Data processing method and apparatus
By establishing secure environment connections between different devices in electronic devices or servers, security capabilities and resources can be shared, solving the problem of security environments not being able to be shared across devices and improving the user experience.
Patent Information
- Application Number
- CN202210467415.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-04-29
- Publication Date
- 2025-11-28
- Estimated Expiration
- 2042-04-29
AI Technical Summary
The inability of electronic devices or servers to share security capabilities across devices can prevent certain security services from being provided, impacting user experience.
By establishing connections between the security environments of different devices and pooling security capabilities, different devices can leverage the security capabilities of other devices, thereby achieving the sharing of security capabilities and resources.
While ensuring data security, the device's secure processing capabilities have been enhanced, improving the user experience and reducing the difficulty of operation.
Smart Images

Figure CN117009971B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] Embodiments of the present application relate to the technical field of terminal, and in particular, to a data processing method and device. BACKGROUND
[0002] Electronic devices (for example, mobile phones, tablet computers, etc.) or servers are generally provided with a secure environment, such as a trusted execution environment (TEE) or a confidential computing environment. The electronic device or server provides a secure state service (for example, secure storage, secure key, secure encryption and decryption, secure driver, etc.) through the secure environment, and protects the data security during the running of the secure state service.
[0003] However, in order to ensure data security, the data in the secure environment can only be processed in the secure environment, and cannot be circulated, so the secure state service that can be provided by the electronic device or server depends on the security capabilities in the secure environment of the electronic device or server itself. If the electronic device or server does not have the security capabilities to process the business corresponding to certain secure state services, the electronic device or server cannot provide these secure state services, affecting the user experience. SUMMARY
[0004] In order to solve the above technical problems, the embodiments of the present application provide a data processing method and device. The technical scheme provided by the embodiments of the present application establishes a connection between different device secure environments, so that different devices can borrow the security capabilities of other devices through the connection, improving the processing capability of the device secure environment, and further improving the user experience.
[0005] In order to achieve the above technical purpose, the embodiments of the present application provide the following technical scheme:
[0006] In a first aspect, a data processing method is provided, applied to a first device, the first device and one or more second devices have a first connection, the first device includes a first secure environment, and the one or more second devices include one or more second secure environments corresponding to the one or more second devices. The method comprises: determining a target second secure environment including a first security capability in the one or more second secure environments; wherein the first security capability is used to process first data to be processed in the first secure environment. Through a second connection, the first data is sent to the target second secure environment, and the second connection is a connection between the first secure environment and the target second secure environment. Through the second connection, a first processing result of the first data is received, and the first processing result is a processing result generated after the first data is processed by the first security capability.
[0007] In some embodiments, by establishing a secure connection between the secure environments of different devices, the secure capabilities are pooled, and the secure environments of various devices in the communication system are aggregated into a super secure environment. Thus, as long as the super secure environment has a secure capability to process the data to be processed, the devices in the communication system can process the data to be processed.
[0008] In this way, by the interaction between the secure environments of different devices, the sharing of the secure capabilities and secure resources of different devices is realized. Moreover, without the need for early adaptation of the REE (i.e., without the need for customization of the application capabilities on the REE side), the secure capabilities of other devices can be adaptively called without user awareness, the user's needs are met, and the user operation difficulty is reduced.
[0009] According to the first aspect, in determining a target second secure environment including a first secure capability in one or more second secure environments for first data to be processed in a first secure environment, the first secure capability information is obtained, and the first secure capability information includes the secure capabilities included in the one or more second secure environments. According to the first secure capability information, the target second secure environment is determined.
[0010] In some embodiments, after determining the first data to be processed in the first secure environment, the first device determines that the secure capability in the first secure environment of the first device is insufficient to process the first data. Therefore, the first device needs to call the secure capability in the second secure environment of the other second device to process or assist in processing the first data. Based on this, the first device needs to obtain the secure capability of the second secure environment of each second device (i.e., by obtaining the secure capability information to determine the secure capability), so as to determine part or all of the second capabilities of the second devices needed.
[0011] In this way, the first device can determine the target second secure environment configured with the first secure capability for processing the first data, and send the first data to the target second secure environment including the target second secure environment for processing. Thus, the data processing needs in the secure environment are met, and the user experience is improved.
