Trusted application operation method, information processing and memory allocation method and device

By compiling the program module of the application in the TEE operating system as a dynamic library and delaying loading when a service request is received, the problem of waste of TEE memory space and increased pressure is solved, and memory utilization efficiency and security are improved.

CN112528288BActive Publication Date: 2025-06-06HUAWEI TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN201910817794.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2019-08-30
Publication Date
2025-06-06
Estimated Expiration
2039-08-30

AI Technical Summary

Technical Problem

With the increase in applications in Trusted Execution Environment (TEE), TEE's memory space management faces problems of waste and increased pressure, especially when the application does not receive a service request, the loaded program module occupies memory.

Method used

A method is proposed, in the TEE operating system, the program modules supporting the target services are compiled into dynamic libraries, and the target TA's memory space is loaded only when the target TA receives the service request.

Benefits of technology

By delaying loading of dynamic libraries, the memory space of TA is reduced, the secure memory utilization efficiency of TEE is improved, and the security of TEE is enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN112528288B_ABST
    Figure CN112528288B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a method for running a trusted application, an information processing method, a memory allocation method and a device, which are applied to a computer system deployed with a trusted execution environment TEE and a rich execution environment REE, a REE operating system deployed on the REE, a TEE operating system deployed on the TEE, and one or more trusted applications TA running on the TEE operating system. Taking one of the target TAs as an example, the target TA can provide a target service, the TEE operating system can start the target TA, and then the target TA can respond to the target service's running request and send a load request for a target dynamic library supporting the target service to the TEE operating system, and the TEE operating system can respond to the load request and load the target dynamic library into the memory space of the target TA. In this way, before the target TA runs the target service, there is no need to load the program module used to support the target service into the memory space of the TA, which can reduce the waste of the TA's memory space.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to a method for running a trusted application, an information processing method, a memory allocation method and a device. Background Art

[0002] With the development of mobile Internet, the application of smart terminal devices is becoming more and more extensive. In order to provide rich functions and scalable properties of smart terminal devices, and protect user privacy and information security, terminal devices are built on rich execution environments (REE) and trusted execution environments (TEE) that provide open operating environments. REE is also called a general operating environment, which mainly includes a rich operating system (Rich OS) running on a general-purpose processor and a client application (CA) running on Rich OS. TEE is an independent operating environment running outside REE, mainly including a trusted operating system (Trusted OS) and a trusted application (TA) running on Trusted OS. TEE is isolated from REE. REE cannot directly access the hardware and software resources of TEE, such as TEE memory. The two can only interact through authorized application programming interfaces (APIs). Therefore, TEE can resist software attacks on the REE side.

[0003] Since TA needs to run part of the code in the code segment of TA's target file and access part of the data in the data segment when implementing a certain function, the program segment (including code and data) corresponding to the function can be logically called the program module corresponding to the function. In the prior art, when the TEE operating system starts TA, it loads the program modules corresponding to each function of TA into TA's memory space. When TA receives a request to run a service, it can use the various program modules that support the service to run the service.

[0004] As the number of TAs deployed in TEE increases, the functions of TAs continue to increase, and the memory space allocated to TAs by the TEE operating system becomes larger and larger, the secure memory of TEE, as a limited security resource of TEE, faces increasingly severe challenges. In the existing TA operation method, TA may not receive a request to run a service, while all program modules supporting the service have been loaded into TA's memory space, resulting in a waste of TA's memory space, further increasing the pressure on TEE's secure memory. Summary of the invention

[0005] The embodiments of the present application provide a method for running a trusted application, an information processing method, a memory allocation method and a device for saving the memory space of the TA.

[0006] In order to protect user privacy and information security, computer systems deployed with rich execution environments (REE) and trusted execution environments (TEE) are becoming more and more widely used. A rich operating system (Rich OS), or REE operating system, is deployed in the REE of the computer system. One or more CAs are generally deployed in the REE operating system. A trusted operating system (Trusted OS), or TEE operating system, is deployed in the TEE of the computer system. One or more TAs are generally deployed on the TEE operating system, and the TA can generally provide one or more services.

[0007] Taking a TA (referred to as the target TA) deployed in the TEE operating system and a service (referred to as the target service) provided by the target TA as an example, the following describes the operation method of the TA provided in the first aspect of the embodiment of the present application. It should be noted that the present application does not limit all TAs deployed in the TEE operating system to operate according to the method provided in the present application.

[0008] The prerequisite for the target TA to run the target service is that the TEE operating system starts the target TA. More specifically, the TEE operating system starts the main process of the target TA, and the program module used to support the target service (or the program module required for the target TA to run the target service) is loaded into the memory space of the target TA.

[0009] Exemplarily, in the process of starting the target TA, the TEE operating system can load the target file of the target TA into the memory space of the target TA, and create a process of the target TA to execute the target file. The type of the target file can be a shared target file (such as a .so file) or an executable file (such as a .os file) or other types of files. In the embodiment of the present application, the specific type of the target file is not limited. Exemplarily, in the embodiment of the present application, taking the target file as an executable file as an example, the target file saves binary code that can be directly loaded into the memory for execution. Dynamic libraries (generally .so files) and executable files (generally .os files) are generally executable and linkable format (executable and linkable format, ELF) format files.

[0010] In the embodiment of the present application, when compiling the target file of the target TA, part or all of the program modules supporting the target service are not copied into the target file, but these part of the program modules are separately compiled into a shared target file, such as a dynamic library. For the convenience of description, the dynamic library compiled by these part of the program modules is called the target dynamic library. The target dynamic library includes the code of the function, or includes the definition of symbols (such as variables or function calls, etc.), and the reference of the symbol in the target dynamic library (such as the identification of the referenced object) and other registration information (such as symbol table and relocation information, etc.) are added to the target file. The TEE operating system can start the target TA in response to the creation request of the target TA; after the target TA is started, it can receive the operation request of the target service sent by the CA or other TA, or spontaneously start (or generate) the operation request of the target service, and then, in response to the operation request, the target TA can send a load request to the TEE operating system, and the load request is used to instruct the TEE operating system to load the target dynamic library. The TEE operating system can receive the load request sent by the target TA, and in response to the load request, the TEE operating system can load the target dynamic library into the memory space of the target TA, and then, the target TA can use the target dynamic library in its own memory space to run the target service.

[0011] The beneficial effects of the TA operation method provided in the first aspect of the embodiment of the present application are analyzed below:

[0012] 1) In the TA operation method provided in the first aspect of the embodiment of the present application, the TEE operating system can load the target dynamic library used to support the target service into the memory space of the target TA after the target TA receives the operation request of the target service, so that the target TA uses the target dynamic library to run the target service. In this way, during the process of the TEE operating system starting the target TA, or before the target TA receives the operation request of the target service, there is no need to load the program module used to support the target service into the memory space of the TA, which is effective in reducing the waste of the TA's memory space.

[0013] 2) The TEE operating system loads the target dynamic library into the target TA, and there is no need to configure the target TA with the permission to load the target dynamic library. For example, there is no need to configure the target TA with the permission to access and configure the properties of the target storage area, which is conducive to improving the security of the TEE. The target storage area stores the target dynamic library, which is other storage space in the storage area of ​​the TEE other than the memory space of the target TA.

[0014] It should be noted that the target TA using the target dynamic library to run the target service does not limit the target TA to only use the target dynamic library to run the target service, but limits the target TA to at least use the target dynamic library to run the target service.

[0015] The aforementioned "the prerequisite for the target TA to run the target service is that the TEE operating system starts the target TA" does not limit the target TA to run the target service. The TEE operating system must start the target TA. Instead, it limits the target TA to run the target service. Before the target TA runs the target service, the TEE operating system executes the step of starting the target TA at least once, so that the target TA enters the running state and can receive or spontaneously generate running requests for the target service.

[0016] The process of the TEE operating system loading the target dynamic library into the memory space of the target TA, as an example, can specifically include the TEE operating system mapping or loading the target dynamic library into the memory space of the target TA, and then performing symbol resolution and relocation to link the target dynamic library to the target file. Among them, symbol resolution can be understood as associating the definition of the symbol in the target dynamic library with the reference of the symbol in the target file; relocation can be understood as pointing the symbol in the target file to the corresponding position in the memory according to the memory position of the target dynamic library. In some implementations, the TEE operating system can also configure corresponding attributes for the memory corresponding to the target dynamic library, for example, configuring the memory corresponding to the code segment in the target dynamic library as an executable attribute, and configuring the memory corresponding to the data segment in the target dynamic library as a read-only attribute.

[0017] It can be considered that the memory of TEE includes the memory mapped to TA, which can be referred to as the memory space of TA or the memory of TA in the embodiment of the present application; the memory of TEE also includes the memory mapped to the TEE operating system, which can be referred to as the memory space of the TEE operating system or the memory of the TEE operating system in the embodiment of the present application; similarly, it can be considered that the memory of REE includes the memory mapped to CA, which can be referred to as the memory space of CA or the memory of CA in the embodiment of the present application; the memory of REE also includes the memory mapped to the REE operating system, which can be referred to as the memory space of the REE operating system or the memory of the REE operating system in the embodiment of the present application. In some embodiments of the present application, TA runs a service or is expressed as TA executes a service. In the embodiment of the present application, running a service and executing a service can be considered to have the same meaning.

[0018] Based on the method provided in the first aspect of the embodiment of the present application, in a first possible implementation manner of the first aspect of the embodiment of the present application, before the TEE operating system receives the loading request, the target dynamic library has been stored in the memory space of the TEE operating system, and the TEE operating system loads the target dynamic library into the memory space of the target TA in response to the loading request, which may include: in response to the loading request, the TEE operating system may load the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA, and the efficiency of loading the target dynamic library into the memory space of the target TA is high, which is conducive to improving the completion efficiency of the target service.

[0019] Based on the method provided in the first aspect of the embodiment of the present application, in a second possible implementation manner of the first aspect of the embodiment of the present application, the target dynamic library can be stored in a storage device (such as a ROM) of the REE, and the TEE operating system loads the target dynamic library into the memory space of the target TA in response to a load request, which may include: in response to the load request, the TEE operating system can obtain the target dynamic library from the REE operating system, and after obtaining the target dynamic library, the TEE operating system can load the target dynamic library into the memory space of the target TA.

[0020] Since the target dynamic library can be stored in the storage device of REE, it is beneficial to save the storage resources of TEE; the TEE operating system can obtain the target dynamic library from the REE operating system after receiving the loading request. Therefore, if the target TA does not receive the running request of the target service, the TEE operating system does not need to obtain the target dynamic library from the storage device of REE to the storage device of TEE, which is beneficial to further save the storage resources of TEE.

[0021] In a second possible implementation of the first aspect of the embodiment of the present application, the target dynamic library can be stored in a storage device of the REE. Based on the second possible implementation of the first aspect of the embodiment of the present application, in a third possible implementation of the first aspect of the embodiment of the present application, in response to the load request, the TEE operating system obtains the target dynamic library from the REE operating system, which may include: in response to the load request, the TEE operating system may send a transfer request for the target dynamic library to the REE operating system, and then the TEE operating system may receive the target dynamic library sent by the REE operating system.

[0022] This implementation does not limit the specific content and content format of the transfer request sent by the TEE operating system, as long as the REE operating system can send the target dynamic library to the TEE operating system in response to the transfer request. For example, the transfer request may include the identifier of the target dynamic library, and the REE operating system can search for the target dynamic library from the REE's storage device according to the identifier of the target dynamic library.

[0023] In the second possible implementation of the first aspect of the embodiment of the present application and the third possible implementation of the first aspect, "the TEE operating system can obtain the target dynamic library from the REE operating system" does not limit the TEE operating system to obtain the target dynamic library that can be directly loaded into the memory space of the target TA from the REE operating system. In some embodiments, the TEE operating system can obtain the target dynamic library after processing the information obtained from the REE operating system. Exemplarily, due to the poor security of REE, in order to improve the security of the target dynamic library stored in REE, the target dynamic library can be encrypted to obtain an encrypted file, and then the encrypted file is saved in the storage device of REE. Based on the second possible implementation of the first aspect of the embodiment of the present application, in the fourth possible implementation of the first aspect of the embodiment of the present application, in response to the load request, the TEE operating system obtains the target dynamic library from the REE operating system, which may include: in response to the load request sent by the target TA, the TEE operating system can obtain the encrypted file from the REE operating system, and then decrypt the encrypted file to obtain the target dynamic library. Based on the third possible implementation method of the first aspect of the embodiment of the present application, in a fifth possible implementation method of the first aspect of the embodiment of the present application, the TEE operating system receives the target dynamic library sent by the REE operating system, which may include: the TEE operating system receives the encrypted file passed by the REE operating system, and then the TEE operating system decrypts the encrypted file to obtain the target dynamic library.

[0024] In this implementation, the information obtained by decrypting the encrypted file is not limited to only the target dynamic library. Therefore, the file obtained by decrypting the encrypted file can be called a decrypted file, and the decrypted file at least includes the target dynamic library. In addition, in some implementations, the decrypted file may also include other information. For example, in the ninth possible implementation of the first aspect of the present application below, the decrypted file may also include information indicating whether a TA has the authority to call the target dynamic library, referred to as target permission information.

[0025] In order to improve the security of the target dynamic library, in addition to encrypting and storing it in REE, optionally, in some implementations, the target dynamic library can also be signed, and the signature is used to verify the authenticity of the information. Encrypting and signing the target dynamic library can be specifically as follows:

[0026] 1) Encrypt the target dynamic library to obtain encrypted information, and then generate the signature of the encrypted information. The TEE operating system can obtain the encrypted information and standard signature corresponding to the target dynamic library from the REE operating system, and first verify whether the signature of the encrypted information is consistent with the standard signature. If they are inconsistent, the target dynamic library is determined to be unsafe and the acquisition of the target dynamic library fails. If they are consistent, the encrypted information is decrypted to obtain the target dynamic library.

[0027] Alternatively, 2) a signature of the target dynamic library is generated, and then the target dynamic library and its signature are encrypted to obtain encrypted information. The TEE operating system can obtain the encrypted information corresponding to the target dynamic library from the REE operating system, decrypt the encrypted information to obtain the target dynamic library and the standard signature, and the TEE operating system can verify whether the signature of the target dynamic library is consistent with the standard signature. If they are inconsistent, the target dynamic library is determined to be unsafe and the acquisition of the target dynamic library is determined to have failed. If they are consistent, the target dynamic library is determined to have been successfully acquired.

[0028] Similar to the second possible implementation of the first aspect of the embodiment of the present application, based on the method provided in the first aspect of the embodiment of the present application or the first possible implementation of the first aspect of the embodiment of the present application, in the sixth possible implementation of the first aspect of the embodiment of the present application, the target dynamic library can also be stored in the storage device of the REE; the main difference is that in the second possible implementation of the first aspect of the embodiment of the present application, the target dynamic library is obtained from the REE operating system by the TEE operating system in response to the load request sent by the target TA, and in the sixth possible implementation of the first aspect of the embodiment of the present application, the target dynamic library is sent to the TEE operating system by the REE side in response to the first transfer request sent by the target TA. The sixth possible implementation of the first aspect of the embodiment of the present application is specifically introduced below.

[0029] In a sixth possible implementation of the first aspect of the embodiment of the present application, the REE side includes a REE operating system and a CA (referred to as a target CA in the embodiment of the present application) that sends a target service operation request to the target TA. The target CA deployed on the REE operating system has the authority to call the target TA to operate the target service. After the target TA receives the target service operation request sent by the target CA, it can send a first transfer request to the target CA; in response to the first transfer request, the target CA can send a second transfer request to the REE operating system; in response to the second transfer request, the REE operating system can send the target dynamic library to the TEE operating system. Two specific implementation methods are introduced below:

[0030] 1) The target CA is configured with permission to access the target storage area of ​​REE, where the target dynamic library is stored. In response to a first transfer request, the target CA can read the target dynamic library in the target storage area, and then send a second transfer request to the REE operating system. In response to the second transfer request, the REE operating system sends the target dynamic library read by the target CA to the TEE operating system;

[0031] 2) The target dynamic library is stored in the target storage area. In response to the first transfer request, the target CA can send a second transfer request to the REE operating system. In response to the second transfer request, the REE operating system can read the target dynamic library from the target storage area, and then send the target dynamic library to the TEE operating system.

[0032] The specific content and content form of the first transfer request and the second transfer request are not limited in this implementation, as long as the target CA can send the second transfer request to the REE operating system in response to the first transfer request, and the REE operating system can send the target dynamic library to the TEE operating system in response to the second transfer request. For example, the first transfer request and the second transfer request can both include the identifier of the target dynamic library, and the REE operating system can search for the target dynamic library from the storage device of the REE according to the identifier of the target dynamic library.

[0033] Based on the first aspect of the embodiment of the present application or any possible implementation method from the first possible implementation method of the first aspect to the sixth possible implementation method of the first aspect, in the seventh possible implementation method of the first aspect of the embodiment of the present application, during the process of the TEE operating system starting the target TA, the target file of the target TA can be loaded into the memory space of the target TA, and the target file records the various dynamic libraries required by the target TA in the process of running the service, for example, records the identifiers representing each dynamic library, and the dynamic libraries recorded in the target file can be stored in the REE to save the storage resources of the TEE. During the process of the TEE operating system starting the target TA, the TEE operating system can read the identifiers of one or more dynamic libraries from the target file, and then obtain the corresponding one or more dynamic libraries from the REE operating system, and store the obtained dynamic libraries in the memory space of the TEE operating system.

