System and method for adjusting access to secure functions
Through the detector and control circuit in the integrated circuit, the host's access to security functions is adjusted using the restart flag and authorization status, and the problem of malicious operating systems bypassing authorized access to security applications is solved, and effective protection of security functions and reasonable management of access rights is achieved.
Patent Information
- Application Number
- CN202411369651.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-06
- Filing Date
- 2024-09-29
- Publication Date
- 2025-06-06
AI Technical Summary
In electronic devices, a malicious operating system (OS) can gain access to secure applications by bypassing the authorization state, resulting in unauthorized sensitive data extraction and operation.
An integrated circuit (IC) is designed, including a detector and a control circuit. The detector receives the host's reset alarm signal and generates a restart flag; the control circuit receives a request to access the security function, and combines the restart flag and authorization status to adjust the host's access to the security function.
Through the coordinated work of the detector and control circuit, the authorization status can be updated after the host restarts, restrict access to malware, ensure the security of security functions, and restore access after the authorization is successful.
Smart Images

Figure CN120105408A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates generally to electronic circuits and, more particularly, to a system and method for regulating access to security functions. Background Art
[0002] The electronic device includes a host and a security element. At each restart cycle of the device, the host authorizes the security application in the security element to establish trust with the security element. Therefore, at each restart cycle, the authorization status indicating the authorized execution of the security application is permanently stored in the security element. In the case where the security of the device is compromised due to an attack by a malicious operating system (OS), the malicious OS can obtain access to the security application because the authorization status associated with the previous restart cycle indicates that the security application is authorized. Therefore, unauthorized extraction of sensitive data and execution of unauthorized operations may occur within the security element. Summary of the invention
[0003] According to a first aspect of the present invention, there is provided an integrated circuit (IC), comprising:
[0004] A detector coupled to a host, wherein the detector is configured to:
[0005] receiving a reset alarm signal from the host;
[0006] detecting a restart state of the host based on a state of the reset alarm signal, wherein the state of the reset alarm signal switches during a reset operation of the host; and
[0007] generating a restart flag based on the restart status of the host; and
[0008] a control circuit coupled to the detector and the host, wherein the control circuit is configured to:
[0009] receiving, from the host, an access request to access a plurality of security functions of the IC;
[0010] Upon receiving the access request, determining a status of the reboot flag and an authorization status of the host; and
[0011] Access to the plurality of security functions by the host is adjusted based on the condition of the restart flag and the authorization status.
[0012] In one or more embodiments, the IC further comprises a secure memory coupled to the detector and the control circuit, wherein the secure memory is configured to:
[0013] storing the restart flag; and
[0014] The restart flag is provided to the control circuit based on the access request.
[0015] In one or more embodiments, the control circuit is further configured to:
[0016] generating a status request based on the access request received from the host; and
[0017] The status request is sent to the detector, wherein the control circuit receives the restart flag from the secure memory based on the sending of the status request to the detector.
[0018] In one or more embodiments, when the control circuit determines that the authorization status is associated with a successful authorization between the control circuit and the host before the reset operation of the host and the condition of the restart flag indicates the reset operation of the host, the control circuit is further configured to update the authorization status to indicate that there is no authorization between the control circuit and the host after the reset operation of the host, and
[0019] Wherein when the authorization status is updated to indicate the absence of the authorization, the control circuit is further configured to restrict the host's access to the plurality of security functions, thereby regulating the access rights of the host.
[0020] In one or more embodiments, the authorization between the host and the control circuit is initiated by the host when the control circuit restricts the host's access to the plurality of security functions.
[0021] In one or more embodiments, when the authorization between the control circuit and the host is successful based on the initiation of the authorization after the reset operation of the host, the control circuit is further configured to update the authorization status to indicate the successful authorization between the control circuit and the host after the reset operation of the host, and
[0022] Wherein when the authorization status indicates the successful authorization after the reset operation, the control circuit is further configured to grant access to the plurality of security functions to the host, thereby regulating the access rights of the host.
[0023] In one or more embodiments, when the authorization between the control circuit and the host fails at the initiation of the authorization after the reset operation of the host, the control circuit limits the access rights of the host to the plurality of security functions.
[0024] In one or more embodiments, the secure memory is further configured to store a plurality of security applications, and wherein each of the plurality of security applications is associated with at least one of the plurality of security functions.
[0025] In one or more embodiments, the plurality of security functions is one of the group consisting of: device authorization, payment processing, identity verification, secure messaging, cryptographic operations, access control, digital signatures, and tokenization.
[0026] In one or more embodiments, the authorization state is associated with authorization between the host and the control circuit, and wherein the authorization indicates at least one of the group consisting of: trusted binding, multi-factor authorization, token-based authorization, credential-based authorization, blockchain-based authorization, and behavior-based authorization.
[0027] In one or more embodiments, the reset alert signal includes at least one of a secure general purpose input / output (GPIO) signal and a pad power signal.
[0028] In one or more embodiments, the state of the pad power signal during the reset operation is one of: (i) an asserted state when the host remains on; and (ii) a de-asserted state when the host remains off, and wherein the detector is further configured to generate the restart flag based on the de-assertion of the pad power signal.
[0029] In one or more embodiments, the state of the secure GPIO signal is an asserted state during the reset operation, and wherein the detector is further configured to generate the restart flag based on the assertion of the secure GPIO signal.
[0030] In one or more embodiments, the detector is further configured to transition from a low power mode to a normal mode upon receiving the reset alarm signal, wherein during the normal mode, the detector generates the restart flag indicating the restart state of the host, and wherein during the low power mode, the detector is further configured to operate in a low energy consumption state.
[0031] According to a second aspect of the present invention, there is provided an access right adjustment method, comprising:
[0032] receiving a reset alarm signal from a host by a detector of an integrated circuit (IC);
[0033] detecting, by the detector, a restart state of the host based on the reset alarm signal, wherein a state of the reset alarm signal switches during a reset operation of the host;
[0034] generating, by the detector, a restart flag based on the restart status of the host;
[0035] receiving, by a control circuit of the IC, from the host, an access request to access a plurality of security functions of the IC;
[0036] Upon receiving the access request, the control circuit determines the status of the restart flag and the authorization status between the host and the control circuit; and
[0037] Access to the plurality of security functions by the host is adjusted by the control circuit based on the condition of the restart flag and the authorization status.
[0038] In one or more embodiments, the access rights adjustment method further includes:
[0039] storing the restart flag in a secure memory of the IC; and
[0040] The restart flag is provided to the control circuit by the secure memory based on the access request.
[0041] In one or more embodiments, the access rights adjustment method further includes:
[0042] generating, by the control circuitry, a status request indicating detection of the reboot state of the host based on the access request received from the host; and
[0043] The status request is sent by the control circuit to the detector, wherein the restart flag is received by the control circuit from the secure memory based on the sending of the status request to the detector.
[0044] In one or more embodiments, the access rights adjustment method further includes:
[0045] Upon determining that the authorization status indicates successful authorization between the control circuit and the host before the reset operation of the host and the condition of the restart flag indicates the reset operation of the host, updating, by the control circuit, the authorization status to indicate that there is no authorization between the control circuit and the host after the reset operation of the host; and
[0046] The access rights of the host are regulated by limiting the host's access rights to the plurality of security functions by the control circuit when the authorization status is updated to indicate that the authorization between the control circuit and the host does not exist after the reset operation of the host.
