Authentication method and terminal device

By using TEE and NFCC to quickly respond to card reader verification instructions in terminal devices, the problem of low cost and strict latency requirements in the prior art is solved, and a wider application range and lower cost are achieved, while ensuring user experience.

CN116074832BActive Publication Date: 2025-07-01HONOR DEVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111538861.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2021-11-03
Filing Date
2021-12-15
Publication Date
2025-07-01
Estimated Expiration
2041-12-15

AI Technical Summary

Technical Problem

Existing terminal devices with NFC function cannot take into account the problems of low cost and strict application in scenarios with strict delay requirements.

Method used

By introducing a trusted application of a trusted execution environment (TEE) into the terminal device, the near field communication controller (NFCC) transmits interrupt requests to the processor, quickly responding to the card reader's verification instructions, thereby generating and sending an answer message, reducing response delay.

Benefits of technology

It realizes scenarios that meet strict delay requirements without installing embedded security modules (eSE), expands the application scope, reduces costs, and ensures user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116074832B_ABST
    Figure CN116074832B_ABST
Patent Text Reader

Abstract

The present application provides an authentication method and a terminal device, relating to the technical field of terminals. For this authentication method, in response to a verification instruction from a card reader, the NFCC transmits an interrupt request to the processor. In response to the interrupt request, the processor calls the TA running in the TEE to pause the process being processed without waiting for the process being processed to finish execution. Immediately, the processor calls the TA in the TEE to read the verification instruction from the NFCC and generate a response message. The processor sends the response message to the card reader via the NFCC. The processor receives the encrypted second verification information from the card reader. The processor uses the first verification information, the encrypted second verification information, and a preset card key to complete the authentication interaction with the card reader. This enables the terminal device to have a shorter response delay, allowing the terminal device to be applied to scenarios with strict latency requirements, with a wider range of applications, and without the need to install an eSE, resulting in low costs.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application claims the priority of a Chinese patent application titled "Authentication Method" with the application number 202111294528.0, which was filed with the Chinese Patent Office on November 3, 2021. The entire content of this application is incorporated herein by reference. Technical Field

[0002] This application relates to the field of terminal technologies, and particularly to an authentication method and a terminal device. Background Art

[0003] Currently, the near field communication technology NFC (near field communication, NFC) has been widely used in terminal devices. Generally, a user can use a terminal device with NFC function to approach a card reader and authenticate with the card reader. After the authentication is completed, the target function can be achieved. For example, a user can use a terminal device with NFC function to approach the card reader of a bus and authenticate with the bus card reader. After the authentication is completed, the function of swiping the bus card can be completed; another example is that a user can use a terminal device with NFC function to approach the card reader of an access control and authenticate with the card reader of the access control. After the authentication is completed, the function of unlocking the access control can be completed.

[0004] Generally, an embedded secure element (eSE) can be integrated in the NFC chip of a terminal device. When the NFC chip of the terminal device receives an authentication instruction from the card reader, the eSE can immediately feedback a response message to the card reader. Furthermore, the eSE performs authentication interaction with the card reader in a secure environment. However, installing an eSE in a terminal device has a relatively high cost.

[0005] Alternatively, when the NFC chip of the terminal device receives an authentication instruction from the card reader, it transmits the authentication instruction to the processor of the terminal device. The processor of the terminal device performs authentication interaction with the card reader by running the host based card emulation (HCE) application in the rich execution environment (REE). However, the latency of the HCE application running in the REE to feedback a response message to the card reader is relatively long. In some scenarios with strict latency requirements (such as the scenario of unlocking an access control), the response message feedback by the HCE application will be misrecognized as an invalid message by the card reader. In this way, the terminal device cannot complete the authentication interaction with the card reader, resulting in a narrow application range.

[0006] Thus, the current terminal devices with NFC function have the problem that they cannot balance both low cost and being applicable to scenarios with strict latency requirements. Summary of the Invention

[0007] The present application provides an authentication method and a terminal device to solve the problem that a terminal device with NFC function cannot achieve both low cost and application in scenarios with strict latency requirements.

[0008] In a first aspect, the present application provides an authentication method applied to a terminal device, where the terminal device includes a Near Field Communication Controller (NFCC) and a processor. The method includes: The NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader. The processor, in response to the interrupt request, calls a Trusted Application (TA) in a Trusted Execution Environment (TEE) to pause the process being processed. The processor calls the TA in the TEE to read the verification instruction from the NFCC and generate a response message, where the response message carries first verification information. The processor sends the response message to the card reader via the NFCC. The processor receives encrypted second verification information from the card reader via the NFCC. The processor uses the first verification information, the encrypted second verification information, and a preset card key to complete the authentication interaction with the card reader.

[0009] In the authentication method provided by the present application, after the NFCC receives a verification instruction from the card reader, it transmits an interrupt request to the processor. Further, the processor immediately calls the TA in the TEE to pause the process being processed, and without waiting for the process being processed to complete, it can read the verification instruction from the NFCC and generate a response message. Further, the processor sends the response message to the card reader via the NFCC. This saves time and enables the terminal device to have a short response latency. In this way, it can meet the requirement that the duration (i.e., the response latency) from when the card reader issues a verification instruction to when it receives a response message within a preset duration as specified by the preset protocol of the card reader. In this way, the response message fed back by the terminal device will be recognized as a valid message by the card reader. In this way, the authentication interaction between the terminal device and the card reader can be completed. In this way, a terminal device with NFC function can be applied to scenarios with strict latency requirements, has a wider application range, does not require the installation of an eSE, has a low cost, and at the same time, ensures that the user's card swiping experience remains unchanged.

[0010] In a possible implementation, the NFCC is provided with an irq_tee interrupt source. The NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader, including: The NFCC, in response to a verification instruction from a card reader, activates the irq_tee interrupt source to transmit an interrupt request to the processor.

[0011] It can be understood that by separately setting the irq_tee interrupt source in the NFCC, the process in the TEE can be interrupted by the NFCC without affecting the process in the Rich Execution Environment (REE).

[0012] In a possible implementation, the processor calls the trusted application (TA) of the trusted execution environment (TEE) to suspend the process being processed, including: the processor calls the TA of the TEE to set the process in the runnable state to an interruptible waiting state process.

[0013] In a possible implementation, the processor sends a response message to the card reader via the NFCC, including: the processor pulls down the chip select signal and transmits a data write request to the NFCC. In response to the data write request, the NFCC detects whether the chip select signal is pulled down. If it is pulled down, the NFCC reads the response message from the processor. The NFCC sends the response message to the card reader.

[0014] In a possible implementation, data interaction between the NFCC and the processor is performed via the SPI bus.

[0015] Understandably, the SPI bus is a high-speed serial bus, and the data transfer rate can reach 20 Mbps. In this way, the response delay of the mobile phone 100 can be further shortened.

[0016] In a possible implementation, the processor uses the first verification information, the encrypted second verification information, and a preset card key to complete the authentication interaction with the card reader, including: the processor decrypts the second verification information in the TEE according to the preset card key. The processor verifies the card reader in the TEE according to the second verification information and the first verification information. If the verification of the card reader is passed, the processor encrypts the second verification information in the TEE based on the preset card key. The processor sends the encrypted second verification information to the card reader via the NFCC so that the card reader verifies the terminal device according to the received second verification information and the sent second verification information.

[0017] In a possible implementation, the bus through which the processor communicates with the NFCC in the rich execution environment (REE) is the same as or different from the bus through which the processor communicates with the NFCC in the TEE.

[0018] In a possible implementation, the bus through which the processor communicates with the NFCC in the REE is the same as the bus through which the processor communicates with the NFCC in the TEE. The method further includes: when being instructed to communicate with the NFCC via the bus in the TEE, the processor detects whether the bus is in a communication state in the TEE. If it is not in a communication state, the processor locks the bus in the TEE. The processor communicates with the NFCC via the bus in the TEE. After the processor finishes communicating with the NFCC, the processor unlocks the bus.

