Electronic device and secure resource restriction method using same

By using a real-time clock to manage security resource availability and usage counts, the electronic device ensures secure and controlled use even in network disruptions, preventing indefinite or unauthorized use of security resources.

WO2025143752A1PCT designated stage expired Publication Date: 2025-07-03SAMSUNG ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/KR2024/021032
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-02-29
Filing Date
2024-12-24
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Electronic devices face challenges in managing security resources when network connections are disrupted, leading to potential indefinite use or misuse due to the inability to determine if security resources have expired.

Method used

The electronic device checks the availability time and usage count of security resources using a real-time clock (RTC) when disconnected from the network, restricting their use if they are below specified thresholds, and updates this information upon reconnection.

Benefits of technology

This method ensures secure and controlled use of security resources by preventing indefinite use and misuse, even when network connectivity is lost, by relying on unmodifiable RTC time and periodic updates.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure KR2024021032_03072025_PF_FP_ABST
    Figure KR2024021032_03072025_PF_FP_ABST
Patent Text Reader

Abstract

An electronic device, according to one embodiment of the present disclosure, may comprise: a communication circuit; a memory for storing instructions; and a processor. According to one embodiment, the instructions, when executed by the processor, may instruct the electronic device to receive a secure resource associated with a function of the electronic device from a server via the communication circuit. According to one embodiment, the instructions, when executed by the processor, may instruct the electronic device to check the availability time and the available number of times of use of the secure resource, if a network connection is confirmed to have been released under a specified condition. According to one embodiment, the instructions, when executed by the processor, may instruct the electronic device to check whether the availability time of the secure resource is less than a specified time, on the basis of time information acquired through a real time clock (RTC). According to one embodiment, the instructions, when executed by the processor, may instruct the electronic device to check whether the available number of times of use of the secure resource is less than a specified number of times. According to one embodiment, the instructions, when executed by the processor, may instruct the electronic device to restrict the use of the secure resource if the availability time of the secure resource is confirmed to be less than the specified time, or the available number of times of use of the secure resource is confirmed to be less than the specified number of times. Other various embodiments in addition to various embodiments disclosed in the present document are possible.
Need to check novelty before this filing date? Find Prior Art

Description

Electronic devices and methods for limiting security resources using the same

[0001] Embodiments of the present disclosure relate to an electronic device and a method for limiting secure resources using the same.

[0002] An electronic device can receive security resources related to its functions from a server over a network. The security resources may include security certificates and function control policy data. When the security resources expire, the electronic device can reclaim the security resources and restrict the execution of the functions. For example, the electronic device can obtain current time information from the server, and if the security resource expiration date is determined to be less than the obtained current time information, the electronic device can reclaim the security resources and restrict the execution of the functions.

[0003] The above information may be provided as background art to aid in understanding the present disclosure. No claim or determination is made as to whether any of the above is applicable as prior art related to the present disclosure.

[0004] However, if the network connection is lost, the electronic device may not be able to obtain current time information from the server. In this case, the electronic device may not be able to determine whether the security resource has expired. Consequently, the security resource may not only be used without limitation, but may also be exploited.

[0005] According to various embodiments of the present disclosure, an electronic device may, after receiving a security resource from a server and then disconnecting from a network, check the available time of the security resource and the number of times the security resource can be used based on current time information acquired through a real time clock (RTC). The electronic device may restrict the use of the security resource if the available time of the security resource is less than a specified time or if the number of times the security resource can be used is less than a specified number.

[0006] According to one embodiment of the present disclosure, an electronic device may include a communication circuit, a memory storing instructions, and a processor. According to one embodiment, the instructions, when executed by the processor, may cause the electronic device to receive a security resource related to a function of the electronic device from a server through the communication circuit. According to one embodiment, the instructions, when executed by the processor, may cause the electronic device to check the available time and the number of times the security resource can be used when it is determined that a network connection has been released under a specified condition. According to one embodiment, the instructions, when executed by the processor, may cause the electronic device to check whether the available time of the security resource is less than a specified time based on time information acquired through a real time clock (RTC). According to one embodiment, the instructions, when executed by the processor, may cause the electronic device to check whether the number of times the security resource can be used is less than a specified number. According to one embodiment, the instructions, when executed by the processor, may cause the electronic device to limit the use of the security resource if the available time of the security resource is determined to be less than the specified time, or if the available number of times the security resource is determined to be less than the specified number of times.

[0007] According to one embodiment of the present disclosure, a method for limiting a security resource may include receiving a security resource related to a function of an electronic device from a server through a communication circuit. According to one embodiment, the method for limiting a security resource may include checking the available time and the number of times the security resource can be used when it is determined that a network connection has been released under a specified condition. According to one embodiment, the method for limiting a security resource may include checking whether the available time of the security resource is less than a specified time based on time information acquired through a real time clock (RTC). According to one embodiment, the method for limiting a security resource may include checking whether the number of times the security resource can be used is less than a specified number. According to one embodiment, the method for limiting a security resource may include limiting the use of the security resource when it is determined that the available time of the security resource is less than the specified time or the number of times the security resource can be used is less than the specified number.

[0008] According to one embodiment of the present disclosure, a non-transitory computer-readable storage medium (or, a computer program product) storing one or more programs may be described. The one or more programs according to one embodiment may, when executed by a processor of an electronic device, include instructions for receiving a security resource related to a function of the electronic device from a server via a communication circuit. The one or more programs according to one embodiment may, when executed by the processor of the electronic device, include instructions for checking the available time and the number of times the security resource can be used if it is determined that a network connection has been released under a specified condition. The one or more programs according to one embodiment may, when executed by the processor of the electronic device, include instructions for checking whether the available time of the security resource is less than a specified time based on time information acquired through a real time clock (RTC). The one or more programs according to one embodiment may, when executed by the processor of the electronic device, include instructions for checking whether the number of times the security resource can be used is less than a specified number. One or more programs according to one embodiment may include a command that, when executed by a processor of an electronic device, limits the use of the security resource if the available time of the security resource is determined to be less than the specified time, or if the number of times the security resource is available is determined to be less than the specified number of times.

[0009] An electronic device according to one embodiment of the present disclosure can check the availability time of a security resource using current time information obtained through an RTC that cannot be arbitrarily modified by a user when a network connection is disconnected, and can limit the use of the security resource by considering the number of times the security resource can be used in parallel, thereby preventing the security resource from being used without limitation and from being misused.

[0010] FIG. 1 is a block diagram of an electronic device within a network environment according to one embodiment of the present disclosure.

[0011] FIG. 2 is a block diagram illustrating an electronic device according to one embodiment of the present disclosure.

[0012] FIG. 3 is a diagram illustrating signal flow between a server, a general area operated in an electronic device, and a secure area according to one embodiment of the present disclosure.

[0013] FIG. 4 is a flowchart illustrating a method of issuing a security resource of a server according to one embodiment of the present disclosure.

[0014] FIG. 5 is a flowchart illustrating a method for receiving (or acquiring) a security resource of an electronic device according to one embodiment of the present disclosure.

[0015] FIG. 6 is a flowchart illustrating a method for limiting security resources according to one embodiment of the present disclosure.

[0016] FIG. 7 is a flowchart illustrating a method for limiting security resources when a network connection is released under specified conditions, according to one embodiment of the present disclosure.

[0017] FIG. 8 is a flowchart illustrating a method for limiting security resources when network connection is established under specified conditions, according to one embodiment of the present disclosure.

[0018] FIG. 9 is a flowchart illustrating a method for limiting security resources when network connection is established under specified conditions, according to one embodiment of the present disclosure.

[0019] FIG. 10 is a flowchart illustrating a method for limiting security resources when a network is reconnected from a disconnected state, according to one embodiment of the present disclosure.

[0020] FIG. 11 is a flowchart illustrating a method for updating time information when an event related to a time change is detected, according to one embodiment of the present disclosure.

[0021] Hereinafter, embodiments of the present disclosure will be described in detail with reference to the drawings so that those skilled in the art can easily implement the present disclosure. However, the present disclosure may be implemented in various different forms and is not limited to the embodiments described herein. In connection with the description of the drawings, the same or similar reference numerals may be used for identical or similar components. Furthermore, in the drawings and related descriptions, descriptions of well-known functions and configurations may be omitted for clarity and conciseness.

[0022] FIG. 1 is a block diagram of an electronic device (101) within a network environment (100) according to one embodiment of the present disclosure.

[0023] Referring to FIG. 1, in a network environment (100), an electronic device (101) may communicate with an electronic device (102) via a first network (198) (e.g., a short-range wireless communication network), or may communicate with at least one of an electronic device (104) or a server (108) via a second network (199) (e.g., a long-range wireless communication network). According to one embodiment, the electronic device (101) may communicate with the electronic device (104) via the server (108). According to one embodiment, the electronic device (101) may include a processor (120), a memory (130), an input module (150), an audio output module (155), a display module (160), an audio module (170), a sensor module (176), an interface (177), a connection terminal (178), a haptic module (179), a camera module (180), a power management module (188), a battery (189), a communication module (190), a subscriber identification module (196), or an antenna module (197). In some embodiments, the electronic device (101) may omit at least one of these components (e.g., the connection terminal (178)), or may have one or more other components added. In some embodiments, some of these components (e.g., the sensor module (176), the camera module (180), or the antenna module (197)) may be integrated into one component (e.g., the display module (160)).