[0012] According to the first aspect, or any one of the implementation manners of the first aspect, before sending the first data to be processed in the first secure environment to a target second secure environment including a first secure capability in one or more second secure environments through a second connection, the method further includes: negotiating a first key for data transmission between the first secure environment and the target second secure environment with a target second device including the target second secure environment, the first key being used to encrypt the first data and the first processing result transmitted through the second connection.
[0013] In some scenarios, in order to ensure the security of data transmission between the secure environments, after determining that the first security capability in the target second secure environment of the target second device needs to be used, the first device can negotiate a first key with the target second device for transmitting data.
[0014] In this way, after the data is transmitted by negotiating the key, the communication security of the secure environment is effectively ensured.
[0015] According to the first aspect or any one of the implementations of the first aspect, the method further includes deleting the first key.
[0016] According to the first aspect or any one of the implementations of the first aspect, the method further includes determining that the target second secure environment includes a second security capability, and the second security capability is used to process second data to be processed in the first secure environment. Negotiating a second key between the first secure environment and the target second secure environment for data transmission, and the second key is used to encrypt second data transmitted through a second connection and a second processing result corresponding to the second data.
[0017] In this way, the first device needs to negotiate the key for this communication with the determined target second device each time the security capability of the other device needs to be invoked. And after this communication ends, the key used in this communication is deleted. Thus, the key leakage is avoided, and the security of data transmission is affected.
[0018] According to the first aspect or any one of the implementations of the first aspect, before obtaining the first security capability information, the method further includes receiving first information of one or more second secure environments sent by one or more second devices through the first connection. According to the first information, it is determined that the one or more second secure environments are secure. A secure connection between the first secure environment and the one or more second secure environments is established respectively, and the secure connection is used to obtain the first security capability information of the one or more second devices. The second connection is a connection corresponding to the target second secure environment in the secure connection.
[0019] In some embodiments, the first device and the second device determine the security between the first secure environment and the second secure environment through the interaction of the device certificate. Then, the secure connection between the secure environments can be established. Subsequently, the security capability of the other device can be invoked through the secure connection to realize the sharing of the security capability in the distributed scenario.
[0020] In this way, the security of the secure environment interaction between the first device and the second device can be further ensured.
[0021] According to the first aspect or any one of the implementations of the first aspect, the method further includes sending second security capability information of the security capability included in the first secure environment to the one or more second devices through the secure connection.
[0022] In some embodiments, the first device sends, to the one or more second devices, the security capability information including security capabilities of the first security environment, through the first connection.
[0023] In this way, the sharing of the security capability information in the communication system is implemented, so as to facilitate the subsequent one or more second devices to invoke the security capabilities of the first device.
[0024] According to the first aspect, or any one of the implementations of the first aspect, the obtaining the security capability information comprises: obtaining the first security capability information stored locally. And / or, obtaining the first security capability information sent by the center node.
[0025] In some embodiments, the security capability information stored locally, or the security capability information stored by the center node, comprises second security capability information corresponding to the first device, and first security capability information corresponding to the one or more second devices.
[0026] According to the first aspect, or any one of the implementations of the first aspect, the method further comprises: sending, to the center node, second security capability information of the security capabilities included in the first security environment.
[0027] In this way, the first device and the one or more second devices in the communication system can share the security capability information in various ways, so as to facilitate the subsequent devices to implement the shared security capabilities.
[0028] According to the first aspect, or any one of the implementations of the first aspect, the method further comprises: disconnecting the first connection with a target second device including a target second security environment. Deleting the security capability information of the target second security environment of the target second device in the security capability information.
[0029] In this way, the synchronous update of the security capability information in the communication system is ensured, and the security capability information of the device that has not accessed the communication system is avoided to be included in the synchronous security capability information, so as to cause the failure of the other devices to invoke the security capabilities of the device.
[0030] According to the first aspect, or any one of the implementations of the first aspect, the security capabilities included in the one or more second security environments comprise: security capabilities of security state applications running in the one or more second security environments, and / or security state services supported by the one or more second security environments.
[0031] According to the first aspect, or any one of the implementations of the first aspect, the first security environment or the second security environment is a trusted execution environment (TEE) or a confidential computing environment.
[0032] According to the first aspect, or any implementation of the first aspect above, before obtaining the first security capability information, the method further includes: detecting a user's first operation; determining the pending data of a first service corresponding to the first operation; determining the first data based on the pending data of the first service; or, obtaining a second service; determining the first data in the pending data of the second service.
[0033] Optionally, the first device is an electronic device or a server.
[0034] In some embodiments, the first security capability may be the complete security capability of a security-state application in the target second security environment of the target second device, or it may be a partial capability of the security-state application (such as a security-state service).
