Electronic device, communication software integrity guaranteeing method in electronic device, and storage medium
Patent Information
- Application Number
- PCT/KR2024/004718
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-06-07
- Filing Date
- 2024-04-09
- Publication Date
- 2025-08-14
AI Technical Summary
Electronic devices are vulnerable to malicious attacks that compromise the integrity of communication software, leading to security breaches and disruption of communication functions.
Incorporating a security processor and secure memory within electronic devices to verify the integrity of communication software, store trusted versions, and switch to a backup version upon integrity failure, ensuring continuous communication functionality.
Prevents malicious tampering and ensures the integrity and security of communication software, allowing for immediate recovery and restoration of normal communication functions.
Smart Images

Figure KR2024004718_14082025_PF_FP_ABST
Abstract
Description
Method for ensuring integrity of communication software in electronic devices and electronic devices, and storage media
[0001] Embodiments of the present disclosure relate to an electronic device and an operating method thereof, and a storage medium, and to a method for ensuring the integrity of communication software in an electronic device.
[0002] As information and communication technology develops, various functions are being integrated into communication devices or electronic devices, and electronic devices include a central processing unit (CPU) (e.g., an application processor) and memory, and can execute programs stored in the memory (e.g., a communication program (or communication software)) through the central processing unit.
[0003] Electronic devices can communicate with external devices by running communication software. Electronic devices can transmit and receive information with external entities through communication. Information received by the electronic device through communication may include malicious information intended to target or attack the communication software.
[0004] The above information may be provided as background art to aid in understanding the present disclosure. No claim or determination is made as to whether any of the above is applicable as prior art related to the present disclosure.
[0005] Malicious information received by an electronic device targeting or attacking the communication software can allow an external attacker to seize control of the communication software, or the communication software can be modified to operate as the attacker intends. If control of the communication software is seized or maliciously modified, compromising its integrity, the electronic device may not be able to perform its communication functions properly, and the security of various information stored on the electronic device may be compromised.
[0006] According to one embodiment of the present disclosure, an electronic device may include a first memory, a second memory, a secure memory including instructions, a communication processor, an application processor, and a security processor. The instructions according to one embodiment may be configured to cause the electronic device to obtain first information for integrity verification of communication software received from the application processor through a first storage area of the second memory and store the first information in the secure memory when executed by the security processor. The security processor according to one embodiment may store first communication software corresponding to the communication software in a second storage area of the second memory. The instructions according to one embodiment may, when executed by the security processor, cause the electronic device to command the communication processor to execute the first communication software. The instructions according to one embodiment may, when executed by the security processor, cause the electronic device to obtain second information for integrity verification of the first communication software based on satisfaction of a specified condition. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to suspend execution of the first communication software based on identification of an integrity verification failure of the first communication software based on a comparison of the first information and the second information. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to load second communication software corresponding to the communication software into the second storage area. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to command execution of the second communication software by the communication processor.
[0007] According to one embodiment of the present disclosure, a method for ensuring the integrity of communication software in an electronic device may include an operation of acquiring first information for integrity verification of communication software received from an application processor through a first storage area of a second memory and storing the information in a secure memory. According to one embodiment, the method may include an operation of storing first communication software corresponding to the communication software in a second storage area of the second memory. According to one embodiment, the method may include an operation of commanding execution of the first communication software by the communication processor. According to one embodiment, the method may include an operation of acquiring second information for integrity verification of the first communication software based on satisfaction of the specified condition. According to one embodiment, the method may include an operation of stopping execution of the first communication software based on identification of a failure in integrity verification of the first communication software based on a comparison of the first information and the second information. According to one embodiment, the method may include an operation of loading second communication software corresponding to the communication software in the second storage area and commanding execution of the second communication software by the communication processor.
[0008] According to one embodiment of the present disclosure, in a non-transitory storage medium storing commands, the commands are configured to cause the electronic device to perform at least one operation when executed by the electronic device, wherein the at least one operation may include: an operation of obtaining first information for integrity verification of communication software received from an application processor through a first storage area of a second memory and storing the information in a secure memory; an operation of storing first communication software corresponding to the communication software in a second storage area of the second memory; an operation of commanding execution of the first communication software by the communication processor; an operation of obtaining second information for integrity verification of the first communication software based on satisfaction of the specified condition; an operation of stopping execution of the first communication software based on identification of integrity verification failure of the first communication software based on comparison of the first information and the second information; and an operation of loading second communication software corresponding to the communication software into the second storage area and commanding execution of the second communication software by the communication processor.
[0009] According to one embodiment of the present disclosure, integrity verification of communication software is possible and recovery of communication software is possible upon integrity verification failure.
[0010] According to one embodiment of the present disclosure, if control of the communication software is hijacked or the communication software is maliciously modified while the communication software is running, the running communication software can be stopped and the original communication software can be re-run.
[0011] FIG. 1 is a block diagram of an electronic device within a network environment according to one embodiment.