[0024] The processor (120) may, for example, execute software (e.g., a program (140)) to control at least one other component (e.g., a hardware or software component) of the electronic device (101) connected to the processor (120) and perform various data processing or calculations. According to one embodiment, as at least a part of the data processing or calculations, the processor (120) may store commands or data received from other components (e.g., a sensor module (176) or a communication module (190)) in a volatile memory (132), process the commands or data stored in the volatile memory (132), and store result data in a non-volatile memory (134). According to one embodiment, the processor (120) may include a main processor (121) (e.g., a central processing unit or an application processor) or a secondary processor (123) (e.g., a graphics processing unit, a neural processing unit (NPU), an image signal processor, a sensor hub processor, or a communication processor)) that can operate independently or together therewith. For example, if the electronic device (101) includes a main processor (121) and a secondary processor (123), the secondary processor (123) may be configured to use less power than the main processor (121) or to be specialized for a specified function. The secondary processor (123) may be implemented separately from the main processor (121) or as a part thereof.

[0025] The auxiliary processor (123) may control at least a portion of functions or states associated with at least one component (e.g., a display module (160), a sensor module (176), or a communication module (190)) of the electronic device (101), for example, on behalf of the main processor (121) while the main processor (121) is in an inactive (e.g., sleep) state, or together with the main processor (121) while the main processor (121) is in an active (e.g., application execution) state. In one embodiment, the auxiliary processor (123) (e.g., an image signal processor or a communication processor) may be implemented as a part of another functionally related component (e.g., a camera module (180) or a communication module (190)). In one embodiment, the auxiliary processor (123) (e.g., a neural network processing unit) may include a hardware structure specialized for processing artificial intelligence models. The artificial intelligence models may be generated through machine learning. This learning can be performed, for example, on the electronic device (101) itself where the artificial intelligence model is executed, or can be performed through a separate server (e.g., server (108)). The learning algorithm can include, for example, supervised learning, unsupervised learning, semi-supervised learning, or reinforcement learning, but is not limited to the examples described above. The artificial intelligence model can include multiple artificial neural network layers.The artificial neural network may be one of a deep neural network (DNN), a convolutional neural network (CNN), a recurrent neural network (RNN), a restricted Boltzmann machine (RBM), a deep belief network (DBN), a bidirectional recurrent deep neural network (BRDNN), a deep Q-network, or a combination of two or more of the above, but is not limited to the examples described above. In addition to, or alternatively to, a hardware structure, an artificial intelligence model may include a software structure.

[0026] The memory (130) can store various data used by at least one component (e.g., processor (120) or sensor module (176)) of the electronic device (101). The data can include, for example, software (e.g., program (140)) and input data or output data for commands related thereto. The memory (130) can include volatile memory (132) or non-volatile memory (134).

[0027] The program (140) may be stored as software in the memory (130) and may include, for example, an operating system (142), middleware (144), or an application (146).

[0028] The input module (150) can receive commands or data to be used in a component of the electronic device (101) (e.g., a processor (120)) from an external source (e.g., a user) of the electronic device (101). The input module (150) can include, for example, a microphone, a mouse, a keyboard, a key (e.g., a button), or a digital pen (e.g., a stylus pen).

[0029] The audio output module (155) can output audio signals to the outside of the electronic device (101). The audio output module (155) can include, for example, a speaker or a receiver. The speaker can be used for general purposes, such as multimedia playback or recording playback. The receiver can be used to receive incoming calls. In one embodiment, the receiver can be implemented separately from the speaker or as part of the speaker.

[0030] The display module (160) can visually provide information to an external party (e.g., a user) of the electronic device (101). The display module (160) may include, for example, a display, a holographic device, or a projector and a control circuit for controlling the device. In one embodiment, the display module (160) may include a touch sensor configured to detect a touch, or a pressure sensor configured to measure the intensity of a force generated by the touch.

[0031] The audio module (170) can convert sound into an electrical signal, or vice versa, convert an electrical signal into sound. According to one embodiment, the audio module (170) can acquire sound through the input module (150), output sound through the sound output module (155), or an external electronic device (e.g., electronic device (102)) (e.g., speaker or headphone) directly or wirelessly connected to the electronic device (101).

[0032] The sensor module (176) can detect the operating status (e.g., power or temperature) of the electronic device (101) or the external environmental status (e.g., user status) and generate an electrical signal or data value corresponding to the detected status. According to one embodiment, the sensor module (176) can include, for example, a gesture sensor, a gyro sensor, a barometric pressure sensor, a magnetic sensor, an acceleration sensor, a grip sensor, a proximity sensor, a color sensor, an IR (infrared) sensor, a biometric sensor, a temperature sensor, a humidity sensor, or an illuminance sensor.

[0033] The interface (177) may support one or more designated protocols that may be used to directly or wirelessly connect the electronic device (101) with an external electronic device (e.g., the electronic device (102)). In one embodiment, the interface (177) may include, for example, a high definition multimedia interface (HDMI), a universal serial bus (USB) interface, an SD card interface, or an audio interface.

[0034] The connection terminal (178) may include a connector through which the electronic device (101) may be physically connected to an external electronic device (e.g., electronic device (102)). According to one embodiment, the connection terminal (178) may include, for example, an HDMI connector, a USB connector, an SD card connector, or an audio connector (e.g., a headphone connector).

[0035] A haptic module (179) can convert electrical signals into mechanical stimuli (e.g., vibration or movement) or electrical stimuli that a user can perceive through tactile or kinesthetic sensations. In one embodiment, the haptic module (179) can include, for example, a motor, a piezoelectric element, or an electrical stimulation device.

[0036] The camera module (180) can capture still images and videos. According to one embodiment, the camera module (180) may include one or more lenses, image sensors, image signal processors, or flashes.

[0037] The power management module (188) can manage power supplied to the electronic device (101). According to one embodiment, the power management module (188) can be implemented, for example, as at least a part of a power management integrated circuit (PMIC).

[0038] A battery (189) may power at least one component of the electronic device (101). In one embodiment, the battery (189) may include, for example, a non-rechargeable primary battery, a rechargeable secondary battery, or a fuel cell.

[0039] The communication module (190) may support the establishment of a direct (e.g., wired) communication channel or a wireless communication channel between the electronic device (101) and an external electronic device (e.g., electronic device (102), electronic device (104), or server (108)), and the performance of communication through the established communication channel. The communication module (190) may operate independently from the processor (120) (e.g., application processor) and may include one or more communication processors that support direct (e.g., wired) communication or wireless communication. According to one embodiment, the communication module (190) may include a wireless communication module (192) (e.g., a cellular communication module, a short-range wireless communication module, or a global navigation satellite system (GNSS) communication module) or a wired communication module (194) (e.g., a local area network (LAN) communication module, or a power line communication module). Among these communication modules, the corresponding communication module can communicate with an external electronic device (104) via a first network (198) (e.g., a short-range communication network such as Bluetooth, wireless fidelity (WiFi) direct, or infrared data association (IrDA)) or a second network (199) (e.g., a long-range communication network such as a legacy cellular network, a 5G network, a next-generation communication network, the Internet, or a computer network (e.g., a LAN or WAN)). These various types of communication modules can be integrated into a single component (e.g., a single chip) or implemented as multiple separate components (e.g., multiple chips). The wireless communication module (192) can verify or authenticate the electronic device (101) within a communication network such as the first network (198) or the second network (199) by using subscriber information (e.g., an international mobile subscriber identity (IMSI)) stored in the subscriber identification module (196).

[0040] The wireless communication module (192) can support 5G networks and next-generation communication technologies following the 4G network, such as NR access technology (new radio access technology). The NR access technology can support high-speed transmission of high-capacity data (eMBB (enhanced mobile broadband)), minimization of terminal power and connection of multiple terminals (mMTC (massive machine type communications)), or high reliability and low latency (URLLC (ultra-reliable and low-latency communications)). The wireless communication module (192) can support, for example, a high-frequency band (e.g., mmWave band) to achieve a high data transmission rate. The wireless communication module (192) can support various technologies for securing performance in a high-frequency band, such as beamforming, massive multiple-input and multiple-output (MIMO), full dimensional MIMO (FD-MIMO), array antenna, analog beam-forming, or large scale antenna. The wireless communication module (192) can support various requirements specified in the electronic device (101), an external electronic device (e.g., the electronic device (104)), or a network system (e.g., the second network (199)). According to one embodiment, the wireless communication module (192) can support a peak data rate (e.g., 20 Gbps or more) for eMBB realization, a loss coverage (e.g., 164 dB or less) for mMTC realization, or a U-plane latency (e.g., 0.5 ms or less for downlink (DL) and uplink (UL), or 1 ms or less for round trip) for URLLC realization.

[0041] The antenna module (197) can transmit or receive signals or power to or from an external device (e.g., an external electronic device). In one embodiment, the antenna module (197) may include an antenna including a radiator formed of a conductor or a conductive pattern formed on a substrate (e.g., a printed circuit board (PCB)). In one embodiment, the antenna module (197) may include a plurality of antennas (e.g., an array antenna). In this case, at least one antenna suitable for a communication method used in a communication network, such as the first network (198) or the second network (199), may be selected from the plurality of antennas by, for example, the communication module (190). A signal or power may be transmitted or received between the communication module (190) and an external electronic device through the selected at least one antenna. In some embodiments, in addition to the radiator, another component (e.g., a radio frequency integrated circuit (RFIC)) may be additionally formed as a part of the antenna module (197).

[0042] According to various embodiments, the antenna module (197) may form a mmWave antenna module. According to one embodiment, the mmWave antenna module may include a printed circuit board, an RFIC disposed on or adjacent a first side (e.g., a bottom side) of the printed circuit board and capable of supporting a designated high-frequency band (e.g., a mmWave band), and a plurality of antennas (e.g., an array antenna) disposed on or adjacent a second side (e.g., a top side or a side side) of the printed circuit board and capable of transmitting or receiving signals in the designated high-frequency band.

[0043] At least some of the above components can be interconnected and exchange signals (e.g., commands or data) with each other via a communication method between peripheral devices (e.g., a bus, GPIO (general purpose input and output), SPI (serial peripheral interface), or MIPI (mobile industry processor interface)).

