Mobile terminal based on trusted execution environment, trusted service system and trusted application management method
By combining a unified general trusted application and a customized trusted application in mobile terminals, and utilizing a routing information management system, the development and deployment cost issues of different banking institutions in mobile payment systems have been solved, achieving cost reduction and improved ease of use.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-23
- Publication Date
- 2026-04-14
AI Technical Summary
The need for separate development and deployment of trusted applications from different banking institutions in mobile payment systems results in significant development and deployment costs for mobile terminal manufacturers, hindering widespread adoption.
By combining a unified general trusted application with customized trusted applications, trusted applications are installed and deployed on mobile terminals through a routing information management system. The routing management server is used for business application registration and routing table management, simplifying the application development and deployment process.
It significantly reduces the development costs of trusted applications for banking institutions and the deployment costs of trusted applications for mobile terminal manufacturers, and improves the scalability and ease of use of mobile payment systems.
Smart Images

Figure CN115835164B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of mobile terminal security technology, and in particular to mobile terminals based on trusted execution environments, trusted service systems, and trusted application management methods. Background Technology
[0002] With the development of the mobile internet and the increasing prevalence of mobile devices, mobile terminals have become an indispensable part of people's daily work and life. Data security and privacy protection on mobile terminals have become important issues of public concern. Privacy-preserving computing technology can enable data exchange, sharing, analysis, and computation while ensuring data security.
[0003] Privacy-preserving computation includes hardware-based Trusted Execution Environments (TEEs), which utilize chip-level protection schemes and offer advantages such as high security, high performance, and high versatility. They have broad application prospects in areas such as data-driven financial risk control, transaction privacy protection, blockchain, artificial intelligence, and healthcare. One important application in mobile terminals is mobile payment based on a Trusted Execution Environment. The financial industry standard "Technical Specification for Trusted Environment of Mobile Terminal Payment" (JR / T 0156-2017) specifies two application scenarios: mobile banking applications and identity authentication applications. Mobile banking applications include applying for certificates during the activation phase and generating digital signatures during the application phase.
[0004] A complete mobile payment solution involves mobile device manufacturers, certification authorities (CAs), banking institutions, and solution providers. Because different banking institutions have different business operations and needs, each institution must develop its own dedicated trusted application. Then, the mobile device manufacturer deploys these trusted applications on the mobile devices. Managing the mobile payment services of different banking institutions places a huge and heavy burden of development and integration work on the mobile device manufacturers, leading to increased development and deployment costs and making widespread adoption extremely difficult. Although other mobile payment solutions exist, such as eID, IFFA, and electronic signatures, these solutions all require deployment and development on mobile phones.
[0005] Therefore, there is a need to provide new application management systems and methods based on trusted execution environments to reduce the development costs of trusted applications for banking institutions and the deployment costs of trusted applications for mobile terminal manufacturers. Summary of the Invention
[0006] In view of the above problems, the purpose of this invention is to provide a mobile terminal, a trusted service system and a trusted application management method based on a trusted execution environment, wherein a unified general trusted application is used to reduce the development cost of trusted applications, and trusted application routing information management is used to reduce the deployment cost of trusted applications.
[0007] According to a first aspect of the present invention, a trusted application management method is provided, comprising: installing a plurality of trusted applications in a trusted execution environment of a mobile terminal; and invoking a corresponding trusted application among the plurality of trusted applications to complete a third-party service based on routing information of the plurality of trusted applications.
[0008] Preferably, the plurality of trusted applications include at least some general trusted applications shared by service providers and at least one customized trusted application of a specific service provider; or the plurality of trusted applications include a general trusted application shared by multiple service providers; or the plurality of trusted applications include a customized trusted application of multiple specific service providers.
[0009] Preferably, it further includes: obtaining a trusted application corresponding to the third-party service based on the data query results of the routing management server.
[0010] Preferably, it further includes: obtaining a trusted application corresponding to the third-party service based on the data query results of the local routing table.
[0011] Preferably, the local routing table includes at least one routing information item, which includes a third-party service identifier and a trusted application identifier. The third-party service identifier is used to distinguish third-party services from multiple service providers, and the trusted application identifier is used to indicate a trusted application corresponding to the third-party service.
[0012] Preferably, the routing information in the local routing table further includes a trusted user interface identifier, which is used to indicate a trusted user interface corresponding to the third-party service.
[0013] Preferably, the method further includes: downloading a routing table from the routing management server to create the local routing table; and / or updating the local routing table based on the data query results from the routing management server.
[0014] Preferably, the local routing table includes version information, and the application management method further includes comparing the version information of the local routing table with the management information of the routing table on the routing management server to determine whether to update the local routing table.
[0015] Preferably, the local routing table is a file in the secure file system of the trusted execution environment.
[0016] Preferably, the mobile terminal further includes a security element, and the local routing table is a file stored in the security element.
[0017] Preferably, the third-party services include at least one of the following services provided by the service provider: electronic certificate application, transaction signature verification, mobile payment, and bank account inquiry.
[0018] Preferably, it further includes: when issuing third-party services, the service provider files a business application registration with the routing management server; and the routing management server creates routing information for the trusted application corresponding to the third-party service based on the registration information of the business application registration.
[0019] Preferably, the filing information includes: a third-party business identifier, used to distinguish third-party businesses from multiple service providers; and a trusted application identifier, used to indicate a trusted application corresponding to the third-party business.
[0020] Preferably, the filing information further includes at least one of the following: a trusted user interface identifier, used to indicate a trusted user interface corresponding to the third-party service; a signature public key of the third-party service server, used to verify the signature issued by the third-party service; the Chinese name of the service provider, used to be displayed on the business application management page; and the English name of the service provider, used to be displayed on the business application management page.
[0021] Preferably, the third-party business identifier is the hash value of the public key of the third-party business application's signature, or the installation package name of the third-party business application, or a unique identifier representing the third-party business application.
[0022] Preferably, the trusted application identifier is a globally unique identifier for the corresponding trusted application.
[0023] According to a second aspect of the present invention, a mobile terminal is provided, comprising: a client application installed in a rich execution environment of the mobile terminal; a plurality of trusted applications installed in a trusted execution environment of the mobile terminal; and an application management module, wherein the application management module invokes a corresponding trusted application among the plurality of trusted applications to complete a third-party service based on routing information of the plurality of trusted applications.
[0024] Preferably, the plurality of trusted applications include at least some general trusted applications shared by service providers and at least one customized trusted application of a specific service provider; or the plurality of trusted applications include a general trusted application shared by multiple service providers; or the plurality of trusted applications include a customized trusted application of multiple specific service providers.
[0025] Preferably, the application management module obtains a trusted application corresponding to the third-party service based on the data query results from the routing management server.
[0026] Preferably, it further includes: a local routing table for storing routing information of the plurality of trusted applications, wherein the application management module obtains the trusted application corresponding to the third-party service based on the data query results of the local routing table.
[0027] Preferably, the local routing table includes at least one routing information item, which includes a third-party service identifier and a trusted application identifier. The third-party service identifier is used to distinguish third-party services from multiple service providers, and the trusted application identifier is used to indicate a trusted application corresponding to the third-party service.
