IP Library › Granted Patent US 12,627,469
Granted Patent B2
US 12,627,469 · App. 18/520,023 · Granted May 12, 2026

Electronic device for storing secure data and method for operating the same

Inventors: Jinha Hwang (Suwon-si, KR); Inho Kim (Suwon-si, KR); Dongsun Lee (Suwon-si, KR); Jaemin Ryu (Suwon-si, KR); Kyungim Jung (Suwon-si, KR)
Assignee: SAMSUNG ELECTRONICS CO., LTD.
H04L9/0637G06F21/602H04L9/0631
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,627,469
App. No.
18/520,023
Granted
May 12, 2026
Kind
B2
Abstract

An electronic device comprises: a first processor operating in a general non-secure environment; a second processor operating in a secure environment; a first memory allocated to the general non-secure environment; a second memory allocated to the secure environment; and a third memory shared in the general non-secure environment and the secure environment, wherein the second processor is configured to: encrypt at least a portion of secure data to generate an encrypted portion, the secure data generated by a trusted application executed in the secure environment, store the encrypted portion in the third memory, and store first information used to encrypt the at least a portion of the secure data and second information generated while encrypting the at least the portion of the secure data in the second memory, and wherein the first processor is configured to, store the encrypted portion stored in the third memory in the first memory.

Claims (67)

1 . An electronic device comprising:

a first processor operating in a general non-secure environment;

a second processor operating in a secure environment;

a first memory allocated to the general non-secure environment;

a second memory allocated to the secure environment; and

a third memory shared in the general non-secure environment and the secure environment,

wherein the second processor is configured to:

encrypt at least a portion of secure data to generate an encrypted portion, the secure data generated by a trusted application executed in the secure environment,

store the encrypted portion in the third memory, and

store first information used to encrypt the at least the portion of the secure data and second information generated while encrypting the at least the portion of the secure data in the second memory, and

request the secure data to the first processor as the trusted application is executed in the secure environment, and

wherein the first processor is configured to,

store, in the first memory, the encrypted portion stored in the third memory,

based on the request from the second processor, copy the encrypted portion in the first memory as a copied portion and store the copied portion in the third memory, and

wherein the second processor is configured to decrypt the copied portion in the third memory using the first information and the second information.

2 . The electronic device of claim 1 , wherein the second processor is configured to:

encrypt the at least the portion of the secure data on a per-block basis using a different anti-replay counter (ARC) value for each block;

encrypt an ARC table storing the ARC value for each block; and

encrypt a tag table storing tag values generated while encrypting the at least the portion of the secure data on the per-block basis.

3 . The electronic device of claim 2 ,

wherein the first processor is configured to store the encrypted at least the portion of the secure data, the encrypted ARC table, and the encrypted tag table in a file form in the first memory.

4 . The electronic device of claim 2 ,

wherein the first information is a master ARC, and the second information is a master tag.

5 . The electronic device of claim 1 ,

wherein the encrypted portion stored in the third memory includes (i) an encrypted ARC table storing anti-replay counter (ARC) values used while encrypting the at least the portion of the secure data on a per-block basis and (ii) an encrypted tag table storing tag values generated while encrypting the at least the portion of the secure data on the per-block basis, and

wherein the second processor is configured to:

decrypt the encrypted ARC table using the first information and the second information,

decrypt the encrypted tag table, and

decrypt the encrypted portion using the decrypted ARC table and the decrypted tag table.

6 . The electronic device of claim 1 ,

wherein the first processor is configured to read a file including the encrypted portion, the encrypted ARC table, and the encrypted tag table from the first memory, store the encrypted portion, the encrypted ARC table, and the encrypted tag table separately in the third memory.

7 . The electronic device of claim 2 ,

wherein the second processor is configured to encrypt the at least the portion of the secure data and the ARC table in an advanced encryption standard (AES)-galois/counter mode (GCM) scheme.

8 . The electronic device of claim 1 ,

wherein the second processor is configured to decrypt the encrypted portion in an advanced encryption standard (AES)-galois/counter mode (GCM) scheme.

9 . The electronic device of claim 2 ,

wherein the second processor is configured to encrypt the tag table in an advanced encryption standard (AES)-electronic code block (ECB) scheme.

10 . A method for operating an electronic device, the method comprising:

executing a trusted application in a secure environment and generating secure data by a first processor operating in the secure environment;

encrypting, by the first processor, at least a portion of the generated secure data to generate an encrypted portion and storing the encrypted portion in a first memory shared in the secure environment and a general non-secure environment;

storing, by the first processor, first information used to encrypt the at least the portion of the secure data and second information generated while encrypting the at least the portion of the secure data in a second memory allocated to the secure environment;

storing, by a second processor operating in the general non-secure environment, the encrypted portion stored in the first memory in a third memory allocated to the general non-secure environment;

requesting, by the second processor, the secure data to the first processor as the trusted application is executed in the secure environment;

based on the request from the second processor, copying, by the first processor, the encrypted portion in the first memory as a copied portion and store the copied portion in the third memory; and

decrypting, by the second processor, the copied portion in the third memory using the first information and the second information.