[0019] In this way, when the processor calls an application running in the REE or calls a TA running in the TEE, there will be no conflict in communicating with the NFCC via the same bus, and since a single bus is reused, resources are saved.

[0020] Alternatively, in another possible implementation, the processor communicates with the NFCC through a first bus in the REE, and the processor communicates with the NFCC through a second bus in the TEE, and the first bus and the second bus share the same GPIO interface of the processor. The method further includes: when being instructed to communicate with the NFCC through the first bus in the TEE, the processor detects whether the GPIO interface is in a communication state in the TEE. If not, the processor locks the GPIO interface in the TEE. The processor communicates with the NFCC through the first bus and the GPIO interface in the TEE. After the communication between the processor and the NFCC is completed, the processor unlocks the GPIO interface.

[0021] In this way, when the processor calls an application running in the REE or calls a TA running in the TEE, there will be no conflict in communicating with the NFCC through the same CPIO interface, and since the same CPIO interface is reused, resources are saved.

[0022] In a possible implementation, the method provided by this application further includes: after the processor establishes an SCP02 / 03 secure channel with the server in the TEE, the processor manages preset card information in response to a user's trigger operation, where the preset card information includes a card key.

[0023] After the processor establishes an SCP02 / 03 secure channel with the server in the TEE, managing the preset card information ensures data security.

[0024] Further, managing the preset card information includes: before the NFCC transmits an interrupt request to the processor in response to an authentication instruction from a card reader, the processor creates the preset card information in the TEE. And / or the processor activates the preset card information in the TEE. And / or the processor backs up the preset card information to the server in the TEE. And / or the processor downloads the preset card information from the server in the TEE. And / or after the processor completes the authentication interaction with the card reader using the first authentication information, the encrypted second authentication information, and the preset card information, the processor deletes the preset card information or switches the activated card information in the TEE.

[0025] In a possible implementation, the card reader is a card reader for access control, a card reader for a bus, or a card reader for a bank card.

[0026] In a possible implementation, in response to a verification instruction from a card reader, the NFCC transmits an interrupt request to the processor; in response to the interrupt request, the processor calls a trusted application (TA) in the trusted execution environment (TEE) to pause the process being processed; the processor calls the TA in the TEE to read the verification instruction from the NFCC and generate a response message, where the response message carries first verification information; the processor sends the response message to the card reader via the NFCC, which is replaced by: In response to a verification instruction from a card reader, the NFCC generates a response message. Wherein, the response message carries first verification information. The NFCC sends the response message to the card reader. The NFCC writes the response message to the processor.

[0027] In this way, the terminal device with NFC function can be applied to scenarios with strict latency requirements, has a wider application range, does not require the installation of eSE, and has low cost; at the same time, the user experience is ensured to remain unchanged. In this way, the terminal device with NFC function can be applied to scenarios with strict latency requirements, has a wider application range, does not require the installation of eSE, and has low cost; at the same time, the user experience is ensured to remain unchanged.

[0028] In a second aspect, the present application further provides a terminal device, including a processor, an NFCC, and a memory, where the memory is used to store code instructions; the NFCC and the processor are used to run the code instructions, so that the terminal device executes the authentication method described in the first aspect or any one of the implementation manners of the first aspect.

[0029] In a third aspect, the present application provides a computer-readable storage medium, where the computer-readable storage medium stores instructions, and when the instructions are executed, the computer executes the authentication method described in the first aspect or any one of the implementation manners of the first aspect.

[0030] In a fourth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is run, the computer executes the authentication method described in the first aspect or any one of the implementation manners of the first aspect.

[0031] It should be understood that the second aspect to the fourth aspect of the present application correspond to the technical solutions of the first aspect of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated. Description of the Drawings

[0032] Figure 1 It is a running environment diagram of the terminal device;

[0033] Figure 2 It is an interaction schematic diagram between the terminal device and the card reader of the bus;

[0034] Figure 3 It is a signal latency diagram of the card reader for access control;

[0035] Figure 4 Schematic diagram of the hardware architecture of mobile phone 100 provided by an embodiment of the present application;

[0036] Figure 5 One of the operating environment diagrams when the mobile phone 100 provided by an embodiment of the present application interacts with the access control card reader 101;

[0037] Figure 6 One of the interaction flowcharts of the authentication method provided by an embodiment of the present application;

[0038] Figure 7 Scene diagram of the user holding the mobile phone 100 close to the access control card reader 101 provided by an embodiment of the present application;

[0039] Figure 8 Flowchart of the steps executed by the NFCC 103 when feedbacking a response message to the access control card reader 101 provided by an embodiment of the present application;

[0040] Figure 9 Flowchart of the steps executed by the processor 102 when feedbacking a response message to the access control card reader 101 provided by an embodiment of the present application;

[0041] Figure 10 Is Figure 6 Further interaction flowchart of S507 in

[0042] Figure 11 Another interaction flowchart of the authentication method provided by an embodiment of the present application;

[0043] Figure 12 Schematic diagram of the interface for the mobile phone 100 provided by an embodiment of the present application to read the card information stored in the access control card 106 in response to a user's trigger operation;

[0044] Figure 13 Interaction flowchart of the mobile phone 100 provided by an embodiment of the present application to create card information;

[0045] Figure 14 Schematic diagram of the interface for the mobile phone 100 provided by an embodiment of the present application to delete card information in response to a user's trigger operation;

[0046] Figure 15 Schematic diagram of the interface for the mobile phone 100 provided by an embodiment of the present application to download card information in response to a user's trigger operation;

[0047] Figure 16 Schematic diagram of the interface for the mobile phone 100 provided by an embodiment of the present application to activate card information in response to a user's trigger operation;

[0048] Figure 17The second operational environment diagram when the mobile phone 100 provided in the embodiment of the present application interacts with the access control card reader 101;

[0049] Figure 18 The third operational environment diagram when the mobile phone 100 provided in the embodiment of the present application interacts with the access control card reader 101;

[0050] Figure 19 The fourth operational environment diagram when the mobile phone 100 provided in the embodiment of the present application interacts with the access control card reader 101;

[0051] Figure 20 The third interaction flowchart of the authentication method provided in the embodiment of the present application;

[0052] Figure 21 The schematic diagram of the hardware structure of a terminal device provided in the embodiment of the present application;

[0053] Figure 22 The schematic diagram of the structure of a chip provided in the embodiment of the present application. Detailed implementation manners

[0054] For the convenience of clearly describing the technical solutions of the embodiments of the present application, in the embodiments of the present application, terms such as "first" and "second" are used to distinguish identical or similar items with basically the same functions and effects. For example, the first value and the second value are only used to distinguish different values, and do not limit their sequence. Those skilled in the art can understand that terms such as "first" and "second" do not limit the quantity and execution order, and terms such as "first" and "second" do not necessarily limit being different.

[0055] It should be noted that in the present application, words such as "exemplary" or "for example" are used to represent examples, illustrations or explanations. Any embodiment or design solution described as "exemplary" or "for example" in the present application should not be construed as being more preferred or having more advantages than other embodiments or design solutions. Exactly speaking, using words such as "exemplary" or "for example" is intended to present related concepts in a specific manner.

[0056] In this application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the relationship between associated objects and indicates that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B can be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item)" or similar expressions refer to any combination of these items, including any combination of single-item (item) or multiple-items (items). For example, at least one (item) of a, b, or c can represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c can be single or multiple.

[0057] Currently, the near field communication technology NFC (near field communication, NFC) has been widely used in terminal devices. Generally, users can use a terminal device with NFC function to approach a card reader and perform authentication interaction with the card reader. After the authentication interaction is successful, the card reader can implement the target function.

[0058] In addition, as Figure 1 shown, the operating environment when the processor of the terminal device processes data includes a rich execution environment (REE) and a trusted execution environment (rusted execution environment, TEE). The client application (CA) runs in the REE, and the trusted application (TA) runs in the TEE.

