ESE and eSIM combined device, operation isolation method and related device
The TrustZone mechanism divides the secure core and non-security core on the chip, and is used in eSIM and eSE systems respectively, solving the isolation and security problems after integration, and achieving efficient isolation and safe operation of eSE and eSIM.
Patent Information
- Application Number
- CN202510202331.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-06-10
AI Technical Summary
When eSE and eSIM are integrated into the same chip, there are problems of access conflicts and mutual influence, resulting in potential isolation risks and affecting the security of the all-in-one chip.
The processor is divided into secure core and non-security core through TrustZone mechanism, which is used in eSIM and eSE systems respectively to achieve operational isolation. The security core includes the eSIM system, and the non-safe core includes the eSE system. Each has independent stack space and interrupt processing table to ensure isolation and security.
It improves the isolation between the eSE system and the eSIM system, avoids system crashes caused by stack overflow and address out-of-bounds problems, and ensures that eSE and eSIM operate safely on the same chip.
Smart Images

Figure CN120124115A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present disclosure relate to the field of security chip technology, and more particularly to an eSE and eSIM combination device, an operation isolation method, and related apparatuses. Background Art
[0002] At present, the solution of integrating eSE and eSIM into the same chip has gradually become the mainstream application of security chips in the field of consumer electronics and the Internet of Things. Compared with the original solution of eSE and eSIM being located in two discrete chips, the integration of eSE and eSIM into the same chip has lower energy consumption and higher integration. However, when eSE and eSIM are placed on the same chip, since they share the same memory space and hardware resources in the core, there may be access conflicts and mutual influence between the two. The increase in integration brings hidden dangers in isolation.
[0003] Therefore, eSE and eSIM isolation is the key technology to realize all-in-one chip and has become a technical problem that needs to be solved urgently. Summary of the invention
[0004] In order to solve the above technical problems or at least partially solve the above technical problems, the embodiments of the present disclosure provide an eSE and eSIM combination device, an operation isolation method and related devices.
[0005] A first aspect of an embodiment of the present disclosure provides an eSE and eSIM combination device, wherein the eSE and eSIM combination device integrates an eSE function and an eSIM function in the same chip, and a processor in the chip is divided into a secure core and a non-secure core through a TrustZone mechanism;
[0006] The security core includes an eSIM system, the eSIM system includes an eSIM virtual machine, an eSIM entry function, an eSIM stack resource, and an eSIM register, and the security core also includes a secure boot system and a secure base system of the Main system;
[0007] The non-secure core includes an eSE system, the eSE system includes an eSE virtual machine, an eSE entry function, an eSE stack resource and an eSE register, and the non-secure core also includes a non-secure boot system and a non-secure basic system.
[0008] A second aspect of the embodiments of the present disclosure provides an operation isolation method, which is applied to the eSE and eSIM combination device described in the first aspect, and the method includes:
[0009] In the case where a first target function in the secure core calls a second target function in the non-secure core, the secure core saves the context information currently being executed to the stack resource of the secure core, where the context information includes the content in the register and the return address;
[0010] The secure core sets the content in the LR to a preset value;
[0011] The non-secure core executes the second target function;
[0012] In the case where the execution of the second target function is completed, the secure core retrieves the preset value from the LR, and under the indication of the preset value, retrieves the context information from the stack resource of the secure core, and continues to execute the first target function based on the context information.
[0013] A third aspect of the embodiments of the present disclosure provides an operation isolation device, which is applied to the eSE and eSIM combined device described in the first aspect. The device includes:
[0014] A first saving module, which is used for, in the case where a first target function in the secure core calls a second target function in the non-secure core, the secure core saves the context information currently being executed to the stack resource of the secure core, where the context information includes the content in the register and the return address;
[0015] A first setting module, which is used for the secure core to set the content in the LR to a preset value;
[0016] A first execution module, which is used for the non-secure core to execute the second target function;
[0017] A second execution module, which is used for, in the case where the execution of the second target function is completed, the secure core retrieves the preset value from the LR, and under the indication of the preset value, retrieves the context information from the stack resource of the secure core, and continues to execute the first target function based on the context information.
[0018] A fourth aspect of the embodiments of the present disclosure provides an electronic device, including: a processor and a memory, where a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the method in the second aspect above.
[0019] A fifth aspect of the embodiments of the present disclosure provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the method in the second aspect above can be implemented.
[0020] The technical solutions provided by the embodiments of the present disclosure have the following advantages compared with the prior art:
[0021] In an embodiment of the present disclosure, an eSE and eSIM combined device integrates the eSE function and the eSIM function in the same chip. The processor in the chip is divided into a secure core and a non-secure core through the TrustZone mechanism; the secure core includes an eSIM system, and the eSIM system includes an eSIM virtual machine, an eSIM entry function, eSIM stack resources, and eSIM registers. The secure core also includes a secure boot system and a secure basic system of the Main system; the non-secure core includes an eSE system, and the eSE system includes an eSE virtual machine, an eSE entry function, eSE stack resources, and eSE registers. The non-secure core also includes a non-secure boot system and a non-secure basic system. It can be seen that by adopting the above technical solution, the eSE function and the eSIM function are integrated in the same chip, and the eSE system and the eSIM system are isolated in two virtual cores (the secure core and the non-secure core) through the TrustZone mechanism. In this way, the isolation between the eSE system and the eSIM system can be improved, which is beneficial to the eSE system and the eSIM system to operate safely in the same chip. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present disclosure and, together with the specification, are used to explain the principles of the present disclosure.
