Access authorization method, device, terminal and storage medium
By encrypting user identity information in the TEE and decrypting it in the SIM card, the security risks of information transmission between the TEE and the SIM card are resolved, and a secure access authorization process is achieved.
Patent Information
- Application Number
- CN202110298419.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-03-19
- Publication Date
- 2025-12-09
- Estimated Expiration
- 2041-03-19
AI Technical Summary
Information security risks exist when authorizing SIM card access in the terminal environment, especially the risk of password tampering or theft during information transmission between TEE and SIM card.
In the TEE, the received first information representing the user's identity is encrypted based on the first TA setting to obtain the second information. The first information is then decrypted in the SIM card based on the second TA setting to obtain the first information. The first information is verified by the SIM card application to determine whether to authorize access to the terminal application.
By encrypting the transmission between the TEE and the SIM card, the risk of information leakage is reduced, information security risks are avoided, and the security of the access authorization process is ensured.
Smart Images

Figure CN115175179B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and in particular to an access authorization method and device, a terminal and a storage medium. BACKGROUND
[0002] A subscriber identity module (SIM) is an important physical identity of a user's mobile identity. A SIM card, as a secure carrier with spatial openness, can carry various card applications and provide various services for users through terminal applications. However, due to various security risks in the terminal environment, there are information security risks when the SIM card is accessed and authorized. SUMMARY
[0003] To solve the problems in the related art, the present application provides an access authorization method, device, terminal and storage medium.
[0004] The technical solution of the present application is implemented as follows:
[0005] The present application provides an access authorization method, which includes the following steps.
[0006] In the case that a terminal application initiates a first request, a first information received is encrypted in a trusted execution environment (TEE) based on a first set of trusted applications (TA), to obtain a second information; wherein the first request is used to request access to a subscriber identity module (SIM) card application; and the first information represents a user identity.
[0007] The second information is decrypted in the SIM card based on a second set of TAs to obtain the first information.
[0008] The first information is verified by the SIM card application, to determine whether to authorize the terminal application to access the SIM card application according to the verification result.
[0009] In an embodiment, a first public key and a second public key used for encryption and decryption are pre-set in the TEE and the SIM card; the first public key is generated by a first trusted service manager (TSM) corresponding to the TEE; and the second public key is generated by a second TSM corresponding to the SIM card.
[0010] Before the terminal application initiates the first request, the method further includes the following steps.
[0011] loading, by a first TSM in the TEE, a first private key corresponding to the first public key to the first provisioning TA, and loading, by a second TSM in the SIM card, a second private key corresponding to the second public key to the second provisioning TA.
[0012] In an embodiment, before the encrypting, in the TEE, the received first information based on the first provisioning TA, the method further comprises:
[0013] receiving, in the TEE, the first information based on a third provisioning TA; wherein,
[0014] the third provisioning TA is used for receiving, in the TEE, the first information input by a user.
[0015] In an embodiment, before the receiving, in the TEE, the first information based on the third provisioning TA, the method further comprises:
[0016] after the terminal application initiates the first request, sending, by the terminal application, a second request to a SIM card access agent in a rich execution environment (REE); the second request is used for requesting a user to input the first information;
[0017] sending, by the SIM card access agent, the second request to the TEE.
[0018] In an embodiment, the method further comprises:
[0019] sending, by the SIM card access agent in the REE, the second information generated by the first provisioning TA to the SIM card.
[0020] In an embodiment, the method further comprises:
[0021] sending the verification result to the SIM card access agent in the REE;
[0022] sending, by the SIM card access agent, the verification result to the terminal application.
[0023] Embodiments of the present application also provide an access authorization apparatus, comprising:
[0024] a TEE module, configured to, in the case that a terminal application initiates a first request, encrypt, in the TEE, received first information based on a first provisioning TA, to obtain second information; wherein the first request is used for requesting access to a SIM card application; and the first information represents a user identity.
[0025] a SIM card module configured to decrypt the second information based on a second configured TA in the SIM card to obtain the first information, and verify the first information by the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
[0026] The embodiment of the present application further provides a terminal, which comprises a first processor and a first communication interface, wherein,
[0027] The first processor is configured to, in the case that a terminal application initiates a first request, perform an encryption operation on the received first information based on a first configured TA in the TEE to obtain second information, decrypt the second information based on a second configured TA in the SIM card to obtain the first information, and verify the first information by the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
[0028] The first request is used for requesting to access the SIM card application, and the first information represents a user identity.