[0012] Figure 2 is a block diagram of an electronic device according to one embodiment.
[0013] FIG. 3 is a diagram illustrating a security processor and a secure memory according to one embodiment.
[0014] FIG. 4 is a flowchart illustrating operations between processes for ensuring communication software integrity in an electronic device according to one embodiment.
[0015] FIG. 5 is a flowchart illustrating the operation of a security processor of an electronic device according to one embodiment.
[0016] FIG. 6 is a flowchart illustrating an operation of a security processor of an electronic device according to one embodiment of the present invention to double-load and process data in an area of a second memory.
[0017] FIG. 7 is a flowchart illustrating an operation of a security processor of an electronic device performing integrity verification and recovery based on an integrity verification process start event according to one embodiment.
[0018] In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components.
[0019] The terms used in this document are used only to describe specific embodiments and may not be intended to limit the scope of other embodiments. The singular expression may include the plural expression unless the context clearly indicates otherwise. All terms used herein, including technical or scientific terms, may have the same meaning as commonly understood by those of ordinary skill in the art of the present invention. Terms defined in commonly used dictionaries may be interpreted as having the same or similar meaning in the context of the relevant technology, and shall not be interpreted in an idealized or overly formal sense unless explicitly defined in this document. In some cases, even if a term is defined in this document, it cannot be interpreted to exclude embodiments of the present invention.
[0020] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to one embodiment.
[0021] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).
[0022] The processor (120) may control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) by executing, for example, software (e.g., a program (140)), and may perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculation, the processor (120) may store a command or data received from another component (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the command or data stored in the volatile memory (132), and store the resulting data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.
[0023] The auxiliary processor (123) may control at least a part of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.
[0024] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).
[0025] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).
[0026] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).
[0027] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. According to one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.
[0028] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. According to one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.
[0029] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).
[0030] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.
[0031] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.
[0032] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., the electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).
[0033] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. According to one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.
[0034] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.
[0035] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented as, for example, at least a part of a power management integrated circuit (PMIC).
[0036] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.
[0037] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).
[0038] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) may support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.
[0039] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). According to one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a PCB). According to one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas, for example, by the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device via the selected at least one antenna. According to some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).
[0040] In one embodiment, the antenna module (197) may form a mmWave antenna module. In one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent to a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent to a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.
[0041] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).
[0042] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service by itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.
[0043] Figure 2 is a block diagram of an electronic device according to one embodiment.
[0044] Referring to FIG. 2, an electronic device (201) according to an embodiment (e.g., the electronic device (101) of FIG. 1) may include an application processor (221), a communication processor (290), a security processor (223), an access controller (235), a first memory (234), a second memory (232), and / or a secure memory (236). The electronic device (201) according to an embodiment is not limited thereto and may further include various components or may be configured by excluding some of the components. The electronic device (201) according to an embodiment may further include all or part of the electronic device (101) illustrated in FIG. 1.
[0045] According to one embodiment, the first memory (234) may store communication software (or a communication program or a communication application program) (20). The communication software (20) according to one embodiment may be installed during the manufacturing of the electronic device (201) or downloaded and stored after the manufacturing of the electronic device (201). According to one embodiment, the first memory (234) may include a nonvolatile memory (e.g., the nonvolatile memory (134) of FIG. 1).
[0046] The second memory (232) according to one embodiment may include a first storage area (21), a second storage area (23), and / or a third storage area (25). The first storage area (21), the second storage area (23), and / or the third storage area (25) according to one embodiment may be areas that are divided or designated based on access rights. The first storage area (21) according to one embodiment may include a command transmission and reception area that is accessible to all of the application processor (221), the communication processor (290), and the security processor (223). The application processor (221), the communication processor (290), and the security processor (223) according to one embodiment may each access the command transmission and reception area when an event occurs or periodically in order to transmit and receive commands among themselves. In one embodiment, the first storage area (21) may store commands (and / or data) transmitted and received between the application processor (221) and the communication processor (290), commands (and / or data) transmitted and received between the application processor (221) and the security processor (223), and commands (and / or data) transmitted and received between the communication processor (290) and the security processor (223). In one embodiment, the second storage area (23) may include a communication software execution area exclusively accessible by the communication processor (290). In one embodiment, the second storage area (23) may include an area in which communication software (e.g., the first communication software) stored by the communication processor (290) may be executed. In one embodiment, the third storage area (25) may include a preservation area exclusively accessible by the security processor (223). In one embodiment, the third storage area (25) may store communication software (e.g., second communication software) by the security processor (223).
