Secure Processor Core OS Verification for Mobile Chipsets

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The secure processor in mobile radio-enabled end devices with integrated subscriber identity modules faces memory constraints due to high security costs, necessitating external non-volatile memory for storing subscription profiles, and there is a need to verify the trustworthiness of the core operating system to protect the application operating system from untrustworthy core OS components.

Innovation Solution

A chipset with a secure processor that includes a core OS verification apparatus to ensure the integrity of the core OS, utilizing a bootloader to load and decrypt the core OS from external non-volatile memory, and storing the application OS in internal secure working memory to prevent external influence, allowing the application OS to verify the core OS integrity and prevent execution if untrustworthy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If the core OS is stored in external non-volatile memory to reduce secure processor memory costs, then memory cost is reduced, but security risk increases due to potential tampering

Engineering Contradiction:
Improvememory spaceVSAvoidsecurity
Core Design Contradiction:
Quantity of substanceVSReliability

Solution Approach 1:

The patent applies preliminary action by implementing a verification mechanism that checks the integrity of the core OS before it is executed. The application OS verifies the core OS using cryptographic signatures or hash values stored in secure memory, preventing tampered versions from executing. This advance verification resolves the contradiction by allowing external storage while maintaining security through pre-execution validation.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary verification layer between the external storage and the execution environment. The application OS acts as a mediator that validates the core OS integrity before allowing it to run, and the bootloader serves as an intermediary that securely loads and verifies system components. This intermediary mechanism enables external storage while preventing security risks from tampered software.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If the operating system is divided into core OS and application OS, then system flexibility and security management are improved, but system complexity increases

Engineering Contradiction:
Improvesystem flexibilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent applies segmentation by dividing the operating system into two distinct components: core OS (responsible for hardware control and basic functions) and application OS (handling higher-level applications and user interfaces). This segmentation allows independent development, verification, and updating of each component, improving flexibility while managing complexity through clear separation of concerns and dedicated verification mechanisms for each segment.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11310622B2Integrated subscriber identity module having a core OS and an application OS
Publication Date: 2022.04.19 GIESECKE & DEVRIENT EPAYMENTS GMBH
  • US11310622B2 patent drawing
  • US11310622B2 patent drawing

AI summary

A chipset for a mobile radio-enabled end device is provided in which an integrated subscriber identity module is arranged in a secure processor of the chipset, and in which an operating system of the secure processor is arranged or arrangeable. The operating system comprises a core OS and an application OS, wherein the application OS comprises a core OS verification apparatus which is arranged to verify the integrity of the core OS upon it being put into operation and to continue the putting into operation at most only in the case of a successful verification of the core OS and to cause a fault measure and/or to interrupt or terminate the putting into operation in the case of an unsuccessful verification.