Electronic device for storing secure data and operating method thereof

By designing a structure of two processors and three memory in an electronic device, the problem of secure data processing and storage in a wireless communication system is solved, and data sharing and storage between secure and non-secure environments is realized, ensuring the security and reliability of data.

CN120202471APending Publication Date: 2025-06-24SAMSUNG ELECTRONICS CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202380078175.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-11-25
Filing Date
2023-11-21
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

In wireless communication systems, prior art is difficult to effectively process and store secure data, especially in electronic devices, where encrypted data is required to be shared between secure and non-secure environments.

Method used

An electronic device is designed, including two processors and three memory. The first processor operates in a non-secure environment and the second processor operates in a secure environment. The first memory is used for a non-secure environment, the second memory is used for a secure environment, and the third memory is shared in both environments. The device encrypts the secure data through the second processor and stores the encrypted portion in the third memory while storing the information required for encryption and decryption in the second memory. The first processor stores the encrypted portion in the third memory in the first memory.

Benefits of technology

A solution to effectively share and store secure data between secure and non-secure environments ensures the security and reliability of data.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120202471A_ABST
    Figure CN120202471A_ABST
Patent Text Reader

Abstract

According to one embodiment, an electronic device may include: a first processor operating in a generally non-secure environment; a second processor operating in a secure environment; a first memory allocated to a generally non-secure environment; a second memory allocated to the secure environment; and a third memory shared between the generally non-secure environment and the secure environment. The second processor may be configured to encrypt at least a portion of secure data to generate an encrypted portion, where the secure data is generated by a trusted application running in a secure environment; storing the encrypted portion in a third memory; and storing, in a second memory, first information for encrypting at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data. The first processor may be configured to store the encrypted portion stored in the third memory in the first memory.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to an electronic device for storing secure data and an operating method thereof. Background Art

[0002] In a wireless communication system, an electronic device (e.g., a user equipment (UE)) may access a wireless communication network and use a voice communication service or a data communication service while being in a fixed position or moving. More and more services and additional functions as well as the voice communication service or the data communication service may be provided through the electronic device. In order to provide various services and additional functions to the electronic device, an appropriate authentication process is required, and data that requires security needs to be processed securely.

[0003] Generally, a universal integrated circuit card (UICC) is inserted into the electronic device, and authentication is performed between the electronic device and a server of a mobile network operator (MNO) through a universal subscriber identity module (USIM) installed in the UICC. If a user of the electronic device subscribes to a wireless communication service provided by the MNO, the MNO may provide the UICC (e.g., a SIM card or a USIM card) to the user. The user may insert the provided UICC into his / her own electronic device. Recently, a new type of UICC called an embedded UICC (eUICC) has been proposed, which is configured to remotely install a profile for providing a communication service through a network without replacing the UICC even when the user changes the MNO. The eUICC may be manufactured as a pre-installed UICC chip fixed in the terminal during the terminal manufacturing process. An integrated SIM (iSIM) that is more advanced than the eUICC has been proposed, in which the SIM function is integrated into the hardware of the electronic device and is configured in the form of a system on a chip (SOC).

[0004] The iSIM can be used in various electronic devices that may have a structure in which it is not easy to physically attach / detach the UICC, such as machine-to-machine (M2M) terminals or device-to-device (D2D) terminals and Internet of Things (IoT) devices as well as conventional wireless terminals (such as mobile phones). Summary of the Invention

[0005] According to one or more embodiments, an electronic device includes: a first processor operating in a general non-secure environment; a second processor operating in a secure environment; a first memory allocated to the general non-secure environment; a second memory allocated to the secure environment; and a third memory shared between the general non-secure environment and the secure environment, wherein the second processor is configured to: encrypt at least a portion of secure data generated by a trusted application executed in the secure environment to generate an encrypted portion, store the encrypted portion in the third memory, and store first information used to encrypt at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data in the second memory, and wherein the first processor is configured to store the encrypted portion stored in the third memory in the first memory.

[0006] According to one or more embodiments, a method for operating an electronic device is provided, the method including: executing, by a first processor operating in a secure environment, a trusted application in the secure environment and generating secure data; encrypting, by the first processor, at least a portion of the generated secure data to generate an encrypted portion and storing the encrypted portion in a first memory shared between the secure environment and the general non-secure environment; storing, by the first processor, first information used to encrypt at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data in a second memory allocated to the secure environment; and storing, by a second processor operating in the general non-secure environment, the encrypted portion stored in the first memory in a third memory allocated to the general non-secure environment.

[0007] According to one or more embodiments, a non-transitory computer-readable medium having instructions stored therein is provided, which when executed by at least one processor in an electronic device, causes the at least one processor to perform a method for operating the electronic device, the method including: executing a trusted application in a secure environment and generating secure data; encrypting at least a portion of the generated secure data to generate an encrypted portion and storing the encrypted portion in a first memory shared between the secure environment and the general non-secure environment; storing first information used to encrypt at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data in a second memory allocated to the secure environment; and storing the encrypted portion stored in the first memory in a third memory allocated to the general non-secure environment. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] Figure 1 is a block diagram illustrating an electronic device 100 in a network environment according to one or more embodiments;

[0009] Figure 2is a block diagram showing a program according to one or more embodiments;

[0010] Figure 3 is a block diagram showing program modules according to one or more embodiments;

[0011] Figure 4 is a view showing an example of an operating environment of program modules of an electronic device according to one or more embodiments;

[0012] Figure 5 is a flowchart showing an example of an operation of an electronic device according to one or more embodiments;

[0013] Figure 6 is showing according to one or more embodiments Figure 5 a view of an example of an operation of an electronic device;

[0014] Figure 7 is a flowchart showing an example of an operation of an electronic device according to one or more embodiments;

[0015] Figure 8 is showing according to one or more embodiments Figure 7 a view of an example of an operation of an electronic device; and

[0016] Figure 9 is a view showing an example of a format of security data stored in a memory of an electronic device according to one or more embodiments. Detailed Description

[0017] Figure 1 is a block diagram showing an electronic device 101 in a network environment 100 according to various embodiments.

[0018] Referring to Figure 1, the electronic device 101 in the network environment 100 may communicate with the electronic device 102 via the first network 198 (e.g., a short-range wireless communication network), or communicate with the electronic device 104 or the server 108 via the second network 199 (e.g., a long-range wireless communication network). According to one or more embodiments, the electronic device 101 may communicate with the electronic device 104 via the server 108. According to one or more embodiments, the electronic device 101 may include a processor 120, a memory 130, an input module 150, a sound output module 155, a display module 160, an audio module 170, a sensor module 176, an interface 177, a connection end 178, a haptic module 179, a camera module 180, a power management module 188, a battery 189, a communication module 190, a subscriber identity module (SIM) 196, or an antenna module 197. In one or more embodiments, at least one of the above components (e.g., the connection end 178) may be omitted from the electronic device 101, or one or more other components may be added to the electronic device 101. According to one or more embodiments, some of the above components (e.g., the sensor module 176, the camera module 180, or the antenna module 197) may be integrated into a single component (e.g., the display module 160).

[0019] The processor 120 may run software (e.g., the program 140) to control at least one other component (e.g., a hardware component or a software component) connected to the processor 120 of the electronic device 101, and may perform various data processing or calculations. According to one or more embodiments, as at least part of the data processing or calculation, the processor 120 may store a command or data received from another component (e.g., the sensor module 176 or the communication module 190) in the volatile memory 132, process the command or data stored in the volatile memory 132, and store the resulting data in the non-volatile memory 134. According to one or more embodiments, the processor 120 may include a main processor 121 (e.g., a central processing unit (CPU) or an application processor (AP)) or an auxiliary processor 123 (e.g., a graphics processing unit (GPU), a neural processing unit (NPU), an image signal processor (ISP), a sensor hub processor, or a communication processor (CP)) that is operationally independent of or combined with the main processor 121. For example, when the electronic device 101 includes the main processor 121 and the auxiliary processor 123, the auxiliary processor 123 may be configured to consume less power than the main processor 121 or be configured to be dedicated to a specified function. The auxiliary processor 123 may be implemented separately from the main processor 121 or as part of the main processor 121.