[0047] An access controller (235) according to an embodiment may be included as part of a bus or may include an access control circuit. The access controller (235) according to an embodiment may control access rights of the communication software (20) of the first memory (234), the first storage area (21) of the second memory (232), the second storage area (23) of the second memory (232), and / or the third storage area (25) of the second memory (232). The access controller (235) according to an embodiment may include a shared access controller (242) and / or an exclusive access controller (244). The shared access controller (242) according to an embodiment may perform shared access control of the first storage area (21) of the second memory (232). According to one embodiment, an exclusive access controller (244) may perform exclusive access control of the communication software (20) of the first memory (234), the second storage area (23) of the second memory (232), and / or the third storage area (25) of the second memory (232).
[0048] An application processor (221) according to one embodiment (e.g., processor (120) of FIG. 1) may include a central processing unit (CPU). The application processor (221) according to one embodiment may perform overall control operations associated with the electronic device (201) and may execute, process, or install application software.
[0049] According to an embodiment, the application processor (221) may load (or load or store) the communication software (20) stored in the first memory (234) into the first storage area (21) of the second memory (232). According to an embodiment, the application processor (221) may read the communication software (20) stored in the first memory (234) based on the booting of the electronic device (201), access the first storage area (21) of the second memory (232) through the access controller (235), and load the read communication software (20) into the first storage area (21). According to an embodiment, the application processor (221) may store a command (or data) for causing the security processor (223) to start an integrity verification process after loading the communication software (20) into the first storage area (21), in the first storage area (21).
[0050] A security processor (223) according to an embodiment may receive communication software through a first storage area (21) of a second memory (232). A security processor (223) according to an embodiment may obtain first information for integrity verification of the communication software and store it in a secure memory (236), and store first communication software (e.g., a first copy of the received communication software) corresponding to the communication software in a second storage area (23) of a second memory (232). The first information for integrity verification of the communication software according to an embodiment may include a first hash value that is pre-specified or calculated corresponding to the communication software. A security processor (223) according to an embodiment may further store second communication software (e.g., a second copy of the received communication software) corresponding to the communication software in a third storage area (25) of the second memory (232). According to an embodiment, the security processor (223) may transmit a command to the communication processor (290) to execute the first communication software stored in the second storage area (23) to the first storage area (21) of the second memory (232). According to an embodiment, the communication processor (290) may execute the first communication software based on the command obtained through the first storage area (21) to perform a communication process. According to an embodiment, the security processor (223) may obtain second information for integrity verification of the first communication software based on a specified condition. According to an embodiment, the specified condition may include a specified time period or the occurrence of a specified event. According to an embodiment, the second information may include a second hash value calculated corresponding to the first communication software at a point in time according to the specified time period or the occurrence of the event. According to an embodiment, the security processor (223) may compare the first information with the second information to identify whether the integrity verification of the first communication software succeeds or fails.A security processor (223) according to an embodiment may identify a success of the integrity verification of the first communication software based on a match between the first information and the second information. A security processor (223) according to an embodiment may identify a failure of the integrity verification of the first communication software based on a mismatch between the first information and the second information. A security processor (223) according to an embodiment may suspend the operation of a communication process using the first communication software based on a failure of the integrity verification using the first information and the second information and load the second communication software corresponding to the communication software (e.g., the second communication software stored in the third storage area (25) or the communication software re-received from the first memory (234)) into the second storage area (23). A security processor (223) according to an embodiment may transmit a command to re-perform the communication process using the second communication software re-loaded into the second storage area (23) to the first storage area (21) of the second memory (232). According to one embodiment, a communication processor (290) can re-perform a communication process by executing second communication software based on a command obtained through the first storage area (21).
[0051] The secure memory (236) according to one embodiment may include memory accessible only by the security processor (223). The secure memory (236) according to one embodiment may store a program and data for integrity verification of the first communication software stored in the first storage area (21), and may store first information (e.g., a first hash value) designated or acquired for integrity verification of the first communication software.
[0052] According to one embodiment, a communication processor (290) can perform, suspend, or re-perform a communication process by executing communication software (first communication software or second communication software) stored in a second storage area (23) based on a command obtained through a first storage area (21).
[0053] An electronic device (201) according to an embodiment may further include a display (e.g., a display module (160) of FIG. 1), although not shown in FIG. 2, and may visually provide information to an external device (e.g., a user) of the electronic device (201). The display of the electronic device (201) according to an embodiment may, based on the control of the application processor (221), display information regarding a failure in integrity verification of the communication software (or the first communication software), and display information related to recovery of the communication software in response to the failure in integrity verification.
[0054] FIG. 3 is a diagram illustrating a security processor (223) and a security memory (236) according to one embodiment.
[0055] A security processor (223) according to one embodiment may include a software deployment engine (310), an integrity verification engine (320), and / or an integrity recovery engine (330). Each of the software deployment engine (310), the integrity verification engine (320), and / or the integrity recovery engine (330) according to one embodiment may be a software module or a program module.
[0056] A software deployment engine (310) according to one embodiment may receive communication software from an application processor (e.g., an application processor (221) of FIG. 2) through a first storage area (e.g., a first storage area (21) of FIG. 2) of a second memory (e.g., a second memory (232) of FIG. 2)), and store first software corresponding to the received communication software in a second storage area (e.g., a second storage area (23) of FIG. 2) of the second memory (e.g., a second memory (232) of FIG. 2).