[0028] Preferably, the routing information in the local routing table further includes a trusted user interface identifier, which is used to indicate a trusted user interface corresponding to the third-party service.
[0029] Preferably, the mobile terminal downloads a routing table from the routing management server to create the local routing table; and / or updates the local routing table based on the data query results from the routing management server.
[0030] Preferably, the local routing table includes version information, and the mobile terminal compares the version information of the local routing table with the management information of the routing table on the routing management server to determine whether to update the local routing table.
[0031] Preferably, the local routing table is a file in the secure file system of the trusted execution environment.
[0032] Preferably, the mobile terminal further includes a security element, and the local routing table is a file stored in the security element.
[0033] Preferably, the third-party services include at least one of the following services provided by the service provider: electronic certificate application, transaction signature verification, mobile payment, and bank account inquiry.
[0034] Preferably, the third-party business identifier is the hash value of the public key of the third-party business application's signature, or the installation package name of the third-party business application, or a unique identifier representing the third-party business application.
[0035] Preferably, the trusted application identifier is a globally unique identifier for the corresponding trusted application.
[0036] According to a third aspect of the present invention, a trusted service system is provided, comprising: a third-party business server; and the aforementioned mobile terminal, wherein the mobile terminal submits a business invocation request to the third-party business server and establishes a secure channel with the third-party business server to complete the third-party business.
[0037] Preferably, it further includes: a routing management server, the routing management server including a filing routing table, the filing routing table being used to store routing information of the multiple trusted applications, wherein, when issuing a third-party service, the service provider files a business application with the routing management server, and the routing management server creates routing information of the trusted applications corresponding to the third-party service based on the filing information of the business application filing.
[0038] Preferably, the filing information includes: a third-party business identifier, used to distinguish third-party businesses from multiple service providers; and a trusted application identifier, used to indicate a trusted application corresponding to the third-party business.
[0039] Preferably, the filing information further includes at least one of the following: a trusted user interface identifier, used to indicate a trusted user interface corresponding to the third-party service; a signature public key of the third-party service server, used to verify the signature issued by the third-party service; the Chinese name of the service provider, used to be displayed on the business application management page; and the English name of the service provider, used to be displayed on the business application management page.
[0040] According to the trusted application management method of this embodiment, for third-party services from multiple service providers, the third-party services of at least some service providers are merged into a unified general trusted application. Therefore, at least some service providers can directly use the unified general trusted application. Mobile terminal manufacturers can pre-install the unified general trusted application on the mobile terminal and deploy customized trusted applications from specific service providers on the mobile terminal. Therefore, in the case where third-party services from multiple service providers are deployed on a mobile terminal, the trusted applications installed on the mobile terminal can include the unified general trusted application and a subset of all customized trusted applications from multiple service providers. In the aforementioned trusted service system, at least some service providers can use the unified general trusted application; therefore, this trusted service system can significantly reduce the trusted application development costs for service providers.
[0041] Furthermore, in the aforementioned trusted application management method, the mobile terminal selects the corresponding trusted application based on the routing information of the trusted application. The trusted application deployment process of the mobile terminal can be simplified to a data query interface of the routing management server, or to downloading a customized trusted application from a specific service provider and updating the local routing table of the mobile terminal. Therefore, this trusted service system can significantly reduce the trusted application deployment cost for mobile terminal manufacturers. Attached Figure Description
[0042] The above and other objects, features and advantages of the present invention will become more apparent from the following description of embodiments of the invention with reference to the accompanying drawings, in which:
[0043] Figure 1 A schematic block diagram of a trusted service system according to a first embodiment of the present invention is shown.
[0044] Figure 2 Show Figure 1 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system.
[0045] Figure 3 Show Figure 2 The diagram shows the data file of the local routing table.
[0046] Figure 4 A schematic block diagram of a trusted service system according to a second embodiment of the present invention is shown.
[0047] Figure 5 Show Figure 4 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system.
[0048] Figure 6 Show Figure 4 The diagram shows a schematic block diagram of the routing management server in a trusted service system.
[0049] Figure 7 A schematic block diagram of a trusted service system according to a third embodiment of the present invention is shown.
[0050] Figure 8 Show Figure 7 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system.
[0051] Figure 9 Show Figure 7 The diagram shows a schematic block diagram of the routing management server in a trusted service system.
[0052] Figure 10 A schematic flowchart illustrating a trusted application management method according to a fourth embodiment of the present invention is shown.
[0053] Figure 11 Show Figure 10 The flowchart shown is a detailed flowchart of the local routing table update in the trusted application management method.
[0054] Figure 12 Show Figure 10 The flowchart shown is a detailed process for applying for digital certificates in the trusted application management method.
[0055] Figure 13 Show Figure 10 The flowchart shown is a detailed representation of the use of digital certificates in the trusted application management method. Detailed Implementation
[0056] Various embodiments of the invention will now be described in more detail with reference to the accompanying drawings. In the various drawings, the same elements are indicated by the same or similar reference numerals. For clarity, the various parts in the drawings are not drawn to scale. Furthermore, certain well-known parts may not be shown in the drawings.
[0057] The terminology used herein is for the purpose of describing specific embodiments only, and unless clearly indicated in the context, the terminology itself is not intended to limit the disclosure of this application. For the purpose of clearly describing specific embodiments, only exemplary descriptions of some terms are given below.
[0058] the term
[0059] "Mobile terminal," also known as "smart terminal," includes, but is not limited to, mobile phones, mobile computers, tablets, personal digital assistants (PDAs), media players, smart TVs, smartwatches, smart glasses, smart bracelets, smart cars, and in-vehicle terminals.
[0060] An "Operating System" (OS) is a computer program that manages computer hardware and software resources; it is the kernel and foundation of a computer system. Mobile terminals provide a Rich Execution Environment (REE) and a Trusted Execution Environment (TEE). The main operating system, such as Android or iOS, runs in the REE and boasts high processing power and multimedia capabilities. The TEE is a secure environment isolated from the main operating system; for example, a highly secure operating system may run within the TEE.
[0061] A Trusted Execution Environment (TEE) is a secure environment within a computer system, isolated from the main operating system, using both hardware and software to provide isolation. A TEE typically offers greater security than the main operating system and provides an increased level of security for running applications. Trusted applications running in a TEE have full access to the device's main processor and memory, while hardware isolation protects them from user-installed applications running on the main operating system. Software and cryptographic isolation within the TEE protects the trusted applications contained within it from interfering with each other. A TEE can be implemented by a processor that incorporates secure execution technologies, such as Intel's SGX technology, Intel's Manageable Engine, or ARM's TrustZone.
[0062] A Secure Element (SE) is also a type of secure environment. It's an electronic component with tamper-proof capabilities that can be installed on mobile terminals to provide a secure and confidential data storage and operating environment. More broadly, any hardware device that provides storage space for installing applications and has application management functions can be considered a Secure Element. For example, a smartphone running the Android system can install third-party applications, and the Android operating system can manage these applications and provide some protection; therefore, it can be considered a broadly defined Secure Element. An SE consists of software and tamper-proof hardware, supports high levels of security, and can operate with devices such as SIM cards, financial IC cards, and smart SD cards.
