Device and method for protecting the integrity of operating system instances
The use of a secure element to encrypt and decrypt operating system instances in mobile devices ensures robust security and data integrity by preventing unauthorized access and verifying PINs or cryptographic information, addressing the lack of isolation in existing technologies.
Patent Information
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2014-05-13
- Publication Date
- 2026-04-02
AI Technical Summary
Existing mobile communication devices lack robust security mechanisms to ensure the integrity and isolation of multiple operating system instances, particularly in scenarios requiring high security such as online banking or company network communication.
A device and method utilizing a secure element, like a smart card, to encrypt and decrypt operating system instances, ensuring data integrity and isolation by verifying PINs or cryptographic information, and only allowing access to authorized instances based on secure element verification.
Enhances security by ensuring that unauthorized access to sensitive data and processes is prevented, even if the lock screen is bypassed, and maintains data integrity through cryptographic verification and hash checks.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] The application concerns integrity assurance and in particular a device and a method for protecting the integrity of operating system containers or virtualized operating system instances.
[0002] Communication devices, especially mobile communication devices such as smartphones, have become an integral part of our lives. They are used for a wide variety of tasks, both in our personal and professional lives. The different tasks performed with a smartphone typically have different security requirements. For example, using a smartphone for online banking places high security demands on security. Similarly, high security demands apply when a mobile communication device communicates with a company network.
[0003] Isolation concepts, such as virtualization and containerization, enable the deployment of multiple isolated system environments. Examples include system virtualization and operating system-level virtualization. A well-known example of system virtualization is Xen, and a well-known example of operating system-level virtualization is Linux Containers (LXC). The underlying operating system mechanisms of LXC allow multiple isolated Linux systems to run on a single system unit. Specifically, in LXC, each container has its own virtual environment. Each container has its own namespaces for processes and the file directory system, among other things, which are isolated from the other containers and therefore inaccessible. However, all containers use the kernel of the underlying operating system.In the case of system virtualization, each instance uses its own kernel, which in turn implements processes. Here too, each instance has its own file directory system, which is inaccessible to the other instances.
[0004] US 2013 / 0042295 A1 discloses a method and apparatus for a secure virtual environment on a mobile device for document processing and the performance of secure activities. This creates a secure application environment in which secure data and documents can be separated from insecure data by means of document encryption. This makes it possible to apply security policies exclusively to secure application environments.
[0005] US 2007 / 0150736 A1 discloses a system and method for protecting mobile devices, such as laptops and mobile phones, using a portable token. The method performs token-based authentication to enable the operation of the mobile device.
[0006] It would be desirable to provide improved concepts that enhance the security of mobile communication units.
[0007] The object of the present invention is achieved by a device according to claim 1, by a system according to claim 16, by an information element according to claim 18, by a system according to claim 19, by a method according to claim 20 and by a computer program according to claim 21.
[0008] A device is provided. The device comprises a processor unit, which includes one or more processors; a storage unit, which includes non-volatile memory; an interface for data transmission to and reception from an information element; and a group of operating system instances. The group of operating system instances comprises one or more operating environment instances, each operating system instance of the group containing data, and the data of each operating system instance of the group containing the operating system instances being stored encrypted in the non-volatile memory of the storage unit.The device is configured, when a verification result has a first result, to decrypt the data of one or more work environment instances in order to generate decrypted data of that work environment instance, and, depending on the decrypted data of that work environment instance, to execute one or more processes associated with that work environment instance on the processor unit; and the device is configured, when the verification result has a second result that differs from the first result, to decrypt the data of none of the one or more work environment instances.
[0009] The group of operating system instances also includes a login instance. The interface is configured to receive cryptographic information or other data from the information element. Based on this cryptographic information or other data, the device is configured to decrypt the login instance's data in order to generate decrypted login instance data and, depending on the decrypted login instance data, to execute one or more processes associated with the login instance on the processor unit to provide a graphical user interface that allows user input.Furthermore, the interface is designed to transmit user input or a send message dependent on the user input to the information element, and is further configured to receive a response message containing the verification result after this transmission. Depending on the verification result, either decryption and execution of one of the work environment instances occurs, or decryption and, consequently, execution of one of the work environment instances are omitted.
[0010] In one embodiment, a system without a login instance is implemented. PIN entry is eliminated, but integrity protection is still ensured.
[0011] The device may preferably be a communication unit. It is particularly preferred that the device be a mobile communication unit, such as a smartphone or tablet.
[0012] Furthermore, an information element is provided. The information element comprises a storage unit containing non-volatile memory, a processor unit, and an interface. The non-volatile memory of the storage unit stores one or more private cryptographic keys of one or more asymmetric key pairs. The interface is configured to receive an encrypted cryptographic key or other data, wherein the encrypted cryptographic key is decryptable using the private cryptographic key. The processor unit is configured to decrypt the encrypted cryptographic key or other data using the one or more private cryptographic keys in order to obtain a decrypted cryptographic key or decrypted data.The interface is designed to output the decrypted cryptographic key or the decrypted data.
[0013] Furthermore, the interface is configured to receive an encrypted PIN that can be decrypted using the private cryptographic key or the decrypted data. The processor unit is configured to decrypt the encrypted PIN using the private cryptographic key or the decrypted data in order to obtain a decrypted PIN. In other embodiments, an unencrypted PIN is transmitted in plaintext as an alternative.
[0014] The processor unit is configured to compare the (possibly decrypted) PIN with a stored PIN to obtain a verification result, the stored PIN being held in the non-volatile memory of the storage unit. The verification result is either a first result if it indicates that the decrypted PIN and the stored PIN match, or a second result, different from the first, if it indicates that the decrypted PIN and the stored PIN do not match. Furthermore, the processor unit is configured to generate a response message containing the verification result. The interface is configured to output this response message.
[0015] The information element is hereinafter also referred to as the "secure element". Preferably, the information element is a smartcard designed as described below.
[0016] Furthermore, a procedure is provided. The procedure includes: - If a verification result has a first result, decrypt data of a workspace instance of one or more workspace instances of a group of operating system instances to generate decrypted data of that workspace instance, wherein each operating system instance of the group of operating system instances has data, wherein the data of each operating system instance of the group of operating system instances is stored encrypted in the non-volatile memory of a memory unit, and, depending on the decrypted data of said workspace instance, execute one or more processes associated with that workspace instance on a processor unit. And: - If the verification result shows a second result that differs from the first result, no decryption of the data of one or more work environment instances.
[0017] Furthermore, a computer program with program code for carrying out the procedure described above is provided.
[0018] Embodiments of the present invention are based on the use of separately isolated operating system instances on a mobile communication unit. These instances are specially protected against unauthorized access by special access mechanisms, thereby ensuring their data integrity. A so-called secure element, which comprises an integrated circuit such as a smart card, plays a key role in this process. In embodiments of the present invention, the operating system instances of the mobile communication unit are coupled to a special secure element. This results in a coupling between the device, e.g., a smartphone, and the secure element, and vice versa.
[0019] Preferred embodiments of the invention are described below with reference to the drawings.
[0020] The drawings depict: Fig. 1a shows a device according to a first embodiment, Fig. 1b shows a device according to a second embodiment, Fig. 2 shows a device according to a third embodiment, Fig. Figure 3 shows a device according to a fourth embodiment, Fig. 4 shows a device according to a fifth embodiment, and Fig. Figure 5 shows an information element according to one embodiment.
[0021] Fig. Figure 1a shows a device according to one embodiment.
[0022] The device 100 comprises a processor unit 110, which includes one or more processors.
[0023] Furthermore, the device 100 includes a storage unit 120, which comprises non-volatile memory.
[0024] Furthermore, the device 100 includes an interface 130 for data transmission to an information element 900 and for data reception from the information element 900.
[0025] Furthermore, the device comprises a group of operating system instances 140, 141, 142. The group of operating system instances 140, 141, 142 comprises one or more work environment instances 141, 142.
