Key usage methods and related products
By entrusting the key to a second device with a secure hardware environment, the risks of key leakage and limitations in computing power during key storage and use in terminal devices are resolved, thereby improving security and reliability.
Patent Information
- Application Number
- CN202010890848.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-08-29
- Publication Date
- 2025-10-21
- Estimated Expiration
- 2040-08-29
AI Technical Summary
In terminal devices, there is a risk of leakage during the storage and use of keys, and the computing power limits the complexity and type of keys, resulting in insufficient security and reliability.
By entrusting the key to a second device with a secure hardware environment for processing, the first device only sends the key usage request and result, avoiding storage and computation in a secure hardware environment of its own, and using the connection status to select the optimal device for data processing.
It achieves secure storage and efficient processing of keys, avoids the risk of key leakage in insecure environments, increases the complexity of keys and the types and complexity supported, and enhances the security and reliability of terminals.
Smart Images

Figure CN114117458B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of terminal technology, and in particular to a key usage method and related products. Background Art
[0002] With the continuous advancement of electronic and computer technologies, mobile phones, tablets, smart wearable devices, and other terminals have become ubiquitous. Terminal operations such as data encryption, data integrity protection, and identity authentication rely on keys to ensure security and reliability. The complete key lifecycle includes key generation, storage, use, transmission, and destruction. Each stage carries the risk of leakage. Summary of the Invention
[0003] This application provides a key usage method and related products.
[0004] In a first aspect, an embodiment of the present application provides a method for using a key, comprising:
[0005] The first device sends a key usage request to the second device, the second device including a secure hardware environment;
[0006] The first device receives a key usage result sent by the second device, where the key usage result is obtained by the second device processing the data to be processed in the key usage request according to the key in the secure hardware environment.
[0007] In this way, during the key usage process, the key does not need to be stored on the first device that does not have a secure hardware environment, nor does the first device need to use the key to process the data to be processed. This can not only prevent the key from being cracked by the first device that does not have a secure hardware environment, but also ensure that the complexity of the key is not limited by the computing power of the first device, allowing the first device to support more types of more complex keys.
[0008] In this application, the first device may be a device that does not have a secure hardware environment. The first device may also be called a thin device, and the second device may be called a rich device.
[0009] In some embodiments, before the first device sends the key usage request to the second device, the method further includes:
[0010] The first device obtains, by the device, a connection status between one or more second devices in the device list and the first device;
[0011] The first device selects, from the one or more second devices, a second device for processing the key usage request according to a connection status between the one or more second devices and the first device;
[0012] The first device sending a key usage request to the second device includes:
[0013] The first device sends the key usage request to the second device for processing the key usage request.
[0014] In this way, the first device can select the second device with the best connection status from multiple second devices, so that the key in the second device can be used to process the data to be processed more quickly and efficiently.
[0015] In some embodiments, before the first device sends the key usage request to the second device, the method further includes:
[0016] The first device sends a key escrow request to the second device, where the key escrow request includes the key, and the key escrow request is used to request the second device to save the key.
[0017] In some embodiments, the key escrow request further includes an index of the key, and the key escrow is further used to request the second device to save the index of the key; the key usage request includes the index of the key and the data to be processed.
[0018] In this way, after generating the key, the first device can escrow the key to the second device. The second device stores the key in a secure hardware environment, thereby ensuring the storage security of the key.
[0019] In a second aspect, an embodiment of the present application provides another key usage method, including:
[0020] A second device receives a key usage request sent by the first device, the second device including a secure hardware environment;
[0021] The second device processes the data to be processed in the key usage request using the key in the secure hardware environment to obtain a key usage result;
[0022] The second device sends the key usage result to the first device.
[0023] In this way, during the key usage process, the key does not need to be stored on the first device that does not have a secure hardware environment, nor does the first device need to use the key to process the data to be processed. This can not only prevent the key from being cracked by the first device that does not have a secure hardware environment, but also ensure that the complexity of the key is not limited by the computing power of the first device, allowing the first device to support more types of more complex keys.
[0024] In some embodiments, before the second device receives the key usage request sent by the first device, the method further includes:
[0025] The second device receives a key escrow request from the first device, where the key escrow request includes the key;
[0026] The second device stores the key in the secure hardware environment.
[0027] In this way, after generating the key, the first device can escrow the key to the second device. The second device stores the key in a secure hardware environment, thereby ensuring the storage security of the key.
[0028] In some embodiments, the key escrow request further includes an index of the key; the method further includes: the second device storing the index of the key in the secure hardware environment;
[0029] The key usage request includes the index of the key and the data to be processed.
[0030] In this way, the second device can find the key to be used according to the index of the key in the key use request, thereby helping to improve the accuracy and efficiency of responding to the key use request of the first device.
[0031] In a third aspect, the present application provides an electronic device comprising a memory, one or more processors, and multiple applications. The memory stores one or more programs, and when the one or more processors run the one or more programs, the terminal executes the application processing method in any possible implementation of the first aspect.
[0032] In a fourth aspect, an embodiment of the present application provides a computer storage medium comprising computer instructions, which, when executed on a terminal, enables the terminal to execute a method for processing an application in any possible implementation of the first aspect.
[0033] In a fifth aspect, an embodiment of the present application provides a computer program product, which, when running on a terminal, enables the terminal to execute a method for processing an application in any possible implementation of the first aspect above. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 A schematic diagram of the network architecture of an embodiment of the present application;
[0035] Figure 2 A schematic diagram of the structure of a terminal provided in an embodiment of the present application;
[0036] Figure 3 A software structure diagram of the terminal provided in the embodiment of the present application;
[0037] Figure 4AA flowchart of a method for using a key according to an embodiment of the present application is shown;
[0038] Figure 4B A flowchart of another key usage method according to an embodiment of the present application;
[0039] Figure 5 A schematic diagram of a key storage method according to an embodiment of the present application;
[0040] Figure 6 This is a module diagram of the first device and the second device according to an embodiment of the present application;
[0041] Figure 7 This is another flowchart of the key storage method according to an embodiment of the present application;
[0042] Figure 8 This is another flowchart of the key usage method according to an embodiment of the present application. DETAILED DESCRIPTION
[0043] The following is a clear and detailed description of the technical solutions in the embodiments of the present application in conjunction with the accompanying drawings. In the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the text is only a description of the association relationship between related objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of the present application, "multiple" means two or more than two.