[0063] The "Client Application" (CA) and "Trusted Application" (TA) are applications running on the REE and TEE, respectively. The CA is the sole channel for third-party business applications to access the TA, handling access control and managing the TA. It separates the core code, critical business logic, and sensitive data of third-party business applications that require isolation and protection into the TA. For example, the CA provides management and certificate management functions for the TA, including: downloading, installing, updating, deleting, and access control of the TA, as well as applying for, downloading, updating, and deleting certificates. The TA can access all functions of the device's main processor and memory, and hardware isolation technology protects it from the influence of application software installed on the REE. Although the CA and TA run in isolated environments, the CA can still access the TA by calling the Application Programming Interface (API) of the TEE client located on the REE, thereby using the security functions provided by the TEE and TA.
[0064] A Trusted Virtual Machine (TVM) is a trusted virtual machine environment that runs on a computer system based on hardware isolation technology. Its security features are similar to those of a TEE environment, and it can run trusted applications such as TUI and trusted operating systems.
[0065] A Trusted User Interface (TUI) is an application interface that runs on a TEE or TVM and is used to securely present an interactive interface to the user, prevent attacks such as phishing, and provide the interaction results to the user.
[0066] First Embodiment
[0067] The specific embodiments of the present invention will be described in further detail below with reference to the accompanying drawings and examples.
[0068] Figure 1 A schematic block diagram of a trusted service system according to a first embodiment of the present invention is shown. As shown, the trusted service system 100 includes a plurality of mobile terminals 110 and a plurality of third-party service servers 120 connected via a network.
[0069] The third-party service server 120 is a dedicated computer system provided by a service provider (SP) to mobile terminals within a network environment. The third-party service server 120 includes, but is not limited to, CISC (Complex Instruction Set Computing) architecture servers, RISC (Reduced Instruction Set Computing) architecture servers, and EPIC architecture servers. Third-party services include, for example, online banking, online commerce, online education, and online voting. Therefore, the data security of the third-party service server 120 is extremely important.
[0070] Mobile terminal 110 is a communication device that can be used while in motion. Mobile terminal 110 includes, but is not limited to, mobile phones, mobile computers, tablets, personal digital assistants (PDAs), media players, smart TVs, smartwatches, smart glasses, smart bracelets, smart cars and in-vehicle terminals, etc.
[0071] Mobile terminal 110 supports multiple third-party service providers, i.e., multiple third-party service servers 120. In the application scenario of mobile security tokens, mobile terminal 110 is, for example, a smartphone used by a user, and the service provider of the third-party service server 120 is, for example, a bank, and the third-party service is, for example, mobile payment services provided by the bank. Therefore, multiple bank-specific trusted applications need to be deployed on the mobile phone.
[0072] In the trusted service system according to this embodiment, for third-party services from multiple service providers, at least some of the third-party services are merged into a unified general trusted application. In this embodiment, the services supported by the general trusted application include: encryption / decryption services, signature verification services, trusted input services, trusted display services, digital certificate management, and signature verification functions, etc.
[0073] Therefore, among multiple service providers, at least some can use a unified, universal trusted application. Mobile terminal manufacturers can pre-install the unified, universal trusted application on mobile terminal 110, and deploy customized trusted applications from specific service providers on mobile terminal 110. Therefore, in the case of deploying third-party services from multiple service providers on a mobile terminal, the trusted applications installed on the mobile terminal can include a unified, universal trusted application, as well as a subset of all customized trusted applications from multiple service providers. Optionally, the technical solution of this application supports at least the following three scenarios: the simultaneous existence of universal and customized applications; only a universal application; no customized application; and no universal application, only customized applications. That is, multiple trusted applications include at least some universal trusted applications shared by service providers, and at least one customized trusted application from another specific service provider; or multiple trusted applications include universal trusted applications shared by multiple service providers; or multiple trusted applications include customized trusted applications from multiple specific service providers.
[0074] In the aforementioned trusted service system, at least some service providers can use a unified, universal trusted application. Therefore, this trusted service system can significantly reduce the trusted application development costs for service providers.
[0075] In a preferred embodiment, for third-party services from multiple service providers, at least some of the third-party services are merged into a unified, general-purpose toolkit. Third-party service applications invoke trusted applications via interfaces provided by the toolkit. Therefore, in the case of deploying third-party services from multiple service providers on a mobile terminal, the toolkit installed on the mobile terminal may include a unified, general-purpose toolkit, as well as a subset of all customized toolkits from multiple service providers.
[0076] Furthermore, the mobile terminal 110 includes a pre-configured local routing table. Based on the third-party service identifier, the client application of the mobile terminal 110 searches the local routing table to obtain the routing information of the corresponding trusted application, and then selects the appropriate trusted application from general trusted applications and customized trusted applications to execute business logic in the secure environment based on the routing information.
[0077] For example, when a user uses a third-party service, the application on mobile terminal 110 selects a general trusted application based on routing information. The user enters their personal password in the general trusted application on mobile terminal 110 for identity verification, and a secure communication key ciphertext is generated using a public key certificate in the secure environment of mobile terminal 110. The client application on mobile terminal 110 submits a service call request and sends the secure communication key ciphertext to the third-party service server 120 to establish a secure channel for performing secure information exchange. Other services of the trusted application are then completed via this secure channel.
[0078] In the aforementioned trusted service system, the mobile terminal 110 selects the corresponding trusted application based on the routing information in its local routing table. The trusted application deployment process of the mobile terminal 110 has been simplified to downloading a customized trusted application from a specific service provider and updating the mobile terminal's local routing table. Therefore, this trusted service system can significantly reduce the trusted application deployment costs for mobile terminal manufacturers.
[0079] Figure 2 Show Figure 1 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system. As shown, the operating environment of the mobile terminal 110 includes a Rich Execution Environment (REE), a Trusted Execution Environment (TEE), and a Secure Element (SE).
[0080] The REE deploys a Rich Operating System (ROS) and a Client Application (CA). The Trusted Operating System (TOS) and several Trusted Applications (TA_A, TA_B1, TA_B2, etc.) corresponding to the Client Applications (CA) in the REE are deployed within the Trusted Execution Environment (TEE). The TOS and the Trusted Applications (TA_A, TA_B1, TA_B2) are typically stored encrypted in persistent storage media.
[0081] The Security Element (SE) deploys a Chip Operating System and corresponding Applets for the TAs (Task Agents) within it. The SE may also include a communication module, through which it can receive messages from the Trusted Execution Environment (TEE) and return response messages. The TEE may also include an SE driver to enable communication with the SE. The Rich Execution Environment (REE) may also include an SE access interface to access the Applets within the SE.
[0082] The client application (CA) and the rich operating system (ROS) communicate through the Trusted Execution Environment (TEE) client interface, while the trusted application (TA) and the trusted operating system (TOS) communicate through the TEE internal interface. Data is transferred between the client application (CA) and the trusted application (TA) via shared memory. The ROS and TOS have a communication interface, and the client application (CA) and the trusted application (TA) can also communicate by calling the communication interface between the ROS and TOS. Both the TEE client interface and the TEE internal interface can be Application Programming Interfaces (APIs); for example, the TEE client interface is a TEE client API, and the TEE internal interface is a TEE internal API. Since the trusted application (TA) and the trusted operating system (TOS) can communicate through the TEE internal interface, some common functions of the trusted application (TA) can be integrated into the trusted operating system (TOS). The trusted operating system (TOS) can then provide these common functions to the trusted application (TA) as security services through the TEE internal interface, thereby simplifying the complexity of the trusted application (TA).