[0026] Each operating system instance 140, 141, 142 of the group of operating system instances 140, 141, 142 contains data. The data of each operating system instance 140, 141, 142 of the group of operating system instances 140, 141, 142 is stored encrypted in the non-volatile memory of storage unit 120.
[0027] The device 100 is configured, when a verification result has a first result, to decrypt the data of a work environment instance 141 of one or more work environment instances 141, 142, in order to generate decrypted data of this work environment instance 141, and depending on the decrypted data of this work environment instance 141, to execute one or more processes assigned to this work environment instance 141 on the processor unit 110.
[0028] Furthermore, the device 100 is designed to decode the data of none of the one or more working environment instances 141 if the verification result shows a second result that differs from the first result.
[0029] Depending on the verification result, one of the work environment instances will either be decrypted and executed, or the decryption and corresponding execution of one of the work environment instances will not occur.
[0030] The first result of such a verification process might indicate, for example, that a PIN was entered as user input that matches the PIN stored in the information element. If the response message contains the second result instead, the second piece of information might indicate, for example, that a PIN was entered as user input that does not match the PIN stored in the information element.
[0031] Alternatively, a verification result could, for example, compare a stored hash value with a calculated hash value, where the stored and calculated hash values refer to the specific work environment instance. The first result might indicate a match between the stored and calculated hash values, while the second result might show a discrepancy between them.
[0032] In some embodiments, processor unit 110, memory unit 120, and interface 130 are considered hardware components. In contrast, operating system instances 140, 141, and 142 are implemented in software in some embodiments.
[0033] In Fig. Figure 1a shows two work environment instances 141 and 142. However, a device can have a plurality of work environment instances. In embodiments, new work environment instances can be created and existing work environment instances 141 and 142 can be deleted while the device is in operation, for example, provided that the user initiating this has the necessary authorization.
[0034] The device 100 is preferably a communication unit designed to send messages to and receive messages from other communication units in a wireless or wired network. It is particularly preferred that the device 100 is a mobile communication unit designed to send messages to and receive messages from other communication units in a wireless or wired network. For example, the device 100 could be a mobile communication unit such as a smartphone or tablet.
[0035] Information element 900 is also referred to as the "secure element".
[0036] Fig. Figure 1b shows a device 100 according to a further embodiment. In such an embodiment, the group of operating system instances 140, 141, 142 further comprises a registration instance 140. The interface 130 is configured to receive cryptographic information or other data from the information element 900.
[0037] The device 100 is configured to decrypt the data of the login instance 140 based on the cryptographic information or other data, in order to generate decrypted data of the login instance 140, and, depending on the decrypted data of the login instance 140, to execute one or more processes associated with the login instance 140 on the processor unit 110 in order to provide a graphical interface that allows user input.
[0038] Furthermore, in such an embodiment, the interface 130 is configured to transmit the user input or a transmission message that depends on the user input to the information element 900, wherein the interface 130 is further configured to receive a response message after this transmission, which includes the verification result.
[0039] Depending on the verification result, either one of the work environment instances 141, 142 is decrypted and executed, or the decryption and corresponding execution of one of the work environment instances 141, 142 is omitted.
[0040] If one considers in Fig. 1b the overall system comprising the device 100 and the information element (secure element) 900, in embodiments the information element 900 may be configured to transmit cryptographic information to the interface 130 of the device 100.
[0041] For example, device 100 can send data, which is then decrypted by information unit 900 and sent back to device 100. Such data could be, for example, cryptographic information, such as a symmetric key for storage encryption.
[0042] The device 100 is configured to decrypt the data of the login instance 140 based on this cryptographic information, in order to generate decrypted data of the login instance 140, and, depending on the decrypted data of the login instance 140, to execute one or more processes associated with the login instance 140 on the processor unit 100 in order to provide a graphical interface that allows user input. The interface 130 of the device 100 is configured to transmit the user input or a transmission message dependent on the user input to the information element 900.
[0043] The information element 900 is configured to perform a comparison between stored information and received information (e.g., between a stored PIN and a PIN entered by the user), wherein the received information depends on the user input or the transmitted message. Furthermore, the information element 900 is configured to generate a response message and transmit it to the device, wherein the response message includes a verification result that, depending on the comparison, either shows a first result or a second result that differs from the first result.
[0044] Interface 130 of device 100 is configured to receive the response message. Device 100 is configured, when the verification result shows the first result (where the first result indicates, for example, that the entered PIN was correct), to decrypt the data of a work environment instance 141 of one or more work environment instances 141, 142, in order to generate decrypted data of this work environment instance 141, and, depending on the decrypted data of this work environment instance 141, to execute one or more processes assigned to this work environment instance 141 on the processor unit 110 of device 100.Furthermore, the device 100 is configured to not decrypt the data of any of the one or more work environment instances 141, 142 if the verification result shows the first result (where the first result indicates, for example, that the entered PIN was incorrect) (and accordingly not to execute any of the one or more work environment instances 141, 142).
[0045] An alternative embodiment, on the other hand, does without a registration authority, while still ensuring integrity protection.
[0046] In some embodiments, the PIN can be changed in information element 900. A PIN can, for example, consist of (a very) many characters, e.g., even arbitrary data.
[0047] In embodiments, the information element 900 has an internal state that is changed by a correct PIN entry, thereby unlocking the decryption functionality of the information element.
[0048] Another implementation is, for example, a virtualized system based on system virtualization. In this case, there is one operating system kernel per instance and a hypervisor underneath, such as Xen.
[0049] Fig. Figure 2 shows a device 200 according to a further embodiment. In Fig. Figure 2 shows the operating system kernel 150 of the device 200. The operating system kernel 150 is configured to operate based on the configuration described above. Fig. 1b mentioned cryptographic information, to decrypt the data of the login instance 140 in order to generate the decrypted data of the login instance 140, and, depending on the decrypted data of the login instance 140, to execute the above-mentioned one or more processes associated with the login instance 140 on the processor unit 110 in order to provide the graphical interface that enables user input.
[0050] Furthermore, the operating system kernel 150 is configured, if the verification result is the aforementioned first result, to decrypt the data of the aforementioned work environment instance 141 in order to generate the decrypted data of this work environment instance 141, and, depending on the decrypted data of this work environment instance 141, to execute the one or more processes assigned to this work environment instance 141 on the processor unit. Furthermore, the operating system kernel 150 is configured, if the verification result is the aforementioned second result, which differs from the first result, to decrypt the data of none of the one or more work environment instances 141, 142.
[0051] It is also preferred that each of the operating system instances 140, 141, 142 is based on the Android operating system. Isolation can preferably be implemented using namespaces. A second possible operating system would be, for example, GNU / Linux.
[0052] It is also preferred if each of the operating system instances is based on Linux. For example, the operating system instances can be implemented as the aforementioned prior art LinuX Containers (LXC).
[0053] Fig. Figure 3 shows a device 300 according to a further embodiment, wherein the device further comprises an operating system instance management layer 160. The operating system instance management layer 160 can also be referred to as a container management layer 160.
[0054] The operating system instance management layer 160 is formed when the verification result shows the first result, to transmit one or more instructions to the operating system kernel 150, thereby causing the operating system kernel to decrypt the data of said work environment instance 141 in order to generate the decrypted data of this work environment instance 141, and, depending on the decrypted data of this work environment instance 141, to execute the one or more processes assigned to this work environment instance 141 on the processor unit 110, and, wherein the operating system instance management layer 160 is formed, is formed when the verification result shows the second result, not to transmit an instruction to the operating system kernel 150, by which the operating system kernel 150 would be caused to decrypt the data of one of the work environment instances 141, 142.
[0055] In some implementations, the data is not immediately and completely decrypted. Instead, the key is stored in the Linux kernel and then used whenever the file system is accessed; and even then, only the blocks currently in use are encrypted or decrypted. For example, in such implementations, the blocks are also cached to enable faster access.
[0056] Preferred embodiments of the invention are explained in detail below.
