Invention Grant
- Patent Title: TrustZone-based security isolation method for shared library and system thereof
-
Application No.: US16109870Application Date: 2018-08-23
-
Publication No.: US10754953B2Publication Date: 2020-08-25
- Inventor: Hai Jin , Weiqi Dai , Jun Deng , Deqing Zou
- Applicant: HUAZHONG UNIVERSITY OF SCIENCE AND TECHNOLOGY
- Applicant Address: CN Wuhan
- Assignee: Huazhong University of Science and Technology
- Current Assignee: Huazhong University of Science and Technology
- Current Assignee Address: CN Wuhan
- Agency: Morris, Manning & Martin, LLP
- Agent Michael X. Ye
- Priority: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@a922a77
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F9/54 ; G06F21/44 ; G06F21/53 ; G06F21/62 ; H04L29/06

Abstract:
The present invention provides a TrustZone-based security isolation system for shared library, the system at least comprising: a sandbox creator, a library controller, and an interceptor, the sandbox creator, in a normal world, dynamically creating a sandbox isolated from a Rich OS, the interceptor, intercepting corresponding system-calling information and/or Android framework APIs by means of inter-process stack inspection, the library controller, performing analysis based on the intercepted system-calling information and/or Android framework APIs, redirecting a library function to the sandbox, and switching calling states of the library function in the sandbox as well as setting up a library authority. The present invention has good versatility, low cost and high security. It realizes isolation of the library without increasing the trusted bases in the Secure World of the TrustZone, effectively reducing the risk of being attacked.
Public/Granted literature
- US20190294798A1 TRUSTZONE-BASED SECURITY ISOLATION METHOD FOR SHARED LIBRARY AND SYSTEM THEREOF Public/Granted day:2019-09-26
Information query