[0020] When the main processor 121 is in an inactive (e.g., sleep) state, the auxiliary processor 123 (instead of the main processor 121) may control at least some of the functions or states related to at least one of the components of the electronic device 101 (e.g., the display module 160, the sensor module 176, or the communication module 190), or when the main processor 121 is in an active state (e.g., running an application), the auxiliary processor 123 may control, together with the main processor 121, at least some of the functions or states related to at least one of the components of the electronic device 101 (e.g., the display module 160, the sensor module 176, or the communication module 190). According to one or more embodiments, the auxiliary processor 123 (e.g., an image signal processor or a communication processor) may be implemented as part of another component (e.g., the camera module 180 or the communication module 190) that is functionally related to the auxiliary processor 123. According to one or more embodiments, the auxiliary processor 123 (e.g., a neural processing unit) may include a hardware structure dedicated to artificial intelligence model processing. The artificial intelligence model may be generated via machine learning. For example, such learning may be performed by the electronic device 101 where the artificial intelligence is executed or via a separate server (e.g., the server 108). The learning algorithms may include, but are not limited to, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning. The artificial intelligence model may include multiple artificial neural network layers. The artificial neural network may be a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), or a deep Q-network, or a combination of two or more of them, but is not limited thereto. Additionally or alternatively, the artificial intelligence model may include a software structure in addition to the hardware structure.

[0021] The memory 130 may store various data used by at least one component of the electronic device 101 (e.g., the processor 120 or the sensor module 176). The various data may include, for example, software (e.g., the program 140) and input data or output data for commands related thereto. The memory 130 may include a volatile memory 132 or a non-volatile memory 134.

[0022] The program 140 may be stored as software in the memory 130, and the program 140 may include, for example, an operating system (OS) 142, middleware 144, or an application 146.

[0023] The input module 150 may receive commands or data to be used by other components of the electronic device 101 (e.g., the processor 120) from the outside of the electronic device 101 (e.g., a user). The input module 150 may include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus).

[0024] The sound output module 155 may output a sound signal to the outside of the electronic device 101. The sound output module 155 may include, for example, a speaker or a receiver. The speaker may be used for general purposes such as playing multimedia or playing a record. The receiver may be used for receiving an incoming call. According to an embodiment, the receiver may be implemented separately from the speaker or as part of the speaker.

[0025] The display module 160 may visually provide information to the outside of the electronic device 101 (e.g., to a user). The display module 160 may include, for example, a display, a holographic device, or a projector, and a control circuit for controlling a corresponding one of the display, the holographic device, and the projector. According to one or more embodiments, the display module 160 may include a touch sensor configured to detect a touch or a pressure sensor configured to measure an intensity of a force caused by the touch.

[0026] The audio module 170 may convert a sound into an electrical signal and vice versa. According to one or more embodiments, the audio module 170 may obtain a sound via the input module 150, or output a sound via the sound output module 155 or a headset of an external electronic device (e.g., the electronic device 102) directly (e.g., wiredly) or wirelessly coupled to the electronic device 101.

[0027] The sensor module 176 may detect an operating state of the electronic device 101 (e.g., power or temperature) or an environmental state outside the electronic device 101 (e.g., a state of a user), and then generate an electrical signal or a data value corresponding to the detected state. According to one or more embodiments, the sensor module 176 may include, for example, a gesture sensor, a gyro sensor, an atmospheric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an infrared (IR) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0028] The interface 177 may support one or more specific protocols used to directly (e.g., wiredly) or wirelessly couple the electronic device 101 to an external electronic device (e.g., the electronic device 102). According to one or more embodiments, the interface 177 may include, for example, a high-definition multimedia interface (HDMI), a universal serial bus (USB) interface, a secure digital (SD) card interface, or an audio interface.

[0029] The connection terminal 178 may include a connector through which the electronic device 101 may be physically connected to an external electronic device (e.g., the electronic device 102). According to one or more embodiments, the connection terminal 178 may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headset connector).

[0030] The haptic module 179 may convert an electrical signal into a mechanical stimulus (e.g., vibration or motion) or an electrical stimulus that can be recognized by the user via his sense of touch or kinesthesia. According to one or more embodiments, the haptic module 179 may include, for example, a motor, a piezoelectric element, or an electrical stimulator.

[0031] The camera module 180 may capture still images or moving images. According to one or more embodiments, the camera module 180 may include one or more lenses, an image sensor, an image signal processor, or a flash.

[0032] The power management module 188 may manage the power supply to the electronic device 101. According to one or more embodiments, the power management module 188 may be implemented as at least part of, for example, a power management integrated circuit (PMIC).

[0033] The battery 189 may supply power to at least one component of the electronic device 101. According to one or more embodiments, the battery 189 may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0034] The communication module 190 may support establishing a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device 101 and an external electronic device (e.g., the electronic device 102, the electronic device 104, or the server 108), and perform communication via the established communication channel. The communication module 190 may include one or more communication processors capable of operating independently of the processor 120 (e.g., an application processor (AP)), and support direct (e.g., wired) communication or wireless communication. According to one or more embodiments, the communication module 190 may include a wireless communication module 192 (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module 194 (e.g., a local area network (LAN) communication module or a power line communication (PLC) module). Each of these communication modules may communicate via a first network 198 (e.g., a short-range communication network, such as Bluetooth TM, a wireless fidelity (Wi-Fi) direct connection, or an Infrared Data Association (IrDA), or a second network 199 (e.g., a long-distance communication network such as a traditional cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a local area network (LAN) or a wide area network (WAN))) communicates with an external electronic device 104. These various types of communication modules may be implemented as a single component (e.g., a single chip), or these various types of communication modules may be implemented as multiple separate components (e.g., multiple chips). The wireless communication module 192 may identify or authenticate an electronic device 101 in a communication network (such as the first network 198 or the second network 199) using user information (e.g., an International Mobile Subscriber Identity (IMSI)) stored in the user identification module 196.

[0035] The wireless communication module 192 may support a 5G network after a 4G network and next-generation communication technologies (e.g., a New Radio (NR) access technology). The NR access technology may support enhanced mobile broadband (eMBB), massive machine type communication (mMTC), or ultra-reliable low-latency communication (URLLC). The wireless communication module 192 may support a high frequency band (e.g., a millimeter wave band) to achieve, for example, a high data transfer rate. The wireless communication module 192 may support various technologies for ensuring performance on the high frequency band, such as, for example, beamforming, massive multiple-input multiple-output (massive MIMO), full-dimensional MIMO (FD-MIMO), array antennas, analog beamforming, or massive antennas. The wireless communication module 192 may support various requirements specified in the electronic device 101, an external electronic device (e.g., the electronic device 104), or a network system (e.g., the second network 199). According to one or more embodiments, the wireless communication module 192 may support a peak data rate for implementing eMBB (e.g., 20 Gbps or greater), a loss coverage for implementing mMTC (e.g., 164 dB or less), or a U-plane latency for implementing URLLC (e.g., 0.5 ms or less for each of downlink (DL) and uplink (UL), or a round-trip of 1 ms or less).

[0036] The antenna module 197 may transmit signals or power to the outside (e.g., an external electronic device) or receive signals or power from the outside (e.g., an external electronic device). According to one or more embodiments, the antenna module 197 may include an antenna, and the antenna may include a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a printed circuit board (PCB)). According to one or more embodiments, the antenna module 197 may include a plurality of antennas (e.g., an antenna array). In this case, at least one antenna suitable for a communication scheme to be used in a communication network (such as the first network 198 or the second network 199) may be selected from the plurality of antennas by, for example, the communication module 190. Subsequently, signals or power may be transmitted or received between the communication module 190 and an external electronic device via the selected at least one antenna. According to one or more embodiments, additional components (e.g., a radio frequency integrated circuit (RFIC)) other than the radiator may be further formed as part of the antenna module 197.