[0059] Exemplarily, in the scenario of swiping a card on a bus, when the user holds the terminal device close to the card reader of the bus, as Figure 2 shown, the card reader of the bus establishes a short - distance communication connection with the near field communication controller NFCC (near field communication controler, NFCC) of the terminal device. Furthermore, the terminal device can complete the authentication interaction with the card reader of the bus in any of the following ways.

[0060] The first way: An embedded eSE can be integrated in the NFC chip of the terminal device. When the NFC chip of the terminal device receives an authentication instruction from the card reader of the bus, the eSE can immediately feedback a response message to the card reader of the bus. Furthermore, the eSE performs authentication interaction with the card reader of the bus in a secure environment. However, installing eSE in the terminal device has a relatively high cost.

[0061] The second type: When the NFC chip of the terminal device receives the authentication instruction from the card reader of the bus, it transmits the authentication instruction to the processor of the terminal device. The processor of the terminal device feeds back a response message to the card reader of the bus through the card simulation HCE application in REE, or the terminal device uses the cloud server to feed back a response message to the card reader of the bus. Then, the terminal device performs authentication interaction with the card reader; or, the terminal device uses the cloud server to complete the authentication interaction with the card reader. However, this will result in a longer delay in the feedback of the response message by the terminal device, that is, the interval between the issuance of the verification instruction by the access control card reader and the receipt of the response message is longer than the preset duration (such as 400us).

[0062] Generally, the protocol of the bus card reader has a relatively low requirement for latency. Even if the above interval is longer than 400us, the bus card reader confirms that the received response message is valid. Then, the bus card reader can interact with the terminal device for authentication based on the first verification information to complete the deduction function. However, the protocol of the access control card reader has a relatively strict requirement for latency, such as Figure 3 As shown in the figure, the interval between the card reader sending the verification command and receiving the response message must be within Figure 3 In this way, the above authentication method cannot be applied to the access control unlocking scenario.

[0063] In summary, the terminal devices with NFC function have the problem of not being able to achieve both low cost and being applicable to scenarios with strict latency requirements.

[0064] In view of this, the present application provides an authentication method, which is applied to a terminal device, and the terminal device includes a near field communication controller NFCC and a processor. The method provided by the present application includes: the NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader. In response to the interrupt request, the processor calls a trusted application TA in a trusted execution environment TEE to suspend the execution of the process being processed. The processor calls the TA in the TEE to read the verification instruction from the NFCC and generates a response message, wherein the response message carries the first verification information. The processor sends a response message to the card reader via the NFCC. The NFCC or the processor receives the encrypted second verification information from the card reader. The NFCC or the processor uses the first verification information, the encrypted second verification information, and the preset card key to complete the authentication interaction with the card reader.

[0065] It can be seen that in the authentication method provided in this application, after the NFCC receives the verification instruction from the card reader, it transmits an interrupt request to the processor. Subsequently, the processor immediately calls the TA in the TEE to pause the process being processed, and without waiting for the process being processed to complete, it can read the verification instruction from the NFCC and generate a response message. Subsequently, the processor sends the response message to the card reader via the NFCC. This saves time and can make the response latency of the terminal device shorter. In this way, it can meet the requirement that the duration (i.e., the response latency) from the card reader sending the verification instruction to receiving the response message within the preset duration as specified by the preset protocol of the card reader. In this way, the response message fed back by the terminal device will be recognized as a valid message by the card reader. In this way, the authentication interaction between the terminal device and the card reader can be completed. In this way, the terminal device with NFC function can be applied to scenarios with strict latency requirements, has a wide application range, and does not require the installation of eSE, with low cost.

[0066] It can be understood that the above terminal device can also be referred to as a terminal, (terminal), user equipment (UE), mobile station (MS), mobile terminal (MT), etc. The terminal device can be a wearable device, a tablet computer (Pad), a computer with wireless transceiver function, a virtual reality (VR) terminal device, an augmented reality (AR) terminal device, and so on. The specific technologies and specific device forms adopted by the terminal device in the embodiments of this application are not limited.

[0067] In order to better understand the embodiments of this application, the structure of the terminal device in the embodiments of this application will be introduced below. Exemplarily, Figure 4 It is a schematic structural diagram of a terminal device provided by an embodiment of this application.

[0068] The terminal device may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a sensor module 180, a key 190, an indicator 192, a camera 193, and a display screen 194, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0069] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the terminal device. In other embodiments of the present application, the terminal device may include more or fewer components than those illustrated, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0070] The processor 110 may include one or more processing units. Among them, different processing units may be independent devices or integrated in one or more processors. A memory may also be provided in the processor 110 for storing instructions and data.

[0071] The USB interface 130 is an interface that complies with the USB standard specification, and may specifically be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 may be used to connect a charger to charge the terminal device, and may also be used for data transmission between the terminal device and peripheral devices. It may also be used to connect a headset to play audio through the headset. This interface may also be used to connect other electronic devices, such as AR devices, etc.

[0072] The charging management module 140 is used to receive a charging input from a charger. Among them, the charger may be a wireless charger or a wired charger. The power management module 141 is used to connect the charging management module 140 and the processor 110.

[0073] The wireless communication function of the terminal device may be implemented through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, a modulation and demodulation processor, and a baseband processor, etc.

[0074] Antenna 1 and Antenna 2 are used for transmitting and receiving electromagnetic wave signals. The antennas in the terminal device can be used to cover single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas.

[0075] The mobile communication module 150 can provide solutions for wireless communications such as 2G / 3G / 4G / 5G applied to the terminal device. The mobile communication module 150 can include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves through Antenna 1, and perform processing such as filtering and amplifying on the received electromagnetic waves, and then transmit them to the modulation and demodulation processor for demodulation.

[0076] The wireless communication module 160 can provide solutions for wireless communications applied to the terminal device, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), etc.

[0077] The terminal device realizes the display function through the GPU, the display screen 194, and the application processor, etc. The GPU is a microprocessor for image processing, and is connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering.

[0078] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. In some embodiments, the terminal device may include one or N display screens 194, where N is a positive integer greater than 1.

[0079] The terminal device can realize the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor, etc.

[0080] The camera 193 is used to capture static images or videos. In some embodiments, the terminal device may include one or N cameras 193, where N is a positive integer greater than 1.

[0081] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to implement the storage capacity expansion of the terminal device. The external memory card communicates with the processor 110 through the external memory interface 120 to implement the data storage function. For example, files such as music and videos are saved in the external memory card.

[0082] The internal memory 121 can be used to store computer-executable program codes, and the executable program codes include instructions. The internal memory 121 can include a program storage area and a data storage area.

[0083] The terminal device can implement audio functions through the audio module 170, the speaker 170A, the receiver 170B, the microphone 170C, and the application processor, etc. For example, music playback, recording, etc.

[0084] The audio module 170 is used to convert digital audio information into an analog audio signal for output, and is also used to convert an analog audio input into a digital audio signal. The speaker 170A, also known as a "loudspeaker", is used to convert an audio electrical signal into a sound signal. The terminal device can listen to music or hands-free calls through the speaker 170A. The receiver 170B, also known as a "handset", is used to convert an audio electrical signal into a sound signal. When the terminal device answers a call or voice information, the receiver 170B can be placed close to the human ear to listen to the sound. The microphone 170C, also known as a "microphone", "transmitter", is used to convert a sound signal into an electrical signal.

[0085] The pressure sensor 180A is used to sense pressure signals and can convert the pressure signals into electrical signals. In some embodiments, the pressure sensor 180A can be disposed on the display screen 194. The gyroscope sensor 180B can be used to determine the motion posture of the terminal device. The barometric pressure sensor 180C is used to measure barometric pressure. The magnetic sensor 180D includes a Hall sensor. The acceleration sensor 180E can detect the magnitude of the acceleration of the terminal device in various directions (generally three axes). The distance sensor 180F is used to measure distance. The proximity light sensor 180G can include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode. The ambient light sensor 180L is used to sense the ambient light brightness. The fingerprint sensor 180H is used to collect fingerprints. The temperature sensor 180J is used to detect temperature. The touch sensor 180K, also known as a "touch device". The touch sensor 180K can be disposed on the display screen 194, and the touch sensor 180K and the display screen 194 form a touch screen, also known as a "touch panel". The bone conduction sensor 180M can obtain vibration signals.