[0044] According to one embodiment, commands or data may be transmitted or received between the electronic device (101) and an external electronic device (104) via a server (108) connected to a second network (199). Each of the external electronic devices (102 or 104) may be the same or a different type of device as the electronic device (101). According to one embodiment, all or part of the operations executed in the electronic device (101) may be executed in one or more of the external electronic devices (102, 104, or 108). For example, when the electronic device (101) is to perform a certain function or service automatically or in response to a request from a user or another device, the electronic device (101) may, instead of or in addition to executing the function or service itself, request one or more external electronic devices to perform the function or at least a part of the service. One or more external electronic devices that receive the request may execute at least a portion of the requested function or service, or an additional function or service related to the request, and transmit the result of the execution to the electronic device (101). The electronic device (101) may process the result as is or additionally and provide it as at least a portion of a response to the request. For this purpose, cloud computing, distributed computing, mobile edge computing (MEC), or client-server computing technology may be used, for example. The electronic device (101) may provide an ultra-low latency service by using distributed computing or mobile edge computing, for example. In another embodiment, the external electronic device (104) may include an Internet of Things (IoT) device. The server (108) may be an intelligent server utilizing machine learning and / or a neural network. According to one embodiment, the external electronic device (104) or the server (108) may be included in the second network (199).The electronic device (101) can be applied to intelligent services (e.g., smart home, smart city, smart car, or healthcare) based on 5G communication technology and IoT-related technology.

[0045] FIG. 2 is a block diagram illustrating an electronic device (101) according to one embodiment of the present disclosure.

[0046] Referring to FIG. 2, an electronic device (101) (e.g., the electronic device (101) of FIG. 1) may include a communication circuit (210) (e.g., the communication module (190) of FIG. 1), a memory (220) (e.g., the memory (130) of FIG. 1), and / or a processor (230) (e.g., the processor (120) of FIG. 1).

[0047] According to one embodiment of the present disclosure, a communication circuit (210) (e.g., a communication module (190) of FIG. 1) can control a communication connection between an electronic device (101) and at least one external electronic device (e.g., an electronic device (102) of FIG. 1, an electronic device (104)) (and / or a server (e.g., a server (108) of FIG. 1, a server (310) of FIG. 3)) under the control of a processor (230).

[0048] In one embodiment, the communication circuit (210) may, under the control of the processor (230), receive (or acquire) security resources related to the functions of the electronic device (101) from the server (310). For example, the security resources may include security certificates and function control policy data. In one embodiment, the communication circuit (210) may, under the control of the processor (230), periodically acquire current time information from the server (310).

[0049] In one embodiment, the communication circuit (210) may transmit information related to usage restrictions of secure resources to the server (310) under the control of the processor (230).

[0050] According to one embodiment of the present disclosure, the memory (220) (e.g., the memory (130) of FIG. 1) performs a function of storing a program (e.g., the program (140) of FIG. 1), an operating system (OS) (e.g., the operating system (142) of FIG. 1), various applications, and / or input / output data for processing and controlling the processor (230) of the electronic device (101), and may store a program that controls the overall operation of the electronic device (101). The memory (220) may store various setting information required when processing functions related to various embodiments of the present disclosure in the electronic device (101). The memory (220) may store executable instructions. For example, the memory (220) may store instructions that, when executed by the processor (230), cause the electronic device (101) to perform operations. For example, the instructions may be stored on a computer-readable recording medium. The recording medium may be tangible and non-transitory. The memory (220) and / or the recording medium may store one or more programs including the instructions.

[0051] According to one embodiment of the present disclosure, the processor (230) may include, for example, a micro controller unit (MCU), and may control a plurality of hardware components connected to the processor (230) by running an operating system (OS) or an embedded software program. The processor (230) may control a plurality of hardware components according to, for example, instructions stored in a memory (220) (e.g., a program (140) of FIG. 1).

[0052] In one embodiment, the electronic device (101) may operate multiple execution environments having multiple security levels to enhance security. For example, the multiple execution environments may include a general area (e.g., general area (320) of FIG. 3) and a secure area (e.g., secure area (340) of FIG. 3). The general area (320) may be, for example, a first execution environment having a first security level. The secure area (340) may be, for example, a second execution environment having a second security level that is different from the first security level (e.g., higher than the first security level). The security area (340) operates on the processor (230) of the electronic device (101) (e.g., an application processor (AP) (e.g., the main processor (121) of FIG. 1)) and may operate based on a reliable hardware structure determined during the manufacturing process of the electronic device (101). However, the security area (340) is not limited thereto, and may be implemented and operated as separate hardware in addition to operating on the processor (230) (e.g., the application processor).

[0053] In one embodiment, the processor (230) may receive a security resource related to a function of the electronic device (101) from the server (310). The processor (230) may store the security resource received (or acquired) from the server (310) in the memory (220). If it is determined that the network connection has been released under a specified condition, the processor (230) may check the available time and number of times the security resource has been used. The specified condition may include one of a condition in which an event related to the execution of a function of the electronic device (101) occurs or a condition in which an event related to the rebooting of the electronic device (101) occurs. However, the present invention is not limited thereto, and the processor (230) may check whether the network connection has been released at a specified time interval (or a specified cycle).

[0054] In one embodiment, the processor (230) can check the available time of a security resource stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3). For example, the processor (230) can check the available time of a security resource calculated based on the issuance date and expiration date of the security resource (e.g., the available time of the security resource = expiration date - issuance date). The processor (230) can check the available number of times of a security resource stored in a count management module (e.g., the count management module (345) of FIG. 3). The processor (230) can check whether the available time of the security resource is less than a specified time based on time information acquired through an RTC (real time clock) (e.g., the time information providing module (360) of FIG. 3). For example, the time information acquired through the RTC may be unmodified time information. In addition, the processor (230) can check whether the available number of times of the security resource is less than a specified number. The processor (230) may limit the use of a security resource if the available time of the security resource is confirmed to be less than a specified time or if the number of times the security resource is available is confirmed to be less than a specified number of times. As the use of the security resource is limited, the functions of the electronic device (101) may not be performed (e.g., the functions of the electronic device (101) may be limited).

[0055] Restricting the use of a secure resource according to one embodiment may mean that the secure resource has expired. In one embodiment, restricting the use of the secure resource may include deleting the secure resource, restricting permissions to only the functions of the requested electronic device (101) among the permissions provided by the secure resource, and / or initializing metadata of the secure resource. When the network is connected via the communication circuit (210) while the use of the secure resource is restricted (e.g., expired) due to a network disconnection, the processor (230) may transmit information related to the restricted use of the secure resource to the server (310).

[0056] FIG. 3 is a diagram illustrating signal flow between a server (310), a general area (320) operated in an electronic device (101), and a secure area (340) according to one embodiment of the present disclosure.

[0057] Referring to FIG. 3, an electronic device (e.g., the electronic device (101) of FIG. 1) may operate multiple execution environments with multiple security levels to enhance security. For example, the multiple execution environments may include a general area (320) and a secure area (340). The general area (320) may be, for example, a first execution environment with a first security level. The secure area (340) may be, for example, a second execution environment with a second security level that is different from the first security level (e.g., higher than the first security level). For example, the secure area (340) may store data requiring a relatively high security level in a secure environment and perform related operations. The secure area (340) may operate on an application processor (AP) of the electronic device (101) (e.g., the main processor (121) of FIG. 1) and may operate based on a reliable hardware structure determined during the manufacturing process of the electronic device (101). In one embodiment, the security area (340) may refer to an area where software or hardware requiring security operates. This is not a limitation, and in one embodiment, the security area (340) may be implemented and operated as separate hardware in addition to operating on the application processor.

[0058] In one embodiment, the general area (320) and the secure area (340) may be operated physically or logically separated. For example, the physically separated secure area may include an embedded secure element (eSE) or a secure processor. The logically separated secure area may include a TrustZone or a hypervisor.

[0059] In one embodiment, the general area (320) may be defined as a rich execution environment (REE), and the secure area (340) may be defined as a trusted execution environment (TEE).

[0060] In one embodiment, the server (310) may be a server that issues (or transmits, distributes, or provides) a security resource. The server (310) may issue a security resource including meta information to the electronic device (101). For example, the meta information may include the validity period and / or the number of times the security resource can be used. The validity period of the security resource may be set based on the issuance date (and / or issuance time) and the expiration date (and / or expiration time). The expiration date of the security resource may be set to a specified expiration date at the discretion of a security manager or server manager. However, the expiration date of the security resource may be set to an expiration date set by the manufacturer, or may be set by the user's selection within a limited period. The number of times the security resource can be used may be set by the security manager.

[0061] In one embodiment, the server (310) can map and manage security resources supported by each function of the electronic device (101). As another example, the server (310) can map and manage a plurality of resources supporting a specific function of the electronic device (101). In this case, when the server (310) receives a signal requesting a security resource related to the function of the electronic device (101) from the electronic device (101), the server (310) can issue at least one resource mapped to the function of the electronic device (101) to the electronic device (101).

[0062] In one embodiment, the server (310) may periodically provide time information to the electronic device (101) upon request of the electronic device (101).

[0063] In one embodiment, the general area (320) may include a security resource management module (325) and / or an event processing module (330).

[0064] In one embodiment, the security resource management module (325) can communicate with the server (310). For example, the security resource management module (325) can request a security resource from the server (310) via network communication. In response to requesting the security resource from the server (310), the security resource management module (325) can receive the security resource from the server (310). The security resource management module (325) can store the security resource received from the server (310) in a memory (e.g., the memory (220) of FIG. 2) and control the function of the electronic device (101).

[0065] In one embodiment, when a situation that restricts the use of a security resource (e.g., a situation in which a security resource has expired) is detected, the security resource management module (325) may transmit information related to the restriction on the use of the security resource to the server (310) while connected to a network.