[0047] In one or more embodiments, when the access rights of the host to the plurality of security functions are restricted, the authorization between the host and the control circuit is initiated after the reset operation of the host.
[0048] In one or more embodiments, the access rights adjustment method further includes:
[0049] When the authorization between the control circuit and the host is successful after the reset operation of the host, updating the authorization status by the control circuit to indicate successful authorization between the control circuit and the host after the reset operation of the host; and
[0050] The access rights of the host are regulated by granting, by the control circuit, the access rights to the plurality of security functions to the host when the authorization status indicates the successful authorization after the reset operation.
[0051] These and other aspects of the invention will be apparent from and elucidated with reference to the embodiments described hereinafter. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The following detailed description of embodiments of the present disclosure will be better understood when read in conjunction with the accompanying drawings.The present disclosure is illustrated by way of example and not limited by the accompanying drawings, in which like numerals indicate similar elements.
[0053] Figure 1 is a schematic block diagram of an electronic device including an integrated circuit (IC) according to an embodiment of the present disclosure;
[0054] Figure 2A-2B The storage in the embodiment according to the present disclosure is shown Figure 1 A restart database in the secure memory of the IC;
[0055] Figure 3 The storage in the embodiment according to the present disclosure is shown Figure 1 An authorization database in the secure memory of the IC;
[0056] Figure 4 The embodiment according to the present disclosure is shown Figure 1 Host pair Figure 1 A process flow chart of regulating access rights to multiple security functions of an IC; and
[0057] Figures 5A-5C The embodiment of the present disclosure is shown together to adjust the Figure 1 A flow chart of an access right adjustment method for access rights of a security function of an IC. DETAILED DESCRIPTION
[0058] The detailed description of the accompanying drawings is intended as a description of the embodiments of the present disclosure, and is not intended to represent the only form in which the present disclosure can be implemented. It should be understood that the same or equivalent functions can be implemented by different embodiments intended to be included in the spirit and scope of the present disclosure.
[0059] Summary:
[0060] In electronic devices, authorization between a host and a security element is a basic security mechanism implemented to protect multiple security functions and sensitive data of the security element. Authorization can protect security functions from unauthorized access, thereby reducing potential security vulnerabilities. The security element stores the authorization status of the host, which is based on the authorization between the host and the security element. Therefore, the security of the electronic device depends on the authorization between the host and the security element. However, the authorization may be bypassed by malware in the host or by any other means. This may lead to unauthorized access to multiple security functions and sensitive data because in conventional devices, the pre-existing authorization status remains unchanged.
[0061] Various embodiments of the present disclosure disclose an integrated circuit (IC). The IC may include a detector, a secure memory, and a control circuit. The detector may be coupled to a host and a secure memory. In addition, the detector may be configured to receive a reset alarm signal from the host. Based on the state of the reset alarm signal, the detector may be further configured to detect the restart state of the host. The detector may be further configured to generate a restart flag indicating the restart state of the host. The secure memory may be configured to store the restart flag. The control circuit may be coupled to the host, the secure memory, and the detector. The control circuit may be configured to receive an access request from the host to access multiple security functions of the IC. The control circuit may be further configured to determine the status of the restart flag based on receiving the access request. The status of the restart flag may indicate one of the following: (i) when the restart flag is set (e.g., the restart flag is set to one), a reset operation of the processor; and (ii) when the restart flag is reset (e.g., the restart flag is set to zero), the normal operation of the processor. In addition, the control circuit may be further configured to determine the authorization status of the host indicating the authorization between the control circuit and the host. Based on the status of the restart flag and the authorization state, the control circuitry may additionally be configured to adjust the host's access to a plurality of security functions.
[0062] The detector and control circuit add an extra security layer to the electronic device. The detector can detect the restart state of the processor based on the state of the reset alarm signal. In the case of an attack by malware that obtains control of the host, the control circuit limits the access rights of such software based on determining that there is no authorization or authorization failure after the reset operation of the host. Therefore, the malware cannot access the security functions of the device, and the security of the electronic device remains intact. For the host's genuine application that attempts to obtain access to multiple security applications, the authorization between the control circuit and the host is used as a decisive factor in granting access to multiple security applications to the host after the reset operation of the host. When the authorization between the host and the control circuit is successful after the reset operation of the host, the control circuit can grant access to at least one of the multiple host applications to multiple security applications. Similarly, for each remote Internet of Things (IoT) device that can control security operations, such a device can be remotely authorized after each reset operation to ensure that the security of the basic security operation remains intact.
[0063] Figure 1 1 is a schematic block diagram of an electronic device 100 according to an embodiment of the present disclosure. Examples of the electronic device 100 may include a mobile phone, a smart watch, a personal computer, a smart wearable device, an Internet of Things (IoT) device, an automotive system, etc. The electronic device 100 may include a host 102 and an integrated circuit (IC) 104. The IC 104 may be a security element and is referred to as "security element 104" hereinafter.
[0064] Host 102:
[0065] The host 102 may correspond to the main computer of the electronic device 100. The host 102 may be configured to execute a plurality of host applications H1-Hm. Examples of the plurality of host applications H1-Hm may include wallet applications, browser applications, media players, game applications, social media applications, content management applications, document management applications, and the like. In addition, the host 102 may be configured to undergo one of (i) normal operation and (ii) reset operations. The normal operation of the host 102 may indicate that the host 102 performs various functions. Examples of various functions may include, but are not limited to, application execution, data processing, data storage, system maintenance, payment processing, and the like. The reset operation may indicate a restart of the host 102 (e.g., the host 102 is turned off and reopened). In addition, a reset operation may be initiated to configure software updates in the electronic device 100, update firmware of the electronic device 100, system maintenance of the electronic device 100, and the like.
[0066] The host 102 may include a processor 106 and a host memory 108. The processor 106 may include suitable logic, circuit systems and / or interfaces that may be configured to perform one or more operations. For example, the processor 106 may be configured to initiate (i) one of the normal operation of the host 102 and (ii) a reset operation of the host 102, execute multiple host applications H1-Hm, and initiate authorization between the host 102 and the security element 104 at the reset operation of the host 102. In an embodiment, the multiple host applications H1-Hm may be configured to generate access requests AR with the aid of the processor 106 to access the security functions of the IC 104, as explained in the ongoing disclosure. The access request AR may be generated in response to a user request to the host 102 received from an external circuit system, or generated by the host 102, and is related to a security policy, an application software programming interface (API) call, an external event, a time-based policy, etc. The processor 106 may be a central processing unit (CPU), a graphics processing unit (GPU), a microcontroller, an application-specific integrated circuit (ASIC), etc.
[0067] The processor 106 may be configured to generate a reset alarm signal RS such that a state of the reset alarm signal RS switches during a reset operation. For example, the reset alarm signal RS may switch from an asserted state (e.g., a logic high state) to a de-asserted state (e.g., a logic low state) to indicate a reset operation. Alternatively, the reset alarm signal RS may switch from an asserted state to a de-asserted state to indicate a reset operation. In addition, the reset alarm signal RS may include at least one of a secure general purpose input / output (GPIO) signal SGS and a pad power supply signal PSS.