[0037] According to one or more various embodiments, the antenna module 197 may form a millimeter-wave antenna module. According to one or more embodiments, the millimeter-wave antenna module may include a printed circuit board, a radio frequency integrated circuit (RFIC), and a plurality of antennas (e.g., an array antenna), wherein the RFIC is disposed on a first surface (e.g., a bottom surface) of the printed circuit board or adjacent to the first surface and capable of supporting a specified high-frequency band (e.g., a millimeter-wave band), and the plurality of antennas are disposed on a second surface (e.g., a top surface or a side surface) of the printed circuit board or adjacent to the second surface and capable of transmitting or receiving signals of the specified high-frequency band.

[0038] At least some of the above components may be interconnected via an inter-peripheral communication scheme (e.g., a bus, a general-purpose input / output (GPIO), a serial peripheral interface (SPI), or a mobile industry processor interface (MIPI)) and communicatively transmit signals (e.g., commands or data) therebetween.

[0039] According to one or more embodiments, commands or data may be sent or received between the electronic device 101 and an external electronic device 104 via a server 108 coupled to a second network 199. Each of the external electronic device 102 or the external electronic device 104 may be a device of the same type as the electronic device 101 or a device of a different type from the electronic device 101. According to one or more embodiments, all or some of the operations running on the electronic device 101 may be run on one or more of the external electronic device 102, the external electronic device 104, or the server 108. For example, if the electronic device 101 is to automatically perform a function or service or is to perform a function or service in response to a request from a user or another device, the electronic device 101 may request one or more of the external electronic devices to perform at least part of the function or service instead of running the function or service, or in addition to running the function or service, the electronic device 101 may also request one or more of the external electronic devices to perform at least part of the function or service. The one or more external electronic devices that receive the request may perform the requested at least part of the function or service or perform additional functions or additional services related to the request and send the result of the execution to the electronic device 101. The electronic device 101 may provide the result as at least part of a reply to the request with or without further processing of the result. For this purpose, for example, cloud computing technology, distributed computing technology, mobile edge computing (MEC) technology, or client-server computing technology may be used. The electronic device 101 may use, for example, distributed computing or mobile edge computing to provide ultra-low latency services. In one or more embodiments, the external electronic device 104 may include an Internet of Things (IoT) device. The server 108 may be an intelligent server using machine learning and / or neural networks. According to one or more embodiments, the external electronic device 104 or the server 108 may be included in the second network 199. The electronic device 101 may be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology or IoT-related technology.

[0040] Figure 2 FIG. 200 is a block diagram showing a program 140 according to one or more embodiments. According to one or more embodiments, the program 140 may include an operating system (OS) 142, middleware 144, or an application 146 that can run on the OS 142 for controlling one or more resources of the electronic device 101. The OS 142 may include, for example, Android TM , iOS TM , Windows TM , Symbian TM , Tizen TM , or BadaTM At least a part of Program 140 may be pre-loaded onto Electronic Device 101 (e.g., during manufacturing), or may be downloaded or updated by an external electronic device (e.g., Electronic Device 102 or 104 or Server 108) in the environment where the user uses the electronic device.

[0041] OS 142 may control (e.g., allocate or reclaim) system resources (e.g., a processor, memory, or power) of Electronic Device 101. Additionally or alternatively, OS 142 may include one or more drivers to drive other hardware devices of Electronic Device 101, such as Input Device 150, Sound Output Device 155, Display Device 160, Audio Module 170, Sensor Module 176, Interface 177, Haptic Module 179, Camera Module 180, Power Management Module 188, Battery 189, Communication Module 190, User Identification Module 196, or Antenna Module 197.

[0042] Middleware 144 may provide various functions to Application 146 such that Application 146 can use functions or information provided from one or more resources of Electronic Device 101. Middleware 144 may include, for example, Application Manager 201, Window Manager 203, Multimedia Manager 205, Resource Manager 207, Power Manager 209, Database Manager 211, Package Manager 213, Connection Manager 215, Notification Manager 217, Location Manager 219, Graphics Manager 221, Security Manager 223, Phone Manager 225, or Voice Recognition Manager 227. Application Manager 201 may manage, for example, the life cycle of Application 146. Window Manager 203 may manage, for example, graphical user interface (GUI) resources used on the screen. Multimedia Manager 205 may recognize, for example, the format required to play a media file and encode or decode the media file using a codec suitable for the corresponding format. Resource Manager 207 may manage, for example, the source code or memory space of Application 146. Power Manager 209 may manage, for example, the capacity, temperature, or power of the battery and use such corresponding information to determine and provide power information required for the operation of Electronic Device 101. According to one or more embodiments, Power Manager 209 may work in cooperation with the basic input / output system (BIOS).

[0043] The database manager 211 may generate, search, or change a database to be used in the application 146. The package manager 213 may manage, for example, the installation or update of an application distributed in the form of a package file. The connection manager 215 may manage a wireless or wired connection, for example, between the electronic device 101 and an external electronic device. The notification manager 217 may provide a function for notifying a user of an event that has occurred (e.g., a call, a message, or an alert), for example. The location manager 219 may manage location information about the electronic device 101, for example. The graphics manager 221 may manage, for example, graphic effects to be provided to a user and their related user interfaces. The security manager 223 may provide system security or user authentication, for example. The phone manager 225 may manage, for example, the voice call function or the video call function of the electronic device 101. The voice recognition manager 227 may send voice data of a user, for example, to the server 108 and receive a command corresponding to a function to be executed on the electronic device 101 based on the voice data or text data converted from the voice data. According to one or more embodiments, the middleware 244 may dynamically delete some existing components or add new components. According to one or more embodiments, at least a part of the middleware 144 may be included as a part of the OS 142 or may be implemented in software separate from the OS 142.

[0044] The application 146 may include, for example, applications such as a home page 251, a dialer 253, SMS / MMS 255, instant messaging (IM) 257, a browser 259, a camera 261, an alarm 263, contacts 265, voice recognition 267, an email 269, a calendar 271, a media player 273, an album 275, a watch 277, health 279 (e.g., measuring exercise level or blood sugar), or environmental information 281 (e.g., air pressure, humidity, or temperature information). According to one or more embodiments, the application 146 may further include an information exchange application configured to support or facilitate information exchange between the electronic device 101 and an external electronic device. The information exchange application may include, for example, a notification forwarding application for sending specified information (e.g., a call, a message, or an alert) to an external electronic device or a device management application for managing an external electronic device. The notification forwarding application may send notification information corresponding to an event (e.g., receipt of an email) occurring in another application (e.g., the email application 269) of the electronic device 101 to an external electronic device, or the notification forwarding application may receive notification information from an external electronic device and provide the notification information to a user of the electronic device 101. The device management application may control the power (e.g., turn on or off) or functions (e.g., adjustment of brightness, resolution, or focus) of an external electronic device or some of its components (e.g., a display device or a camera module of the external electronic device). Additionally or alternatively, the device management application may support the installation, deletion, or update of an application running on the external electronic device.

[0045] In the following, an example of the configuration of an electronic device (e.g., Figure 1 electronic device 101) according to various embodiments is described. Since the description of the electronic device 101 combined with Figure 1 can be applied to the electronic devices described below, repeated descriptions are not given.

[0046] Figure 3 is a view showing an example of the configuration of an electronic device 101 according to one or more embodiments. However, as understood by those of ordinary skill in the art, the electronic device 101 can be implemented to include more or fewer components than those Figure 3 shown. The following refers to Figure 4 for description Figure 3 .

[0047] Figure 4 is a view showing an example of the operating environment of program modules according to an electronic device (e.g., Figure 1 electronic device 101) according to one or more embodiments.

