Electronic Module Secure Message Routing for Trusted OS

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In electronic devices with both general-purpose and trusted execution environments, malicious applications can intercept and deny messages intended for the trusted operating system, leading to a denial-of-service issue.

Innovation Solution

An electronic module determines the target operating system for incoming messages and routes them directly to the intended environment, using dedicated communication channels and memory access controls to prevent interception by the general-purpose operating system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If messages are transmitted through the general-purpose operating system to elements controlled by it, then message routing is simple, but malicious applications can intercept or destroy messages intended for the trusted operating system

Engineering Contradiction:
Improvemessage routing complexityVSAvoidmessage delivery security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the message routing path into separate channels: one for general-purpose OS messages and another direct channel for trusted OS messages. The transceiver is divided into distinct modules: determination means for identifying the target OS, and communication means for executing the routing decision. This segmentation prevents malicious applications from accessing messages intended for the trusted OS.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary electronic module (comprising determination means and communication means) that sits between the transceiver and the operating systems. This intermediary determines the target OS and routes messages appropriately, preventing malicious applications in the general-purpose OS from intercepting trusted OS messages while maintaining simple routing for general messages.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If messages are routed directly to the targeted operating system without interception, then message security is improved, but additional routing determination mechanisms are required

Engineering Contradiction:
Improvemessage delivery securityVSAvoidrouting determination complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The determination means is designed with multi-functionality: it can identify messages intended for the trusted OS, determine the appropriate communication channel, and route messages accordingly. This universal module handles both simple general-purpose message routing and secure trusted OS message routing, reducing overall system complexity despite the added security functionality.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentEP2736275B1Electronic module for making a message accessible to a target operating system
Publication Date: 2020.05.27 IDEMIA FRANCE SAS
  • EP2736275B1 patent drawingFigure 1A
  • EP2736275B1 patent drawingFigure 1B
  • EP2736275B1 patent drawingFigure 1C

AI summary

The module (10) has a determination unit (12) for determining an operating system targeted by a message received by a transmitter-receiver (E/R) of an electronic device, from among a Rich-OS operating system (100) and a trusted operating system (200) executed on a chipset of the device, where the message becomes accessible to the targeted operating system. The determination unit is set in operation in response to receipt of the message by the transmitter-receiver. An initialization unit (18) initializes a communication channel between the electronic module and the targeted operating system. Independent claims are also included for the following: (1) a terminal (2) a message routing method (3) a computer program for routing a message (4) a computer readable recording medium storing a computer program for routing a message.