[0068] Reset alarm signal RS = pad power signal PSS
[0069] The pad power signal PSS may indicate an operating state (e.g., an on state and an off state) of the processor 106. In an embodiment, the pad power signal PSS is asserted when the processor 106 is turned on (e.g., during normal operation of the host 102). Alternatively, the pad power signal PSS is de-asserted when the processor 106 is turned off during a reset operation of the host 102. In other words, when the host 102 undergoes a reset operation, the state of the reset alarm signal (e.g., the pad power signal PSS) switches from an asserted state to a de-asserted state. In an embodiment, the pad power signal PSS may be de-asserted to close a communication interface (not shown) between the host 102 (e.g., the processor 106) and the security element 104. Examples of communication interfaces may include a serial peripheral interface (SPI), an interconnect integrated circuit (I2C), a universal asynchronous receiver / transmitter (UART), a universal serial bus (USB), and the like.
[0070] Reset alarm signal RS = safety GPIO signal SGS
[0071] During the reset operation, when the processor 106 transitions from the off state to the on state (e.g., turned on), the processor 106 may be configured to execute built-in software (not shown) stored in the host memory 108. Examples of built-in software may include a basic input / output system (BIOS), a boot loader, a unified extensible firmware interface (UEFI) firmware, a power-on self-test (POST), a device driver, etc. The processor 106 may additionally include a plurality of secure GPIO pins (not shown) configured to generate a secure GPIO signal SGS when executing the built-in software. The built-in software may be designed to have an anti-tampering feature to prevent interference from any malicious software. In an embodiment, the processor 106 may be configured to assert the secure GPIO signal SGS via at least one of the plurality of secure GPIO pins, so that when the processor 106 is turned on to execute the built-in software, the state of the secure GPIO signal SGS switches. In addition, the state of the secure GPIO signal SGS may be switched so that the secure GPIO signal SGS may be deasserted after the built-in software is executed. In other words, during the reset operation, the processor 106 is turned on to execute the built-in software, and thus, the state of the reset alert signal (eg, the safety GPIO signal SGS) is switched from the de-asserted state to the asserted state.
[0072] The host memory 108 may be coupled to the processor 106. The host memory 108 may include suitable logic, circuit systems and / or interfaces that may be configured to perform one or more operations. For example, the host memory 108 may be configured to store a plurality of host applications H1-Hm. Examples of the host memory 108 may include a hard disk drive (HDD), a solid state drive (SSD), an external hard disk, etc.
[0073] Security element 104:
[0074] The security element 104 may be a secure hardware for various applications, such as secure storage, digital identification, user authentication, secure messaging, payment authentication, etc. The security element 104 may be coupled to the host 102. In addition, the security element 104 may be configured to receive a reset alarm signal RS from the host 102 (e.g., the processor 106). The security element 104 may be configured to determine whether the host 102 has undergone a reset operation based on the state of the reset alarm signal RS, so that the state of the reset alarm signal RS is switched during the reset operation of the host 102. Based on determining that the host 102 has undergone a reset operation, the security element 104 may be additionally configured to adjust the host 102's access to multiple security functions of the security element 104. During the restart of the security element 104, firmware may be updated in the security element 104, irregular behavior of the security element 104 may be corrected, or security policy changes may be implemented on the security element 104. In an embodiment, the security element 104 may be configured to restart during the reset operation of the host 102. In another embodiment, the secure element 104 may reboot independently of the host 102 based on a user requested reset or a request generated within the electronic device 100 .
[0075] The security element 104 may be further configured to receive a stable and consistent power supply PS to ensure standard operation of the security element 104 during the reset operation. In an embodiment, the processor 106 provides the power supply PS. In another embodiment, the security element 104 may be configured to receive the power supply PS from an external source (not shown) so that the processor 106 and the security element 104 operate based on independent power supplies. Examples of the power supply PS may include a battery power supply, a USB power supply, a wireless power supply, etc.
[0076] Secure element 104 may include detector 110 , secure memory 112 , and control circuitry 118 .
[0077] Detector 110:
[0078] The detector 110 may be coupled to the processor 106. The detector 110 may include suitable logic, circuitry, and / or interfaces that may be configured to perform one or more operations. For example, the detector 110 may be configured to receive a reset alarm signal RS from the processor 106. Based on the state (e.g., restart state) of the reset alarm signal RS, the detector 110 may be further configured to detect the restart state of the processor 106 (e.g., the host 102) and determine whether the host 102 has undergone a reset operation. In an embodiment, the state of the pad power supply signal PSS may be one of the following during the reset operation: (i) when the host 102 remains on, it is an asserted state; and (ii) when the host 102 remains off, it is a de-asserted state. Therefore, the detector 110 may detect that the restart state of the pad power supply signal PSS is a de-asserted state, thereby determining that the host 102 has undergone a reset operation. In another embodiment, the detector 110 may be configured to receive a secure GPIO signal SGS. Based on the assertion of the secure GPIO signal SGS, the detector 110 may detect the restart state of the host 102 and determine that the host 102 has undergone a reset operation. In yet another embodiment, the detector 110 may be configured to receive the pad power signal PSS and the secure GPIO signal SGS. Based on the assertion of the secure GPIO signal SGS and the deassertion of the pad power signal PSS, the detector 110 may detect the restart state of the host 102. The restart state of the processor 106 may be detected based on the pad power signal PSS and the secure GPIO signal SGS to further improve the reliability and fault tolerance of the detector 110.
[0079] The detector 110 may be configured to generate a restart flag RFL based on a restart state of the host 102. In an embodiment, when the detector 110 determines that the host 102 has undergone a reset operation based on the detected restart state, the state of the restart flag RFL may be set (e.g., the restart flag RFL is set to one). The secure memory 112 may be configured to store the restart flag RFL. The detector 110 may generate the restart flag RFL based on at least one of the de-assertion of the pad power supply signal PSS and the assertion of the secure GPIO signal SGS.
[0080] The detector 110 may be further configured to transition from the low power mode to the normal mode when the state of the reset alarm signal RS switches (e.g., the reset alarm signal RS may switch from the asserted state to the deasserted state to indicate a reset operation). During the normal mode, the detector 110 may generate a restart flag RFL indicating a restart state of the host 102. The detector 110 may be configured to actively monitor and detect the reset alarm signal RS.
[0081] During the low power mode, the detector 110 may be additionally configured to operate in a low energy state, so that the efficiency of the detector 110 is improved and the battery life associated with the electronic device 100 can be extended. In an embodiment, the detector 110 may be configured to operate with reduced power and processing power in a low energy state, so that the reset alarm signal RS can be monitored at a reduced frequency. In another embodiment, the safety element 104 may include an interrupt circuit (not shown) that can be coupled to the processor 106. In addition, the detector 110 may be configured to remain in a sleep state during the low power mode. In addition, the interrupt circuit may be configured to receive the reset alarm signal RS, and generate an interrupt signal (not shown) when the state of the reset alarm signal RS is switched. The interrupt circuit may be additionally configured to send an interrupt signal to the detector 110. When the interrupt signal is received, the detector 110 may be additionally configured to transition from the low power mode to the normal mode.
