Secure Switch Disconnects Processor From Memory

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The processor and secure memory in electronic devices are electrically connected for extended periods, making personal information vulnerable to theft by malicious applications due to vulnerabilities in the operating system.

Innovation Solution

An electronic device with a secure switch that electrically disconnects the processor from the memory in a first state and connects them in a second state, allowing encryption information to be provided to a secure application through a secure operating system, minimizing the connection time and enhancing security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If the processor and secure memory are electrically connected for extended periods to enable secure application access, then the secure application can access encryption information, but the personal information becomes vulnerable to theft by malicious applications

Engineering Contradiction:
ImprovesecurityVSAvoidvulnerability to malicious applications
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a dynamic switching mechanism that alternates the electrical connection state between the processor and secure memory. The switch transitions between connected and disconnected states based on operational requirements, making the connection temporary rather than permanent. This dynamic approach allows the system to maintain security by minimizing exposure time while still enabling secure application access when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system employs periodic connection and disconnection cycles between the processor and secure memory. The switch is activated only during specific time windows when secure application access is required, then deactivated to restore security. This periodic action pattern ensures that the vulnerable connected state exists only briefly and periodically, rather than continuously, thereby reducing the window of opportunity for malicious attacks.

Inventive Principle:
Principle #19Periodic action

2Reliability

If the switch is activated frequently to minimize connection time, then security is enhanced, but the operational efficiency for secure applications may be reduced

Engineering Contradiction:
ImprovesecurityVSAvoidoperational efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary actions by pre-establishing the switch activation protocol and preparing the secure memory access pathway before actual data operations begin. The switch is activated in advance of the specific data access operation, allowing the secure application to proceed without interruption once connected. This preliminary activation reduces the total time the switch needs to remain active, thereby minimizing security exposure while maintaining operational efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP3770790B1Electronic device and method for protecting personal information using secure switch
Publication Date: 2023.05.10 SAMSUNG ELECTRONICS CO LTD
  • EP3770790B1 patent drawingFigure 1
  • EP3770790B1 patent drawingFigure 2
  • EP3770790B1 patent drawingFigure 3

AI summary

An electronic device according to an embodiment includes: a memory configured to store encryption information, a processor, and a switch configured to electrically disconnect the processor from the memory in a first state and to electrically connect the processor and the memory in a second state. The processor is configured to receive a user input for switching the switch from the first state to the second state, provide the encryption information stored in the memory to a secure application executing only in a second execution environment through a secure operating system of the second execution environment, when the switch is switched from the first state to the second state to generate an electrical path between the memory and the processor, acquire signature information for a transaction based on the encryption information, and provide the signature information acquired based on the encryption information to a signature request application.