[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present disclosure or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0024] Figure 1 is a flowchart of a running isolation method provided by an embodiment of the present disclosure;
[0025] Figure 2 is a schematic structural diagram of an eSE and eSIM combined device provided by an embodiment of the present disclosure;
[0026] Figure 3 is a flowchart of a system running method provided by an embodiment of the present disclosure;
[0027] Figure 4 is a flowchart of an RTOS startup process provided by an embodiment of the present disclosure;
[0028] Figure 5 is a flowchart of an eSE system startup process provided by an embodiment of the present disclosure;
[0029] Figure 6It is a flowchart of the startup process of an eSIM system provided by an embodiment of the present disclosure;
[0030] Figure 7 It is a schematic structural diagram of an operating isolation device provided by an embodiment of the present disclosure;
[0031] Figure 8 It is a schematic structural diagram of an electronic device in an embodiment of the present disclosure. Detailed implementation manners
[0032] In order to more clearly understand the above objects, features and advantages of the present disclosure, the solutions of the present disclosure will be further described below. It should be noted that, without conflict, the embodiments of the present disclosure and the features in the embodiments may be combined with each other.
[0033] Many specific details are set forth in the following description in order to fully understand the present disclosure, but the present disclosure may also be implemented in other ways different from those described herein; obviously, the embodiments in the specification are only a part of the embodiments of the present disclosure, rather than all of the embodiments.
[0034] First, the eSE and eSIM combined device provided by the embodiment of the present disclosure will be described in detail.
[0035] Exemplarily, Figure 1 It is a schematic structural diagram of an eSE and eSIM combined device provided by an embodiment of the present disclosure. Refer to Figure 1 , the eSE and eSIM combined device integrates the eSE function and the eSIM function in the same chip, and the processor in the chip is divided into a secure core and a non-secure core through the TrustZone mechanism;
[0036] The secure core includes an eSIM system, and the eSIM system includes an eSIM virtual machine, an eSIM entry function, eSIM stack resources and eSIM registers. The secure core also includes the secure startup system and the secure basic system of the Main system;
[0037] The non-secure core includes an eSE system, and the eSE system includes an eSE virtual machine, an eSE entry function, eSE stack resources and eSE registers. The non-secure core also includes a non-secure startup system and a non-secure basic system.
[0038] Specifically, the secure core (i.e., the S core) is a secure world (SecureWorld) divided through the TrustZone mechanism. The secure core mainly includes an eSIM system and a part of the Main system (i.e., the main operating system). The non-secure core (i.e., the NS core) is a normal world (Non-Secure World) divided through the TrustZone mechanism. The non-secure core mainly includes an eSE system and a part of the Main system.
[0039] Among them, the eSIM system includes an eSIM virtual machine, an eSIM entry function, eSIM stack resources, and eSIM registers.
[0040] The eSIM virtual machine is the virtual machine corresponding to the eSIM function (i.e., JCVM). Exemplarily, the virtual machine can be a virtual machine based on JAVA Card and Global Platform standards, etc., but is not limited thereto.
[0041] The eSIM stack resources are the stack resources corresponding to the eSIM function. Figure 2 It is a schematic structural diagram of an eSE and eSIM combined device provided by an embodiment of the present disclosure. Refer to Figure 2 , Optionally, the eSIM stack resources include MSPLIM (Main StackPointer Limit), PSPLIM (Process Stack Pointer Limit), Main Stack Pointer (MSP), and / or Process Stack Pointer (PSP). MSPLIM is used to limit the main stack pointer, PSPLIM is used to limit the process stack pointer, MSP is a stack pointer maintained by hardware and is mainly used for stack operations in the processing mode, and PSP is a stack pointer maintained by software and is mainly used for stack operations in the thread mode.
[0042] The eSIM entry function is the entry function corresponding to the eSIM function (i.e., ENTRY), and the eSIM entry function is the first function to be executed when the eSIM system starts.
[0043] The eSIM registers are the registers corresponding to the eSIM function. Optionally, the eSIM registers include: Status Register, Control Register, Data Register, Key Management Register, Authentication Register, Access Control Register, PLMN Selection Register, IMS Information Register, SMS Register, and / or Special Function Register. Continue to refer to Figure 2, Further optionally, the special function registers include: CONTROL, FAULTMASK, PRIMASK, and / or BASEEPRI. CONTROL is an 8-bit special function register used to control the selection of the stack pointer (MSP or PSP) and other privilege level-related behaviors. FAULTMASK is a 32-bit special function register used to globally mask all maskable exceptions (except NMI and HardFault). PRIMASK is a 32-bit special function register used to globally mask all maskable exceptions with a priority lower than the configured value. BASEPRI is a 32-bit special function register used to set a priority threshold, and exceptions above this threshold can be triggered, while those below or equal to this threshold are masked.
[0044] Among them, the eSE system includes an eSE virtual machine, an eSE entry function, eSE stack resources, and eSE registers.
[0045] The eSE virtual machine is the virtual machine corresponding to the eSE function (i.e., JCVM).
[0046] The eSE stack resources are the stack resources corresponding to the eSE function. See Figure 2 , Optionally, the eSE stack resources include MSPLIM, PSPLIM, MSP, and / or PSP.
[0047] The eSE entry function is the entry function corresponding to the eSE function (i.e., ENTRY). The eSE entry function is the first function to be executed when the eSE system starts.
[0048] The eSE registers are the registers corresponding to the eSE function. Optionally, the eSE registers include: Status Register, Control Register, Data Register, Key Management Register, Authentication Register, Access Control Register, PLMN Selection Register, IMS Information Register, SMS Register, and / or special function registers. Continue to see Figure 2 , Further optionally, the special function registers include: CONTROL, FAULTMASK, PRIMASK, and / or BASEEPRI.