[0044] In the following, the terms "first" and "second" are used for descriptive purposes only and should not be understood to imply or suggest relative importance or implicitly indicate the number of the technical features indicated. Therefore, the features defined as "first" and "second" may explicitly or implicitly include one or more of the features. In the description of the embodiments of this application, unless otherwise specified, "plurality" means two or more.
[0045] See also Figure 1 , Figure 1 This is a network architecture diagram provided by the embodiment of this application. Figure 1 As shown, the network architecture 100 includes a first device 10 and a second device 20. One first device 10 can communicate with one or more second devices 20. The communication between the first device 10 and the second device 20 can be wireless communication or wired communication. The first device 10 and the second device 20 are both electronic devices.
[0046] The first device 10 may be, for example, a terminal. The second device 20 may be, for example, a server or a terminal. The first device 10 does not include a secure hardware environment, while the second device 20 includes a secure hardware environment.
[0047] Terminals may include but are not limited to personal computers, smart phones, smart wearable devices, tablet computers, personal digital assistants, Bluetooth speakers, Bluetooth headsets, smart home appliances, etc.
[0048] Figure 2 A schematic diagram of the structure of a terminal is shown. The terminal can be a first device or a second device.
[0049] The following embodiment is specifically described using a terminal as an example. It should be understood that Figure 2 The terminal shown is only an example and the terminal may have more Figure 2 The more or less components shown in the figure can be combined with two or more components, or can have different component configurations. The various components shown in the figure can be implemented in hardware, software, or a combination of hardware and software including one or more signal processing and / or application specific integrated circuits.
[0050] The terminal may include: a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, an earphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display 194, and a subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, an air pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0051] It should be understood that the structures illustrated in the embodiments of the present invention do not constitute specific limitations on the terminal. In other embodiments of the present application, the terminal may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0052] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU). The different processing units may be independent devices or integrated into one or more processors.
[0053] The controller can be the nerve center and command center of the terminal. It can generate operation control signals based on instruction operation codes and timing signals to complete the control of instruction fetching and execution.
[0054] Processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 110 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 110. If processor 110 needs to use the same instruction or data again, it can directly access the memory. This avoids duplicate accesses, reduces processor 110 latency, and thus improves system efficiency.
[0055] In some embodiments, the processor 110 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface.
[0056] The I2C interface is a bidirectional synchronous serial bus that includes a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C bus lines. The processor 110 may be coupled to the touch sensor 180K, the charger, the flash, the camera 193, and the like via different I2C bus interfaces. For example, the processor 110 may be coupled to the touch sensor 180K via the I2C interface, enabling communication between the processor 110 and the touch sensor 180K via the I2C bus interface, thereby implementing the touch function of the terminal.
[0057] The I2S interface can be used for audio communication. In some embodiments, the processor 110 can include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface, enabling the function of answering calls through a Bluetooth headset.
[0058] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via a PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering calls via a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0059] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial communication and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface, enabling the function of playing music through Bluetooth headphones.
[0060] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display 194 and the camera 193. MIPI interfaces include the camera serial interface (CSI) and the display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to implement the terminal's camera function. The processor 110 and the display 194 communicate via the DSI interface to implement the terminal's display function.
[0061] The GPIO interface can be configured via software. The GPIO interface can be configured as either a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to the camera 193, display 194, wireless communication module 160, audio module 170, sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0062] USB interface 130 is an interface that complies with USB standards and specifications, and may be a Mini USB interface, a Micro USB interface, a USB Type-C interface, or the like. USB interface 130 can be used to connect a charger to charge the terminal, or to transfer data between the terminal and peripheral devices. It can also be used to connect headphones to play audio. This interface can also be used to connect other electronic devices, such as augmented reality devices.
[0063] It is understood that the interface connection relationship between the modules illustrated in the embodiment of the present invention is only a schematic illustration and does not constitute a structural limitation on the terminal. In other embodiments of the present application, the terminal may also adopt a different interface connection method from the above embodiment, or a combination of multiple interface connection methods.
[0064] The charging management module 140 is used to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input via the terminal's wireless charging coil. While charging the battery 142, the charging management module 140 can also power the electronic device through the power management module 141.
[0065] The power management module 141 is used to connect the battery 142, the charging management module 140 and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, and provides power to the processor 110, the internal memory 121, the external memory, the display 194, the camera 193, and the wireless communication module 160. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance). In some other embodiments, the power management module 141 can also be set in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be set in the same device.
[0066] The wireless communication function of the terminal can be implemented through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor.
[0067] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the terminal can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0068] The mobile communication module 150 can provide solutions for wireless communications including 2G / 3G / 4G / 5G applied on the terminal. The mobile communication module 150 may include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves from the antenna 1, and filter, amplify and process the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modulation and demodulation processor, and convert it into electromagnetic waves for radiation through the antenna 1. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the processor 110. In some embodiments, at least some of the functional modules of the mobile communication module 150 can be set in the same device as at least some of the modules of the processor 110.
[0069] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, the receiver 170B, etc.) or displays an image or video through the display screen 194. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 110 and be set in the same device as the mobile communication module 150 or other functional modules.
[0070] The wireless communication module 160 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc. applied on the terminal. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive the signal to be sent from the processor 110, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0071] In some embodiments, antenna 1 of the terminal is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, so that the terminal can communicate with a network and other devices via wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology. The GNSS may include global positioning system (GPS), global navigation satellite system (GLONASS), Beidou navigation satellite system (BDS), quasi-zenith satellite system (QZSS) and / or satellite-based augmentation system (SBAS).
[0072] The terminal implements display functions through a GPU, display screen 194, and an application processor. The GPU is a microprocessor for image processing that connects display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs that execute program instructions to generate or modify display information.
[0073] Display screen 194 is used to display images, videos, and the like. Display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLED, a Micro-oLed, or a quantum dot light-emitting diode (QLED). In some embodiments, the terminal may include one or N display screens 194, where N is a positive integer greater than one.
[0074] The terminal can realize the shooting function through the ISP, camera 193, video codec, GPU, display 194 and application processor.
[0075] The ISP processes data fed back by camera 193. For example, when taking a photo, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, which is then passed to the ISP for processing and converted into a visible image. The ISP can also perform algorithmic optimization on image noise, brightness, and skin tone. It can also optimize parameters such as exposure and color temperature of the captured scene. In some embodiments, the ISP can be located within camera 193.
