IP Library › Granted Patent US 12,585,756
Granted Patent B2
US 12,585,756 · App. 18/261,461 · Granted Mar 24, 2026

Apparatus for reinforcing security of mobile trusted execution environment

Inventors: Jinsoo Jang (Daejeon, KR); Brent Byunghoon Kang (Daejeon, KR)
Assignees: The Industry & Academic Cooperation Chungnam National University; Korea Advanced Institute of Science and Technology
G06F21/53G06F21/54G06F21/78G06F21/121
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,585,756
App. No.
18/261,461
Granted
Mar 24, 2026
Kind
B2
Abstract

The present invention relates to an apparatus for reinforcing security of a mobile trusted execution environment, and relates to an apparatus for reinforcing security of a mobile trusted execution environment for constructing a general-purpose trusted execution environment. According to an embodiment of the present invention, a technology available for a general purpose in a mobile device operating on the basis of an ARM architecture has effects of configuring a trusted execution environment for guaranteeing safe execution of an application without depending on an existing commercial security technology, and of configuring a mobile trusted execution environment by using a write area execution prevention function and a debugging watchpoint, which are general-purpose hardware functions.

Claims (15)

1 . An apparatus for reinforcing security of a trusted execution environment in a mobile device, the apparatus comprising:

a hypervisor configured to separate regions into a privileged region and a non-privileged region;

a region switch configured to perform switching between the privileged region and the non-privileged region by controlling a watchpoint and memory execution area write protection; and

a mode switch configured to perform switching between OS kernel mode and hypervisor mode by trapping by branch based on an exception occurrence privilege in order to protect vector integrity.

2 . The apparatus of claim 1 , wherein the privileged region protects a writable object such as a page table as privileged data, and separates an exception vector and privileged region code based on a granularity of page.

3 . The apparatus of claim 1 , wherein the non-privileged region emulates, for a monitored OS kernel, updates of a page table and a system register.

4 . The apparatus of claim 1 , wherein the region switch unit checks an OS request type in an exception vector, and performs the switching between the regions through a secure gate that configures the watchpoint and a memory execution area write protection flag in order to isolate the privileged region.

5 . The apparatus of claim 1 , wherein the region switch performs switching to the privileged region by using a hypercall captured by an exception vector upon receiving a request for updating a hypervisor page table while executing the non-privileged region.

6 . The apparatus of claim 1 , wherein, in the mode switch, a hypercall triggered in an OS kernel is trapped by branch due to an exception with a lower privilege, and

all exceptions that occur in hypervisor mode execution are trapped by branch for a current privilege.

7 . A method for reinforcing security of a trusted execution environment in a mobile device, the method comprising:

invoking, from an OS kernel, a hypercall ported for OS kernel monitoring;

in response to the invoking, trapping, by an exception vector in a privileged region, a hypercall exception;

checking an OS request type to dispatch a handler in a non-privileged region and causing a region switch to occur from the privileged region to the non-privileged region; and

performing switching between the privileged region and the non-privileged region through a secure gate that configures a watchpoint and a memory execution area write protection flag in order to isolate the privileged region.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 13, 2023
From: JANG, JINSOO; KANG, BRENT BYUNGHOON
To: THE INDUSTRY & ACADEMIC COOPERATION IN CHUNGNAM NATIONAL UNIVERSITY; KOREA ADVANCED INSTITUTE OF SCIENCE AND TECHNOLOGY
Reel/Frame 064274/0018 →
Priority Claims (1)
KR 10-2021-0005601 · Jan 14, 2021 · national
Continuity (1)
Related Publication 20240078307A1 · Mar 7, 2024
References Cited (39)
US 7711914B2 · Thelen · 2010 [cited by examiner]
US 8055828B2 · Conti · 2011 [cited by examiner]
US 10108800B1 · Surdu · 2018 [cited by examiner]
US 10255090B2 · Tuch · 2019 [cited by examiner]
US 10467410B2 · Lee et al. · 2019 [cited by applicant]
US 20110047542A1 · Dang et al. · 2011 [cited by applicant]
US 20110093723A1 · Brown · 2011 [cited by examiner]
US 20110093750A1 · Williams et al. · 2011 [cited by applicant]
US 20120180050A1 · Manczak et al. · 2012 [cited by applicant]
US 20140372719A1 · Lange · 2014 [cited by examiner]
US 20150052325A1 · Persson · 2015 [cited by examiner]
US 20150089213A1 · Isozaki · 2015 [cited by examiner]
US 20150089246A1 · Kanai · 2015 [cited by examiner]
US 20150220455A1 · Chen · 2015 [cited by examiner]
US 20150271184A1 · Josang · 2015 [cited by examiner]
US 20160073258A1 · Fukuoka · 2016 [cited by examiner]
US 20160125201A1 · Villatel · 2016 [cited by examiner]
US 20160195919A1 · Bühler · 2016 [cited by examiner]
US 20160299851A1 · Mattson, Jr. · 2016 [cited by examiner]
US 20160378693A1 · Sasaki · 2016 [cited by examiner]
US 20170060637A1 · Persson · 2017 [cited by examiner]
US 20180239896A1 · Kato · 2018 [cited by examiner]
US 20180248847A1 · Guri · 2018 [cited by examiner]
US 20190095625A1 · Surdu · 2019 [cited by examiner]
US 20200012820A1 · Nara · 2020 [cited by examiner]
US 20200125772A1 · Volos · 2020 [cited by examiner]
US 20210026950A1 · Ionescu · 2021 [cited by examiner]
US 20220100673A1 · Craske · 2022 [cited by examiner]
US 20220405430A1 · Huh · 2022 [cited by examiner]
US 20230281135A1 · Zhang · 2023 [cited by examiner]
KR 101324693B1 · 2013 [cited by applicant]
KR 101816866B1 · 2018 [cited by applicant]
Jinsoo Jang et al., “Revisiting the ARM Dbug Facility for OS Kernel Security”, DAC '19, Jun. 2-6, 2019, Las Vegas, USA (Year: 2019). [cited by examiner]
Jinsoo Jang et al., ‘SelMon: Reinforcing Mobile Device Security with Self-protected Trust Anchor’, In: The 18th Annual International Conference on Mobile Systems, Applications, and Services (MobiSys'20), pp. 135-147, Ju… [cited by applicant]
Ahmed M. Azab et al., “SKEE: A lightweight Secure Kernel-level Execution Environment for ARM”, In 23rd Annual Network and Distributed System Security Symposium, NDSS 2016, San Diego, California, USA, Feb. 21-24, 2016, p… [cited by applicant]
Yeongpil Cho et al., “Dynamic Virtual Address Range Adjustment for Intra-Level Privilege Separation on ARM”, In 24th Annual Network and Distributed System Security Symposium, NDSS 2017, San Diego, California, USA, Feb. … [cited by applicant]
Nathan Dautenhahn et al., “Nested kernel: An operating system architecture for intrakernel privilege separation”, In ACM SIGPLAN Notices, vol. 50. ACM, pp. 191-206. [cited by applicant]
Jinsoo Jang et al. “Revisiting the ARM Debug Facility for OS Kernel Security”, DAC '19, Jun. 2-6, 2019, Las Vegas, NV, USA. [cited by applicant]
Yutao Liu et al., “Thwarting Memory Disclosure with Efficient Hypervisor-enforced Intra-domain Isolation”, CCS'15, Oct. 12-16, 2015, Denver, Colorado, USA. [cited by applicant]