[0034] The dynamic libraries obtained by the TEE operating system during the process of starting the target TA can be all the dynamic libraries recorded in the target file, or, in order to save TEE storage resources, can also be part of the dynamic libraries recorded in the target file. When the TEE operating system receives a request to load the target dynamic library, if the target dynamic library has been pre-stored in the TEE operating system, it will improve the efficiency of the TEE operating system in loading the target dynamic library into the memory space of the target TA.

[0035] If the TEE operating system only pre-acquires some dynamic libraries recorded in the target file during the process of starting the target TA, in order to increase the probability of the pre-acquired dynamic libraries being called by the target TA, the TEE operating system can predict one or more dynamic libraries with a higher probability of being called from the dynamic libraries recorded in the target file, and obtain the predicted corresponding dynamic libraries during the process of starting the target TA.

[0036] Different TAs in the TEE are independent of each other, and a TA cannot access the security resources of another TA without authorization. The target dynamic library can be regarded as the security resource of the target TA. In order to improve the security of the TEE, based on the first aspect of the embodiment of the present application or any possible implementation of the first aspect to the sixth possible implementation of the first aspect, in the eighth possible implementation of the first aspect of the embodiment of the present application, the TEE operating system can set target permission information for the target dynamic library, and the target permission information is used to indicate which TAs have the permission to call the target dynamic library, or indicate which TAs do not have the permission to call the target dynamic library. Exemplarily, the target permission information may include the identification of the TA with the permission to call the target dynamic library. In response to the loading request of the target dynamic library, the TEE operating system loads the target dynamic library into the memory space of the target TA, which may include: in response to the loading request of the target dynamic library, the TEE operating system determines whether the target TA has the permission to call the target dynamic library according to the target permission information, and based on the target TA having the permission to call the target dynamic library, the TEE operating system can load the target dynamic library into the memory space of the target TA.

[0037] Based on the eighth possible implementation method of the first aspect of the embodiment of the present application, in the ninth possible implementation method of the first aspect of the embodiment of the present application, in order to prevent the target permission information from being tampered with and to facilitate the TEE operating system to find the target permission information corresponding to the target dynamic library, the target permission information and the target dynamic library can be encrypted together into the same encrypted file. When the TEE operating system needs to obtain the target dynamic library, the encrypted file can be decrypted. The decrypted file obtained includes the target permission information and the target dynamic library. Afterwards, optionally, the TEE operating system can store the target permission information and the target dynamic library in association in the memory space of the TEE operating system.

[0038] Continuing with the example of a TA (called the target TA) deployed in the TEE operating system and a service (called the target service) provided by the target TA, the operating method of the TA provided in the second aspect of the embodiment of the present application is introduced.

[0039] The premise for the target TA to run the target service is that the TEE operating system starts the target TA. More specifically, the TEE operating system starts the main process of the target TA, and the program modules used to support the target service (or the program modules required by the target TA to run the target service) are loaded into the memory space of the target TA. In the embodiment of the present application, some or all of the program modules supporting the target service are encapsulated as shared target files, or specifically referred to as target dynamic libraries.

[0040] In the TA operation method provided in the aforementioned first aspect and the various implementations of the first aspect, after the TEE operating system starts the target TA, in response to the operation request of the target service, the target TA sends a load request of the target dynamic library to the TEE operating system, and in response to the load request, the TEE operating system loads the target dynamic library into the memory space of the target TA; and in the TA operation method provided in the second aspect of the embodiment of the present application, the permission to load the dynamic library can be configured for the target TA, the TEE operating system can start the target TA, and then the TEE operating system can provide the target TA with a target dynamic library. In response to the operation request of the target service, the target TA can load the target dynamic library into the memory space of the target TA and use the target dynamic library to run the target service. The beneficial effects of the TA operation method provided in the second aspect of the embodiment of the present application are analyzed below:

[0041] 1) In the existing TA operation method, the TEE operating system loads the program segments required to start the TA and the program modules corresponding to the various functions that the TA can implement into the memory space of the TA during the process of starting the TA. Different from the prior art, in the TA operation method provided in the second aspect of the embodiment of the present application, the TEE operating system can provide the target TA with the target dynamic library required to load for running the target service after starting the target TA, which is conducive to achieving that before the target TA receives the running request of the target service, the target dynamic library is not loaded into the memory space of the target TA. After the target TA receives the running request of the target service, the target TA loads the target dynamic library provided by the TEE operating system into the memory space of the target TA, which is conducive to reducing the waste of TA's memory space.

[0042] 2) The target TA loads the target dynamic library, which is conducive to the decoupling of the TA and the TEE operating system in the TEE, facilitates the upgrade of the TA and the TEE operating system, and helps to reduce the operation of the TEE operating system.

[0043] It should be noted that the target TA using the target dynamic library to run the target service does not limit the target TA to only use the target dynamic library to run the target service, but limits the target TA to at least use the target dynamic library to run the target service.

[0044] The process of the target TA loading the target dynamic library can refer to the description of the process of the TEE operating system loading the target dynamic library in the first aspect above, which will not be repeated here. As an example, configuring the target TA with the permission to load the dynamic library can be specifically understood as configuring the target TA with the permission to access and configure the properties (executable or readable, etc.) of the target storage area of ​​the TEE, and the target storage area is the storage area where the target dynamic library is stored.

[0045] The TEE operating system provides the target TA with a target dynamic library. Exemplarily, it can be understood that the target dynamic library required to be loaded by the target TA needs to be obtained by the TEE operating system, and then the target TA loads the target dynamic library obtained by the TEE operating system into the memory space of the target TA; it can also be understood that the target TA needs to access the memory space of the TEE operating system to load the target dynamic library into the memory space of the target TA; it can also be understood as a combination of the first two implementation methods, for example, the target dynamic library required to be loaded by the target TA is obtained by the TEE operating system, and the TEE operating system saves the obtained target dynamic library in the memory space of the TEE operating system, etc. The specific implementation method of the second aspect of the present application provided below continues to introduce "the TEE operating system provides the target TA with a target dynamic library".

[0046] Based on the method provided in the second aspect of the embodiment of the present application, in a first possible implementation of the second aspect of the embodiment of the present application, the target TA may send an acquisition request to the TEE operating system in response to a run request of the target service, and the acquisition request is used to instruct the TEE operating system to acquire the target dynamic library; the TEE operating system provides the target dynamic library for the target TA, which may include: the TEE operating system may receive the acquisition request sent by the target TA, and after receiving the acquisition request, the TEE operating system may acquire the target dynamic library. After the TEE operating system acquires the target dynamic library, the target dynamic library may be saved in the memory of the TEE, for example, in the cache of the TEE. In this implementation, the TEE operating system may acquire the target dynamic library after the target TA receives the run request of the target service, which is beneficial to saving the memory of the TEE.

[0047] Based on the first possible implementation method of the second aspect of the embodiment of the present application, in the second possible implementation method of the second aspect of the present application, the target dynamic library can be stored in the storage device of the REE to save the storage resources of the TEE. At this time, the TEE operating system obtains the target dynamic library, which may include: the TEE operating system obtains the target dynamic library from the REE operating system.

[0048] In the second possible implementation of the second aspect of the present application, "TEE operating system can obtain the target dynamic library from REE operating system", which does not limit the TEE operating system to obtain the target dynamic library that can be directly loaded into the memory space of the target TA from the REE operating system. In some embodiments, the TEE operating system can obtain the target dynamic library after processing the information obtained from the REE operating system. Exemplarily, due to the poor security of REE, in order to improve the security of the target dynamic library stored in REE, the target dynamic library can be encrypted to obtain an encrypted file, and then the encrypted file is saved in the storage device of REE. For example, based on the second possible implementation of the second aspect of the embodiment of the present application, in the third possible implementation of the second aspect of the present application, the TEE operating system obtains the target dynamic library from the REE operating system, which may include: the TEE operating system obtains the encrypted file from the REE operating system; the TEE operating system decrypts the encrypted file to obtain a decrypted file, and the decrypted file includes the target dynamic library.

[0049] In order to improve the security of the target dynamic library, in addition to encrypting and storing it in REE, optionally, in some implementations, the target dynamic library can also be signed, and the signature is used to verify the authenticity of the information. Encrypting and signing the target dynamic library can be specifically as follows:

[0050] 1) Encrypt the target dynamic library to obtain encrypted information, and then generate the signature of the encrypted information. The TEE operating system can obtain the encrypted information and standard signature corresponding to the target dynamic library from the REE operating system, and first verify whether the signature of the encrypted information is consistent with the standard signature. If they are inconsistent, the target dynamic library is determined to be unsafe and the acquisition of the target dynamic library fails. If they are consistent, the encrypted information is decrypted to obtain the target dynamic library.

[0051] Alternatively, 2) a signature of the target dynamic library is generated, and then the target dynamic library and its signature are encrypted to obtain encrypted information. The TEE operating system can obtain the encrypted information corresponding to the target dynamic library from the REE operating system, decrypt the encrypted information to obtain the target dynamic library and the standard signature, and the TEE operating system can verify whether the signature of the target dynamic library is consistent with the standard signature. If they are inconsistent, the target dynamic library is determined to be unsafe and the acquisition of the target dynamic library is determined to have failed. If they are consistent, the target dynamic library is determined to have been successfully acquired.

[0052] Based on the second possible implementation method of the second aspect of the embodiment of the present application, in a fourth possible implementation method of the second aspect of the embodiment of the present application, a specific method for the TEE operating system to obtain a target dynamic library from the REE operating system is provided, which may specifically include: the TEE operating system sends a transfer request for the target dynamic library to the REE operating system, the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system, after which the TEE operating system can receive the target dynamic library sent by the REE operating system.

[0053] Based on the first possible implementation method of the second aspect of the embodiment of the present application, in the fifth possible implementation method of the second aspect of the present application, the target dynamic library can be stored in the storage device of REE to save the storage resources of TEE, and the running request of the target service is sent by the target client application CA deployed on the REE operating system. The target CA has the authority to call the target service. In response to the running request of the target service, the target TA can send a first delivery request to the target CA, and the target CA can send a second delivery request to the TEE operating system in response to the first delivery request. In response to the second delivery request, the REE operating system can send the target dynamic library to the TEE operating system. The "TEE operating system provides the target dynamic library for the target TA" in the first possible implementation method of the second aspect may include: the TEE operating system receives the target dynamic library sent by the REE operating system in response to the second delivery request.

[0054] Based on the second aspect of the embodiment of the present application or any possible implementation of the second aspect, in the sixth possible implementation of the second aspect of the present application, in the process of the TEE operating system starting the target TA, the target file of the target TA can be loaded into the memory space of the target TA, and the target file records the various dynamic libraries required by the target TA in the process of running the service, for example, records the identifiers representing each dynamic library, and the dynamic libraries recorded in the target file can be stored in the REE to save the storage resources of the TEE. In the process of the TEE operating system starting the target TA, the TEE operating system can read the identifiers of one or more dynamic libraries from the target file, and then obtain the corresponding one or more dynamic libraries from the REE operating system, and store the obtained dynamic libraries in the memory space of the TEE operating system.

[0055] The dynamic libraries obtained by the TEE operating system during the process of starting the target TA can be all the dynamic libraries recorded in the target file, or, in order to save TEE storage resources, can also be part of the dynamic libraries recorded in the target file. When the TEE operating system receives a request to load the target dynamic library, if the target dynamic library has been pre-stored in the TEE operating system, it will improve the efficiency of the TEE operating system in loading the target dynamic library into the memory space of the target TA.

[0056] If the TEE operating system only pre-acquires some dynamic libraries recorded in the target file during the process of starting the target TA, in order to increase the probability of the pre-acquired dynamic libraries being called by the target TA, the TEE operating system can predict one or more dynamic libraries with a higher probability of being called from the dynamic libraries recorded in the target file, and obtain the predicted corresponding dynamic libraries during the process of starting the target TA.

[0057] Based on the second aspect of the embodiment of the present application or any possible implementation of the second aspect, in the seventh possible implementation of the second aspect of the embodiment of the present application, the TEE operating system can save the target dynamic library in the memory space of the TEE operating system, and the target TA can load the target dynamic library by accessing the memory space of the TEE operating system. In order to improve the security of information in the memory space of the TEE operating system, the TEE operating system can set access rights for the memory space of the TEE operating system. For example, the TEE operating system provides the target dynamic library for the target TA, which may include: the TEE operating system receives an access request sent by the target TA, and the access request is used to request access to the memory space of the TEE operating system; in response to the access request of the target TA, the TEE operating system can determine whether the target TA has the right to access the memory space of the TEE operating system. If it is determined that the target TA has the right to access the memory space of the TEE operating system, the TEE operating system can send access permission information to the target TA, and the access permission information is used to notify the target TA to access the memory space of the TEE operating system. After receiving the access permission information, the target TA can access the memory space of the TEE operating system and load the target dynamic library therein into its own memory space.

[0058] Based on the seventh possible implementation of the second aspect of the embodiment of the present application, in the eighth possible implementation of the second aspect of the embodiment of the present application, in order to further improve the security of the target dynamic library stored in the memory space of the TEE operating system, the TEE operating system may have call permissions for the target dynamic library. Then the access request sent by the target TA needs to indicate the specific file that the target TA accesses in the TEE operating system. If the access request of the target TA is used to request access to the target dynamic library, the TEE operating system sends access permission information to the target TA, which may specifically include: based on the target TA having permission to access the memory space of the TEE operating system, the TEE operating system determines whether the target TA has permission to call the target dynamic library, and based on the target TA having permission to call the target dynamic library, the TEE operating system sends access permission information to the target TA.

[0059] Continuing with the example of a TA (called the target TA) deployed in the TEE operating system and a service (called the target service) provided by the target TA, the operating method of the TA provided in the third aspect of the embodiment of the present application is introduced.

[0060] The premise for the target TA to run the target service is that the TEE operating system starts the target TA. More specifically, the TEE operating system starts the main process of the target TA, and the program modules used to support the target service (or the program modules required by the target TA to run the target service) are loaded into the memory space of the target TA. In the embodiment of the present application, some or all of the program modules supporting the target service are encapsulated as shared target files, or specifically referred to as target dynamic libraries.

[0061] Similar to the method provided in the second aspect of the aforementioned embodiment of the present application, in the TA operation method provided in the third aspect of the embodiment of the present application, the target TA can be configured with the permission to load the dynamic library, and in response to the operation request of the target service, the target TA can load the target dynamic library into the memory space of the target TA, and then the target service can be operated using the target dynamic library. The following is an analysis of the beneficial effects of the TA operation method provided in the third aspect of the embodiment of the present application:

[0062] 1) In the existing TA operation method, during the process of starting TA, the TEE operating system loads the program segments required to start TA and the program modules corresponding to each function that TA can implement into the memory space of TA. Different from the prior art, in the TA operation method provided in the second aspect of the embodiment of the present application, the target TA can load the target dynamic library into the memory space of the target TA after receiving the operation request of the target service. Therefore, before receiving the operation request of the target service, the target TA does not need to load the target dynamic library into the memory space of the target TA, which is beneficial to reduce the waste of the memory space of the target TA.

[0063] 2) The target TA loads the target dynamic library, which is conducive to the decoupling of the TA and the TEE operating system in the TEE, facilitates the upgrade of the TA and the TEE operating system, and helps to reduce the operation of the TEE operating system.

[0064] It should be noted that the target TA using the target dynamic library to run the target service does not limit the target TA to only use the target dynamic library to run the target service, but limits the target TA to at least use the target dynamic library to run the target service.

[0065] As an example, configuring the target TA with permission to load a dynamic library can be specifically understood as configuring the target TA with permission to access and configure properties (executable or readable, etc.) the target storage area of ​​the TEE, where the target storage area is the storage area for storing the target dynamic library.

[0066] Based on the method provided in the third aspect of the embodiment of the present application, in a first possible implementation manner of the third aspect of the embodiment of the present application, the target dynamic library loaded by the target TA is provided by the TEE operating system, and the target TA loads the target dynamic library into the memory space of the target TA, which can specifically refer to that the target TA loads the target dynamic library provided by the TEE operating system into the memory space of the target TA.

[0067] The target dynamic library required to be loaded by the target TA is provided by the TEE operating system. Exemplarily, it can be understood that the target dynamic library required to be loaded by the target TA needs to be obtained by the TEE operating system, and then the target TA loads the target dynamic library obtained by the TEE operating system into the memory space of the target TA; it can also be understood that the target dynamic library required to be loaded by the target TA is saved in the memory space of the TEE operating system by the TEE operating system, and the target TA needs to access the memory space of the TEE operating system to load the target dynamic library into the memory space of the target TA; it can also be understood as a combination of the first two implementation methods, for example, the target dynamic library required to be loaded by the target TA is obtained by the TEE operating system, and the TEE operating system saves the obtained target dynamic library in the memory space of the TEE operating system, etc. Regarding the TEE operating system providing the target dynamic library for the target TA, it can be understood by referring to the corresponding implementation method of the second aspect of the present application mentioned above, which will not be repeated here.

[0068] The process of the target TA loading the target dynamic library into the memory space of the target TA may specifically include, for example, mapping or loading the target dynamic library into the memory space of the target TA, parsing and relocating the symbols in the target dynamic library, and configuring corresponding attributes for the memory corresponding to the target dynamic library, for example, configuring the memory corresponding to the code segment in the target dynamic library as executable attributes, and configuring the memory corresponding to the data segment in the target dynamic library as read-only.