[0076] The camera 193 is used to capture still images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then passes the electrical signal to the ISP for conversion into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV or other format. In some embodiments, the terminal may include 1 or N cameras 193, where N is a positive integer greater than 1.
[0077] A digital signal processor (DSP) processes digital signals. Besides digital image signals, it can also process other digital signals. For example, when a terminal selects a frequency, the DSP performs a Fourier transform on the frequency energy.
[0078] Video codecs are used to compress or decompress digital video. A terminal can support one or more video codecs. This allows the terminal to play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, and MPEG4.
[0079] The NPU is a neural network (NN) computing processor. Drawing on the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it rapidly processes input information and can continuously self-learn. The NPU enables intelligent cognitive applications in terminals, such as image recognition, face recognition, speech recognition, and text comprehension.
[0080] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the terminal's storage capacity. The external memory card communicates with the processor 110 via the external memory interface 120 to implement data storage. For example, files such as music and videos can be stored on the external memory card.
[0081] The internal memory 121 can be used to store computer executable program codes, which include instructions. The processor 110 executes various functional applications and data processing of the terminal by running the instructions stored in the internal memory 121. The internal memory 121 may include a program storage area and a data storage area. Among them, the program storage area can store an operating system, an application required for at least one function (such as a sound playback function, an image playback function, etc.), etc. The data storage area can store data created during the use of the terminal (such as audio data, a phone book, etc.), etc. In addition, the internal memory 121 may include a high-speed random access memory, and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0082] The terminal can implement audio functions such as music playback and recording through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, the headphone jack 170D, and the application processor.
[0083] The audio module 170 is used to convert digital audio information into analog audio signal output, and is also used to convert analog audio input into digital audio signals. The audio module 170 can also be used to encode and decode audio signals. In some embodiments, the audio module 170 can be provided in the processor 110, or some functional modules of the audio module 170 can be provided in the processor 110.
[0084] The speaker 170A, also called a "speaker", is used to convert audio electrical signals into sound signals. The terminal can listen to music or listen to hands-free calls through the speaker 170A.
[0085] The receiver 170B, also called a "handset", is used to convert audio electrical signals into sound signals. When the terminal receives a call or voice message, the voice can be heard by placing the receiver 170B close to the ear.
[0086] Microphone 170C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 170C to input the sound signal into the microphone 170C. The terminal can be provided with at least one microphone 170C. In other embodiments, the terminal can be provided with two microphones 170C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the terminal can also be provided with three, four or more microphones 170C to realize sound signal collection, noise reduction, and can also identify the sound source to realize directional recording function, etc.
[0087] The headphone jack 170D is used to connect a wired headphone and can be the USB interface 130 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0088] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be located on display screen 194. There are many types of pressure sensors 180A, such as resistive, inductive, and capacitive. A capacitive pressure sensor can include at least two parallel plates made of conductive material. When force acts on pressure sensor 180A, the capacitance between the electrodes changes. The terminal determines the intensity of the pressure based on this change in capacitance. When a touch operation is applied to display screen 194, the terminal detects the touch operation intensity based on pressure sensor 180A. The terminal can also calculate the touch location based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch location but with different touch operation intensities can correspond to different operation instructions. For example, when a touch operation with an intensity less than a first pressure threshold is applied to a short message application icon, a command to view short messages is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to a short message application icon, a command to create a new short message is executed.
[0089] The gyroscope sensor 180B can be used to determine the motion posture of the terminal. In some embodiments, the angular velocity of the terminal around three axes (i.e., x, y, and z axes) can be determined by the gyroscope sensor 180B. The gyroscope sensor 180B can be used for anti-shake shooting. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of terminal shaking, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to offset the shaking of the terminal through reverse motion to achieve anti-shake. The gyroscope sensor 180B can also be used for navigation and somatosensory game scenes.
[0090] The air pressure sensor 180C is used to measure air pressure. In some embodiments, the terminal calculates the altitude based on the air pressure value measured by the air pressure sensor 180C to assist in positioning and navigation.
[0091] Magnetic sensor 180D includes a Hall sensor. The terminal can use magnetic sensor 180D to detect the opening and closing of the flip cover. In some embodiments, when the terminal is a flip phone, the terminal can detect the opening and closing of the flip cover based on magnetic sensor 180D. Based on the detected opening and closing status of the holster or flip cover, features such as automatic unlocking of the flip cover can be configured.
[0092] The accelerometer 180E detects the magnitude of the device's acceleration in all directions (generally three axes). When the device is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the device's posture, enabling applications such as switching between landscape and portrait modes and pedometers.
[0093] Distance sensor 180F is used to measure distance. The terminal can measure distance using infrared or laser. In some embodiments, when shooting a scene, the terminal can use distance sensor 180F to measure distance to achieve fast focus.
[0094] The proximity light sensor 180G may include, for example, a light emitting diode (LED) and a light detector, such as a photodiode. The light emitting diode may be an infrared light emitting diode. The terminal emits infrared light outward through the light emitting diode. The terminal uses a photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the terminal. When insufficient reflected light is detected, the terminal can determine that there is no object near the terminal. The terminal can use the proximity light sensor 180G to detect when the user holds the terminal close to the ear to talk, so as to automatically turn off the screen to save power. The proximity light sensor 180G can also be used in leather case mode and pocket mode to automatically unlock and lock the screen.
[0095] The ambient light sensor 180L senses ambient light brightness. The terminal can adaptively adjust the brightness of the display screen 194 based on the perceived ambient light. The ambient light sensor 180L can also be used to automatically adjust the white balance when taking photos. The ambient light sensor 180L can also work with the proximity light sensor 180G to detect whether the terminal is in a pocket to prevent accidental touches.
[0096] Fingerprint sensor 180H is used to collect fingerprints. The terminal can use the collected fingerprint characteristics to achieve fingerprint unlocking, access application locks, fingerprint photography, fingerprint answering calls, etc.
