Secure Element OS Switching via External Data Storage
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current system on chip (SoC) technologies face challenges in supporting multiple secure operating systems while ensuring high security and low implementation costs, as they often require complex secure element integration and lengthy certification processes for secure operating systems, limiting flexibility and efficiency in supporting diverse application software.
Innovation Solution
A system on chip with a secure element and central processing unit that enables secure operating system switching by suspending one OS, encrypting or performing MAC computations on its data, and storing it externally, allowing for rapid switching between multiple secure operating systems without the need for large memory capacity within the SoC, thereby supporting coexistence and efficient integration.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a secure element supports multiple secure operating systems simultaneously, then the adaptability and versatility improve, but the device complexity and memory requirements increase
Solution Approach 1:
The patent segments the memory resources by creating separate dedicated storage areas within the secure element for each secure operating system. Each OS has its own isolated memory space, allowing multiple OSes to coexist without interfering with each other while maintaining security boundaries. This segmentation enables the secure element to support multiple OSes without proportionally increasing overall system complexity.
Solution Approach 2:
The secure element is designed with universal memory management capabilities that can accommodate multiple secure operating systems through a unified architecture. The memory controller and management mechanisms serve multiple OSes simultaneously, allowing the same hardware infrastructure to support diverse secure applications without requiring separate dedicated hardware for each OS.
2Adaptability or versatility
If a secure element integrates large memory capacity to support multiple secure operating systems, then the adaptability improves, but the manufacturing cost and device complexity increase
Solution Approach 1:
The patent merges multiple secure operating systems into a single secure element with shared memory resources. Instead of requiring separate secure elements or large dedicated memory for each OS, the system combines multiple OSes and their memory requirements into one integrated structure, reducing overall manufacturing costs and complexity while maintaining the ability to support multiple secure applications.
Solution Approach 2:
The memory management implementation uses local quality by providing each secure operating system with dedicated storage areas within the secure element's memory space. Each OS receives appropriate memory allocation based on its specific needs rather than requiring uniform large capacity across the entire system, optimizing resource usage and reducing manufacturing costs.
3Adaptability or versatility
If secure operating system software is frequently modified to meet new application requirements, then the adaptability improves, but the security reliability deteriorates due to certification requirements
Solution Approach 1:
The patent implements dynamic secure operating system switching capability within the secure element, allowing the system to load and execute different secure OSes based on application requirements without permanently modifying the underlying secure firmware. This dynamic approach enables adaptability to new requirements while maintaining the stability and certification status of the core secure element firmware.
Solution Approach 2:
The system performs preliminary actions by pre-loading multiple secure operating systems into the secure element's memory before runtime. This allows the secure element to switch between pre-certified OSes based on application needs without requiring frequent firmware modifications or recertification, maintaining both adaptability and security reliability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
A system on chip and method for implementing secure operating system switching are disclosed. The system on chip is integrated in a first semiconductor chip, and includes a secure element and at least one central processing unit that is coupled to the secure element. Security isolation exists between the secure element and the at least one central processing unit. The at least one central processing unit is configured to communicate with the secure element. The secure element includes a secure processor and a first memory that is coupled to the secure processor. The secure processor can suspend running first secure operating system software and further start second secure operating system software, to implement switching between multiple pieces of secure operating system software. Running data of running secure operating system software is stored in the first memory, and running data of secure operating system software that is not run is stored in a second memory outside the system on chip.