[0086] The button 190 includes a power on / off button, volume buttons, etc. The button 190 can be a mechanical button or a touch button. The terminal device can receive button inputs and generate key signal inputs related to the user settings and function controls of the terminal device. The indicator 192 can be an indicator light, which can be used to indicate the charging status, power change, and can also be used to indicate messages, missed calls, notifications, etc.

[0087] The software system of the terminal device can adopt a layered architecture, event-driven architecture, microkernel architecture, microservices architecture, or cloud architecture, etc., which will not be elaborated here.

[0088] Technical terms related to this patent:

[0089] REE, TEE: REE can also be referred to as the normal world of the ARM CPU, and TEE can also be referred to as the secure world of the ARM CPU. When the CA runs in the user mode of the normal world of the ARM CPU, the CA is used to receive the input data of the applications in the terminal device and transfer the received data to the TA running in the user mode of the secure world of the ARM CPU, enabling the TA to perform critical operations. For example, the TA can perform fingerprint verification, personal identification number (PIN) verification, security memory such as private keys or certificates, etc.

[0090] NFCC: It can be understood as the microcontroller unit (MCU) integrated in the NFC module, which can be used for functions such as data processing and transmission.

[0091] I2C (Inter-Integrated Circuit) bus: It is a two-way two-wire synchronous serial bus, which only requires two wires to transmit information between the devices connected to the bus.

[0092] SPI bus: That is, the Serial Peripheral Interface (SPI), which is a high-speed, full-duplex, synchronous communication bus, and only occupies four wires on the chip pins, saving the chip pins.

[0093] Chip select signal: When many chips are connected to the same bus and independent transmission of data, address, or command to the target chip is required, at this time, the chip select signal CS (chip select) or SS (slave select) is needed to tell the multiple chips connected to the bus that the data and address are for the target chip. In this way, the target chip knows that these data are for itself and responds accordingly. Usually, the chip select signal is a low-level signal.

[0094] Interrupt source: An interrupt refers to the process in which, due to the occurrence of an event (either hardware or software), the processor pauses the execution of the current program and switches to execute another program to handle the occurred event, and then returns to the original program to continue the operation after the handling is completed. An interrupt is a description of a working state of the processor. Among them, the cause that triggers an interrupt or the source that can send an interrupt request signal is called an interrupt source.

[0095] GPIO interface: That is, the General-purpose input / output (GPIO) interface. Its pins can be freely used by the user through programming. The PIN pins of the GPIO interface can be used as general-purpose input (GPI), general-purpose output (GPO), or general-purpose input and output (GPIO).

[0096] Next, taking the terminal device as mobile phone 100 and the card reader as access control card reader 101 as an example, the authentication method provided by the embodiments of the present application will be described. This example does not limit the embodiments of the present application. The following embodiments can be combined with each other, and the same or similar concepts or processes will not be repeated.

[0097] Among them, as Figure 5 shown, mobile phone 100 includes processor 102 and NFCC 103. Among them, the operating environment when processor 102 processes data includes the Rich Execution Environment (REE) and the Trusted Execution Environment (TEE). The client application (CA) runs in the REE, and the trusted application (TA) runs in the TEE. Among them, CA can interact with data of a wallet application or an access control application (i.e., the target application) that can interact with the user. NFCC 103 is connected to processor 102 through a bus. Among them, when the data of processor 102 is in the REE, it can interact with NFCC 103 through the I2C bus; when the data of processor 102 is in the TEE, it can interact with NFCC 103 through the SPI bus. It can be understood that before unlocking the access control using mobile phone 100, it is necessary to create card information in mobile phone 100. Among them, the process of creating card information can refer to the description of Figure 12 here, and will not be introduced here. As Figure 6 shown, the authentication method provided by the embodiments of the present application includes:

[0098] S501: NFCC 103 establishes a short-range communication connection with access control card reader 101 of the access control.

[0099] It can be understood that, as Figure 7 shown, when the user holds mobile phone 100 and wants to unlock the access control, mobile phone 100 can be brought close to access control card reader 101 of the access control. Further, NFCC 103 can establish a short-range communication connection with access control card reader 101 of the access control.

[0100] S502: In response to a verification instruction from the card reader 101 of the access control, the NFCC 103 transmits an interrupt request to the processor 102.

[0101] It should be noted that the NFCC 103 maintains two interrupt sources, namely the irq_ree interrupt source and the irq_tee interrupt source. Among them, the irq_ree interrupt source is used to interrupt and maintain the NFC service in the REE unchanged, and the irq_tee interrupt source is used to interrupt the service in the TEE.

[0102] Exemplarily, after the NFCC 103 establishes a short-range communication connection with the card reader 101 of the access control, the card reader 101 of the access control sends a verification instruction (i.e., Auth CMD or Mifare CMD) to the NFCC 103. Furthermore, in response to the verification instruction (i.e., Auth CMD or Mifare CMD) from the card reader 101 of the access control, the NFCC 103 raises the irq_tee interrupt source and transmits an interrupt request to the processor 102 via the SPI bus.

[0103] S503: In response to the interrupt request, the processor 102 calls the trusted application TA in the trusted execution environment TEE to pause the process being processed.

[0104] Exemplarily, the processor 102 can call the trusted application TA in the trusted execution environment TEE to set a process in the runnable state (TASK_RUNNING) (i.e., the process being executed on the processor 102 or the process in the pending scheduling queue) to a process in the interruptible waiting state (TASK_INTERRUPTIBLE) (i.e., set to the sleep state). In this way, the trusted application TA in the trusted execution environment TEE pauses the process being processed.

[0105] S504: The processor 102 calls the TA in the TEE to read the verification instruction from the NFCC 103 and generate a response message. The response message carries the first verification information.

[0106] Exemplarily, the processor 102 calls the TA in the TEE to read the verification instruction from the NFCC 103 via the SPI bus. The first verification information can be the first random number "Token RB".

[0107] S505: The processor 102 sends the response message to the card reader 101 of the access control via the NFCC 103.

[0108] It can be understood that after the processor 102 generates the response message, it can write the response message to the NFCC 103 via the SPI bus. Furthermore, the NFCC 103 sends the response message to the card reader 101 of the access control.

[0109] Understandably, as Figure 8 shown, based on the above S502 - S505, the steps executed by NFCC103 can be summarized as follows:

[0110] S601: NFCC103 receives a message from the card reader 101 of the access control.

[0111] S602: NFCC103 determines whether the message from the card reader 101 of the access control is a verification instruction. If not, it executes S603; if so, it executes S604.

[0112] Understandably, when NFCC103 receives a message from the card reader 101 of the access control, it can trigger a determination of whether the message from the card reader 101 of the access control is a verification instruction. Among them, the method of detecting whether the message is a verification instruction can be to detect whether the content of the message is Auth CMD or Mifare CMD. If so, the message is a verification instruction; otherwise, it is not a verification instruction.

[0113] S603: NFCC103 raises the irq_ree interrupt source to transmit an interrupt request to the processor 102.

[0114] Among them, the irq_ree interrupt source is used to keep the implementation of the NFC service unchanged.

[0115] S604: NFCC103 raises the irq_tee interrupt source to transmit an interrupt request to the processor 102.

[0116] S605: NFCC103 determines whether the chip select signal is pulled low. If not, it executes S606; if so, it executes S607.

[0117] S606: NFCC103 pulls low the chip select signal and continues to determine whether the chip select signal is pulled low until the chip select signal is pulled low.

[0118] S607: NFCC103 writes a verification instruction to the processor 102.

[0119] For example, NFCC103 writes a verification instruction to the processor 102 via the SPI bus. In this way, NFCC103 can obtain the verification instruction.

[0120] S608: NFCC103 determines whether the chip select signal is pulled low. If not, it executes S609; if so, it executes S610.