[0029] The embodiment of the present application further provides a terminal, which comprises a first processor and a first memory for storing a computer program capable of running on the processor,
[0030] The first processor is configured to execute the steps of the method in any of the above embodiments when the computer program is run.
[0031] The embodiment of the present application further provides a storage medium having a computer program stored thereon, and the computer program is configured to implement the steps of the method in any of the above embodiments when executed by a processor.
[0032] The authorization access method and device, the terminal and the storage medium provided by the embodiment of the present application are used for, in the case that a terminal application initiates a first request for requesting to access a SIM card application, performing an encryption operation on the received first information representing a user identity based on a first configured TA in the TEE to obtain second information, then decrypting the second information based on a second configured TA in the SIM card to obtain the first information, and verifying the first information by the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result. In the above access authorization process, the first information representing the user identity is encrypted and transmitted between the TEE and the SIM card, which reduces the information leakage risk when the information is transmitted between the TEE and the SIM card, and avoids the information security risk. BRIEF DESCRIPTION OF DRAWINGS
[0033] Figure 1 It is a schematic diagram of a terminal architecture of the related art.
[0034] Figure 2 An implementation flowchart of a method for authorizing access of an embodiment of the present application;
[0035] Figure 3 A terminal architecture diagram of an embodiment of the present application;
[0036] Figure 4 An implementation flowchart of a method for authorizing access of an embodiment of the present application;
[0037] Figure 5 A device structure diagram of an embodiment of the present application;
[0038] Figure 6 A terminal structure diagram of an embodiment of the present application. DETAILED DESCRIPTION
[0039] A SIM card and a Universal Subscriber Identity Module (USIM) card are important physical identities of a user's mobile identity. The SIM card, as a secure carrier with spatial openness, can carry various SIM card applications developed by operators and third-party application developers in cooperation, and provide various services for users through terminal applications. At present, there are various security risks in the terminal environment, including privacy leakage, authentication risk, transaction network and malicious software, phishing websites, etc. When a terminal application accesses a SIM card, the terminal cannot provide a secure environment, and there is a potential information security risk. For example, when a bank application performs a transfer transaction based on a bank certificate stored in a SIM card, a password needs to be input to the SIM card. Referring to Figure 1 In the related art, password input is performed in the TEE, but since there is no communication interface between the TEE and the SIM card, the password input in the TEE needs to be input to the SIM card again through the REE, and there is a risk of password tampering or theft in this process.
[0040] Therefore, in the embodiments of the present application, in the case that a terminal application initiates a first request for requesting access to a SIM card application, a first information representing a user identity received is encrypted in the TEE based on a first set TA to obtain second information, and then the second information is decrypted in the SIM card based on a second set TA to obtain the first information, and the first information is verified by the SIM card application, so as to determine whether to authorize the terminal application to access the SIM card application according to the verification result.
[0041] The terms used in the embodiments of the present application are defined as follows:
[0042] TEE: Trusted Execution Environment, is an application management standard based on secure chip technology provided by Global Platform. The purpose of TEE is to isolate high-security sensitive applications from the general software environment, and to provide secure access to hardware resources, including secure storage, secure display, and user interface capabilities.
[0043] REE: is a traditional terminal application running environment, such as iOS, Android, and other mobile operating systems.
[0044] Among them, TEE is used to install, store and protect trusted applications, and REE is used to install and store other applications other than trusted applications. TEE has its own operating system, which is isolated from the operating system in the REE environment. The authorized application in the REE cannot directly access the resources of the TEE, and needs to pass through the SIM card access agent to communicate with the TEE.
[0045] SIM card access agent: located in the REE, used to provide terminal application access to the SIM card interface and access interface between REE and TEE. The secure access agent can receive instructions sent by the terminal application to the SIM card, and send the instructions to the TEE, and can receive instructions returned by the TEE and send the instructions to the SIM card. In addition, the secure access agent can also receive the results returned by the SIM card and return the results to the terminal application.