[0066] In one embodiment, the event processing module (330) may detect an event related to the execution of a function of the electronic device (101), an event related to a change in date and / or time, an event related to a timer operation, and / or an event related to the rebooting of the electronic device (101). When the above-described event is detected, the event processing module (330) may request the time information management module (350) to update time information. However, the event processing module (330) may also detect an event related to a network connection of the electronic device (101) (e.g., a network connection or a network disconnection).

[0067] In one embodiment, the security area (340) may include a count management module (345), a time information management module (350), a secure storage management module (355), and / or a time information provision module (360).

[0068] In one embodiment, the count management module (345) can manage the number of times a security resource can be used. For example, the count management module (345) can store and manage the number of times a security resource can be used during the process of acquiring and using the security resource. The count management module (345) can store the number of times a security resource can be used, included in the security resource meta information, in the security storage management module (355) during the process of acquiring the security resource. When using the security resource, the count management module (345) can deduct the number of times a security resource can be used, and store the deducted number of times a security resource can be used in the security storage management module (355).

[0069] In one embodiment, when an event (e.g., an event related to the execution of a function of the electronic device (101), an event related to a change in date and / or time, an event related to a timer operation, and / or an event related to the reboot of the electronic device (101)) is detected by the event processing module (330), the time information management module (350) may obtain current time information through the time information provision module (360) and update previously stored time information.

[0070] In one embodiment, the secure storage management module (355) may store and / or manage data stored in the number of times management module (345) and / or the time information management module (350). For example, the secure storage management module (355) may store and / or manage the number of times a secure resource is available, the time of availability of the secure resource (e.g., the issuance date (and / or issuance time) and the expiration date (and / or expiration time)), and / or time information (e.g., current time information obtained from the server (310), current time information obtained through the time information provision module (360)).

[0071] In one embodiment, the time information provision module (360) may provide unmodified time information. For example, the time information provision module (360) may include a real time clock (RTC). The RTC is a hardware clock of the electronic device (101), and time information (e.g., current time information) obtained through the RTC may not be arbitrarily modified by the user. Accordingly, the time information obtained through the RTC may be highly reliable. In one embodiment, the RTC may update time information (e.g., current time information) at a specified time interval (or periodically) even when the electronic device (101) is powered off, if there is a remaining battery (e.g., battery (189) of FIG. 1). In one embodiment, the time information (e.g., current time information) may be stored in the secure storage management module (355).

[0072] An electronic device (101) according to one embodiment of the present disclosure may include a communication circuit (210), a memory (220) storing instructions, and a processor (230). The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to receive a security resource related to a function of the electronic device (101) from a server (310) through the communication circuit (210). The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to check the available time and the number of times the security resource can be used when it is determined that a network connection has been released under a specified condition. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to check whether the available time of the security resource is less than a specified time based on time information acquired through an RTC (real time clock). The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to determine whether the number of times a security resource can be used is less than a specified number of times. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to limit the use of a security resource if the available time of the security resource is determined to be less than a specified time or the number of times a security resource can be used is determined to be less than a specified number of times.

[0073] The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to update the available time of a security resource based on time information acquired through the RTC. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to check whether the available time of the updated security resource is less than a specified time.

[0074] Instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to store time information acquired through the RTC in the memory (220) and allow a function of the electronic device (101) if it is determined that the availability time of the security resource is not less than a specified time. Instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to acquire second time information through the RTC if it is determined that a second specified time has elapsed after allowing the function of the electronic device (101).

[0075] The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to determine whether a network is connected if a second specified time has elapsed after enabling a function of the electronic device (101). The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to initialize the number of available uses of a security resource and obtain time information from the server (310) if a network is connected.

[0076] Instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to execute a function of the electronic device (101) after deducting the number of available times if it is determined that the number of available times of the security resource is not less than a specified number.

[0077] Instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to transmit information related to the restriction of use of the security resource to the server (310) via the communication circuit (210) when a network connection is detected after restricting the use of the security resource.

[0078] The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to obtain second time information from a server if the network connection is not disconnected. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to restrict the use of a security resource if it is determined that the expiration time of the security resource is less than the second time information. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to allow a function of the electronic device (101) if it is determined that the expiration time of the security resource is not less than the second time information.

[0079] The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to obtain third time information from the RTC if it is determined that the expiration time of the security resource is not less than the second time information. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to update the available time of the security resource based on the third time information acquired through the RTC. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to store the third time information if the available time of the updated security resource is not less than a specified time. The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to restrict the use of the security resource if the available time of the updated security resource is less than a specified time.

[0080] A specified condition according to one embodiment may include one of a condition in which an event related to the execution of a function of the electronic device (101) occurs, a condition in which an event related to the reboot of the electronic device (101) occurs, or a condition in which a certain period occurs.

[0081] The instructions according to one embodiment, when executed by the processor (230), may cause the electronic device (101) to limit the use of the security resource based on at least one of deleting the security resource, limiting permissions for functions of the electronic device (101) among permissions provided by the security resource, or initializing meta information of the security resource.

[0082] FIG. 4 is a flowchart illustrating a method of issuing a security resource of a server (310) according to one embodiment of the present disclosure.

[0083] In the following embodiments, the operations of FIG. 4 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 4 may be changed, and at least two operations may be performed in parallel.

[0084] According to one embodiment, operations 405 to 420 of FIG. 4 may be understood to be performed in a server (e.g., server (310) of FIG. 3).

[0085] Referring to FIG. 4, when the server (310) receives a signal requesting a security resource from an electronic device (e.g., the electronic device (101) of FIG. 1) in operation 405, the server (310) may load information related to the requested security resource in operation 410. For example, the information related to the security resource may include a policy and / or resource content, but is not limited thereto.

[0086] In one embodiment, the server (310) may set meta information including the validity period and / or available number of times of the security resource to verify the validity of the security resource in operation 415.

[0087] In one embodiment, the validity period of a security resource can be set based on the issuance date and expiration date. The expiration date of a security resource can be set to the expiration date set by the manufacturer. However, this is not limited to the expiration date, and the expiration date of a security resource can also be set to the expiration date specified by the security administrator or server administrator. Alternatively, the expiration date of a security resource can be set by the user (e.g., by the user selecting a period within a limited period).

[0088] In one embodiment, the number of available times for a security resource may be set to a number of available times specified by a security manager.

[0089] In one embodiment, the server (310) may, in operation 420, sign a security resource including meta information and issue (or transmit, distribute) the security resource to the electronic device (101) that requested the security resource. For example, the server (310) may sign with the private key of the server (310) and issue (or transmit) the security resource to the electronic device (101) that requested the security resource. In one embodiment, a public key corresponding to the private key of the server (310) may be pre-stored in the electronic device (101). For example, the public key may be mapped in advance through secure communication between the server (310) and the electronic device (101) and distributed to the electronic device (101). In one embodiment, the security resource issued to the electronic device (101) may include meta information.

[0090] In one embodiment, the server (310) can map and manage security resources supported by each function of the electronic device (101). As another example, the server (310) can map and manage a plurality of resources supporting a specific function of the electronic device (101). In this case, when the server (310) receives a signal requesting a security resource related to the function of the electronic device (101) from the electronic device (101), the server (310) can issue (or transmit, distribute, provide) at least one resource mapped to the function of the electronic device (101) to the electronic device (101).

[0091] FIG. 5 is a flowchart illustrating a method of receiving (or acquiring) a security resource of an electronic device (101) according to one embodiment of the present disclosure.

[0092] In the following embodiments, the operations of FIG. 5 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 5 may be changed, and at least two operations may be performed in parallel.

[0093] According to one embodiment, operations 505 to 520 of FIG. 5 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0094] Referring to FIG. 5, the processor (230) may detect a signal requesting a security resource related to a function of the electronic device (101) in operation 505. For example, a user of the electronic device (101) may request a security resource after setting the type and / or expiration date of the security resource to be requested. The processor (230) may transmit a signal requesting the security resource to a server (e.g., the server (310) of FIG. 3) based on the detection of a signal requesting the security resource. The present invention is not limited thereto, and when an input for executing a function of the electronic device (101) is detected and a security resource related to the function of the electronic device (101) is not stored in a memory (e.g., the memory (220) of FIG. 2), the processor (230) may also transmit a signal requesting a security resource related to the function of the electronic device (101) to the server (310).

[0095] In one embodiment, the processor (230) may, in operation 510, verify the validity of a security resource issued from the server (310) and then allow the reception (or acquisition) of the security resource. For example, the processor (230) may verify the validity of the security resource by verifying the signature of the security resource during the process of receiving (or acquiring) the security resource issued from the server (310). In one embodiment, the public key of the server (310) used for verifying the signature of the security resource (e.g., a public key corresponding to the private key of the server (310)) may be pre-stored in the electronic device (101).

[0096] In one embodiment, the processor (230) may receive the security resource by allowing the receipt (or acquisition) of the security resource when the validation of the security resource issued from the server (310) is successful through signature verification.

[0097] In one embodiment, if the validity of a security resource issued from the server (310) fails through signature verification, the processor (230) may not allow the receipt (or acquisition) of the security resource. In this case, the execution of functions of the electronic device (101) may be restricted due to the refusal to allow the receipt (or acquisition) of the security resource.

[0098] In one embodiment, the processor (230) may store the number of available uses of a security resource in operation 515. For example, the processor (230) may store the number of available uses of a security resource included in the meta information of the security resource in a security storage management module (e.g., the security storage management module (355) of FIG. 3).

[0099] In one embodiment, the processor (230) may calculate and store the available time of the security resource in operation 520. The processor (230) may check the validity period included in the meta information of the security resource. For example, the processor (230) may calculate the available time based on the issuance date and expiration date of the security resource described as the validity period of the security resource (e.g., the available time of the security resource = expiration date - issuance date), and store the calculated available time of the security resource in the security storage management module (355).

