首页> 外国专利> TRUSTZONE-BASED SECURITY ISOLATION METHOD FOR SHARED LIBRARY AND SYSTEM THEREOF

TRUSTZONE-BASED SECURITY ISOLATION METHOD FOR SHARED LIBRARY AND SYSTEM THEREOF

机译:基于信任区的共享库安全隔离方法及系统

摘要

The present invention provides a TrustZone-based security isolation system for shared library, the system at least comprising: a sandbox creator, a library controller, and an interceptor, the sandbox creator, in a normal world, dynamically creating a sandbox isolated from a Rich OS, the interceptor, intercepting corresponding system-calling information and/or Android framework APIs by means of inter-process stack inspection, the library controller, performing analysis based on the intercepted system-calling information and/or Android framework APIs, redirecting a library function to the sandbox, and switching calling states of the library function in the sandbox as well as setting up a library authority. The present invention has good versatility, low cost and high security. It realizes isolation of the library without increasing the trusted bases in the Secure World of the TrustZone, effectively reducing the risk of being attacked.
机译:本发明提供了一种用于共享库的基于TrustZone的安全隔离系统,该系统至少包括:沙箱创建者,库控制器和拦截器,在通常情况下,沙箱创建者动态创建与Rich隔离的沙箱。 OS,拦截器,通过进程间堆栈检查拦截相应的系统调用信息和/或Android框架API,库控制器,基于拦截的系统调用信息和/或Android框架API进行分析,重定向库函数到沙箱中,以及在沙箱中切换库函数的调用状态以及设置库权限。本发明通用性好,成本低,安全性高。它无需增加TrustZone的“安全世界”中的受信基础即可实现库的隔离,从而有效地降低了遭受攻击的风险。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号