[0048] Referring to Figure 4 , the program module 400 may include a Rich Execution Environment (REE) 410 and a Trusted Execution Environment (TEE) 420. For example, the REE 410 and the TEE 420 may be divided either in hardware or in software. In one or more examples, the REE 410 and the TEE 420 may be physically separated and / or separated in software. The REE 410 may be an environment in which a general-purpose operating system (e.g., Figure 2 operating system 242) runs. For example, the Android operating system, the Windows operating system, and the Linux operating system or any other operating system known to those of ordinary skill in the art may be run in the REE 410. The TEE 420 may be an environment in which a securely and reliably protected operating system (e.g., a secure operating system) runs. For example, secure operating systems such as Qualcomm's QSee and Trustonic's Kinibi may be run in the TEE 420. According to one or more embodiments, an application supporting the iSIM function may be run in the TEE420. Data processing based on the secure operating system may be securely and reliably executed in the TEE 420. The TEE 420 may be implemented in various ways, such as a trust zone, a secure execution environment, a platform security processor, trusted execution technology, software protection extensions, or any other implementation configuration known to those of ordinary skill in the art. As understood by those of ordinary skill in the art, there is no limitation in the implementation configuration.

[0049] According to one or more embodiments, the REE 410 may include an application layer 411, a framework layer 412, and a kernel layer 413. In the application layer 411, various applications (e.g., Figure 2 application 246) may be run. In the framework layer 412, functions that support the operation of the application and services provided by the operating system may be run. The kernel layer 413 may be a layer in which core functions of the operating system run. The kernel layer 413 may control or manage system resources for executing operations or functions implemented in other programs. In addition, the kernel layer 413 may provide an interface configured to control or manage system resources by accessing various components of the electronic device 101.

[0050] According to one or more embodiments, the TEE 420 may include a trusted application layer 421, a trusted framework layer 422, and a secure operating system (OS) kernel layer 423. In the trusted application layer 421, trusted applications may be run. According to one or more embodiments, the electronic device 101 may run an application that executes the iSIM function in the trusted application layer 421. The trusted application may generate, send, receive, and store data that requires security during the execution of the application, which will be described in more detail below. In the trusted framework layer 422, an operating system (e.g., a secure operating system) that operates in the TEE 420 may be run. The secure OS kernel layer 423 may be a layer in which core functions of the secure operating system run. The secure OS kernel layer 423 may control or manage system resources for executing operations or functions implemented in the trusted application or the secure operating system.

[0051] In the hardware layer 430, various hardware of the electronic device 101 (e.g., the memory 330 and the processor 320) may be run.

[0052] The processor 320 may include a first processor 321 and a second processor 322. According to one or more embodiments, the first processor 321 and the second processor 322 may perform operations executed in a plurality of execution environments isolated from each other (e.g., REE 410 and TEE 420). For example, the plurality of execution environments may be implemented as execution environments isolated in software, may be implemented as execution environments isolated in hardware, or may be implemented as a combination of both. According to one or more embodiments, each of the first processor 321 and the second processor 322 may operate in at least one of the plurality of execution environments to perform specified operations and / or control at least one hardware component included in the electronic device 101. According to one or more embodiments, the first processor 321 may include an application processor (AP) and may perform operations executed in the REE 410. According to one or more embodiments, the second processor 322 may include a security processor (SP) and may perform operations executed in the TEE 420. Operations of the processor 320 (e.g., the first processor 321 and the second processor 322) described below may be executed according to the execution of modules stored in the memory 330. For example, at least some of the modules may be implemented (e.g., executed) in the form of software, firmware, or a combination of at least two of them. For example, the modules may be implemented in the form of an application, a program, computer code, instructions, routines, or processes executable by the processor 320. Therefore, when the modules are executed by the processor 320, the modules may trigger the processor 320 to perform operations associated with the modules (or functions provided by the modules). Therefore, when a specific module is described as performing an operation below, it may be interpreted that the processor 320 performs the operation when executing the specific module. In one or more examples, the modules may be implemented as part of a specific application. In one or more examples, without being limited to what is described and / or shown, each module may be implemented as a hardware device (e.g., a processor or a control circuit) separate from the processor 320.

[0053] The memory 330 may include a first memory 331, a second memory 332, a third memory 333, and a fourth memory 334.

[0054] The first memory 331 (e.g., Figure 1At least a portion of the non-volatile memory 138) may be a non-secure memory and may be a non-volatile memory. The first memory 332 may store data output from an application running in the application layer 311 of the REE 410. In one or more embodiments, the application may be executed by the first processor 321 in the application layer 411, and the first processor 321 may store data generated during the execution of the application in the first memory 332 through the kernel layer 413. In one or more embodiments, the first processor 321 may read data required during the execution of the application from the first memory 331 through the kernel layer 413.

[0055] The second memory 332 may be a volatile memory and may be a memory shared by the REE 410 and the TEE 420. The second memory 332 may be a dynamic random access memory (DRAM). The second memory 332 may temporarily store at least a portion of the secure data output from a trusted application running in the trusted application layer 421 under the control of the first processor 321 and the second processor 322. In one or more embodiments, the trusted application may be executed by the second processor 322 in the trusted application layer 421. The second processor 322 may send a request for data to the first processor 321 through the mailbox of the secure OS kernel layer 423 during the execution of the trusted application. The first processor 321 may read the data stored in the first memory 331 through the daemon process and may temporarily store the read data in the second memory 332 when the currently executing daemon process receives the request from the second processor 322 through the mailbox of the kernel layer 413. The second processor 322 may read the data temporarily stored in the second memory 332 through the secure OS kernel layer 423 and may send the read data to the trusted application layer 421. In one or more embodiments, the trusted application may be executed by the second processor 322 in the trusted application layer 421. The second processor 322 may store the secure data generated during the execution of the trusted application in the second memory 332 and may request the first processor 321 to store the secure data temporarily stored in the second memory 332 through the mailbox of the secure OS kernel layer 423. When the currently executing daemon process receives the request from the second processor 322 through the mailbox of the kernel layer 413, the first processor 321 may read the secure data temporarily stored in the second memory 332 through the daemon process and store the read secure data in the first memory 331. The request from the second processor 322 may include the address of the second memory 332 for storing the secure data.

[0056] The third memory 333 may be a volatile memory (e.g., Figure 1a volatile memory 132), and may have a lower storage capacity than the first memory 331. The third memory 333 may be a static random access memory (SRAM). The third memory 333 may temporarily store at least a part of the security data output from the trusted applications running in the trusted application layer 421. In one or more embodiments, the trusted applications may be executed by the second processor 322 in the trusted application layer 421, and the second processor 322 may temporarily store at least a part of the security data generated when executing the trusted applications in the third memory 333 through the secure OS kernel layer 423. In one or more embodiments, under the control of the second processor 322, the data stored in the third memory 333 may be encrypted and copied (e.g., swapped out) to the second memory 332, and the data stored in the second memory 332 may be decrypted and copied (e.g., swapped in) to the third memory 333.

[0057] In one or more embodiments, the fourth memory 334 (e.g., Figure 1 at least a part of the non-volatile memory 138) may be a non-volatile memory and may be a secure memory. The fourth memory 334 may store at least a part of the security data output from the trusted applications running in the trusted application layer 421. In one or more embodiments, the trusted applications may be executed by the second processor 322 in the trusted application layer 421, and the second processor 322 may temporarily store at least a part of the security data generated when executing the trusted applications in the fourth memory 334 through the secure OS kernel layer 423. The fourth memory 334 may be a storage space that infrequently performs functions of reading, modifying, or deleting data. The electronic device 101 may be configured to allow access to the fourth memory 334 only for a specific instruction set. For example, the data of the fourth memory 334 may be read, modified, or deleted according to instructions from the trusted applications. In addition, the data of the fourth memory 334 may not be read, modified, or deleted according to instructions from general applications other than the trusted applications. According to one or more embodiments, the information used when encrypting the security data may be stored in the fourth memory 334. The information stored in the fourth memory 334 may be used to decrypt the security data that will be encrypted later. This will be described in more detail below.