[0100] As discussed in FIGS. 4 and 5 according to various embodiments, the processor (230) can check the available time and number of times a security resource can be used based on the meta information of the security resource received from the server (310). In FIGS. 6 to 11 described below, various embodiments for limiting the use of a security resource, regardless of whether or not a network connection is present, will be described based on the available time (or expiration time) of the security resource and / or the number of times the security resource can be used.

[0101] FIG. 6 is a flowchart illustrating a method for limiting security resources according to one embodiment of the present disclosure.

[0102] In the following embodiments, the operations of FIG. 6 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 6 may be changed, and at least two operations may be performed in parallel.

[0103] According to one embodiment, operations 605 to 625 of FIG. 6 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0104] Referring to FIG. 6, the processor (230) (e.g., the security resource management module (325) of FIG. 3) may receive a security resource related to a function of the electronic device (101) from a server (e.g., the server (310) of FIG. 3) in operation 605. For example, a user of the electronic device (101) may request a security resource after setting the type and / or expiration date of the security resource to be requested. The processor (230) (e.g., the security resource management module (325) of FIG. 3) may transmit a signal requesting the security resource to the server (310) through a communication circuit (e.g., the communication circuit (210) of FIG. 2) based on detecting a signal requesting the security resource. In response to transmitting a signal requesting a security resource to the server (310), the processor (230) (e.g., the security resource management module (325) of FIG. 3) may receive (or acquire) the security resource from the server (310) via the communication circuit (210). The processor (230) (e.g., the security resource management module (325) of FIG. 3) may store the security resource received (or acquired) from the server (310) in a memory (e.g., the memory (220) of FIG. 2).

[0105] In one embodiment, the processor (230) may, in operation 610, check the availability time and number of times the security resource is available when it is determined that the network connection is released under a specified condition.

[0106] In one embodiment, the specified condition may include one of a condition in which an event related to the execution of a function of the electronic device (101) occurs or a condition in which an event related to the reboot of the electronic device (101) occurs. The present invention is not limited thereto, and the processor (230) may also check whether a network connection has been released at regular intervals. According to one embodiment, the aforementioned specified condition and an event related to a network connection may be detected by an event processing module (e.g., the event processing module (330) of FIG. 3 ).

[0107] In one embodiment, the processor (230) can check the availability time of a security resource stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3). For example, the meta information included in the secure resource may include the issuance date and expiration date of the security resource as the validity period of the security resource. The processor (230) can check the availability time of the security resource (e.g., the availability time of the security resource = expiration date - issuance date) calculated based on the issuance date and expiration date of the security resource and stored in the secure storage management module (355).

[0108] In one embodiment, the processor (230) can check the available number of times a security resource is stored in a number management module (e.g., the number management module (345) of FIG. 3).

[0109] In one embodiment, the processor (230) may, at operation 615, determine whether the available time of the security resource is less than a specified time based on time information obtained through an RTC (real time clock) (e.g., the time information provision module (360) of FIG. 3). At operation 620, the processor (230) may determine whether the number of available times of the security resource is less than a specified number.

[0110] According to one embodiment, the aforementioned operations 615 and 620 may be performed in parallel.

[0111] In one embodiment, the processor (230) may limit the use of a security resource in operation 625 if the available time of the security resource is determined to be less than a specified time, or the number of times the security resource is available is determined to be less than a specified number of times. For example, the specified time may include 0 hours, and the specified number of times may include 0 times. However, this is not a limitation.

[0112] In one embodiment, if the available time of a security resource is confirmed to be less than a specified time, or the number of times the security resource can be used is confirmed to be less than a specified number, the processor (230) may determine that the security resource has expired and may restrict the use of the security resource. For example, restricting the use of a security resource may mean deleting the security resource. In another example, restricting the use of a resource may mean restricting only the permissions for the requested function of the electronic device (101) among the permissions provided by the security resource. In yet another example, restricting the use of a resource may mean initializing the meta information of the security resource. Since the method of restricting the security resource varies depending on the environment in which the function of the electronic device (101) according to one embodiment is performed, the above-described methods of restricting the security resource periodically or according to specified conditions may be used interchangeably.

[0113] In one embodiment, a processor (e.g., a security resource management module (325)) may transmit information related to the use of a security resource to a server (310) when a network is connected via the communication circuit (210) after the use of the security resource is restricted (e.g., expired).

[0114] In one embodiment, as the use of security resources is limited, functions of the electronic device (101) may not be performed (e.g., functions of the electronic device (101) may be limited).

[0115] FIG. 7 is a flowchart illustrating a method for limiting security resources when a network connection is released under specified conditions, according to one embodiment of the present disclosure.

[0116] In the following embodiments, the operations of FIG. 7 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 7 may be changed, and at least two operations may be performed in parallel.

[0117] According to one embodiment, operations 705 to 770 of FIG. 7 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0118] FIG. 7 according to various embodiments is a drawing that embodies each operation of FIG. 6 described above.

[0119] Referring to FIG. 7, the processor (230) (e.g., the security resource management module (325) of FIG. 3) may, in operation 705, receive (or acquire) a security resource related to a function of the electronic device (101) from a server (e.g., the server (310) of FIG. 3). The processor (230) (e.g., the security resource management module (325) of FIG. 3) may store the security resource received (or acquired) from the server (310) in a memory (e.g., the memory (220) of FIG. 2). For example, the security resource may include a security certificate and function control policy data. However, the present invention is not limited thereto.

[0120] In one embodiment, the processor (230) may determine, in operation 710, whether a network connection has been released under a specified condition. The specified condition may include one of a condition in which an event related to the execution of a function of the electronic device (101) occurs, a condition in which an event related to the reboot of the electronic device (101) occurs, or a condition in which a certain period occurs.

[0121] In one embodiment, if it is determined that the network connection is disconnected under a specified condition (e.g., YES in operation 710), the processor (230) may obtain time information (e.g., current time information) through a real time clock (RTC) (e.g., time information provision module (360) of FIG. 3) in operation 715. For example, the RTC is a hardware clock of the electronic device (101), and the time information obtained through the RTC may not be arbitrarily modified by the user. Since it is impossible to be arbitrarily modified by the user, the time information obtained through the RTC in a state where the network connection is disconnected may be highly reliable.

[0122] In one embodiment, time information obtained through RTC may be stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3).

[0123] In one embodiment, after obtaining time information (e.g., current time information) through an RTC (e.g., a time information provision module (360)), the processor (230) may, in operation 720, check the availability time of the security resource. For example, the specified time may include 0 hours, but is not limited thereto. In one embodiment, the availability time of the security resource may be stored in a security storage management module (e.g., a security storage management module (355)).

[0124] In one embodiment, the processor (230) may update the available time of the security resource at operation 725 based on time information (e.g., current time information) acquired through the RTC. At operation 730, the processor (230) may determine whether the updated available time of the security resource is less than a specified time. If the updated available time of the security resource is determined to be less than the specified time (e.g., YES in operation 730), the processor (230) may restrict the use of the security resource at operation 735. For example, if the updated available time of the security resource is determined to be less than the specified time, the processor (230) may determine that the security resource has expired and restrict the use of the security resource. For example, restricting the use of the security resource may mean deleting the security resource. As another example, restricting the use of the resource may mean restricting only the authority for the function of the requested electronic device (101) among the authority provided by the security resource. As another example, limiting the use of a resource might mean clearing the metadata of the secure resource.

[0125] In one embodiment, a processor (e.g., a security resource management module (325)) may transmit information related to the use of a security resource to a server (310) when the use of the security resource is restricted (e.g., expired), and then, when a network is connected via the communication circuit (210).

[0126] In one embodiment, if it is determined that the updated availability time of the secure resource is not less than the specified time (e.g., NO in operation 730), the processor (230) may store time information (e.g., current time information) obtained through the RTC (e.g., time information provision module (360)) in operation 740. For example, the processor (230) may store time information (e.g., current time information) obtained through the RTC (e.g., time information provision module (360)) in the secure storage management module (355). The processor (230) may enable the function of the electronic device (101) in operation 745.

[0127] In one embodiment, after enabling the function of the electronic device (101), the processor (230) may check whether a second specified time has elapsed in operation 750. For example, the processor (230) may operate a timer of the electronic device (101). The processor (230) may check whether a second specified time has elapsed after enabling the function of the electronic device (101) through the timer. The second specified time may be about 6 hours. However, the present invention is not limited thereto. The operation of the timer according to one embodiment may be performed in a secure area (e.g., the secure area (340) of FIG. 3). Since the operation of the timer is performed in the secure area (340), the time counted by the timer may not be tampered with (e.g., tampering may be impossible).

[0128] In one embodiment, after allowing the function of the electronic device (101), if it is determined that the second specified time has elapsed (e.g., YES in operation 750), the processor (230) may branch to operation 715 to obtain time information (e.g., current time information) through the RTC (e.g., time information provision module (360)). Thereafter, operations 720 to 750 may be performed. After allowing the function of the electronic device (101), if it is determined that the second specified time has not elapsed (e.g., NO in operation 750), the processor (230) may repeatedly perform operation 750 to determine whether the second specified time has elapsed.

[0129] In one embodiment, if it is determined that the network connection has been disconnected under a specified condition (e.g., YES in operation 710), the processor (230) may check the number of available uses of the security resource in operation 755. For example, the processor (230) may check the number of available uses of the security resource stored in a number management module (e.g., number management module (345) of FIG. 3). In operation 760, the processor (230) may check whether the number of available uses of the security resource is less than a specified number. For example, the specified number may include 0, but is not limited thereto. If it is determined that the number of available uses of the security resource is less than a specified number (e.g., YES in operation 760), the processor (230) may branch to operation 735 to limit the use of the security resource.