[0083] In a preferred embodiment, a Trusted User Interface (TUI) is also provided within the Trusted Execution Environment (TEE). The Secure Element (SE) primarily performs cryptographic operations. When using the TUI within the TEE, after a trusted application (TA) interacts with the user through the TUI, it sends the result of the user interaction to the communication module of the Secure Element (SE) via the SE driver. Upon receiving the interaction result through the communication module, the SE executes it directly, for example, verifying the user's PIN code or signing data confirmed by the user.
[0084] The REE also deploys third-party business applications (APPn) provided by multiple service providers, along with corresponding software development kits (SDKn). The third-party business applications (APPn) call the client application (CA) through the interfaces of their respective SDKn.
[0085] The Client Application CA, also known as the Regular Application, and the Trusted Application (TA), also known as the Secure Application, are separate entities. The Client Application CA serves as the sole channel for third-party business applications (APPn) to access the TA. It manages access control to the TA, separating the core code, critical business logic, and sensitive data that require isolation and protection from the third-party business application into the Trusted Application (TA). This significantly reduces security threats from Rich Execution Environments (REEs). For example, the Client Application CA receives data from the server and, based on routing information, transmits critical data to the corresponding Trusted Application. The Trusted Application then processes this critical data transmitted by the Client Application CA.
[0086] For example, the Trusted Application (TA) is responsible for user certificate management, secure input and display, biometric identification, and device trust key management. It enables user key application and user password and biometric authentication through interaction with the Secure Element (SE) application.
[0087] In existing mobile terminals, a complete application from any third-party service provider includes a client application (CA) and a corresponding trusted application (TA). The client application CA and its corresponding trusted application (TA) work together to realize the full functionality of the application.
[0088] For example, in cases where a service provider's third-party business is mobile payment, a client application (CA) running in a Rich Execution Environment (REE) and a trusted application (TA) running in a Trusted Execution Environment (TEE) can be provided, with a one-to-one correspondence between the client application CA and the trusted application TA. For instance, in the Alipay application, developers create two installation files. In the REE, the processor loads the installation file for the Alipay client application CA to run it. In the TEE, the processor loads the installation file for the Alipay trusted application TA to run it.
[0089] In the mobile terminal according to this embodiment, multiple third-party service providers each provide their own third-party service application APPn. The third-party service application APPn calls the interfaces provided by the corresponding toolkit SDKn. The toolkits include SDKn, for example, one of the following: a unified general toolkit SDK_A shared by at least some third-party service providers, and customized toolkits SDK_B1 and SDK_B2 for specific third-party service providers. Therefore, for at least some third-party service providers, the third-party service application APPn calls the unified client application CA via the unified general toolkit SDK_A, thereby accessing the unified general trusted application TA_A. For specific third-party service providers, the third-party service application APPn calls the unified client application CA via the corresponding customized toolkits in the customized toolkits SDK_B1 and SDK_B2, thereby accessing the corresponding customized trusted applications TA_B1 and TA_B2.
[0090] Furthermore, the mobile terminal 110 also includes an application management module 111 and a local routing table 112. Based on the third-party service identifier, the application management module 111 searches the local routing table 112 to obtain the routing information of the corresponding trusted application for the third-party service. The client application CA selects the appropriate trusted application from the general trusted application TA_A and the customized trusted applications TA_B1 and TA_B2 based on the routing information to execute business logic in the secure environment.
[0091] See Figure 3 Local routing table 112 is a data file stored in a secure environment. For example, this data file is a file in the secure file system of a Trusted Execution Environment (TEE) or a file stored in a Secure Element (SE).
[0092] The local routing table 112 includes version information and at least one routing entry. Each routing entry includes at least a third-party service identifier and a trusted application identifier. Preferably, each routing entry may also include an additional trusted user interface identifier.
[0093] Third-party service identifiers are used to distinguish third-party service applications from different service providers and serve as an access control (AC) field in routing information. A third-party service identifier can be, for example, the name of the third-party service or the hash value (e.g., HASH256) of the public key used to sign the third-party service application (APPn). Trusted application identifiers are used to distinguish trusted applications from different service providers. A trusted application identifier can be, for example, the name of the trusted application or a globally unique identifier (UUID) for the trusted application. Trusted user interface identifiers can be, for example, the name of the trusted user interface or a globally unique identifier (UUID) for the trusted user interface. As is known, the unique identifier (UUID) is a unique identifier generated by a computer using an algorithm.
[0094] Second Embodiment
[0095] Figure 4 A schematic block diagram of a trusted service system according to a second embodiment of the present invention is shown. As shown, the trusted service system 200 includes a plurality of third-party business servers 120, a routing management server 230, and a plurality of mobile terminals 210 connected via a network.
[0096] The third-party service server 120 is a dedicated computer system provided by a service provider (SP) to mobile terminals within a network environment. The third-party service server 120 includes, but is not limited to, CISC (Complex Instruction Set Computing) architecture servers, RISC (Reduced Instruction Set Computing) architecture servers, and EPIC architecture servers. Third-party services include, for example, online banking, online commerce, online education, and online voting. Therefore, the data security of the third-party service server 120 is extremely important.
[0097] The routing management server 230 is a dedicated computer system provided by a mobile terminal manufacturer (MTM) or a third-party service provider (SP) to offer routing information services for trusted applications on mobile terminals within a network environment. The routing management server 230 includes, but is not limited to, CISC (Complex Instruction Set Computing) architecture servers, RISC (Reduced Instruction Set Computing) architecture servers, and EPIC architecture servers. Routing information services include, for example, business application registration and routing table downloading.
[0098] Mobile terminal 210 is a communication device that can be used while in motion. Mobile terminal 210 includes, but is not limited to, mobile phones, mobile computers, tablets, personal digital assistants (PDAs), media players, smart TVs, smartwatches, smart glasses, smart bracelets, etc.
[0099] Mobile terminal 210 supports multiple third-party service providers, i.e., multiple third-party service servers 120. In the application scenario of mobile security tokens, mobile terminal 210 is, for example, a smartphone used by a user, and the service provider of the third-party service server 120 is, for example, a bank, and the third-party service is, for example, a mobile payment service provided by the bank. Therefore, multiple bank-specific trusted applications need to be deployed on the mobile phone.
[0100] Similar to the first embodiment, the trusted applications in the mobile terminal 210 include general trusted applications that support at least some service providers, and customized trusted applications that support specific service providers; it may also support only general applications without customized applications; or support only customized applications without general applications.
[0101] Furthermore, the third-party business server 120 registers its business applications with the routing management server 230 via the network, and writes or modifies the routing information of trusted applications in the routing table on the server. The mobile terminal 210 downloads the routing table from the routing management server 230 via the network and saves it as a local routing table. Based on the third-party business identifier, the client application of the mobile terminal 210 searches the local routing table to obtain the routing information of the corresponding trusted application, and then selects the appropriate trusted application from general trusted applications and customized trusted applications to execute business logic in the secure environment based on the routing information.