[0058] According to one or more embodiments, the electronic device 101 may be implemented to perform operations (or functions) in multiple execution environments based on independently implemented hardware (e.g., memories 331 to 334 and / or processors 321 and 322). According to one or more embodiments, different hardware associated with different permissions may be allocated for each of the multiple execution environments (e.g., REE 410 and TEE 420). For example, referring to Figure 4, the hardware devices located to the left of the dashed line can be allocated to the REE 410 (or driven in the REE 410), and the hardware devices located to the right can be allocated to the TEE 420 (or driven in the TEE 420). For example, referring to Figure 4 , different memories 331 to 334 can be allocated for each of multiple execution environments (e.g., the REE 410 and the TEE 420). The first processor 321 can execute a first operating system in the REE 410 to perform at least one operation, and can read data from / write data to the first memory 331 allocated to the REE 410. The second processor 322 can execute a second operating system separate and independent from the first operating system of the REE 410 in the TEE 420 to perform at least one operation, and can read data from / write data to the third memory 323 and the fourth memory 334 allocated to the TEE 420. According to one or more embodiments, the permissions and / or security for the TEE 420 can be higher than those for the REE 410. In one or more examples, the second processor 322 can access the first memory 331 allocated to the REE 410 from the TEE 420 to read and write data, but can restrict the first processor 321 in the REE 410 from accessing the fourth memory 334 allocated to the TEE 420. For example, the first processor 321 cannot write data to the fourth memory 334 or read the data stored in the fourth memory 334. According to one or more embodiments, the REE 410 and the TEE 420 can be allowed to access the second memory 332. For example, the first processor 321 can write data to the second memory 332 or read the data stored in the second memory 332 in the REE 410. For example, the second processor 322 can write data to the second memory 332 or read the data stored in the second memory 332 in the TEE 420.

[0059] Hereinafter, examples of the operation of the electronic device 101 according to one or more embodiments are described.

[0060] According to one or more embodiments, the electronic device 101 may encrypt the secure data generated by executing a trusted application in the TEE 420, store the encrypted secure data in the form of a file in the first memory 331 allocated to the REE 410 through the second memory 332, and store the information for encrypting and / or decrypting the secure data in the fourth memory 334. According to one or more embodiments, the electronic device 101 may read the encrypted secure data stored in the form of a file in the first memory 331 allocated to the REE 410 by the currently executing daemon process, copy the read secure data to the second memory 332, read the security information for encrypting and / or decrypting the secure data from the fourth memory 334, decrypt the encrypted secure data copied to the second memory 332 using the security information and temporarily store the decrypted secure data in the third memory 333, and use the decrypted secure data when executing the trusted application.

[0061] Figure 5 FIG. 500 is a flowchart illustrating an example of the operation of the electronic device 101 according to one or more embodiments. As will be understood by those of ordinary skill in the art, Figure 5 the operations shown are not limited to the order shown and may be performed in various other orders. In addition, according to one or more embodiments, more or fewer operations than Figure 5 the operations shown may be performed. Reference is made below to Figure 6 describe Figure 5 .

[0062] According to one or more embodiments, in operation 501, the electronic device 101 (e.g., the second processor 322) may generate secure data by executing a trusted application in the trusted application layer 421 of the TEE 420. For example, when iSIM is executed in the trusted application, the generated data may include at least one of the information requiring security, such as user identification information, authentication key, user phone number, local ID, personal identification number (PIN), and service provider information. According to one or more embodiments, the secure data may vary according to the executed application and may include information specified by the corresponding application developer. The electronic device 101 (e.g., the second processor 322) may temporarily store the secure data (e.g., Figure 6 631) generated by executing the trusted application in the third memory 333 through the secure OS kernel layer 423.

[0063] In operation 503, the electronic device 101 (e.g., the second processor 322) may encrypt the secure data or a part thereof used in the trusted application (e.g., Figure 6 601), and may copy (e.g., swap out) the encrypted secure data to the second memory 332 (e.g.,Figure 6 In one or more embodiments, the Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) may be used to encrypt data. The encryption method is not limited thereto, and other encryption methods known to those of ordinary skill in the art for ensuring confidentiality and integrity may be used. In one or more embodiments, data encryption may be performed in units of blocks obtained by dividing the data into a predetermined size. When encrypting data in units of blocks, techniques for preventing rollback may be used. As understood by those of ordinary skill in the art, rollback of encrypted data may include changing the encrypted data to a previous form, such as unencrypted data. According to one or more embodiments, an Anti-Replay Counter (ARC) may be used to prevent rollback. Different ARC values may be used for each data block to prevent rollback. The different ARC values for each data block may be temporarily stored in the form of a table in the third memory 333. In one or more embodiments, the different ARC values for each data block may be temporarily stored in the form of a table in the third memory 333( Figure 6 In one or more embodiments, the ARC table may be a linear array composed of ARC values. The number of ARC values may be determined according to the size of the secure data copied (e.g., swapped out) to the second memory 332. For example, 256 ARC values may be used to encrypt 2MB of secure data and copy (e.g., swap out) the encrypted secure data to the second memory 332. In one or more examples, each ARC value may be incremented by 1 from a predetermined initial value. In one or more embodiments, when copying (e.g., swapping out) secure data to the second memory 332 or copying (e.g., swapping in) secure data from the second memory 332, the corresponding ARC value may be used as an Initialization Vector (IV) for encrypting or decrypting the secure data. In one or more embodiments, the IV may be calculated by the following equation.

[0064] [Equation 1]

[0065] IV = device-specific value + ARC + zero padding

[0066] In the above equation, the device-specific value is a value unique to the electronic device and may be configured as 4 bytes. The ARC may be configured as 8 bytes, and the IV may be configured as 16 bytes, including 4 bytes of zero padding.

[0067] The electronic device 101 (e.g., the second processor 322) may encrypt the parameter values generated when encrypting data based on each block and store the encrypted parameter values in the second memory 332 through the secure OS kernel layer 423. According to one or more embodiments, when using AES-GCM to encrypt data, a tag TAG (e.g., Figure 6of 651), and the electronic device 101 (e.g., the second processor 322) may encrypt the tags generated during the encryption process in the form of a table (e.g., Figure 6 of 603), and store (e.g., swap out) the encrypted tags in the second memory 332 through the secure OS kernel layer 423 (e.g., Figure 6 of 623). In one or more embodiments, the electronic code block (AES-ECB) mode may be used to encrypt the tags. The encryption method is not limited thereto, and other encryption methods known to those of ordinary skill in the art for ensuring confidentiality may be used.

[0068] In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may encrypt the information generated and stored in the third memory 333 during the data encryption process, and may copy (e.g., swap out) the encrypted information to the second memory 332 through the secure OS kernel layer 423. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may encrypt the ARC table stored in the third memory 333 (e.g., Figure 6 of 605), and may copy (e.g., swap out) the encrypted ARC table to the second memory 332 through the secure OS kernel layer 423 (e.g., Figure 6 of 622). In one or more embodiments, AES-GCM may be used to encrypt the ARC table. The encryption method is not limited thereto, and other encryption methods known to those of ordinary skill in the art for ensuring confidentiality and integrity may be used. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may store, through the secure OS kernel layer 423, the parameters used and generated when encrypting multiple pieces of information generated during the encryption process in the fourth memory 334. In one or more embodiments, when encrypting the ARC table, the electronic device 101 (e.g., the second processor 322) may use the master ARC as the initial vector (IV). The master ARC may be generated as a random value whenever secure data generated from a trusted application is stored. In one or more examples, the master ARC may be used to decrypt the encrypted ARC table. For example, the electronic device 101 (e.g., the second processor 322) may store the master ARC in the fourth memory 334 through the secure OS kernel layer 423 (e.g., Figure 6 of 641). In one or more embodiments, the master tag may be generated when encrypting the ARC table. The master tag may be used to decrypt the encrypted ARC table. For example, the electronic device 101 (e.g., the second processor 322) may store the master tag in the fourth memory 334 through the secure OS kernel layer 423 (e.g., Figure 6 of 642).