[0046] SIM card authorized access management TA: including SIM card authorized access management TA located in TEE and SIM card authorized access management TA located in SIM card. The SIM card authorized access management TA located in TEE is used to receive information input by the user through other TAs in the TEE, such as password input TA, fingerprint input TA or other biometric input TA, and to encrypt the user input information by using various encryption algorithms, such as RSA algorithm, Elliptic Curves Cryptography (ECC) algorithm, Advanced Encryption Standard (AES) algorithm, Triple Data Encryption (3DES) algorithm and national encryption algorithm. The SIM card authorized access management TA located in the SIM card receives instructions from the SIM card application in the SIM card, decrypts and verifies the instructions, and then sends the verification result and the decrypted instructions to the corresponding SIM card application.
[0047] The SIM card application is a card-in-security application of the SIM card, has self-service logic, and has an authorized access capability, that is, after receiving an instruction sent by a SIM card access agent in the REE, the instruction is sent to an authorized access management TA in the SIM card for verification, after receiving a verification result and a decryption instruction of the authorized access management TA of the SIM card, corresponding instructions are executed, and an execution result is returned to the SIM card access agent in the REE.
[0048] The application will be further described in detail below with reference to the drawings and embodiments.
[0049] Figure 2 An implementation schematic diagram of an authorized access method according to an embodiment of the application is shown, referring to Figure 2 The method comprises the following steps.
[0050] Step 201: In the case where a terminal application initiates a first request, performing an encryption operation on received first information based on a first set TA in a TEE, to obtain second information.
[0051] The first request is used to request access to a SIM card application; and the first information represents a user identity.
[0052] In actual application, the terminal application runs in the REE and requests to access the SIM card application. For example, a bank application running in the REE requests to access a bank certificate application in the SIM card in a transfer transaction. Before the terminal application accesses the SIM card application, the SIM card application needs to verify the user identity of the terminal application, and only after the verification is passed, the terminal application is authorized to access the SIM card application. Here, the first information representing the user identity is encrypted in the TEE based on the first set TA.
[0053] In the embodiment of the application, a SIM card authorized access management TA, that is, a first set TA, is deployed in the TEE, and a SIM card authorized access management TA, that is, a second set TA, is also deployed in the SIM card. The first set TA and the second set TA are mainly used to complete encryption and decryption operations on the first information, respectively. In an embodiment, a first public key and a second public key used for encryption and decryption are pre-set in the TEE and the SIM card; the first public key is generated by a first TSM corresponding to the TEE; and the second public key is generated by a second TSM corresponding to the SIM card.
[0054] Before the terminal application initiates the first request, the method further comprises the following steps.
[0055] The first private key corresponding to the first public key is loaded to the first set TA in the TEE by the first TSM, and the second private key corresponding to the second public key is loaded to the second set TA in the SIM card by the second TSM.
[0056] The first TSM-generated public-private key pair and the second TSM-generated public-private key pair use the same cryptographic algorithm.
[0057] For example, the operator negotiates with the terminal manufacturer to use the SM2 algorithm, the TSM of the terminal manufacturer generates a set of SM2 public-private key pair 1, retains the private key 1 in the SM2 public-private key pair 1 on the TSM, and synchronizes the public key 1 in the SM2 public-private key pair 1 to the TSM of the operator. Similarly, the TSM of the operator generates a set of SM2 public-private key pair 2, retains the private key 2 in the SM2 public-private key pair 2 on the TSM, and synchronizes the public key 2 in the SM2 public-private key pair 2 to the TSM of the terminal manufacturer. Before the terminal is shipped, the public key 1 and the public key 2 are obtained from the TSM of the terminal manufacturer and pre-stored in the terminal, and the public key 1 and the public key 2 are obtained from the TSM of the operator before the SIM card is shipped and pre-stored in the SIM card. During the terminal runtime, the TEE downloads the private key 1 to the first designated TA through the TSM of the terminal manufacturer by over-the-air loading, and the SIM card downloads the private key 2 to the second designated TA through the TSM of the operator.
[0058] Through the above-mentioned public-private key pair acquisition method, a secure private key transmission channel can be established between the TEE and the corresponding TSM, and between the SIM card and the corresponding TSM, effectively ensuring the information security of the private key during transmission.
[0059] In an embodiment, before the encryption operation on the received first information based on the first designated TA in the TEE, the method further comprises:
[0060] receiving the first information based on a third designated TA in the TEE; wherein,
[0061] The third designated TA is used to receive the first information input by the user in the TEE.