[0082] Secure Memory 112:
[0083] The secure memory 112 may be coupled to the detector 110. The secure memory 112 may include a restart database 114, a security database 115, and an authorization database 116. The secure memory 112 may include suitable logic, circuit systems, and / or interfaces that may be configured to perform one or more operations. For example, when the security element 104 is restarted, the secure memory 112 may persist data (e.g., a restart flag RFL associated with each of a plurality of host applications H1-Hm) to ensure data integrity. The secure memory 112 may be a non-volatile memory or a storage-level memory. Examples of the secure memory 112 may include flash memory, a solid-state drive (SSD), a non-volatile random access memory (NVRAM), a magnetoresistive random access memory (MRAM), a phase change memory (PCM), a battery-backed static random access memory (SRAM), a resistive random access memory (ReRAM), and the like.
[0084] The secure memory 112 may set a restart flag RFL (described later in Figure 2A-2B ) is stored in the restart database 114, because each of the plurality of security functions associated with at least one of the plurality of security applications S1-Sn may be called at different times. Examples of the restart database 114 may include a relational database, an extensible markup language (XML) database, an in-memory database, a blockchain database, etc.
[0085] The secure memory 112 may be further configured to store multiple security applications S1-Sn in a secure database 115. In one embodiment, the installation of multiple security applications S1-Sn in the secure memory 112 may be initiated by the processor 106. Examples of the secure database 115 may include a library database, a software repository, an application library, etc. Examples of multiple security applications S1-Sn may include authentication applications, payment applications, password management applications, IoT applications, etc. Multiple security applications S1-Sn may be associated with at least one of multiple security functions. In an example, the first security application S1 may be associated with one or more of the multiple security functions. Multiple security functions may be associated with specific tasks or operations performed on the security element 104. Examples of multiple security functions may include device authorization, payment processing, identity authentication, secure messaging, cryptographic operations, access control, digital signatures, tokenization, etc.
[0086] The secure memory 112 may be additionally configured to store a plurality of general-purpose applications (not shown) in the secure database 115. Examples of a plurality of general-purpose applications may include messaging applications, device management applications, cloud storage applications, health and fitness applications, etc. A plurality of general-purpose applications may be associated with at least one of a plurality of general-purpose functions. In an example, a first general-purpose application may be associated with one or more of a plurality of general-purpose functions. A plurality of security functions may be associated with a specific task or operation performed on the secure element 104 and may not be associated with sensitive data. In an embodiment, a plurality of general-purpose applications may be stored outside the secure memory 112. Examples of a plurality of general-purpose functions may include device information, error logging, device updates, power management, timing, etc.
[0087] Each of the plurality of security applications S1-Sn may be linked to at least one of the plurality of host applications H1-Hm. In one scenario, the first host application H1 is a wallet application stored in the host memory 108. Thus, the secure memory 112 may include a first plurality of security applications that may be linked to the wallet application. Additionally, a plurality of security functions may be associated with the first plurality of security applications. In an example, when a credit card payment is initiated in a wallet application (e.g., the first host application H1), a security function associated with at least one of the first plurality of security applications (e.g., the first security function) may be accessed via the processor 106 to complete the payment. Alternatively, when a debit card payment is initiated in a wallet application (e.g., the first host application H1), a security function associated with at least one of the first plurality of security applications (e.g., the second security function) may be accessed via the processor 106 to successfully complete the payment.
[0088] The secure memory 112 may further be configured to store an authorization state AS associated with each of the plurality of host applications H1-Hm (described later in Figure 2A-2B 106) is persistently stored in the authorization database 116. The authorization status AS may indicate the authorization between the control circuit 118 and the processor 106.
[0089] Control circuit 118:
[0090] The control circuit 118 may be coupled to the processor 106. The control circuit 118 may be further coupled to the detector 110 and the secure memory 112. The processor 106 may be configured to send an access request AR to the control circuit 118. The control circuit 118 may include suitable logic, circuit systems and / or interfaces that may be configured to perform one or more operations. For example, the control circuit 118 may be configured to receive the access request AR from the processor 106. The control circuit 118 may be further configured to generate a status request SR based on the received access request AR. The status request SR may be generated in response to the access request AR received from the processor 106. In an embodiment, the status request SR may indicate a request to receive a restart flag RFL associated with at least one of the multiple host applications H1-Hm. In addition, the control circuit 118 may be configured to send the status request SR to the detector 110. Based on the status request SR, the secure memory 112 may be further configured to provide the control circuit 118 with a restart flag RFL associated with at least one of the multiple host applications H1-Hm. The restart flag RFL associated with at least one of the plurality of host applications H1 -Hm may be reset by the secure memory 112 when the control circuit 118 retrieves the associated restart flag RFL.
[0091] In another embodiment, the control circuit 118 may receive an access request AR to access at least one of the plurality of security functions from at least one of the plurality of host applications H1-Hm during a reset operation of the host 102. Therefore, the control circuit 118 may generate a status request SR based on the received access request AR, and send the status request SR to the detector 110. Upon receiving the status request SR, the detector 110 may detect a restart state of the host 102 when the state of the reset alarm signal RS is switched. In addition, the detector 110 may be configured to provide a restart flag RFL to the control circuit 118 when the restart state indicates that the host 102 has undergone a reset operation. Therefore, the control circuit 118 may determine the state of the restart flag RFL based on receiving the access request AR.
[0092] The control circuit 118 may determine the authorization status AS of the host 102 (e.g., each of the plurality of host applications H1-Hm) and store the authorization status AS in the authorization database 116. Examples of the control circuit 118 may include a microprocessor, control logic, a central processing unit (CPU), etc. In an embodiment, the authorization status AS may be associated with the authorization between the control circuit 118 and the processor 106 (e.g., the host 102). In one embodiment, the host 102 may be configured to initiate authorization after the reset operation is completed and when the access request AR is generated. In another embodiment, the host 102 may be configured to initiate authorization during the reset operation. An example of authorization may be at least one of the following groups: trusted binding, multi-factor authorization, token-based authorization, credential-based authorization, blockchain-based authorization, behavior-based authorization, etc. The authorization status AS may be one of the following: (i) a first state indicating that there is no authorization or an authorization failure between the control circuit 118 and the processor 106 after the reset operation; and (ii) a second state indicating successful authorization between the control circuit 118 and the processor 106 after the reset operation.
[0093] The control circuit 118 may be further configured to regulate access rights of the host 102 (eg, at least one of the plurality of host applications H1 -Hm) to at least one of the plurality of security functions based on the status of the restart flag RFL and the authorization status AS.
[0094] To restrict access after a reset operation:
[0095] In one scenario, the host 102 initiates authorization, and the authorization status AS indicates a successful authorization. A reset operation of the host 102 occurs thereafter. At least one of the plurality of host applications H1-Hm generates an access request AR after the reset operation. Therefore, the control circuit 118 may determine the status of the restart flag RFL based on receiving the access request AR. When the restart flag RFL is set (e.g., the restart flag RFL is set to one), the status of the restart flag RFL may indicate a reset operation of the host 102.