[0097] Temperature sensor 180J is used to detect temperature. In some embodiments, the terminal uses the temperature detected by temperature sensor 180J to implement a temperature handling strategy. For example, when the temperature reported by temperature sensor 180J exceeds a threshold, the terminal reduces the performance of a processor located near temperature sensor 180J to reduce power consumption and implement thermal protection. In other embodiments, when the temperature is below another threshold, the terminal heats battery 142 to prevent abnormal shutdown of the terminal due to low temperature. In other embodiments, when the temperature is below yet another threshold, the terminal boosts the output voltage of battery 142 to prevent abnormal shutdown due to low temperature.
[0098] The touch sensor 180K is also called a "touch panel." The touch sensor 180K can be provided on the display screen 194. The touch sensor 180K and the display screen 194 form a touch screen, also called a "touch screen." The touch sensor 180K is used to detect touch operations applied on or near the touch sensor. The touch sensor can transmit the detected touch operations to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through the display screen 194. In other embodiments, the touch sensor 180K can also be provided on the surface of the terminal, in a location different from that of the display screen 194.
[0099] The bone conduction sensor 180M can obtain vibration signals. In some embodiments, the bone conduction sensor 180M can obtain vibration signals from the vibrating bones of the human body. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure pulse signals. In some embodiments, the bone conduction sensor 180M can also be set in headphones to form bone conduction headphones. The audio module 170 can parse out voice signals based on the vibration signals of the vibrating bones of the human body obtained by the bone conduction sensor 180M to implement voice functions. The application processor can parse heart rate information based on the blood pressure pulse signals obtained by the bone conduction sensor 180M to implement heart rate detection functions.
[0100] Keys 190 include a power button, a volume button, etc. Keys 190 may be mechanical keys or touch keys. The terminal may receive key inputs and generate key signal inputs related to user settings and function control of the terminal.
[0101] Motor 191 can generate vibration prompts. Motor 191 can be used for incoming call vibration prompts, and can also be used for touch vibration feedback. For example, touch operations acting on different applications (such as taking pictures, audio playback, etc.) can correspond to different vibration feedback effects. For touch operations acting on different areas of the display screen 194, motor 191 can also correspond to different vibration feedback effects. Different application scenarios (for example: time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.
[0102] The indicator 192 may be an indicator light, which may be used to indicate the charging status, power level changes, messages, missed calls, notifications, etc.
[0103] The SIM card interface 195 is used to connect a SIM card. The SIM card can be connected to and separated from the terminal by inserting it into or removing it from the SIM card interface 195. The terminal can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, and the like. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The terminal interacts with the network through the SIM card to implement functions such as calls and data communications. In some embodiments, the terminal uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the terminal and cannot be separated from the terminal.
[0104] The software system of the terminal can adopt a layered architecture, an event-driven architecture, a micro-kernel architecture, a micro-service architecture, or a cloud architecture. The embodiment of the present invention takes the Android system of the layered architecture as an example to exemplify the software structure of the terminal.
[0105] Figure 3 It is a software structure block diagram of the terminal according to an embodiment of the present invention.
[0106] A layered architecture divides software into several layers, each with distinct roles and responsibilities. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer.
[0107] The application layer can include a series of application packages.
[0108] The application framework layer provides an application programming interface (API) and programming framework for the applications in the application layer. The application framework layer includes some predefined functions.
[0109] like Figure 3 As shown, the application framework layer may include a window manager, a content provider, a view system, a phone manager, a resource manager, a notification manager, and the like.
[0110] The window manager is used to manage window programs. The window manager can obtain the display size, determine whether there is a status bar, lock the screen, take screenshots, etc.
[0111] Content providers are used to store and retrieve data and make it accessible to applications. The data may include videos, images, audio, calls made and received, browsing history and bookmarks, phone books, etc.
[0112] The view system includes visual controls, such as those for displaying text and images. The view system is used to build applications. A display interface can consist of one or more views. For example, a display interface containing a text notification icon might include a view for displaying text and a view for displaying images.
[0113] The phone manager is used to provide terminal communication functions, such as call status management (including answering, hanging up, etc.).
[0114] The resource manager provides various resources for applications, such as localized strings, icons, images, layout files, video files, and so on.
[0115] The Notification Manager allows applications to display notifications in the status bar. These messages can be displayed briefly and then disappear automatically without user interaction. For example, the Notification Manager is used to notify users of completed downloads and message reminders. The Notification Manager can also display notifications in the top status bar of the system as icons or scrolling text, such as notifications from background applications, or as dialog windows on the screen. Examples include text messages in the status bar, beeps, vibrations on electronic devices, and flashing indicator lights.
[0116] Android Runtime includes core libraries and a virtual machine. Android runtime is responsible for scheduling and management of the Android system.
[0117] The core library consists of two parts: one is the function that needs to be called by the Java language, and the other is the Android core library.
[0118] The application layer and application framework layer run in the Android virtual machine (DALVIK). The Android virtual machine executes Java files from the application layer and application framework layer as binary files. The Android virtual machine is responsible for performing functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0119] The system library can include multiple functional modules, such as surface manager, media library, 3D graphics processing library (such as OpenGL ES), 2D graphics engine (such as SGL), etc.
[0120] The surface manager is used to manage the display subsystem and provide fusion of 2D and 3D layers for multiple applications.
[0121] The media library supports playback and recording of a variety of common audio and video formats, as well as static image files. The media library can support a variety of audio and video encoding formats, such as: MPEG4, H.264, MP3, AAC, AMR, JPG, PNG, etc.
[0122] The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, compositing, and layer processing.
[0123] A 2D graphics engine is a drawing engine for 2D drawings.
[0124] The kernel layer is the layer between hardware and software. The kernel layer includes at least display driver, camera driver, audio driver, and sensor driver.
[0125] In the prior art, key management solutions include local key management solutions and key management solutions that rely on cloud interaction.
[0126] In local management solutions, a multi-tiered key management scheme is employed, from a root key to a working key. The root key is composed of key components. When storing the key, root key protection relies on hard-coding the key components. Key components are stored in a distributed manner in local storage. When using the key, the key is first recovered from the key components and then used to encrypt the data to be encrypted. However, this scheme, where the key components are hard-coded, does not protect against decompilation. Unauthorized users can decompile the password and obtain the key components and their assembly, thereby cracking the key.
[0127] In key management solutions that rely on cloud-based interaction, terminals can store keys on cloud servers. This ensures the security of the keys during storage, but the computing power of terminal devices is limited. When using keys, terminals need to use them for encryption and decryption operations, and this limited computing power limits the types of keys they support.