[0057] When the mobile communication unit, for example a smartphone, is started, embodiments of the invention require that a graphical user interface be provided to the user to enable the user to enter a PIN. This is known in the prior art. However, embodiments of the invention already exhibit one or more of the following features that distinguish the device according to the invention from the ordinary prior art.
[0058] Firstly, the graphical user interface is provided by a separate operating system instance, for example, a dedicated LinuX container (as mentioned above) or a separate virtual operating system instance. This operating system instance can be referred to as the login instance (or instance0 or android0). Like the other operating system instances, the login instance is isolated from the other operating system instances of the device. In some implementations, this ensures that the user cannot access data and processes of the operating system instances that provide the actual user environment without correctly entering their PIN.
[0059] Comparing the login instance to a smartphone with a lock screen reveals significant differences. Firstly, with such a prior art lock screen, access is protected by a code stored on the smartphone. In contrast, with the mobile communication unit according to the invention, the PIN is not stored on the mobile communication unit itself, but rather on the secure element, which includes an integrated circuit, such as a smart card.
[0060] Furthermore, in a prior art smartphone, the lock screen is provided by the underlying operating system. If it is possible to bypass or deactivate the lock, all data and processes of the operating system can be accessed. In contrast, if it were possible to bypass the lock screen in the mobile communication unit according to the invention, nothing would be gained; the attacker would only have access to the login instance, but not to the other operating system instances of the mobile communication unit, which are isolated from the login instance and contain the actual data and processes to be protected.
[0061] Optionally, in one embodiment, the registration instance is also encrypted, for example, and can only be decrypted using the secure element.
[0062] For example, the login instance is stored in encrypted form in the non-volatile memory of the mobile communication device. Furthermore, the login instance may have been encrypted using a symmetric key. This symmetric key may, in turn, have been encrypted with a public asymmetric key of the secure element, with the resulting encrypted symmetric key then stored in the non-volatile memory of the mobile communication device. The private asymmetric key of the secure element, on the other hand, resides only on the secure element itself, which contains an integrated circuit or processor, such as a smart card. This ensures that the symmetric key can only be decrypted using the secure element.
[0063] When the mobile communication unit starts, the secure element would use its private asymmetric key to decrypt the encrypted symmetric key used to encrypt the login instance and then pass this symmetric key to the operating system kernel. This could be done, for example, by passing the decrypted symmetric key to an operating system instance management layer (also known as a container management layer; CML), which then forwards the decrypted symmetric key to the operating system kernel. The operating system kernel then uses the received symmetric key to decrypt the login instance.It is advantageous for the operating system kernel to decrypt the login instance rather than the secure element, such as the smart card, performing the decryption. This is because the operating system kernel typically has far greater computing resources and can usually perform the decryption much faster than a smart card could. Furthermore, it is often advantageous to decrypt the login instance with a symmetric key rather than an asymmetric key, as symmetric encryption and decryption are generally faster than asymmetric encryption and decryption.
[0064] Because the symmetric key for encrypting and decrypting the login instance is secured using the asymmetric key of the secure element, the login instance can only be decrypted if the corresponding secure element—for example, the correct smart card assigned to the mobile communication unit—has been inserted into the mobile communication unit. In other words, this establishes a binding relationship between the mobile communication unit and the secure element.
[0065] A connection can be established between, for example, a smartphone and a secure element, as well as between an operating system instance and a secure element. This can be achieved, for instance, by storing the public key of the respective communication partner in the smartphone, the instance, or the secure element during an initial provisioning phase. This public key can also be stored in encrypted form. Based on these keys, the communication partners can then establish a secure channel. In one implementation, this can guarantee that communication only occurs with the communication partner used at the time of provisioning.
[0066] As regards the secure element, in some embodiments it may be designed to take the form of a microSD card, a SIM card or a micro-SIM card, and be inserted into the communication unit in the same way.
[0067] In addition, smartcards could be used as a secure element. These could be connected to the mobile communication unit via an internal smartcard reader or an external smartcard reader, for example, via a USB port. To increase security, the user could always remove the smartcard from the communication unit or the smartcard reader after use and store it in a location separate from the mobile communication unit. This ensures that if the mobile communication unit is lost, the login instance of the mobile communication unit cannot be accessed.
[0068] Furthermore, the secure element can also be designed to communicate with the communication unit via Near Field Communication (NFC) without being inserted directly into the communication unit or a reader.
[0069] Various implementations are conceivable for near-field communication (NFC). On the one hand, the software for accessing NFC-based secure elements can be implemented in the operating system kernel (150), or in the operating system instance management layer (160), or in the login instance (140), or in a hypervisor, or in a Trusted Execution Environment (TEE). NFC and Bluetooth, in particular, are so complex that implementation in the login instance (140) is the simplest. However, implementation in the operating system kernel (150) or in the operating system instance management layer (160) would be preferable.
[0070] The secure element can also be designed to communicate with the communication unit via Bluetooth. Furthermore, the secure element can also communicate with the communication unit via LAN, WLAN, or a telecommunications network, particularly a mobile network, whereby the communication between the communication unit and the secure element is generally encrypted.
[0071] Further embodiments of the invention verify the data integrity of the application instance. For example, the application instance can be secured by one or more hash values.
[0072] Some implementations provide a hash value that represents a cryptographic hash value of the data of the unencrypted login instance.
[0073] In preferred embodiments, a standard procedure is used for encryption, e.g., cryptsetup aes-cbc-essiv:sha256 or aes-xts-plain64 for luks, and a Secure Hash Algorithm (SHA), e.g., SHA1 or SHA256, is used as the cryptographic hash.
[0074] In some implementations, the hash value is stored in the non-volatile memory of the communication unit. It may be preferable to store the hash value of the login instance on the secure element instead. This further enhances data integrity, particularly against intentional falsification.
[0075] In particular, the hash value can be incorporated into the PIN (along with the user's PIN), or the hash value itself can be the PIN for the authentication authority. This means the secure element can only be unlocked if the correct hash value is known on the smartphone. On a "foreign" smartphone, the secure element would therefore be unusable even with the user's PIN. This, in turn, creates a link between the smartphone and the secure element.
[0076] After decrypting the login instance, the data integrity of the login instance is then checked by, for example, the operating system kernel, e.g. a Linux kernel, calculating the hash value for the login instance itself and comparing it with the hash value that is stored, for example, in the non-volatile memory of the communication unit or on the secure element.
[0077] The integrity check is preferably performed before decryption. It is particularly preferred if this is carried out by the operating system management layer. In some embodiments, however, this can also be handled by a hypervisor in a virtualized system.
[0078] Data integrity of the login instance is assumed only if the calculated and stored hash values match. If the calculated and stored hash values do not match, data integrity is assumed to be lacking.
[0079] In one embodiment, the login process is aborted to prevent access to a compromised system. Alternatively, access may be prevented altogether, as the secure element cannot be unlocked with the correct PIN. In another embodiment, the login process continues, but a warning message is issued indicating a data integrity breach and that the system may have been compromised.
[0080] In some embodiments, a hash value for the encrypted login instance is stored, either as an alternative or in addition to a hash value for the decrypted login instance. This hash value of the encrypted login instance is stored, for example, either in the non-volatile memory of the communication unit or, preferably, on the secure element. Before decrypting the login instance, a hash value for the encrypted operating system instance is calculated in the same way and compared with the stored hash value. If the calculated and stored hash values match, the login instance is assumed to have data integrity. If the calculated and stored hash values do not match, data integrity is assumed to be lacking. The consequence of a lack of data integrity can be, for example, the termination of the login process or the display of a warning message.
[0081] Or the secure element simply isn't released. If the secure element isn't released with the correct PIN (which, in some implementations, can include the hash), it cannot decrypt the symmetric key used for storage encryption. Additionally, the one (or more) asymmetric keys in the secure element could also be used for other use cases (e.g., VPN, email decryption, email signature, SSL authentication; tied to the integrity of the instances in which they are used), which is also impossible because the secure element is still locked.