[0049] Among them, the Main system is mainly used to provide basic public services, such as resource management, task scheduling, and basic system services. These functions are independent of the specific business (eSE business and eSIM business) logic, but provide necessary support for the stable operation of the eSE system and eSIM system.
[0050] The Main system located in the secure core is responsible for handling all basic public services related to security. For example, the Main system located in the secure core includes: a secure boot system (i.e., XOS-Boot-S) and a secure basic system (i.e., XOS-Main-S). Among them, the secure boot system is used to initialize the secure basic system when the eSE and eSIM combined device is powered on or reset. The startup process not only involves the initialization of hardware and software, but also ensures the security of the secure basic system. The secure basic system is used to provide all basic public services related to security except for startup. Continue to refer to Figure 2 , optionally, the secure basic system includes a basic library (i.e., Basic Lib) and a secure call interface (i.e., NSCAPI). The basic library is a set of function libraries used to provide basic functions for system and hardware interaction. The secure call interface is used to call the secure services in the secure core from the non-secure core while maintaining the isolation and security of the two cores.
[0051] The Main system located in the non-secure core is responsible for handling all basic public services related to non-security (i.e., conventional application logic and other basic public services that do not require a high security level). For example, the Main system located in the non-secure core includes: a non-secure boot system (i.e., XOS-Boot-NS) and a non-secure basic system (i.e., XOS-Main-NS). Among them, the non-secure boot system is used to initialize the non-secure basic system when the eSE and eSIM combined device is powered on or reset. The startup process not only involves the initialization of hardware and software, but also ensures the security of the non-secure basic system. The non-secure basic system is used to provide all basic public services related to non-security except for startup. Continue to refer to Figure 2, optionally, the non-secure basic system includes a real-time operating system (i.e., RTOS) and non-secure call interfaces. The non-secure call interfaces include an eSE call interface (i.e., API for eSE) and an eSIM call interface (i.e., API for eSIM). The real-time operating system is an operating system specifically designed to handle time-sensitive tasks. The non-secure call interfaces are used to call the secure call interfaces in the secure core from the non-secure core. For the eSE system, the eSE call interface can be obtained by secondarily encapsulating the secure call interface. The eSE call interface is dedicated to interacting with the eSE system; for the eSIM system, the eSIM call interface can be obtained by secondarily encapsulating the secure call interface. The eSIM call interface is dedicated to interacting with the eSIM system. It can be understood that by secondarily encapsulating the secure call interface to obtain the eSE call interface and the eSIM call interface, the complex secure call interface can be converted into a more user-friendly call interface, enabling eSE tasks, eSIM tasks, etc. to directly call these secondarily encapsulated call interfaces without having to understand the underlying security mechanisms and details.
[0052] Exemplarily, the security attributes of different sections in the address space can be divided by configuring the security attribute unit (SAU) and the implementation-defined attribute unit (IDAU) in the processor. The Main system is divided into two parts, one part located in the secure core and the other part located in the non-secure core. The secure boot system, the basic library, and the secure call interfaces are placed in the secure core, and the public functions (i.e., functions of public services) are exported externally through the secure call interfaces to ensure that the upper layer can only access the protected public resources through these secure call interfaces. The non-secure boot system, the real-time operating system, and the non-secure call interfaces are placed in the non-secure core. The non-secure call interfaces are the call interfaces obtained by secondarily encapsulating the secure call interfaces, providing two sets of call interfaces (i.e., the eSE call interface and the eSIM call interface) for the eSE system and the eSIM system to adapt to the access requirements of different business systems (i.e., the eSE system and the eSIM system) to the public resource library. At the specific business system level, the eSE system is placed in the non-secure core, the eSIM system is placed in the secure core, the eSE entry function and the eSIM entry function are provided to the real-time operating system in the Main system to implement task scheduling, and the public resources in the Main system are accessed through their respective call interfaces (the eSE system through the eSE call interface and the eSIM system through the eSIM call interface).
[0053] It can be understood that the eSE and eSIM combined device provided by the present disclosure can place the eSE system in the non-secure core and the eSIM in the secure core by using the TrustZone mechanism. Since the eSE system and the eSIM system are located in virtual cores with different security attributes respectively, they have different security attributes during operation. According to the TrustZone mechanism, these two systems have independent stack address spaces and interrupt vector table spaces, independent stack pointers (MSP / PSP) and independent stack overflow check functions (MSPLIM / PSPLIM), and there are also two independent copies of the special function registers (CONTROL / FAULTMASK / PRIMASK / BASEPRI) related to interrupt exceptions for the two systems. In this way, the two virtual machines of the eSE system and the eSIM system can run on two virtual cores with independent stack spaces, independent interrupt resources, and protected data access and function call functions, so as to achieve the isolation function when the eSE system and the eSIM system run simultaneously, effectively avoiding the normal operation of the other system being affected due to problems such as stack overflow, address out-of-bounds, and system crash that occur during the operation of one of the systems. In this way, when the eSE system and the eSIM system run simultaneously, they cannot directly call the relevant code of the other system through the function address, thus realizing the isolation protection of these two systems during operation.
[0054] Figure 3 It is a flowchart of a system operation method provided by an embodiment of the present disclosure, and this method can be executed by an electronic device. The electronic device includes the eSE and eSIM combined device described in any of the above embodiments, and the electronic device can be exemplarily understood as devices such as mobile phones and bracelets. As Figure 3 shown, the method provided in this embodiment includes the following steps:
[0055] S310. When a first target function in the secure core calls a second target function in the non-secure core, the secure core saves the currently executed context information to the stack resources of the secure core, where the context information includes the content in the register and the return address.
