Dual OS Security State Identification for Electronic Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Linux-based electronic devices are vulnerable to security breaches due to their openness, which compromises their ability to securely provide financial transaction and business processing services.
Innovation Solution
An apparatus and method that identifies the security state of an electronic device by booting a second operating system, generating a hash value of system binaries, and sending security state information to a first operating system, allowing for secure management of private keys and application installations based on the identified security state.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If Linux-based electronic device uses open system for flexibility and various services, then adaptability and ease of operation are improved, but security reliability deteriorates due to vulnerability to security breaches
Solution Approach 1:
The patent divides the electronic device into two distinct operating systems: a first operating system (Linux-based) that provides flexibility and various services, and a second operating system (secure OS) that ensures security. This segmentation allows each OS to perform its specialized function independently, resolving the contradiction between adaptability and security reliability.
Solution Approach 2:
The patent introduces a security management application as an intermediary between the first operating system and the second operating system. This intermediary manages security states, controls access to secure functions, and coordinates between the flexible but vulnerable first OS and the secure but restricted second OS, enabling both flexibility and security to coexist.
2Ease of operation
If Linux-based electronic device allows free system modification, then ease of operation is improved, but security state control deteriorates due to unauthorized changes
Solution Approach 1:
The patent implements a feedback mechanism where the second operating system continuously monitors the security state of system binaries and communicates this information back to the first operating system through the security management application. This feedback loop enables real-time detection of unauthorized modifications while allowing legitimate system changes in the first OS.
Solution Approach 2:
The patent establishes security state information and baseline security configurations in advance through the second operating system before the first operating system performs any system modifications. This preliminary security setup enables proactive detection and prevention of unauthorized changes while maintaining operational flexibility.
Data Source
AI summary
An apparatus and a method for identifying security of an electronic device are provided. The method includes identifying a security state of a system binary loaded to a memory of the electronic device based on booting of the electronic device in a second operating system of the electronic device, and sending security state information to a first operating system in the second operating system based on a request from the first operating system of the electronic device.