[0121] S609: NFCC103 pulls low the chip select signal and continues to determine whether the chip select signal is pulled low until the chip select signal is pulled low.

[0122] S610: The NFCC103 reads the response message from the processor 102.

[0123] S611: The NFCC103 sends the response message to the card reader 101 of the access control.

[0124] Understandably, as Figure 9 shown, based on the above S502 - S505, the steps executed by the processor 102 can be summarized as:

[0125] S701: The processor 102 determines whether it has received an interrupt request from the irq_tee interrupt source of the NFCC103. If so, it executes S702.

[0126] Exemplarily, the processor determines whether it has received an interrupt request from the irq_tee interrupt source of the NFCC103 at intervals of a preset duration.

[0127] S702: The processor 102 reads the verification instruction from the NFCC103.

[0128] Specifically, the processor 102 pauses the process being executed or the process in the pending scheduling queue and immediately reads the verification instruction from the NFCC.

[0129] S703: The processor 102 generates a response message in response to the verification instruction.

[0130] Among them, the principle of S703 is the same as that of the above S504 and will not be elaborated here.

[0131] S704: The processor 102 pulls down the chip select signal.

[0132] S705: The processor 102 writes the response message to the NFCC103.

[0133] Exemplarily, the processor 102 can write the response message to the NFCC103 through the SPI bus. In this way, the NFCC103 obtains the response message. Understandably, after the processor 102 writes the response message to the NFCC103 through the SPI bus, it can resume executing the process being executed or the process in the pending scheduling queue.

[0134] It should be noted that, as can be seen from the above S502 - S505, after the NFCC103 receives the verification instruction from the card reader 101 of the access control, it transmits an interrupt request to the processor 102. Subsequently, the processor 102 immediately calls the TA in the TEE to pause the process being processed, and without waiting for the process being processed to complete, it can read the verification instruction from the NFCC103 and generate a response message. Then, the processor 102 sends the response message to the card reader 101 of the access control via the NFCC103. This saves time and enables the response latency of the mobile phone 100 to be shorter. In this way, the time taken for the mobile phone 100 to send a response message from receiving the verification instruction to the card reader 101 of the access control is shorter, which can meet the latency requirement stipulated by the protocol preset by the card reader 101 of the access control, that is, the duration from the card reader 101 of the access control sending the verification instruction to receiving the response message is within the preset duration. Thus, the card reader 101 of the access control determines that the response message is valid.

[0135] S506: The processor 102 receives the encrypted second verification information from the card reader 101 of the access control via the NFCC103.

[0136] It can be understood that after the card reader 101 of the access control receives the response message carrying the first random number "Token RB", it generates a second random number "Token RA". Subsequently, based on the preset card key, it encrypts the first random number "Token RB" and the second random number "Token RA". It can be understood that the encrypted first random number "Token RB" and second random number "Token RA" are the second verification information. Thus, the NFCC103 can receive the encrypted first random number "Token RB" and second random number "Token RA" from the card reader 101 of the access control. Then, the NFCC103 can write the encrypted first random number "Token RB" and second random number "Token RA" (i.e., the second verification information) into the secure memory in the TEE of the processor 102 based on the SPI bus.

[0137] S507: The processor 102 completes the authentication interaction with the card reader 101 in the TEE based on the first verification information, the encrypted second verification information, and the preset card key.

[0138] Exemplarily, such as Figure 10As shown, the specific process of S507 described above may include: S801: The processor 102 may call the TA running in the TEE to decrypt the second verification information based on a preset card key. If the decryption is successful, the first random number "Token RB" and the second random number "Token RA" can be obtained. S802: The TA compares whether the first random number "Token RB" sent by the processor 102 is the same as the received first random number "Token RB". If they are the same, the verification of the access control card reader 101 is passed. Furthermore, S803: The TA encrypts the second random number "Token RA" using the initialized encryption machine based on the preset card key. Thus, S804: The processor 102 writes the encrypted second random number "Token RA" to the NFCC 103. S805: The NFCC 103 sends the encrypted second random number "Token RA" to the access control card reader 101. S806: The access control card reader 101 decrypts the encrypted second random number "Token RA" based on the preset card key. If the decryption is successful, the access control card reader 101 compares whether the second random number "Token RA" sent is the same as the received second random number "Token RA". If they are the same, the verification of the mobile phone 100 is passed. Furthermore, the access control card reader 101 notifies the unlocking module to unlock, completing the function of unlocking the access control.

[0139] It can be understood that the above Figure 10 introduces the process of the verification of the access control card reader 101 by the processor 102 of the mobile phone 100 and the verification of the mobile phone 100 by the access control card reader 101. That is, the authentication interaction process between the processor 102 of the mobile phone 100 and the card reader 101.

[0140] In summary, in the authentication method provided in the embodiment of the present application, after the NFCC 103 receives the verification instruction from the card reader 101 of the access control, it transmits an interrupt request to the processor 102. Furthermore, the processor 102 immediately calls the TA in the TEE to pause the process being processed, and without waiting for the process being processed to finish execution, it can read the verification instruction from the NFCC 103 and generate a response message. Furthermore, the processor 102 sends the response message to the card reader 101 of the access control via the NFCC 103. This saves time and can make the response latency of the mobile phone 100 shorter. In this way, it can meet the requirement that the duration (i.e., the response latency) from the card reader 101 of the access control sending the verification instruction to receiving the response message within a preset duration as stipulated by the preset protocol of the card reader 101 of the access control. In this way, the response message fed back by the mobile phone 100 will be recognized as a valid message by the card reader 101 of the access control. In this way, the authentication interaction between the mobile phone 100 and the card reader 101 of the access control can be completed. In this way, the mobile phone 100 with NFC function can be applied to scenarios with strict latency requirements, has a wider application range, and does not require the installation of eSE, with low cost.

[0141] It can be understood that in the above S507, the process of the mobile phone 100 implementing authentication interaction with the card reader 101 of the access control is in the processor 102. In another embodiment, the mobile phone 100 can also implement the authentication interaction process with the card reader 101 of the access control through the NFCC 103. Among them, the NFCC 103 pre-caches encrypted card information, which can ensure the security of the card information. As Figure 11 shown, the above S506 - S507 can be replaced by:

[0142] S904: The NFCC 103 receives the encrypted second verification information from the card reader 101 of the access control.

[0143] S905: The NFCC 103 completes the authentication interaction with the card reader 101 of the access control card based on the first verification information, the encrypted second verification information, and the preset card key.

[0144] Among them, the card key is the content in the card information cached by the NFCC 103. In addition, the principles of S904 - S905 are the same as those of the above S506 - S507, and will not be elaborated here.

[0145] It can be seen that in the above process, the objects executing S904 - S905 are all the NFCC 103.

[0146] Understandably, the interactions between the above-mentioned processor 102 and NFCC 103 are all through the SPI bus. Among them, the SPI bus is a high-speed serial bus, and the data transfer rate can reach 20 Mbps. In this way, the response latency of the mobile phone 100 can be further shortened. In addition, the SPI bus can also be replaced by other high-speed serial buses or medium- and low-speed serial buses, which can all meet the response latency of the mobile phone 100, and are not limited here.

[0147] In addition, the preset card key used by the TA mentioned in the above S507 can be the content in the pre-created card information. Understandably, in order to improve the security of the card information, the processor 102 can establish an SCP02 / 03 secure channel between the TEE and the server, and then the mobile phone 100 manages the card information. The mobile phone 100 can manage the card information in the following ways. Among them, managing card information includes creating card information, deleting card information, activating card information, backing up card information, and downloading card information, etc. Below, taking the target application as the "wallet" application as an example, it is introduced how the mobile phone 100 manages the card information.