[0056] In the embodiment of the present disclosure, before the first target function in the secure core calls the second target function in the non-secure core, the secure core needs to do some preparatory work before the call: save the currently executed context information to the stack resources of the secure core, and set the content in LR to a preset value. In this way, it can be avoided that the non-secure core snoops on the data in the secure core, thereby improving the security of the secure core.
[0057] Specifically, the first target function can be any function located in the secure core that needs to call the second target function.
[0058] Specifically, the second objective function can be any function located in the non-secure core and called by the first objective function.
[0059] Specifically, the context information refers to the status information when the first objective function is executed. Among them, the context information includes the data stored in the registers involved when the first objective function is executed (i.e., the content in the registers) and the return address (which refers to the instruction address when continuing to execute the first objective function after the second objective function call is completed).
[0060] Specifically, the stack resources of the secure core include eSIM stack resources. Therefore, the context information can be saved to the eSIM stack resources, but it is not limited to this.
[0061] S320. The secure core sets the content in LR to a preset value.
[0062] Specifically, LR is the link register. In the embodiments of the present disclosure, when the first objective function calls the second objective function, the real return address is not stored in LR, but a preset value (referred to as FNC_RETURN) is stored in LR. In this way, after the second objective function call is completed, the secure core can determine that it is currently jumping back from the non-secure core to the secure core based on the preset value stored in LR, and needs to retrieve the context information from the stack resources of the secure core.
[0063] S330. The non-secure core executes the second objective function.
[0064] In the embodiments of the present disclosure, after the secure core finishes the pre-call preparation work, it can switch from the secure core to the non-secure core, and the non-secure core executes the second objective function.
[0065] S340. When the second objective function execution is completed, the secure core retrieves the preset value from LR, and under the indication of the preset value, retrieves the context information from the stack resources of the secure core, and continues to execute the first objective function based on the context information.
[0066] In the embodiments of the present disclosure, after the second objective function execution is completed, the secure core will detect the data stored in LR. When the data stored in LR is the preset value, the secure core can determine that it is currently switching from the non-secure core to the secure core, and needs to retrieve and restore the context information previously saved in the stack resources of the secure core so as to continue to execute the first objective function from the correct position.
[0067] It can be understood that, based on the characteristics of the TrustZone mechanism, when the second target function in the non-secure core is called from the first target function in the secure core, it cannot be directly accessed through the address information of the second target function, and the call needs to be implemented according to the principles described in S310 - S340. In the embodiments of the present disclosure, when the first target function in the secure core calls the second target function in the non-secure core, the general registers in the secure state need to be cleared before the call to avoid the exposure of the running information belonging to the secure core when jumping to the non-secure core. And the operation of storing the address of the next running instruction into the LR register when making a normal function call cannot be performed, as this will expose the running address of the secure core to the non-secure core, which does not meet the requirements of security isolation and protection. Therefore, before the function jump, the secure core will store the contents of the relevant registers and the return address into the stack exclusive to the secure core, and set the LR to a special FNC_RETURN value. When the function returns from the non-secure core to the secure core, by identifying the special value of the LR, the restoration operation of the data in the stack exclusive to the secure core is realized. When S310 and S320 are not executed, the call process of the first target function in the secure core to the second target function in the non-secure core will be intercepted and recognized as a dangerous operation.
[0068] In another embodiment of the present disclosure, the method further includes: S410, when the third target function in the non-secure core calls the fourth target function in the secure core, the non-secure core executes the SG instruction.
[0069] In the embodiments of the present disclosure, before the third target function in the non-secure core calls the fourth target function in the secure core, the non-secure core needs to perform some pre-call preparation work: execute the SG instruction so that the processor checks whether it is currently allowed to enter the secure core and whether there is sufficient permission to execute the requested fourth target function.
[0070] Specifically, the third target function can be any function located in the non-secure core that needs to call the fourth target function.
[0071] Specifically, the fourth target function can be any function located in the secure core that is called by the third target function.
[0072] Specifically, the SG instruction (Secure Gateway) is a key instruction in the TrustZone mechanism for implementing secure switching between the secure core and the non-secure core. The main functions of the SG instruction are as follows: (1) Secure switching: When the third target function in the non-secure core needs to call the fourth target function in the secure core, it can request to enter the secure core through the SG instruction. After the fourth target function is executed in the secure core, the SG instruction can be used to return to the non-secure core. (2) Data transfer: Parameters are passed to the fourth target function of the secure core through registers or memory; after the secure core finishes execution, the result is returned to the non-secure core through registers or memory. (3) Before entering the secure core, the context information of the non-secure core is saved, including general registers, stack pointer, link register, etc.; when returning from the secure core, the context information of the non-secure core is restored to ensure that the third target function can continue to execute correctly.
[0073] S420. The non-secure core calls the secure call interface corresponding to the fourth target function.
[0074] S430. The secure core executes the fourth target function.
[0075] In the embodiment of the present disclosure, after the non-secure core finishes the preparation work before the call, the non-secure core can save the context information of the non-secure core, call the secure call interface corresponding to the fourth target function, switch from the non-secure core to the secure core, and the secure core executes the fourth target function.
[0076] Specifically, the secure call interface corresponding to the fourth target function is the secure call interface located in the secure core that can call the fourth target function.
[0077] S440. In the case where the fourth target function has been executed, the non-secure core continues to execute the third target function.
[0078] In the embodiment of the present disclosure, after the fourth target function is executed, it can switch back from the secure core to the non-secure core through the SG instruction, and restore the previously saved context information of the non-secure core, and the non-secure core continues to execute the third target function.
