Secure Element Boot Verification for Trusted OS Communication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Electronic devices face challenges in securely exchanging secret and critical data without protection, particularly in the context of integrating functionalities like bank payment and authentication services, where data exchanged between different modules and software layers are not adequately safeguarded.
Innovation Solution
Implementing a dual-layer operating system architecture with a secure element that executes a low-level operating system to verify the reliability and authenticity of a high-level operating system, and perform wireless communication, ensuring verification at each boot-up and upon request from applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a dual-layer operating system architecture with verification is implemented, then data security and reliability are improved, but device complexity increases
Solution Approach 1:
The patent divides the operating system into two distinct layers: a high-level operating system (HLOS) for general application execution and a low-level operating system (LLOS) for security-critical functions. This segmentation allows each layer to have specialized responsibilities, with LLOS verifying HLOS authenticity before allowing data exchanges, thereby improving security while keeping the architecture manageable through clear functional separation.
Solution Approach 2:
The low-level operating system acts as an intermediary between the high-level operating system and the secure element. LLOS verifies the authenticity of HLOS and mediates all data exchanges between HLOS and the secure element, ensuring that only authenticated applications can access sensitive data. This intermediary role enhances security without requiring direct trust between HLOS and the secure element.
2Reliability
If verification of operating system authenticity is performed at each booting, then reliability is improved, but processing time is increased
Solution Approach 1:
The low-level operating system performs authenticity verification of the high-level operating system during the booting process before the HLOS becomes fully operational. This preliminary action ensures that only authenticated HLOS instances can access the secure element, establishing security trust early in the system initialization while preventing unauthorized access from the outset.
3Reliability
If secure elements are added to verify and protect data, then data protection capability is improved, but device complexity increases
Solution Approach 1:
The patent combines the secure element with the low-level operating system in a tightly integrated architecture. The secure element is embedded within the LLOS environment, allowing seamless verification and data exchange processes. This merging reduces the need for separate verification hardware and simplifies the overall system architecture while maintaining strong security guarantees through the unified LLOS-secure element relationship.
Data Source
AI summary
An electronic device includes a processor and one or more secure elements. The processor executes a first high-level operating system and a first application. The one or more secure elements execute a first low-level operating system to verify a reliability, an authenticity, or a reliability and an authenticity of the first high-level operating system, and execute a second low-level operating system to execute a second application and to perform wireless communication with the first application. At each booting of the electronic device, the first low-level operating system performs a verification of the reliability, of the authenticity, or of the reliability and the authenticity of the first high-level operating system. In response to a request from the first application to the second application, the second low-level operating system requests a result of the verification from the first low-level operating system, and transmits the result to the second application.