[0148] Exemplarily, as Figure 12 shown in (a) of, the mobile phone 100 displays the system main interface 701, and the system main interface 701 includes the icon 702 of the "wallet" application (i.e., the target application). Among them, the "wallet" application runs in the REE of the processor 102 of the mobile phone 100. The mobile phone 100 can display the first interface 703 in response to the user's trigger operation on the icon 702 of the "wallet" application. As Figure 12 shown in (b) of, the first interface 703 includes a first control 704, and the first control 704 is used to indicate creating card information. As Figure 12 shown in (c) of, the mobile phone 100 can display a plurality of second controls on the first interface 703 in response to the user's trigger operation on the first control 704, and each second control is used to indicate different card types to be created. The card types can include access control cards, bus cards, bank cards, car keys, etc., and are not limited here. In this way, the user can bring the access control card 706 close to the mobile phone 100. Furthermore, still as Figure 12 shown in (c) of, the mobile phone 100 can read the card information stored in the access control card 706 through the NFCC 103 in response to the user's trigger operation on the second control 705 indicating the access control card type.

[0149] Understandably, the above process is that the mobile phone 100 reads the card information stored in the access control card 106 in response to the user's trigger operation. Below, in combination with Figure 13 it is introduced how the mobile phone 100 stores the read card information.

[0150] As Figure 13As shown in the figure, S1001: NFCC103 reads the card information stored in the access control card 106. NFCC103 can write the read card information into the secure memory of the REE running on the processor 102 via the I2C bus. Furthermore, S1002: NFCC103 can write the read card information into the secure memory of the REE running on the processor 102 via the I2C bus. Among them, the processor 102 can establish an SCP02 / 03 secure channel between the TEE and the server. In this way, the security of the data can be guaranteed. The mobile phone 100 calls the "wallet" application running in the REE to send a creation request (create card req) for the card information to the server of the "wallet" application. S1003: The "wallet" application receives a creation instruction (create card cmd) for the card information from the server of the "wallet" application. S1004: The "wallet" application transmits the creation command (excute cmd) of the card information to the TA located in the TEE through the application interface (OM API). Among them, the creation instruction (excute cmd) carries the card information. Furthermore, S1005: The TA located in the TEE writes the card information into the secure memory of the TEE to complete the creation of the card information. S1006: The TA located in the TEE sends a feedback message (excute rsp) to the "wallet" application through the application interface. Among them, the feedback message (excute rsp) is used to indicate that the card information creation is successful. S1007: The "wallet" application sends a feedback message (create card CMD rsp) indicating the successful creation of the card information to the server of the "wallet" application to notify the server of the "wallet" application that the card information creation is successful. It can be understood that in the above process, the card information is created and stored in the TEE, so that the security of the card information can be improved.

[0151] In addition, the above feedback message (create card CMD rsp) indicating successful creation can also carry the card information. Furthermore, the server of the "wallet" application can also store the card information to complete the backup of the card information on the server of the "wallet" application.

[0152] In some other embodiments, as Figure 14 shown in (a) of the figure, the first interface 703 may further include a third control 901 for indicating the deletion of the card information. The mobile phone 100 can display a second interface 902 in response to the user's triggering operation on the third control 901. As Figure 14 shown in (b) of the figure, the second interface 902 includes a plurality of fourth controls, and each fourth control is used to indicate the identification of different types of cards. The mobile phone 100 can delete the card information of the stored access control card in response to the user's triggering operation on the fourth control 903 indicating the identification of the access control card.Figure 14 As shown in (c) therein, after the card information of the access control card is deleted, the fourth control 903 indicating the identifier of the access control card is no longer displayed on the second interface 902.

[0153] Understandably, the process of the above Figure 14 corresponding embodiment is how the mobile phone 100 reads the card information stored in the access control card 106 in response to the user's operation. Additionally, similarly, the mobile phone 100 can, based on the same principle as the introduced Figure 10 corresponding embodiment, delete the created card information, which will not be elaborated here.

[0154] Similarly, as Figure 15 shown in (a) therein, the second interface 902 further includes a fifth control 1001, and the fifth control 1001 is used to indicate viewing the deleted card information. The mobile phone 100 also responds to the user's triggering operation on the fifth control 1001 and displays a third interface 1002. As Figure 15 shown in (b) therein, the third interface 1002 includes the identifier of the deleted card (i.e., the access control card), and a sixth control 1003 located on one side of the identifier of the deleted card. The mobile phone 100 can respond to the user's triggering operation on the sixth control 1003 and send a download request for the card information of the access control card to the server of the "Wallet" application. Furthermore, the "Wallet" application of the mobile phone 100 receives the card information of the access control card from the server of the "Wallet" application, and the "Wallet" application of the mobile phone 100 transmits the card information to the TA located in the TEE through the application interface, and then the TA located in the TEE stores the card information. In the above process, the downloaded card information is stored by the TA in the TEE, so that the security of the card information can be improved. Understandably, the above Figure 15 described process is: the process of the mobile phone 100 downloading the card information of the access control card from the server of the "Wallet" application in response to the user's operation.

[0155] In addition, the mobile phone 100 can also respond to the user's triggering operation to activate the card information. Exemplarily, as Figure 16 shown in (a) therein, the second interface 703 of the mobile phone 100 further includes a seventh control 1401, and the seventh control 1401 is used to indicate activating the created card information. The mobile phone 100 responds to the user's triggering operation on the seventh control 1401 and displays a fourth interface 1402. As Figure 16As shown in (b) of [description], the fourth interface 1402 includes a plurality of eighth controls, and each eighth control is used to indicate different types of cards. Furthermore, the "wallet" application running in the REE of the processor 102 can transmit an activation instruction to the TA running in the TEE of the processor 102 through the application interface in response to the user's triggering operation on the eighth control 1403 for indicating the access control card. In this way, the TA running in the TEE of the processor 102 activates the card information of the access control card in the secure memory of the TEE. It can be understood that after the card information of the access control card is activated, the mobile phone 100 can use the key in the card information of the access control card to complete the authentication interaction with the access control card reader 101.

[0156] It should be noted that if there is other card information in the secure memory of the TEE that is in an activated state (such as the card information of the bus card), then the other card information in the activated state needs to be set to the sleep state. In this way, it is equivalent to completing the "switching" of the activated card information.

[0157] It can be understood that in the above embodiment, when the processor 102 calls the "wallet" application running in the REE, it communicates with the NFCC103 through one of the GIPO interfaces and the I2C bus; and when the processor 102 calls the TA running in the TEE, it communicates with the NFCC103 through another GIPO interface and the SPI bus. This is used as an example for illustration. In other embodiments, as Figure 17 shown, when the processor 102 calls the TA running in the TEE, it can communicate with the NFCC103 through another GIPO interface and the I2C bus or the SWP bus.

[0158] It can be seen that in the above embodiment, the "wallet" application running in the REE and the TA in the TEE communicate with the NFCC103 through different buses and different GIPO interfaces. In other embodiments, as Figure 18 shown, when the processor 102 calls the "wallet" application running in the REE or calls the TA running in the TEE, it can also communicate with the NFCC103 through the same I2C bus. In this way, resources can be saved.

[0159] It can be understood that in order to prevent conflicts when the processor 102 calls the "wallet" application running in the REE or calls the TA running in the TEE and communicates with the NFCC103 through the same I2C bus, the processor 102 needs to perform a LOCK lock on the I2C bus in the communication state. Next, it will be introduced how the processor 102 performs a LOCK lock on the I2C bus in the communication state to complete the communication between the "wallet" application in the REE and the NFCC103 through the I2C bus, or the communication between the TA in the TEE and the NFCC103 through the I2C bus.

[0160] Exemplarily, the first identifier indicating that the I2C bus is occupied or the second identifier indicating that the I2C bus is idle is pre-stored in the secure memory in the TEE by the processor 102. When the processor 102 needs to call the TA in the TEE to read and write data from / to the NFCC 103 via the I2C bus (such as reading the response message from the NFCC 103 and writing the encrypted second random number "Token RA" to the NFCC 103), the processor 102 calls the TA in the TEE to detect whether the identifier in the secure memory in the TEE is the second identifier. If it is not the second identifier, it means that the "wallet" application in the REE is communicating with the NFCC 103 via the I2C bus, and then the TA in the TEE waits until the second identifier is detected. If it is the second identifier, it means that the I2C bus is in an idle state. Furthermore, the TA in the TEE updates the second identifier in the secure memory in the TEE to the first identifier to indicate that the I2C bus is occupied. In this way, the processor 102 can call the TA in the TEE to read and write data from / to the NFCC 103 via the I2C bus. After the data reading and writing are completed, the processor updates the first identifier in the secure memory in the TEE to the second identifier to indicate that the I2C bus resumes to the idle state.