[0096] The control circuit 118 may determine that the authorization state AS indicates a successful authorization between the control circuit 118 and the processor 106 (e.g., the host 102) before the reset operation of the host 102 occurs, and the status of the restart flag RFL indicates the reset operation of the host 102. Therefore, the control circuit 118 may determine that there is no authorization between the control circuit 118 and the processor 106 (e.g., the host 102) after the reset operation of the host 102 occurs. Therefore, the control circuit 118 may update the authorization state AS to a first state so that the first state indicates that there is no authorization after the reset operation of the host 102. In addition, the control circuit 118 may limit the access rights of at least one of the multiple host applications H1-Hm to at least one of the multiple security functions to prevent any unauthorized access. In an embodiment, the control circuit 118 may be further configured to send a lock signal (not shown) to the processor 106 so that based on the lock signal, the processor 106 can detect that the access rights to the multiple security functions are restricted. In an embodiment, the authorization state AS may include a first timestamp (not shown). The first timestamp may indicate the time of the authorization between the control circuit 118 and the processor 106. In addition, the restart flag RFL may include a second timestamp (not shown). The second timestamp may indicate the time of the reset operation of the host 102. In addition, based on the first timestamp and the second timestamp, the control circuit 118 may be configured to determine the time of authorization. In an example, when the first timestamp of the authorization state AS is earlier than the second timestamp of the received restart flag RFL, the control circuit 118 may determine that the authorization state AS corresponds to the authorization between the host 102 and the control circuit 118 before the reset operation occurs in the aforementioned scenario. Therefore, the authorization state AS may indicate a successful authorization between the control circuit 118 and the processor 106 before the reset operation. In addition, the control circuit 118 may update the authorization state AS to the first state and restrict the host 102 from accessing multiple security functions.
[0097] To grant access after restricting it during a reset operation:
[0098] When the control circuit 118 restricts the access rights of at least one of the multiple host applications H1-Hm to at least one of the multiple security functions, the host 102 may be further configured to initiate authorization with the control circuit 118. In addition, when the authorization between the control circuit 118 and the processor 106 is successful after the reset operation of the host 102, the control circuit 118 may be further configured to update the authorization state AS to a second state. In addition, based on the authorization state AS being the second state, the control circuit 118 may be further configured to grant access rights to multiple security functions and multiple general functions to at least one of the multiple host applications H1-Hm. In the above example, when the authorization is successful, the updated time of the first timestamp is later than the time of the second timestamp. In addition, the authorization state AS is updated to the second state. Therefore, the control circuit 118 grants the host 102 access rights to multiple security functions.
[0099] To restrict access after an authorization failure during a reset operation:
[0100] In another scenario, authorization between the host 102 and the control circuit 118 after the reset operation fails. Authorization may fail due to incorrect credentials, communication protocol mismatch, clock synchronization problems, memory corruption, etc. Therefore, the control circuit 118 can determine the failure of authorization between the control circuit 118 and the processor 106 after the reset operation of the host 102 occurs. Therefore, the control circuit 118 can update the authorization state AS to a first state, so that the first state indicates the failure of authorization after the reset operation of the host 102. In addition, the control circuit 118 can limit the access rights of at least one of the multiple host applications H1-Hm to at least one of the multiple security functions to prevent any unauthorized access. When the authorization between the control circuit 118 and the processor 106 fails, additional troubleshooting steps may be required. Examples of additional troubleshooting steps may include software updates, factory resets, service center repairs, etc. Alternatively, once the authorization fails, the processor 106 can re-initiate the authorization.
[0101] In another scenario, when the status of the restart flag RFL indicates normal operation of the host 102 (for example, the status of the restart flag RFL is reset), the control circuit 118 can be further configured to maintain the authorization state AS based on the authorization. In an example, when the authorization is successful, the authorization state AS is updated to the second state. In another example, when the authorization fails, the authorization state AS is updated to the first state. In addition, the control circuit 118 can adjust the access rights of multiple host applications H1-Hm to at least one of the multiple security functions and the multiple general functions based on the authorization state AS.
[0102] In operation:
[0103] The processor 106 may initiate the installation of one of the plurality of security applications S1-Sn (e.g., the first security application S1) in the secure memory 112. The first security application S1 may be a small program of at least one of the plurality of host applications H1-Hm. For example, when the first host application H1 is a wallet application stored in the host memory 108, the first plurality of small programs may be linked to the wallet application so that when a payment is initiated in the wallet application, at least one of the first plurality of small programs may be accessed via the processor 106 to complete the payment. In an embodiment, the first security application S1 may include a cryptographic credential (e.g., a digital signature, a digital credential, etc.). The cryptographic credential may be used to ensure the authenticity and integrity of the first security application S1. The processor 106 may be further configured to establish a secure channel (not shown) with the detector 110. A secure channel may be established to protect the cryptographic credential. The detector 110 may be configured to authorize the installation of the first security application S1 by verifying the digital signature or the digital credential. The control circuit 118 may install the first security application S1 in the secure memory 112.
[0104] The control circuit 118 may be configured to determine a status of a restart flag RFL associated with at least one of the plurality of host applications H1-Hm stored in the host memory 108 of the host 102 based on the installation of the first security application S1. The control circuit 118 may be further configured to determine the successful installation of the first security application S1. In addition, the control circuit 118 may be configured to send a confirmation signal (not shown) to the processor 106. Based on the confirmation signal, the processor 106 may be notified of the successful installation of the first security application S1.
[0105] The host 102 may undergo a reset operation. The detector 110 may receive a reset alarm signal RS (e.g., a pad power supply signal PSS or a secure GPIO signal SGS) from the processor 106. In addition, the detector 110 may detect a restart state of the processor 106 when the state of the reset alarm signal RS switches, and determine that the host 102 has undergone a reset operation. In addition, the detector 110 may set a restart flag RFL indicating the restart state of the processor 106, and store the restart flag RFL in the secure memory 112.
[0106] At least one of the plurality of host applications H1-Hm may generate an access request AR for accessing at least one of the plurality of security functions associated with the first security application S1 by means of the processor 106. The processor 106 may send the access request AR to the control circuit 118. The control circuit 118 may generate a status request SR based on the received access request AR. In addition, the control circuit 118 may send the status request SR to the detector 110.
[0107] The secure memory 112 may provide an authorization status AS from the secure memory 112 based on the status request SR. In addition, the control circuit 118 may determine that the authorization status AS indicates authorization before the reset operation, and the authorization status AS of each of the plurality of host applications H1-Hm indicates successful authorization before the reset operation. Based on the status request SR, the secure memory 112 may provide a restart flag RFL associated with at least one of the plurality of host applications H1-Hm to the control circuit 118. Based on the restart flag RFL, the control circuit 118 may determine that the processor 106 has undergone a reset operation. In addition, once the control circuit 118 retrieves the restart flag RFL associated with at least one of the plurality of host applications H1-Hm, the restart flag RFL may be reset by the secure memory 112.