[0102] For example, when a user uses a third-party service, the application on mobile terminal 210 selects a general trusted application based on routing information. The user enters their personal password in the general trusted application on mobile terminal 210 for identity verification, and a secure communication key ciphertext is generated using a public key certificate in the secure environment of mobile terminal 210. The client application on mobile terminal 210 submits a service call request and sends the secure communication key ciphertext to the third-party service server 120 to establish a secure channel for performing secure information exchange processes. Other trusted application services are then completed via this secure channel.
[0103] In the aforementioned trusted service system, the mobile terminal 210 selects the corresponding trusted application based on the routing information in its local routing table. The deployment process of the secure application of the mobile terminal 210 has been simplified to downloading a customized trusted application from a specific service provider and updating the local routing table of the mobile terminal 210 based on the routing table of the routing management server 230. Therefore, this trusted service system can significantly reduce the trusted application deployment cost for mobile terminal manufacturers.
[0104] Figure 5 Show Figure 4 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system. As shown, the operating environment of the mobile terminal 210 includes a Rich Execution Environment (REE), a Trusted Execution Environment (TEE), and a Secure Element (SE).
[0105] Similar to the first embodiment, the mobile terminal 210 includes an application management module 111 and a local routing table 112.
[0106] Furthermore, the client application CA of the mobile terminal 210 is used not only to interact with the third-party business server 120 to implement third-party business calls, but also to interact with the routing management server 230 to obtain the latest routing table.
[0107] Based on the update notification from the routing management server 230, or based on the status query result of the mobile terminal 210 on the routing management server 230, the mobile terminal 210 can download the latest routing table from the routing management server 230.
[0108] When mobile terminal 210 invokes a third-party service, the application management module 111 of mobile terminal 210 searches the local routing table 112 based on the third-party service identifier to obtain the routing information of the corresponding trusted application. The client application CA selects the appropriate trusted application from the general trusted application TA_A and the customized trusted applications TA_B1 and TA_B2 based on the routing information to execute the business logic in the secure environment.
[0109] Figure 6 Show Figure 4 The diagram shows a schematic block diagram of a routing management server in a trusted service system. As shown, the routing management server 230 includes a registration module 231, a routing table 232, and a download module 233.
[0110] The routing information services provided by the routing management server 230 include, for example, business application registration and routing table download.
[0111] The filing module 231 of the routing management server 230 performs the above-mentioned business application filing function, including: before providing third-party services, the service provider files the third-party services online via the network, or sends the filing information of the third-party services to the mobile terminal manufacturer for offline filing.
[0112] The filing information for third-party services includes, but is not limited to, the following fields:
[0113] 1. The Chinese name of the service provider: For example, Bank of Communications of China. This information is used to display on the business application management page;
[0114] 2. The English name of the service provider: for example, BCM. This information is used to display on the business application management page.
[0115] 3. Third-party business identifier: For example, the hash value of the public key for signing the third-party business application APPn (e.g., HASH256);
[0116] 4. Trusted Application Identifier: Used to distinguish trusted applications from different service providers. For example, the Trusted Application Identifier is a globally unique identifier (Universally Unique Identifier, abbreviated as UUID) for a trusted application.
[0117] 5. Trusted User Interface Identifier: Used to indicate the trusted user interface corresponding to the third-party service. For example, the trusted user interface identifier is a globally unique identifier (UUID) for the trusted user interface.
[0118] Compared to the routing table 112 on the mobile terminal 210, the routing table 232 on the routing management server 230 includes the same or more fields. For example, each routing information entry in the routing table 232 includes at least a third-party service identifier and a trusted application identifier; that is, the routing table 232 includes at least the third and fourth information items of the aforementioned registration information. Preferably, each routing information entry may also include an additional trusted user interface identifier; that is, the routing table 232 may also include the fifth information item of the aforementioned registration information.
[0119] The download module 233 of the routing management server 230 performs the above-mentioned routing table download function, including: when the mobile terminal 210 submits a request to the routing management server 230 to download the routing table, sending the routing information of the routing table 232 on the routing management server 230 to the mobile terminal 210, thereby updating the routing table 112 on the mobile terminal 210.
[0120] Third Embodiment
[0121] Figure 7A schematic block diagram of a trusted service system according to a third embodiment of the present invention is shown. As shown, the trusted service system 300 includes a plurality of third-party business servers 120, a routing management server 330, and a plurality of mobile terminals 310 connected via a network.
[0122] The third-party service server 120 is a dedicated computer system provided by a service provider (SP) to mobile terminals within a network environment. The third-party service server 120 includes, but is not limited to, CISC (Complex Instruction Set Computing) architecture servers, RISC (Reduced Instruction Set Computing) architecture servers, and EPIC architecture servers. Third-party services include, for example, online banking, online commerce, online education, and online voting. Therefore, the data security of the third-party service server 120 is extremely important.
[0123] The routing management server 330 is a dedicated computer system provided by a mobile terminal manufacturer (MTM) or a third-party service provider (SP) to offer routing information services for trusted applications on mobile terminals within a network environment. The routing management server 330 includes, but is not limited to, CISC (Complex Instruction Set Computing) architecture servers, RISC (Reduced Instruction Set Computing) architecture servers, and EPIC architecture servers. Routing information services include, for example, business application registration and business application resolution.
[0124] Mobile terminal 310 is a communication device that can be used while in motion. Mobile terminal 310 includes, but is not limited to, mobile phones, mobile computers, tablets, personal digital assistants (PDAs), media players, smart TVs, smartwatches, smart glasses, smart bracelets, etc.
[0125] Mobile terminal 310 supports multiple third-party service providers, i.e., multiple third-party service servers 120. In the application scenario of mobile security tokens, mobile terminal 310 is, for example, a smartphone used by a user, and the service provider of the third-party service server 120 is, for example, a bank, and the third-party service is, for example, mobile payment services provided by the bank. Therefore, multiple bank-specific trusted applications need to be deployed on the mobile phone.
[0126] Similar to the first embodiment, the trusted applications in the mobile terminal 310 include general trusted applications that support at least some service providers, and customized trusted applications that support specific service providers; it may also support only general applications without customized applications; or support only customized applications without general applications.
[0127] Furthermore, the mobile terminal 310 submits a service resolution request to the routing management server 330 via the network. This service resolution request includes a third-party service identifier. The routing management server 330 queries its routing table based on the third-party service identifier and returns the routing information of the corresponding trusted application to the mobile terminal 310. Therefore, based on the routing information returned by the service resolution request, the mobile terminal 310 selects the appropriate trusted application from general trusted applications and / or customized trusted applications to execute business logic in the secure environment.
[0128] For example, when a user uses a third-party service, the application on mobile terminal 310 selects a general trusted application based on routing information. The user enters their personal password in the general trusted application on mobile terminal 310 for identity verification, and a secure communication key ciphertext is generated using a public key certificate in the secure environment of mobile terminal 310. The client application on mobile terminal 310 submits a service call request and sends the secure communication key ciphertext to the third-party service server 120 to establish a secure channel for performing secure information exchange processes. Other trusted application services are then completed via this secure channel.