[0161] Similarly, when the processor 102 needs to read and write data (such as reading the card message written to the NFCC 103 or the deletion instruction written by the NFCC 103, etc.) when the "wallet" application in the REE communicates with the NFCC 103 via the I2C bus, the processor 102 calls the "wallet" application in the REE to obtain the identifier from the secure memory in the TEE through the application interface. Furthermore, the "wallet" application in the REE detects whether the identifier in the secure memory in the TEE is the second identifier. If it is not the second identifier, it means that the TA in the TEE is communicating with the NFCC 103 via the I2C bus, and then the "wallet" application in the REE waits until the second identifier is detected. If it is the second identifier, it means that the I2C bus is in an idle state. Furthermore, the "wallet" application in the REE notifies the TA in the TEE to update the second identifier in the secure memory in the TEE to the first identifier to indicate that the I2C bus is occupied. In this way, the "wallet" application in the REE reads and writes data from / to the NFCC 103 via the I2C bus. After the data reading and writing are completed, the "wallet" application in the REE notifies the TA in the TEE to update the first identifier in the secure memory in the TEE to the second identifier to indicate that the I2C bus resumes to the idle state.

[0162] It should be noted that the above first identifier may be the string "true", and the second identifier may be the string "false"; or, the above first identifier may be the string "false", and the second identifier may be the string "true". Additionally, the above first identifier may also be the binary number "1", and the second identifier may be the binary number "0"; or, the above first identifier may be the binary number "0", and the second identifier may be the binary number "1", which is not limited herein.

[0163] In addition, different from Figure 18 the corresponding embodiment, in some other embodiments, as Figure 19 shown, the "wallet" application running in the REE and the TA in the TEE can communicate with the NFCC103 through different buses and the same GIPO interface (i.e., the GPIO multiplexed I2C interface or the SPI interface). In this way, resources can also be saved.

[0164] In order to prevent conflicts when the "wallet" application in the REE communicates with the NFCC103 through the I2C bus and the TA in the TEE communicates with the NFCC103 through the I2C bus. The processor 102 can also perform a LOCK lock on the GIPO interface of the processor 102. The way the processor performs a LOCK lock on the GIPO interface is the same as that of Figure 18 the corresponding embodiment for performing a LOCK lock on the I2C bus in the communication state, which will not be elaborated herein.

[0165] In addition, the above embodiment is described by taking the card reader 101 for access control as an example. The card reader provided by the embodiments of the present application may also be a card reader for a bus card, a card reader for a bank card, a card reader for a vehicle, etc., which will not be elaborated herein.

[0166] In addition, in the above description of the authentication method provided by the embodiments of the present application, the trigger operations mentioned may include: click operations, long-press operations, gesture trigger operations, etc., which are not limited herein.

[0167] In addition, after the mobile phone 100 feeds back a response message to the card reader 101 for access control, functions such as data reading and writing, data increment and decrement, data recovery, data transmission, etc. may also be implemented, which are not limited herein.

[0168] In addition, as Figure 20 shown, the above S502 - S505 may also be replaced with:

[0169] S2201: The NFCC103 generates a response message in response to a verification instruction from the card reader 101 for access control. Among them, the response message carries first verification information.

[0170] S2202: The NFCC103 sends a response message to the access control card reader 101.

[0171] S2203: The NFCC103 writes the response message to the processor 102.

[0172] It can be seen that after the NFCC103 responds to the verification instruction from the access control card reader 101 of the access control, the response message is directly generated by the NFCC103; and the NFCC103 directly sends the response message to the access control card reader 101 of the access control without passing through the processor 102, saving time and achieving the same effect as S502 - S505.

[0173] Exemplarily, Figure 21 is a schematic diagram of the hardware structure of a terminal device provided by an embodiment of the present application. As Figure 21 shown, the terminal device includes a processor 2101, a communication line 2104, an NFCC 2106, and at least one communication interface ( Figure 21 exemplarily, the communication interface 2103 is taken as an example for illustration).

[0174] The processor 2101 may be a general - purpose central processing unit (CPU), a microprocessor, an application - specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the solution of the present application.

[0175] The communication line 2104 may include a circuit for transmitting information between the above - mentioned components.

[0176] The communication interface 2103 uses any device such as a transceiver to communicate with other devices or communication networks, such as Ethernet, wireless local area networks (WLAN), etc.

[0177] Possibly, the terminal device may further include a memory 2102.

[0178] The memory 2102 can be a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM) or other types of dynamic storage devices that can store information and instructions, or can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. The memory can exist independently and be connected to the processor through the communication line 2104. The memory can also be integrated with the processor.

[0179] Among them, the memory 2102 is used to store the computer execution instructions for executing the solution of this application, and is controlled by the processor 2101 for execution. The processor 2101 is used to execute the computer execution instructions stored in the memory 2102, so as to implement the authentication method provided by the embodiments of this application or the steps of responding to the authentication instruction in the authentication method. For example, the NFCC 2106 transmits an interrupt request to the processor 2101 in response to a verification instruction from the card reader. The processor 2101, in response to the interrupt request, calls the trusted application TA in the trusted execution environment TEE to pause the process being processed. The processor 2101 calls the TA in the TEE to read the verification instruction from the NFCC 2106 and generate a response message, where the response message carries the first verification information. The processor 2101 sends the response message to the card reader via the NFCC 2106. The processor 2101 receives the encrypted second verification information from the card reader. The processor 2101 uses the first verification information, the encrypted second verification information, and the preset card key to complete the authentication interaction with the card reader.

[0180] For another example, the processor 2101, in response to the interrupt request, calls the trusted application TA in the trusted execution environment TEE to pause the process being processed. The processor 2101 calls the TA in the TEE to read the verification instruction from the NFCC and generate a response message, where the response message carries the first verification information. The processor 2101 sends the response message to the card reader via the NFCC.

[0181] Possibly, the computer execution instructions in the embodiments of this application can also be referred to as application code, and the embodiments of this application do not make specific limitations thereon.

[0182] In a specific implementation, as an example, the processor 2101 may include one or more CPUs, such as Figure 21 CPU0 and CPU1 in

[0183] In a specific implementation, as an example, the terminal device may include multiple processors, such as Figure 21 processor 2101 and processor 2105 in . Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. The processor here may refer to one or more devices, circuits, and / or processing cores for processing data (such as computer program instructions).

[0184] In a specific implementation, as an example, NFCC 2106 may be the MCU (microprocessor) in the NFC chip, and NFCC 2106 can communicate with the card reader over a short distance. NFCC 2106 is used to execute the computer-executable instructions stored in the memory 2102, thereby implementing the authentication interaction steps in the authentication method provided by the embodiments of the present application.

[0185] For example, NFCC transmits an interrupt request to the processor in response to a verification instruction from the card reader.

[0186] Exemplarily, Figure 22 is a schematic structural diagram of a chip provided by an embodiment of the present application. The chip 220 includes one or more than two (including two) processors 2210, a communication interface 2230, and NFCC 2250.

[0187] In some embodiments, the memory 2240 stores the following elements: executable modules or data structures, or subsets thereof, or extended sets thereof.

[0188] In the embodiments of the present application, the memory 2240 may include a read-only memory and a random access memory, and provide instructions and data to the processor 2210. A part of the memory 2240 may also include a non-volatile random access memory (NVRAM).