[0108] After the host 102 undergoes a reset operation, the control circuit 118 may update the authorization state AS associated with at least one of the multiple host applications H1-Hm to a first state to indicate that there is no authorization. In addition, the control circuit 118 may limit the access rights of at least one of the multiple host applications H1-Hm to at least one of the multiple security functions associated with the first security application S1. The processor 106 may initiate authorization with the control circuit 118. When the authorization between the control circuit 118 and the processor 106 is successful, the control circuit 118 may update the authorization state AS to a second state. In addition, based on the authorization state AS being the second state, the control circuit 118 may grant access rights to multiple security functions and multiple general functions to at least one of the multiple host applications H1-Hm. When the authorization between the control circuit 118 and the processor 106 fails, the control circuit 118 may update the authorization state AS to a first state. In addition, based on the authorization state AS being the first state, the control circuit 118 may limit the access rights of multiple host applications H1-Hm to multiple security functions.
[0109] Figure 2A-2B A restart database 114 stored in secure memory 112 is shown according to an embodiment of the present disclosure.
[0110] Reference now Figure 2A, the restart database 114 includes a column 200. Column 200 may correspond to a plurality of reference addresses 202-210 of the restart database 114. Each of the plurality of reference addresses 202-210 may be associated with the storage of a restart flag RFL corresponding to a host application in a plurality of host applications H1-Hm. The plurality of host applications may include a first host application H1, a second host application H2, ..., and an Mth host application Hm. In the example, before generating an access request AR corresponding to the first host application H1, the first reference address 202 of the plurality of reference addresses 202-210 may store a restart flag RFL associated with the first host application H1 (e.g., the restart flag RFL is set to '1'). Similarly, the restart flag RFL of each of the second host application H2 and the Mth host application Hm may be set to '1'. Examples of the restart database 114 may include a relational database, an extensible markup language (XML) database, an in-memory database, a blockchain database, and the like.
[0111] Reference now Figure 2B , column 200 corresponds to a restart flag RFL indicating a restart state of the processor 106. In an exemplary embodiment, the Mth host application Hm may be configured to generate an access request AR to access at least one of a plurality of secure applications S1-Sn stored in the secure memory 112. In addition, the processor 106 may send an access request AR to the control circuit 118. The control circuit 118 may receive the access request AR from the processor 106. The control circuit 118 may generate a status request SR based on the received access request AR. In addition, the control circuit 118 may be configured to send the status request SR to the detector 110. Based on the status request SR, the secure memory 112 may provide a restart flag RFL associated with the Mth host application Hm. In addition, once the control circuit 118 retrieves the restart flag RFL associated with the Mth host application Hm, the secure memory 112 may reset the restart flag RFL (e.g., the restart flag RFL is set to "0"). In addition, the restart flag RFL associated with each of the second host application H2 and the first host application H1 continues to remain at '1'.
[0112] although Figure 2B It is described that the Mth host application Hm generates an access request AR for accessing at least one of the multiple security applications S1-Sn stored in the secure memory 112, but the scope of the present disclosure is not limited thereto. In various other embodiments, without departing from the scope of the present disclosure, different or multiple host applications may generate an access request AR for accessing at least one of the multiple security applications S1-Sn stored in the secure memory 112.
[0113] Figure 3 An authorization database 116 is shown stored in secure memory 112 according to an embodiment of the present disclosure.
[0114] The authorization database 116 includes a column 300. The column 300 may correspond to a plurality of reference addresses 302-310 of the authorization database 116. Each of the plurality of reference addresses 302-310 may be associated with storage of an authorization state AS corresponding to a host application in a plurality of host applications H1-Hm. In an example, before generating an access request AR corresponding to a first host application H1, a first reference address 302 in the plurality of reference addresses 302-310 may store the authorization state AS as a first state associated with the first host application H1 (e.g., the authorization state AS is set to 'FS'). Similarly, the authorization state AS of each of the second host application H2 and the Mth host application Hm may be set to a first state. Examples of the authorization database 116 may include a relational database, an extensible markup language (XML) database, an in-memory database, a blockchain database, and the like. In another embodiment, before generating an access request AR corresponding to at least one of the first host application H1 and the second host application H2, the first reference address 302 may store the authorization state AS as a first state associated with the first host application H1 and the second host application H2 (e.g., the authorization state AS is set to 'FS'). Similarly, the authorization state AS of the Mth host application Hm may be set to the first state.
[0115] Figure 4 A process flow chart 400 illustrating host 102 access rights regulation to multiple security functions according to an embodiment of the present disclosure is shown. For simplicity and without departing from the scope of the present disclosure, assume that the host 102 generates an access request to access a first security application S1.
[0116] The installation of the first security application S1 is initiated by the processor 106 of the host 102 (as indicated by arrow 402). The first security application is installed in the secure memory 112 by the control circuit 118 (as indicated by arrow 404). The control circuit 118 may determine the status of the restart flag RFL associated with at least one of the plurality of host applications H1-Hm stored in the host memory 108 of the host 102 (as indicated by arrow 406). Based on the successful installation of the first security application S1, the control circuit 118 may send a confirmation signal to the host 102 indicating the successful installation of the first security application (as indicated by arrow 410).
[0117] The processor 106 may perform a reset operation of the host 102 (as shown by arrow 412). During the reset operation, the processor 106 may switch the state of the reset alarm signal RS and send the reset alarm signal RS to the detector 110 (as shown by arrow 414). In addition, when the state of the reset alarm signal RS is switched, the detector 110 may detect a restart state of the host 102 (as shown by arrow 416). In an embodiment, when the restart state indicates a reset operation, the detector 110 may set a restart flag RFL (e.g., set the restart flag RFL to one) (as shown by arrow 418).
[0118] At least one of the plurality of host applications H1-Hm stored in the host memory 108 may generate an access request AR to access at least one of the plurality of security functions associated with the first security application S1 stored in the secure memory 112. The host 102 may send the access request AR to the control circuit 118 (as indicated by arrow 420). A status request SR is generated by the control circuit 118 to determine a restart flag RFL associated with at least one of the plurality of host applications H1-Hm (as indicated by arrow 422). Based on the status request SR, a restart flag RFL indicating a reset operation is received by the control circuit 118 (as indicated by arrow 424). When the control circuit 118 receives the restart flag RFL, the detector 110 may reset the restart flag RFL (e.g., restart flag RFL='0') (as indicated by arrow 426). Based on the status of the restart flag RFL indicating the reset operation, the authorization state AS associated with at least one of the plurality of host applications H1-Hm is updated to a first state (as indicated by arrow 428). The control circuit 118 may restrict access rights of at least one of the plurality of host applications H1-Hm to the plurality of security functions (as indicated by arrow 430). Authorization between the host 102 and the control circuit 118 is initiated by the processor 106 after the reset operation (as indicated by arrow 432). For the sake of brevity and without departing from the scope of the present disclosure, it is assumed that the authorization is successful. In addition, after the authorization between the host 102 and the control circuit 118, the host 102 may send an access request AR to the control circuit 118. Based on the successful authorization between the host 102 and the control circuit 118, the authorization state AS may be updated from the first state to the second state (as indicated by arrow 434). The control circuit 118 may grant access rights to the plurality of security functions to the host 102 (as indicated by arrow 436). A status request SR (as indicated by arrow 438) for determining a restart flag RFL associated with at least one of the plurality of host applications H1-Hm may be generated by the control circuit 118. Based on the status request SR, a restart flag RFL indicating normal operation of the host 102 may be received by the control circuit 118 (as indicated by arrow 440). The control circuit 118 may grant at least one of the plurality of host applications H1-Hm access to the plurality of security functions (as indicated by arrow 442).