[0079] It can be understood that based on the characteristics of the TrustZone mechanism, calling the fourth target function in the secure core from the third target function in the non-secure core cannot directly access through the address information of the fourth target function. In the embodiment of the present disclosure, the call needs to be implemented according to the principles described in S410-S440. When the three-target function in the non-secure core calls the fourth target function in the secure core, special SG instructions are required for the preparation operation before the jump, and the called secure call interface must be located within the NSC (Non-Secure Callable) area, and the NSC area serves as the transfer area for the non-secure core to jump to the secure core.
[0080] In yet another embodiment of the present disclosure, the method further includes: S510, the secure core runs the secure startup system to initialize the secure basic system.
[0081] In an embodiment of the present disclosure, when it is necessary to start a real-time operating system (i.e., RTOS), the secure core may first run the secure startup system (i.e., XOS_Boot_S) to execute the system initialization process of the secure basic system (i.e., XOS_Main_S).
[0082] S520, in the case where the address information of the non-secure startup system is provided to the secure basic system in the form of a macro in advance, when the secure core runs the secure basic system, the secure basic system calls the non-secure startup system in the form of a function pointer according to the address information of the non-secure startup system.
[0083] In an embodiment of the present disclosure, the code segment address information of the non-secure startup system (i.e., XOS_Boot_NS) needs to be provided to the secure basic system (i.e., XOS_Main_S) in the form of a macro in advance. Based on this, when the secure core runs the secure basic system, in the case where the secure basic system (which can be regarded as the first target function at this time) calls the entry function of the non-secure startup system (i.e., XOS_Boot_NS) (which can be regarded as the second target function at this time), the secure core saves the currently executed context information to the stack resource of the secure core, and sets the content in LR to a preset value. Furthermore, the secure basic system can set the MSP of the non-secure core according to the address information of the non-secure startup system, and call the entry function of the non-secure startup system in the form of a function pointer, and jump to the ResetHandler function of the non-secure startup system to start the non-secure startup system.
[0084] S530, the non-secure core runs the non-secure startup system to initialize the non-secure basic system.
[0085] In an embodiment of the present disclosure, the non-secure core may first run the non-secure startup system (i.e., XOS_Boot_NS) to execute the system initialization process of the non-secure basic system (i.e., XOS_Main_NS).
[0086] S540, the non-secure basic system initializes the real-time operating system and creates an APDU task, an eSE task, and an eSIM task.
[0087] In the embodiments of the present disclosure, during the operation of the non-secure core running the non-secure basic system (i.e., XOS_Main_NS), the initialization of the real-time operating system (i.e., RTOS) and the initialization of communication components such as queue semaphores can be completed, and an APDU task, an eSE task, and an eSIM task are created according to specific configuration information. These three RTOS tasks all run in the non-secure core and are managed by the real-time operating system, serving as the basis for the co-operation of the eSE system and the eSIM system.
[0088] Specifically, the APDU task, the eSE task, and the eSIM task are all RTOS tasks. Among them, the APDU task is used to process the commands and responses of the application protocol data unit to ensure the security of sensitive operations. The eSE task is used to process operations related to the eSE function. The eSIM task is used to process operations related to the eSIM function.
[0089] Exemplarily, Figure 4 is a flowchart of the RTOS startup process provided by the embodiments of the present disclosure. Due to the characteristic principles of TrustZone, to start the eSE system and the eSIM system, it is first necessary to start the RTOS as the scheduling manager of the two systems. The startup process of the real-time operating system is as Figure 4 shown. First, start from XOS_Boot_S and execute some system initialization processes of XOS_Main_S. After the initialization is completed, it is necessary to jump to the non-secure core to prepare for starting the RTOS. Therefore, the code segment address information of XOS_Boot_NS needs to be provided to XOS_Main_S in advance in the form of a macro. Based on this, XOS_Main_S can set the main stack pointer (MSP) of the non-secure core according to the provided code segment address information, and through the form of function pointers, combined with the register clear protection operation, call the entry function to jump to the ResetHandler function of XOS_Boot_NS to start XOS_Boot_NS. Then, XOS_Boot_NS jumps to XOS_Main_NS to realize the startup of XOS_Main_NS. In XOS_Main_NS, the initialization of the RTOS and the initialization of communication components such as queue semaphores are completed, and an APDU task, an eSE task, and an eSIM task are created according to specific configuration information.
[0090] In another embodiment of the present disclosure, the method further includes: S610. When the address information of the eSE entry function is provided to the eSE task in advance in the form of a macro, the eSE task calls the eSE entry function through the form of a function pointer according to the address information of the eSE entry function.
[0091] In the embodiments of the present disclosure, it is necessary to provide the code segment address information of the eSE entry function to the eSE task (i.e., eSE Task) in advance in the form of a macro. Based on this, when the non-secure core runs the eSE task, the eSE task can call the eSE entry function in the form of a function pointer according to the address information of the eSE entry function, so that the non-secure core runs the eSE entry function.
[0092] S620. The non-secure core executes the eSE entry function to initialize the eSE virtual machine and start the eSE system.
[0093] In the embodiments of the present disclosure, during the process of the non-secure core executing the eSE entry function, the eSE virtual machine can be initialized to start the eSE system running on the non-secure core.
[0094] Exemplarily, Figure 5 is a flowchart of the startup process of an eSE system provided by the embodiments of the present disclosure. Since the RTOS runs in the non-secure core, the eSE system can be started in the form of a direct function jump. As Figure 5 shown, the address information of the eSE entry function of the eSE system is provided to the eSE task in the form of a macro definition, and is called in the form of a function pointer to enter the eSE entry function, so as to perform the initialization operation of the eSE virtual machine, and then start the eSE system running on the non-secure core.