[0189] In the embodiments of the present application, the memory 2240, the communication interface 2230, and the memory 2240 are coupled together through a bus system 2220. Among them, the bus system 2220 may include a power bus, a control bus, a status signal bus, etc. in addition to a data bus. For the sake of description, in Figure 22 all kinds of buses are labeled as the bus system 2220.

[0190] The method described in the embodiments of the present application above can be applied to NFCC2250, or NFCC2250 and processor 2210.

[0191] NFCC2250 and processor 2210 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in NFCC2250, or NFCC2250 and processor 2210, or in the form of instructions in software. The above-mentioned processor 2210 may be a general-purpose processor (e.g., a microprocessor or a conventional processor), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate, transistor logic devices, or discrete hardware components. The processor 2210 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present invention.

[0192] The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as hardware decoding by NFCC2250, or completed by NFCC2250 and processor 2210 executing, or completed by a combination of hardware and software modules in the decoding processor. Among them, the software module can be located in a mature storage medium in the art such as a random access memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable read-only memory (EEPROM). This storage medium is located in memory 2240, NFCC2250, or NFCC2250 and processor 2210 reads the information in memory 2240 and combines its hardware to complete the steps of the above method.

[0193] In the above embodiment, the instructions stored in the memory for the processor to execute can be implemented in the form of a computer program product. Among them, the computer program product can be pre-written in the memory, or downloaded and installed in the memory in the form of software.

[0194] A computer program product includes one or more computer instructions. When the computer instructions are loaded and executed on a computer, a process or function according to the embodiments of the present application is generated in whole or in part. The computer may be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions may be transmitted from a website, a computer, a server, or a data center to another website, computer, server, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line (DSL)) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium may be any available medium that can be stored by a computer or a data storage device such as a server or a data center that includes one or more available media integrated. For example, the available medium may include magnetic media (such as floppy disks, hard disks, or magnetic tapes), optical media (such as digital versatile discs (DVDs)), or semiconductor media (such as solid state disks (SSDs)).

[0195] Embodiments of the present application also provide a computer-readable storage medium. The methods described in the above embodiments may be implemented in whole or in part by software, hardware, firmware, or any combination thereof. The computer-readable medium may include computer storage media and communication media, and may also include any medium that can transfer a computer program from one place to another. The storage medium may be any target medium accessible by a computer.

[0196] As a possible design, the computer-readable medium may include a compact disc read-only memory (CD-ROM), RAM, ROM, EEPROM, or other optical disc memories; the computer-readable medium may include disk memories or other disk storage devices. Moreover, any connecting line may also be appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, a server, or other remote sources using coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies (such as infrared, radio, and microwave), then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. As used herein, disks and optical discs include optical discs (CDs), laser discs, optical discs, digital versatile discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs use lasers to optically reproduce data.

[0197] The above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. An authentication method, characterized in that, Applied to a terminal device, the terminal device includes a Near Field Communication Controller (NFCC) and a processor, and the method includes: The NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader; The processor, in response to the interrupt request, calls a Trusted Application (TA) in a Trusted Execution Environment (TEE) to suspend the process being processed, reads the verification instruction from the NFCC, and generates a response message, where the response message carries first verification information; The processor sends the response message to the card reader via the NFCC; The processor receives encrypted second verification information from the card reader via the NFCC; The processor uses the first verification information, the encrypted second verification information, and a preset card key to complete an authentication interaction with the card reader.

2. The method according to claim 1, wherein The NFCC is provided with an irq_tee interrupt source, and the NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader, including: The NFCC, in response to the verification instruction from the card reader, raises the irq_tee interrupt source to transmit an interrupt request to the processor.

3. The method according to claim 1, wherein The processor calls a Trusted Application (TA) in a Trusted Execution Environment (TEE) to suspend the process being processed, including: The processor calls the TA in the TEE to set the process in a runnable state to a process in an interruptible waiting state.

4. The method according to claim 1, characterized in that The processor sends the response message to the card reader via the NFCC, including: The processor pulls down the chip select signal and transmits a data write request to the NFCC; The NFCC, in response to the data write request, detects whether the chip select signal is pulled down; If it is pulled down, the NFCC reads the response message from the processor; The NFCC sends the response message to the card reader.

5. The method according to claim 4, wherein Data interaction between the NFCC and the processor is performed via an SPI bus.

6. The method according to claim 1, wherein The processor uses the first verification information, the encrypted second verification information, and the preset card key to complete an authentication interaction with the card reader, including: The processor decrypts the second verification information according to the preset card key in the TEE; The processor verifies the card reader according to the second verification information and the first verification information in the TEE; If the verification of the card reader is passed, the processor encrypts the second verification information based on the preset card key in the TEE; The processor sends the encrypted second verification information to the card reader via the NFCC, so that the card reader verifies the terminal device according to the received second verification information and the sent second verification information.

7. The method according to claim 1, characterized in that, The bus for the processor to communicate with the NFCC in the Rich Execution Environment (REE) is the same as or different from the bus for the processor to communicate with the NFCC in the TEE.

8. The method according to claim 7, wherein The bus for the processor to communicate with the NFCC in the REE is the same as the bus for the processor to communicate with the NFCC in the TEE, and the method further includes: When being instructed to communicate with the NFCC via the bus in the TEE, the processor detects in the TEE whether the bus is in a communication state; If not in a communication state, the processor locks the bus in the TEE; The processor communicates with the NFCC via the bus in the TEE; After the communication between the processor and the NFCC is completed, the processor unlocks the bus.

9. The method according to claim 7, characterized in that, The processor communicates with the NFCC via a first bus in the REE, and the processor communicates with the NFCC via a second bus in the TEE, and the first bus and the second bus share the same GPIO interface of the processor. The method further includes: When being instructed to communicate with the NFCC via the first bus in the TEE, the processor detects in the TEE whether the GPIO interface is in a communication state; If not in a communication state, the processor locks the GPIO interface in the TEE; The processor communicates with the NFCC via the first bus and the GPIO interface in the TEE; After the communication between the processor and the NFCC is completed, the processor unlocks the GPIO interface.

10. The method according to any one of claims 1-9, characterized in that, The method further includes: After the processor establishes an SCP02 / 03 secure channel with the server in the TEE, the processor manages preset card information in response to a trigger operation of a user, where the preset card information includes the card key.

11. The method according to claim 10, wherein The managing of the preset card information includes: Before the NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader, The processor creates the preset card information in the TEE; and / or the processor activates the preset card information in the TEE; and / or the processor backs up the preset card information to the server in the TEE; and / or the processor downloads the preset card information from the server in the TEE; and / or after the processor completes an authentication interaction with the card reader by using the first verification information, the encrypted second verification information, and the preset card information, the processor deletes the preset card information or switches the activated card information in the TEE.

12. The method according to any one of claims 1-9, characterized in that, The card reader is a card reader for an access control, a card reader for a bus, or a card reader for a bank card.

13. The method according to claim 1, characterized in that, The NFCC transmits an interrupt request to the processor in response to a verification instruction from a card reader; the processor, in response to the interrupt request, calls a trusted application TA of the trusted execution environment TEE to pause the process being processed; the processor calls the TA in the TEE to read the verification instruction from the NFCC and generate a response message, where the response message carries first verification information; the processor sends the response message to the card reader via the NFCC, replaced with: The NFCC generates a response message in response to a verification instruction from a card reader, wherein the response message carries first verification information; The NFCC sends the response message to the card reader; The NFCC writes the response message to the processor.

14. A terminal device, characterized in that, It includes a processor, an NFCC, and a memory, where the memory is used to store code instructions; the NFCC and the processor are used to run the code instructions so that the terminal device executes the authentication method according to any one of claims 1-13.

15. A computer-readable storage medium, characterized in that, It includes a computer-readable storage medium storing instructions that, when executed, cause a computer to execute the authentication method according to any one of claims 1-13.

16. A computer program product, characterized in that, It includes a computer program that, when run, causes a computer to execute the authentication method according to any one of claims 1-13.

Citation Information

Patent Citations

  • Security information inputting / outputting method and electronic device adapted to the method

    US20150234757A1