[0129] In the aforementioned trusted service system, the mobile terminal 310 selects the corresponding trusted application based on the routing information in the routing table of the routing management server 330. The deployment process of the mobile terminal 310 has been simplified to downloading a customized trusted application from a specific service provider. Therefore, this trusted service system can significantly reduce the trusted application deployment cost for mobile terminal manufacturers.
[0130] Figure 8 Show Figure 7 The diagram shows a schematic block diagram of a mobile terminal in a trusted service system. As shown, the operating environment of the mobile terminal 310 includes a Rich Execution Environment (REE), a Trusted Execution Environment (TEE), and a Secure Element (SE).
[0131] Similar to the first embodiment, the mobile terminal 310 includes an application management module 111. However, in this embodiment, the mobile terminal 310 does not include a local routing table.
[0132] Furthermore, the client application CA of the mobile terminal 310 is used not only to interact with the third-party business server 120 to realize third-party business calls, but also to interact with the routing management server 330 to query the routing information of the third-party business applications.
[0133] When mobile terminal 310 invokes a third-party service, the application management module 111 of mobile terminal 310 submits a service application resolution request to the routing management server 330, and obtains the routing information of the corresponding trusted application of the third-party service by querying the routing table 332 of the routing management server 330. The client application CA selects the corresponding trusted application from the general trusted application TA_A and the customized trusted applications TA_B1 and TA_B2 based on the routing information to execute the business logic in the secure environment.
[0134] Figure 9 Show Figure 7 The diagram shows a schematic block diagram of a routing management server in a trusted service system. As shown, the routing management server 330 includes a registration module 331, a routing table 332, and a resolution module 333.
[0135] The routing information services provided by the routing management server 330 include, for example, business application filing and business application resolution.
[0136] The filing module 331 of the routing management server 330 in the trusted service system according to the third embodiment has the same filing function as the filing module 231 of the routing management server 230 in the trusted service system according to the second embodiment, and will not be described in detail here.
[0137] According to the trusted service system of the third embodiment, the parsing module 333 of the routing management server 330 performs the above-mentioned business application parsing function, including: when the mobile terminal 310 submits a business application parsing request to the routing management server 330, querying the routing table according to the third-party business identifier, and returning the routing information of the corresponding trusted application to the mobile terminal 310.
[0138] The parsing module 333, for example, is a data query module based on Structured Query Language (SQL), which performs data queries on the routing table 332 on the routing management server 330 to obtain routing information for the corresponding trusted applications, and returns the routing information as the query result to the mobile terminal 310.
[0139] Fourth embodiment
[0140] Figure 10 A schematic flowchart illustrating a trusted application management method according to a fourth embodiment of the present invention is shown.
[0141] The trusted application management method includes steps S01 to S03 as described below. For example, this trusted application management method can be applied to… Figures 4 to 6 The trusted service system shown below, in conjunction with Figures 4 to 6 The trusted application management method according to this embodiment will be described in detail.
[0142] In step S01, multiple trusted applications are installed on the mobile terminal.
[0143] Mobile terminal 210 includes a Rich Execution Environment (REE) and a Trusted Execution Environment (TEE). Multiple trusted applications TA_A, TA_B1, and TA_B2 are installed in the TEE of mobile terminal 210. Trusted application TA_A is a general trusted application shared by at least some service providers. Trusted applications TA_B1 and TA_B2 are customized trusted applications from two specific service providers.
[0144] In step S02, the mobile terminal downloads the routing tables of multiple trusted applications.
[0145] The local routing table is a file in the secure file system of the Trusted Execution Environment (TEE) of the mobile terminal 210, or a file stored in the Secure Element (SE).
[0146] A routing table for third-party services is created on the routing management server. When issuing a third-party service, the service provider registers the service application with the routing management server. Based on the registration information, the routing management server writes the routing information of the trusted application corresponding to the third-party service into the routing table.
[0147] If the mobile terminal 210 cannot find a local routing table, it downloads the routing table from the routing management server 230 to create a local routing table 112. If the mobile terminal 210 has found a local routing table, it downloads the routing table from the routing management server 230 and updates the local routing table 112.
[0148] The local routing table 112 includes at least one piece of routing information. This routing information includes a third-party service identifier and a trusted application identifier. The third-party service identifier distinguishes third-party services from multiple service providers, and the trusted application identifier indicates a trusted application corresponding to the third-party service. For example, the third-party service identifier is the hash value of the public key of the third-party service application APPn. The trusted application identifier is a globally unique identifier for the trusted application. Preferably, the routing information also includes a trusted user interface identifier, which indicates a trusted user interface corresponding to the third-party service.
[0149] The local routing table 112 also includes version information. The application management method further includes comparing the version information of the local routing table with the management information of the routing table on the routing management server to determine whether the local routing table needs to be updated.
[0150] In step S03, based on the routing information in the local routing table, the mobile terminal invokes the corresponding trusted application to complete the third-party service.
[0151] When a user submits a request for a third-party service, the mobile terminal 210 obtains the third-party service identifier.
[0152] Based on the third-party service identifier, the mobile terminal 210 performs a data query on the local router to obtain the trusted application identifier of the third-party service.
[0153] Furthermore, the application management module 111 in the mobile terminal 210 invokes the corresponding trusted application based on the trusted application identifier to complete third-party services. For example, third-party services include at least one of the following services provided by the service provider: digital certificate application, transaction signature verification, mobile payment, bank account inquiry, etc.
[0154] In step S03, the application management module 111 may only be responsible for managing the local routing table. The client application CA in the mobile terminal 210 directly calls the corresponding trusted application based on the trusted application identifier to complete third-party services. For example, third-party services include at least one of the following services provided by the service provider: digital certificate application, transaction signature verification, mobile payment, and bank account inquiry. Figure 12 Figure 13 The detailed process example will not be described further for this embodiment.
[0155] Figure 11 Show Figure 10 The flowchart shown is a detailed flowchart of the local routing table update in the trusted application management method.
[0156] When a user submits a third-party service request in the third-party service application APPn, the third-party service application APPn generates a version query command, thereby executing the following local routing table update process. The third-party service application APPn on the mobile terminal 210 can support third-party services from multiple service providers. For example, the third-party service application APPn is a mobile wallet application that supports mobile payment functions provided by multiple banking institutions.
[0157] In step S11, the mobile terminal 210 submits a version query request to the routing management server 230.
[0158] The version query command sent by the third-party business application APPn of the mobile terminal 210 is submitted to the routing management server 230 via network communication.
[0159] In step S12, the routing management server 230 performs a data query on the registered routing table to obtain the version information of the registered routing table, and then returns it to the mobile terminal 210.
[0160] The third-party business application APPn of mobile terminal 210 obtains the version information of the filing routing table.
[0161] In step S13, the mobile terminal 210 compares the version information of the local routing table with the version information of the registered routing table.
[0162] The third-party business application APPn of mobile terminal 210 reads the local routing table from the application management module 111 through the client application CA to obtain the version information of the local routing table, and then compares the versions of the local routing table and the filing routing table.
[0163] If the local routing table is not found, or the version of the local routing table is lower than the version of the registered routing table, the third-party business application APPn of the mobile terminal 210 submits a routing table download request to the routing management server 230 via network communication.
[0164] In step S14, the mobile terminal 210 downloads the routing table from the routing management server.