[0130] In one embodiment, if the number of available times of the security resource is not confirmed to be less than the specified number (e.g., NO in operation 760), the processor (230) may deduct the number of available times of the security resource in operation 765, and allow the function of the electronic device (101) in operation 770. Thereafter, the processor (230) may branch to operation 755 to confirm the number of available times of the security resource, and perform operation 760 to confirm whether the deducted number of available times of the security resource is less than the specified number.

[0131] According to one embodiment, the above-described operations 715 to 730, operations 740 to 750, and operations 755 to 770 may be performed in parallel. For example, if the processor (230) performs operations 715 to 730, operations 740 to 750 and determines that the available time of the security resource is less than a specified time, or performs operations 755 to 770 and determines that the available number of times the security resource can be used is less than a specified number, the processor (230) may restrict the use of the security resource. As the use of the security resource is restricted, the functions of the electronic device (101) may not be performed.

[0132] In one embodiment, if it is determined that the network connection is not released under a specified condition (e.g., NO of operation 710), the processor (230) may perform the operation of FIG. 8 or FIG. 9.

[0133] In FIG. 7 according to various embodiments, the processor (230) is described as limiting the use of a security resource if the updated available time of the security resource is confirmed to be less than a specified time or the number of available times of the security resource is confirmed to be less than a specified number of times. However, this is not limited thereto. For example, the metadata of the security resource may not include the number of available times. In this case, the processor (230) may only perform operations 705 to 750, which limit the use of the security resource, if the updated available time of the security resource is confirmed to be less than a specified time.

[0134] As seen in FIG. 7 according to various embodiments, when a network connection is released under a specified condition, current time information that cannot be tampered with by the user is acquired through the RTC, the available time of the updated security resource based on the acquired current time information is compared with the specified time, and the number of times the security resource is available is compared with the specified time information to limit the use of the security resource, thereby preventing the security resource from being used without limitation and also preventing it from being misused.

[0135] FIG. 8 is a flowchart illustrating a method for limiting security resources when network connection is established under specified conditions, according to one embodiment of the present disclosure.

[0136] In the following embodiments, the operations of FIG. 8 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 8 may be changed, and at least two operations may be performed in parallel.

[0137] According to one embodiment, operations 805 to 825 of FIG. 8 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0138] FIG. 8 according to various embodiments is a diagram for explaining an operation of obtaining current time information from a server (e.g., server (310) of FIG. 3) and restricting the use of a security resource based thereon when it is confirmed that the network connection is not released under a specified condition (e.g., when it is confirmed that the network is connected).

[0139] Referring to FIG. 8, if it is determined that the network connection is not disconnected under a specified condition (e.g., if it is determined that the network is connected) (e.g., NO in operation 710), the processor (230) may obtain second time information from the server (310) in operation 805. For example, the second time information may mean current time information.

[0140] In one embodiment, the second time information obtained from the server (310) may be stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3).

[0141] In one embodiment, although not shown, if it is determined that the network connection is not released under a specified condition (e.g., if it is determined that the network is connected) (e.g., NO of operation 710), the processor (230) may perform an operation of initializing the number of available uses of the security resource before performing operation 805.

[0142] In one embodiment, the processor (230) may, in operation 810, determine whether the expiration time of the security resource is less than the second time information (e.g., current time information received from the server (310). For example, the meta information included in the security resource may include the issuance date (and / or issuance time) and the expiration date (and / or expiration time) of the security resource as the validity period of the security resource. The processor (230) may determine the expiration time (or expiration date) of the security resource included in the meta information of the security resource.

[0143] In one embodiment, if the expiration time of the security resource is determined to be less than the second time information (e.g., current time information received from the server (310)) (e.g., YES in operation 810), the processor (230) may limit the use of the security resource in operation 815. For example, if the expiration time of the security resource is less than the second time information (e.g., current time information received from the server (310), the processor (230) may determine that the security resource has expired and may limit the use of the security resource. If the use of the security resource is limited (e.g., expired), the processor (e.g., the security resource management module (325)) may transmit information related to the limitation of the use of the security resource to the server (310).

[0144] In one embodiment, if it is determined that the expiration time of the security resource is not less than the second time information (e.g., current time information received from the server (310)) (e.g., NO in operation 810), the processor (230) may allow the function of the electronic device (101) in operation 820. After allowing the function of the electronic device (101), the processor (230) may determine whether the second specified time has elapsed in operation 825. For example, the processor (230) may operate a timer of the electronic device (101). After allowing the function of the electronic device (101) through the timer, the processor (230) may determine whether the second specified time has elapsed. After allowing the function of the electronic device (101), if it is determined that the second specified time has elapsed (e.g., YES in operation 825), the processor (230) may branch to operation 805 to obtain time information, for example, third time information, from the server (310). For example, the third time information may mean current time information. After allowing the function of the electronic device (101), if it is determined that the second specified time has not elapsed (e.g., NO in operation 825), the processor (230) may repeatedly perform operation 825 to determine whether the second specified time has elapsed.

[0145] FIG. 9 is a flowchart illustrating a method for limiting security resources when network connection is established under specified conditions, according to one embodiment of the present disclosure.

[0146] In the following embodiments, the operations of FIG. 9 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 9 may be changed, and at least two operations may be performed in parallel.

[0147] According to one embodiment, operations 905 to 950 of FIG. 9 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0148] FIG. 9 according to various embodiments is a diagram for explaining an operation of limiting the use of a security resource based on current time information obtained from a server (e.g., server (310) of FIG. 3) and / or current time information obtained through an RTC (e.g., time information provision module (360) of FIG. 3) when it is confirmed that the network connection is not released under a specified condition (e.g., when it is confirmed that the network is connected).

[0149] Since operations 905 to 925 of FIG. 9 according to various embodiments are substantially the same as operations 805 to 825 of FIG. 8 described above, a detailed description thereof may be replaced with the description of FIG. 8.

[0150] Referring to FIG. 9, if it is determined that the network connection is not released under a specified condition (e.g., if it is determined that the network is connected) (e.g., NO in operation 710), the processor (230) may obtain second time information from the server (310) in operation 905. For example, the second time information may mean current time information. In operation 910, the processor (230) may determine whether the expiration time of the security resource is less than the second time information (e.g., current time information received from the server (310). If it is determined that the expiration time of the security resource is less than the second time information (e.g., YES in operation 910), the processor (230) may restrict the use of the security resource in operation 915. In one embodiment, when the use of the security resource is restricted (e.g., expired), the processor (e.g., the security resource management module (325)) may transmit information related to the restriction on the use of the security resource to the server (310).

[0151] In one embodiment, if it is determined that the expiration time of the security resource is not less than the second time information (e.g., NO in operation 910), the processor (230) may allow the function of the electronic device (101) in operation 920. After allowing the function of the electronic device (101), the processor (230) may determine whether the second specified time has elapsed in operation 925. For example, the processor (230) may determine whether the second specified time has elapsed after allowing the function of the electronic device (101) through the timer of the electronic device (101). If it is determined that the second specified time has elapsed after allowing the function of the electronic device (101) (e.g., YES in operation 925), the processor (230) may branch to operation 905 to obtain time information, for example, third time information, from the server (310). If it is determined that the second specified time has not elapsed after allowing the function of the electronic device (101) (e.g., NO in operation 925), the processor (230) may repeatedly perform operation 925 to determine whether the second specified time has elapsed.

[0152] In one embodiment, if it is determined that the expiration time of the security resource is not less than the second time information (e.g., NO in operation 910), the processor (230) may obtain time information (e.g., current time information) through the RTC (e.g., the time information providing module (360)) in operation 930. The processor (230) may check the available time of the security resource in operation 935. For example, the available time of the security resource may be stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3). The processor (230) may update the available time of the security resource based on the time information obtained through the RTC in operation 940. The processor (230) may check whether the updated available time of the security resource is less than a specified time in operation 945. If the updated available time of the security resource is determined to be less than the specified time (e.g., YES in operation 945), the processor (230) may limit the use of the security resource in operation 915. If the updated available time of the security resource is determined to not be less than the specified time (e.g., NO in operation 945), the processor (230) may branch to operation 930 and perform an operation of acquiring time information through the RTC.

[0153] As described in FIG. 9 according to various embodiments, even in a situation where a network is connected under specified conditions, the current time information obtained through the server (310) is compared with the expiration time of the security resource, and the available time of the updated security resource based on the current time information obtained through the RTC is compared with the specified time to restrict the use of the security resource, thereby not only accurately determining the expiration time of the security resource, but also preventing the security resource from being used without limit.

[0154] FIG. 10 is a flowchart illustrating a method for limiting security resources when a network is reconnected from a disconnected state, according to one embodiment of the present disclosure.

[0155] According to one embodiment, operations 1005 and 1010 of FIG. 10 may be understood to be performed in a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0156] FIG. 10 according to various embodiments may be an additional operation of operation 750 or operation 770 of FIG. 7 described above.

[0157] Referring to FIG. 10, in a state where the network connection is disconnected, the processor (230) (e.g., the event processing module (330) of FIG. 3) may determine whether a network connection is detected in operation 1005. If a network connection is detected (e.g., YES in operation 1005), the processor (230) may initialize the number of available uses of the security resource in operation 1010 and perform an operation of acquiring second time information through a server (e.g., the server (310) of FIG. 3) in operation 805 of FIG. 8. Thereafter, the processor (230) may perform operations 810 to 825 of determining whether to restrict the use of the security resource based on the second time information acquired from the server (310).