[0069] Based on the first possible implementation of the third aspect of the embodiment of the present application, in the second possible implementation of the third aspect of the embodiment of the present application, the target TA loads the target dynamic library into the memory space of the target TA, which may include: the target TA may send an acquisition request to the TEE operating system, and the acquisition request is used to request the TEE operating system to acquire the target dynamic library; after the TEE operating system acquires the target dynamic library, the target TA may load the target dynamic library acquired by the TEE operating system into the memory space of the target TA. Since the target TA can request the TEE operating system to acquire the target dynamic library after receiving the running request of the target service, the TEE operating system can acquire the target dynamic library after the target TA receives the running request of the target service, which is conducive to saving the memory of the TEE.

[0070] Based on the second possible implementation method of the third aspect of the embodiment of the present application, in the third possible implementation method of the third aspect of the embodiment of the present application, the target dynamic library can be stored in the storage device of the REE to save the storage resources of the TEE, and the target dynamic library required to be loaded by the target TA can be obtained by the TEE operating system from the REE operating system.

[0071] Based on the first possible implementation method of the third aspect of the embodiment of the present application, in a fourth possible implementation method of the third aspect of the embodiment of the present application, the target dynamic library can be stored in the storage device of REE to save the storage resources of TEE, and the running request of the target service is sent by the target client application CA deployed on the REE operating system, the target CA has the authority to call the target service, and the target TA loads the target dynamic library into the memory space of the target TA, which can include: in response to the running request of the target service, the target TA can send a first transfer request to the target CA, the target CA can send a second transfer request to the TEE operating system in response to the first transfer request, and in response to the second transfer request, the REE operating system can send the target dynamic library to the TEE operating system; thereafter, the target TA can load the target dynamic library received by the TEE operating system into the memory space of the target TA.

[0072] Based on any one of the first to fourth possible implementation methods of the third aspect of the embodiment of the present application, in the fifth possible implementation method of the third aspect of the embodiment of the present application, the TEE operating system provides the target dynamic library for the target TA, which can be understood as the TEE operating system saves the target dynamic library in the memory space of the TEE operating system, and the target TA loads the target dynamic library provided by the TEE operating system into the memory space of the target TA, which can include: the target TA loads the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA.

[0073] Based on the fifth possible implementation of the third aspect of the embodiment of the present application, in the sixth possible implementation of the third aspect of the embodiment of the present application, the TEE operating system can save the target dynamic library in the memory space of the TEE operating system, and the target TA can load the target dynamic library by accessing the memory space of the TEE operating system. In order to improve the security of information in the memory space of the TEE operating system, the TEE operating system can set access rights for the memory space of the TEE operating system, and the target TA loads the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA, which may include: the target TA sends an access request to the TEE operating system, the access request is used to request access to the memory space of the TEE operating system, the TEE operating system can determine whether the target TA has the right to access the memory space of the TEE operating system according to the access request, and if the target TA has the right to access the memory space of the TEE operating system, the TEE operating system can send access permission information to the target TA; based on the target TA receiving the access permission information sent by the TEE operating system, the target TA can access the memory space of the TEE operating system and load the target dynamic library therein into the memory space of the target TA.

[0074] In the prior art, if the files required by TEE are stored in the storage device of REE, the files required by TEE can be obtained by CA, and then the obtained files can be sent to the TEE operating system. The fourth aspect of the embodiment of the present application provides an information processing method in the aforementioned computer system, which adds a function for TEE operating system to obtain the required files for TEE, which is conducive to reducing the development difficulty of CA. Specifically, in response to a transfer request, the REE operating system can obtain the target file, and then send the obtained target file to the TEE operating system, wherein the transfer request is used to instruct the REE operating system to send the target file to the TEE operating system.

[0075] Based on the method provided in the fourth aspect, in a first possible implementation of the fourth aspect of the embodiment of the present application, the target file indicated in the transfer request can be a target dynamic library, the target dynamic library is a dynamic library required to be called by the target TA to run the target service, and is stored in the storage device of the REE, the target TA is a TA deployed in the TEE operating system, and the target service is a service provided by the target TA. The REE operating system can provide the TEE operating system with a dynamic library required to be called when the TA runs the service, which is conducive to dynamically loading the program segments required by the TA into the memory space of the TA, thereby helping to save the memory space of the TA.

[0076] Based on the first possible implementation manner of the fourth aspect, in a second possible implementation manner of the fourth aspect, the transfer request received by the REE operating system may be sent by the TEE operating system.

[0077] Based on the first possible implementation of the fourth aspect, in a third possible implementation of the fourth aspect, the transfer request received by the REE operating system may be sent by a target client application CA, and the target CA has the authority to call the target service.

[0078] The first, second and third possible implementation methods of the fourth aspect of the present application can be understood by referring to the corresponding schemes provided in the first to fourth aspects of the aforementioned embodiments of the present application, and will not be repeated here.

[0079] In a computer system where a rich execution environment REE and a trusted execution environment TEE are deployed, TEE and REE share memory devices. Generally, part of the memory is allocated to TEE according to a certain ratio. TEE configures the attribute of this part of the memory as secure memory for use by processes in TEE; the attribute of other memory is non-secure memory for use by processes in REE. Processes in REE (such as REE operating system or CA) can only access non-secure memory, and processes in TEE (such as TEE operating system or TA) can only access secure memory. The prior art uses CA and TA to collaborate on business logic. When TA needs a large memory, CA applies for memory from the REE operating system and sends the information of the applied memory (such as the address of the memory) to TA. The TEE operating system allocates the memory to the TA for use. If an abnormal situation occurs, such as CA being killed abnormally, the REE operating system will reclaim the memory allocated to CA. Since the memory is occupied by TA, if the REE operating system allocates the memory to other processes of the REE operating system for use, it will cause memory access abnormalities and reduce the stability of the computer system.

[0080] In order to reduce memory access anomalies and improve the stability of the computer system, the fifth aspect of the embodiment of the present application provides a memory processing method in a computer system, wherein the REE on the computer system is deployed with a REE operating system, the TEE is deployed with a TEE operating system, and one or more TAs are deployed on the TEE operating system. The memory allocation method provided in the fifth aspect of the present application may include: the TEE operating system may send a first memory request to the REE operating system, and the first memory request is used to apply for memory from the TEE operating system; in response to the first memory request, the REE operating system may allocate memory (called target memory) to the TEE operating system, and send memory allocation information to the TEE operating system, and the memory allocation information is used to indicate that the memory allocated to the TEE operating system is the target memory. Exemplarily, the memory allocation information may include the address of the target memory; the TEE operating system may configure the target memory as secure memory. Since the target memory is allocated by the REE operating system to the TEE operating system, the probability of anomalies in the TEE operating system is low, so it is not easy to cause memory access anomalies, which is conducive to improving the stability of the computer system.

[0081] Based on the method provided in the fifth aspect of the embodiment of the present application, in the first possible implementation of the fifth aspect of the embodiment of the present application, the TEE operating system can apply for memory from the REE operating system for the TA, and before the TEE operating system sends the first memory request to the REE operating system, the memory allocation method also includes: the TEE operating system obtains the second memory request sent by the target TA, the target TA is any one of the one or more TAs deployed on the TEE operating system, and the second memory request is used to apply for memory from the TEE operating system. It should be noted that this implementation does not limit the TEE operating system to send the first memory request to the REE operating system when it obtains the second memory request sent by the target TA. For example, after receiving the second memory request, the TEE operating system can determine whether the TEE's secure memory is sufficient. If sufficient, the TEE's secure memory can be allocated to the target TA. If insufficient, the memory can be applied to the REE operating system.

[0082] Based on the first possible implementation of the fifth aspect of the embodiment of the present application, in the second possible implementation of the fifth aspect of the embodiment of the present application, after the TEE operating system configures the target memory as secure memory, the memory allocation method may further include: the TEE operating system allocates the target memory to the target TA. The TEE operating system allocating the target memory to the target TA can also be understood as the TEE operating system mapping the target memory to the target TA.

[0083] Based on the first or second possible implementation of the fifth aspect, in the third possible implementation of the fifth aspect, the target service is a service provided by the target TA. After receiving the running request of the target service, if the memory space of the target TA is insufficient to run the target service, the target TA can send a second memory request to the TEE operating system, and the second memory request is used to apply to the TEE operating system for the memory required for the target TA to run the target service.

[0084] Based on any one of the first to third possible implementations of the fifth aspect, in a fourth possible implementation of the fifth aspect, the memory requested by the TEE operating system to the REE operating system may be greater than the memory requested by the target TA to the TEE operating system, that is, the memory requested by the first memory request is greater than the memory requested by the second memory request, which is beneficial to reducing the number of times the target TA requests memory from the TEE operating system, reducing the operations of the target TA and the TEE operating system, and saving the computing resources of the computer system.

[0085] Based on the second possible implementation of the fifth aspect, in the fifth possible implementation of the fifth aspect, after the TEE operating system allocates the first memory to the target TA, the memory allocation method may further include: the TEE operating system may receive a memory release request sent by the target TA (for ease of distinction, the memory release request sent by the target TA here is referred to as a TA memory release request), the TA memory release request is used to request the TEE operating system to release the target memory; in response to the TA memory release request, the TEE operating system may release the target memory. The TEE operating system releasing the target memory can be understood as the TEE operating system canceling the mapping between the target memory and the target TA.

[0086] Based on the fifth possible implementation of the fifth aspect, in a sixth possible implementation of the fifth aspect, after the TEE operating system releases the target memory, the memory allocation method may further include: the TEE operating system configures the target memory as non-secure memory, and then the TEE operating system may send a TEE memory release request to the REE operating system, and the TEE memory release request is used to request the REE operating system to release the target memory. After receiving the TEE memory release request, the REE operating system may release the target memory, and the REE operating system releasing the target memory can be understood as the REE operating system canceling the mapping between the target memory and the TEE operating system.

[0087] It should be noted that after the TEE operating system releases the target memory, the target memory is in an idle state. The TEE operating system may not allocate the target memory to the process in the TEE again for use, but immediately configure the target memory as non-secure memory and return it to the REE operating system; or, after the TEE operating system releases the target memory, the TEE operating system may allocate the target memory to the process in the TEE again for use, and delay returning it to the REE operating system.

[0088] Any possible implementation of the first to sixth possible implementations of the fifth aspect of the embodiment of the present application may be applied to the operating method of the TA of the first aspect of the aforementioned embodiment of the present application or any possible implementation of the first aspect, or applied to the operating method of the TA of the second aspect of the aforementioned embodiment of the present application or any possible implementation of the second aspect, or applied to the operating method of the TA of the third aspect of the aforementioned embodiment of the present application or any possible implementation of the third aspect.

[0089] From the perspective of functional modules, those skilled in the art can divide the functional modules of the target CA, REE operating system, TEE operating system and target TA respectively according to the above method embodiments. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one functional module. The above integrated functional modules can be implemented in the form of hardware or in the form of software functional units.

[0090] Exemplarily, according to the scheme provided in the first aspect, in the case of dividing each functional unit in an integrated manner, the sixth aspect of the embodiment of the present application provides a TEE operating system, and the TEE operating system may include: a startup module, used to start the target TA, the target TA is any one of the one or more TAs; a receiving module, used to receive a load request sent by the target TA in response to a running request of a target service, the load request is used to indicate loading a target dynamic library, wherein the target service is a service provided by the target TA; a loading module, used to load the target dynamic library into the memory space of the target TA in response to the load request, and the target dynamic library is used to support the running of the target service.

[0091] In a possible implementation, the loading module is used to load the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA.

[0092] In a possible implementation, the loading module includes: a TEE communication unit, used to obtain the target dynamic library from the REE operating system; and a dynamic library loading unit, used to load the target dynamic library into the memory space of the target TA.

[0093] In one possible implementation, the TEE communication unit is used to: send a transfer request for the target dynamic library to the REE operating system, the transfer request including an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; and receive the target dynamic library sent by the REE operating system.

[0094] In a possible implementation, the TEE communication unit is used to: obtain an encrypted file from the REE operating system; decrypt the encrypted file to obtain a decrypted file, wherein the decrypted file includes the target dynamic library.

[0095] In one possible implementation, the startup module is used to obtain one or more dynamic libraries from the REE operating system and store the one or more dynamic libraries in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in a target file of the target TA, and optionally, the target file is an executable file of the target TA.

[0096] In a possible implementation, the loading module is used to: determine whether the target TA has the permission to call the target dynamic library according to the target permission information; and load the target dynamic library into the memory space of the target TA based on the fact that the target TA has the permission to call the target dynamic library.

[0097] In one possible implementation, the TEE operating system also includes a TEE memory module, which is used to: obtain a memory request sent by the target TA in response to a running request of the target service, and the memory request is used to apply to the TEE operating system for the memory required to run the target service; in response to the memory request, obtain memory allocation information from the REE operating system, and the memory allocation information is used to instruct the REE operating system to allocate a first memory to the TEE operating system; and allocate the first memory to the target TA.

[0098] In a possible implementation, the TEE memory module is specifically used to: configure the first memory as a secure memory; and allocate the first memory configured as a secure memory to the target TA.

[0099] In one possible implementation, the TEE memory module is also used to: after allocating the first memory to the target TA, receive a TA memory release request sent by the target TA, wherein the TA memory release request is used to request the TEE operating system to release the first memory; and release the first memory in response to the TA memory release request.

[0100] In a possible implementation, the TEE memory module is specifically used to: configure the first memory as non-secure memory; and release the first memory configured as non-secure memory.

[0101] In a possible implementation, the TEE memory module is further used to: after releasing the first memory, send a TEE memory release request to the REE operating system, and the TEE memory release request is used to request the REE operating system to release the first memory.

[0102] Exemplarily, according to the solution provided in the second aspect of the invention content, in the case of dividing each functional unit in an integrated manner, the seventh aspect of the present application provides a TEE operating system, and the TEE operating system may include: a startup module, used to start the target TA, and the target TA is any one of the one or more TAs; a dynamic library providing module, used to provide a target dynamic library for the target TA, and the target dynamic library is loaded by the target TA into the memory space of the target TA to support the target TA to run the target service, and the target service is the service provided by the target TA.

[0103] In one possible implementation, the dynamic library providing module may include: an acquisition request receiving unit, used to receive an acquisition request sent by the target TA in response to a running request of the target service, the acquisition request being used to instruct the TEE operating system to acquire the target dynamic library; a dynamic library acquisition unit, used to acquire the target dynamic library in response to the acquisition request.

[0104] In a possible implementation manner, the dynamic library acquisition unit is used to acquire the target dynamic library from the REE operating system.

[0105] In one possible implementation, the dynamic library acquisition unit is specifically used to: send a transfer request for the target dynamic library to the REE operating system, the transfer request including an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; and receive the target dynamic library sent by the REE operating system.

[0106] In a possible implementation, the dynamic library acquisition unit is specifically used to: acquire an encrypted file from the REE operating system; decrypt the encrypted file to obtain a decrypted file, wherein the decrypted file includes the target dynamic library.

[0107] In one possible implementation, the dynamic library providing module is specifically used to: receive the target dynamic library sent by the REE operating system in response to a second transfer request, the running request of the target service is sent by a target client application CA deployed on the REE operating system, the target CA has the authority to call the target service, the second transfer request is sent by the target CA to the REE operating system in response to the first transfer request, and the first transfer request is sent by the target TA to the target CA in response to the running request of the target service.

[0108] In one possible implementation, the startup module includes: obtaining one or more dynamic libraries from the REE operating system, and storing the one or more dynamic libraries in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in the target file of the target TA, and optionally, the target file is the executable file of the target TA.

[0109] In one possible implementation, the dynamic library providing module includes: an access request receiving unit, used to receive an access request sent by the target TA, the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; an permission information sending unit, used to send permission access information to the target TA based on the target TA having the permission to access the memory space of the TEE operating system, and the permission access information is used to notify the target TA to access the memory space of the TEE operating system.

[0110] In one possible implementation, the access request is used to request access to the target dynamic library; the permission information sending unit is used to: based on the target TA having the permission to access the memory space of the TEE operating system, and based on the target TA having the permission to call the target dynamic library, send the response information to the target TA.

[0111] Exemplarily, according to the solution provided in the third aspect, in the case of dividing each functional unit in an integrated manner, the eighth aspect of this embodiment provides a TA, which corresponds to the target TA in the solution of the third aspect, and the TA may include: a loading module, used to load the target dynamic library into the memory space of the target TA in response to a running request of the target service, the target TA is any one of the one or more TAs, and the target service is a service provided by the target TA; a service running module, used to run the target service using the target dynamic library.

[0112] In a possible implementation manner, the target dynamic library is provided to the target TA by the TEE operating system.

[0113] In a possible implementation, the loading module is used to: send an acquisition request to the TEE operating system, where the acquisition request is used to request the TEE operating system to acquire the target dynamic library; and load the target dynamic library acquired by the TEE operating system into the memory space of the target TA.

[0114] In a possible implementation, the target dynamic library is obtained by the TEE operating system from the REE operating system.

[0115] In one possible implementation, the loading module is used to: send a first transfer request to a target client application CA, the target CA is deployed in the REE operating system and has the authority to call the target service, and the running request of the target service is sent by the target CA; load the target dynamic library received by the TEE operating system into the memory space of the target TA, and the target dynamic library is sent by the REE operating system to the TEE operating system in response to a second transfer request, and the second transfer request is sent by the target CA to the REE operating system in response to the first transfer request.

[0116] In a possible implementation, the loading module is used to load the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA.

[0117] In one possible implementation, the loading module is specifically used to: send an access request to the TEE operating system, the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; based on receiving the access permission information sent by the TEE operating system, access the target dynamic library in the memory space of the TEE operating system, and load the target dynamic library into the memory space of the target TA.