[0082] If, on the other hand, the login instance could be decrypted and the data integrity of the login instance can be assumed, the login instance is started (for example, by the operating system instance management layer), and a graphical user interface (GUI) is displayed, through which the user can enter a PIN.
[0083] For example, the user enters a PIN via the user interface, and the PIN is transmitted to the secure element. The secure element checks whether the PIN matches the one stored on the secure element, thus determining whether the user is authorized to access it.
[0084] If the user is not authorized to access, according to one embodiment, the secure unit stores information such as the fact that further PIN entries are no longer possible and the login process is aborted.
[0085] For example, it can also be provided that after a predefined number of consecutive incorrect PIN entries, e.g., three consecutive incorrect PIN entries, the secure unit stores a message indicating that further PIN entries are no longer possible, and the login process is aborted. For example, the try counter would then be stored in the non-volatile memory of the secure element, and it would be permanently locked after n attempts. In some embodiments, it can be unlocked again using a PUK (Personal Unblocking Key).
[0086] For example, when the mobile communication unit starts up, the secure element can use this stored value to determine whether further PIN entries are still permitted. If not, it can, for instance, immediately abort the login process after the mobile communication unit starts up.
[0087] If the user has entered the correct PIN, a menu may be displayed to the user, showing a selection of all (additional) operating system instances available on the communication unit. The user can then select one of these operating system instances from the menu. These additional operating system instances then provide the user with the processes and files that are actually of interest to the user. In this respect, these additional operating system instances, in contrast to the login instance, can be described as "working environment instances".
[0088] In an alternative embodiment, the communication unit contains only one work environment instance in addition to the login instance. In this case, for example, the user is not shown a selection menu after correctly entering the PIN; instead, this single work environment instance is started immediately after the PIN is entered and verified.
[0089] In other embodiments, each of the work environment instances has its own PIN, which is stored on the secure element. In such embodiments, after the communication unit is started, the user would first be shown a graphical menu by the login instance, listing the various available work environment instances. After selecting one of the work environment instances, the user is then prompted to enter the PIN of that work environment instance. The entered PIN is then transmitted (preferably encrypted, e.g., with a public asymmetric key of the secure element) to the secure element and verified by it. If the entered PIN matches the stored PIN, the corresponding work environment instance is started. If the PINs do not match, the process either stops immediately or, for example,After one or more consecutive incorrect PIN entries, access to this operating system instance, or, in other embodiments, to all operating system instances of the communication unit, is blocked. If the respective operating system instance is blocked, this can be done by storing a bit in the secure element that indicates that the respective operating system instance or the communication unit is blocked, and that is queried by the communication unit when the respective operating system instance is to be started. According to another embodiment, if (possiblyIf repeated incorrect PIN entry by an operating system instance blocks access to all operating system instances of the communication unit, this can be achieved by storing a bit in the secure element indicating that all operating system instances of the communication unit are blocked, and which is queried by the communication unit, for example, when the communication unit is switched on or started.
[0090] In various embodiments, there are several secure elements. For example, in one embodiment using NFC, there can be an NFC smartcard / token for each container.
[0091] Furthermore, some NFC-all implementations also incorporate a PAKE protocol, similar to that used in the new German identity card. This establishes a secure channel between the secure element and the smartphone (which in this case acts as a terminal).
[0092] In some implementations, the entered PIN is first encrypted. The PIN is then transmitted in encrypted form to the secure element. For encryption, the secure element's public asymmetric key can be used, for example. The secure element is only able to decrypt the encrypted PIN if it possesses the correct private asymmetric key, i.e., if the correct secure element is inserted into or connected to the mobile communication unit. This prevents, for example, the PIN entered by the user from being transmitted in plaintext and intercepted unencrypted by an attacker. Alternatively, the PAKE protocol mentioned above could be used.
[0093] Furthermore, this also prevents an attacker from replacing a secure element with a spy element, which would then impersonate a secure element and log the user's entered PIN in plaintext. Such a spy element cannot decrypt the received PIN because it does not possess the private asymmetric key of the true secure element.
[0094] Not only the login instance can be in encrypted form. In preferred embodiments, one or more work environment instances are also encrypted. Again, one or more symmetric keys can be used for encryption.
[0095] In one embodiment, the same symmetric key is always used for encryption in each of the operating system instances. A private asymmetric key is stored on the secure element, and the corresponding public asymmetric key is used to encrypt the single symmetric key. The encrypted symmetric key is then stored in the non-volatile memory of the communication unit or on the secure element.
[0096] In another embodiment, a different symmetric key is used to encrypt each of the operating system instances. A private asymmetric key is stored on the secure element, and the corresponding public asymmetric key is used to encrypt each of the symmetric keys. Each of the symmetric keys thus encrypted is then stored in the non-volatile memory of the communication unit or on the secure element. This increases security compared to the previous embodiment because, if an unencrypted symmetric key is discovered by an attacker, the other operating system instances remain protected.
[0097] However, the other side is also important here: encrypting a symmetric storage key with multiple asymmetric keys, thus securing the data. The symmetric key is then stored on the smartphone, encrypted multiple times with different asymmetric keys. This allows the use of a single instance with different smartcards and is particularly helpful when a smartcard expires and the user receives a new one with a different asymmetric key.
[0098] In another embodiment, a different symmetric key is used to encrypt each of the operating system instances. Furthermore, a different public asymmetric key is used to encrypt each of the symmetric keys. The corresponding private asymmetric key for each of the public asymmetric keys is stored on the secure element. Each of the symmetric keys encrypted in this way is then stored in the non-volatile memory of the communication unit or on the secure element. Compared to the previous embodiments, the security is very high, because even if an attacker were to gain possession of one of the private asymmetric keys, the other operating system instances would still be protected.
[0099] In one embodiment, the device 100; 200; 300 is configured, for example, to transmit one of the operating system instances 140, 141, 142 in a communication network. According to one embodiment, the device 100; 200; 300 is, for example, a communication unit of a communication network, wherein the device 100; 200; 300 is configured to transmit one of the operating system instances 140, 141, 142 of the device 100; 200; 300 in the communication network to another communication unit of the communication network. Such a communication network can, for example, be a wireless or wired telecommunications network or a computer network.
[0100] Furthermore, a system is provided comprising a first device 100; 200; 300 as described above and a second device 100; 200; 300 as described above. The first device 100; 200; 300 is configured to transfer one of the operating system instances 140, 141, 142 of the first device 100; 200; 300 from the first device 100; 200; 300 to the second device 100; 200; 300. The second device 100; 200; 300 is configured to receive said one of the operating system instances 140, 141, 142 of the first device 100; 200; 300 from the first device 100; 200; 300.
[0101] In another embodiment, instances are transferred from one smartphone to another (e.g., via a backend server to which the file system image of the first smartphone is uploaded, and from which the second smartphone downloads this file system image, including the encrypted symmetric keys). If, for example, the NFC-based smartcard is then held against a second smartphone, the container can be decrypted there. In one embodiment, this process—provided a suitable backend exists—is transparent to the user, for example, by the user holding their smartcard against a smartphone and their instance(s) being automatically downloaded from the backend. The only requirement is that the devices involved are mutually trusted, supported by a shared Public Key Infrastructure (PKI).
[0102] In one embodiment, the device 100; 200; 300 can be configured to encrypt a first working environment instance of the operating system instances 140, 141, 142 with a first cryptographic key, for example a first symmetric key, wherein the device 100; 200; 300 can further be configured to encrypt a second working environment instance of the operating system instances 140, 141, 142 with a second cryptographic key, for example a second symmetric key, and wherein the first cryptographic key and the second cryptographic key have different key lengths.