[0158] Not limited thereto, and although not shown, when the network is reconnected in a state where the network is disconnected, the processor (230) may perform an operation of initializing the number of times the security resource can be used in operation 1010 and obtaining second time information through a server (e.g., server (310) of FIG. 3) of operation 905 of FIG. 9. Thereafter, the processor (230) may perform operations 910 to 950 of determining whether to restrict the use of the security resource based on the second time information obtained from the server (310) and / or current time information obtained through the RTC (e.g., time information providing module (360) of FIG. 3).

[0159] In one embodiment, if a network connection is not detected (e.g., N0 of operation 1005), the processor (230) may perform operations 715 and 755 of FIG. 7. For example, the processor (230) may perform operation 715 to obtain time information (e.g., current time information) through an RTC (e.g., a time information provision module (360)), and then perform operations 720 to 750 to determine whether to limit the use of security resources based on the time information. In addition, the processor (230) may perform operation 755 to check the number of available uses of security resources, and then perform operations 760 to 770 to determine whether to limit the use of security resources based on the time information.

[0160] FIG. 11 is a flowchart illustrating a method for updating time information when an event related to a time change is detected, according to one embodiment of the present disclosure.

[0161] In the following embodiments, the operations of FIG. 11 may be performed sequentially, but are not necessarily performed sequentially. For example, the order of the operations of FIG. 11 may be changed, and at least two operations may be performed in parallel.

[0162] According to one embodiment, operations 1105 to 1130 of FIG. 11 may be understood to be performed by a processor (e.g., processor (230) of FIG. 2) of an electronic device (e.g., electronic device (101) of FIG. 1).

[0163] FIG. 11 according to various embodiments is a drawing for explaining an operation of updating the available time of a security resource by acquiring time information (e.g., current time information) through an RTC (e.g., time information provision module (360) of FIG. 3) when an event related to a time change is detected.

[0164] Referring to FIG. 11, in operation 1105, when an event related to a time change is detected, the processor (230) may acquire time information through the RTC (e.g., the time information providing module (360)). For example, the time information acquired through the RTC (e.g., the time information providing module (360)) may include current time information. In one embodiment, the time information (e.g., current time information) acquired through the RTC (e.g., the time information providing module (360)) may be stored in a secure storage management module (e.g., the secure storage management module (355) of FIG. 3).

[0165] In one embodiment, the processor (230) may, in operation 1110, check the availability time of a security resource. For example, the availability time of the security resource may be stored in a security storage management module (e.g., the security storage management module (355)). The processor (230) may check the availability time of the security resource stored in the security storage management module (355).

[0166] In one embodiment, the processor (230) may update the available time of the security resource based on time information (e.g., current time information) obtained through the RTC (e.g., time information provision module (360)) in operation 1115. The processor (230) may determine whether the updated available time of the security resource is less than a specified time in operation 1120. For example, the specified time may include 0 hours, but is not limited thereto. If it is determined that the updated available time of the security resource is less than the specified time (e.g., YES in operation 1120), the processor (230) may delete the time information (e.g., current time information) in operation 1125. For example, the processor (230) may delete time information (e.g., current time information obtained in operation 1105) obtained through the RTC (e.g., time information provision module (360)) stored in the secure storage management module (355). For example, if the updated availability time of the security resource is confirmed to be less than a specified time, the processor (230) may determine that the use of the security resource is restricted (e.g., the security resource has expired) and delete the time information stored in the security storage management module (355) (e.g., the current time information acquired in operation 1105).

[0167] In one embodiment, if it is determined that the updated available time of the security resource is not less than the specified time (e.g., NO in operation 1120), the processor (230) may store time information (e.g., current time information) in operation 1130. For example, the processor (230) may store time information (e.g., current time information obtained in operation 1105) obtained through an RTC (e.g., time information provision module (360)) in the secure storage management module (355). For example, if it is determined that the updated available time of the security resource is not less than the specified time, the processor (230) may determine that the situation is to limit the use of the security resource (e.g., determine that the security resource has not expired) and store the time information (e.g., current time information obtained in operation 1105) in the secure storage management module (355), so that it may be used to check the available time of the security resource later.

[0168] A method for limiting a security resource according to one embodiment of the present disclosure may include an operation of receiving a security resource related to a function of an electronic device (101) from a server (310) through a communication circuit (210). A method for limiting a security resource according to one embodiment may include an operation of checking the available time and the number of times the security resource can be used when it is determined that a network connection has been released under a specified condition. A method for limiting a security resource according to one embodiment may include an operation of checking whether the available time of the security resource is less than a specified time based on time information acquired through a real time clock (RTC). A method for limiting a security resource according to one embodiment may include an operation of checking whether the number of times the security resource can be used is less than a specified number. A method for limiting a security resource according to one embodiment may include an operation of limiting the use of the security resource when it is determined that the available time of the security resource is less than a specified time or the number of times the security resource can be used is less than a specified number.

[0169] The operation of determining whether the available time of a security resource is less than a specified time according to one embodiment may include updating the available time of the security resource based on time information acquired through the RTC. The operation of determining whether the available time of the security resource is less than a specified time according to one embodiment may include determining whether the updated available time of the security resource is less than a specified time.

[0170] A method for limiting a security resource according to one embodiment may include an operation of storing time information acquired through an RTC in a memory (220) and allowing a function of an electronic device (101) if it is confirmed that the available time of a security resource is not less than a specified time. A method for limiting a security resource according to one embodiment may include an operation of acquiring second time information through an RTC if it is confirmed that a second specified time has elapsed after allowing the function of the electronic device (101).

[0171] A method for limiting a secure resource according to one embodiment may include an operation for determining whether a network is connected when a second specified time has elapsed after allowing a function of an electronic device (101). If a network is connected, the method for limiting a secure resource according to one embodiment may include an operation for initializing the number of times a secure resource can be used and obtaining time information from a server (310).

[0172] A method for limiting security resources according to one embodiment may include an operation of executing a function of an electronic device (101) after deducting the number of available times when it is confirmed that the number of available times of a security resource is not less than a specified number.

[0173] A method for limiting a security resource according to one embodiment may include an operation of limiting the use of a security resource, and then, when a network connection is detected, transmitting information related to the limit on the use of the security resource to a server (310) via a communication circuit (210).

[0174] A method for restricting a secure resource according to one embodiment may include an operation for obtaining second time information from a server, if the network connection is not disconnected. A method for restricting a secure resource according to one embodiment may include an operation for restricting the use of the secure resource if the expiration time of the secure resource is determined to be less than the second time information. A method for restricting a secure resource according to one embodiment may include an operation for allowing a function of the electronic device (101) if the expiration time of the secure resource is determined to not be less than the second time information.

[0175] A method for restricting a security resource according to one embodiment may include an operation of acquiring third time information from an RTC if it is confirmed that the expiration time of the security resource is not less than the second time information. A method for restricting a security resource according to one embodiment may include an operation of updating the available time of the security resource based on the third time information acquired through the RTC. A method for restricting a security resource according to one embodiment may include an operation of storing the third time information if the available time of the updated security resource is not less than a specified time. A method for restricting a security resource according to one embodiment may include an operation of restricting the use of the security resource if the available time of the updated security resource is less than a specified time.

[0176] A specified condition according to one embodiment may include one of a condition in which an event related to the execution of a function of the electronic device (101) occurs, a condition in which an event related to the reboot of the electronic device (101) occurs, or a condition in which a certain period occurs.

[0177] Restricting the use of a security resource according to one embodiment may include at least one of deleting the security resource, restricting only the permissions provided by the security resource to functions of the electronic device (101), or initializing meta information of the security resource.

[0178] A non-transitory computer-readable recording medium storing instructions that, when executed by a processor (230) of an electronic device (101) according to one embodiment of the present disclosure, cause the processor (230) to perform operations, may cause the processor (230) to perform an operation of receiving a security resource related to a function of the electronic device (101) from a server (310) via a communication circuit (210). A non-transitory computer-readable recording medium storing instructions that, when executed by a processor (230) of an electronic device (101) according to one embodiment, cause the processor (230) to perform operations, may cause the processor (230) to perform an operation of checking the available time and the available number of times the security resource is available when it is determined that a network connection has been released under a specified condition. A non-transitory computer-readable recording medium storing instructions that, when executed by a processor (230) of an electronic device (101) according to one embodiment, cause the processor (230) to perform operations, may cause the processor (230) to perform an operation of checking whether the available time of a security resource is less than a specified time based on time information acquired through a real time clock (RTC). A non-transitory computer-readable recording medium storing instructions that, when executed by a processor (230) of an electronic device (101) according to one embodiment, cause the processor (230) to perform operations, may cause the processor (230) to perform an operation of checking whether the available number of times a security resource is available is less than a specified number.A non-transitory computer-readable recording medium storing instructions that, when executed by a processor (230) of an electronic device (101) according to one embodiment, cause the processor (230) to perform operations, may cause an operation to be executed to limit the use of a security resource when the available time of a security resource is confirmed to be less than a specified time or when the available number of security resources is confirmed to be less than a specified number of times.

[0179] Electronic devices according to the various embodiments disclosed in this document may take various forms. Electronic devices may include, for example, portable communication devices (e.g., smartphones), computer devices, portable multimedia devices, portable medical devices, cameras, wearable devices, or home appliances. Electronic devices according to the embodiments of this document are not limited to the aforementioned devices.

[0180] The various embodiments of this document and the terminology used therein are not intended to limit the technical features described in this document to specific embodiments, but should be understood to include various modifications, equivalents, or substitutes of the embodiments. In connection with the description of the drawings, similar reference numerals may be used for similar or related components. The singular form of a noun corresponding to an item may include one or more of the items, unless the context clearly indicates otherwise. In this document, each of the phrases “A or B,” “at least one of A and B,” “at least one of A or B,” “A, B, or C,” “at least one of A, B, and C,” and “at least one of A, B, or C” can include any one of the items listed together in the corresponding phrase among those phrases, or all possible combinations thereof. Terms such as “first,” “second,” or “first” or “second” may be used merely to distinguish one component from another, and do not limit the components in any other respect (e.g., importance or order). When a component (e.g., a first component) is referred to as “coupled” or “connected” to another component (e.g., a second component), with or without the terms “functionally” or “communicatively,” it means that the component can be connected to the other component directly (e.g., wired), wirelessly, or through a third component.