[0062] Here, in the case where the terminal application initiates a first request, the first information input by the user is received based on a third designated TA in the TEE. The third designated TA runs in the TEE, and the received first information includes but is not limited to fingerprint, voiceprint, password, iris image, and other characteristic information that can represent the identity of the user. By receiving the first information based on the third designated TA in the TEE, it can be ensured that the information representing the identity of the user is input in a trusted environment, avoiding information leakage.
[0063] In an embodiment, before receiving the first information based on the third designated TA in the TEE, the method further comprises:
[0064] After the terminal application initiates the first request, a second request is sent by the terminal application to a SIM card access agent in the REE; the second request is used to request the user to input the first information;
[0065] The second request is sent to the TEE by the SIM card access agent.
[0066] Here, the SIM card access agent in the REE is configured as a communication interface between the REE and the TEE, and the second request is sent to the TEE, so that the first information input by the user is received in the TEE based on the third set TA.
[0067] Step 202: The second information is decrypted in the SIM card based on the second set TA to obtain the first information.
[0068] Here, the second information encrypted by the first information in the TEE based on the first set TA is transmitted to the SIM card, and the second information is decrypted in the SIM card based on the second set TA, so that the first information is restored. In actual application, there is no direct access interface between the TEE and the SIM card, and the TEE and the SIM card communicate through the REE. Based on this, in an embodiment, the method further comprises:
[0069] The second information generated by the first set TA is sent to the SIM card through the SIM card access agent in the REE.
[0070] Here, the SIM card access agent in the REE is configured as a communication interface between the TEE and the SIM card, and the second information encrypted in the TEE is sent to the SIM card, so that the second information is decrypted in the SIM card based on the second set TA, and the first information is restored.
[0071] Step 203: The first information is verified by the SIM card application, and whether the terminal application is authorized to access the SIM card application is determined according to the verification result.
[0072] In an embodiment, the method further comprises:
[0073] The verification result is sent to the SIM card access agent in the REE;
[0074] The verification result is sent to the terminal application by the SIM card access agent.
[0075] Here, the SIM card access agent arranged in the REE is arranged as a communication interface between the REE and the SIM card, and the SIM card sends the verification result of the first information by the SIM application to the terminal application in the REE, so that in the case that the verification result represents that the terminal application is authorized by the SIM application, the terminal application can access the SIM application, and in the case that the verification result represents that the terminal application is not authorized by the SIM application, the terminal application cannot access the SIM application.
[0076] In the case that the terminal application initiates the first request for requesting to access the SIM application, the first information representing the user identity is encrypted in the TEE based on the first set TA, and the second information is obtained, and then the second information is decrypted in the SIM card based on the second set TA to obtain the first information, and the first information is verified by the SIM application to determine whether to authorize the terminal application to access the SIM application according to the verification result. In the above access authorization process, the first information representing the user identity is encrypted and transmitted between the TEE and the SIM card, which reduces the risk of information leakage when the information is transmitted between the TEE and the SIM card, and avoids the security risk of information.
[0077] Figure 3 The terminal architecture related to the embodiments of the application is shown, and the comparison is made Figure 1 It can be seen that the SIM card authorization access management TA is additionally arranged in the TEE and the SIM card in the embodiments of the application, so that the first information representing the user identity is encrypted in the SIM card authorization access management TA of the TEE, and is decrypted in the SIM card authorization access management TA of the SIM card after being transmitted to the SIM card, thereby realizing the encrypted transmission of the first information between the TEE and the SIM card.
[0078] The application will be further described in detail in combination with application examples.
[0079] Figure 4 The mobile phone payment method provided by the embodiments of the application is shown, and specifically, the user starts the bank application on the mobile phone to make mobile phone payment, and when the bank application needs to access the SIM application for storing the bank certificate on the SIM card during the mobile phone payment, the following steps are included:
[0080] Step 1: The bank application sends a second request to the SIM card access agent in the REE, that is, a request for the user to input the first information representing the user identity.
[0081] Step 2: The SIM card access agent sends the second request to the TEE.
[0082] Step 3: The TEE sends the second request to the third set TA.
[0083] Here, according to the difference of the information type requested in the second request, the TEE sends the second request to the third setting TA corresponding to the information type. For example, if the user's fingerprint information is requested in the second request, the third setting TA is a TA running in the TEE for detecting and analyzing the fingerprint image input by the user.
[0084] Step 4: The third setting TA receives the first information input by the user.
[0085] Step 5: The third setting TA sends the first information to the SIM card authorized access management TA in the TEE.
