首页> 外国专利> Trusted execution environment access control rules derivation

Trusted execution environment access control rules derivation

机译:可信执行环境访问控制规则的推导

摘要

An access control method for Trusted Applications (20) characterised by inferring an access control rule (28) for a Trusted Application (20) from a rule (26) applied in a Rich OS (12) to a Rich OS application (16). The access control method is suitably implemented in a system comprising a Rich Execution Environment (12) and a Trusted Execution Environment (14), and whereby for each facility for which access control rules (24, 26) is defined in the Rich OS (12), a corresponding set of access control rules (28, 29) is defined in the TEE (14). An apparatus is also disclosed, which comprises a TEE (12) capable, in use, of running Trusted Applications (20) and a Rich OS (12) capable, in use, of running Rich applications (16), a secured interface between Rich OS (12) and the TEE (14), characterised by each Rich application (16) having access rights to facilities defined by an access control protocol (22) comprising access control rules (24) for the Rich OS application (16); and by the TEE (14) comprising a Session Access Control module (29) adapted in use, to block or allow sessions (18) from the Rich application (16) to a Trusted Application (20), wherein the session access control module (29) is configured to accept or deny session requests (18) depending on the context of the request (18).
机译:一种用于受信任的应用程序(20)的访问控制方法,其特征在于,从在Rich OS(12)中应用到Rich OS应用程序(16)的规则(26)推断受信任的应用程序(20)的访问控制规则(28)。该访问控制方法适当地在包括富执行环境(12)和受信任执行环境(14)的系统中实现,从而在富操作系统(12)中为每个设施定义了访问控制规则(24、26)。 ),在TEE(14)中定义了一组相应的访问控制规则(28、29)。还公开了一种设备,该设备包括能够使用中运行受信任的应用程序(20)的TEE(12)和能够使用中运行富应用程序(16)的富操作系统(12),富操作系统之间的安全接口。 OS(12)和TEE(14),其特征在于,每个富应用程序(16)具有对由访问控制协议(22)所定义的设施的访问权,访问控制协议(22)包括用于富OS应用程序(16)的访问控制规则(24); TEE(14)包括会话使用控制模块(29),该会话使用控制模块在使用中适合于阻止或允许从Rich应用程序(16)到受信任的应用程序(20)的会话(18),其中会话访问控制模块( 29)被配置为根据请求(18)的上下文接受或拒绝会话请求(18)。

著录项

  • 公开/公告号EP2746981A1

    专利类型

  • 公开/公告日2014-06-25

    原文格式PDF

  • 申请/专利权人 ST-ERICSSON SA;

    申请/专利号EP20130368034

  • 发明设计人 SIBERT HERVÉ;

    申请日2013-09-20

  • 分类号G06F21/53;G06F21/74;

  • 国家 EP

  • 入库时间 2022-08-21 15:45:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号