[0057] An integrity verification engine (320) according to an embodiment may obtain first information (e.g., a first hash value) for integrity verification of communication software received through a first storage area (21) of a second memory (232) and store it in a secure memory (236), and may obtain second information (e.g., a second hash value) for integrity verification corresponding to the first communication software stored in a second storage area (23) of a second memory (232) at a time according to a specified time period or at a time of occurrence of an event. An integrity verification engine (320) according to an embodiment may compare the first information and the second information at a time according to a specified time period or at a time of occurrence of an event to identify success or failure in integrity verification of the first communication software, and may execute an integrity recovery engine (330) when integrity verification fails.
[0058] In one embodiment, the integrity recovery engine (330) may stop the operation of the communication process using the first communication software based on the failure of the integrity verification using the first information and the second information and load the second communication software corresponding to the communication software (e.g., the second communication software stored in the third storage area (25) of FIG. 2 or the communication software re-received from the first memory (234)) into the second storage area (23). In one embodiment, the integrity recovery engine (330) may transmit a command to re-perform the communication process using the second communication software re-loaded into the second storage area (23) to the first storage area (21) of the second memory (232). In one embodiment, the communication processor (290) may execute the second communication software based on the command obtained through the first storage area (21) to re-perform the communication process.
[0059] An electronic device (e.g., electronic device (101) of FIG. 1 or electronic device (201) of FIG. 2) according to an embodiment may include a first memory (e.g., 134 of FIG. 1 or 234 of FIG. 2), a second memory (e.g., 132 of FIG. 1 or 232 of FIG. 2), a secure memory (e.g., 236 of FIG. 2) for storing commands, a communication processor (e.g., communication module 190 of FIG. 1 or communication processor 290 of FIG. 2), an application processor (e.g., processor 120 of FIG. 1 or application processor 221 of FIG. 2), and a security processor (e.g., security processor 223 of FIG. 2). The commands according to an embodiment, when executed by the security processor, may cause the electronic device to obtain first information for integrity verification of communication software received from the application processor through a first storage area of the second memory and store the first information in the secure memory. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to store first communication software corresponding to the communication software in a second storage area of the second memory. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to command the communication processor to execute the first communication software. The commands according to one embodiment, when executed by the security processor, may cause the electronic device to obtain second information for integrity verification of the first communication software based on satisfaction of the specified condition.The instructions according to one embodiment, when executed by the security processor, may cause the electronic device to stop execution of the first communication software based on identification of a failure in integrity verification of the first communication software based on a comparison of the first information and the second information, load second communication software corresponding to the communication software into the second storage area, and command the communication processor to execute the second communication software.
[0060] According to one embodiment, the first information may include a first hash value corresponding to the communication software, and the second information may include a second hash value corresponding to the first communication software.
[0061] The instructions according to one embodiment, when executed by the security processor, may cause the electronic device to further store the second communication software corresponding to the communication software in a third storage area of the second memory, and to load the second communication software stored in the third storage area into the second storage area when an integrity verification failure of the first communication software is identified.
[0062] In one embodiment, the electronic device further includes the access controller, and the access controller may be configured to control the application processor, the communication processor, and the security processor to access the first storage area, control the communication processor to access the second storage area, and control the security processor to access the third storage area.
[0063] The specified condition according to one embodiment may include a specified time period or the occurrence of a specified event.
[0064] The instructions according to one embodiment, when executed by the secure processor, may cause the electronic device to identify a success in the integrity verification of the first communication software based on a match between the first information and the second information, and to identify a failure in the integrity verification of the first communication software based on a mismatch between the first information and the second information.
[0065] The instructions according to one embodiment, when executed by the security processor, may cause the electronic device to identify whether the specified condition is satisfied upon successful integrity verification of the first communication software.
[0066] According to one embodiment, the security processor may include a software deployment engine, an integrity verification engine, and an integrity recovery engine.
[0067] According to one embodiment, the secure memory may be configured to be accessible only by the secure processor.
[0068] According to one embodiment, the application processor may be configured to transmit the communication software stored in the first memory to the security processor through the first storage area of the second memory based on booting of the electronic device.
[0069] FIG. 4 is a flowchart illustrating operations between processes for ensuring communication software integrity in an electronic device according to one embodiment.
[0070] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0071] Referring to FIG. 4, an application processor (221), a communication processor (290), or a security processor (223) of an electronic device (201) (e.g., the electronic device (101) of FIG. 1) according to one embodiment may perform at least one of operations 410 to 480.