[0069] In operation 505, the electronic device 101 (e.g., the first processor 321) may store the encrypted data stored in the second memory 332 in the first memory 331 allocated to the REE 410. In one or more embodiments, the second processor 322 of the electronic device 101 may request the first processor 321 to store the secure data in the first memory 331 allocated to the REE 410 through the mailbox of the secure OS kernel layer 423. When the daemon process is being executed in the REE 410, the first processor 321 of the electronic device 101 may receive a request for secure data from the second processor 322 through the mailbox of the kernel layer 413. In one or more embodiments, the request sent from the second processor 322 to the first processor 321 may include the address of the second memory 332 storing the secure data. The first processor 321 of the electronic device 101 may read the encrypted data stored in the second memory 332 through the daemon process running in the REE 410, and may store the encrypted data read through the kernel layer 413 in the first memory 331 (e.g., Figure 6 of 607). In one or more embodiments, the encrypted data stored in the second memory 332 may include encrypted secure data (e.g., Figure 6 of 611), an encrypted ARC table (e.g., Figure 6 of 612), and an encrypted tag table (e.g., Figure 6 of 613), and the encrypted data may be stored in the first memory 331 in the form of a single file (e.g., Figure 6 of 610).

[0070] Figure 7 Flowchart 700 is an example showing the operations of the electronic device 101 according to one or more embodiments. As understood by those of ordinary skill in the art, Figure 7 the operations shown are not limited to the order shown and may be performed in various other orders. Additionally, according to one or more embodiments, more or fewer operations than Figure 7 the operations shown may be performed. The following is described with reference to Figure 8 . Figure 7 .

[0071] According to one or more embodiments, in operation 701, the electronic device 101 (e.g., the second processor 322) may execute a trusted application in the trusted application layer 421 of the TEE 420. In one or more embodiments, when executing the trusted application, the second processor 322 may request the secure data stored in the first memory 331 from the first processor 321 through the mailbox of the secure OS kernel 423.

[0072] In operation 703, the electronic device 101 (e.g., the first processor 321) may read the encrypted data file stored in the first memory 331 (e.g., Figure 8 's 610) (e.g., Figure 8 's 801). In one or more embodiments, when the first processor 321 receives a secure data request from the second processor 322 via the mailbox of the kernel layer 413, the first processor 321 may read the encrypted data file stored in the second memory 332 via a daemon running in the REE 410 (e.g., Figure 8 's 610) (e.g., Figure 8 's 801). According to one or more embodiments, when AES-GCM is used as the encryption scheme for secure data and ARC is used to prevent rollback, the encrypted data (e.g., Figure 8 's 611), the encrypted ARC table (e.g., Figure 8 's 612), and the encrypted tag table (e.g., Figure 8 's 613) may be stored in the first memory 331. In this case, the electronic device 101 (e.g., the first processor 321) may copy the encrypted data (e.g., Figure 8 's 611), the encrypted ARC table (e.g., Figure 8 's 612), and the encrypted tag table (e.g., Figure 8 's 613) included in the file read from the first memory 331 to the second memory 332. In one or more embodiments, the first processor 321 may copy the encrypted data (e.g., Figure 8 's 611), the encrypted ARC table (e.g., Figure 8 's 612), and the encrypted tag table (e.g., Figure 8 's 613) included in the file read from the first memory 331 to the second memory 332 via a daemon running in the REE 410.

[0073] In operation 705, the electronic device 101 (e.g., the second processor 322) may decrypt the encrypted data copied to the second memory 332 (e.g., Figure 8 's 611) for use in a trusted application. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may decrypt the encrypted data (e.g., Figure 6 's 411), the encrypted ARC table (e.g., Figure 8 's 612), and the encrypted tag table (e.g., Figure 8Each of those in 613) is decrypted. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may use the encrypted information stored in the fourth memory 334 to verify and decrypt the encrypted data generated during the encryption process. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may decrypt the encrypted ARC table (e.g., Figure 8 in 622) (e.g., Figure 8 in 803). In one or more embodiments, when the ARC table is encrypted using AES-GCM while encrypting the secure data, the primary ARC (e.g., Figure 8 in 641) and the primary tag (e.g., Figure 8 in 642) generated and used during the encryption process are stored in the fourth memory 334. In one or more embodiments, the second processor 322 may read the primary ARC (e.g., Figure 8 in 641) and the primary tag (e.g., Figure 8 in 642) stored in the fourth memory 334 through the secure OS kernel layer 423, and may use the primary ARC (e.g., Figure 8 in 641) and the primary tag (e.g., Figure 8 in 642) to decrypt the encrypted ARC table (e.g., Figure 8 in 622) stored in the second memory 332 (e.g., Figure 8 in 803). According to one or more embodiments, the primary tag may be used to verify the encrypted ARC table. The electronic device 101 (e.g., the second processor 322) may store (e.g., swap in) the decrypted ARC table in the third memory 333 (e.g., Figure 8 in 632) through the secure OS kernel layer 423.

[0074] The electronic device 101 (e.g., the second processor 322) may decrypt the encrypted secure data using the decrypted information. In one or more embodiments, the electronic device 101 (e.g., the second processor 322) may use the ARC value of the decrypted ARC table (e.g., Figure 8 in 632) copied to the second memory 332 and the tag value of the decrypted tag table (e.g., Figure 8 in 623) to decrypt the encrypted secure data (e.g., Figure 8 in 621) copied to the second memory 332 based on each block (e.g., Figure 8 in 805). For example, the data may be divided into one or more blocks, where the data is encrypted based on each block and subsequently decrypted based on each block.

[0075] In one or more embodiments, an electronic device 101 (e.g., a second processor 322) may store (e.g., swap in) decrypted secure data in a third memory 333 through a secure OS kernel layer 423 (e.g., Figure 8 631 of). Thereafter, the electronic device 101 (e.g., the second processor 322) may use the decrypted secure data stored in the third memory 333 through a trusted application running in a trusted application layer 421 of the TEE 420.

[0076] Figure 9 is a view showing an example of a format of secure data stored in a fourth memory 334 of an electronic device 101 according to one or more embodiments.

[0077] In one or more embodiments, the fourth memory 334 may store at least a portion of secure data output from a trusted application running in the trusted application layer 421. In one or more embodiments, the trusted application may be executed by the second processor 322 in the trusted application layer 421, and the second processor 322 may temporarily store at least a portion of the secure data generated when executing the trusted application in the fourth memory 334 through the secure OS kernel layer 423. According to one or more embodiments, information used when encrypting the secure data may be stored in the fourth memory 334.

[0078] Referring to Figure 9 , data 910 generated by executing the trusted application 1SA#1 may be stored in a slot A920 of the fourth memory 334. According to one or more embodiments, data including a primary ARC field 915 used as an initial vector (IV) when the second processor 322 encrypts an ARC table and a primary tag field 916 generated when encrypting the ARC table may be stored in the fourth memory 334. In addition to the primary ARC field 915 and the primary tag field 916, the data stored in the fourth memory 334 may further include a magic field 911, a version field 912, an active set field 913, a data size field 914, and a reserved field 917.