[0165] If the mobile terminal 210 does not find a local routing table, it downloads the routing table from the routing management server 230. The application management module 111 then creates and stores the local routing table 112 in the secure file system of the Trusted Execution Environment (TEE). If the mobile terminal 210 has already found a local routing table in the secure file system of the TEE, it downloads the routing table from the routing management server 230. The application management module 111 then uses the downloaded routing table to replace the local routing table 112, thus updating the system.
[0166] Preferably, before storing or updating the local routing table 112, the application management module 111 verifies the trustworthiness of the routing table downloaded from the routing management server 230.
[0167] Figure 12 Show Figure 10 The flowchart shown is a detailed process for applying for digital certificates in the trusted application management method.
[0168] In this embodiment, the user executes the following digital certificate activation process in the third-party business application APPn. The third-party business application APPn on the mobile terminal 210 is a third-party service of a service provider. For example, the third-party business application APPn is a mobile wallet application that supports mobile payment functions provided by multiple banking institutions, or the third-party business application APPn is a mobile banking application of a banking institution.
[0169] In step S21, the third-party business application APPn requests a digital certificate request message.
[0170] The third-party application APPn calls the toolkit SDKn to generate a certificate request interface. The toolkit SDKn sends a key pair request message and a user key setting instruction to the application management module 111 via the client application CA. Both the key pair request message and the user key setting instruction include a third-party business identifier.
[0171] In step S22, the corresponding trusted application is invoked to perform permission verification based on the routing information of the third-party service.
[0172] After receiving the key pair request message, the application management module 111 of the mobile terminal 210 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier corresponding to the third-party service identifier. Further, the application management module 111 calls the trusted application corresponding to the trusted application identifier. The trusted application communicates with the security element SE via the SE driver. The security element SE performs security or cryptographic-related operations to generate a key pair.
[0173] Furthermore, the trusted application returns to the SDKn toolkit.
[0174] In step S23, the trusted user interface is invoked to set the user key based on the routing information of the third-party service.
[0175] After receiving the user key setting instruction, the application management module 111 of the mobile terminal 210 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier and trusted user interface identifier corresponding to the third-party service identifier. Further, the application management module 111 calls the trusted user interface corresponding to the trusted user interface identifier, where the user sets the user key and calls the trusted application corresponding to the trusted application identifier to save the user key.
[0176] Furthermore, the trusted application returns to the SDKn toolkit.
[0177] In step S24, a digital certificate request message is generated by calling the corresponding trusted application based on the routing information of the third-party service.
[0178] The toolkit SDKn of mobile terminal 210 generates a message generation request. The message generation request includes a third-party service identifier. After receiving the message generation request, application management module 111 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier corresponding to the third-party service identifier.
[0179] Furthermore, the application management module 111 invokes the trusted application corresponding to the trusted application identifier. The trusted application communicates with the security element SE via the SE driver. The security element SE performs security or cryptographic-related operations, generating a public key and a signature of the public key based on the user key and key pair. Further, the trusted application generates a digital certificate request message using the public key and public key signature generated by the security element SE, and signs it with the device key of the mobile terminal.
[0180] Furthermore, the application management module 111 of the mobile terminal 210 obtains a digital certificate request message from a trusted application, and the third-party business application APPn of the mobile terminal 210 obtains a digital certificate request message from the application management module 111 via the client application CA.
[0181] In step S25, the mobile terminal submits a digital certificate issuance request to the third-party business server. Specifically, the third-party business application APPn of the mobile terminal 210 sends the digital certificate request message to the third-party business server 120.
[0182] In step S26, the third-party business server issues a digital certificate. Specifically, after verifying the digital certificate request message using the mobile terminal's device public key, the third-party business server requests the certificate authority to generate a digital certificate and then returns the digital certificate to the mobile terminal 210.
[0183] In step S27, a digital certificate is written into the mobile terminal.
[0184] After receiving the digital certificate, the third-party application APPn on mobile terminal 210 sends the digital certificate to the toolkit SDKn. The toolkit SDKn queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier corresponding to the third-party service identifier.
[0185] Furthermore, the application management module 111 calls the trusted application corresponding to the trusted application identifier, and the trusted application writes the digital certificate into the secure file system of the Trusted Execution Environment (TEE) of the mobile terminal 210.
[0186] Figure 13 Show Figure 10 The flowchart shown is a detailed representation of the use of digital certificates in the trusted application management method.
[0187] In this embodiment, when a user uses a third-party service in the third-party business application APPn, the third-party business application APPn will execute the following digital certificate usage process. The third-party business application APPn on the mobile terminal 210 can support third-party services from multiple service providers. For example, the third-party business application APPn is a mobile wallet application that supports mobile payment functions provided by multiple banking institutions.
[0188] In step S31, the third-party business application APPn requests a transaction signature.
[0189] The third-party business application APPn calls the toolkit SDKn to generate a transaction signature request interface. The toolkit SDKn sends a transaction signature message and a user key verification instruction to the application management module 111 via the client application CA. The transaction signature and user key verification instruction each include a third-party business identifier.
[0190] In step S32, the corresponding trusted application is invoked to perform permission verification based on the routing information of the third-party service.
[0191] After receiving the transaction signature, the application management module 111 of the mobile terminal 210 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier corresponding to the third-party service identifier. Further, the application management module 111 calls the trusted application corresponding to the trusted application identifier. The trusted application performs permission verification, and saves the signature request data after successful verification.
[0192] Furthermore, the trusted application returns to the SDKn toolkit.
[0193] In step S33, the trusted user interface is invoked based on the routing information of the third-party service to display the content to be signed and to request verification of the user key.
[0194] After receiving a user key verification request instruction, the application management module 111 of the mobile terminal 210 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier and trusted user interface identifier corresponding to the third-party service identifier. Further, the application management module 111 calls the trusted user interface corresponding to the trusted user interface identifier, displays the content to be signed, and prompts the user to enter the user key (or user PIN code) in the trusted user interface, and calls the trusted application corresponding to the trusted application identifier to verify the user key.
[0195] Furthermore, the trusted application returns the user key verification request result to the toolkit SDKn.
[0196] In step S34, the corresponding trusted application is invoked to generate a signature verification message based on the routing information of the third-party service.
[0197] The toolkit SDKn of mobile terminal 210 generates a message generation request. The message generation request includes a third-party service identifier. After receiving the message generation request, application management module 111 queries the local routing table 112 based on the third-party service identifier to obtain the trusted application identifier corresponding to the third-party service identifier.
[0198] Furthermore, the application management module 111 calls the trusted application corresponding to the trusted application identifier. The trusted application communicates with the security element SE via the SE driver. The security element SE performs security or cryptographic-related operations, verifies the user key based on the user key and the data to be signed, and generates a signature result. Further, the trusted application generates a signature verification message after obtaining the signature result.
[0199] Furthermore, the application management module 111 of the mobile terminal 210 obtains the signature verification message from the trusted application, and the third-party business application APPn of the mobile terminal 210 obtains the signature verification message from the application management module 111 via the client application CA.
[0200] In step S35, the mobile terminal submits a signature verification request to the third-party service server. Specifically, the third-party service application APPn of the mobile terminal 210 sends a signature verification message to the third-party service server 120.