[0118] Exemplarily, according to the scheme provided in the fourth aspect, when each functional unit is divided in an integrated manner, the ninth aspect of the embodiment of the present application provides a REE operating system, which may include: a file acquisition module, used to acquire a target file in response to a transfer request, and the transfer request is used to instruct the REE operating system to transfer the target file to the TEE operating system; a REE communication module, used to send the target file to the TEE operating system.

[0119] In one possible implementation, the target file is a target dynamic library, which is used to be loaded into the memory space of the target TA to support the target TA to run the target service, the target service is a service provided by the target TA, and the target TA is any one of the one or more TAs deployed on the TEE operating system.

[0120] In a possible implementation, the transfer request is sent by the TEE operating system, or the transfer request is sent by a target client application CA, and the target CA has the authority to call the target service.

[0121] Exemplarily, according to the scheme provided in the fifth aspect, in the case of dividing each functional unit in an integrated manner, the tenth aspect of the embodiment of the present application provides a TEE operating system, which TEE operating system may include: a memory application module, used to send a first memory request to the REE operating system, the first memory request is used to request the REE operating system to allocate memory for the TEE operating system; a memory receiving module, used to receive memory allocation information sent by the REE operating system, the memory allocation information is used to indicate that the memory allocated to the TEE operating system is the target memory; a memory configuration module, used to configure the target memory as secure memory.

[0122] In a possible implementation, the memory application module is further used to:

[0123] Before sending a first memory request to the REE operating system, a second memory request sent by a target TA is obtained, where the target TA is any one of one or more TAs deployed on the TEE operating system, and the second memory request is used to apply for memory from the TEE operating system.

[0124] In a possible implementation, the memory configuration module is further used to:

[0125] After configuring the target memory as a secure memory, the target memory is allocated to the target TA.

[0126] In a possible implementation, the second memory request is sent by the target TA in response to an operation request of a target service, and the second memory request is used to apply for memory required by the target TA to run the target service, and the target service is a service provided by the target TA.

[0127] In a possible implementation, the memory requested by the first memory request is greater than the memory requested by the second memory request.

[0128] In a possible implementation, the memory application module is further used to:

[0129] After the memory configuration module allocates the first memory to the target TA, receiving a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the target memory;

[0130] In response to the TA memory release request, the target memory is released.

[0131] In a possible implementation, the memory configuration module is further used to configure the target memory as a non-secure memory after the memory configuration module releases the target memory;

[0132] The memory application module is also used to send a TEE memory release request to the REE operating system, and the TEE memory release request is used to request the REE operating system to release the target memory.

[0133] An eleventh aspect of an embodiment of the present application provides a computer device, comprising a processor and a memory. When the processor runs the computer instructions stored in the memory, the processor executes the first aspect of the embodiment of the present application or any possible implementation of the first aspect, or executes the second aspect of the embodiment of the present application or any possible implementation of the second aspect, or executes the third aspect of the embodiment of the present application or any possible implementation of the third aspect, or executes the fourth aspect of the embodiment of the present application or any possible implementation of the fourth aspect, or executes the fifth aspect of the embodiment of the present application or any possible implementation of the fifth aspect.

[0134] A twelfth aspect of an embodiment of the present application provides a computer-readable storage medium, comprising instructions. When the instructions are executed on a computer, the computer executes the first aspect of the embodiment of the present application or any possible implementation of the first aspect, or executes the second aspect of the embodiment of the present application or any possible implementation of the second aspect, or executes the third aspect of the embodiment of the present application or any possible implementation of the third aspect, or executes the fourth aspect of the embodiment of the present application or any possible implementation of the fourth aspect, or executes the fifth aspect of the embodiment of the present application or any possible implementation of the fifth aspect.

[0135] The thirteenth aspect of the embodiments of the present application provides a computer program product (or computer program), including instructions. When the instructions are executed on a computer, the computer executes the first aspect of the embodiments of the present application or any possible implementation of the first aspect, or executes the second aspect of the embodiments of the present application or any possible implementation of the second aspect, or executes the third aspect of the embodiments of the present application or any possible implementation of the third aspect, or executes the fourth aspect of the embodiments of the present application or any possible implementation of the fourth aspect, or executes the fifth aspect of the embodiments of the present application or any possible implementation of the fifth aspect.

[0136] Since the various devices provided in the embodiments of the present application can be used to execute the corresponding embodiment methods mentioned above, the technical effects that can be obtained by the various device embodiments of the present application can refer to the corresponding method embodiments mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0137] Figure 1 It is a structural diagram of the terminal equipment;

[0138] Figure 2A It is a schematic diagram of the startup process of the fingerprint TA in the prior art;

[0139] Figure 2B It is a schematic diagram of the process of fingerprint TA performing fingerprint matching service in the prior art;

[0140] Figure 2C This is a schematic diagram of TA's memory structure;

[0141] Figure 3A It is a schematic diagram of the memory structure of the fingerprint TA in the prior art;

[0142] Figure 3B It is a schematic diagram of the memory structure of the storage medium of REE in the prior art;

[0143] Figure 3C It is a schematic diagram of fingerprint TA loading dynamic library 1 in an embodiment of the present application;

[0144] Figure 4 This is a schematic diagram of an embodiment of the operation method of the TA of the present application;

[0145] Figure 5 It is a schematic diagram of another embodiment of the operation method of TA of the present application;

[0146] Figure 6 This is a schematic diagram of an embodiment of a method for transferring a dynamic library from a REE operating system to a TEE operating system of the present application;

[0147] Figure 7This is another embodiment schematic diagram of the method of transferring a dynamic library from the REE operating system to the TEE operating system of the present application;

[0148] Figure 8 It is a schematic diagram of the existing memory allocation method;

[0149] Fig. 9 This is a schematic diagram of an embodiment of the memory allocation method of the present application;

[0150] Fig.10 This is a schematic diagram of an embodiment of the TEE operating system of the present application;

[0151] Fig.11 This is a schematic diagram of another embodiment of the TEE operating system of the present application;

[0152] Fig.12 It is a schematic diagram of an embodiment of TA of the present application;

[0153] Fig.13 This is a schematic diagram of an embodiment of the REE operating system of the present application;

[0154] Fig.14 This is a schematic diagram of another embodiment of the TEE operating system of the present application;

[0155] Fig.15 It is a schematic diagram of an embodiment of a computer device of the present application. DETAILED DESCRIPTION

[0156] The embodiments of the present application provide a method for running a trusted application, an information processing method, a memory allocation method and a device. The method of the embodiment of the present application can be applied to a computer system. Exemplarily, the computer system can be a terminal device. Common terminal devices include, for example: mobile phones, tablet computers, desktop computers, wearable devices (such as smart watches), smart home devices (such as smart speakers or smart TVs), in-vehicle smart devices, unmanned driving devices, virtual reality devices, augmented reality devices, mixed reality devices, and artificial intelligence devices. The following takes the computer system as an example of a terminal device, and describes the embodiments of the present application in conjunction with the accompanying drawings.

[0157] With the development of mobile Internet, the application of smart terminal devices is becoming more and more extensive. In order to provide rich functions and scalable properties of smart terminal devices, terminal devices are usually built on a rich execution environment (REE) that provides an open operating environment. REE is also called a general operating environment, which mainly includes a rich operating system (Rich OS) running on a general-purpose processor, or REE operating system, and a client application (CA) running on the REE operating system. However, the open environment provides a channel for information leakage and malware propagation, exposing terminal devices to a growing number of attacks, resulting in increasingly prominent security issues for terminal devices.

[0158] In order to protect user privacy and information security, the Global Platform Organization proposed the Trusted Execution Environment (TEE) standard. Figure 1 This is a schematic diagram of the terminal device. Figure 1, the terminal device is built on REE and TEE. TEE is an independent operating environment running outside REE, mainly including a trusted operating system (Trusted OS), or TEE operating system, and one or more trusted applications (TA) running on the TEE operating system. TEE is isolated from REE. In a possible implementation, the switching of the processor between the REE operating system and the TEE operating system can be completed by the monitoring system (monitor system). When the REE process is running on the processor, the TEE process is suspended, and when the TEE process is running on the processor, the REE process is suspended. Each TA running on the TEE operating system is independent, and the TA cannot access the security resources of another TA without authorization. REE cannot directly access the hardware and software resources of TEE. The two can only interact through the authorized application programming interface (API). In order to simplify the description, the interaction between the process in TEE (such as the process of TA or the process of TEE operating system) and the process in REE (such as the process of CA or the process of REE operating system) described in this application no longer emphasizes that it is implemented through API. Therefore, TEE can resist software attacks occurring on the REE side. For example, some storage media of the terminal device (called TEE storage media) are configured as security attributes and can only be accessed by TEE; other storage media of the terminal device (called REE storage media) can only be accessed by REE. TEE storage media includes TEE memory, which includes memory allocated to TA (TA memory) and memory of TEE operating system (TEE operating system memory). It should be noted that TEE storage media and REE storage media may be physically separated or integrated.

[0159] CA can access TA by calling the API area of ​​TEE to call TA to perform security services. For example, CA can request TA to provide services related to identity authentication. Taking the TA as a fingerprint TA, which is used to perform fingerprint comparison service as an example, the process of fingerprint TA performing fingerprint comparison service is introduced below.

[0160] First, the startup process of the fingerprint TA is introduced. Figure 2A ,The startup process of fingerprint TA includes the following steps:

[0161] 201A, the TEE operating system obtains a request to create the fingerprint TA, and obtains the target file of the fingerprint TA passed by CA2;

[0162] Assuming that CA2 needs to call fingerprint TA to perform fingerprint matching service during operation, and fingerprint TA has not yet been started, CA2 can obtain the target file of fingerprint TA from the ROM of REE, send a request to create fingerprint TA to the TEE operating system, and pass the target file of fingerprint TA to the TEE operating system.

[0163] 202A, the TEE operating system stores the target file of the fingerprint TA in the TEE file management subsystem;

[0164] After the TEE operating system receives the target file of the fingerprint TA transmitted by CA2, the target file of the fingerprint TA can be stored in the TEE operating system memory. Exemplarily, the target file of the fingerprint TA can be stored in the TEE file management subsystem.

[0165] 203A. The TEE operating system loads the target file of the fingerprint TA into the memory of the fingerprint TA and starts the process of the fingerprint TA.

[0166] The TEE operating system can allocate memory for the fingerprint TA according to the creation request of the fingerprint TA, load the target file of the fingerprint TA into the memory of the fingerprint TA, start the fingerprint TA, and execute the target file using the process of the fingerprint TA.

[0167] After the TEE operating system starts the fingerprint TA process, the fingerprint TA can perform fingerprint comparison services. Figure 2B ,The process of the fingerprint TA performing the fingerprint matching service includes the following steps:

[0168] 201B, the fingerprint TA obtains the fingerprint comparison service operation request sent by CA2;

[0169] After the fingerprint TA is started, CA2 can send a fingerprint comparison service request to the fingerprint TA to request the fingerprint TA to obtain the user's fingerprint and compare the user's fingerprint with the standard fingerprint.

[0170] After the fingerprint TA obtains the fingerprint comparison service request sent by CA2, it can use the target file of the fingerprint TA to perform the fingerprint comparison service. Figure 2C ,TA's memory generally includes the following multiple segments:

[0171] 1) Stack: used to store local variables temporarily created by the TA process;

[0172] 2) Heap: used to store the memory segments dynamically allocated during the running of the TA process;

[0173] 3) Data segment: usually used to store initialized global variables in the program;

[0174] 4) Code segment: usually used to store executable code in TA's target file.

[0175] The target file of a TA can generally be logically considered to include the running program segment used by the target TA when running the service. A TA generally needs to use multiple functions to execute a single service. When implementing a certain function, a TA needs to run part of the code segment and access part of the data segment. In the embodiment of the present application, the part of the data and the part of the code are referred to as the program module corresponding to the function. Since a TA usually has multiple functions, it can be considered that the code segment and data segment of the TA include multiple program modules, and each program module corresponds to a function.

[0176] Figure 2C Taking the example of the code segment and data segment of the fingerprint TA including the program modules corresponding to the three functions required for the fingerprint matching service, the three program modules are respectively the fingerprint module, the image processing module and the matching module. The process of the fingerprint TA using these three program modules to perform the fingerprint matching service can refer to the following steps 202B to 204B.

[0177] 202B, the fingerprint TA uses the fingerprint module to call the fingerprint recognition device to obtain the user's fingerprint;

[0178] 203B, the fingerprint TA uses the image processing module to perform image processing on the acquired user fingerprint;

[0179] 204B, the fingerprint TA compares the processed user fingerprint with the standard fingerprint using the comparison module to obtain the execution result of the fingerprint comparison service;

[0180] The execution result of the fingerprint comparison service is used to indicate whether the user's fingerprint is consistent with the standard fingerprint.

[0181] 205B. Fingerprint TA returns the execution result of the fingerprint matching service to CA2.

[0182] After CA obtains the execution result of the fingerprint matching service, it can authenticate the current user and accept or reject the user's request to access protected content (encrypted documents or payment interfaces, etc.) based on the authentication result.

[0183] The corresponding function of the fingerprint module is to drive the fingerprint recognition device to detect the user's fingerprint. In order to drive fingerprint recognition devices from different manufacturers, different fingerprint modules need to be compiled. Different terminal devices of the same model may use different models of fingerprint recognition devices produced by different manufacturers, and the image requirements of each terminal device of the same model are consistent. Therefore, it is necessary to compile corresponding fingerprint modules for each model of fingerprint recognition device used by the terminal device of this model. Assuming that there are multiple models of fingerprint recognition devices, n represents the number of models, then n fingerprint modules need to be added to the target file of the fingerprint TA. Assume that the n fingerprint modules are fingerprint module 1, fingerprint module 2, ..., fingerprint module n. When the TEE operating system is started, the model of the fingerprint recognition device can be determined, thereby determining the fingerprint module corresponding to the fingerprint recognition device of this model. However, since each fingerprint module is compiled in the target file of the fingerprint TA, when creating the fingerprint TA, all fingerprint modules still need to be loaded into the memory of the TA. Figure 3A The structure of the memory of the fingerprint TA. The larger the shipment volume of the terminal device of this model, the larger the value of n, the larger the target file of the fingerprint TA, and the larger the TEE memory occupied by the fingerprint TA, resulting in a waste of TEE memory.

[0184] In order to save TEE memory, the prior art proposes to compile multiple fingerprint TA target files, and each fingerprint TA target file adds a fingerprint module corresponding to a model of fingerprint recognition device. Assuming that there are n models of fingerprint recognition devices, it is necessary to compile n fingerprint TA target files, and store the compiled n fingerprint TA target files in the REE storage medium. Figure 3B The schematic diagram of the target files of n fingerprint TAs (fingerprint TA1, fingerprint TA2, ..., fingerprint Tan) in the REE storage medium. When the TEE operating system is started, the model of the fingerprint recognition device can be determined, thereby determining the fingerprint TA corresponding to the fingerprint recognition device of the model. The compiled target files of the n fingerprint TAs are stored in the storage device of the REE, for example, they can be stored in the ROM of the REE. Since there are a lot of repeated program contents between different fingerprint TAs, such as the contents in the stack and heap, and the common program modules in the code segment and the data segment, such as Figure 2B The image processing module and the comparison module in the corresponding embodiment will therefore waste a lot of storage resources of the REE.

[0185] In order to save the storage resources of TEE and REE, continuing to take the application scenario of the above-mentioned fingerprint matching service as an example, this application proposes to compile fingerprint modules 1 to fingerprint modules n into separate dynamic libraries, for example, using the GNU compiler collection (GNU compiler collection, gcc) to compile fingerprint modules 1 to fingerprint modules n into dynamic libraries 1 to dynamic libraries n, respectively. The "-fPIC" option can be enabled during compilation, and "-share" can be used during linking; the relevant information of each dynamic library (such as the identifier or symbol of the function in the dynamic library, etc.) is embedded into the target file of fingerprint TA. In order to improve the security of the file, optionally, the target files of dynamic library 1, dynamic library 2, ..., dynamic library n and fingerprint TA can be encrypted, or encrypted and signed, to obtain the encrypted files of dynamic library 1, the encrypted files of dynamic library 2, ..., the encrypted files of dynamic library n and the encrypted files of fingerprint TA, and each encrypted file is stored in the storage device of REE. The signature of the information is used to verify the information, encrypt and sign the information. Exemplarily, the information may be encrypted first and then a signature of the encrypted information is generated, or the signature of the information is generated first and then the information and its signature are encrypted. In the embodiment provided in the present application, the example of encrypting and signing the dynamic library that the TA needs to call and then storing it in the storage device of the REE is taken as an example. In actual applications, the dynamic library stored in the REE may not be encrypted and signed, or may only be encrypted but not signed. Figure 3C It shows a schematic diagram of fingerprint TA loading dynamic library 1, Figure 3C It is only used to briefly illustrate the process of fingerprint TA loading dynamic library 1. Figure 3C Other parts of REE and TEE omitted in the article (such as REE operating system and TEE operating system, etc.) can be found in Figure 1 Compared with compiling a fingerprint TA for each fingerprint module, this application is conducive to reducing repeated program content and saving REE storage resources. Figure 3C REE can pass the encrypted file of the dynamic library (assuming it is dynamic library 1) corresponding to the model of the fingerprint recognition device used to TEE. After the TEE operating system decrypts and verifies it, it loads the obtained dynamic library 1 into the memory of the fingerprint TA, so that the fingerprint TA can perform the fingerprint comparison service.

[0186] The following is a detailed introduction to the operation method of the TA provided in the present application. The target TA mentioned in the following method embodiments may be, but is not limited to, the above-mentioned fingerprint TA.