[0079] The magic number field 911 may be formed of 4 bytes and may be an integer for identifying an instruction. The version field 912 may be formed of 4 bytes and may be a value indicating version information about the corresponding data. The active set field 913 may be formed of 4 bytes and may be a flag value indicating a set storing correct information. The data size field 914 may be formed of 4 bytes and may be a value indicating the size of secure data generated by the corresponding trusted application. The main ARC field 915 may be formed of 8 bytes and the main ARC may be a random value generated whenever secure data generated by a trusted application is stored. The main ARC may be used as an initial vector (IV) when encrypting the ARC table or decrypting the encrypted ARC table. The main tag field 916 may be formed of 16 bytes and the main tag may be an authentication tag generated as a result of encryption when the ARC table is encrypted and copied (e.g., swapped out) to the second memory 332. The main tag may be used as an authentication tag when decrypting the encrypted ARC table.

[0080] An electronic device according to one or more embodiments may include: a first processor 321 operating in a general environment 410; a second processor 322 operating in a secure environment 420; a first memory 331 allocated to the general environment; a second memory 334 allocated to the secure environment; and a third memory 332 shared between the general environment and the secure environment. The second processor may be configured to encrypt at least a portion of secure data generated by a trusted application executed in the secure environment and store the encrypted portion in the third memory, and store first information for encrypting at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data in the second memory. The first processor may be configured to store at least a portion of the encrypted secure data stored in the third memory in the first memory.

[0081] In one or more embodiments, the second processor may be configured to encrypt at least a portion of secure data based on each block using a different anti-replay counter (ARC) value for each block, encrypt the ARC table 432, where the ARC table 432 stores ARC values, and encrypt the tag table, where the tag table stores tag values 651 generated when encrypting at least a portion of secure data based on each block.

[0082] In one or more embodiments, the first processor may be configured to store at least a portion 611 of the encrypted secure data, the encrypted ARC table 612, and the encrypted tag table 613 in the first memory in a file form 610.

[0083] In one or more embodiments, the first information may be the main ARC 641 and the second information may be the main tag 642.

[0084] In one or more embodiments, the first processor may be configured to copy at least a portion of encrypted security data stored in the first memory and store the copied portion in the third memory when executing a trusted application in a secure environment, and the second processor may be configured to decrypt at least a portion of the encrypted security data stored in the third memory using the first information and the second information.

[0085] In one or more embodiments, at least a portion of the encrypted security data stored in the third memory may include: an encrypted ARC table 622 storing an anti-replay counter (ARC) value used when encrypting at least a portion of the security data on a per-block basis; and an encrypted tag table 623 storing tag values generated when encrypting at least a portion of the security data on a per-block basis. The second processor may be configured to decrypt the encrypted ARC table using the first information and the second information, decrypt the tag table, and decrypt at least a portion of the per-block encrypted security data using the decrypted ARC table and the decrypted tag table.

[0086] In one or more embodiments, the first processor may be configured to read a file 610 including encrypted security data, an encrypted ARC table, and an encrypted tag table from the first memory and store the encrypted security data, the encrypted ARC table, and the encrypted tag table in the third memory respectively.

[0087] In one or more embodiments, the second processor may be configured to encrypt at least a portion of the security data and the ARC table in an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

[0088] In one or more embodiments, the second processor may be configured to decrypt at least a portion of the encrypted security data in an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

[0089] In one or more embodiments, the second processor may be configured to encrypt the tag table in an Advanced Encryption Standard (AES)-Electronic Codebook (ECB) scheme.

[0090] A method for operating an electronic device 101 according to one or more embodiments may include: executing a trusted application in a secure environment by a first processor 322 operating in the secure environment 420 and generating secure data 501. The method may include: encrypting at least a portion of the generated secure data by the first processor and storing the encrypted portion in a first memory 332 shared by the secure environment and a general environment 410 503. The method may include: storing, by the first processor, first information for encrypting at least a portion of the secure data and second information generated when encrypting at least a portion of the secure data in a second memory allocated to the secure environment 503. The method may include: storing, by a second processor 321 operating in the general environment, at least a portion of the encrypted secure data stored in the first memory in a third memory allocated to the general environment 505.

[0091] In one or more embodiments, the operation of encrypting 503 may include: encrypting at least a portion of the secure data by the first processor based on each block using a different anti-replay counter (ARC) value for each block 601, encrypting a tag table 603, where the tag table stores tag values generated when encrypting at least a portion of the secure data based on each block, and encrypting an ARC table 605, where the ARC table stores ARC values.

[0092] In one or more embodiments, the operation of storing 505 in the third memory may include: storing, by the second processor, at least a portion of the encrypted secure data, the encrypted ARC table, and the encrypted tag table in the first memory in a file format 610 607.

[0093] In one or more embodiments, the first information may be a master ARC 641, and the second information may be a master tag 642.

[0094] In one or more embodiments, the method may further include: when executing the trusted application 701 in the secure environment, copying 703 at least a portion of the encrypted secure data stored in the first memory by the second processor and storing the copied portion in the first memory, and decrypting 705 at least a portion of the encrypted secure data stored in the first memory by the first processor using the first information and the second information.

[0095] In one or more embodiments, at least a portion of the encrypted security data stored in the first memory may include: an encrypted ARC table 621 storing anti-replay counter (ARC) values used when encrypting at least a portion of the security data on a per-block basis; and an encrypted tag table 623 storing tag values generated when encrypting at least a portion of the security data on a per-block basis. The operation of decryption 705 may include: the first processor decrypting 803 the encrypted ARC table using first information and second information, decrypting 805 the tag table, and decrypting 805 at least a portion of the security data encrypted on a per-block basis using the decrypted ARC table and the decrypted tag table.

[0096] In one or more embodiments, the method may further include: the second processor reading 801 from a third memory a file 610 including encrypted security data, an encrypted ARC table, and an encrypted tag table, and storing the encrypted security data 621, the encrypted ARC table 622, and the encrypted tag table 623 in the first memory, respectively.

[0097] In one or more embodiments, the operation of encryption 601 or 605 may include: encrypting at least a portion of the security data and the ARC table in an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

[0098] In one or more embodiments, the operation of decryption 705 may include: decrypting at least a portion of the encrypted security data in an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

[0099] In one or more embodiments, the operation of encrypting 603 the tag table may include: encrypting the tag table in an Advanced Encryption Standard (AES)-Electronic Codebook (ECB) scheme.

[0100] An electronic device according to one or more embodiments of the present disclosure may be one of various types of electronic devices. The electronic device may include, for example, a portable communication device (e.g., a smart phone), a computer device, a portable multimedia device, a portable medical device, a camera, a wearable device, or a home appliance. According to one or more embodiments of the present disclosure, the electronic device is not limited to the above-described electronic devices.

[0101] It should be understood that the various embodiments of the present disclosure and the terms used therein are not intended to limit the technical features set forth herein to specific embodiments, but include various changes, equivalent forms or alternative forms for the corresponding embodiments. For the description of the drawings, like reference numerals may be used to refer to like or related elements. It will be understood that a singular noun corresponding to an item may include one or more things, unless the relevant context clearly indicates otherwise. As used herein, each of the phrases such as "A or B", "at least one of A and B", "at least one of A or B", "A, B or C", "at least one of A, B and C", and "at least one of A, B or C" may include any one or all possible combinations of the items listed together in the corresponding one of the plurality of phrases. As used herein, terms such as "first" and "second" or "1st" and "2nd" may be used to simply distinguish the corresponding components from another component, and do not limit the components in other respects (e.g., importance or order). It will be understood that in the case where the term "operably" or "communicatively" is used or where the term "operably" or "communicatively" is not used, if an element (e.g., a first element) is referred to as "coupled to another element (e.g., a second element)", "coupled with another element (e.g., a second element)", "connected to another element (e.g., a second element)", or "connected with another element (e.g., a second element)", it means that the one element can be directly (e.g., wired) connected to the other element, wirelessly connected to the other element, or connected to the other element via a third element.

[0102] As used herein, the term "module" may include a unit implemented in hardware, software or firmware, and may be used interchangeably with other terms (e.g., "logic", "logic block", "portion" or "circuit"). A module may be a single integrated component adapted to perform one or more functions or the smallest unit or portion of the single integrated component. For example, according to one or more embodiments, a module may be implemented in the form of an application specific integrated circuit (ASIC).

