IP Library › Granted Patent US 11,947,709
Granted Patent B2
US 11,947,709 · App. 17/006,229 · Granted Apr 2, 2024

Electronic device for controlling access to device resource and operation method thereof

Inventors: Hyungseok Yu (Gyeonggi-do, KR); Taeho Kim (Gyeonggi-do, KR); Kwangsik Choi (Gyeonggi-do, KR); Seyoung Choi (Gyeonggi-do, KR)
Assignee: Samsung Electronics Co., Ltd
G06F21/629G06F9/45558G06F21/575G06F21/74G06F2009/45587G06F2221/2141
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,947,709
App. No.
17/006,229
Granted
Apr 2, 2024
Kind
B2
Abstract

An electronic device for controlling access to a device resource, and an operation method thereof, are disclosed. The electronic device may include a memory; and a processor configured to execute at least one operating system executed in a first region allowing an operation based on a first authority; execute at least one application executed in a second region allowing an operation based on a second authority; and in response to detection of access to at least one device resource by the at least one application, determine authority of access to the at least one device resource by using an authority determination module executed in a third region allowing an operation based on a third authority.

Claims (35)

1. An electronic device comprising:

a memory; and

a processor configured to:

execute at least one operating system executed in a first region of the processor allowing an operation based on a first authority,

execute at least one application executed in a second region of the processor allowing an operation based on a second authority,

in response to detection of access to at least one device resource by the at least one application, configure authority of access to the at least one device resource by using an authority determination module executed in a third region of the processor allowing an operation based on a third authority,

store an authority policy defining a device resource restricted from being accessed by the at least one application, in the third region allowing an operation based on the third authority, and

provide the authority policy through a secure region of the processor to a non-secure region of the processor allowing an operation based on the third authority, wherein the third region allowing an operation based on the third authority comprises a region in which at least one of a hypervisor which is a non-secure region, or a secure exception level, is executed.

2. The electronic device of claim 1 , wherein the third authority comprises an authority higher than the first authority.

3. The electronic device of claim 1 , wherein the processor is further configured to obtain the authority policy in the electronic device or from an external device.

4. The electronic device of claim 1 , wherein the processor is further configured to provide the authority policy through a non-secure region of the processor to a non-secure region of the processor allowing an operation based on the third authority.

5. The electronic device of claim 1 , wherein the processor is further configured to provide the authority policy through a secure region of the processor to a secure region of the processor allowing an operation based on the third authority.

6. The electronic device of claim 1 , wherein the processor is further configured to:

determine access authority of the at least one application, based on the configured authority of access to the at least one device resource; and

if the configured authority is determined to be an authority by which access to the at least one device resource is restricted, provide information indicating restriction of access to the at least one device resource.

7. The electronic device of claim 1 , wherein the authority determination module comprises a hypervisor.

8. An operation method of an electronic device, the method comprising:

executing at least one operating system executed in a first region of a processor allowing an operation based on a first authority;

executing at least one application executed in a second region of the processor allowing an operation based on a second authority; and

in response to detection of access to at least one device resource by the at least one application, configuring authority of access to the at least one device resource by using an authority determination module executed in a third region of the processor allowing an operation based on a third authority,

storing an authority policy defining a device resource restricted from being accessed by the at least one application, in the third region allowing an operation based on the third authority, and

providing the authority policy through a secure region of the processor to a non-secure region of the processor allowing an operation based on the third authority, wherein the third region allowing an operation based on the third authority comprises a region in which at least one of a hypervisor which is a non-secure region, or a secure exception level, is executed.

9. The method of claim 8 , wherein the third authority comprises an authority higher than the first authority.

10. The method of claim 8 , further comprising:

obtaining the authority policy in the electronic device or from an external device.

11. The method of claim 10 , wherein obtaining the authority policy comprises:

obtaining a designated first authority policy during a boot-on operation; and

after the boot-on operation is complete, obtaining a second authority policy.

12. The method of claim 8 , further comprising:

providing the authority policy through a non-secure region of the processor to a non-secure region of the processor allowing an operation based on the third authority.

13. The method of claim 8 , further comprising:

providing the authority policy through a secure region of the processor to a secure region of the processor allowing an operation based on the third authority.

14. The method of claim 8 , further comprising:

determining access authority of the at least one application, based on the configured authority of access to the at least one device resource; and

if the configured authority is determined to be an authority by which access to the at least one device resource is restricted, providing information indicating restriction of access to the at least one device resource.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 3, 2020
From: YU, HYUNGSEOK; KIM, TAEHO; CHOI, KWANGSIK; CHOI, SEYOUNG
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 053683/0564 →
Priority Claims (1)
KR 10-2019-0106729 · Aug 29, 2019 · national
Continuity (1)
Related Publication 20210064770A1 · Mar 4, 2021