[0119] Figures 5A-5C 5 and 6. Collectively, a flowchart 500 illustrating an access adjustment method for adjusting access to a security function is shown according to an embodiment of the present disclosure.
[0120] Reference now Figure 5AAt step 502, the detector 110 may receive a reset alarm signal RS sent by the host 102 (e.g., the processor 106). The reset alarm signal RS may include at least one of a secure GPIO signal SGS and a pad power supply signal PSS. At step 504, when the state of the reset alarm signal RS switches, the detector 110 may detect a restart state of the host 102. At step 506, the detector 110 may generate a restart flag RFL (e.g., set the restart flag RFL or reset the restart flag RFL) based on the restart state of the host 102. For example, when the restart state indicates a reset operation, the detector 110 may set the restart flag RFL to one. At step 508, the secure memory 112 may store a restart flag RFL associated with each of a plurality of host applications H1-Hm stored in the host 102 (e.g., the host memory 108). The secure memory 112 may store the restart flag RFL in the restart database 114. At step 510, the control circuit 118 may receive an access request AR from the host 102 to access at least one of a plurality of security functions associated with a plurality of security applications S1-Sn stored in the secure memory 112. At step 512, the control circuit 118 may generate a status request SR based on the received access request AR. At step 514, the control circuit 118 may send the status request SR to the detector 110.
[0121] Reference now Figure 5B At step 516, the secure memory 112 may provide a restart flag RFL to the control circuit 118 based on the access request AR sent to the detector 110. At step 518, it is determined whether the authorization status AS indicates a successful authorization between the host 102 and the control circuit 118. If at step 518, it is determined that the authorization status AS indicates a successful authorization (e.g., before a reset operation), step 520 is performed. At step 520, it is determined whether the status of the restart flag RFL indicates a reset operation. If at step 520, it is determined that the status of the restart flag RFL indicates a reset operation, step 522 is performed. At step 522, the control circuit 118 may update the authorization status AS to a first state, so that the first state may indicate that there is no authorization. If at step 518, it is determined that the authorization status AS does not indicate a successful authorization (e.g., before a reset operation), step 524 is performed.
[0122] At step 524, the control circuit 118 may restrict access to the plurality of security functions based on the authorization status AS. The control circuit 118 may grant access to the plurality of general functions. In addition, the host 102 may initiate authorization after a reset operation of the host 102.
[0123] Reference now Figure 5C, at step 526, it is determined whether the initiation of the authorization between the control circuit 118 and the host 102 is successful. If at step 526, it is determined that the authorization between the control circuit 118 and the host 102 is successful after the reset operation, step 528 is executed. At step 528, the control circuit 118 may update the authorization state AS to a second state, so that the second state may indicate the successful authorization between the control circuit 118 and the host 102 after the reset operation of the host 102. If at step 520, it is determined that the status of the restart flag RFL does not indicate a reset operation, step 530 is executed. At step 530, the control circuit 118 may grant access to a plurality of security functions and a plurality of general functions to the host 102. If at step 526, it is determined that the authorization between the control circuit 118 and the host 102 fails after the reset operation, step 532 is executed. At step 532, the control circuit 118 may update the authorization state AS to a first state, so that the first state may indicate the failure of the authorization. At step 534 , the control circuitry 118 may restrict access to the plurality of security functions.
[0124] The authorization database 116 can store the authorization status AS persistently in the secure memory 112. In addition, the detector 110 and the control circuit 118 add an additional security layer to the electronic device 100. The detector 110 can detect the restart state of the host 102 based on the state of the reset alarm signal RS. In the case of an attack by malware that obtains control of the host 102, the control circuit 118 limits the access rights of such software based on determining that an authorization failure occurs or there is no authorization after the reset operation of the host 102. When initiating authorization, an authorization failure may occur due to the control of the host 102 by the malware. Therefore, the malware cannot access the security functions of the electronic device 100, and the security of the electronic device 100 is improved. When the genuine application of the host 102 can generate an access request AR to access multiple security applications S1-Sn with the help of the processor 106, the authorization between the control circuit 118 and the host 102 is used as a decisive factor in granting access rights to multiple security applications S1-Sn to the host 102 after the reset operation of the host 102. When the authorization between the host 102 and the control circuit 118 succeeds after the reset operation of the host 102, the control circuit 118 may grant access to the plurality of security functions to at least one of the plurality of host applications H1-Hm. Similarly, the authorization may occur in a remote IoT device that may remotely control the security operation to ensure the security of the basic security operation.
[0125] In an embodiment, an integrated circuit (IC) may include a detector coupled to a host, wherein the detector may be configured to receive a reset alarm signal from the host. In addition, the detector may be configured to detect a restart state of the host based on a state of the reset alarm signal, wherein the state of the reset alarm signal switches during a reset operation of the host. The detector may be further configured to generate a restart flag based on the restart state of the host. A control circuit of the IC may be coupled to the detector and the host, wherein the control circuit may be configured to receive an access request from the host to access multiple security functions of the IC. The control circuit may be further configured to determine the status of the restart flag and the authorization status of the host when receiving the access request. In addition, the control circuit may be configured to adjust the host's access to multiple security functions based on the status and authorization status of the restart flag.
[0126] In some embodiments, the IC may further include a secure memory coupled to the detector and the control circuit, wherein the secure memory may be configured to store a restart flag. The secure memory may further be configured to provide the restart flag to the control circuit based on an access request.
[0127] In some embodiments, the control circuit may be further configured to generate a status request based on an access request received from the host. In addition, the control circuit may be configured to send a status request to the detector, wherein the control circuit may receive a restart flag from the secure memory based on sending the status request to the detector.
[0128] In some embodiments, when the control circuit can determine that the authorization status is associated with a successful authorization between the control circuit and the host before a reset operation of the host and the status of the restart flag can indicate a reset operation of the host, the control circuit can be further configured to update the authorization status to indicate that there is no authorization between the control circuit and the host after the reset operation, and wherein when the authorization status is updated to indicate that there is no authorization, the control circuit can be further configured to limit the host's access to multiple security functions, thereby adjusting the host's access rights.
[0129] In some embodiments, authorization between the host and the control circuitry may be initiated by the host, when the control circuitry may limit the host's access to a plurality of security functions.
[0130] In some embodiments, when authorization between the control circuit and the host can succeed based on initiation of authorization after a reset operation of the host, the control circuit can be further configured to update the authorization status to indicate successful authorization between the control circuit and the host after the reset operation of the host. When the authorization status indicates successful authorization after the reset operation, the control circuit can be further configured to grant access to the host to multiple security functions, thereby adjusting the access rights of the host.
[0131] In some embodiments, when authorization between the control circuit and the host may fail at initiation of authorization after a reset operation of the host, the control circuit may limit the host's access to the plurality of security functions.
[0132] In some embodiments, the secure memory may be further configured to store a plurality of security applications, wherein each of the plurality of security applications may be associated with at least one of the plurality of security functions.
[0133] In some embodiments, the plurality of security functions may be one of the group consisting of: device authorization, payment processing, identity verification, secure messaging, cryptographic operations, access control, digital signatures, and tokenization.