[0103] In one embodiment, a characteristic of the symmetric key can be made dependent on the protection status of an operating system instance. If the required protection for one operating system instance is lower than for another, a key offering less protection but faster encryption can be used to encrypt the instance requiring less protection. Conversely, a key offering slower encryption but higher protection can be used to encrypt the instance requiring more protection. For example, keys with different lengths can be used, with longer keys used when higher protection is needed for an operating system instance, compared to shorter keys when less protection is required.For example, the key length of the symmetric key can be 128 bits, 256 bits, or 512 bits, depending on the protection status. The protection status can be defined at runtime by an administrator or a user, or it can be predefined.
[0104] With regard to the one or more public asymmetric keys used by the communication unit to encrypt the one or more symmetric keys and, if applicable, to encrypt the PIN, these may, for example, be permanently stored in the communication unit's non-volatile memory.
[0105] In preferred embodiments, the communication unit receives the one or more public asymmetric keys from a certification authority. For example, the one or more public asymmetric keys can be transferred from the certification authority to the communication unit as needed.
[0106] In this PKI scenario, each smartphone (or its management instance or container management layer) would have a certificate, and each secure element would have one or more certificates, all signed by the CA or an intermediate instance. The trustworthiness of the other party can then be verified using the CA's public certificate, without the need for prior knowledge of the other party.
[0107] In some implementations, the data integrity of one or more work environment instances is also ensured. Just as described above for the login instance, a hash value can also be calculated for the work environment instance(s), which is then stored in the non-volatile memory of the communication unit or on the secure element.
[0108] In some implementations, the hash value for a work environment instance can be calculated after the work environment instance has been encrypted. A check is then performed to ensure that the respective work environment instance has data integrity before it has been decrypted.
[0109] For example, in some implementations the encrypted hard disk image file is hashed in order to then send this hash to the secure element, which then makes decryption possible.
[0110] The hash value for a workspace instance can be calculated before the instance is encrypted. A check is then performed to verify the data integrity of the respective workspace instance after it has been decrypted and before it is started. The hash value is generated after decryption in the same way as it was generated before encryption. For example, a cryptographic hash (e.g., SHA) is used.
[0111] If the stored hash value and the hash value generated after decryption match, data integrity is assumed. If the hash values do not match, data integrity is assumed to be lacking.
[0112] According to one implementation, if data integrity is lacking, the workspace instance is not started. Instead, the user is shown an error message indicating the lack of data integrity.
[0113] In an alternative implementation, a warning message can be issued to alert the user to the lack of data integrity in the workspace instance, and the communication unit can still attempt to start the workspace instance. This requires that the hash is not included in the PIN. Otherwise, the secure element would not release the symmetric key for decryption.
[0114] Creating a hash value before encrypting the operating system instance is advantageous because, after decryption, it is possible to check whether an attacker has altered the working environment instance and whether the decryption of the working environment instance was performed correctly.
[0115] In another embodiment, the hash value can also be calculated only after encryption. For example, if an operating system instance is first compressed, this results in a smaller amount of data, which is then encrypted. It can be advantageous to perform the hash on the compressed, encrypted data, as this may allow the hash calculation to be performed faster, thus increasing the efficiency of the hash calculation.
[0116] For both the one or more work environment instances and the login instance, the instance to be encrypted can also be compressed according to some implementations. If the corresponding instance is to be started later, decompression then takes place in addition to decryption. In some implementations, this is not done for the entire filesystem image, but in one implementation, for example, block by block.
[0117] Instead of checking data integrity for only one operating system instance at a time, a hash value can be generated across all operating system instances present in the communication unit. For example, when the communication unit starts, the overall hash value can be calculated and compared with the stored value to verify whether data integrity exists for all operating system instances within the communication unit.
[0118] The Trusted Computing Base (TCB) should be considered in this approach. For example, for the integrity of an instance, not only must the instance itself be intact, but also all other components that influence it. This applies particularly to the kernel, the management layer, and the login instance. All of these must be trustworthy and must not be compromised by an attacker. Otherwise, depending on which component they have compromised, an attacker could potentially gain access to keys, PINs, etc. Therefore, the approach here would be to hash all these components together or calculate a hash chain.
[0119] In some embodiments, the operating system instances are encrypted and / or the corresponding hash values are generated whenever the user issues a command to switch off the communication unit or shuts down the communication unit's operating system. In other embodiments, it may be provided that the operating system instances are encrypted and / or the corresponding hash values are generated when the battery level is critically low. In particular, it is generally provided that a hash value for an operating system instance is generated and / or that operating system instance is encrypted when its execution is terminated.
[0120] In other embodiments, the operating system instances are continuously encrypted at time intervals during their execution, and a hash may also be generated. In some embodiments, the encryption can be block-based, for example.
[0121] In some implementations, the actual persistent storage occurs at intervals, and the data is cached otherwise. This is particularly useful when the hash is to be incorporated into the PIN of a secure element. In that case, the PIN must be changed every time the hash changes, which cannot be done indefinitely with slow secure elements. Here, the smartphone would store two states: one for the old hash (and thus the PIN), and one for the new hash (and thus the PIN). The old state can then be deleted as soon as the secure element confirms the PIN change.
[0122] In some embodiments, after each command execution by an operating system instance, the hash for that operating system instance is generated and the operating system instance is encrypted.
[0123] Some implementations use a transaction concept: Before an operating system instance executes a transaction, the respective operating system instance is encrypted, and after the transaction is completed, the operating system instance is encrypted again. The transactions are defined such that, both before and after the transaction, the operating system instance is in a state where data integrity prevails.
[0124] There are special encryption modes for block-based symmetric encryption, e.g., CBC or XTS, see also above. These encryption modes can be used in various implementations.
[0125] If the communication unit crashes during the execution of a transaction or, for example, its power supply is interrupted, this is not a problem, because when the communication unit is restarted and when this operating system instance is started, the encrypted operating system instance is decrypted, which is then in a state where data integrity exists.
[0126] The essential tasks associated with encrypting and decrypting, and optionally compressing, operating system instances, and generating hash values can be controlled and monitored by the operating system instance management layer 160 (also known as the container management layer; CML). Such an operating system instance management layer can, for example, be configured to instruct the operating system kernel 150 to encrypt, decrypt, and compress the respective operating system instance. The operating system instance management layer 160 can also compare a calculated hash value for an operating system instance with the hash value that was determined for that same operating system instance.
[0127] Fig. Figure 4 shows a device according to a further embodiment. The application instance is designated as “android0” and the working environment instances as “android1” and “android2”. The working environment instances can also be generally referred to as “androidX” instances. The block of the in Fig. 4 the hardware 135 comprises in one embodiment the processor unit 110, the memory unit 120 and the interface 130 of the Fig. 1a to 3.
[0128] In some embodiments, the integrity of the operating system instances is enforced at runtime for all encrypted operating system instances in the operating system instance management layer. For this purpose, as explained above, the secure element and the (communication) unit are bound to each other, for example, by asymmetric keys. This means that a (communication) unit is bound to a specific secure element (SE) and cannot function with any other. In some embodiments, the secure element can, for example, store hash values of all protected operating system instance images and operating system instance configuration files in the system. These hash values are only accessible if a correct PIN is entered and if the determined hash values match the corresponding hash values from the last execution of the operating system instance.
[0129] In some implementations, a locked secure element does not grant access to stored keys. For example, an operating system instance without a valid hash cannot be decrypted—at least not if the operating system instance's management layer has not been tampered with. Each workspace instance can have a key stored in the secure element, protected by its own PIN (e.g., a private asymmetric key that can decrypt a symmetric key used to encrypt that workspace instance).
[0130] According to embodiments, the key of the filing instance (in Fig. 4. The key “android0”) (e.g., a symmetric key used to encrypt the login instance) is encrypted in the secure element but is not protected by a PIN, as it must be decrypted before a GUI for PIN entry is provided (this GUI is provided by the login instance). Since the login instance does not store any user data, this does not pose a security risk. In another embodiment, the PIN is the hash of the login instance.