[0128] The present invention provides a key protection scheme based on Figure 1 In the network architecture shown, a first device is associated with one or more second devices. The first device can be understood as a thin device, and the second device can be understood as a rich device. A rich device is a device with a secure hardware environment, while a thin device is a device without a secure hardware environment.
[0129] During the key storage process, the first device stores the key on multiple second devices. When the first device needs to use the key, for example, when the first device needs to use the key to encrypt data to be encrypted, the encrypted data can be sent to the second device. The second device encrypts the data to be encrypted using the stored key and then sends the encrypted data to the first device. In this way, the first device can obtain the encrypted data from the second device. Even if the first device does not have a secure hardware environment, since the key is not stored on the first device, it can prevent an unauthorized user from stealing and decompiling the key. Moreover, the encryption process is implemented on the second device, so the complexity of the key is not limited by the computing power of the first device, thereby supporting more and more complex key types.
[0130] In this application, the first device may be understood as a thin device, and the second device may be understood as a rich device.
[0131] The first device may be, for example, a terminal device that does not have a secure hardware environment. Specifically, the first device may be, for example, but not limited to, a smart speaker, a smart home appliance, a mobile phone that does not have a secure hardware environment, a media player, and the like.
[0132] The second device may be, for example but not limited to, a server, a mobile phone with a secure hardware environment, a personal computer, a tablet computer, etc.
[0133] In one possible implementation, the secure hardware environment is a trusted execution environment (TEE). For example, the second device includes a trusted execution environment (TEE) and a rich execution environment (REE). The TEE provides a secure environment for trusted applications (TAs), while also protecting the confidentiality, integrity, and access rights of TA resources and data. The terminal's operating system, such as the Android system, runs in the rich execution environment (REE).
[0134] In another possible implementation, the secure hardware environment is Software Guard Extensions (SGX). SGX is a secure hardware environment on Intel chips.
[0135] In another possible implementation, the secure hardware environment is a secure enclave processor (SEP). The second device may include a hardware environment for running an iOS system and the SEP.
[0136] The technical solution of this application is described in detail below in conjunction with the key usage method.
[0137] like Figure 4A The key usage method of the embodiment of the present application includes the following steps:
[0138] 401. A first device sends a key usage request to a second device, where the second device includes a secure hardware environment.
[0139] The first device is a terminal device on the user side, and the second device can be a terminal device, or a server or a cloud device. The first device and the second device can communicate with each other via wired or wireless communication.
[0140] Specifically, the first device sends a key usage request to the second device according to the key usage request of the service module.
[0141] The key usage request includes data to be processed. The data to be processed can be understood as the object of key usage. Optionally, the key usage request may also include at least one of an identifier of the first device, a key index, parameters required for key usage, an identifier of a service module, and a key usage operation.
[0142] The key usage operation may be, for example, but not limited to, a key usage step such as requesting encryption or decryption of data to be processed, requesting certificate generation or certificate verification.
[0143] The business module is used to implement the functional business of the first device. For example, the smart speaker can implement the business function of voiceprint encryption, but the smart speaker does not have a secure hardware environment. The smart speaker uses a key to encrypt the voiceprint and save the key, which may cause the key to be stolen. Then, using the technical solution of the present application, when the smart speaker needs to use a key to encrypt the voiceprint and save the key, after generating the key, it can send a key usage request to the second device. The key usage request includes data to be processed, and the data to be processed may include the voiceprint to be encrypted. The second device includes a secure hardware environment, so the voiceprint can be encrypted using the key stored in the second device. The key stored in the second device may be sent by the first device to the second device.
[0144] 402. The second device processes the key usage request according to the key usage request using the key stored in the secure hardware environment to obtain a key usage result.
[0145] Specifically, the second device processes the data to be processed using the key stored in the secure environment to obtain a key usage result.
[0146] For example, if the key usage request is to encrypt a voiceprint, the second device may use the key stored in the secure environment to encrypt the voiceprint and obtain a key usage result, which includes the encrypted voiceprint. Of course, the key usage result may also include whether the key usage result is successful or failed, and the key usage result may also include other information.
[0147] Optionally, the key usage request may include verification information of the first device. The second device may verify the legality of the key usage request sent by the first device based on the verification information of the first device, and then process the data to be encrypted to obtain a key usage result.
[0148] 403. The second device sends the key usage result to the first device.
[0149] The key usage result may include data obtained after executing the key usage step on the data to be processed, and may also include result information such as whether the key usage step is executed normally.
[0150] In this way, the second device can send the key usage result to the first device. For example, after the second device encrypts the voiceprint, it sends the encrypted voiceprint to the first device.
[0151] The first device can then obtain the encrypted voiceprint.
[0152] It can be seen that in the technical solution of the present application, the first device that does not have a secure hardware environment can entrust the key to the second device that has a secure hardware environment. When the first device needs to use the key, it can send a key usage request to the second device. The key usage request includes the data to be processed, and the data to be processed can be understood as the key usage object. After the second device uses the key stored in the secure environment to process the data to be processed, it obtains the key usage result and sends the key usage result to the first device. In this way, during the key usage process, there is no need to store the key in the first device that does not have a secure hardware environment, nor is there any need for the first device to use the key to process the data to be processed. This can not only prevent the key from being cracked when it is stored in the first device that does not have a secure hardware environment, but also make the complexity of the key not limited by the computing power of the first device, so that the first device can support more types and more complex keys.
[0153] Optional, such as Figure 4B As shown in the flowchart, before step 401, the key usage method may further include the following steps:
[0154] 404. The first device checks the connection status of one or more second devices in the device list, and selects a second device from the one or more devices in the device list for processing the key usage request. In step 401, the first device may send a key usage request to the second device selected for processing the key usage request.
[0155] The first device stores a device list and an association relationship. The device list includes an identifier of a second device that has a connection relationship with the first device and stores a key of the first device. The association relationship includes a connection mode between each second device in the device list and the first device.
[0156] For example, the device list may include the identifiers of second device 1, 2, 3, and 4, which are associated with the first device and store the key of the first device. The associations include: the association between the first device and second device 1 is a Bluetooth link, the association between the first device and second device 2 is a Bluetooth link, the association between the first device and second device 3 is a WiFi connection, and the association between the first device and second device 4 is a wired connection.