[0072] In operation 410, the application processor (221) according to one embodiment may load (or load or store) communication software stored in a first memory (e.g., the first memory (234) of FIG. 2) into a first storage area (e.g., the first storage area (21) of FIG. 2) of a second memory (e.g., the second memory (232) of FIG. 2). The application processor (221) according to one embodiment may read the communication software (e.g., the communication software (20) of FIG. 2) stored in the first memory (234) based on booting of the electronic device (201), access the first storage area (21) of the second memory (232) through an access controller (e.g., a control accessor (235) of FIG. 2), and load the read communication software (20) into the first storage area (21). According to one embodiment, the application processor (221) may store a command (or data) in the first storage area (21) that causes the security processor (223) to start an integrity verification process after loading communication software (20) in the first storage area (21).
[0073] In operation 420, the security processor (223) according to one embodiment can receive communication software through the first storage area (21) of the second memory (232).
[0074] In operation 430, a security processor (223) according to an embodiment may obtain first information for integrity verification of communication software and store it in a secure memory (e.g., the secure memory (236) of FIG. 2). The first information for integrity verification of communication software according to an embodiment may include a first hash value that is pre-specified or calculated in response to the communication software.
[0075] In operation 440, the security processor (223) according to one embodiment may store first communication software (e.g., a first copy of the received communication software) corresponding to the communication software in a second storage area (e.g., the second storage area (23) of FIG. 2) of the second memory (232). The security processor (223) according to one embodiment may further store second communication software (e.g., a second copy of the received communication software) corresponding to the communication software in a third storage area (e.g., the third storage area (25) of FIG. 2) of the second memory (232). The security processor (223) according to one embodiment may transmit a command to the first storage area (21) of the second memory (232) to cause the communication processor (290) to execute the first communication software stored in the second storage area (23).
[0076] In operation 450, a communication processor (290) according to one embodiment may perform a communication process by executing first communication software based on a command obtained through the first storage area (21).
[0077] In operation 460, the security processor (223) according to an embodiment may obtain second information for integrity verification of the first communication software based on a specified condition. The specified condition according to an embodiment may include a specified time period or the occurrence of a specified event. The second information according to an embodiment may include a second hash value calculated in response to the first communication software at a point in time according to the specified time period or the occurrence of the event. The security processor (223) according to an embodiment may identify the success or failure of the integrity verification of the first communication software by comparing the first information and the second information. The security processor (223) according to an embodiment may identify the success of the integrity verification of the first communication software based on a match between the first information and the second information. The security processor (223) according to an embodiment may identify the failure of the integrity verification of the first communication software based on a mismatch between the first information and the second information.
[0078] In operation 470, the security processor (223) according to one embodiment may stop the operation of the communication process using the first communication software based on the failure of the integrity verification using the first information and the second information, and load the second communication software corresponding to the communication software (e.g., the second communication software stored in the third storage area (25) or the communication software re-received from the first memory (234)) into the second storage area (23).
[0079] In operation 480, the security processor (223) according to an embodiment may instruct the second communication processor to perform a communication process. The security processor (223) according to an embodiment may transmit a command to re-perform the communication process using the second communication software reloaded in the second storage area (23) to the first storage area (21) of the second memory (232). The communication processor (290) according to an embodiment may re-perform the communication process by executing the second communication software based on the command obtained through the first storage area (21).
[0080] In an embodiment, a method for ensuring the integrity of communication software in an electronic device (e.g., 101 of FIG. 1 or 201 of FIG. 2) may include an operation of acquiring first information for integrity verification of communication software received from an application processor (e.g., processor 120 of FIG. 1 or application processor 221 of FIG. 2) through a first storage area of a second memory (e.g., 132 of FIG. 1 or 232 of FIG. 2) and storing the first information in a secure memory (e.g., 236 of FIG. 2). The method according to an embodiment may include an operation of storing first communication software corresponding to the communication software in a second storage area of the second memory. The method according to an embodiment may include an operation of commanding execution of the first communication software by the communication processor (e.g., communication module 190 of FIG. 1 or communication processor 290 of FIG. 2). According to one embodiment, the method may include an operation of obtaining second information for integrity verification of the first communication software based on satisfaction of the specified condition. According to one embodiment, the method may include an operation of stopping execution of the first communication software based on identification of a failure in integrity verification of the first communication software based on a comparison of the first information and the second information. According to one embodiment, the method may include an operation of loading second communication software corresponding to the communication software into the second storage area and commanding execution of the second communication software by the communication processor.
[0081] In the method according to one embodiment, the first information may include a first hash value corresponding to the communication software, and the second information may include a second hash value corresponding to the first communication software.
[0082] According to one embodiment, the method may include an operation of storing the second communication software corresponding to the communication software in a third storage area of the second memory. According to one embodiment, the method may further include an operation of loading the second communication software stored in the third storage area into the second storage area when an integrity verification failure of the first communication software is identified.
[0083] According to one embodiment, the method may include an operation of controlling the application processor, the communication processor, and the security processor to access the first storage area. According to one embodiment, the method may include an operation of controlling the communication processor to access the second storage area. According to one embodiment, the method may include an operation of controlling the security processor to access the third storage area.