[0134] In some embodiments, the authorization state may be associated with authorization between the host and the control circuit, wherein the authorization may indicate at least one of the group consisting of: trusted binding, multi-factor authorization, token-based authorization, credential-based authorization, blockchain-based authorization, and behavior-based authorization.
[0135] In some embodiments, the reset alarm signal may include at least one of a plurality of secure general purpose input / output (GPIO) signals and a pad power signal.
[0136] In some embodiments, the state of the pad power signal can be one of the following during a reset operation: (i) an asserted state when the host remains on; and (ii) a de-asserted state when the host remains off, wherein the detector can be further configured to generate a restart flag based on the de-assertion of the pad power signal.
[0137] In some embodiments, the state of the secure GPIO signal may be an asserted state during a reset operation, wherein the detector may be further configured to generate a restart flag based on the assertion of the secure GPIO signal.
[0138] In some embodiments, the detector can be further configured to transition from a low power mode to a normal mode upon receiving a reset alarm signal, wherein during the normal mode, the detector can generate a restart flag indicating a restart status of the host, and wherein during the low power mode, the detector can be further configured to operate in a low energy consumption state.
[0139] In another embodiment, a method for adjusting access rights may include receiving a reset alarm signal from a host by a detector of an integrated circuit (IC). The method may include detecting a restart state of the host based on the reset alarm signal by the detector, wherein the state of the reset alarm signal may be switched during a reset operation of the host. The method may include generating a restart flag by the detector based on the restart state of the host. In addition, the method may include receiving an access request to access multiple security functions of the IC from the host by a control circuit of the IC. The method may include determining, by the control circuit, the status of the restart flag and the authorization status between the host and the control circuit upon receiving the access request. In addition, the method may include adjusting the host's access rights to multiple security functions based on the status and authorization status of the restart flag by the control circuit.
[0140] In some embodiments, the method may further include: storing, by a secure memory of the IC, a restart flag; and providing, by the secure memory, the restart flag to the control circuit based on the access request.
[0141] In some embodiments, the method may further include generating, by the control circuit, a status request that may indicate detection of a restart state of the host based on an access request received from the host. The method may further include the control circuit sending the status request to the detector, wherein the restart flag may be received by the control circuit from the secure memory based on sending the status request to the detector.
[0142] In some embodiments, the method may further include, when determining that the authorization state may indicate successful authorization between the control circuit and the host before the reset operation of the host and the status of the restart flag may indicate the reset operation of the host, updating, by the control circuit, the authorization state to indicate that there is no authorization between the control circuit and the host after the reset operation of the host. The method may further include, when the authorization state may be updated to indicate that there is no authorization between the control circuit and the host after the reset operation of the host, limiting, by the control circuit, access rights of the host to the plurality of security functions, thereby regulating the access rights of the host.
[0143] In some embodiments, when the host's access to a plurality of security functions is restricted, authorization between the host and the control circuitry may be initiated after a reset operation of the host.
[0144] In some embodiments, the method may further include, when authorization between the control circuit and the host is successful after a reset operation of the host, updating, by the control circuit, an authorization status to indicate successful authorization between the control circuit and the host after a reset operation of the host. The method may further include, when the authorization status may indicate successful authorization after a reset operation, granting, by the control circuit, access to a plurality of security functions to the host, thereby regulating access rights of the host.
[0145] In the present disclosure, the term "assert" is used to mean placing a signal in an active state. For example, for an active-low signal, the signal is in a logic low state when asserted, and for an active-high signal, the signal is in a logic high state when asserted.
[0146] Although various embodiments of the present disclosure have been shown and described, it should be clear that the present disclosure is not limited to these embodiments. Without departing from the spirit and scope of the present disclosure described in the claims, many modifications, changes, variations, substitutions and equivalents will be apparent to those skilled in the art. In addition, unless otherwise stated, terms such as "first" and "second" are used to arbitrarily distinguish the elements described by such terms. Therefore, these terms are not necessarily intended to indicate the priority or other priority of such elements in time.
Claims
1. An integrated circuit IC, characterized in that: include: A detector coupled to a host, wherein the detector is configured to: receiving a reset alarm signal from the host; detecting a restart state of the host based on a state of the reset alarm signal, wherein the state of the reset alarm signal switches during a reset operation of the host; and generating a restart flag based on the restart status of the host; as well as a control circuit coupled to the detector and the host, wherein the control circuit is configured to: receiving, from the host, an access request to access a plurality of security functions of the IC; Upon receiving the access request, determining a status of the restart flag and an authorization status of the host; and Access to the plurality of security functions by the host is adjusted based on the condition of the restart flag and the authorization status.
2. The IC according to claim 1, characterized in that Also included is a secure memory coupled to the detector and the control circuit, wherein the secure memory is configured to: storing the restart flag; and The restart flag is provided to the control circuit based on the access request.
3. The IC according to claim 2, characterized in that The control circuit is further configured to: generating a status request based on the access request received from the host; and The status request is sent to the detector, wherein the control circuit receives the restart flag from the secure memory based on the sending of the status request to the detector.
4. The IC according to claim 3, It is characterized in that When the control circuit determines that the authorization status is associated with a successful authorization between the control circuit and the host prior to the reset operation of the host and the condition of the restart flag indicates the reset operation of the host, the control circuit is further configured to update the authorization status to indicate that there is no authorization between the control circuit and the host after the reset operation of the host, and Wherein when the authorization status is updated to indicate the absence of the authorization, the control circuit is further configured to restrict the host's access to the plurality of security functions, thereby regulating the access rights of the host.
5. The IC according to claim 4, It is characterized in that The authorization between the host and the control circuit is initiated by the host when the control circuit restricts the access right of the host to the plurality of security functions.
6. The IC according to claim 2, characterized in that The secure memory is additionally configured to store a plurality of security applications, and wherein each of the plurality of security applications is associated with at least one of the plurality of security functions.
7. The IC according to claim 1, characterized in that The plurality of security functions is one of the group consisting of: device authorization, payment processing, identity verification, secure messaging, cryptographic operations, access control, digital signatures, and tokenization.
8. The IC according to claim 1, wherein: The authorization state is associated with authorization between the host and the control circuit, and wherein the authorization indicates at least one of the group consisting of: trusted binding, multi-factor authorization, token-based authorization, credential-based authorization, blockchain-based authorization, and behavior-based authorization.
9. The IC according to claim 1, characterized in that The detector is further configured to transition from a low power mode to a normal mode upon receiving the reset alarm signal, wherein during the normal mode, the detector generates the restart flag indicating the restart state of the host, and wherein during the low power mode, the detector is further configured to operate in a low energy consumption state.
10. A method for adjusting access rights, characterized in that: include: The detector of the integrated circuit IC receives a reset alarm signal from the host; detecting, by the detector, a restart state of the host based on the reset alarm signal, wherein a state of the reset alarm signal switches during a reset operation of the host; generating, by the detector, a restart flag based on the restart status of the host; receiving, by a control circuit of the IC, from the host, an access request to access a plurality of security functions of the IC; Upon receiving the access request, the control circuit determines the status of the restart flag and the authorization status between the host and the control circuit; as well as Access to the plurality of security functions by the host is adjusted by the control circuit based on the condition of the restart flag and the authorization status.