[0157] When a first device obtains the connection status of one or more second devices in a device list, it first determines whether each second device in the device list can properly connect to the first device according to the connection method in the stored association relationship. The first device then selects the second device with the best connection status from among the second devices that can properly connect. The second device with the best connection status can be, for example, the second device that first responds to the connection request or the second device with the highest security level for the connection method with the first device.
[0158] If the first device selects the second device k according to the above selection method, the first device sends a key usage request to the second device k.
[0159] In this way, the first device can select the second device with the best connection status from multiple second devices, so that the key in the second device can be used to process the data to be processed more quickly and efficiently.
[0160] It should be understood that steps 401-404 are steps in the process of using the key. Before using the key, the first device may escrow the key to the second device. In other words, before using the key, the first device may send the key to the second device, which will then store the key in a secure hardware environment.
[0161] Specifically, before using the key, the key usage method of the embodiment of the present application may further include a key trusteeship step, which may also be understood as a key storage step, such as Figure 5 As shown in the flowchart, the steps of key escrow may include:
[0162] 501. A first device generates a key;
[0163] Specifically, the first device generates a key based on a service request from a service module. Specifically, the first device generates a key based on key parameters input by the service. The key parameters may be, for example, plain text provided by the service module, which the first device encrypts to obtain the key.
[0164] 502. The first device sends a key escrow request to the second device, where the key escrow request includes a key.
[0165] After generating the key, the first device sends a key escrow request to the second device to escrow the key to the second device.
[0166] Specifically, the key escrow request may also include a key index, or an index of an escrow key, so that when a subsequent business module needs to use the key, the first device and the second device can determine which key the business module needs to use based on the key index.
[0167] Optionally, the key escrow request may further include an identifier of the first device, so that the second device can identify which first device sent the key based on the key escrow request.
[0168] Optionally, the key escrow request may further include a service identifier corresponding to the service module. In this way, the second device can identify which service module corresponds to the key based on the service identifier in the key escrow request.
[0169] 503. The second device stores the received key;
[0170] Specifically, the second device stores the key in a secure hardware environment.
[0171] Optionally, the second device includes a device list and an association relationship. The device list of the second device includes the identifiers of multiple first devices, where the identifier of a first device in the device list of the second device is the identifier of a first device that has a communication connection relationship with the second device and hosts the key stored by the second device. The association relationship stored on the second device includes the connection method between each first device in the device list and the second device.
[0172] For example, the device list of the second device includes the identifier of first device 1, the identifier of first device 2, the identifier of first device 3, and the identifier of first device 4. The second device also stores that the association relationship between the first device 1 and the second device is relation_1, the association relationship between the first device 2 and the second device is relation_2, the association relationship between the first device 3 and the second device is relation_3, and the association relationship between the first device 4 and the second device is relation_4.
[0173] If the first device that sends the key is the first device 5, and the connection method between the first device 5 and the second device is WiFi connection, the second device adds the identifier of the first device 5 to the device list and stores the association relationship between the first device 5 and the second device as WiFi connection.
[0174] In this way, after generating the key, the first device can escrow the key to the second device. The second device stores the key in a secure hardware environment, thereby ensuring the storage security of the key.
[0175] The association between the first device and the second device during the key escrow phase is the same as the association between the first device and the second device during key usage. During the key usage phase, the second device can determine the communication method with the first device based on the association in the device list stored on the second device.
[0176] Optionally, the key escrow step may further include:
[0177] 504. The second device sends a hosting completion notification message to the first device.
[0178] In this way, after storing the key, the second device notifies the first device that the key has been successfully stored by sending a trusteeship completion notification message. The first device confirms that the trusteeship of the key has been completed according to the trusteeship completion notification message.
[0179] Specifically, if Figure 6 As shown, in the technical solution of the present application, the first device and the second device both include a key escrow logic processing module, a local key management module, a device connection module and a device association relationship storage module.
[0180] The key escrow logic processing module is used to connect with upper-layer business and lower-layer functional modules, and is specifically used for the logical processing of key escrow and usage processes.
[0181] The local key management module is used to handle processes related to key lifecycle management, such as key generation, key storage, key usage, and key destruction.
[0182] The device connection module includes a device connection status sensing submodule and a connection mode processing module. The device connection status sensing submodule is used to sense the connection status between the local device and the rich devices in the managed device list. The connection mode processing module is used to manage the connection between the first device and the second device.
[0183] The device association relationship storage module is used to store the device list and the association relationship between each device in the device list and itself.
[0184] In order to better describe the technical solution of this application, the following is based on Figure 6 The module structure of the first device and the second device shown is combined with the key storage method and the key usage method to elaborate the technical solution of the present application.
[0185] like Figure 7 The key storage method of the embodiment of the present application includes the following steps:
[0186] 701. The key escrow logic processing module of the first device UDID_S receives a key escrow request sent by the business module;
[0187] When the service module of the first device needs to generate and store a key, it sends a key escrow request to the key escrow logic processing module of the first device. The escrow request may include key parameters for generating the key. For example, the key parameters may be plain text, so that the local key management module can generate the key based on the plain text.
[0188] Optionally, the service module may specify a key index keyAlias, a device list, and an association relationship. The association relationship may be understood as a communication connection method between the first device and the second device.
[0189] For example, the service module may specify that the device list includes second device 1 (UDID_1), second device 2 (UDID_2), second device 3 (UDID_3), and second device 4 (UDID_4), and indicate the connection relationships between second device 1-second device 4 and the first device respectively.
[0190] Specifically, the business module may specify the index keyAlias of the managed key, and input a specified managed device list and corresponding association relationships {(UDID_1, relation_1), (UDID_2, relation_2)...}.
[0191] 702. The key escrow logic processing module of the first device sends a key generation request to the local key management module;
[0192] After the key escrow logic processing module of the first device receives the key escrow request from the business module, the key escrow logic processing module of the first device sends a key generation request to the local key management module. The key generation request includes key parameters keyParams for generating a key.
[0193] 703. The local key management module of the first device generates a key according to the key generation request.
[0194] The local key management module of the first device generates a key according to the key parameters keyParams in the key generation request and the key generation algorithm.
[0195] 704. The local key management module of the first device sends the generated key to the key escrow logic processing module of the first device.
[0196] 705. The key escrow logic processing module of the first device sends a key escrow request to the device connection module of the first device, and requests that the key generated by the local key management module be saved to the second device.
