has been used is equal to or less than a reference number, the security processor 230 may determine that the authentication information stored in the secure memory 240 is valid. For example, the reference number may be configured at the time of issuance of the electronic device 200 or may be configured by a user.

[0112] According to various embodiments, if the electronic device (e.g., processor 120 or security processor 230) has determined that the authentication information stored in the secure memory 240 is valid (e.g., "yes" related to operation 905), then in operation 907, the electronic device may identify whether firmware authentication based on the authentication information is successful. According to an embodiment, the security processor 230 may compare the hash value corresponding to the firmware received from the main processor 220 with the hash value included in the authentication information stored in the secure memory. If the hash value corresponding to the firmware received from the main processor 220 is the same as the hash value included in the authentication information, the security processor 230 may determine that the firmware authentication is successful. Additionally, if the hash value of the firmware received from the main processor 220 and the hash value of the authentication information stored in the secure memory are the same as each other, and the version information of the firmware and the version information of the authentication information are also the same as each other, the security processor 230 may determine that the firmware authentication is successful.

[0113] According to various embodiments, if the electronic device (e.g., processor 120 or security processor 230) has successfully authenticated the firmware based on the authentication information (e.g., "yes" related to operation 907), then in operation 909, the electronic device may update the firmware of the electronic device to the firmware related to the authentication information. According to an embodiment, if the security processor 230 has successfully performed firmware authentication based on the authentication information, the security processor may transmit a request signal for confirming whether to install the firmware to the main processor 220. The main processor 220 may control a display device (e.g., Figure 1 the display device 160 in Figure 10BAs shown, a display device (e.g., the display device 160 in Figure 1 ) can display a message 1010 related to determining whether to install firmware. For example, if an input corresponding to the cancel button 1014 in the message 1010 shown in at least a part of the display device as shown in Figure 10B is detected, the security processor 230 can determine that the user does not want to install the firmware at the current time point. The security processor 230 can identify whether the usage environment of the electronic device satisfies the firmware installation conditions. For example, if an input corresponding to the confirmation button 1012 in the message 1010 shown in at least a part of the display device as shown in Figure 10B is detected, the security processor 230 can determine that the user wants to install the firmware at the current time point. Accordingly, the security processor 230 can update the firmware of the electronic device to the firmware related to the authentication information. For example, the security processor 230 can store the updated firmware of the electronic device 200 in the secure memory 240. As another example, the security processor 330 can store the updated firmware of the electronic device 300 in the non-secure memory 350 through the main processor 320. The updated firmware can be stored in the active area (e.g., the first area 352) of the non-secure memory 350 together with the signature of the security processor 330.

[0114] According to various embodiments, if the authentication information stored in the secure memory is invalid (e.g., "No" related to operation 905), or the firmware authentication based on the authentication information fails (e.g., "No" related to operation 907), then in operation 911, the electronic device (e.g., the processor 120 or the security processor 230) can perform user re-authentication of the firmware. According to an embodiment, if an external device (e.g., a server) that has transmitted the firmware is reliable, and the version of the firmware is later (higher) than the version of the firmware running in the electronic device 200, the security processor 230 can control the display device (e.g., the display device 160) through the main processor 220 so that the display device displays the patch information of the firmware.

[0115] According to various embodiments, in operation 913, the electronic device (e.g., the processor 120 or the security processor 230) can identify whether the user re-authentication of the firmware is successful. According to an embodiment, if the security processor 230 detects a user input corresponding to the patch information displayed in at least a part of the display device before a reference time interval has elapsed since the time point when the patch information is displayed on the display device, the security processor 230 can determine that the user re-authentication of the firmware is successful.

[0116] According to various embodiments, if the user re - authentication of the firmware is successful (e.g., "Yes" related to operation 913), then in operation 909, an electronic device (e.g., processor 120 or security processor 230) may update the firmware of the electronic device to the firmware for which the user re - authentication is successful.

[0117] According to various embodiments, if the user re - authentication of the firmware fails (e.g., "No" related to operation 913), then in operation 915, the electronic device (e.g., processor 120 or security processor 230) may output firmware update restriction information. According to an embodiment, if the security processor 230 fails in the user re - authentication of the firmware, the security processor may transmit the firmware update restriction information to the main processor 220. The main processor 220 may control at least one element (e.g., sound output device 155, display device 160, or indicator) to output the firmware update restriction information received from the security processor 230 to the outside. For example, as Figure 10C shown, the display device (e.g., display device 160) may display a warning message 1020 such as "Firmware cannot be updated".

[0118] According to various embodiments, an operation method of an electronic device (e.g., Figure 2 the electronic device 200 in Figure 2 may include: in a security integrated circuit (IC) (e.g., Figure 2 the security integrated circuit 210 in Figure 2 ) including a main processor (e.g., Figure 2 the main processor 220 in

[0119] operating in a general execution environment) and a security processor (e.g.,

[0120] the security processor 230 in

[0121] operating in a secure execution environment), performing user authentication by the security processor based on firmware update information received from a server through the main processor; if the user authentication is successful, generating authentication information corresponding to the firmware update information; storing the authentication information in at least a part of a secure memory (e.g., Figure 2 the secure memory 240 in ); if the corresponding firmware is installed, performing authentication of the firmware based on the authentication information stored in the secure memory; and if the firmware authentication is successful, installing the firmware.

[0119] According to various embodiments, the authentication information may be stored in at least a part of a secure memory included in the security integrated circuit.