[0181] The term "module" used in various embodiments of this document may include a unit implemented in hardware, software, or firmware, and may be used interchangeably with terms such as logic, logic block, component, or circuit. A module may be an integral component, or a minimum unit or part of such a component that performs one or more functions. For example, according to one embodiment, a module may be implemented in the form of an application-specific integrated circuit (ASIC).

[0182] Various embodiments of the present document may be implemented as software (e.g., a program (140)) including one or more instructions stored in a storage medium (e.g., an internal memory (136) or an external memory (138)) readable by a machine (e.g., an electronic device (101)). For example, a processor (e.g., a processor (120)) of the machine (e.g., an electronic device (101)) may call at least one instruction among the one or more instructions stored from the storage medium and execute it. This enables the machine to operate to perform at least one function according to the at least one called instruction. The one or more instructions may include code generated by a compiler or code executable by an interpreter. The machine-readable storage medium may be provided in the form of a non-transitory storage medium. Here, 'non-transitory' simply means that the storage medium is a tangible device and does not contain signals (e.g., electromagnetic waves), and the term does not distinguish between cases where data is stored semi-permanently or temporarily on the storage medium.

[0183] According to one embodiment, the method according to various embodiments disclosed in this document may be provided as a computer program product. The computer program product may be traded between sellers and buyers as a product. The computer program product may be distributed in the form of a device-readable storage medium (e.g., compact disc read-only memory (CD-ROM)) or may be provided through an application store (e.g., Play Store). TM ) or directly between two user devices (e.g., smart phones), online distribution (e.g., downloading or uploading). In the case of online distribution, at least a portion of the computer program product may be at least temporarily stored or temporarily created in a machine-readable storage medium, such as the memory of a manufacturer's server, an application store's server, or an intermediary server.

[0184] According to various embodiments, each component (e.g., a module or a program) of the above-described components may include one or more entities, and some of the entities may be separated and placed in other components. According to various embodiments, one or more components or operations of the aforementioned components may be omitted, or one or more other components or operations may be added. Alternatively or additionally, a plurality of components (e.g., a module or a program) may be integrated into a single component. In such a case, the integrated component may perform one or more functions of each of the plurality of components identically or similarly to those performed by the corresponding component among the plurality of components prior to the integration. According to various embodiments, the operations performed by a module, program, or other component may be executed sequentially, in parallel, iteratively, or heuristically, or one or more of the operations may be executed in a different order, omitted, or one or more other operations may be added.

Claims

1. In an electronic device (101), Communication circuit (210); Memory (220) for storing instructions; and Contains a processor (230), The above instructions, when executed by the processor (230), cause the electronic device (101) to: Receive security resources related to the function of the above electronic device (101) from the server (310) through the communication circuit (210), When it is determined that the network connection is disconnected under the specified conditions, the availability time and number of times the security resource can be used are checked. Based on the time information obtained through the RTC (real time clock), it is checked whether the available time of the security resource is less than the specified time, Check whether the number of available times for the above security resource is less than the specified number of times, and An electronic device that restricts the use of the security resource when the available time of the security resource is confirmed to be less than the specified time, or when the available number of times of the security resource is confirmed to be less than the specified number of times.

2. In paragraph 1, The above instructions, when executed by the processor (230), cause the electronic device (101) to: Based on the time information obtained through the above RTC, the availability time of the above security resource is updated, Check whether the availability time of the above updated security resource is less than the above specified time, The above instructions, when executed by the processor (230), cause the electronic device (101) to: If it is confirmed that the available time of the above security resource is not less than the specified time, the time information obtained through the RTC is stored in the memory (220), and the function of the electronic device (101) is permitted, and An electronic device that acquires second time information through the RTC when it is confirmed that a second designated time has elapsed after allowing the function of the electronic device (101).

3. In paragraph 2, The above instructions, when executed by the processor (230), cause the electronic device (101) to: After allowing the function of the above electronic device (101), if it is confirmed that the second specified time has elapsed, it is checked whether the network is connected, and An electronic device that initializes the available number of times of the security resource is used when the above network is connected and obtains time information from the server (310).

4. In any one of paragraphs 1 to 3, The above instructions, when executed by the processor (230), cause the electronic device (101) to: An electronic device that, if it is confirmed that the number of available times of the above security resource is not less than the specified number of times, deducts the number of available times and then executes the function of the electronic device (101).

5. In any one of paragraphs 1 to 4, The above instructions, when executed by the processor (230), cause the electronic device (101) to: An electronic device that, after restricting the use of the above security resource, when the network connection is detected, transmits information related to the restriction of the use of the above security resource to the server (310) through the communication circuit (210).

6. In any one of paragraphs 1 to 5, The above instructions, when executed by the processor (230), cause the electronic device (101) to: If the above network connection is not disconnected, obtain the second time information from the server, If it is confirmed that the expiration time of the above security resource is less than the second time information, the use of the above security resource is restricted, and An electronic device that allows the function of the electronic device (101) if it is confirmed that the expiration time of the above security resource is not less than the second time information.

7. In paragraph 6, The above instructions, when executed by the processor (230), cause the electronic device (101) to: If it is confirmed that the expiration time of the above security resource is not less than the second time information, the third time information is obtained from the RTC, Based on the third time information obtained through the above RTC, the availability time of the security resource is updated, If the availability time of the above updated security resource is not less than the above specified time, store the third time information, and An electronic device that restricts the use of the security resource if the available time of the updated security resource is less than the specified time.

8. In any one of paragraphs 1 to 7, The above specified condition includes one of a condition in which an event related to the execution of a function of the electronic device (101) occurs, a condition in which an event related to the reboot of the electronic device (101) occurs, or a condition in which a certain period occurs, and An electronic device wherein limiting the use of the security resource comprises at least one of deleting the security resource, limiting only the permissions for functions of the electronic device (101) among the permissions provided by the security resource, or initializing the meta information of the security resource.

9. In the method of limiting security resources, An operation of receiving a security resource related to the function of an electronic device (101) from a server (310) through a communication circuit (210); When it is determined that the network connection is disconnected under specified conditions, an action is taken to check the availability time and the number of times the security resource can be used; An action to check whether the available time of the security resource is less than a specified time based on time information acquired through the RTC (real time clock); An operation to check whether the number of available times of the above security resource is less than a specified number; and A method including an action of limiting the use of the security resource when the available time of the security resource is confirmed to be less than the specified time, or when the available number of times of the security resource is confirmed to be less than the specified number of times.

10. In paragraph 9, The action of checking whether the availability time of the above security resource is less than the specified time is: An operation of updating the availability time of the security resource based on the time information obtained through the RTC; and An action to check whether the availability time of the above updated security resource is less than the above specified time; If it is confirmed that the available time of the above security resource is not less than the above specified time, an operation of storing the time information acquired through the RTC in the memory (220) and allowing the function of the electronic device (101); and A method further comprising an operation of acquiring second time information through the RTC when it is confirmed that a second specified time has elapsed after allowing the function of the electronic device (101).

11. In Article 10, After allowing the function of the electronic device (101), if it is confirmed that the second specified time has elapsed, an operation of checking whether the network is connected; and A method further comprising the steps of initializing the available number of times of the security resource is used when the above network is connected and obtaining time information from the server (310).

12. In any one of paragraphs 9 to 11, A method further comprising an operation of executing a function of the electronic device (101) after deducting the available number of times if it is confirmed that the available number of times of the security resource is not less than the specified number of times.

13. In any one of paragraphs 9 to 12, A method further comprising: after restricting the use of the above security resource, if the network connection is detected, transmitting information related to the restriction on the use of the above security resource to the server (310) through the communication circuit (210).

14. In any one of paragraphs 9 to 13, An operation of obtaining second time information from the server if the above network connection is not disconnected; If it is determined that the expiration time of the above security resource is less than the second time information, an action to restrict the use of the above security resource; If it is confirmed that the expiration time of the above security resource is not less than the second time information, an operation of allowing the function of the electronic device (101); An operation of acquiring third time information from the RTC if it is confirmed that the expiration time of the above security resource is not less than the second time information; An operation of updating the availability time of the security resource based on the third time information obtained through the RTC; An operation of storing the third time information if the availability time of the above updated security resource is not less than the above specified time; and A method further comprising an action of limiting the use of the security resource if the availability time of the updated security resource is less than the specified time.

15. A non-transitory computer-readable medium storing instructions that, when executed by a processor (230) of an electronic device (101), cause the processor (230) to perform operations, An operation of receiving a security resource related to the function of the above electronic device (101) from a server (310) through a communication circuit (210); When it is determined that the network connection is disconnected under specified conditions, an action is taken to check the availability time and the number of times the security resource can be used; An action to check whether the available time of the security resource is less than a specified time based on time information acquired through the RTC (real time clock); An operation to check whether the number of available times of the above security resource is less than a specified number; and A computer-readable recording medium that causes an operation to be executed to limit the use of the security resource when the available time of the security resource is confirmed to be less than the specified time, or when the available number of times of the security resource is confirmed to be less than the specified number of times.

Citation Information

Patent Citations

  • Resource management device, resource management method and resource management program

    JP2019074798A

  • Resource management device, user device side resource management device, resource management method, user device side resource management method, program, and storage medium

    JP2020154530A

  • CPU resource management device

    JP2021092904A

  • Semiconductor memory device

    KR1020230155302A

  • KR20190142108A