[0187] Figure 4 This is a schematic diagram of an embodiment of the TA operation method provided in this application, refer to Figure 4 An embodiment of the operation method of the TA of the present application may include the following steps:

[0188] 401. TEE operating system starts the target TA;

[0189] The TEE operating system can obtain the encrypted file of the target TA passed by the REE operating system, decrypt and verify the encrypted file of the target TA, obtain the target file of the target TA, and in the process of starting the target TA, load the target file of the target TA into the memory allocated for the target TA, and create a process of the target TA to execute the code segment in the target file.

[0190] For example, when CA needs to call the function of the target TA, it can request the TEE operating system to create the target TA through the interface provided by the SDK. After that, CA uses the opensession interface provided by libteec to request the TEE operating system to run the target TA in the TEE.

[0191] 402. Based on the target TA obtaining the target service's running request, the target TA sends a target dynamic library loading request to the TEE operating system;

[0192] After the process of the target TA is started, it can be called by other TAs in TEE or CA in REE to execute the target service. Assuming that the target TA needs to use the target function to execute the target service, in the embodiment of the present application, the code segment and data segment corresponding to the target function can be encapsulated as a target dynamic library, and the relevant information of the target dynamic library (such as symbol references, symbol tables, and relocation information, etc.) is embedded in the target file of the target TA, and the target TA can call the target dynamic library when executing the target service.

[0193] In an embodiment of the present application, the encrypted file of the target dynamic library can be stored in the storage device of the REE. When the target TA needs to call the target dynamic library, a load request of the target dynamic library can be sent to the TEE operating system. The load request can include the identifier of the target dynamic library, or the identifier of the target TA. Exemplarily, the target TA can call the dlopen interface to request the TEE operating system to load the target dynamic library.

[0194] 403. The TEE operating system determines whether the target dynamic library is stored in the TEE operating system memory. If not, execute step 404. If yes, execute step 409.

[0195] After the TEE operating system receives the loading request sent by the target TA, it can use the identifier of the target dynamic library, or use the identifier of the target dynamic library and the identifier of the target TA to search for the target dynamic library in the TEE operating system memory. If the target dynamic library is not stored in the TEE operating system memory, step 404 can be executed. If the target dynamic library is stored in the TEE operating system memory, step 409 can be executed.

[0196] 404. The TEE operating system sends a transfer request for the target dynamic library to the REE operating system;

[0197] Based on the fact that the target dynamic library is not stored in the memory of the TEE operating system, the TEE operating system can send a transfer request for the target dynamic library to the REE operating system. Assuming that the agent process in the REE operating system is used to transfer the encrypted file of the dynamic library to the TEE operating system, the TEE operating system can wake up the agent process and send a transfer request to the agent process, and the transfer request can include the identifier of the target dynamic library, or include the identifier of the target dynamic library and the identifier of the target TA.

[0198] 405. The REE operating system obtains the encrypted file of the target dynamic library from the storage device of the REE according to the transfer request;

[0199] The encrypted files of the dynamic library are all stored in the storage device of REE. Specifically, assuming that they are stored in the vendor / bin directory, the proxy process can search for the encrypted files of the target dynamic library in the vendor / bin directory according to the identifier of the target dynamic library, or according to the identifier of the target dynamic library and the identifier of the target TA. Exemplarily, in order to uniquely identify the target dynamic library that the target TA needs to call, the file name of the encrypted file of the target dynamic library can be uuid1-fingerdriver1.so.sec, and the REE operating system can find the encrypted files of the target dynamic library in the vendor / bin directory according to the identifier "uuid1" of the target TA and the identifier "fingerdriver1" of the target dynamic library in the received transfer request.

[0200] 406. The REE operating system passes the encrypted file of the target dynamic library to the TEE operating system;

[0201] For example, after finding the encrypted file of the target dynamic library, the agent process of REE can pass the encrypted file of the target dynamic library to the TEE operating system.

[0202] 407. The TEE operating system decrypts and verifies the encrypted file of the target dynamic library to obtain the target dynamic library;

[0203] The TEE operating system can decrypt the encrypted file of the target dynamic library, obtain the target dynamic library, and perform signature verification on the target dynamic library. If the verification is successful, it indicates that the target dynamic library has not been modified, and step 408 can be continued; if the verification is not successful, it indicates that the target dynamic library may have been modified, and other operations can be performed, such as executing step 404 again.

[0204] 408. The TEE operating system stores the target dynamic library in the TEE operating system memory;

[0205] After the TEE operating system obtains the target dynamic library, it can store the target dynamic library in the TEE operating system memory (eg, a file system).

[0206] 409. The TEE operating system loads the target dynamic library into the memory of the target TA;

[0207] In the existing dynamic linking technology, generally, the application is given permission to access the system memory and the permission to configure its own memory attributes, so that the application can load the dynamic library that needs to be called into its own memory space and configure the corresponding attributes for the dynamic library. There are certain security risks in configuring the application with permission to access the system memory and the permission to configure its own memory attributes. In order to improve the security of TEE, in the embodiment of the present application, the TA may not be given permission to access the TEE operating system memory and the permission to configure its own memory attributes. The TEE operating system loads the target dynamic library into the memory of the target TA. The loading process can generally include that the TEE operating system maps or loads the target dynamic library into the memory space of the target TA, performs symbol resolution and relocation, and configures the corresponding attributes of the memory corresponding to the target dynamic library. For example, the memory corresponding to the code segment in the target dynamic library is configured as executable attributes, and the memory corresponding to the data segment in the target dynamic library is configured as read-only.

[0208] 410. The target TA uses the target dynamic library to execute the target service;

[0209] Based on the target dynamic library being loaded into the memory space of the target TA, the target TA can use the function of the target dynamic library to execute the target service. It should be noted that the target TA can use the function of the target dynamic library to execute the target service. It does not limit the target TA to only use the target dynamic library to execute the target service, but it is used to limit the target TA to at least use the target dynamic library to execute the target service. In actual applications, in addition to using the target dynamic library, the target TA can also use the content in the target file of the target TA, or use other dynamic libraries to execute the target service. Exemplarily, the target TA can call the dlsym interface to obtain the code of the function in the target dynamic library. After completion, the dlclose interface can be called to end the call.

[0210] The program segments corresponding to some functions of TA are individually encapsulated as dynamic libraries, which improves the flexibility of TA loading strategy. Figure 4In the corresponding embodiment, when the TA needs to call a dynamic library, the TEE operating system can obtain the encrypted file of the dynamic library from the REE operating system. After the encrypted file passes the decryption verification, the TEE operating system can load the dynamic library into the TA's memory so that the TA can execute the function corresponding to the dynamic library. Taking the application scenario of the aforementioned fingerprint matching service as an example, the TEE operating system can store the dynamic library corresponding to the model of the fingerprint recognition device in the TEE operating system memory instead of obtaining the dynamic library corresponding to other models, which is conducive to reducing the waste of TEE memory. In addition, during the operation of the fingerprint TA, it may not be necessary to execute the fingerprint matching service. Figure 4 In the corresponding embodiment, the TEE operating system obtains the target dynamic library from the REE only when it receives a loading request for the target dynamic library from the TA, and loads it into the TA's memory, which is conducive to further saving TEE memory.

[0211] Figure 4 The corresponding embodiments are only used as examples. In actual applications, all or part of steps 403 to 408 may not be executed as needed. For example, after step 402, step 409 may be directly executed.

[0212] In a possible implementation, after the TEE operating system stores the target dynamic library in the TEE operating system memory, the TEE operating system can load the target dynamic library into the memory of other TAs when receiving a loading request for the target dynamic library from other TAs. Sharing the same dynamic library by multiple TAs is conducive to further saving the secure memory of TEE.

[0213] Each TA running in TEE is independent, and TA cannot access the security resources of another TA without authorization. If the dynamic library dynamically linked by TA is regarded as the security resource of TA, in order to improve the security of TEE, in a possible implementation, the TEE operating system can set target permission information for the target dynamic library. The target permission information is used to indicate which TA has the permission to call the target dynamic library, or which TA does not have the permission to call the target dynamic library; Figure 4 In the corresponding method embodiment, after executing step 408 and before executing step 409, the following steps may also be executed:

[0214] 411. The TEE operating system determines whether the target TA has the authority to call the target dynamic library according to the target permission information. If so, execute step 409; if not, execute step 412;

[0215] Based on the TEE operating system obtaining the target TA's loading request for the target dynamic library, the TEE operating system can read the target permission information of the target dynamic library, and determine whether the target TA has the permission to call the target dynamic library based on the target permission information. If it has the permission, execute step 409; if it does not have the permission, execute step 412.

[0216] In a possible implementation, the target permission information may be an identifier of a TA having the permission to call the target dynamic library. For ease of description, the identifier of a TA having the permission to call the target dynamic library is referred to as a TA identifier.

[0217] In one possible implementation, the TA identifier can be added to the file name of the target dynamic library. Then, the TEE operating system can read the TA identifier from the file name of the target dynamic library and determine whether the identifier of the target TA is consistent with the TA identifier. If they are consistent, it is determined that the target TA has the authority to call the target dynamic library; if they are inconsistent, it is determined that the target TA does not have the authority to call the target dynamic library.

[0218] In the embodiment of the present application, the target dynamic library is not limited to being called by only a single TA. In some application scenarios, it can be called by multiple TAs. Then the target permission information includes multiple TA identifiers, each TA identifier corresponds to a TA that can call the target dynamic library. In this case, as long as the identifier of the target TA is consistent with any one of the TA identifiers, it can be determined that the target TA has the authority to call the target dynamic library; if the identifier of the target TA is inconsistent with all the TA identifiers, it can be determined that the target TA does not have the authority to call the target dynamic library.

[0219] 412. The TEE operating system performs other operations.

[0220] If the target TA does not have the permission to call the target dynamic library, the TEE operating system can reject the target TA's request to load the target dynamic library.

[0221] In order to improve the security of the target permission information, in a possible implementation, the target permission information may be encrypted and signed. In this case, step 407 may specifically perform the following steps:

[0222] 4071. The TEE operating system decrypts and verifies the encrypted file of the target dynamic library to obtain the target dynamic library and target permission information;

[0223] Exemplarily, before using an encryption tool to encrypt the target dynamic library, the identifier of the TA that can call the target dynamic library (TA identifier for short) can be configured in the "gpd.ta.service_name" field in the configuration information (manifest) of the encryption tool. For example, the TA identifier can be uuid2, and "gpd.ta.islib:" is configured as "true" to indicate that the target dynamic library can only be called by the TA corresponding to the identifier. When decrypting the encrypted file of the target dynamic library, the TEE operating system can obtain the configuration information, extract the TA identifier from it, and determine that the target dynamic library can only be run by the TA corresponding to the TA identifier.

[0224] Step 408 may specifically perform the following steps:

[0225] 4081. The TEE operating system associates the target dynamic library and the target permission information and stores them in the TEE operating system memory;

[0226] After the TEE operating system obtains the target dynamic library and the target permission information, in order to facilitate the determination of the target permission information of the target dynamic library, the target dynamic library and the target permission information can be associated and stored in the TEE operating system memory (e.g., the file system). Exemplarily, the TEE operating system can add the target permission information to the file name of the target dynamic library. Taking the target permission information as uuid2 as an example, the file name of the target dynamic library stored in the TEE operating system memory can be "uuid2-fingerdriver1.so". The TEE operating system can determine the target permission information corresponding to the target dynamic library through the file name of the target dynamic library.

[0227] exist Figure 4 In the corresponding embodiment, in order to improve the security of TEE, the TA is not given the permission to access the TEE operating system memory and the permission to configure its own memory attributes. The TEE operating system loads the target dynamic library into the memory of the target TA. In another embodiment of the TA operation method of the present application, the TA can also be given the permission to access the TEE operating system memory and the permission to configure its own memory attributes. Figure 5 Another embodiment of the operation method of the TA of the present application may include the following steps:

[0228] 501. The TEE operating system starts the process of the target TA;

[0229] Step 501 can be understood by referring to the description of step 401 above, which will not be repeated here.

[0230] 502. Based on the obtained target service operation request, the target TA determines whether the target dynamic library is stored in the TEE operating system memory. If not, execute step 503. If yes, execute step 509.

[0231] Assume that the target TA needs to use the function of the target dynamic library to execute the target service. Based on the target TA obtaining the running request of the target service, the target TA can use the identifier of the target dynamic library, or use the identifier of the target dynamic library and the identifier of the target TA to search for the target dynamic library in the TEE operating system memory. If the target dynamic library is not stored in the TEE operating system memory, step 503 can be executed. If the target dynamic library is stored in the TEE operating system memory, step 509 can be executed.

[0232] 503. The target TA sends a request to obtain the target dynamic library to the TEE operating system;

[0233] Based on the fact that the target dynamic library is not stored in the TEE operating system memory, the target TA may send a request to the TEE operating system to obtain the target dynamic library, and the request may include the identifier of the target dynamic library, or may also include the identifier of the target TA. Exemplarily, the target TA may call the dlopen interface to request the TEE operating system to obtain the target dynamic library and store the target dynamic library in the TEE operating system memory.

[0234] 504. The TEE operating system sends a transfer request for the target dynamic library to the REE operating system;

[0235] 505. The REE operating system obtains the encrypted file of the target dynamic library from the storage device of the REE according to the transfer request;

[0236] 506. The REE operating system transfers the encrypted file of the target dynamic library to the TEE operating system;

[0237] 507. The TEE operating system decrypts and verifies the encrypted file of the target dynamic library to obtain the target dynamic library;

[0238] 508. The TEE operating system stores the target dynamic library in the TEE operating system memory;

[0239] Steps 504 to 508 may refer to the description of steps 404 to 408 above, which will not be repeated here.

[0240] 509. The target TA loads the target dynamic library into the memory of the target TA;

[0241] After the TEE operating system stores the target dynamic library in the TEE operating system memory, it can notify the target TA that the target dynamic library has been obtained. The target TA can load the target dynamic library into its own memory. The loading process can generally include the target TA mapping or loading the target dynamic library into the target TA's memory space, parsing and relocating the symbols in the target dynamic library, and configuring corresponding attributes for the memory corresponding to the target dynamic library. For example, the memory corresponding to the code segment in the target dynamic library is configured as executable, and the memory corresponding to the data segment in the target dynamic library is configured as read-only.

[0242] 510. The target TA uses the target dynamic library to execute the target service;

[0243] Exemplarily, the target TA may call the dlsym interface to obtain the code of the function in the target dynamic library, and after completion, may call the dlclose interface to end the call.

[0244] Figure 5 The corresponding embodiment is only used as an example. In actual application, all or part of the steps from step 502 to step 508 may not be executed as needed. For example, after the target TA obtains the operation request of the target service, step 509 is directly executed.

[0245] In order to improve the security of TEE, in one possible implementation, the TEE operating system can set target permission information for the target dynamic library, and the target permission information is used to indicate which TAs have the permission to call the target dynamic library, or indicate which TAs do not have the permission to call the target dynamic library. Before step 510, Figure 5 The corresponding method embodiment may also include the following steps:

[0246] 511. The target TA sends a request to the TEE operating system for accessing the target dynamic library in the memory of the TEE operating system;

[0247] Based on the TEE operating system storing the target dynamic library in the TEE operating system memory, the target TA may send an access request to the TEE operating system for the target dynamic library in the TEE operating system memory, and the access request may include an identifier of the target dynamic library.

[0248] 512. The TEE operating system determines whether the target TA has the authority to call the target dynamic library according to the target permission information. If yes, execute step 513; if no, execute step 514;

[0249] The method by which the TEE operating system determines whether the target TA has the permission to call the target dynamic library based on the target permission information can be found in the relevant description of the aforementioned step 409, which will not be repeated here.

[0250] 513. The TEE operating system sends the target TA access permission information of the target dynamic library;

[0251] Based on the target TA obtaining the access permission information of the target dynamic library sent by the TEE operating system, the target TA may execute step 509 .

[0252] 514. The TEE operating system sends a target TA a notification of denial of access to the target dynamic library;

[0253] Based on the target TA obtaining the access denial notification of the target dynamic library sent by the TEE operating system, the target TA cannot load the target dynamic library, which is helpful to prevent the TA that does not have the authority to call the target dynamic library from loading the target dynamic library and prevent the target dynamic library from being leaked.

[0254] In some embodiments, after receiving an access request from the target TA, the TEE operating system can also determine whether the target TA has permission to access the TEE operating system memory. Based on the fact that the target TA has permission to access the TEE operating system memory and the target TA has permission to call the target dynamic library, the TEE operating system sends the target dynamic library's access permission information to the target TA.

[0255] In the above-mentioned operation method of the TA of the present application, the target dynamic library is loaded into the memory of the target TA after the target TA is started. In a possible implementation, the TEE operating system can load the target dynamic library into the memory of the target TA during the initialization of the target TA. Specifically, during the initialization of the target TA, the TEE operating system can obtain all or part of the dynamic libraries (including or excluding the target dynamic library) recorded in the target file of the target TA according to the identifier of the dynamic library recorded in the target file of the target TA. For example, referring to steps 404 to 408, the TEE operating system stores all or part of the dynamic libraries called by the target TA in the memory of the TEE operating system; thereafter, the TEE operating system can directly load each dynamic library into the memory of the target TA, or, based on the load request of the target service sent by the target TA, if the target dynamic library has been stored in the memory of the TEE operating system, the TEE operating system loads the target dynamic library from the TEE operating system memory to the memory of the target TA.

[0256] Before the target TA obtains the target service's running request, the target dynamic library may have been stored in the TEE operating system memory or even loaded into the target TA's memory, which is beneficial to improving the completion efficiency of the target service.