[0084] In the method according to one embodiment, the specified condition may include a specified time period or the occurrence of a specified event.
[0085] According to one embodiment, the method may include an operation of identifying a success in the integrity verification of the first communication software based on a match between the first information and the second information. According to one embodiment, the method may include an operation of identifying a failure in the integrity verification of the first communication software based on a mismatch between the first information and the second information.
[0086] The method according to one embodiment may include an operation of identifying whether the specified condition is satisfied when the integrity verification of the first communication software is successful.
[0087] In the method according to one embodiment, the secure memory may be set to be accessible only by the secure processor.
[0088] The method according to one embodiment may include an operation of storing the communication software stored in the first memory in the first storage area of the second memory based on booting of the electronic device.
[0089] FIG. 5 is a flowchart illustrating the operation of a security processor of an electronic device according to one embodiment.
[0090] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0091] Referring to FIG. 5, a security processor (e.g., a security processor (223) of FIG. 2) of an electronic device (201) (e.g., an electronic device (101) of FIG. 1) according to one embodiment may perform at least one of operations 510 to 550.
[0092] In operation 510, a security processor (223) according to one embodiment may receive communication software through a first storage area (e.g., the first area (21) of FIG. 2) of a second memory (e.g., the second memory (232) of FIG. 2).
[0093] In operation 520, a security processor (223) according to one embodiment may generate (or obtain) a first hash value that is pre-specified or calculated in response to the received communication software and store it in a secure memory (e.g., the secure memory (236) of FIG. 2).
[0094] In operation 530, the security processor (223) according to one embodiment may store first communication software (e.g., a first copy of the received communication software) corresponding to the communication software in a second storage area (e.g., the second storage area (23) of FIG. 2) of the second memory (232).
[0095] In operation 540, the security processor (223) according to one embodiment may obtain a second hash value corresponding to the first communication software at a point in time according to a specified time period or at the time of occurrence of the event based on a specified condition (e.g., at a specified time period or at the occurrence of a specified event).
[0096] In operation 550, the security processor (223) according to one embodiment may stop the operation of the communication process using the first communication software based on a mismatch between the first hash value and the second hash value and load the second communication software corresponding to the communication software (e.g., the communication software re-received from the first memory (234) of FIG. 2) into the second storage area (23). The communication processor (290) according to one embodiment may re-perform the communication process by executing the second communication software re-loaded into the second storage area (23).
[0097] FIG. 6 is a flowchart illustrating an operation of a security processor of an electronic device according to one embodiment of the present invention to double-load and process data in an area of a second memory.
[0098] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0099] Referring to FIG. 6, a security processor (e.g., a security processor (223) of FIG. 2) of an electronic device (201) (e.g., an electronic device (101) of FIG. 1) according to one embodiment may perform at least one of operations 610 to 650.
[0100] In operation 610, a security processor (223) according to one embodiment may receive communication software through a first storage area (e.g., the first storage area (21) of FIG. 2) of a second memory (e.g., the second memory (232) of FIG. 2).
[0101] In operation 620, a security processor (223) according to one embodiment may generate (or obtain) a first hash value that is pre-specified or calculated in response to the received communication software and store it in a secure memory (e.g., the secure memory (236) of FIG. 2).
[0102] In operation 630, the security processor (223) according to one embodiment may load first communication software (e.g., a first copy of the received communication software) corresponding to the communication software into a second storage area (e.g., the second storage area (23) of FIG. 2) of the second memory (232), and load second communication software (e.g., a second copy of the received communication software) corresponding to the communication software into a third storage area (e.g., the third storage area (25) of FIG. 2) of the second memory (232).
[0103] In operation 640, the security processor (223) according to one embodiment may obtain a second hash value corresponding to the first communication software at a point in time according to a specified time period or at the time of occurrence of the event based on a specified condition (e.g., at a specified time period or at the occurrence of a specified event).
[0104] In operation 650, the security processor (223) according to one embodiment may stop the operation of the communication process using the first communication software based on a mismatch between the first hash value and the second hash value and load the second communication software loaded in the third storage area (25) into the second storage area (23). The communication processor (290) according to one embodiment may re-perform the communication process by executing the second communication software re-loaded into the second storage area (23).
[0105] FIG. 7 is a flowchart illustrating an operation of a security processor of an electronic device performing integrity verification and recovery based on an integrity verification process start event according to one embodiment.
[0106] In the following examples, the operations may be performed sequentially, but are not necessarily sequential. For example, the order of the operations may be changed, and at least two operations may be performed in parallel.
[0107] Referring to FIG. 7, a security processor (223) of an electronic device (201) (e.g., the electronic device (101) of FIG. 1) according to one embodiment may perform at least one of operations 710 to 770.