11 . The method of claim 10 , wherein the encrypting by the first processor includes:

encrypting the at least the portion of the secure data on a per-block basis using a different anti-replay counter (ARC) value for each block;

encrypting a tag table storing tag values generated while encrypting the at least the portion of the secure data on the per-block basis; and

encrypting an ARC table storing the ARC value for each block.

12 . The method of claim 11 , wherein the storing by the second processor in the third memory includes,

storing the encrypted portion, the encrypted ARC table, and the encrypted tag table in a file form in the first memory.

13 . The method of claim 11 ,

wherein the first information is a master ARC, and the second information is a master tag.

14 . The method of claim 10 ,

wherein the encrypted portion stored in the first memory includes (i) an encrypted ARC table storing anti-replay counter (ARC) values used while encrypting the at least the portion of the secure data on a per-block basis and (ii) an encrypted tag table storing tag values generated while encrypting the at least the portion of the secure data on the per-block basis, and

wherein the decrypting by the first processor includes:

decrypting the encrypted ARC table using the first information and the second information;

decrypting the tag table; and

decrypting the encrypted portion using the decrypted ARC table and the decrypted tag table.

15 . The method of claim 10 , further comprising,

reading, by the second processor, a file including the encrypted portion, the encrypted ARC table, and the encrypted tag table from the third memory, storing the encrypted portion, the encrypted ARC table, and the encrypted tag table separately in the first memory.

16 . The method of claim 11 ,

wherein the encrypting encrypts the at least the portion of the secure data and the ARC table in an advanced encryption standard (AES)-galois/counter mode (GCM) scheme.

17 . The method of claim 10 ,

wherein the decrypting decrypts the encrypted portion in an advanced encryption standard (AES)-galois/counter mode (GCM) scheme.

18 . The method of claim 11 ,

wherein the encrypting the tag table encrypts the tag table in an advanced encryption standard (AES)-electronic code block (ECB) scheme.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 27, 2023
From: HWANG, JINHA; LEE, DONGSUN; RYU, JAEMIN; JUNG, KYUNGIM
To: SAMSUNG ELECTRONICS CO., LTD.
Reel/Frame 065670/0715 →
Priority Claims (1)
KR 10-2022-0160173 · Nov 25, 2022 · national
Continuity (2)
Continuation PCTKR2023018740 · Nov 21, 2023
Related Publication 20240178990A1 · May 30, 2024
References Cited (23)
US 8332653B2 · Buer · 2012 [cited by examiner]
US 9753868B2 · Yamada · 2017 [cited by examiner]
US 10700865B1 · Hendrick et al. · 2020 [cited by applicant]
US 20060090084A1 · Buer · 2006 [cited by applicant]
US 20080320263A1 · Nemiroff et al. · 2008 [cited by applicant]
US 20130042295A1 · Kelly et al. · 2013 [cited by applicant]
US 20140189370A1 · Jang et al. · 2014 [cited by applicant]
US 20140223197A1 · Gueron et al. · 2014 [cited by applicant]
US 20170048714A1 · Attfield et al. · 2017 [cited by applicant]
US 20170317990A1 · Kim et al. · 2017 [cited by applicant]
US 20190050347A1 · Bolotov · 2019 [cited by examiner]
US 20200304295A1 · Paudyal et al. · 2020 [cited by applicant]
US 20200358620A1 · Kim et al. · 2020 [cited by applicant]
US 20210357514A1 · Agarwal et al. · 2021 [cited by applicant]
US 20220006653A1 · Ghetie · 2022 [cited by applicant]
US 20220156411A1 · Benoit et al. · 2022 [cited by applicant]
CN 113553204A · 2021 [cited by applicant]
KR 1020160141462A · 2016 [cited by applicant]
KR 1020170124360A · 2017 [cited by applicant]
KR 1020200129776A · 2020 [cited by applicant]
KR 1020220062866A · 2022 [cited by applicant]
International Search Report and Written Opinion (PCT/ISA/210 and PCT/ISA/237) dated Feb. 26, 2024, issued by International Searching Authority for International Application No. PCT/KR2023/018740. [cited by applicant]
Extended European Search Report dated Oct. 14, 2025, issued by the European Patent Office in European Application No. 23894985.3. [cited by applicant]