Secure OS Gateway for IoT Communication Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing IoT technologies face security vulnerabilities due to the integration of various electronic apparatuses, making them susceptible to hacking and compromising communication security.

Innovation Solution

The implementation of a method and electronic apparatus that utilize a secure operating system (OS) to manage communication between devices, generating and exchanging key values to establish and maintain secure connections, while blocking unauthorized access and updating keys periodically.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a secure OS is installed to enhance communication security, then security reliability is improved, but device complexity increases

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system is divided into two distinct OS environments: a secure OS for security-critical operations and a normal OS for general-purpose functions. This segmentation allows each OS to be optimized for its specific purpose without compromising the other, resolving the contradiction between security reliability and device complexity by isolating security functions in a dedicated environment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A gateway component acts as an intermediary between the secure OS and normal OS, managing communication and data exchange between the two environments. This intermediary controls access points and enforces security policies, allowing the normal OS to operate with reduced complexity while the secure OS maintains security reliability through controlled interactions via the gateway.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If key values are updated periodically to maintain security, then security reliability is improved, but loss of time occurs during key updates

Engineering Contradiction:
Improvecommunication securityVSAvoidtime for key updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

Multiple key values are pre-generated and stored in the secure OS before they are needed. When a key update is required, the system can immediately switch to a pre-generated key without requiring time-consuming generation or computation during the update moment, thus maintaining security reliability while minimizing time loss.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements periodic key updates at predetermined intervals rather than on-demand updates. This allows the secure OS to proactively refresh keys during low-activity periods, ensuring security reliability is maintained while avoiding time loss during critical operations by scheduling updates in advance.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3304412B1Electronic apparatus and method for controlling the same
Publication Date: 2019.11.06 SAMSUNG ELECTRONICS CO LTD
  • EP3304412B1 patent drawingFigure 1~2
  • EP3304412B1 patent drawingFigure 3~4A
  • EP3304412B1 patent drawingFigure 4B~5A

AI summary

Provided are an electronic apparatus in which a normal operating system (OS) and a secure OS are installed and a method for controlling the electronic apparatus. The method for controlling the electronic apparatus includes searching for at least one external terminal in which a secure OS is installed, selecting a first terminal from among the at least one external terminal in which a secure OS is installed, in response to a first terminal being selected from the retrieved at least one external terminal, performing communication connection with the first terminal, searching for at least one terminal in which only a normal OS is installed, from among at least one external terminal that is capable of being communication-connected to the first terminal, and performing communication with a second terminal of the at least one terminal in which only the normal OS is installed, through the first terminal.