[0108] In operation 710, a security processor according to an embodiment (e.g., a security processor (223) of FIG. 2) may obtain a first hash value stored in a secure memory (236) based on an integrity verification process start event. The security processor (223) according to an embodiment may activate (or execute) an integrity verification engine (e.g., an integrity verification engine (320) of FIG. 3) based on a command of an application processor (e.g., an application processor (221) of FIG. 2) or based on a user input when the electronic device (201) boots up.
[0109] In operation 720, a security processor (223) according to one embodiment may access a second storage area (e.g., the second storage area (23) of FIG. 2) of a second memory (e.g., the second memory (232) of FIG. 2) to obtain a second hash value for the first communication software stored in the second storage area (23).
[0110] In operation 730, the security processor (223) according to one embodiment can identify whether the first hash value and the second hash value match.
[0111] In operation 740, the security processor (223) according to one embodiment may wait for a time based on a specified period based on a match between the first hash value and the second hash value, and perform operation 720.
[0112] In operation 750, the security processor (223) according to one embodiment may stop the operation of a communication process using the first communication software of the communication processor (e.g., the communication processor (290) of FIG. 2) based on a mismatch between the first hash value and the second hash value.
[0113] In operation 760, the security processor (223) according to one embodiment may execute an integrity recovery engine (e.g., an integrity recovery engine (330) of FIG. 3) and load second communication software corresponding to the communication software into the second storage area (23).
[0114] In operation 770, the security processor (223) according to one embodiment may command the communication processor (290) to restart the communication process. The security processor (223) according to one embodiment may transmit a command to re-perform the communication process using the second communication software loaded in the second storage area (23) to the first storage area of the second memory (232) (e.g., the first storage area (21) of FIG. 2). The communication processor (290) according to one embodiment may re-perform the communication process by executing the second communication software based on the command obtained through the first storage area (21).
[0115] Electronic devices according to various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to embodiments of the present disclosure are not limited to the aforementioned devices.
[0116] The various embodiments of the present disclosure and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases "A or B," "at least one of A and B," "at least one of A or B," "A, B, or C," "at least one of A, B, and C," and "at least one of A, B, or C" can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as "first," "second," or "first" or "second" may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as "coupled" or "connected" to another (e.g., a second component), with or without the terms "functionally" or "communicatively," it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.
[0117] The term "module" as used herein may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).
[0118] Various embodiments of the present disclosure may be implemented as software (e.g., a program (140)) including one or more commands stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one command among the one or more commands stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one command called. The one or more commands may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.
[0119] According to one embodiment, the method according to the various embodiments disclosed in the present document may be provided as included in a computer program product. The computer program product may be traded as a product between a seller and a buyer. The computer program product may be distributed in the form of a machine-readable storage medium (e.g., compact disc read only memory (CD-ROM)), or may be distributed online (e.g., downloaded or uploaded) via an application store (e.g., Play Store™) or directly between two user devices (e.g., smartphones). In the case of online distribution, at least a portion of the computer program product may be temporarily stored or temporarily generated in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.
[0120] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.
[0121] According to one embodiment, a non-transitory storage medium storing commands may be configured to cause the electronic device to perform at least one operation when the commands are executed by the electronic device, wherein the at least one operation may include: an operation of obtaining first information for integrity verification of communication software received from an application processor through a first storage area of a second memory and storing the information in a secure memory; an operation of storing first communication software corresponding to the communication software in a second storage area of the second memory; an operation of commanding execution of the first communication software by the communication processor; an operation of obtaining second information for integrity verification of the first communication software based on satisfaction of the specified condition; an operation of stopping execution of the first communication software based on identification of integrity verification failure of the first communication software based on comparison of the first information and the second information; and an operation of loading second communication software corresponding to the communication software into the second storage area and commanding execution of the second communication software by the communication processor.
[0122] And the embodiments of the present disclosure described in this specification and drawings are merely specific examples presented to easily explain the technical contents according to the embodiments of the present disclosure and to help understand the embodiments of the present disclosure, and are not intended to limit the scope of the embodiments of the present disclosure. Therefore, the scope of the various embodiments of the present disclosure should be interpreted as including all changes or modified forms derived based on the technical ideas of the various embodiments of the present disclosure in addition to the embodiments invented herein.
Claims
1. In an electronic device (101 of FIG. 1 or 201 of FIG. 2), First memory (134 in Fig. 1 or 234 in Fig. 2); Second memory (132 in Fig. 1 or 232 in Fig. 2); Secure memory for storing commands (236 in Fig. 2); Communication processor (communication module 190 of FIG. 1 or communication processor 290 of FIG. 2); an application processor (processor 120 of FIG. 1 or application processor 221 of FIG. 2); and Includes a security processor (security processor 223 of FIG. 2), The above commands, when executed by the security processor, cause the electronic device to: An electronic device which acquires first information for integrity verification of communication software received from the application processor through the first storage area of the second memory and stores it in the secure memory, stores first communication software corresponding to the communication software in the second storage area of the second memory, commands execution of the first communication software by the communication processor, acquires second information for integrity verification of the first communication software based on satisfaction of the designated condition, suspends execution of the first communication software based on identification of integrity verification failure of the first communication software based on comparison of the first information and the second information, loads second communication software corresponding to the communication software into the second storage area, and commands execution of the second communication software by the communication processor.
