Secure Module Isolation for Hardware Attack Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Related-art electronic devices are vulnerable to hardware attacks when providing secure processing, and lack of a physical button connected to secure hardware complicates trust in user input, making secure data processing unreliable.

Innovation Solution

An electronic device with a secure module physically separated from the processor, featuring a secure processor that disables the main display driver and enables a secure display driver to output a user interface for secure data, enhancing security by isolating sensitive operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If secure data processing is provided through a processor's secure world, then secure processing capability is achieved, but the device becomes vulnerable to hardware attacks

Engineering Contradiction:
Improvesecure processing capabilityVSAvoidhardware attack vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the electronic device into two physically separate modules: a main processor for general operations and a secure module for secure data processing. This segmentation isolates secure operations from the main processor, preventing hardware attacks on the main processor from compromising secure data. The secure module contains its own secure processor and display driver, creating a physically separated secure enclave that maintains security even if the main processor is compromised.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If a physical button is not directly connected to secure hardware, then device complexity is reduced, but trust in user input cannot be guaranteed

Engineering Contradiction:
Improvehardware connection complexityVSAvoiduser input trust
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent introduces a secure module as an intermediary between the display driver and the secure processor. This secure module acts as a trusted mediator that verifies user inputs (such as button presses) before processing secure data. By placing the display driver within the secure module rather than directly connecting external buttons to secure hardware, the system maintains input trust while reducing overall hardware complexity. The secure module mediates all input validation for secure operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11550963B2Method of processing secure data and electronic device supporting the same
Publication Date: 2023.01.10 SAMSUNG ELECTRONICS CO LTD
  • US11550963B2 patent drawing
  • US11550963B2 patent drawing
  • US11550963B2 patent drawing

AI summary

An electronic device is provided. The electronic device includes a communication circuit, a display, a memory including a first display driver, a processor functionally connected with the communication circuit, the display, and the memory, and a secure module which is physically separated from the processor, and includes a secure processor and a second display driver, and the secure processor is configured to: when secure data is received from an external server through the communication circuit, disable the first display driver and enable the second display driver, and output a user interface including a first object corresponding to the secure data to the display by using the enabled second display driver.