EMBEDDED SECURE ELEMENT
An embedded electronic system includes a volatile memory and a processor configured to execute a low-level operating system that manages allocation of areas of the volatile memory to a plurality of high-level operating systems. Each high-level operating system executes one or more applications. The system is configured so that execution data of one or a plurality of tasks of a first application are partly transferred, by the low-level operating system, from the volatile memory to a non-volatile memory when the execution of the task of the first application is interrupted by the execution of a task of a second application. The system is also configured so that the applications of any one of the high-level operating systems do not have access to the areas of the volatile memory allocated to the applications of all the other high-level operating systems.
1 . An embedded electronic system comprising:
a volatile memory;
a processor configured to execute a low-level operating system that manages allocation of areas of the volatile memory to a plurality of high-level operating systems, each high-level operating system executing one or more applications;
wherein the system is configured so that execution data of one or a plurality of tasks of a first application are partly transferred, by the low-level operating system, from the volatile memory to a non-volatile memory when the execution of the task of the first application is interrupted by the execution of a task of a second application; and
wherein the system is configured so that the applications of any one of the high-level operating systems do not have access to the areas of the volatile memory allocated to the applications of all the other high-level operating systems.
2 . The system according to claim 1 , wherein the non-volatile memory is external to the embedded electronic system.
3 . The system according to claim 2 , wherein the system is configured so that an execution code of an application is transferred to the volatile memory for execution.
4 . The system according to claim 1 , wherein the non-volatile memory is internal to the embedded electronic system.
5 . The system according to claim 4 , wherein the system is configured so that an execution code of an application remains in the non-volatile memory during the execution of a task.
6 . The system according to claim 1 , wherein the system is configured so that a non-volatile memory area allocated to a high-level operating system is seen by the high-level operating system as a volatile working memory.
7 . The system according to claim 1 , wherein the system is configured so that the high-level operating systems manage a virtual image of the volatile and non-volatile memories where the volatile and non-volatile memories appear to be one and the same.
8 . The system according to claim 1 , the system is configured so that a main task of an application is allocated a volatile memory area execution of the main task.
9 . The system according to claim 1 , wherein the system is configured so that a volatile memory area is allocated to the first application while the first application is not executed, the data of the first application being transferred to the non-volatile memory when the available volatile memory size is not sufficient for the execution of the second application.
10 . The system according to claim 1 , wherein the system is configured so that execution data of a plurality of applications are simultaneously present in the volatile memory.
11 . The system according to claim 1 , wherein the system is configured so that the low-level operating system executes a memory management function or unit that forbids access of data of one application to other applications.
12 . The system according to claim 1 , wherein the system is part of an embedded secure element.
13 . A method implemented in an embedded electronic system that includes a volatile memory, the system comprising:
managing, by a low-level operating system, an allocation of areas of the volatile memory to a plurality of high-level operating systems, each high-level operating system executing one or more applications, wherein the applications of each of the high-level operating systems do not have access to the areas of the volatile memory allocated to the applications of any other high-level operating system;
executing a task of a first application;
executing a task of a second application, execution of the task of the second application interrupting execution of the task of the first application; and
partly transferring, by the low-level operating system, execution data of the task of the first application from the volatile memory to an area of a non-volatile memory in response to the task of the first application being interrupted by the execution of the task of the second application.
14 . The method according to claim 13 , wherein the non-volatile memory is external to the embedded electronic system.
15 . The method according to claim 14 , further comprising transferring an execution code of an application from the non-volatile memory to the volatile memory for execution.
16 . The method according to claim 13 , wherein the non-volatile memory is internal to the embedded electronic system.
17 . The method according to claim 16 , wherein an execution code of an application remains in the non-volatile memory during the execution of a task.
18 . The method according to claim 13 , wherein a non-volatile memory area allocated to a high-level operating system is seen by the high-level operating system as a volatile working memory.
19 . The method according to claim 13 , wherein the high-level operating systems manage a virtual image of the volatile and non-volatile memories where the volatile and non-volatile memories appear as a single memory.
20 . The method according to claim 13 , wherein managing the allocation comprises allocating a main task of an application to a volatile memory area and executing the main task.
21 . The method according to claim 13 , wherein the allocating comprises allocating a volatile memory area to the first application while the first application is not executed, the method further comprising:
transferring data of the first application to the non-volatile memory if the available volatile memory size is not sufficient for execution of the second application; and
executing the second application.
22 . The method according to claim 13 , wherein execution data of a plurality of applications are simultaneously present in the volatile memory.
23 . The method according to claim 13 , further comprising executing a memory management function or unit by the low-level operating system to forbid access of the execution data of one application to other applications.