[0131] In some embodiments, the work environment instances, and in some of these embodiments also the login instance, can be implemented as an operating system instance that implements an Android system. Here, the login instance can be designated as "android0" and the work environment instance as "android1", "android2", etc., or generally as "androidX".
[0132] Fig. Figure 4 shows an example of integrity protection for the login instance (android0) and for the workspace instances (androidX). Specifically, it shows Fig. 4. A system implementation of one embodiment as a layered architecture. Some of the units of the layered architecture are classified as trusted. These would logically be included in the TCB (Trusted Boot Block) and accordingly incorporated into the hash calculation of the individual instances (directly or as a hash chain). The bootloader, etc., could also be included, resulting in a Secure Boot-based system. For other units, protection is implemented through encryption.
[0133] In other implementations, the operating system is Linux-based. At least two operating system instances exist, each implemented as a different Linux system. For example, one operating system instance could implement a Firefox OS system, another an Ubuntu system, and a third an Android system.
[0134] According to some embodiments, system updates also require a valid cryptographic signature, which in one embodiment is validated by the secure element.
[0135] Returning to the Fig. Regarding the security provided by cryptographic encryption, in one embodiment of devices 1a to 3, interface 130 can be configured to receive a first symmetric cryptographic key from information element 900 as the cryptographic information. Devices 100, 200, and 300 can then be configured to decrypt the data of the login instance 140 based on this first symmetric cryptographic key, in order to generate decrypted data of login instance 140. Furthermore, devices 100, 200, and 300 can be configured to send the user input with a public asymmetric cryptographic key to generate the transmission message. Finally, the interface can be configured to transmit the transmission message to the information element.
[0136] According to a further embodiment, an encrypted second symmetric cryptographic key is stored in the non-volatile memory of the storage unit 120. The interface 130 is configured to transmit the encrypted second symmetric cryptographic key to the information element 900 in order to receive an unencrypted second cryptographic key from the information element.The device 100; 200; 300 is configured to decrypt the data of said one work environment instance 141, the one or more work environment instances 141, 142 using the unencrypted second cryptographic key, in order to generate the decrypted data of this work environment instance 141, and, depending on the decrypted data of this work environment instance 141, to execute the one or more processes assigned to this work environment instance 141 on the processor unit 120.
[0137] In a further embodiment, the device 100; 200; 300 can be configured to provide a further graphical interface that allows the user to select one of the work environment instances 141; 142 as the selected work environment instance 141, and to decrypt the data of the selected work environment instance 141 in order to generate decrypted data of the selected work environment instance 141, and, depending on the decrypted data of the selected work environment instance 141, to execute one or more processes associated with the selected work environment instance 141 on the processor unit 110.
[0138] Regarding integrity protection by means of hash values, in one embodiment the device 100; 200; 300 can be configured, when the verification result shows the first result, to decrypt the data of one or more work environment instances 141, 142 in order to generate decrypted data of this work environment instance 141, wherein the device 100; 200; 300 is further configured to perform a hash calculation that depends on the decrypted data of this work environment instance 141 in order to obtain a calculated hash value for this work environment instance 141, and wherein the device 100; 200; 300 is configured to compare the calculated hash value for this work environment instance 141 with a stored hash value for this work environment instance 141.
[0139] According to one embodiment, the device 100; 200; 300 can be configured to decrypt the data of the application instance 140 based on the cryptographic information in order to generate decrypted data of the application instance 140, wherein the device 100; 200; 300 is further configured to perform a hash calculation that depends on the decrypted data of the application instance 140 in order to obtain a calculated hash value for the application instance 140, and wherein the device is configured to compare the calculated hash value for the application instance 140 with a stored hash value for the application instance 140.
[0140] The system comprises the device 100; 200; 300 and the information element 900. Fig. With regard to paragraphs 1a-3, in one embodiment the information element 900 can be configured to transmit a first cryptographic key as cryptographic information to the interface 130 of the device 100; 200; 300. The device 100; 200; 300 can be configured, based on the cryptographic key, to decrypt the data of the application instance 140 in order to generate decrypted data of the application instance 140, and, depending on the decrypted data of the application instance 140, to execute one or more processes associated with the application instance 140 on the processor unit 110 of the device 100; 200; 300 in order to provide a graphical interface that allows user input. The device 100; 200; 300 can be configured to encrypt the user input in order to obtain encrypted user input.
[0141] The interface 130 of the device 100; 200; 300 can be configured to transmit the encrypted user input to the information element 900. Furthermore, the information element 900 can be configured to decrypt the encrypted user input in order to obtain decrypted user input. The concepts described above are implemented in various embodiments.
[0142] The information element 900 can be configured to perform a comparison between a stored PIN and the decrypted user input. Furthermore, the information element 900 can be configured to generate a response message and transmit it to the interface 130 of the device 100; 200; 300, which includes the verification result. The verification result is the first result if the stored PIN and the decrypted user input match, and the verification result is the second result if the stored PIN and the decrypted user input do not match.
[0143] Fig. Figure 5 shows an information element 900 (also referred to as a “safe element”) according to one embodiment.
[0144] The information element 900 comprises a storage unit 910, which includes non-volatile memory, a processor unit 920, and an interface 930.
[0145] The non-volatile memory of storage unit 910 stores one or more private cryptographic keys of one or more asymmetric key pairs.
[0146] The 930 interface is designed to receive an encrypted cryptographic key or other data (in embodiments, the information element can also be used, for example, for email signatures, VPN, SSL, etc. after activation), whereby the encrypted cryptographic key can be decrypted using the private cryptographic key.
[0147] The 920 processor unit is designed to decrypt the encrypted cryptographic key or other data using one or more private cryptographic keys in order to obtain a decrypted cryptographic key or decrypted data.
[0148] Interface 930 is configured to output the decrypted cryptographic key or the decrypted data. Furthermore, interface 930 is configured to receive an encrypted PIN that can be decrypted using the private cryptographic key or the decrypted data.
[0149] The processor unit 920 is configured to decrypt the encrypted PIN using the private cryptographic key or the decrypted data to obtain a decrypted PIN. Furthermore, the processor unit 920 is configured to compare the decrypted PIN with a stored PIN to obtain a verification result, the stored PIN being stored in the non-volatile memory of the storage unit 910. The verification result will either have a first result if the verification result indicates that the decrypted PIN and the stored PIN match, or it will have a second result that differs from the first result if the verification result indicates that the decrypted PIN and the stored PIN do not match.
[0150] In some versions, it is possible to change the PIN.
[0151] According to some embodiments, a locked PIN can be unlocked again using a PUK.
[0152] Furthermore, the processor unit 920 is configured to generate a response message containing the verification result. The interface 930 is configured to output the response message.
[0153] Implementation methods realize integrity protection, for example, linking instances to cryptographic keys in secure elements, linking smartphones to secure elements, releasing secure elements only after correct PIN entry, which in turn is derived from the cryptographic hash of all involved software components, using the secure elements in other scenarios such as VPN after successful integrity check and / or changing hashes and thus changing the PIN of the secure element, or alternatively changing the stored hash in the secure element.
[0154] Although some aspects have been described in connection with a device, it is understood that these aspects also constitute a description of the corresponding process, such that a block or component of a device can also be understood as a corresponding process step or as a feature of a process step. Similarly, aspects described in connection with or as a process step also constitute a description of a corresponding block, detail, or feature of a corresponding device. Some or all of the process steps can be performed by (or using) a hardware apparatus, such as a microprocessor, a programmable computer, or an electronic circuit. In some embodiments, some or more of the key process steps can be performed by such an apparatus.
[0155] Depending on specific implementation requirements, embodiments of the invention can be implemented in hardware or in software. The implementation can be carried out using a digital storage medium, for example, a floppy disk, DVD, Blu-ray disc, CD, ROM, PROM, EPROM, EEPROM, FLASH memory, hard disk, or other magnetic or optical storage medium, on which electronically readable control signals are stored. These control signals can interact with, or interact with, a programmable computer system in such a way as to execute the respective method. Therefore, the digital storage medium can be computer-readable.