[0095] In another embodiment of the present disclosure, the method further includes: S710. When the address information of the eSIM entry function is provided to the eSIM task in advance in the form of a macro, the eSIM task calls the non-secure call interface corresponding to the secure function and passes the address information of the eSIM entry function into the non-secure call interface corresponding to the secure function, where the secure function is located in the secure core.
[0096] In the embodiments of the present disclosure, it is necessary to provide the code segment address information of the eSIM entry function to the eSIM task (i.e., eSIM Task) in advance in the form of a macro. In addition, a secure function (Secure Func) is defined to receive a function pointer of the eSIM entry function type and perform a jump call in the secure core. The Secure Func is encapsulated through the NSC area and converted into a secure call interface with an SG instruction and located in the NSC area, and the secure call interface is re-encapsulated to obtain a corresponding non-secure call interface. Based on this, when the non-secure core runs the eSIM task, the eSIM task first calls the non-secure call interface corresponding to the secure function and passes the address information of the eSIM entry function into the non-secure call interface corresponding to the secure function.
[0097] S720. The non-secure core executes the SG instruction.
[0098] In an embodiment of the present disclosure, before the non-secure call interface corresponding to the security function in the non-secure core (which can be regarded as the third target function at this time) calls the secure call interface corresponding to the security function in the secure core (which can be regarded as the fourth target function at this time), the non-secure core needs to perform some preparatory work before the call: execute the SG instruction so that the processor checks whether it is currently allowed to enter the secure core and whether there is sufficient permission to execute the requested fourth target function.
[0099] S730. The non-secure core calls the secure call interface corresponding to the security function through the non-secure call interface corresponding to the security function, and passes the address information of the eSIM entry function into the secure call interface corresponding to the security function.
[0100] In an embodiment of the present disclosure, after the non-secure core has completed the preparatory work before the call, the non-secure core can save the context information of the non-secure core, the secure call interface corresponding to the security function, and pass the address information of the eSIM entry function into the secure call interface corresponding to the security function, switch from the non-secure core to the secure core, and the secure core executes the secure call interface corresponding to the security function.
[0101] S740. The secure core calls the security function through the secure call interface corresponding to the security function.
[0102] S750. The secure core executes the security function so that the security function calls the eSIM entry function in the form of a function pointer according to the address information of the eSIM entry function.
[0103] S760. The secure core executes the eSIM entry function to initialize the eSIM virtual machine and start the eSIM system.
[0104] In an embodiment of the present disclosure, the security function in the secure core takes out the function pointer of the eSIM entry function in the passed formal parameters, calls the eSIM entry function in a secure environment, and during the process of the secure core executing the eSIM entry function, the eSIM virtual machine can be initialized to start the eSIM system running in the secure core.
[0105] Exemplarily, Figure 6 is a flowchart of the startup process of an eSIM system provided by an embodiment of the present disclosure. Since the eSIM system needs to be placed in the secure core to achieve the effect of isolating the operation from the eSE system in the non-secure core, its startup method needs to be designed based on the principles described in S510 - S540. As Figure 6As shown in the figure, first, start the eSIM task located in the non-secure core from the RTOS. Since the eSIM project is compiled after the eSIM task, the eSIM project needs to pass the address of the eSIM entry function to the eSIM task in the form of an absolute address through a macro. At this time, a calling problem occurs, which can be summarized as follows: The eSIM task located in the non-secure core cannot directly call the eSIM entry function in the secure core and will be intercepted by the system's security protection mechanism. Therefore, the embodiment of the present disclosure designs a method for starting the eSIM system in a transfer form: when the eSIM task of the RTOS receives the address information of the eSIM entry function passed by the eSIM project, it does not directly call it, but saves the address information of the eSIM entry function as a function pointer. Since the protection check for data access and function call in the secure core only occurs during access and call, the saving and passing of the address information of the eSIM entry function will not trigger a security alarm. Further, define a secure function (Secure Func) to receive the function pointer of the eSIM entry function type and implement a jump call in the secure core. Package Secure Func through the NSC area, convert it into a secure call interface with an SG instruction and located in the NSC area, and provide this secure call interface to the RTOS task layer and package it as a non-secure call interface. Based on the above preparations, the eSIM task in the RTOS passes the saved function pointer of the eSIM entry function to the non-secure call interface of Secure Func. This non-secure call interface passes this function pointer to the secure call interface of Secure Func. After being processed by the security gate SG, it jumps to the secure core. Secure Func in the secure core extracts the function pointer of the eSIM entry function in the passed formal parameter and calls it in a secure environment, and can successfully jump to the secure eSIM project. After a series of initialization operations, the eSIM virtual machine is started. Based on the above startup process, the function of successfully starting the eSIM system from the non-secure RTOS task is realized.
[0106] In summary, in the embodiments of the present disclosure, in combination with the TrustZone mechanism, the eSE system is placed in the non-secure core, and the eSIM system is placed in the secure core. The eSE system and the eSIM system are isolated and protected from the bottom layer through a security protection mechanism. The two systems have independent stack spaces, which can avoid stack conflict problems during operation; there is a perfect security protection mechanism for the two systems to access data and function calls from each other, which can avoid accidental data access caused by out-of-bounds and illegal operations, and protect the normal and independent operation of the two systems; the two systems have independent interrupt processing tables and interrupt registers, which can handle interrupts independently, and have higher security isolation compared to traditional unified interrupt processing. Based on this, the embodiments of the present disclosure can effectively improve the isolation security when the eSE system and the eSIM system run simultaneously on an integrated chip, ensure that the two parties do not affect each other, reduce new security concerns caused by non-isolation of the multi-in-one chip, and further promote the rapid and secure implementation of the eSE and eSIM multi-in-one chip as a mainstream industry solution. It helps the multi-in-one chip to have higher security while reducing costs and improving integration, and effectively improves the independent reliability of different industry solutions running together.
