Method of operating data security and electronic device supporting the same

US9432195B2 · US · B2

Patent metadata
FieldValue
Publication numberUS-9432195-B2
Application numberUS-201414455268-A
CountryUS
Kind codeB2
Filing dateAug 8, 2014
Priority dateAug 8, 2013
Publication dateAug 30, 2016
Grant dateAug 30, 2016

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method of operating data security and an electronic device supporting the same are provided. The method includes executing a general Application (App) based on a non-trusted execution module; executing a first trusted App related to the execution of the general App based on a trusted execution module; generating a message by encrypting data generated in the first trusted App; transmitting the encrypted message to the general App; and transmitting the encrypted message to a second trusted App related to the execution of the general App and executed based on the trusted execution module.

First claim

Opening claim text (preview).

What is claimed is: 1. A method of operating data security, the method comprising: executing a general Application (App) based on a non-trusted execution controller; executing a first trusted App related to the execution of the general App based on a trusted execution controller; generating an encrypted message by encrypting data generated in the first trusted App using an encryption algorithm; transmitting the encrypted message to the general App; and transmitting the encrypted message to a second trusted App related to the execution of the general App and executed based on the trusted execution controller, wherein the encrypted message includes the data, a unique IDentification (ID) of the second trusted App, a unique ID of the first trusted App, and key selector data. 2. The method of claim 1 , further comprising: decrypting the encrypted message transmitted to the second trusted App; and consuming data included in the decrypted message in the second trusted App. 3. The method of claim 1 , wherein generating the message comprises: collecting the unique ID of the second trusted App by the first trusted App; and collecting the key selector data. 4. The method of claim 3 , wherein collecting the key selector data comprises selecting at least one of a permanent encryption key, a temporary encryption key, and a one time key. 5. The method of claim 4 , wherein collecting the key selector data comprises selecting the at least one of the permanent encryption key, the temporary encryption key, and the one time key according to a security processing level. 6. The method of claim 1 , wherein encrypting the message further comprises encrypting the message by adding a random nonce to the message. 7. The method of claim 1 , wherein generating the message comprises generating a table entry including the unique ID of the first trusted App, the unique ID of the second trusted App, an encryption key based on the key selector data, and a random nonce. 8. The method of claim 7 , further comprising: when the encrypted message includes a one time key, identifying whether the unique ID of the second trusted App and the random nonce included in the message match the table entry; when the table entry does not exist, outputting an error; and when the table entry exists, decrypting the message by using an individual temporary encryption key collected from the table entry. 9. The method of claim 1 , further comprising: collecting the unique ID of the second trusted App by the general App; and transmitting the unique ID of the second trusted App to the first trusted App by the general App. 10. An electronic device supporting a data security operation, the electronic device comprising: a non-trusted execution controller configured to support an execution of a general App; and a trusted execution controller configured to support executions of a first trusted App and a second trusted App related to the execution of the general App, to generate an encrypted message by encrypting data generated in the first trusted App using an encryption algorithm, and to transmit the encrypted message to the second trusted App through the general App, wherein the encrypted message includes the data, a unique IDentification (ID) of the second trusted App, a unique ID of the first trusted App, and key selector data. 11. The electronic device of claim 10 , wherein the trusted execution controller is further configured to decrypt the encrypted message transmitted to the second trusted App, and to consume data included in the decrypted message in the second trusted App. 12. The electronic device of claim 10 , wherein the trusted execution controller is further configured to encrypt the message by adding a random nonce to the message. 13. The electronic device of claim 10 , wherein the key selector data is at least one of a permanent encryption key, a temporary encryption key, and a one time key. 14. The electronic device of claim 13 , wherein the trusted execution controller is further configured to select at least one of the permanent encryption key, the temporary encryption key, and the one time key according to a security processing level. 15. The electronic device of claim 10 , wherein the trusted execution controller is further configured to generate a table entry including the unique ID of the first trusted App, the unique ID of the second trusted App, an encryption key based on the key selector data, and a random nonce. 16. The electronic device of claim 15 , wherein the trusted execution controller is further configured to identify whether the unique ID of the second trusted App and the random nonce included in the message match the table entry when the encrypted message includes a one time key, to output an error when the table entry does not exist, and to decrypt the message by using an individual temporary encryption key collected from the table entry when the table entry exists. 17. The electronic device of claim 10 , wherein the general App collects the unique ID of the second trusted App and transmits the unique ID of the second trusted App to the first trusted App.

Assignees

Inventors

Classifications

  • Program loading or initiating (bootstrapping G06F9/4401; security arrangements for program loading or initiating G06F21/57) · CPC title

  • G06F21/60Primary

    Protecting data · CPC title

  • operating in dual or compartmented mode, i.e. at least one secure mode · CPC title

  • based on the identity of the terminal or configuration, e.g. MAC address, hardware or software configuration or device fingerprint · CPC title

  • by securing the transmission between two devices or processes · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US9432195B2 cover?
A method of operating data security and an electronic device supporting the same are provided. The method includes executing a general Application (App) based on a non-trusted execution module; executing a first trusted App related to the execution of the general App based on a trusted execution module; generating a message by encrypting data generated in the first trusted App; transmitting the…
Who is the assignee on this patent?
Samsung Electronics Co Ltd
What technology area does this patent fall under?
Primary CPC classification G06F21/60. Mapped technology areas include Physics.
When was this patent published?
Publication date Tue Aug 30 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (B2). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 8 related publications on this page (citations in our corpus or others sharing the same primary CPC).