[0156] Some embodiments according to the invention therefore comprise a data carrier which has electronically readable control signals which are able to interact with a programmable computer system in such a way that one of the methods described herein is carried out.
[0157] In general, embodiments of the present invention can be implemented as a computer program product with a program code, wherein the program code is effective in carrying out one of the methods when the computer program product runs on a computer.
[0158] The program code can also be stored on a machine-readable medium, for example.
[0159] Other embodiments include a computer program for carrying out one of the methods described herein, wherein the computer program is stored on a machine-readable medium. In other words, an embodiment of the method according to the invention is thus a computer program that includes program code for carrying out one of the methods described herein when the computer program is executed on a computer.
[0160] Another embodiment of the methods according to the invention is therefore a data carrier (or a digital storage medium or a computer-readable medium) on which the computer program for carrying out one of the methods described herein is recorded.
[0161] Another embodiment of the method according to the invention is thus a data stream or a sequence of signals that represents the computer program for carrying out one of the methods described herein. The data stream or sequence of signals can be configured, for example, to be transferred via a data communication connection, such as the Internet.
[0162] Another embodiment comprises a processing device, for example a computer or a programmable logic device, which is configured or adapted to perform one of the methods described herein.
[0163] Another embodiment comprises a computer on which the computer program for performing one of the procedures described herein is installed.
[0164] Another embodiment of the invention comprises a device or system designed to transmit a computer program for carrying out at least one of the methods described herein to a receiver. The transmission can be, for example, electronic or optical. The receiver can be, for example, a computer, a mobile device, a storage device, or a similar device. The device or system can, for example, include a file server for transmitting the computer program to the receiver.
[0165] In some embodiments, a programmable logic device (for example, a field-programmable gate array, an FPGA) can be used to perform some or all of the functionalities of the methods described herein. In some embodiments, a field-programmable gate array can interact with a microprocessor to perform one of the methods described herein. Generally, in some embodiments, the methods are performed by any hardware device. This can be general-purpose hardware such as a computer processor (CPU) or method-specific hardware such as an ASIC.
[0166] The embodiments described above merely illustrate the principles of the present invention. It is understood that modifications and variations of the arrangements and details described herein will be obvious to other people skilled in the art. Therefore, it is intended that the invention be limited only by the scope of protection set forth in the following claims and not by the specific details presented herein by way of description and explanation of the embodiments.
Claims
[1] Device (100; 200; 300), comprising: a processor unit (110) comprising one or more processors, a storage unit (120) comprising non-volatile memory, an interface (130) for data transmission to an information element (900) and for data reception from the information element (900), and a group of operating system instances (140, 141, 142), wherein the group of operating system instances (140, 141, 142) comprises one or more work environment instances (141, 142), wherein each operating system instance (140, 141, 142) of the group of operating system instances (140, 141, 142) contains data, wherein the data of each operating system instance (140, 141, 142) of the group of operating system instances (140, 141, 142) is stored encrypted in the non-volatile memory of the storage unit (120), wherein the device (100; 200; 300) is configured, when a verification result has a first result, to decrypt the data of one (141) of the one or more work environment instances (141, 142) in order to generate decrypted data of this work environment instance (141), and depending on the decrypted data of this work environment instance (141), to execute one or more processes associated with this work environment instance (141) on the processor unit (110), and wherein the device (100; 200; 300) is configured to decode the data of any of the one or more work environment instances (141, 142) if the verification result has a second result that is different from the first result, wherein the group of operating system instances (140, 141, 142) further includes a login instance (140), wherein the interface (130) is set up to receive cryptographic information or other data from the information element (900), wherein the device (100; 200; 300) is configured to decrypt the data of the filing instance (140) based on the cryptographic information or other data in order to generate decrypted data of the filing instance (140), and, depending on the decrypted data of the filing instance (140), to execute one or more processes associated with the filing instance (140) on the processor unit (110) in order to provide a graphical interface that allows user input, wherein the interface (130) is configured to transmit the user input or a transmission message dependent on the user input to the information element (900), and wherein the interface (130) is configured to receive a response message after this transmission which includes the verification result. [2] Device (100; 200; 300) according to claim 1, wherein the interface (130) is set up to obtain a first symmetric cryptographic key from the information element (900) as the cryptographic information, wherein the device (100; 200; 300) is configured to decrypt the data of the filing instance (140) based on the first symmetric cryptographic key in order to generate decrypted data of the filing instance (140), and wherein the device (100; 200; 300) is configured to send the user input with a public asymmetric cryptographic key in order to generate said transmission message, and wherein the interface (130) is configured to transmit the message to the information element (900). [3] Device (100; 200; 300) according to claim 1 or 2, wherein an encrypted second symmetric cryptographic key is stored in the non-volatile memory of the storage unit (120), wherein the interface (130) is set up to transmit the encrypted second symmetric cryptographic key to the information element (900) in order to receive an unencrypted second cryptographic key from the information element (900). [4] Device (100; 200; 300) according to claim 3, wherein the device (100; 200; 300) is configured to decrypt the data of said one (141) of the one or more work environment instances (141, 142) using the unencrypted second cryptographic key in order to generate the decrypted data of this work environment instance (141) and, depending on the decrypted data of this work environment instance (141), to execute the one or more processes associated with this work environment instance (141) on the processor unit (110). [5] Device (100; 200; 300) according to claim 1 or 2, wherein the device (100; 200; 300) is configured to provide a further graphical interface that enables the user to select one of the work environment instances (141) as the selected work environment instance (141, 142), and to decrypt the data of the selected work environment instance (141) in order to generate decrypted data of the selected work environment instance (141), and, depending on the decrypted data of the selected work environment instance (141), to execute one or more processes associated with the selected work environment instance (141) on the processor unit (110). [6] Device (100; 200; 300) according to any one of the preceding claims, wherein the device (100; 200; 300) further comprises an operating system kernel (150), wherein the operating system kernel (150) is configured, if the verification result shows the said first result, to decrypt the data of said work environment instance (141) in order to generate the decrypted data of this work environment instance (141), and depending on the decrypted data of this work environment instance (141), to execute the one or more processes assigned to this work environment instance (141) on the processor unit (110), and wherein the operating system kernel (150) is configured, if the verification result shows the said second result which differs from the first result, not to decrypt the data of any of the one or more work environment instances (141, 142). [7] Device (100; 200; 300) according to claim 6, wherein the operating system kernel (150) is a Linux operating system kernel. [8] Device (100; 200; 300) according to claim 7, wherein each operating system instance (140, 141, 142) of the group of operating system instances (140, 141, 142) is based on Linux. [9] Device (100; 200; 300) according to any one of claims 6 to 8, wherein the device (100; 200; 300) further comprises an operating system instance management layer, wherein the operating system instance management layer (160) is formed when the verification result shows said first result, to transmit one or more instructions to the operating system kernel (150), causing the operating system kernel (150) to decrypt the data of said working environment instance (141) in order to generate the decrypted data of this working environment instance (141), and depending on the decrypted data of this working environment instance (141), to execute the one or more processes associated with this working environment instance (141) on the processor unit (110), and wherein the operating system instance management layer (160) is formed when the verification result shows the said second result, not to transmit any instruction to the operating system kernel (150) by which the operating system kernel (150) would be caused to decrypt the data of one of the work environment instances (141, 142). [10] Device (100; 200; 300) according to any one of the preceding claims, wherein the device (100; 200; 300) is configured, when the verification result shows said first result, to decrypt the data of one (141) of the one or more work environment instances (141, 142) in order to generate decrypted data of this work environment instance (141), wherein the device (100; 200; 300) is further configured to perform a hash calculation that depends on the decrypted data of this work environment instance (141) in order to obtain a calculated hash value for this work environment instance (141), and wherein the device (100; 200; 300) is configured to compare the calculated hash value for this work environment instance (141) with a