[0103] One or more embodiments of the present disclosure may be implemented as software (e.g., program 140) including one or more instructions stored in a storage medium (e.g., internal memory 136 or external memory 138) readable by a machine (e.g., electronic device 101). For example, a processor (e.g., processor 120) of the machine (e.g., electronic device 101) may, under the control of the processor, invoke and run at least one of the one or more instructions stored in the storage medium, with or without using one or more other components. This allows the machine to be operated according to the at least one invoked instruction to perform at least one function. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, the term "non-transitory" means that the storage medium is a tangible device and does not include signals (e.g., electromagnetic waves), but this term does not distinguish whether the data is stored semi-permanently or temporarily in the storage medium.

[0104] According to one or more embodiments, a method according to one or more embodiments of the present disclosure may be included and provided in a computer program product. The computer program product may be traded between a seller and a buyer as a product. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read-only memory (CD-ROM)), or distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play Store TM ) or directly between two user devices (e.g., smartphones). If distributed online, at least a part of the computer program product may be generated temporarily or stored at least temporarily in a machine-readable storage medium, such as the memory of a manufacturer's server, the server of an application store, or a relay server.

[0105] According to one or more embodiments, each component (e.g., module or program) of the components described above may include a single entity or multiple entities. Some of the multiple entities may be separately provided in different components. According to one or more embodiments, one or more of the components described above may be omitted, or one or more other components may be added. Optionally or additionally, multiple components (e.g., modules or programs) may be integrated into a single component. In this case, according to various embodiments, the integrated component may still perform one or more functions of the corresponding components of the multiple components in the same or similar manner as the way each component of the multiple components performed functions before integration. According to various embodiments, the operations performed by a module, a program, or another component may be sequential, parallel, repetitive, or heuristic, or may be run in a different order or one or more of the operations may be omitted, or one or more other operations may be added.

Claims

1. An electronic device (101), comprising: A first processor (321) operating in a general non - secure environment (410); A second processor (322) operating in a secure environment (420); A first memory (331) allocated to the general non - secure environment; A second memory (334) allocated to the secure environment; And A third memory (332) shared between the general non - secure environment and the secure environment, Wherein, the second processor is configured to: Encrypt at least a part of the secure data to generate an encrypted part, the secure data being generated by a trusted application executed in the secure environment, Store the encrypted part in the third memory, and Store first information used to encrypt at least a part of the secure data and second information generated when encrypting at least a part of the secure data in the second memory, and Wherein, the first processor is configured to: Store the encrypted part stored in the third memory in the first memory.

2. The electronic device according to claim 1, wherein, The second processor is configured to: Use different anti - replay counter ARC values for each block to encrypt at least a part of the secure data based on each block; Encrypt an ARC table (432), where the ARC table stores the ARC values for each block; and Encrypt a tag table, where the tag table stores tag values (651) generated when encrypting at least a part of the secure data based on each block.

3. The electronic device according to claim 2, Among them, The first processor is configured to store at least a part (611) of the encrypted secure data, an encrypted ARC table (612), and an encrypted tag table (613) in the first memory in a file form (610).

4. The electronic device according to claim 2 or claim 3, Among them, The first information is a master ARC (641), and the second information is a master tag (642).

5. The electronic device according to any one of claims 1 to 4, Among them, The first processor is configured to, when the trusted application is executed in the secure environment, copy the encrypted part in the first memory as a copied part and store the copied part in the third memory, Wherein, the second processor is configured to decrypt the encrypted part stored in the third memory using the first information and the second information.

6. The electronic device according to claim 5, Among them, The encrypted part stored in the third memory includes (i) an encrypted ARC table (622) storing anti - replay counter ARC values used when encrypting at least a part of the secure data based on each block, and (ii) an encrypted tag table (623) storing tag values generated when encrypting at least a part of the secure data based on each block, and Wherein, the second processor is configured to: Decrypt the encrypted ARC table using the first information and the second information, decrypt the encrypted tag table, and decrypt the encrypted portion using the decrypted ARC table and the decrypted tag table.

7. The electronic device according to claim 5 or claim 6, Among them, wherein the first processor is configured to read from the first memory a file (610) including the encrypted portion, the encrypted ARC table, and the encrypted tag table, and store the encrypted portion, the encrypted ARC table, and the encrypted tag table in the third memory respectively.

8. The electronic device according to any one of claims 2 to 7, Among them, wherein the second processor is configured to encrypt at least a portion of the security data and the ARC table using an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

9. The electronic device according to any one of claims 5 to 8, Among them, wherein the second processor is configured to decrypt the encrypted portion using an Advanced Encryption Standard (AES)-Galois / Counter Mode (GCM) scheme.

10. The electronic device according to any one of claims 2 to 9, Among them, wherein the second processor is configured to encrypt the tag table using an Advanced Encryption Standard (AES)-Electronic Codebook (ECB) scheme.

11. A method for operating an electronic device (101), the method comprising: executing, by a first processor (322) operating in a secure environment (420), a trusted application in the secure environment and generating security data (501); encrypting, by the first processor, at least a portion of the generated security data to generate an encrypted portion, and storing the encrypted portion in a first memory (332) shared by the secure environment and a general non-secure environment (410) (503); storing, by the first processor, first information for encrypting at least a portion of the security data and second information generated when encrypting at least a portion of the security data in a second memory allocated to the secure environment (503); and storing, by a second processor operating in the general non-secure environment, the encrypted portion stored in the first memory in a third memory allocated to the general non-secure environment (505).

12. The method according to claim 11, wherein, The operation of encrypting by the first processor includes: encrypting at least a portion of the security data based on each block using a different Anti-Replay Counter (ARC) value for each block (601); encrypting a tag table (603), wherein the tag table stores tag values generated when encrypting at least a portion of the security data based on each block; and encrypting an ARC table (605), wherein the ARC table stores the ARC values for each block, wherein the operation of storing (505) by the second processor in the third memory includes, storing (607) the encrypted portion, the encrypted ARC table, and the encrypted tag table in the first memory in the form of a file (610), Wherein, the first information is the master ARC (641), and the second information is the master tag (642).

13. The method according to claim 11 or claim 12, further comprising: When executing the trusted application in the secure environment, copying (703) by the second processor the encrypted portion stored in the first memory and storing the copied portion in the first memory; And Decrypting (705) by the first processor the encrypted portion stored in the first memory using the first information and the second information, Wherein, the encrypted portion stored in the first memory includes (i) an encrypted ARC table (621) storing anti-replay counter ARC values used when encrypting at least a portion of the secure data based on each block, and (ii) an encrypted tag table (623) storing tag values generated when encrypting at least a portion of the secure data based on each block, and Wherein, the operation of decrypting (705) by the first processor includes: Decrypting (803) the encrypted ARC table using the first information and the second information; Decrypting (805) the tag table; and Decrypting (805) the encrypted portion using the decrypted ARC table and the decrypted tag table.

14. The method according to claim 13, further comprising, Reading by the second processor from the third memory a file (610) including the encrypted portion, the encrypted ARC table, and the encrypted tag table, and storing the encrypted portion (621), the encrypted ARC table (622), and the encrypted tag table (623) in the first memory respectively.

15. The method according to any one of claims 12 to 14, Among them, The operation of encrypting (601, 605) includes: encrypting at least a portion of the secure data and the ARC table in an Advanced Encryption Standard AES-Galois / Counter Mode GCM scheme, Wherein, the operation of decrypting (705) includes: decrypting the encrypted portion in an Advanced Encryption Standard AES-Galois / Counter Mode GCM scheme, Wherein, the operation of encrypting (603) the tag table includes: encrypting the tag table in an Advanced Encryption Standard AES-Electronic Codebook ECB scheme.

Citation Information

Cited By

  • Fraud-related label sharing system, fraud-related label sharing method and all-in-one machine device

    CN122451955A