[0257] However, TA generally calls the corresponding dynamic library according to the service to be executed, that is, the target TA may not need to call some dynamic libraries recorded in its target file during operation, and the TEE operating system loads all dynamic libraries that the target TA may call into the target TA's memory during the initialization of the target TA, which easily causes a waste of TEE's secure memory. In order to balance memory resources and loading efficiency, the TEE operating system can predict one or more dynamic libraries with a higher probability of being called from the dynamic libraries recorded in the target file, and obtain the predicted corresponding dynamic libraries during the process of starting the target TA.

[0258] In the above-mentioned operation method of the TA of the present application, the REE operating system executes steps 405 and 406 based on obtaining the transfer request for the target dynamic library sent by the TEE operating system. In a possible implementation, even if the REE operating system does not obtain the transfer request for the target dynamic library sent by the TEE operating system, the REE operating system can actively execute steps 405 and 406 to pass the encrypted file of the target dynamic library to the TEE operating system, which is conducive to reducing the interaction between REE and TEE and saving the computing resources of the terminal device.

[0259] In one possible implementation, reference Figure 6 An embodiment of transferring a dynamic library from the REE operating system to the TEE operating system may include:

[0260] 601. Based on the target CA requesting the TEE operating system to create a target TA, the target CA obtains the identifiers of each dynamic library that the target TA needs to call;

[0261] The running information of the TA that the target CA may call may be recorded in the target file of the target CA. For example, the identifiers of each dynamic library that the target TA needs to call may be associated with the identifier of the target TA and recorded in the target file of the target CA. When the target CA needs to call the target TA to perform a service, the identifiers of each dynamic library that the target TA needs to call may be searched.

[0262] 602. The target CA sends a transfer request for the dynamic library to the REE operating system, where the transfer request includes the obtained identifiers of each dynamic library.

[0263] 603. The REE operating system obtains the encrypted files of each dynamic library from the storage device of the REE according to the transfer request;

[0264] 604. The REE operating system transfers the encrypted files of each dynamic library to the TEE operating system.

[0265] After the TEE operating system obtains the encrypted files of each dynamic library transmitted by the TEE operating system, it can decrypt and verify them, and store the obtained dynamic libraries in the TEE operating system memory. Afterwards, the TEE operating system can load each dynamic library into the target TA's memory during the target TA initialization process, or, when obtaining the target dynamic library loading request sent by the target TA, load the target dynamic library into the target TA's memory, or the target TA can load the target dynamic library into its own memory.

[0266] In one possible implementation, reference Figure 7 Another embodiment of the method of transferring a dynamic library from the REE operating system to the TEE operating system may include:

[0267] 701. The target CA sends a target service operation request to the target TA;

[0268] Based on the target TA being started, the target CA may request the target TA to perform the target service.

[0269] 702. The target TA sends a first transfer request for the target dynamic library to the target TA;

[0270] Based on obtaining the running request of the target service, the target TA can obtain the identifier of the target dynamic library that needs to be called when executing the target service, and send a transfer request for the target dynamic library to the target TA. In order to distinguish it from other transfer requests, the transfer request here is called the first transfer request, and the first transfer request includes the identifier of the target dynamic library.

[0271] 703. The target CA obtains the encrypted file of the target dynamic library from the storage device of the REE according to the first transfer request;

[0272] The target CA may be configured with permission to access the storage device of the REE. In response to the first transfer request, the target CA may obtain the encrypted file of the target dynamic library from the storage device of the REE according to the first transfer request.

[0273] 704. The target CA sends a second transfer request for the target dynamic library to the REE operating system;

[0274] After the target CA obtains the encrypted file of the target dynamic library, it can cache the encrypted file and send a second transfer request for the target dynamic library to the REE operating system, requesting the REE operating system to send the target dynamic library to the TEE operating system. For the sake of distinction, the transfer request here is referred to as the second transfer request, and the second transfer request can include the identifier of the target dynamic library.

[0275] 705. The REE operating system passes the encrypted file of the target dynamic library to the TEE operating system.

[0276] In response to the second transfer request, the REE operating system may transfer the encrypted file obtained by the target CA to the TEE operating system.

[0277] After the TEE operating system obtains the encrypted file of the target dynamic library transmitted by the TEE operating system, it can decrypt and verify it, and store the obtained target dynamic library in the TEE operating system memory. The specific process can refer to the description of step 407 and step 408, which will not be repeated here. Afterwards, the TEE operating system can directly load the target dynamic library into the memory of the target TA, or, when obtaining the target dynamic library loading request sent by the target TA, load the target dynamic library in the TEE operating system memory into the memory of the target TA, or, if the TA is set with the permission to access the TEE operating system memory and the permission to configure its own memory attributes, the target TA can load the target dynamic library into its own memory.

[0278] In a possible implementation, the identifier of the target dynamic library that the target TA needs to call when executing the target service can also be recorded in the target file of the target CA. At this time, when the target CA needs to request the target TA to execute the target service, the steps can be executed without the target TA sending a transfer request.

[0279] TEE and REE share memory devices. Generally, part of the memory is allocated to TEE according to a certain ratio. TEE configures the attributes of this part of the memory as secure memory for TEE use; the attributes of other memory are non-secure memory for REE use. REE can only access non-secure memory, and TEE can only access secure memory. The tasks that CA calls TA to perform may require a large amount of memory, such as face recognition tasks. When performing face recognition tasks, TA needs to calculate a large amount of graphic data, generate a large amount of intermediate data, and require a large amount of memory.

[0280] The existing technology uses CA and TA to collaborate on business logic. When TA needs a large memory, CA applies for memory and passes it to TA. TA then applies to the TEE operating system to configure the memory as secure memory and maps it to TA for use. Before CA exits, if the security attribute is not actively released, such as CA is killed due to an exception, the REE operating system will reclaim the memory allocated to CA and may allocate it to other processes of the REE operating system for use. However, since the attribute of the memory is secure memory, other processes in the REE cannot access it, resulting in stability abnormalities.

[0281] refer to Figure 8 , the existing memory allocation method is specifically introduced below, including the following steps:

[0282] 801. The target CA obtains address information of a first memory fed back by the REE operating system in response to a memory request of the target CA;

[0283] The memory request sent by the target CA is used to apply to the REE operating system for the memory required by the target TA to run the target service.

[0284] 802. The target CA sends the address information of the first memory and the operation request of the target service to the target TA;

[0285] 803. The target TA sends a security attribute configuration request to the TEE operating system, where the security attribute configuration request includes address information of the first memory;

[0286] 804. The TEE operating system modifies the attribute of the first memory to a secure memory according to the security attribute configuration request;

[0287] 805. The target TA executes the target service using the first memory;

[0288] 806. Based on the target TA completing the target service, the target TA sends a non-security attribute configuration request to the TEE operating system, where the non-security attribute configuration request includes address information of the first memory;

[0289] 807. The TEE operating system modifies the attribute of the first memory to non-secure memory according to the non-secure attribute configuration request;

[0290] 808. Based on the target TA completing the target service, the target CA requests the REE operating system to release the first memory.

[0291] Existing memory allocation methods generally have the following problems:

[0292] 1) When TA needs a large amount of memory to perform tasks, CA applies for the memory required by TA from the REE operating system. When TA completes the task, CA notifies the REE operating system to release the corresponding memory. If TA fails to complete the task and CA is killed abnormally, the REE operating system will release the memory allocated to CA. The memory release of CA is not synchronized with the memory attribute modification of TEE, which will lead to memory attribute configuration problems and cause the entire machine to reset.

[0293] 2) When TA needs a lot of memory to run, a lot of interactive operations are required between CA and TA, and the development process of CA and TA is complicated.

[0294] In order to solve the above problems, this application provides a memory allocation method, referring to Fig. 9 , an embodiment of the memory allocation method of the present application may include the following steps:

[0295] 901. The target TA obtains a target service operation request sent by the target CA;

[0296] 902. The target TA sends a TA memory request to the TEE operating system;

[0297] The TA memory request can be used to apply for the memory required by the target service;

[0298] 903. The TEE operating system determines whether the available system memory in the TEE operating system is sufficient according to the TA memory request. If not, execute step 904. If yes, execute step 907.

[0299] 904. The TEE operating system sends a TEE memory request to the REE operating system, and the memory size requested by the TEE memory request is not less than the memory requested by the TA memory request;

[0300] Alternatively, the size of the memory requested by the TEE memory request is determined according to the size of the available secure memory and the size of the memory requested by the TA memory request.

[0301] 905. The REE operating system transmits the address information of the first memory to the TEE operating system according to the TEE memory request;

[0302] The REE operating system can send memory allocation information to the TEE operating system, where the memory allocation information is used to indicate that the memory allocated by the TEE operating system is the first memory. In an embodiment of the present application, the memory allocation information is taken as the address information of the first memory as an example.

[0303] 906. The TEE operating system configures the attribute of the first memory as secure memory;

[0304] 907. The TEE operating system allocates the second memory to the target TA, and the size of the second memory is not less than the memory requested by the TA memory request;

[0305] 908. The target TA executes the target service using the second memory;

[0306] 909. Based on the target TA completing the target service, the target TA sends a TA memory release request to the TEE operating system, where the TA memory release request includes address information of the second memory;

[0307] 910. The TEE operating system releases the second memory according to the TA memory release request;

[0308] 911. Based on the first memory being idle, the TEE operating system configures the attribute of the first memory as non-secure memory;

[0309] 912. The TEE operating system requests the REE operating system to release the first memory.

[0310] The TEE operating system needs to return the first memory (ie, execute step 911 and step 912). If the first memory is larger than the second memory, the TEE operating system can return the first memory at one time, or can return the first memory in multiple times.

[0311] Regarding the TEE operating system returning the second memory: the TEE operating system can return the second memory immediately after step 910 (i.e., execute steps 911 and 912); or, the TEE operating system can delay the return of the second memory. For example, the TEE operating system can determine whether the secure memory delivered by the REE / or the available secure memory is sufficient. If so, it will be returned immediately, otherwise it will not be returned for the time being; or, the TEE operating system can retain the second memory for a certain period of time, and return it if it is not used within the period of time.

[0312] The embodiments of the present application are helpful in solving the instability problem caused by CA applying for memory for TA, and are helpful in reducing the complexity of the TEE memory dynamic expansion solution.

[0313] Fig. 9 The corresponding embodiments are only taken as examples. In practical applications, all or part of steps 901, 902, 903 and 907 to 912 may not be executed as needed.

[0314] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the interaction between the target CA, REE operating system, TEE operating system and target TA in the computer system. It can be understood that the above-mentioned target CA, REE operating system, TEE operating system and target TA, in order to achieve the above-mentioned functions, include hardware structures and / or software modules corresponding to the execution of each function. It should be easily appreciated by those skilled in the art that, in combination with the functions described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0315] From the perspective of functional modules, those skilled in the art can divide the functional modules of the target CA, REE operating system, TEE operating system and target TA respectively according to the above method embodiments. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one functional module. The above integrated functional modules can be implemented in the form of hardware or in the form of software functional units.

[0316] Exemplarily, according to the solution provided in the first aspect of the invention, when each functional unit is divided in an integrated manner, Fig.10 A schematic diagram of the structure of a TEE operating system is shown. Fig.10 As shown, an embodiment of the TEE operating system 1000 of the present application may include:

[0317] A starting module 1010 is used to start a target TA, where the target TA is any one of the one or more TAs;

[0318] The receiving module 1020 is used to receive a load request sent by a target TA in response to a run request of a target service, where the load request is used to instruct to load a target dynamic library, wherein the target service is a service provided by the target TA;

[0319] The loading module 1030 is used to load the target dynamic library into the memory space of the target TA in response to the loading request, and the target dynamic library is used to support the operation of the target service.

[0320] In a possible implementation, the loading module 1030 is used to:

[0321] Load the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA.

[0322] In a possible implementation, the loading module 1030 includes:

[0323] The TEE communication unit is used to obtain the target dynamic library from the REE operating system;

[0324] The dynamic library loading unit is used to load the target dynamic library into the memory space of the target TA.

[0325] In one possible implementation, the TEE communication unit is used to:

[0326] Sending a transfer request of the target dynamic library to the REE operating system, where the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system;

[0327] Receive the target dynamic library sent by the REE operating system.

[0328] In one possible implementation, the TEE communication unit is used to:

[0329] Get encrypted files from REE operating system;

[0330] The encrypted file is decrypted to obtain a decrypted file, which includes a target dynamic library.

[0331] In a possible implementation, the startup module 1010 is used to:

[0332] One or more dynamic libraries are obtained from the REE operating system, and the one or more dynamic libraries are stored in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in a target file of the target TA, and the target file is an executable file of the target TA.

[0333] In a possible implementation, the loading module 1030 is used to:

[0334] Determine whether the target TA has the authority to call the target dynamic library according to the target permission information;

[0335] Based on the target TA having the permission to call the target dynamic library, the target dynamic library is loaded into the memory space of the target TA.

[0336] In a possible implementation, the TEE operating system further includes a TEE memory module, and the TEE memory module is used to:

[0337] Obtain a memory request sent by the target TA in response to a target service's run request, where the memory request is used to apply to the TEE operating system for the memory required to run the target service;

[0338] In response to the memory request, obtain memory allocation information from the REE operating system, where the memory allocation information is used to instruct the REE operating system to allocate the first memory to the TEE operating system;

[0339] The first memory is allocated to the target TA.

[0340] In one possible implementation, the TEE memory module is specifically used for:

[0341] configuring the first memory as a secure memory;

[0342] The first memory configured as a secure memory is allocated to the target TA.

[0343] In one possible implementation, the TEE memory module is also used to:

[0344] After allocating the first memory to the target TA, receiving a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the first memory;

[0345] In response to the TA memory release request, the first memory is released.

[0346] In one possible implementation, the TEE memory module is specifically used for:

[0347] configuring the first memory as a non-secure memory;

[0348] The first memory configured as non-secure memory is released.

[0349] In one possible implementation, the TEE memory module is also used to:

[0350] After releasing the first memory, a TEE memory release request is sent to the REE operating system, where the TEE memory release request is used to request the REE operating system to release the first memory.

[0351] Exemplarily, according to the solution provided in the second aspect of the invention, when each functional unit is divided in an integrated manner, Fig.11 A schematic diagram of the structure of a TEE operating system is shown. Fig.11 As shown, another embodiment of the TEE operating system 1100 of the present application may include:

[0352] A starting module 1110, configured to start a target TA, where the target TA is any one of the one or more TAs;

[0353] The dynamic library providing module 1120 is used to provide a target dynamic library for the target TA. The target dynamic library is loaded by the target TA into the memory space of the target TA to support the target TA to run the target service. The target service is a service provided by the target TA.

[0354] In a possible implementation, the dynamic library providing module 1120 includes:

[0355] An acquisition request receiving unit, used to receive an acquisition request sent by a target TA in response to a run request of a target service, wherein the acquisition request is used to instruct the TEE operating system to acquire a target dynamic library;

[0356] The dynamic library acquisition unit is used to acquire the target dynamic library in response to the acquisition request.

[0357] In a possible implementation, the dynamic library acquisition unit is used to acquire the target dynamic library from the REE operating system.

[0358] In a possible implementation, the dynamic library acquisition unit is specifically used to:

[0359] Sending a transfer request of the target dynamic library to the REE operating system, where the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system;

[0360] Receive the target dynamic library sent by the REE operating system.

[0361] In a possible implementation, the dynamic library acquisition unit is specifically used to:

[0362] Get encrypted files from REE operating system;

[0363] The encrypted file is decrypted to obtain a decrypted file, which includes a target dynamic library.

[0364] In a possible implementation, the dynamic library providing module 1120 is specifically used for:

[0365] Receive the target dynamic library sent by the REE operating system in response to the second transfer request, the target service running request is sent by the target client application CA deployed on the REE operating system, the target CA has the authority to call the target service, the second transfer request is sent by the target CA to the REE operating system in response to the first transfer request, and the first transfer request is sent by the target TA to the target CA in response to the target service running request.

[0366] In a possible implementation, the starting module 1110 includes:

[0367] Obtain one or more dynamic libraries from the REE operating system, and store the one or more dynamic libraries in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in a target file of the target TA, and optionally, the target file is an executable file of the target TA.

[0368] In a possible implementation, the dynamic library providing module 1120 includes:

[0369] An access request receiving unit, used to receive an access request sent by a target TA, where the access request is used to request access to a memory space of a TEE operating system, where a target dynamic library is stored in the memory space of the TEE operating system;

[0370] The permission information sending unit is used to send access permission information to the target TA based on the target TA having the authority to access the memory space of the TEE operating system, and the access permission information is used to notify the target TA to access the memory space of the TEE operating system.

[0371] In a possible implementation, the access request is used to request access to a target dynamic library;

[0372] Allows the information sending unit to:

[0373] Based on the target TA having the permission to access the memory space of the TEE operating system and based on the target TA having the permission to call the target dynamic library, a response message is sent to the target TA.

[0374] Exemplarily, according to the solution provided in the third aspect of the invention, when each functional unit is divided in an integrated manner, Fig.12FIG. 1 shows a schematic diagram of a TA structure. The TA in this embodiment corresponds to the target TA in the above-mentioned method embodiments. Fig.12 As shown, an embodiment of the TA 1200 of the present application may include:

[0375] The loading module 1210 is used to load the target dynamic library into the memory space of the target TA in response to the operation request of the target service, where the target TA is any one of the one or more TAs, and the target service is the service provided by the target TA;

[0376] The service running module 1220 is used to run the target service using the target dynamic library.

