Secure Element Boot Verification for Trusted OS Communication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Electronic devices face challenges in securely exchanging secret and critical data without protection, particularly in the context of integrating functionalities like bank payment and authentication services, where data exchanged between different modules and software layers are not adequately safeguarded.

Innovation Solution

Implementing a dual-layer operating system architecture with a secure element that executes a low-level operating system to verify the reliability and authenticity of a high-level operating system, and perform wireless communication, ensuring verification at each boot-up and upon request from applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a dual-layer operating system architecture with verification is implemented, then data security and reliability are improved, but device complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the operating system into two distinct layers: a high-level operating system (HLOS) for general application execution and a low-level operating system (LLOS) for security-critical functions. This segmentation allows each layer to have specialized responsibilities, with LLOS verifying HLOS authenticity before allowing data exchanges, thereby improving security while keeping the architecture manageable through clear functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The low-level operating system acts as an intermediary between the high-level operating system and the secure element. LLOS verifies the authenticity of HLOS and mediates all data exchanges between HLOS and the secure element, ensuring that only authenticated applications can access sensitive data. This intermediary role enhances security without requiring direct trust between HLOS and the secure element.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If verification of operating system authenticity is performed at each booting, then reliability is improved, but processing time is increased

Engineering Contradiction:
Improveauthenticity verificationVSAvoidboot time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The low-level operating system performs authenticity verification of the high-level operating system during the booting process before the HLOS becomes fully operational. This preliminary action ensures that only authenticated HLOS instances can access the secure element, establishing security trust early in the system initialization while preventing unauthorized access from the outset.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If secure elements are added to verify and protect data, then data protection capability is improved, but device complexity increases

Engineering Contradiction:
Improvedata protectionVSAvoidhardware complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines the secure element with the low-level operating system in a tightly integrated architecture. The secure element is embedded within the LLOS environment, allowing seamless verification and data exchange processes. This merging reduces the need for separate verification hardware and simplifies the overall system architecture while maintaining strong security guarantees through the unified LLOS-secure element relationship.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12505197B2Protection of an electronic device
Publication Date: 2025.12.23 STMICROELECTRONICS (ROUSSET) SAS
  • US12505197B2 patent drawing
  • US12505197B2 patent drawing
  • US12505197B2 patent drawing

AI summary

An electronic device includes a processor and one or more secure elements. The processor executes a first high-level operating system and a first application. The one or more secure elements execute a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and execute a second low-level operating system to execute a second application and to perform wireless communication with the first application. At each booting of the electronic device, the first low-level operating system performs a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system. In response to a request from the first application to the second application, the second low-level operating system requests a result of the verification from the first low-level operating system, and transmits the result to the second application.