[0086] Step 6: The SIM card authorized access management TA in the TEE performs encryption operation on the first information to obtain the second information.
[0087] Step 7: The SIM card authorized access management TA in the TEE returns the second information to the third setting TA.
[0088] Step 8: The third setting TA returns the second information to the TEE.
[0089] Step 9: The TEE returns the second information to the SIM card access agent in the REE.
[0090] Step 10: The SIM card access agent in the REE sends the second information to the SIM card.
[0091] Step 11: The SIM card sends the second information to the SIM card application.
[0092] Step 12: The SIM card application sends the second information to the SIM card authorized access management TA in the SIM card.
[0093] Step 13: The SIM card authorized access management TA in the SIM card decrypts the second information to restore the first information.
[0094] Step 14: The SIM card authorized access management TA in the SIM card returns the first information to the SIM card application.
[0095] Step 15: The SIM card application verifies the first information to obtain a verification result.
[0096] Step 16: The verification result is returned to the bank application.
[0097] In this way, in a case where the verification result represents that the bank application is authorized by the SIM card application, the bank application can access the SIM card application, complete the payment based on the bank certificate stored in the SIM card application, and in a case where the verification result represents that the bank application is not authorized by the SIM card application, the bank application cannot access the SIM card application, and the payment fails.
[0098] To implement the method of the embodiments of the present application, the embodiments of the present application further provide an authorization access device arranged on a terminal, as shown in the figure, the device comprises: Figure 5
[0099] a TEE module 501, configured to, in a case where a terminal application initiates a first request, perform an encryption operation on received first information based on a first set TA in a TEE, to obtain second information; wherein the first request is used to request access to a SIM card application; and the first information represents a user identity;
[0100] a SIM card module 502, configured to, in a SIM card, decrypt the second information based on a second set TA to obtain the first information; and perform verification on the first information through the SIM card application, to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
[0101] In an embodiment, a first public key and a second public key used for encryption and decryption are pre-set in the TEE and the SIM card; the first public key is generated by a first TSM corresponding to the TEE; and the second public key is generated by a second TSM corresponding to the SIM card.
[0102] The TEE module 501 is further configured to, before the terminal application initiates the first request, load a first private key corresponding to the first public key to the first set TA in the TEE through the first TSM.
[0103] The SIM card module 502 is further configured to, before the terminal application initiates the first request, load a second private key corresponding to the second public key to the second set TA in the SIM card through the second TSM.
[0104] In an embodiment, the TEE module 501 is further configured to, before performing the encryption operation on the received first information based on the first set TA in the TEE, receive the first information based on a third set TA in the TEE; wherein
[0105] The third set TA is used to receive the first information input by a user in the TEE.
[0106] In an embodiment, the device further comprises:
[0107] The REE module is used to send a second request to the SIM card access agent in the REE after the terminal application initiates the first request, before the first information is received in the TEE based on the third setting TA; the second request is used to request the user to input the first information; the second request is sent to the TEE through the SIM card access agent.
[0108] In one embodiment, the REE module is further configured to send the second information generated by the first set TA to the SIM card through the SIM card access agent in the REE.
[0109] In one embodiment, the SIM card module 502 is further configured to send the verification result to the SIM card access agent in the REE;
[0110] The REE module is also used to send the verification result to the terminal application via the SIM card access agent.
[0111] In practical applications, the TEE module 501, SIM card module 502, and REE module can be implemented by a processor in an authorized access device.
[0112] It should be noted that: when the authorized access device provided in the above embodiments performs the authorized access method, it uses... Figure 3 The illustrated terminal software architecture division is provided as an example. In practical applications, the above processing can be distributed among different program modules as needed, that is, the internal structure of the device can be divided into different program modules to complete all or part of the processing described above. Furthermore, the authorization access device and authorization access method embodiments provided in the above embodiments belong to the same concept, and their specific implementation process is detailed in the method embodiments, which will not be repeated here.
[0113] Based on the hardware implementation of the above program modules, and in order to implement the authorized access method of this application embodiment, this application embodiment also provides a terminal, such as... Figure 6 As shown, terminal 600 includes:
[0114] The first communication interface 601 is capable of exchanging information with other network nodes;
[0115] The first processor 602 is connected to the first communication interface 601 to enable information interaction with other network nodes and to execute the methods provided by one or more of the above-described technical solutions when running a computer program. The computer program is stored in the first memory 603.