2. In paragraph 1, The above first information includes a first hash value corresponding to the communication software, An electronic device wherein the second information includes a second hash value corresponding to the first communication software.
3. In paragraph 1, The above commands, when executed by the security processor, cause the electronic device to: Further storing the second communication software corresponding to the communication software in the third storage area of the second memory, An electronic device that causes the second communication software stored in the third storage area to be loaded into the second storage area when the integrity verification failure of the first communication software is identified.
4. In paragraph 3, Further comprising the above access controller, An electronic device wherein the access controller is configured to control the application processor, the communication processor, and the security processor to access the first storage area, to control the communication processor to access the second storage area, and to control the security processor to access the third storage area.
5. In paragraph 1, The above specified conditions include an electronic device including a specified time period or the occurrence of a specified event.
6. In paragraph 1, The above commands, when executed by the security processor, cause the electronic device to: An electronic device that identifies success in the integrity verification of the first communication software based on a match between the first information and the second information, and identifies failure in the integrity verification of the first communication software based on a mismatch between the first information and the second information.
7. In paragraph 1, The above commands, when executed by the security processor, cause the electronic device to: An electronic device that identifies whether the above-mentioned specified condition is satisfied when the integrity verification of the above-mentioned first communication software is successful.
8. In paragraph 1, The above security processor, An electronic device comprising a software deployment engine, an integrity verification engine, and an integrity recovery engine.
9. In paragraph 1, The above security memory is, An electronic device that is configured to be accessible only by the above security processor.
10. In paragraph 1, The above application processor, An electronic device configured to transmit the communication software stored in the first memory to the security processor through the first storage area of the second memory based on booting of the electronic device.
11. A method for ensuring the integrity of communication software in an electronic device (101 of FIG. 1 or 201 of FIG. 2), An operation of acquiring first information for integrity verification of communication software received from an application processor (processor 120 of FIG. 1 or application processor 221 of FIG. 2) through a first storage area of a second memory (132 of FIG. 1 or 232 of FIG. 2) and storing the first information in a secure memory (236 of FIG. 2); An operation of storing first communication software corresponding to the communication software in a second storage area of the second memory; An operation of commanding execution of the first communication software of the communication processor (communication module 190 of FIG. 1 or communication processor 290 of FIG. 2); An operation of obtaining second information for integrity verification of the first communication software based on satisfaction of the above-mentioned specified condition; An action of stopping execution of the first communication software based on identification of a failure in integrity verification of the first communication software based on a comparison of the first information and the second information; A method including loading second communication software corresponding to the communication software into the second storage area and commanding execution of the second communication software by the communication processor.
12. In paragraph 11, The above first information includes a first hash value corresponding to the communication software, A method wherein the second information includes a second hash value corresponding to the first communication software.
13. In paragraph 11, An operation of storing the second communication software corresponding to the communication software in the third storage area of the second memory; and A method further comprising the action of loading the second communication software stored in the third storage area into the second storage area when the integrity verification failure of the first communication software is identified.
14. In paragraph 13, An operation for controlling the application processor, the communication processor, and the security processor to access the first storage area; An operation for controlling the communication processor to access the second storage area; and A method comprising: controlling the security processor to access the third storage area.
15. In a non-transitory storage medium storing commands, The above commands, when executed by an electronic device (101 of FIG. 1 or 201 of FIG. 2), are set to cause the electronic device to perform at least one operation, wherein the at least one operation is: An operation of acquiring first information for integrity verification of communication software received from an application processor (processor 120 of FIG. 1 or application processor 221 of FIG. 2) through a first storage area of a second memory (132 of FIG. 1 or 232 of FIG. 2) and storing the first information in a secure memory (236 of FIG. 2); An operation of storing first communication software corresponding to the communication software in a second storage area of the second memory; An operation of commanding execution of the first communication software of the communication processor (communication module 190 of FIG. 1 or communication processor 290 of FIG. 2); An operation of obtaining second information for integrity verification of the first communication software based on satisfaction of the above-mentioned specified condition; An operation of stopping execution of the first communication software based on identification of a failure in integrity verification of the first communication software based on a comparison of the first information and the second information; and A storage medium including an operation of loading second communication software corresponding to the communication software into the second storage area and commanding execution of the second communication software by the communication processor.
Citation Information
Patent Citations
Information processing apparatus and control method thereof, and program
JP2020086469A
Information processing device with startup verification function
JP4769608B2
Memory System
KR101821633B1
Program integrity monitoring and contingency management system and method
US20180336350A1
KR20220094847A