[0197] After obtaining the key generated by the local key management module, the key escrow logic processing module of the first device initiates a key escrow request to the device connection module of the first device to initiate the key escrow process.
[0198] 706. The key management logic processing module of the first device sends the device list and association relationships to the association relationship storage module of the first device.
[0199] In this way, the association relationship storage module of the first device stores the device list and the association relationship.
[0200] Specifically, the association relationship storage module of the first device stores keyAlias_UDID_S_{(UDID_1, relation_1), (UDID_2, relation_2) . . .
[0201] 707. The device connection module of the first device reads the device list and association relationships stored in the device association relationship storage module, and sends a key escrow request to at least one second device in the device list, where the key escrow request includes the key.
[0202] The device connection module of the first device sends a key escrow request to at least one second device in the device list according to the association relationship, so as to escrow the key.
[0203] For example, the device connection module of the first device sends a key escrow request to UDID_1 through relation_1.
[0204] The key escrow request may further include at least one of a key index, an identifier of the first device, and an identifier of a service module.
[0205] 708. The device connection module of the second device receives the key escrow request sent by the device connection module of the first device, and sends the key escrow request to the key escrow logic processing module of the second device.
[0206] After receiving the key escrow request, the device connection module of the second device sends the key escrow request to the key escrow logic processing module of the second device for processing.
[0207] 709. The key escrow logic processing module of the second device sends the key escrow request to the local key management module of the second device.
[0208] 710. The local key management module of the second device receives and stores the key.
[0209] The local key management module of the second device stores the key in a secure hardware environment of the second device.
[0210] In this way, the key generated by the first device is managed by the local key management module stored by the second device.
[0211] 711. The key escrow logic processing module of the second device sends the association relationship between the second device and the first device to the device association relationship storage module of the second device.
[0212] The association relationship between the second device and the first device includes a communication connection mode between the second device and the first device.
[0213] Optionally, step 711 and step 709 may be performed in parallel.
[0214] That is to say, while the key hosting logic processing module of the second device sends the key to the local key management module, it can also send the association relationship between the second device and the first device to the device association relationship storage module of the second device, so that the device association relationship storage module stores the association relationship between the first device and the second device.
[0215] 712. The device association relationship storage module of the second device stores the association relationship between the first device and the second device.
[0216] The association relationship between the first device and the second device is a communication connection method between the first device and the second device.
[0217] The association relationship can be stored in a secure hardware environment of the second device, which can more comprehensively ensure the security of data related to the key, thereby improving the security of the key.
[0218] For example, the device association relationship storage module of the second device i may store any one of UDID_S_UDID_i, relation_i, i=1, 2, 3, and 4.
[0219] 713. The key escrow logic processing module of the second device sends an escrow completion notification to the device connection module of the second device.
[0220] 714. The connection management module of the second device sends a trusteeship completion notification to the device connection module of the first device.
[0221] In this way, through the above-mentioned steps of storing the key, the first device can host the generated key in the secure hardware environment of the second device, thereby ensuring the security during the key storage period.
[0222] Optionally, the device connection module of the first device may send the key completion notification to the key escrow logic processing module of the first device.
[0223] like Figure 8 The flowchart of the key usage method shown in FIG. 1 is a flowchart of the key usage method of the embodiment of the present application, which includes the following steps:
[0224] 801. A key escrow logic processing module of a first device receives a key usage request sent by a business module of the first device, where the key usage request includes data to be processed. The data to be processed can be understood as data of a key usage object.
[0225] Optionally, the key usage request also includes parameters required for key usage, so that the second device can complete the key usage steps according to the key, the parameters required for key usage, and the data to be processed.
[0226] Optionally, the key usage request may further include an index keyAlias of the escrow key, so that the second device that escrows the key can determine the key to be used based on the index keyAlias.
[0227] When the service module of the first device needs to use a key, it sends a key usage request to the key escrow logic processing module of the first device. For example, when the service module for voiceprint recognition needs to encrypt a voiceprint, it can send a key usage request to the key escrow logic processing module of the first device to encrypt the voiceprint using the key. The voiceprint that needs to be encrypted can be understood as the data to be processed, the data for key usage, or the parameters required for key usage.
[0228] 802. The key escrow logic processing module of the first device sends a key usage request to the device connection module.
[0229] The key escrow logic processing module sends the key usage request sent by the business module to the device connection module of the first device.
[0230] 803. The device connection module of the first device obtains a device list and association relationships from the association relationship storage module of the first device.
[0231] For example, the association relationship storage module of the first device stores keyAlias_UDID_S_{(UDID_1, relation_1), (UDID_2, relation_2)...}. The connection module of the first device can obtain keyAlias_UDID_S_{(UDID_1, relation_1), (UDID_2, relation_2)...} stored in the association relationship storage module, thereby obtaining a device list and association relationship corresponding to the key indexed as keyAlias.
[0232] 804. The device connection module of the first device determines a second device for processing the key usage request according to the device list and the association relationship.
[0233] Specifically, the connection mode processing unit of the device connection module checks the connection status of one or more second devices in the device list, and selects a second device for processing the key usage request from the one or more devices in the device list.
[0234] The scheme for the device connection module to select the second device for processing the key usage request can be referred to the relevant description in the explanation of the above step 404 and will not be described in detail here.
[0235] For example, the device connection status perception unit of the device connection module determines the local connection status, and checks one by one whether each second device (UDID_i) in the device list can be connected through the specified connection relationship relation_i (i is 1, 2, 3, 4, ... n, and selects the optimal connection mode relation_k and the optimal second device UDID_k according to the available connection status of each device. The optimal connection mode includes but is not limited to the device that responds first, the connection mode with the highest security level, etc. relation_k is one of relation_1, relation_2, relation_3, ..., relation_n.
[0236] 805. The device connection module of the first device sends a key usage request to the second device for processing the key usage request.
[0237] Optionally, the key usage request includes a key index, data to be processed, and parameters required for key usage. The parameters required for key usage can be understood as algorithm parameters related to key usage.
[0238] 806. The device connection module of the second device receives the key usage request sent by the first device, and sends the key usage request to the key escrow logic processing module of the second device.
[0239] It can be understood that the device connection module of the second device forwards the received key usage request to the key escrow logic processing module of the second device.