[0116] Specifically, the first processor 602 is configured to, in a case where a terminal application initiates a first request, perform an encryption operation on received first information based on a first TA in a TEE to obtain second information, wherein the first request is used to request access to a SIM card application; the first information represents a user identity; the second information is decrypted based on a second configured TA in the SIM card to obtain the first information; and the first information is verified by the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
[0117] In an embodiment, the first public key and the second public key used for encryption and decryption are preconfigured in the TEE and the SIM card; the first public key is generated by a first TSM corresponding to the TEE; and the second public key is generated by a second TSM corresponding to the SIM card.
[0118] The first processor 602 is further configured to, before the terminal application initiates the first request, load a first private key corresponding to the first public key to the first configured TA in the TEE by the first TSM, and load a second private key corresponding to the second public key to the second configured TA in the SIM card by the second TSM.
[0119] In an embodiment, the first processor 602 is further configured to, before performing the encryption operation on the received first information based on the first configured TA in the TEE, receive the first information based on a third configured TA in the TEE; wherein
[0120] The third configured TA is used to receive the first information input by a user in the TEE.
[0121] In an embodiment, the first processor 602 is further configured to, before receiving the first information based on the third configured TA in the TEE, after the terminal application initiates the first request, send a second request to a SIM card access agent in the TEE by the terminal application; and send the second request to the TEE by the SIM card access agent; the second request is used to request a user to input the first information.
[0122] In an embodiment, the first processor 602 is further configured to:
[0123] Send the second information to the SIM card through the SIM card access agent in the TEE.
[0124] In an embodiment, the first processor 602 is further configured to:
[0125] Send the verification result to the SIM card access agent in the TEE;
[0126] The SIM card access agent sends the verification result to the terminal application.
[0127] It should be noted that the specific processing procedure of the first processor 602 can be understood with reference to the above method.
[0128] Of course, in actual application, each component in the terminal 600 is coupled together through the bus system 604. It can be understood that the bus system 604 is used to realize the connection and communication between the components. In addition to the data bus, the bus system 604 also includes a power bus, a control bus and a status signal bus. However, in order to clearly illustrate the present application, all the buses are marked as the bus system 604 in the Figure 6
[0129] The first memory 603 in the embodiment of the present application is used to store various types of data to support the operation of the terminal 600. Examples of these data include: any computer programs used to operate on the terminal 600.
[0130] The method disclosed in the above embodiment of the present application can be applied to or implemented by the first processor 602. The first processor 602 can be an integrated circuit chip with signal processing capability. In the implementation process, each step of the above method can be completed by the integrated logic circuit of hardware or the instruction in the form of software in the first processor 602. The first processor 602 mentioned above can be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The first processor 602 can implement or execute the disclosed methods, steps and logic block diagrams in the embodiments of the present application. The general-purpose processor can be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiments of the present application, the hardware decoding processor can be directly embodied to execute the above-mentioned steps, or the combination of hardware and software modules in the decoding processor can be executed. The software module can be located in the storage medium, which is located in the first memory 603, and the first processor 602 reads the information in the first memory 603 and combines the hardware to complete the steps of the above-mentioned method.
[0131] In an exemplary embodiment, the terminal 600 can be implemented with one or more Application Specific Integrated Circuits (ASICs), DSPs, Programmable Logic Devices (PLDs), Complex Programmable Logic Devices (CPLDs), Field-Programmable Gate Arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic elements for executing the aforementioned methods.
[0132] It can be understood that the first memory 603 of the embodiments of the present application can be a volatile memory or a non-volatile memory, and can also include both volatile and non-volatile memories. The non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM). The magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM) used as an external cache. By way of example but not limitation, many forms of RAM can be used, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), and direct rambus random access memory (DRRAM).The memory described in the embodiments of the present application is intended to include, but not limited to, these and any other suitable types of memory.
[0133] In the example embodiments, the embodiments of the present application also provide a storage medium, i.e. a computer storage medium, specifically a computer readable storage medium, for example including the first memory 603 storing a computer program, which can be executed by the first processor 602 of the terminal 600 to complete the steps of the foregoing authorized access method. The computer readable storage medium can be FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0134] It should be noted that "first", "second", etc. are used to distinguish similar objects, and do not necessarily describe a specific order or sequence.