[0107] Figure 7 FIG. is a schematic structural diagram of an operation isolation device provided by an embodiment of the present disclosure. The operation isolation device can be understood as the above-mentioned eSE and eSIM combined device or some functional modules in the above-mentioned eSE and eSIM combined device. As Figure 7 shown, the operation isolation device includes:
[0108] A first saving module 710, configured to, when a first target function in the secure core calls a second target function in the non-secure core, the secure core saves the currently executed context information to the stack resource of the secure core, where the context information includes the content in the register and the return address;
[0109] A first setting module 720, configured to set the content in the LR to a preset value by the secure core;
[0110] A first execution module 730, configured to execute the second target function by the non-secure core;
[0111] A second execution module 740, configured to, when the second target function is executed, the secure core takes out the preset value from the LR, and under the indication of the preset value, takes out the context information from the stack resource of the secure core, and continues to execute the first target function based on the context information.
[0112] Optionally, the device further includes: a third execution module, configured to execute an SG instruction in the non-secure core when a third target function in the non-secure core calls a fourth target function in the secure core;
[0113] a first call module, configured to call, by the non-secure core, a secure call interface corresponding to the fourth target function;
[0114] a fourth execution module, configured to execute the fourth target function in the secure core;
[0115] a fifth execution module, configured to continue executing the third target function in the non-secure core when the execution of the fourth target function is completed.
[0116] Optionally, the device further includes: a first initialization module, configured to run, by the secure core, a secure startup system to initialize the secure basic system;
[0117] a second call module, configured to, when the address information of the non-secure startup system is provided to the secure basic system in the form of a macro in advance, call, by the secure basic system according to the address information of the non-secure startup system in the form of a function pointer, the non-secure startup system when the secure core runs the secure basic system;
[0118] a second initialization module, configured to run, by the non-secure core, the non-secure startup system to initialize the non-secure basic system;
[0119] a third initialization module, configured to initialize, by the non-secure basic system, the real-time operating system and create an APDU task, an eSE task, and an eSIM task.
[0120] Optionally, the device further includes: a third call module, configured to, when the address information of the eSE entry function is provided to the eSE task in the form of a macro in advance, call, by the eSE task according to the address information of the eSE entry function in the form of a function pointer, the eSE entry function;
[0121] a fourth initialization module, configured to execute, by the non-secure core, the eSE entry function to initialize the eSE virtual machine and start the eSE system.
[0122] Optionally, the device further includes: a third call module, configured to, when the address information of the eSIM entry function is provided to the eSIM task in the form of a macro in advance, call, by the eSIM task, a non-secure call interface corresponding to a secure function and pass the address information of the eSIM entry function into the non-secure call interface corresponding to the secure function, where the secure function is located in the secure core;
[0123] The sixth execution module is used for the non-secure core to execute the SG instruction;
[0124] The fourth call module is used for the non-secure core to call the secure call interface corresponding to the security function through the non-secure call interface corresponding to the security function, and transmit the address information of the eSIM entry function to the secure call interface corresponding to the security function;
[0125] The fifth call module is used for the secure core to call the security function through the secure call interface corresponding to the security function;
[0126] The seventh execution module is used for the secure core to execute the security function, so that the security function calls the eSIM entry function in the form of a function pointer according to the address information of the eSIM entry function;
[0127] The eighth execution module is used for the secure core to execute the eSIM entry function to initialize the eSIM virtual machine and start the eSIM system.
[0128] The device provided in this embodiment can execute the method of any of the above embodiments, and its execution manner and beneficial effects are similar, which will not be elaborated here.
[0129] This embodiment of the present disclosure also provides an electronic device, which includes: a memory in which a computer program is stored; a processor for executing the computer program, and when the computer program is executed by the processor, the method of any of the above embodiments can be implemented.
[0130] Exemplarily, Figure 8 is a schematic structural diagram of an electronic device in an embodiment of the present disclosure. Specifically refer to the following Figure 8 , which shows a schematic structural diagram of the electronic device 800 suitable for implementing the present disclosure. The electronic device 800 in the embodiment of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiments of the present disclosure.
[0131] As Figure 8As shown, the electronic device 800 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 801, which may perform various appropriate actions and processes according to a program stored in the read-only memory (ROM) 802 or a program loaded from the storage device 808 into the random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 are also stored. The processing device 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. The input / output (I / O) interface 805 is also connected to the bus 804.
[0132] Generally, the following devices may be connected to the I / O interface 805: an input device 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 may allow the electronic device 800 to communicate with other devices wirelessly or wireline to exchange data. Although Figure 8 the electronic device 800 with various devices is shown, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included.
[0133] Specifically, according to an embodiment of the present disclosure, the process described above with reference to the flowchart may be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program codes for performing the method shown in the flowchart. In such an embodiment, the computer program may be downloaded and installed from a network through the communication device 809, or installed from the storage device 808, or installed from the ROM 802. When the computer program is executed by the processing device 801, the above functions defined in the method of the embodiment of the present disclosure are executed.
[0134] It should be noted that the above-mentioned computer-readable medium in the present disclosure can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0135] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LAN"), wide area networks ("WAN"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.
[0136] The above-mentioned computer-readable medium can be included in the above-mentioned electronic device; or it can exist separately without being assembled into the electronic device.
[0137] The above computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to: when a first target function in the secure core calls a second target function in the non-secure core, the secure core saves the current execution context information to the stack resource of the secure core, where the context information includes the content in the register and the return address; the secure core sets the content in the LR to a preset value; the non-secure core executes the second target function; when the execution of the second target function is completed, the secure core retrieves the preset value from the LR and, under the indication of the preset value, retrieves the context information from the stack resource of the secure core, and continues to execute the first target function based on the context information.