[0240] 807. The key escrow logic processing module of the second device obtains the stored association relationship from the device association relationship storage module.
[0241] For example, the key logic hosting processing module of the second device can determine the key to be used based on the key usage request, and determine the first device corresponding to the key and the connection relationship between the second device and the first device based on the device list and association relationship stored in the device association relationship storage module.
[0242] 808. The key escrow logic processing module of the second device verifies whether the key usage request is reasonable.
[0243] Specifically, the key escrow logic processing module of the second device verifies whether the first device that sent the key usage request has the authority to request the second device to process the key usage request. For example, the key usage request may include the identifier of the first device. Based on the identifier of the first device, the key escrow logic module of the second device may verify whether the first device is a device in the device list and whether the connection method between the first device and the second device complies with the stored association relationship between the first device and the second device. If the first device is a device in the device list and the connection relationship between the first device and the second device also complies with the stored association relationship between the first device and the second device, the key usage request is verified to be reasonable.
[0244] Step 808 and step 807 may be executed in parallel, or step 808 may be executed first and then step 807, or step 807 may be executed first and then step 808.
[0245] 809. When the key usage request is reasonable, the key escrow logic processing module of the second device sends the data to be processed in the key usage request and the parameters required for key usage to the local key management module of the second device.
[0246] Optionally, the key escrow logic processing module of the second device may further send a key index to the local key management module of the second device, so that the local key management module of the second device can accurately determine which stored key to use to process the pending data.
[0247] 810. The local key management module of the second device executes a key usage step, processes the data to be processed using the stored key and parameters required for key usage, and obtains a key usage result.
[0248] The key usage steps may include encryption, decryption, signing, signature verification, etc. Based on the example of the data to be processed being a voiceprint to be encrypted, the local key management module of the second device may encrypt the voiceprint to be encrypted using the key and related algorithm parameters hosted by the first device.
[0249] The key usage result may include data obtained after executing the key usage step on the data to be processed, and may also include result information such as whether the key usage step is executed normally.
[0250] 811. The local key management module of the second device sends the key usage result to the key escrow logic processing module of the second device.
[0251] 812. The key escrow logic processing module of the second device sends the key usage result to the device connection module.
[0252] 813. The device connection module of the second device sends the key usage result to the device connection module of the first device.
[0253] 814. The device connection module of the first device sends the key usage result to the key escrow logic processing module of the first device.
[0254] 815. The key escrow logic processing module of the first device feeds back the key usage result to the business module.
[0255] Through steps 810 to 815, the second device feeds back the key usage result to the first device, so that the service module that sent the key usage request can obtain the key usage result, completing the key usage process.
[0256] It can be seen from this that the technical solution of the present application is that the first device stores the key on the second device that has been connected and authenticated, and uses the secure hardware environment of the second device to store the key. The first device sends the parameters required for the use of the key and the data to be processed to the second device, and uses the key with the help of the computing power of the second device, or in other words, uses the key to process the data to be processed with the help of the computing power of the second device. In this way, the key is hosted on the second device with a secure hardware environment, which can ensure the security of the key storage; moreover, the keys that can be used by the first device can break through the limitations of the computing power of the first device itself, making the types of keys that can be used by the first device more diverse.
[0257] An embodiment of the present application provides a computer storage medium including computer instructions. When the computer instructions are executed on a terminal, the terminal executes the processing method of the application in any possible embodiment described above.
[0258] An embodiment of the present application provides a computer program product. When the computer program product is run on a terminal, the terminal executes the method for processing an application in any possible embodiment described above.
[0259] As described above, the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present application.
Claims
1. A key usage method, characterized in that: include: The first device obtains a connection status between one or more second devices in the device list and the first device; The first device selects, from the one or more second devices, a second device for processing the key usage request according to a connection status between the one or more second devices and the first device; The first device sends a key usage request to the selected second device, where the second device includes a secure hardware environment, and the key usage request includes at least one of the following: data to be processed, an identifier of the first device, an index of a key, parameters required for key usage, an identifier of a service module, and a key usage operation; The first device receives a key usage result sent by the second device, where the key usage result is obtained by the second device processing the data to be processed in the key usage request according to the key in the secure hardware environment, where the key is a key corresponding to the business module, and the key is a key generated by the first device according to the key parameters input by the business and sent to the second device.
2. The method according to claim 1, characterized in that Before the first device sends the key usage request to the second device, the method further includes: The first device sends a key escrow request to the second device, where the key escrow request includes the key, and the key escrow request is used to request the second device to save the key.
3. The method according to claim 2, characterized in that The key escrow request also includes an index of the key, and the key escrow is further used to request the second device to save the index of the key; the key usage request includes the index of the key and the data to be processed.
4. A method for using a key, characterized in that include: The second device receives a key usage request sent by the first device, where the second device includes a secure hardware environment, and the key usage request includes at least one of the following: data to be processed, an identifier of the first device, an index of a key, parameters required for key usage, an identifier of a service module, and a key usage operation, and the second device is selected by the first device based on a connection status between one or more second devices in a device list and the first device; The second device processes the data to be processed in the key usage request using the key in the secure hardware environment to obtain a key usage result, where the key is a key corresponding to the business module and is generated by the first device according to the key parameters input by the business and sent to the second device; The second device sends the key usage result to the first device.
5. The method according to claim 4, characterized in that Before the second device receives the key usage request sent by the first device, the method further includes: The second device receives a key escrow request from the first device, where the key escrow request includes the key; The second device stores the key in the secure hardware environment.
6. The method according to claim 5, characterized in that The key escrow request further includes an index of the key; the method further includes: the second device storing the index of the key in the secure hardware environment; The key usage request includes the index of the key and the data to be processed.
7. An electronic device comprising a memory, one or more processors, and a plurality of applications, wherein: One or more programs are stored in the memory; it is characterized in that when the one or more processors run the one or more programs, the electronic device executes the method according to any one of claims 1 to 6.
8. A computer storage medium, characterized in that The method comprises computer instructions, which, when executed on a terminal, cause the terminal to execute the method according to any one of claims 1 to 6.
9. A computer program product, characterized in that When the computer program product is run on a terminal, the terminal is enabled to execute the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Encryption machine key injection system based on cloud environment, method and device
CN106161402A
Data encryption method and decryption method and wireless router
CN107454590A