[0135] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.
[0136] The above is only a preferred embodiment of the present application, and is not intended to limit the protection scope of the present application.
Claims
1. An access authorization method characterized by, The method comprises: In the case that a terminal application initiates a first request, performing an encryption operation on received first information based on a first trusted application (TA) in a trusted execution environment (TEE), to obtain second information; wherein the first request is used to request access to a subscriber identity module (SIM) card application; the first information represents a user identity; the terminal application runs in a rich execution environment (REE); after the terminal application initiates the first request, and before the encryption operation on the received first information based on the first TA in the TEE, sending, by the terminal application, a second request to a SIM card access agent in the REE; the second request is used to request the user to input the first information; sending, by the SIM card access agent, the second request to the TEE, so that the TEE receives the first information input by the user; Decrypting the second information based on a second TA in the SIM card to obtain the first information; Performing verification on the first information by the SIM card application, to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
2. The method of claim 1, wherein, A first public key and a second public key used for encryption and decryption are preconfigured in the TEE and the SIM card; the first public key is generated by a first trusted service management (TSM) corresponding to the TEE; The second public key is generated by a second TSM corresponding to the SIM card; Before the terminal application initiates the first request, the method further comprises: Loading, by the first TSM in the TEE, a first private key corresponding to the first public key to the first TA, and loading, by the second TSM in the SIM card, a second private key corresponding to the second public key to the second TA.
3. The method of claim 1, wherein, Before the encryption operation on the received first information based on the first TA in the TEE, the method further comprises: Receiving the first information based on a third TA in the TEE; wherein The third TA is used to receive the first information input by the user in the TEE.
4. The method of claim 3, wherein, Before receiving the first information based on the third TA in the TEE, the method further comprises: After the terminal application initiates the first request, sending, by the terminal application, a second request to a SIM card access agent in a rich execution environment (REE); the second request is used to request the user to input the first information; Sending, by the SIM card access agent, the second request to the TEE.
5. The method of claim 1, wherein, The method further comprises: Sending the second information generated by the first TA to the SIM card through the SIM card access agent in the REE.
6. The method of claim 1, wherein, The method further comprises: Sending the verification result to the SIM card access agent in the REE; Sending, by the SIM card access agent, the verification result to the terminal application.
7. An access authorization device, characterized in that The method comprises: The TEE module is configured to, in response to a first request initiated by a terminal application, perform an encryption operation on received first information based on a first set TA in a TEE to obtain second information, wherein the first request is used to request access to a SIM card application, the first information represents a user identity, and the terminal application runs in a REE. The TEE module is further configured to, after the terminal application initiates the first request and before the encryption operation on the received first information based on the first set TA in the TEE, send a second request to a SIM card access agent in a rich execution environment (REE) through the terminal application, wherein the second request is used to request the user to input the first information, and the second request is sent to the TEE through the SIM card access agent to enable the TEE to receive the first information input by the user. The SIM card module is configured to, in a SIM card, perform a decryption operation on the second information based on a second set TA to obtain the first information, and perform verification on the first information through the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result.
8. A terminal, characterized by comprising: The application comprises: A first processor and a first communication interface. The first processor is configured to, in response to a first request initiated by a terminal application, perform an encryption operation on received first information based on a first set TA in a TEE to obtain second information, perform a decryption operation on the second information based on a second set TA in a SIM card to obtain the first information, and perform verification on the first information through the SIM card application to determine whether to authorize the terminal application to access the SIM card application according to a verification result, wherein the first request is used to request access to a SIM card application, the first information represents a user identity, and the terminal application runs in a REE.
9. A terminal, characterized by comprising: The first processor is further configured to, after the terminal application initiates the first request and before the encryption operation on the received first information based on the first set TA in the TEE, send a second request to a SIM card access agent in a REE through the terminal application, wherein the second request is used to request the user to input the first information, and the second request is sent to the TEE through the SIM card access agent to enable the TEE to receive the first information input by the user. The application comprises: A first processor and a first memory for storing a computer program capable of running on the processor.
10. A storage medium having stored thereon a computer program, characterized in that When the first processor runs the computer program, it performs the steps of the method according to any one of claims 1 to 6. The computer program is executed by the processor to implement the steps of the method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Secure communication method and apparatus, terminal and client identification module card
CN106304052A
Electronic device for authenticating application and operating method thereof
US20170344407A1