[0377] In a possible implementation, the target dynamic library is provided to the target TA by the TEE operating system.

[0378] In a possible implementation, the loading module 1210 is used to:

[0379] Send an acquisition request to the TEE operating system, where the acquisition request is used to request the TEE operating system to acquire the target dynamic library;

[0380] The target dynamic library obtained by the TEE operating system is loaded into the memory space of the target TA.

[0381] In a possible implementation, the target dynamic library is obtained by the TEE operating system from the REE operating system.

[0382] In a possible implementation, the loading module 1210 is used to:

[0383] Sending a first delivery request to a target client application CA, where the target CA is deployed in the REE operating system and has the authority to call the target service, and the target service operation request is sent by the target CA;

[0384] The target dynamic library received by the TEE operating system is loaded into the memory space of the target TA. The target dynamic library is sent to the TEE operating system by the REE operating system in response to the second transfer request. The second transfer request is sent to the REE operating system by the target CA in response to the first transfer request.

[0385] In a possible implementation, the loading module 1210 is used to:

[0386] Load the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA.

[0387] In a possible implementation, the loading module 1210 is specifically used for:

[0388] Send an access request to the TEE operating system. The access request is used to request access to the memory space of the TEE operating system. The target dynamic library is stored in the memory space of the TEE operating system.

[0389] Based on the access permission information received from the TEE operating system, the target dynamic library in the memory space of the TEE operating system is accessed, and the target dynamic library is loaded into the memory space of the target TA.

[0390] Exemplarily, according to the solution provided in the fourth aspect of the invention, when each functional unit is divided in an integrated manner, Fig.13 FIG. 1 shows a schematic diagram of the structure of a REE operating system. Fig.13 As shown, an embodiment of the REE operating system 1300 of the present application may include:

[0391] A file acquisition module 1310, configured to acquire a target file in response to a transfer request, wherein the transfer request is used to instruct the REE operating system to transfer the target file to the TEE operating system;

[0392] The REE communication module 1320 is used to send the target file to the TEE operating system.

[0393] In one possible implementation, the target file is a target dynamic library, which is used to be loaded into the memory space of the target TA to support the target TA to run the target service. The target service is a service provided by the target TA, and the target TA is any one of the one or more TAs deployed on the TEE operating system.

[0394] In a possible implementation, the transfer request is sent by the TEE operating system, or the transfer request is sent by the target client application CA, and the target CA has the authority to call the target service.

[0395] Exemplarily, according to the solution provided in the fifth aspect of the invention, when each functional unit is divided in an integrated manner, Fig.14 A schematic diagram of the structure of a TEE operating system is shown. Fig.14 As shown, another embodiment of the TEE operating system 1400 of the present application may include:

[0396] A memory application module 1410 is used to send a first memory request to the REE operating system, where the first memory request is used to request the REE operating system to allocate memory to the TEE operating system;

[0397] A memory receiving module 1420 is used to receive memory allocation information sent by the REE operating system, where the memory allocation information is used to indicate that the memory allocated to the TEE operating system is the target memory;

[0398] The memory configuration module 1430 is used to configure the target memory as a secure memory.

[0399] In a possible implementation, the memory application module 1410 is further configured to:

[0400] Before sending the first memory request to the REE operating system, a second memory request sent by a target TA is obtained, where the target TA is any one of the one or more TAs deployed on the TEE operating system, and the second memory request is used to apply for memory from the TEE operating system.

[0401] In a possible implementation, the memory configuration module 1430 is further configured to:

[0402] After configuring the target memory as secure memory, the target memory is allocated to the target TA.

[0403] In a possible implementation, the second memory request is sent by the target TA in response to an operation request of the target service, and the second memory request is used to apply for memory required by the target TA to operate the target service, and the target service is a service provided by the target TA.

[0404] In a possible implementation, the memory requested by the first memory request is greater than the memory requested by the second memory request.

[0405] In a possible implementation, the memory application module 1410 is further configured to:

[0406] After the memory configuration module 1430 allocates the first memory to the target TA, a TA memory release request sent by the target TA is received, where the TA memory release request is used to request the TEE operating system to release the target memory;

[0407] The memory application module 1410 is further configured to release the target memory in response to the TA memory release request.

[0408] In a possible implementation, the memory configuration module 1430 is further used to configure the target memory as non-secure memory after the memory configuration module 1430 releases the target memory;

[0409] The memory application module is also used to send a TEE memory release request to the REE operating system. The TEE memory release request is used to request the REE operating system to release the target memory.

[0410] The embodiment of the present application also provides a computer system, which can run any embodiment method provided by the present application, including hardware structures and / or software modules corresponding to the execution of each function. Those skilled in the art should easily appreciate that, in conjunction with the functions described in the embodiments disclosed herein, the computer system of the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional and technical personnel can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of the present application.

[0411] From the perspective of functional modules, those skilled in the art can divide the functional modules according to the computer system of the above method embodiment. For example, each functional module can be divided according to each function, or two or more functions can be integrated into one functional module. The above integrated functional module can be implemented in the form of hardware or in the form of software functional units.

[0412] Exemplarily, the computer operating system provided in the present application may include one or more of the above-mentioned REE operating system, TEE operating system, CA and TA.

[0413] Since the various devices provided in the embodiments of the present application can be used to execute the corresponding embodiment methods mentioned above, the technical effects that can be obtained by the various device embodiments of the present application can refer to the corresponding method embodiments mentioned above, and will not be repeated here.

[0414] The above modules may refer to an application-specific integrated circuit (ASIC), a processor and memory that executes one or more software or firmware programs, an integrated logic circuit, and / or other devices that can provide the above functions. Fig.15 FIG. 1 is a schematic diagram of the hardware structure of a computer device 1500. In a simple embodiment, a person skilled in the art may imagine that the TEE operating system, REE operating system, TA, CA or operating system may be used. Fig.15 The form shown.

[0415] The computer device 1500 may include: a processor radio frequency (RF) circuit 1510, a memory 1520, an input unit 1530, a display unit 1540, a sensor 1550, an audio circuit 1560, a wireless fidelity (WiFi) module 1570, a processor 1580, and a power supply 1590.

[0416] Those skilled in the art will understand that Fig.15 The computer device structure shown in the figure does not constitute a limitation on the computer device, and may include more or less components than shown in the figure, or combine certain components, or arrange the components differently.

[0417] Combine the following Fig.15 A detailed introduction to the various components of computer equipment:

[0418] The RF circuit 1510 may be used for receiving and sending signals during information transmission or calls. In particular, after receiving downlink information from a network-side device, the information is sent to the processor 1580 for processing. In addition, the designed uplink data is sent to the network-side device.

[0419] Typically, the RF circuit 1510 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low noise amplifier (LNA), a duplexer, and the like.

[0420] In addition, RF circuit 1510 can also communicate with a network and other devices through wireless communications.

[0421] The above-mentioned wireless communications may use any communication standard or protocol, including but not limited to global system of mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), long term evolution (LTE), email, short messaging service (SMS), etc.

[0422] The memory 1520 may be used to store software programs and modules. The processor 1580 executes various functional applications and data processing of the computer device by running the software programs and modules stored in the memory 1520 .

[0423] The memory 1520 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system and at least one application required for a function; the data storage area may store data created according to the use of the computer device, etc. In addition, the memory 1520 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0424] The input unit 1530 may be used to receive input digital or character information, and to generate key signal input related to user settings and function control of the computer device.

[0425] Specifically, the input unit 1530 may include a touch panel 1531 and other input devices 1532. The touch panel 1531, also known as a touch screen, can collect user touch operations on or near it (such as operations performed by the user using any suitable object or accessory such as a finger, stylus, etc. on the touch panel 1531 or near the touch panel 1531), and drive the corresponding connection device according to a pre-set program. In addition to the touch panel 1531, the input unit 1530 may also include other input devices 1532. Specifically, other input devices 1532 may include, but are not limited to, one or more of a physical keyboard, function keys (such as a volume control button, a switch button, etc.), a trackball, a mouse, a joystick, etc.

[0426] The display unit 1540 may be used to display information input by the user or information provided to the user and various menus of the computer device. The display unit 1540 may include a display panel 1541. Optionally, the display panel 1541 may be configured in the form of a liquid crystal display (LCD), an organic light-emitting diode (OLED), etc. Further, the touch panel 1531 may cover the display panel 1541. When the touch panel 1531 detects a touch operation on or near it, it is transmitted to the processor 1580 to determine the type of touch event. Subsequently, the processor 1580 provides a corresponding visual output on the display panel 1541 according to the type of touch event. Although in Fig.15 In the embodiment, the touch panel 1531 and the display panel 1541 are used as two independent components to implement the input and output functions of the computer device, but in some embodiments, the touch panel 1531 and the display panel 1541 can be integrated to implement the input and output functions of the computer device.

[0427] The computer device may also include at least one sensor 1550, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 1541 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 1541 and / or the backlight when the computer device is moved to the ear. As a type of motion sensor, the accelerometer sensor can detect the magnitude of acceleration in each direction (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that identify the posture of the computer device (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the computer device, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be repeated here.

[0428] The audio circuit 1560, the speaker 1561, and the microphone 1562 can provide an audio interface between the user and the computer device. The audio circuit 1560 can transmit the received audio data to the speaker 1561 after converting the received audio data into an electrical signal, which is converted into a sound signal for output; on the other hand, the microphone 1562 converts the collected sound signal into an electrical signal, which is received by the audio circuit 1560 and converted into audio data, and then the audio data is processed by the output processor 1580, and then sent to another device through the RF circuit 1510, or the audio data is output to the memory 1520 for further processing.

[0429] WiFi is a short-range wireless transmission technology. Computer devices can help users send and receive emails, browse web pages, and access streaming media through WiFi module 1570. It provides users with wireless broadband Internet access. Fig.15 A WiFi module 1570 is shown, but it is understandable that it is not an essential component of the computer device and can be omitted as needed without changing the essence of the invention.

[0430] The processor 1580 is the control center of the computer device. It uses various interfaces and lines to connect various parts of the entire computer device. By running or executing the software programs and / or modules stored in the memory 1520, and calling the data stored in the memory 1520, it executes various functions of the computer device and processes data, thereby monitoring the computer device as a whole. The processor 1580 can be a central processing unit (CPU), a network processor (NP) or a combination of CPU and NP, a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components. It can implement or execute the various methods, steps and logic block diagrams disclosed in this application. The general processor can be a microprocessor or the processor can also be any conventional processor, etc. The steps of the method disclosed in this application can be directly embodied as a hardware decoding processor to be executed, or a combination of hardware and software modules in the decoding processor can be executed. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory or an electrically erasable programmable memory, a register, etc. The storage medium is located in the memory, and the processor reads the information in the memory and completes the steps of the above method in combination with its hardware. Although only one processor is shown in the figure, the device may include multiple processors or the processor includes multiple processing units. Specifically, the processor may be a single-core processor or a multi-core or many-core processor. The processor may be an ARM architecture processor. Optionally, the processor 1580 may integrate an application processor and a modem processor, wherein the application processor mainly processes the operating system, the user interface, and the application program, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 1580.

[0431] The computer device also includes a power supply 1590 (such as a battery) for supplying power to various components. Preferably, the power supply can be logically connected to the processor 1580 through a power management system, so that the power management system can manage functions such as charging, discharging, and power consumption.

[0432] Although not shown, the computer device may also include a camera, a Bluetooth module, etc., which will not be described in detail here.

[0433] The computer device provided in the embodiments of the present application may be a mobile phone, a tablet computer, a desktop computer, a wearable device (such as a smart watch), a smart home device (such as a smart speaker or a smart TV), an in-vehicle smart device, an unmanned driving device, a virtual reality device, an augmented reality device, a mixed reality device, and an artificial intelligence device, etc.

[0434] The above embodiments may be implemented in whole or in part through software, hardware, firmware or any combination thereof. When implemented by software, they may be implemented in whole or in part in the form of a computer program product.

[0435] The computer program product includes one or more computer instructions. When the computer execution instruction is loaded and executed on a computer, the process or function described in the embodiment of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instruction may be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium, for example, the computer instruction may be transmitted from a website site, a computer, a server or a data center by wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) mode to another website site, computer, server or data center. The computer-readable storage medium may be any available medium that a computer can store or a data storage device such as a server or a data center that includes one or more available media integrations. The available medium may be a magnetic medium, (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive (SSD)), etc.

[0436] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and need not be used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable in appropriate circumstances, which is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment. In the present application embodiment, "plurality" refers to two or more.

[0437] In the embodiments of the present application, the words "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0438] In the various embodiments of the present application, various examples are provided for ease of understanding, however, these examples are merely examples and are not intended to be the best implementation of the present application.

[0439] The technical solution provided by the present application is introduced in detail above. The principles and implementation methods of the present application are explained by using specific examples in the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the idea of ​​the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.

Claims

1. A method for running a trusted application TA, It is characterized in that Applied to a computer system, on which a rich execution environment REE and a trusted execution environment TEE are deployed, a REE operating system is deployed in the REE, a TEE operating system is deployed in the TEE, and one or more trusted application programs TA are deployed on the TEE operating system, the method comprising: The TEE operating system starts a target TA, where the target TA is any one of the one or more TAs; The TEE operating system receives a load request sent by the target TA in response to a run request of a target service, wherein the load request is used to instruct loading of a target dynamic library, wherein the target service is a service provided by the target TA; In response to the loading request, the TEE operating system loads the target dynamic library into the memory space of the target TA, and the target dynamic library is used to support the operation of the target service; wherein, The TEE operating system loading the target dynamic library into the memory space of the target TA includes: the TEE operating system obtaining the target dynamic library from the REE operating system and loading the target dynamic library into the memory space of the target TA; or, The TEE operating system loads the target dynamic library into the memory space of the target TA, including: the TEE operating system loads the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA, the target dynamic library in the memory space of the TEE operating system is obtained by the TEE operating system from the REE operating system during the process of starting the target TA, and the target dynamic library is recorded in the target file of the target TA.

2. The method according to claim 1, It is characterized in that The TEE operating system obtains the target dynamic library from the REE operating system, including: The TEE operating system sends a transfer request for the target dynamic library to the REE operating system, where the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; The TEE operating system receives the target dynamic library sent by the REE operating system.

3. The method according to claim 1, It is characterized in that The TEE operating system obtains the target dynamic library from the REE operating system, including: The TEE operating system obtains the encrypted file from the REE operating system; The TEE operating system decrypts the encrypted file to obtain a decrypted file, where the decrypted file includes the target dynamic library.

4. The method according to claim 1, It is characterized in that The running request of the target service is sent by the target client application CA deployed on the REE operating system, and the target client application CA has the authority to call the target service. The target dynamic library is sent by the REE operating system to the TEE operating system in response to a second transfer request, wherein the second transfer request is sent by the target client application CA to the REE operating system in response to a first transfer request, and the first transfer request is sent by the target TA to the target client application CA in response to the running request of the target service.

5. The method according to any one of claims 1 to 4, It is characterized in that The TEE operating system loads the target dynamic library into the memory space of the target TA, including: The TEE operating system determines whether the target TA has the authority to call the target dynamic library according to the target permission information; Based on the target TA having the authority to call the target dynamic library, the TEE operating system loads the target dynamic library into the memory space of the target TA.

6. The method according to any one of claims 1 to 5, It is characterized in that The method further comprises: The TEE operating system obtains a memory request sent by the target TA in response to a request to run the target service, where the memory request is used to apply to the TEE operating system for memory required to run the target service; In response to the memory request, the TEE operating system obtains memory allocation information from the REE operating system, where the memory allocation information is used to instruct the REE operating system to allocate the first memory to the TEE operating system; The TEE operating system allocates the first memory to the target TA.

7. The method according to claim 6, It is characterized in that The first memory is larger than the memory requested by the memory request.

8. The method according to claim 6, It is characterized in that The TEE operating system allocates the first memory to the target TA, including: The TEE operating system configures the first memory as a secure memory; The TEE operating system allocates the first memory configured as a secure memory to the target TA.

9. The method according to any one of claims 6 to 8, It is characterized in that After the TEE operating system allocates the first memory to the target TA, the method further includes: The TEE operating system receives a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the first memory; In response to the TA memory release request, the TEE operating system releases the first memory.

10. The method according to claim 9, It is characterized in that The TEE operating system releases the first memory, including: The TEE operating system configures the first memory as a non-secure memory; The TEE operating system releases the first memory configured as non-secure memory.

11. The method according to claim 9, It is characterized in that After the TEE operating system releases the first memory, the method further includes: The TEE operating system sends a TEE memory release request to the REE operating system, where the TEE memory release request is used to request the REE operating system to release the first memory.

12. A method for running a trusted application program TA, It is characterized in that Applied to a computer system, on which a rich execution environment REE and a trusted execution environment TEE are deployed, a REE operating system is deployed in the REE, a TEE operating system is deployed in the TEE, and one or more trusted application programs TA are deployed on the TEE operating system, the method comprising: The TEE operating system starts a target TA, where the target TA is any one of the one or more TAs; The TEE operating system provides a target dynamic library for the target TA, and the target dynamic library is loaded by the target TA into the memory space of the target TA to support the target TA to run a target service, and the target service is a service provided by the target TA; wherein, The TEE operating system providing the target dynamic library for the target TA includes: the TEE operating system receiving an acquisition request sent by the target TA in response to a run request of the target service, the acquisition request being used to instruct the TEE operating system to acquire the target dynamic library, and acquiring the target dynamic library from the REE operating system in response to the acquisition request; or The TEE operating system starts the target TA, including the TEE operating system obtaining one or more dynamic libraries from the REE operating system and storing the one or more dynamic libraries in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in the target file of the target TA.