[0035] In this way, the security capabilities of each device are abstracted, security tasks are segmented, and multiple devices cooperate to handle security tasks through their own security capabilities, thereby making full use of the security capabilities of each device.
[0036] Secondly, a data processing method is provided, applied to a second device, the second device having established a first connection with a first device, the second device including a second security environment, and the first device including a first security environment. The method includes: receiving first data sent by a first security environment in the first device through the second connection, the second connection being a connection between the first and second security environments, and the first data being data to be processed in the first security environment; processing the first data through a first security capability to obtain a first processing result; and sending the first processing result to the first security environment through the second connection.
[0037] According to the second aspect, before the second security environment in the second device receives the first data sent by the first security environment in the first device via the second connection, the method further includes: negotiating with the first device a first key for data transmission between the first security environment and the second security environment, the first key being used to encrypt the first data and the first processing result.
[0038] According to the second aspect, or any implementation of the second aspect above, before processing the first data through the first security capability, the method further includes: determining that the first device has permission to invoke the first security capability.
[0039] In some embodiments, the target second device can also be configured with a permission confirmation module in the target second security environment, which is used to determine whether the first device has the permission to invoke the first security capability. For example, the first device can also include the device identifier of the first device in the service tag carried in the first data, and the target second device can determine the permission of the first device according to the device identifier. After determining that the first device has the permission to invoke the first security capability, the target second device processes the obtained first data through the first security capability.
[0040] In this way, the security capability of the security environment of the device without the permission is avoided to be invoked, and the security of the security environment of the device is further ensured.
[0041] According to the second aspect or any one of the implementation forms of the second aspect, the first data carries a service tag corresponding to the first data; and before the first data is processed through the first security capability to obtain the first processing result, the method further includes: determining the first security capability corresponding to the service tag according to the service tag.
[0042] In some embodiments, the service tag of the first data includes, for example, the security capability to be used, the credential information and the like of the security capability. The service tag of the first data is carried in the first data, and the target second device can determine the first security capability used to process the first data according to the service tag. Then, the target second device processes the first data through the first security capability in the target second security environment to obtain the first processing result of the first data.
[0043] The technical effects of the second aspect and any one of the implementation forms of the second aspect can refer to the technical effects of the first aspect and any one of the implementation forms of the first aspect, which will not be described herein.
[0044] In a third aspect, a data processing apparatus is provided. The data processing apparatus includes a processor and a memory coupled to the processor. The memory is configured to store computer readable instructions. When the processor reads the computer readable instructions from the memory, the data processing apparatus is caused to perform the following operations: determining a target second security environment including a first security capability in one or more second security environments; wherein the first security capability is used to process first data to be processed in a first security environment. The first data is sent to the target second security environment through a second connection, and the second connection is a connection between the first security environment and the target second security environment. The first processing result of the first data is received through the second connection, and the first processing result is a processing result generated after the first data is processed through the first security capability.
[0045] According to a third aspect, in determining the target second security environment including the first security capability from the one or more second security environments for the first data to be processed in the first security environment, the data processing apparatus further comprises: obtaining first security capability information, the first security capability information comprising security capabilities included in the one or more second security environments; and determining the target second security environment according to the first security capability information.
[0046] According to the third aspect, or any one of the third aspect of the above implementation forms, when the processor reads the computer readable instructions from the memory, the data processing apparatus further comprises: negotiating, with a target second device including the target second security environment, a first key for data transmission between the first security environment and the target second security environment, the first key being used to encrypt the first data and the first processing result transmitted through the second connection.
[0047] According to the third aspect, or any one of the third aspect of the above implementation forms, when the processor reads the computer readable instructions from the memory, the data processing apparatus further comprises: deleting the first key.
[0048] According to the third aspect, or any one of the third aspect of the above implementation forms, when the processor reads the computer readable instructions from the memory, the data processing apparatus further comprises: determining that the target second security environment includes a second security capability, the second security capability being used to process second data to be processed in the first security environment; and negotiating, with the target second device, a second key for data transmission between the first security environment and the target second security environment, the second key being used to encrypt the second data and a second processing result corresponding to the second data transmitted through the second connection.