stored hash value for this work environment instance (141). compare. [11] Device (100; 200; 300) according to claim 1, wherein the device (100; 200; 300) is configured to decrypt the data of the application instance (140) based on the cryptographic information in order to generate decrypted data of the application instance (140), wherein the device (100; 200; 300) is further configured to perform a hash calculation which depends on the decrypted data of the application instance (140) in order to obtain a calculated hash value for the application instance, and wherein the device (100; 200; 300) is configured to compare the calculated hash value for the application instance (140) with a stored hash value for the application instance (140). [12] Device (100; 200; 300) according to any of the preceding claims, wherein the device (100; 200; 300) is a communication unit designed to send messages to other communication units of a wireless or wired network and to receive messages from these other communication units. [13] Device (100; 200; 300) according to any one of claims 1 to 11, wherein the device (100; 200; 300) is a mobile communication unit designed to send messages to other communication units of a wireless or wired network and to receive messages from these other communication units. [14] Device (100; 200; 300) according to one of the preceding claims, wherein the device (100; 200; 300) is configured to encrypt a first working environment instance (141, 142) of the operating system instances (140, 141, 142) with a first cryptographic key, wherein the device (100; 200; 300) is configured to encrypt a second working environment instance (141, 142) of the operating system instances (140, 141, 142) with a second cryptographic key, and wherein the first cryptographic key and the second cryptographic key have different key lengths. [15] Device (100; 200; 300) according to one of the preceding claims, wherein the device (100; 200; 300) is a communication unit of a communication network which is configured to transfer one of the operating system instances (140, 141, 142) of the device (100; 200; 300) in the communication network to another communication unit of the communication network. [16] System, encompassing: a device (100; 200; 300) according to one of claims 1 to 15, and an information element (900), wherein the information element (900) is configured to transmit cryptographic information to the interface (130) of the device (100; 200; 300), wherein the device (100; 200; 300) is configured to decrypt the data of the login instance (140) based on this cryptographic information in order to generate decrypted data of the login instance (140), and, depending on the decrypted data of the login instance (140), to execute one or more processes associated with the login instance (140) on the processor unit (110) in order to provide a graphical interface that allows user input, wherein the interface (130) of the device (100; 200; 300) is configured to transmit the user input or a transmission message dependent on the user input to the information element (900), wherein the information element (900) is configured to perform a comparison between stored information and the received information, wherein the received information depends on the user input or the sent message in order to obtain a verification result, wherein the verification result, depending on the comparison, either has a first result or has a second result that is different from the first result, wherein the information element (900) is configured to generate a response message and transmit it to the device (100; 200; 300), the response message comprising the verification result, wherein the interface (130) of the device (100; 200; 300) is configured for this purpose, to receive the reply message, wherein the device (100; 200; 300) is configured, when the verification result shows the first result, to decrypt the data of one (141) of the one or more work environment instances (141, 142) in order to generate decrypted data of this work environment instance (141), and depending on the decrypted data of this work environment instance (141), to execute one or more processes associated with this work environment instance (141) on the processor unit (110) of the device (100; 200; 300), and wherein the device (100; 200; 300) is configured to decode the data of none of the one or more work environment instances (141, 142) if the verification result shows the second result. [17] System according to claim 16, wherein the information element (900) is configured to transmit a first cryptographic key as cryptographic information to the interface (130) of the device (100; 200; 300), wherein the device (100; 200; 300) is configured to decrypt the data of the login instance (140) based on the cryptographic key in order to generate decrypted data of the login instance (140), and, depending on the decrypted data of the login instance (140), to execute one or more processes associated with the login instance (140) on the processor unit (110) of the device (100; 200; 300) in order to provide a graphical interface that allows user input, wherein the device (100; 200; 300) is configured to encrypt the user input in order to obtain encrypted user input, wherein the interface (130) of the device (100; 200; 300) is configured to transmit the encrypted user input to the information element (900), wherein the information element (900) is configured to decrypt the encrypted user input in order to obtain a decrypted user input, wherein the information element (900) is configured to perform a comparison between a stored PIN and the decrypted user input, wherein the information element (900) is configured to generate a response message and transmit it to the interface (130) of the device (100; 200; 300) which includes the verification result, wherein the verification result has the first result if the stored PIN and the decrypted user input match, and wherein the verification result has the second result if the stored PIN and the decrypted user input do not match. [18] System according to claim 16, wherein the information element (900) comprises: a storage unit (910) of the information element (900) comprising a non-volatile memory, a processor unit (920) of the information element (900), and an interface (930) of the information element (900), wherein one or more private cryptographic keys of one or more asymmetric key pairs are stored in the non-volatile memory of the storage unit (910) of the information element (900), wherein the interface (930) of the information element (900) is configured to receive an encrypted cryptographic key or other data, wherein the encrypted cryptographic key is decryptable using the private cryptographic key, wherein the processor unit (920) of the information element (900) is configured to decrypt the encrypted cryptographic key or other data using one or more private cryptographic keys in order to obtain a decrypted cryptographic key or decrypted data, wherein the interface (930) of the information element (900) is configured to output the decrypted cryptographic key or the decrypted data, wherein the interface (930) of the information element (900) is configured to receive an encrypted PIN which can be decrypted using the private cryptographic key or the decrypted data, wherein the processor unit (920) of the information element (900) is configured to decrypt the encrypted PIN using the private cryptographic key or the decrypted data in order to obtain a decrypted PIN, wherein the processor unit (920) of the information element (900) is configured to compare the decrypted PIN with a stored PIN in order to obtain a verification result, wherein the stored PIN is stored in the non-volatile memory of the storage unit (910) of the information element (900), wherein the verification result either has a first result if the verification result indicates that the decrypted PIN and the stored PIN match, or has a second result that differs from the first result if the verification result indicates that the decrypted PIN and the stored PIN do not match, and wherein the processor unit (920) of the information element (900) is configured to generate a response message that includes the verification result, wherein the interface (930) of the information element (900) is configured to output the response message. [19] System, encompassing: a first device (100; 200; 300) according to any one of claims 1 to 15, and a second device (100; 200; 300) according to any one of claims 1 to 15, wherein the first device (100; 200; 300) is designed to transfer one of the operating system instances (140, 141, 142) of the first device (100; 200; 300) from the first device (100; 200; 300) to the second device (100; 200; 300), and wherein the second device (100; 200; 300) is designed to receive said one of the operating system instances (140, 141, 142) of the first device (100; 200; 300) from the first device (100; 200; 300). [20] Procedures, including: If a verification result yields a first result, decrypt data of a work environment instance (141) of one or more work environment instances (141, 142) of a group of operating system instances (140, 141, 142) to generate decrypted data of this work environment instance (141), wherein each operating system instance (140, 141, 142) of the group of operating system instances (140, 141, 142) contains data, wherein the data of each operating system instance (140, 141, 142) of the group of operating system instances (140, 141, 142) is stored encrypted in the non-volatile memory of a memory unit (120), and, depending on the decrypted data of said work environment instance (141), execute one or more processes associated with this work environment instance (141) on a processor unit (110), and if the verification result shows a second result that is different from the first result, no decryption of the data of one or more work environment instances (141, 142), wherein the group of operating system instances (140, 141, 142) further includes a login instance (140), wherein cryptographic information or other data is obtained from the information element (900), wherein, based on the cryptographic information or other data, the login instance (140) data is decrypted to generate decrypted login instance (140) data, and, depending on the decrypted login instance (140) data, one or more processes associated with the login instance (140) are executed on the processor unit (110) to provide a graphical interface that allows user input, wherein the user input or a send message dependent on the user input is transmitted to the information element (900), and wherein, following such transmission, a response message is received which includes the verification result. [21] Computer program comprising program code for carrying out the method according to claim 20.
Citation Information
Patent Citations
Token-enabled authentication for securing mobile devices
US20070150736A1
Method and apparatus for providing a secure virtual environment on a mobile device
US20130042295A1