13. The method according to claim 12, It is characterized in that The TEE operating system obtains the target dynamic library from the REE operating system, including: The TEE operating system sends a transfer request for the target dynamic library to the REE operating system, where the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; The TEE operating system receives the target dynamic library sent by the REE operating system.

14. The method according to claim 12, It is characterized in that The TEE operating system obtains the target dynamic library from the REE operating system, including: The TEE operating system obtains the encrypted file from the REE operating system; The TEE operating system decrypts the encrypted file to obtain a decrypted file, where the decrypted file includes the target dynamic library.

15. The method according to claim 12, It is characterized in that The TEE operating system provides the target dynamic library for the target TA, including: The TEE operating system receives the target dynamic library sent by the REE operating system in response to the second transfer request, the running request of the target service is sent by the target client application CA deployed on the REE operating system, the target client application CA has the authority to call the target service, the second transfer request is sent by the target client application CA to the REE operating system in response to the first transfer request, and the first transfer request is sent by the target TA to the target client application CA in response to the running request of the target service.

16. The method according to any one of claims 12 to 15, It is characterized in that The TEE operating system provides the target dynamic library for the target TA, including: The TEE operating system receives an access request sent by the target TA, where the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; Based on the fact that the target TA has the permission to access the memory space of the TEE operating system, the TEE operating system sends access permission information to the target TA, where the access permission information is used to notify the target TA to access the memory space of the TEE operating system.

17. The method according to claim 16, It is characterized in that The access request is used to request access to the target dynamic library; The TEE operating system sending access permission information to the target TA includes: Based on the target TA having the permission to access the memory space of the TEE operating system, and based on the target TA having the permission to call the target dynamic library, the TEE operating system sends a response message to the target TA.

18. A method for running a trusted application program TA, It is characterized in that Applied to a computer system, a rich execution environment REE and a trusted execution environment TEE are deployed on the computer system, a REE operating system is deployed in the REE, a TEE operating system is deployed in the TEE, and one or more TAs are deployed on the TEE operating system, the method includes: In response to a running request of a target service, the target TA sends a loading request to the TEE operating system, where the loading request is used to instruct loading of a target dynamic library, the target TA is any one of the one or more TAs, and the target service is a service provided by the target TA; The target TA uses the target dynamic library to run the target service; wherein, The TEE operating system is used to obtain the target dynamic library from the REE operating system in response to the loading request, and load the target dynamic library into the memory space of the target TA; or, The TEE operating system is used to load the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA in response to the loading request. The target dynamic library in the memory space of the TEE operating system is obtained by the TEE operating system from the REE operating system during the process of starting the target TA. The target dynamic library is recorded in the target file of the target TA.

19. The method according to claim 18, It is characterized in that The target TA loads the target dynamic library into the memory space of the target TA, including: The target TA sends a first transfer request to a target client application CA, the target client application CA is deployed in the REE operating system and has the authority to call the target service, and the running request of the target service is sent by the target client application CA; The target TA loads the target dynamic library received by the TEE operating system into the memory space of the target TA, and the target dynamic library is sent to the TEE operating system by the REE operating system in response to a second transfer request, and the second transfer request is sent to the REE operating system by the target client application CA in response to the first transfer request.

20. The method according to any one of claims 18 to 19, It is characterized in that The target TA loads the target dynamic library into the memory space of the target TA, including: The target TA loads the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA.

21. The method according to claim 20, It is characterized in that The target TA loads the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA, including: The target TA sends an access request to the TEE operating system, where the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; Based on receiving the access permission information sent by the TEE operating system, the target TA accesses the target dynamic library in the memory space of the TEE operating system and loads the target dynamic library into the memory space of the target TA.

22. An information processing method, It is characterized in that Applied to a computer system, on which a rich execution environment REE and a trusted execution environment TEE are deployed, a REE operating system is deployed in the REE, and a TEE operating system is deployed in the TEE, the method includes: In response to a transfer request, the REE operating system obtains a target file, wherein the transfer request is used to instruct the REE operating system to transfer the target file to the TEE operating system; The REE operating system sends the target file to the TEE operating system; wherein, The target file is a target dynamic library, which is used to be loaded into the memory space of the target TA to support the target TA to run the target service. The target service is a service provided by the target TA. The target TA is any one of the one or more TAs deployed on the TEE operating system. The transfer request is sent by the TEE operating system during the process of starting the target TA or in response to a load request sent by the target TA in response to a running request of the target service.

23. A memory allocation method, It is characterized in that Applied to a computer system, on which a rich execution environment REE and a trusted execution environment TEE are deployed, a REE operating system is deployed in the REE, and a TEE operating system is deployed in the TEE, wherein the method comprises: The TEE operating system sends a first memory request to the REE operating system, where the first memory request is used to request the REE operating system to allocate memory to the TEE operating system; The TEE operating system receives memory allocation information sent by the REE operating system, where the memory allocation information is used to indicate that the memory allocated to the TEE operating system is the target memory; The TEE operating system configures the target memory as secure memory.

24. The method according to claim 23, It is characterized in that Before the TEE operating system sends the first memory request to the REE operating system, the method further includes: The TEE operating system obtains a second memory request sent by a target TA, where the target TA is any one of the one or more TAs deployed on the TEE operating system, and the second memory request is used to apply for memory from the TEE operating system.

25. The method according to claim 24, It is characterized in that After the TEE operating system configures the target memory as secure memory, the method further includes: The TEE operating system allocates the target memory to the target TA.

26. The method according to claim 24 or 25, It is characterized in that The second memory request is sent by the target TA in response to an operation request of a target service, and the second memory request is used to apply for the memory required by the target TA to run the target service, and the target service is a service provided by the target TA.

27. The method according to any one of claims 24 to 26, It is characterized in that The memory requested by the first memory request is greater than the memory requested by the second memory request.

28. The method according to claim 25, It is characterized in that After the TEE operating system allocates the first memory to the target TA, the method further includes: The TEE operating system receives a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the target memory; In response to the TA memory release request, the TEE operating system releases the target memory.

29. The method according to claim 28, It is characterized in that After the TEE operating system releases the target memory, the method further includes: The TEE operating system configures the target memory as non-secure memory; The TEE operating system sends a TEE memory release request to the REE operating system, where the TEE memory release request is used to request the REE operating system to release the target memory.

30. A trusted execution environment TEE operating system, It is characterized in that The TEE operating system is deployed in a TEE on a computer system. A rich execution environment REE is also deployed on the computer system. The REE operating system is deployed in the REE. One or more TAs are deployed on the TEE operating system. The TEE operating system includes: A starting module, used to start a target TA, where the target TA is any one of the one or more TAs; a receiving module, configured to receive a loading request sent by the target TA in response to a running request of a target service, wherein the loading request is used to instruct to load a target dynamic library, wherein the target service is a service provided by the target TA; A loading module, used to load the target dynamic library into the memory space of the target TA in response to the loading request, wherein the target dynamic library is used to support the operation of the target service; wherein, The loading module is specifically used to obtain the target dynamic library from the REE operating system and load the target dynamic library into the memory space of the target TA; or, The loading module is specifically used to load the target dynamic library from the memory space of the TEE operating system into the memory space of the target TA. The target dynamic library in the memory space of the TEE operating system is obtained by the TEE operating system from the REE operating system during the process of starting the target TA. The target dynamic library is recorded in the target file of the target TA.

31. The TEE operating system according to claim 30, It is characterized in that The loading module includes a TEE communication unit, and the TEE communication unit is used to: Sending a transfer request of the target dynamic library to the REE operating system, wherein the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; Receive the target dynamic library sent by the REE operating system.

32. The TEE operating system according to claim 30, It is characterized in that The loading module includes a TEE communication unit, and the TEE communication unit is used to: Obtaining an encrypted file from the REE operating system; The encrypted file is decrypted to obtain a decrypted file, wherein the decrypted file includes the target dynamic library.

33. The TEE operating system according to any one of claims 30 to 32, It is characterized in that The loading module is used to: Determining whether the target TA has the authority to call the target dynamic library according to the target authority information; Based on the target TA having the authority to call the target dynamic library, the target dynamic library is loaded into the memory space of the target TA.

34. The TEE operating system according to any one of claims 30 to 33, It is characterized in that The TEE operating system also includes a TEE memory module, and the TEE memory module is used to: Obtaining a memory request sent by the target TA in response to a request to run the target service, where the memory request is used to apply to the TEE operating system for memory required to run the target service; In response to the memory request, obtaining memory allocation information from the REE operating system, where the memory allocation information is used to instruct the REE operating system to allocate the first memory to the TEE operating system; The first memory is allocated to the target TA.

35. The TEE operating system according to claim 34, It is characterized in that The TEE memory module is specifically used for: configuring the first memory as a secure memory; The first memory configured as a secure memory is allocated to the target TA.

36. The TEE operating system according to claim 34 or 35, It is characterized in that The TEE memory module is also used for: After allocating the first memory to the target TA, receiving a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the first memory; In response to the TA memory release request, the first memory is released.

37. The TEE operating system according to claim 36, It is characterized in that The TEE memory module is specifically used for: Configuring the first memory as a non-secure memory; The first memory configured as non-secure memory is released.

38. The TEE operating system according to claim 36, It is characterized in that The TEE memory module is also used for: After releasing the first memory, a TEE memory release request is sent to the REE operating system, where the TEE memory release request is used to request the REE operating system to release the first memory.

39. A trusted execution environment TEE operating system, It is characterized in that The TEE operating system is deployed in a TEE on a computer system. A rich execution environment REE is also deployed on the computer system. The REE operating system is deployed in the REE. One or more TAs are deployed on the TEE operating system. The TEE operating system includes: A starting module, used to start a target TA, where the target TA is any one of the one or more TAs; A dynamic library providing module is used to provide a target dynamic library for the target TA, and the target dynamic library is loaded by the target TA into the memory space of the target TA to support the target TA to run a target service, and the target service is a service provided by the target TA; wherein, The dynamic library providing module is specifically used to receive an acquisition request sent by the target TA in response to the running request of the target service, the acquisition request is used to instruct the TEE operating system to acquire the target dynamic library, and in response to the acquisition request, acquire the target dynamic library from the REE operating system; or The dynamic library providing module is specifically used to obtain one or more dynamic libraries from the REE operating system and store the one or more dynamic libraries in the memory space of the TEE operating system, wherein the one or more dynamic libraries are recorded in the target file of the target TA.

40. The TEE operating system according to claim 39, It is characterized in that The dynamic library acquisition unit is specifically used for: Sending a transfer request of the target dynamic library to the REE operating system, wherein the transfer request includes an identifier of the target dynamic library, and the transfer request is used to instruct the REE operating system to send the target dynamic library to the TEE operating system; Receive the target dynamic library sent by the REE operating system.

41. The TEE operating system according to claim 39, It is characterized in that The dynamic library acquisition unit is specifically used for: Obtaining an encrypted file from the REE operating system; The encrypted file is decrypted to obtain a decrypted file, wherein the decrypted file includes the target dynamic library.

42. The TEE operating system according to claim 39, It is characterized in that The dynamic library provides a module specifically for: Receive the target dynamic library sent by the REE operating system in response to a second transfer request, the target service running request is sent by a target client application CA deployed on the REE operating system, the target client application CA has the authority to call the target service, the second transfer request is sent by the target client application CA to the REE operating system in response to the first transfer request, and the first transfer request is sent by the target TA to the target client application CA in response to the target service running request.

43. A TEE operating system according to any one of claims 39 to 42, It is characterized in that The dynamic library provides a module including: An access request receiving unit, configured to receive an access request sent by the target TA, wherein the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; The permission information sending unit is used to send access permission information to the target TA based on the target TA having the permission to access the memory space of the TEE operating system, wherein the access permission information is used to notify the target TA to access the memory space of the TEE operating system.

44. The TEE operating system according to claim 43, It is characterized in that The access request is used to request access to the target dynamic library; The permission information sending unit is used for: Based on the fact that the target TA has the permission to access the memory space of the TEE operating system, and based on the fact that the target TA has the permission to call the target dynamic library, a response message is sent to the target TA.

45. A trusted application TA, It is characterized in that The TA is deployed on a trusted execution environment TEE operating system, the TEE operating system is deployed in a TEE of a computer system, a rich execution environment REE is also deployed on the computer system, and a REE operating system is deployed in the REE, and the TA includes: A loading module, configured to send a loading request to the TEE operating system in response to a running request of a target service, wherein the loading request is used to instruct to load a target dynamic library, wherein the TA is a target TA, and the target TA is any one of one or more TAs deployed on the TEE operating system, and the target service is a service provided by the target TA; A service running module is used to run the target service using the target dynamic library; wherein, The TEE operating system is used to obtain the target dynamic library from the REE operating system in response to the loading request, and load the target dynamic library into the memory space of the target TA; or, The TEE operating system is used to load the target dynamic library from the memory space of the TEE operating system to the memory space of the target TA in response to the loading request. The target dynamic library in the memory space of the TEE operating system is obtained by the TEE operating system from the REE operating system during the process of starting the target TA. The target dynamic library is recorded in the target file of the target TA.

46. ​​The TA according to claim 45, It is characterized in that The loading module is used to: Sending a first transfer request to a target client application CA, wherein the target client application CA is deployed in the REE operating system and has the authority to call the target service, and the running request of the target service is sent by the target client application CA; The target dynamic library received by the TEE operating system is loaded into the memory space of the target TA, and the target dynamic library is sent to the TEE operating system by the REE operating system in response to a second transfer request, and the second transfer request is sent to the REE operating system by the target client application CA in response to the first transfer request.

47. The TA according to claim 45 or 46, It is characterized in that The loading module is used to: The target dynamic library is loaded from the memory space of the TEE operating system into the memory space of the target TA.

48. The TA according to claim 47, It is characterized in that The loading module is specifically used for: Sending an access request to the TEE operating system, wherein the access request is used to request access to the memory space of the TEE operating system, and the target dynamic library is stored in the memory space of the TEE operating system; Based on the access permission information received from the TEE operating system, the target dynamic library in the memory space of the TEE operating system is accessed, and the target dynamic library is loaded into the memory space of the target TA.

49. A Rich Execution Environment (REE) operating system, It is characterized in that The REE operating system is deployed in a REE on a computer system. A trusted execution environment TEE is also deployed on the computer system. A TEE operating system is deployed in the TEE. The REE operating system includes: A file acquisition module, configured to acquire a target file in response to a transfer request, wherein the transfer request is used to instruct the REE operating system to transfer the target file to the TEE operating system; The REE communication module is used to send the target file to the TEE operating system; wherein, The target file is a target dynamic library, which is used to be loaded into the memory space of the target TA to support the target TA to run the target service. The target service is a service provided by the target TA. The target TA is any one of the one or more TAs deployed on the TEE operating system. The transfer request is sent by the TEE operating system during the process of starting the target TA or in response to a load request sent by the target TA in response to a running request of the target service.

50. A trusted execution environment TEE operating system, It is characterized in that The TEE operating system is deployed in a TEE on a computer system. A rich execution environment REE is also deployed on the computer system. The REE operating system is deployed in the REE. The TEE operating system includes: A memory application module, configured to send a first memory request to the REE operating system, wherein the first memory request is used to request the REE operating system to allocate memory to the TEE operating system; A memory receiving module, used to receive memory allocation information sent by the REE operating system, wherein the memory allocation information is used to indicate that the memory allocated to the TEE operating system is the target memory; A memory configuration module is used to configure the target memory as a secure memory.

51. The TEE operating system according to claim 50, It is characterized in that The memory application module is also used for: Before sending a first memory request to the REE operating system, a second memory request sent by a target TA is obtained, where the target TA is any one of one or more TAs deployed on the TEE operating system, and the second memory request is used to apply for memory from the TEE operating system.

52. The TEE operating system according to claim 51, It is characterized in that The memory configuration module is also used for: After configuring the target memory as a secure memory, the target memory is allocated to the target TA.

53. The TEE operating system according to claim 51 or 52, It is characterized in that The second memory request is sent by the target TA in response to an operation request of a target service, and the second memory request is used to apply for the memory required by the target TA to run the target service, and the target service is a service provided by the target TA.

54. A TEE operating system according to any one of claims 51 to 53, It is characterized in that The memory requested by the first memory request is greater than the memory requested by the second memory request.

55. The TEE operating system according to claim 52, It is characterized in that The memory application module is also used for: After the memory configuration module allocates the first memory to the target TA, receiving a TA memory release request sent by the target TA, where the TA memory release request is used to request the TEE operating system to release the target memory; In response to the TA memory release request, the target memory is released.

56. The TEE operating system according to claim 55, It is characterized in that The memory configuration module is further used to configure the target memory as a non-secure memory after the memory configuration module releases the target memory; The memory application module is also used to send a TEE memory release request to the REE operating system, and the TEE memory release request is used to request the REE operating system to release the target memory.

57. A computer device, It is characterized in that The method comprises a processor and a memory, wherein the processor executes the method according to any one of claims 1 to 29 when executing the computer instructions stored in the memory.

58. A computer readable storage medium, It is characterized in that The method comprises instructions which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 29.

59. A computer program product, It is characterized in that The method comprises instructions which, when executed on a computer, cause the computer to execute the method according to any one of claims 1 to 29.

Citation Information

Patent Citations

  • TrustZone framework-based application program execution method and device as well as terminal

    CN105630534A

  • Dynamic loading method, device and storage medium for diagnostic software

    CN109086102A

  • A secure memory dynamic management system and method based on a trusted execution environment

    CN109426742A