[0120] According to various embodiments, if the secure memory is located outside the security integrated circuit, the authentication information may be encrypted with a security key related to the security processor, and the encrypted authentication information may be stored in at least a part of the secure memory.

[0121] According to various embodiments, the authentication information may include at least one of: version information included in the firmware update information, a hash included in the firmware update information, a hash-based message authentication code (HMAC) related to the security processor, a time related to the permission of the authentication information, or an expiration time of the permission of the authentication information.

[0122] According to various embodiments, performing user authentication may include: determining whether signature information of a server included in the firmware update information satisfies specified conditions; and if the signature information of the server satisfies the specified conditions, performing user authentication of the firmware update information.

[0123] According to various embodiments, performing user authentication may include: determining whether signature information of a server included in the firmware update information satisfies specified conditions; if the signature information of the server satisfies the specified conditions, comparing the version information included in the firmware update information with the version information of the firmware installed in the electronic device; and if the version included in the firmware update information is later than the version of the firmware installed in the electronic device, performing user authentication of the firmware update information.

[0124] According to various embodiments, performing authentication of a firmware may include: if installation conditions of the firmware are satisfied and a request signal is received from the main processor, performing authentication of the firmware based on the authentication information stored in the secure memory.

[0125] According to various embodiments, performing authentication of a firmware may include: determining whether the authentication information stored in the secure memory is valid; and if the authentication information is determined to be valid, performing authentication of the firmware based on the authentication information.

[0126] According to various embodiments, determining whether the authentication information is valid may include: determining whether the authentication information stored in the secure memory is valid based on at least one of an HMAC value, a validity time interval, or a number of uses of the authentication information.

[0127] According to various embodiments, the method may further include: if authentication of the firmware fails, performing user authentication of the firmware; and if the user authentication is successful, installing the firmware.

[0128] Although the present disclosure has been described with various embodiments, various changes and modifications may be inspired to those skilled in the art. The present disclosure is intended to cover such changes and modifications that fall within the scope of the appended claims.

Claims

1. An electronic device for updating firmware, comprising: a main processor operating in a general environment, a security processor operating in a secure execution environment, and a secure memory, wherein the security processor is configured to: receive firmware update information from a server through the main processor; determine whether signature information of the server included in the firmware update information meets specified conditions; based on the signature information of the server meeting the specified conditions, compare version information included in the firmware update information with version information of the firmware installed in the electronic device; in response to the version included in the firmware update information being later than the version of the firmware installed in the electronic device, perform user authentication for determining that the user permits firmware update; based on the successful user authentication, generate authentication information corresponding to the firmware update information; store at least a part of the authentication information in the secure memory; in response to a firmware installation condition being met, determine whether the authentication information stored in the secure memory is valid based on at least one of a validity time interval, a hash-based message authentication code (HMAC) value, or the number of uses of the authentication information; based on the authentication information being valid, perform authentication of the firmware based on the authentication information; and based on the successful authentication of the firmware, install the firmware.

2. The electronic device according to claim 1, wherein the authentication information includes at least one of the following: version information included in the firmware update information, a hash included in the firmware update information, an HMAC related to the security processor, a time related to the permission of the authentication information, or an expiration time of the permission of the authentication information.

3. The electronic device according to claim 1, wherein if the secure memory is external to a secure integrated circuit including the main processor and the security processor, the security processor is configured to: encrypt the authentication information with a security key related to the security processor; and store the encrypted authentication information in the at least a part of the secure memory.

4. The electronic device according to claim 1, wherein: based on the firmware installation condition being met, the main processor is configured to transmit a request signal for installing the firmware to the security processor; and based on receiving the request signal from the main processor, the security processor is configured to perform authentication of the firmware based on the authentication information stored in the secure memory.

5. The electronic device according to claim 1, wherein the security processor is configured to: based on the failure of the authentication of the firmware, perform user re-authentication for determining that the user permits firmware update; and based on the successful user re-authentication, install the firmware.

6. An operation method for updating firmware of an electronic device, comprising: in an electronic device including a main processor operating in a general environment and a security processor operating in a secure execution environment, performed by the security processor: receive firmware update information from a server through the main processor; Determine whether the signature information of the server included in the firmware update information meets the specified conditions; Based on the signature information of the server meeting the specified conditions, compare the version information included in the firmware update information with the version information of the firmware installed in the electronic device; In response to the version included in the firmware update information being later than the version of the firmware installed in the electronic device, perform user authentication for confirming user permission for firmware update; Based on the successful user authentication, generate authentication information corresponding to the firmware update information; Store the authentication information in at least a part of the secure memory; In response to the firmware installation conditions being met, determine whether the authentication information stored in the secure memory is valid based on at least one of the validity time interval, the hash-based message authentication code HMAC value, or the number of times the authentication information is used; Based on the authentication information being valid, perform authentication of the firmware based on the authentication information; And Based on the successful authentication of the firmware, install the firmware.

7. The operation method according to claim 6, wherein, performing authentication of the firmware includes: based on the firmware installation conditions being met, the main processor sends a request signal for updating the firmware to the secure processor, and after receiving the request signal, the secure processor performs authentication of the firmware based on the authentication information stored in the secure memory.

8. The operation method according to claim 6, further including: Based on the failure of the authentication of the firmware, perform user re-authentication for determining user permission for firmware update; And Based on the successful user re-authentication, install the firmware.

Citation Information

Patent Citations

  • Management of device firmware update effects as seen by a host

    CN106990977A

  • Methods and apparatus for user authentication and human intent verification in mobile devices

    CN107211026A