Electronic Module Secure Message Routing for Trusted OS
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In electronic devices with both general-purpose and trusted execution environments, malicious applications can intercept and deny messages intended for the trusted operating system, leading to a denial-of-service issue.
Innovation Solution
An electronic module determines the target operating system for incoming messages and routes them directly to the intended environment, using dedicated communication channels and memory access controls to prevent interception by the general-purpose operating system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If messages are transmitted through the general-purpose operating system to elements controlled by it, then message routing is simple, but malicious applications can intercept or destroy messages intended for the trusted operating system
Solution Approach 1:
The patent segments the message routing path into separate channels: one for general-purpose OS messages and another direct channel for trusted OS messages. The transceiver is divided into distinct modules: determination means for identifying the target OS, and communication means for executing the routing decision. This segmentation prevents malicious applications from accessing messages intended for the trusted OS.
Solution Approach 2:
The patent introduces an intermediary electronic module (comprising determination means and communication means) that sits between the transceiver and the operating systems. This intermediary determines the target OS and routes messages appropriately, preventing malicious applications in the general-purpose OS from intercepting trusted OS messages while maintaining simple routing for general messages.
2Reliability
If messages are routed directly to the targeted operating system without interception, then message security is improved, but additional routing determination mechanisms are required
Solution Approach 1:
The determination means is designed with multi-functionality: it can identify messages intended for the trusted OS, determine the appropriate communication channel, and route messages accordingly. This universal module handles both simple general-purpose message routing and secure trusted OS message routing, reducing overall system complexity despite the added security functionality.
Data Source
Figure 1A
Figure 1B
Figure 1C
AI summary
The module (10) has a determination unit (12) for determining an operating system targeted by a message received by a transmitter-receiver (E/R) of an electronic device, from among a Rich-OS operating system (100) and a trusted operating system (200) executed on a chipset of the device, where the message becomes accessible to the targeted operating system. The determination unit is set in operation in response to receipt of the message by the transmitter-receiver. An initialization unit (18) initializes a communication channel between the electronic module and the targeted operating system. Independent claims are also included for the following: (1) a terminal (2) a message routing method (3) a computer program for routing a message (4) a computer readable recording medium storing a computer program for routing a message.