[0201] In step S36, the third-party business server performs signature verification and then returns the signature verification result to the mobile terminal 210.
[0202] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0203] As described above, these embodiments of the present invention do not exhaustively cover all details, nor do they limit the invention to the specific embodiments described. Clearly, many modifications and variations can be made based on the above description. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to effectively utilize the invention and its modifications. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. A trusted application management method, comprising: Install multiple trusted applications in a trusted execution environment on a mobile terminal; The multiple trusted applications include at least some general trusted applications shared by service providers, and at least one customized trusted application from a specific service provider; or the multiple trusted applications include a general trusted application shared by multiple service providers. as well as Based on the routing information of the multiple trusted applications, the corresponding trusted application among the multiple trusted applications is invoked to complete the third-party business. Among them, trusted applications corresponding to the third-party services are obtained based on the data query results of the routing management server; When issuing third-party services, the service provider files a business application registration with the routing management server; the routing management server creates routing information for the trusted application corresponding to the third-party service based on the registration information of the business application registration. The filing information includes: Third-party service identifiers are used to distinguish third-party services from those of multiple service providers; and Trusted application identifier, used to indicate the trusted application corresponding to the third-party service.
2. The trusted application management method according to claim 1 further includes: Based on the data query results of the local routing table, obtain the trusted application corresponding to the third-party service.
3. The trusted application management method according to claim 2, wherein, The local routing table includes at least one piece of routing information, which includes a third-party service identifier and a trusted application identifier. The third-party service identifier is used to distinguish third-party services from multiple service providers, and the trusted application identifier is used to indicate a trusted application corresponding to the third-party service.
4. The trusted application management method according to claim 3, wherein, The routing information in the local routing table also includes a trusted user interface identifier, which is used to indicate a trusted user interface corresponding to the third-party service.
5. The trusted application management method according to claim 2 further includes: Download the routing table from the routing management server to create the local routing table; and / or The local routing table is updated based on the data query results from the routing management server.
6. The trusted application management method according to claim 5, wherein, The local routing table includes version information, and the application management method further includes comparing the version information of the local routing table with the management information of the routing table on the routing management server to determine whether to update the local routing table.
7. The trusted application management method according to claim 6, wherein, The local routing table is a file in the secure file system of the trusted execution environment.
8. The trusted application management method according to claim 6, wherein, The mobile terminal also includes a security element, and the local routing table is a file stored in the security element.
9. The trusted application management method according to claim 1, wherein, The third-party services include at least one of the following services provided by the service provider: electronic certificate application, transaction signature verification, mobile payment, and bank account inquiry.
10. The trusted application management method according to claim 1, wherein, The filing information also includes at least one of the following: A trusted user interface identifier is used to indicate a trusted user interface corresponding to the third-party service; The public key of the third-party business server is used to verify the signatures issued by the third-party business service; The service provider's Chinese name is used to display on the business application management page; The service provider's English name is used to display on the business application management page.
11. The trusted application management method according to claim 1 or 3, wherein, The third-party business identifier is the hash value of the public key of the third-party business application's signature, or the installation package name of the third-party business application, or a unique identifier representing the third-party business application.
12. The trusted application management method according to claim 4 or 10, wherein, The trusted application identifier is a globally unique identifier for the corresponding trusted application.
13. A mobile terminal, comprising: Client applications installed in the rich execution environment of the mobile terminal; Multiple trusted applications installed in the trusted execution environment of the mobile terminal; The multiple trusted applications include at least some general trusted applications shared by service providers, and at least one customized trusted application from a specific service provider; or the multiple trusted applications include a general trusted application shared by multiple service providers. as well as The application management module, based on the routing information of the multiple trusted applications, invokes the corresponding trusted application among the multiple trusted applications to complete third-party business. The application management module obtains trusted applications corresponding to the third-party services based on the data query results from the routing management server. When issuing third-party services, the service provider files a business application registration with the routing management server; the routing management server creates routing information for the trusted application corresponding to the third-party service based on the registration information of the business application registration. The filing information includes: Third-party service identifiers are used to distinguish third-party services from those of multiple service providers; and Trusted application identifier, used to indicate the trusted application corresponding to the third-party service.
14. The mobile terminal according to claim 13, further comprising: A local routing table is used to store routing information for the multiple trusted applications. The application management module obtains trusted applications corresponding to the third-party services based on the data query results of the local routing table.
15. The mobile terminal according to claim 14, wherein, The local routing table includes at least one piece of routing information, which includes a third-party service identifier and a trusted application identifier. The third-party service identifier is used to distinguish third-party services from multiple service providers, and the trusted application identifier is used to indicate a trusted application corresponding to the third-party service.
16. The mobile terminal according to claim 15, wherein, The routing information in the local routing table also includes a trusted user interface identifier, which is used to indicate a trusted user interface corresponding to the third-party service.
17. The mobile terminal according to claim 14, wherein, The mobile terminal downloads a routing table from the routing management server to create the local routing table; and / or updates the local routing table based on the data query results from the routing management server.
18. The mobile terminal according to claim 17, wherein, The local routing table includes version information. The mobile terminal compares the version information of the local routing table with the management information of the routing table on the routing management server to determine whether to update the local routing table.
19. The mobile terminal according to claim 18, wherein, The local routing table is a file in the secure file system of the trusted execution environment.
20. The mobile terminal according to claim 18, wherein, The mobile terminal also includes a security element, and the local routing table is a file stored in the security element.
21. The mobile terminal according to claim 13, wherein, The third-party services include at least one of the following services provided by the service provider: electronic certificate application, transaction signature verification, mobile payment, and bank account inquiry.
22. The mobile terminal according to claim 15, wherein, The third-party business identifier is the hash value of the public key of the third-party business application's signature, or the installation package name of the third-party business application, or a unique identifier representing the third-party business application.
23. The mobile terminal according to claim 16, wherein, The trusted application identifier is a globally unique identifier for the corresponding trusted application.
24. A trusted service system, comprising: Third-party business server; as well as The mobile terminal according to any one of claims 13 to 23, The mobile terminal submits a service call request to the third-party service server and establishes a secure channel with the third-party service server to complete the third-party service.
25. The trusted service system according to claim 24, further comprising: A routing management server, comprising a registration routing table, which stores routing information for the multiple trusted applications. When issuing third-party services, the service provider files a business application registration with the routing management server. The routing management server then creates routing information for the trusted application corresponding to the third-party service based on the registration information.
26. The trusted service system according to claim 25, wherein, The filing information includes: Third-party service identifiers are used to distinguish third-party services from those of multiple service providers; and Trusted application identifier, used to indicate the trusted application corresponding to the third-party service.
27. The trusted service system according to claim 26, wherein, The filing information also includes at least one of the following: A trusted user interface identifier is used to indicate a trusted user interface corresponding to the third-party service; The public key of the third-party business server is used to verify the signatures issued by the third-party business service; The service provider's Chinese name is used to display on the business application management page; The service provider's English name is used to display on the business application management page.
Citation Information
Patent Citations
Mobile phone shield-based mobile terminal and mobile phone shield managing method
CN108469962A
Constructing common trusted application for a plurality of applications
CN111357255A
Digital wallet security framework system based on security unit and trusted execution environment
CN114465726A