[0138] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., by connecting through the Internet using an Internet service provider).
[0139] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.
[0140] The units involved in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the name of a unit does not constitute a limitation on the unit itself.
[0141] The functions described above herein can be performed, at least in part, by one or more hardware logic components. By way of example, and without limitation, the types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.
[0142] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0143] The embodiments of the present disclosure also provide a computer-readable storage medium having stored therein a computer program, which when executed by a processor can implement the method of any of the foregoing embodiments, and the execution manner and beneficial effects are similar and will not be elaborated herein.
[0144] It should be noted that, in this document, relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or sequence between these entities or operations. Moreover, the terms "comprising", "including" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the phrase "comprising a..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0145] The above are only specific embodiments of the present disclosure, enabling those skilled in the art to understand or implement the present disclosure. Various modifications to these embodiments will be obvious to those skilled in the art, and the general principles defined herein can be implemented in other embodiments without departing from the spirit or scope of the present disclosure. Therefore, the present disclosure will not be limited to these embodiments described herein, but rather will be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. An eSE and eSIM combination device, characterized in that: The eSE and eSIM combination device integrates the eSE function and the eSIM function in the same chip, and the processor in the chip is divided into a secure core and a non-secure core through the TrustZone mechanism; The security core includes an eSIM system, the eSIM system includes an eSIM virtual machine, an eSIM entry function, an eSIM stack resource, and an eSIM register, and the security core also includes a secure boot system and a secure base system of the Main system; The non-secure core includes an eSE system, the eSE system includes an eSE virtual machine, an eSE entry function, an eSE stack resource and an eSE register, and the non-secure core also includes a non-secure boot system and a non-secure basic system.
2. The eSE and eSIM combination device according to claim 1, characterized in that: The security basic system includes a basic library and a security call interface; The non-safety basic system includes a real-time operating system and a non-safety calling interface; The eSIM register and the eSE register both include: CONTROL, FAULTMASK, PRIMASK and BASEEPRI; The eSIM stack resources and the eSE stack resources both include: MSPLIM, PSPLIM, MSP and PSP.
3. A method for operating isolation, characterized in that: Applied to the eSE and eSIM combination device according to claim 1 or 2, the method comprises: In the case where the first target function in the secure core calls the second target function in the non-secure core, the secure core saves the currently executed context information to the stack resources of the secure core, wherein the context information includes the content in the register and the return address; The security core sets the content in the LR to a preset value; The non-safe core executes the second objective function; When the execution of the second target function is completed, the security core takes out the preset value from the LR, and takes out the context information from the stack resources of the security core under the instruction of the preset value, and continues to execute the first target function based on the context information.
4. The method according to claim 3, characterized in that The method further comprises: In the case where the third target function in the non-secure core calls the fourth target function in the secure core, the non-secure core executes the SG instruction; The non-safe core calls the safe calling interface corresponding to the fourth target function; The safety core executes the fourth objective function; When the fourth objective function is executed completely, the non-safe core continues to execute the third objective function.
5. The method according to claim 3 or 4, characterized in that: The method further comprises: The security core runs the secure boot system to initialize the security base system; In a case where the address information of the non-secure boot system is provided to the secure base system in advance in the form of a macro, when the secure core runs the secure base system, the secure base system calls the non-secure boot system in the form of a function pointer according to the address information of the non-secure boot system; The non-secure core runs the non-secure boot system to initialize the non-secure basic system; The non-secure basic system initializes the real-time operating system and creates an APDU task, an eSE task, and an eSIM task.
6. The method according to claim 5, characterized in that The method further comprises: In the case where the address information of the eSE entry function is provided to the eSE task in advance in the form of a macro, the eSE task calls the eSE entry function in the form of a function pointer according to the address information of the eSE entry function; The non-secure core executes the eSE entry function to initialize the eSE virtual machine and start the eSE system.
7. The method according to claim 5, characterized in that The method further comprises: In a case where the address information of the eSIM entry function is provided to the eSIM task in advance in the form of a macro, the eSIM task calls a non-secure call interface corresponding to a secure function, and passes the address information of the eSIM entry function to the non-secure call interface corresponding to the secure function, wherein the secure function is located in the secure core; The non-safe core executes the SG instruction; The non-secure core calls the secure calling interface corresponding to the secure function through the non-secure calling interface corresponding to the secure function, and passes the address information of the eSIM entry function to the secure calling interface corresponding to the secure function; The security core calls the security function through the security calling interface corresponding to the security function; The security core executes the security function so that the security function calls the eSIM entry function in the form of a function pointer according to the address information of the eSIM entry function; The security core executes the eSIM entry function to initialize the eSIM virtual machine and start the eSIM system.
8. A running isolation device, characterized in that: include: Applicable to the eSE and eSIM combination device according to claim 1 or 2, the device comprising: A first saving module is used for, when the first target function in the security core calls the second target function in the non-security core, the security core saves the currently executed context information to the stack resources of the security core, wherein the context information includes the content in the register and the return address; A first setting module, used for the security core to set the content in the LR to a preset value; A first execution module, configured for the non-safe core to execute the second target function; The second execution module is used to, when the execution of the second target function is completed, cause the security core to take out the preset value from the LR, and under the instruction of the preset value, take out the context information from the stack resources of the security core, and continue to execute the first target function based on the context information.
9. An electronic device, characterized in that: include: A processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the processor executes the method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Cited By
UICC application initiative command processing method under multi-file concurrent activation scene in ESIM
CN122269265A