[0049] According to the third aspect, or any one of the third aspect of the above implementation forms, when the processor reads the computer readable instructions from the memory, the data processing apparatus further comprises: receiving, through the first connection, first information of the one or more second security environments sent by the one or more second devices; determining that the one or more second security environments are secure according to the first information; and establishing a secure connection between the first security environment and the one or more second security environments respectively, the secure connection being used to obtain first security capability information of the one or more second devices, the second connection being a connection corresponding to the target second security environment in the secure connection.
[0050] According to the third aspect, or any one of the third aspect of the above implementation forms, when the processor reads the computer readable instructions from the memory, the data processing apparatus further comprises: sending, through the secure connection, second security capability information of the security capabilities included in the first security environment to the one or more second devices.
[0051] According to a third aspect, or any possible implementation mode of the third aspect, the obtaining the security capability information comprises: obtaining the security capability information stored locally. And / or, obtaining the security capability information sent by the central node.
[0052] According to the third aspect, or any possible implementation mode of the third aspect, when the processor reads the computer readable instructions from the memory, the data processing apparatus further performs the following operation: sending, to the central node, the second security capability information of the security capability included in the first security environment.
[0053] According to the third aspect, or any possible implementation mode of the third aspect, when the processor reads the computer readable instructions from the memory, the data processing apparatus further performs the following operation: disconnecting the first connection between the first device and the target second device including the target second security environment. Deleting the security capability information of the target second security environment of the target second device in the security capability information.
[0054] According to the third aspect, or any possible implementation mode of the third aspect, the security capability included in the one or more second security environments comprises: the security capability of the secure state application running in the one or more second security environments, and / or the security state service supported by the one or more second security environments.
[0055] According to the third aspect, or any possible implementation mode of the third aspect, the first security environment or the second security environment is a trusted execution environment (TEE) or a confidential computing environment.
[0056] According to the third aspect, or any possible implementation mode of the third aspect, when the processor reads the computer readable instructions from the memory, the data processing apparatus further performs the following operation: detecting the first operation of the user. Determining the to-be-processed data of the first service corresponding to the first operation. Determining the first data according to the to-be-processed data of the first service. Or, obtaining the second service. Determining the first data in the to-be-processed data of the second service.
[0057] The technical effects of the third aspect and any possible implementation mode of the third aspect can refer to the technical effects of the first aspect and any possible implementation mode of the first aspect, which will not be repeated here.
[0058] In a fourth aspect, a data processing apparatus is provided. The data processing apparatus includes a processor and a memory coupled with the processor, the memory configured to store computer readable instructions that, when read by the processor from the memory, cause the data processing apparatus to perform: receiving, by a second secure environment in a second device, first data sent by a first secure environment in a first device via a second connection, the second connection being a connection between the first secure environment and the second secure environment, the first data being to-be-processed data in the first secure environment; processing the first data by a first security capability to obtain a first processing result; and sending, via the second connection, the first processing result to the first secure environment.
[0059] According to the fourth aspect, when the processor reads the computer readable instructions from the memory, the data processing apparatus is further caused to perform: negotiating, with the first device, a first key for data transmission between the first secure environment and the second secure environment, the first key being used to encrypt the first data and the first processing result.
[0060] According to the fourth aspect, or any one of the implementations of the fourth aspect, when the processor reads the computer readable instructions from the memory, the data processing apparatus is further caused to perform: determining that the first device has the permission to invoke the first security capability.
[0061] According to the fourth aspect, or any one of the implementations of the fourth aspect, the first data carries a service tag corresponding to the first data; and when the processor reads the computer readable instructions from the memory, the data processing apparatus is further caused to perform: determining, according to the service tag, a first security capability corresponding to the service tag.
[0062] The technical effects of the fourth aspect and any one of the implementations of the fourth aspect can refer to the technical effects of the second aspect and any one of the implementations of the second aspect, which will not be described herein again.
[0063] In a fifth aspect, an embodiment of the present application provides a data processing apparatus having a function of implementing the data processing method in the first aspect and any one of the possible implementation manners thereof. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above functions.
[0064] The technical effects of the fifth aspect and any one of the implementations of the fifth aspect can refer to the technical effects of the first aspect and any one of the implementations of the first aspect, which will not be described herein again.
[0065] In a sixth aspect, an embodiment of the present application provides a data processing apparatus having a function of implementing the data processing method according to the second aspect and any one of its possible implementation manners. The function can be implemented by hardware, or by hardware executing corresponding software. The hardware or software includes one or more modules corresponding to the above function.
[0066] The technical effects of the sixth aspect and any one of its possible implementation manners can refer to the technical effects of the second aspect and any one of its possible implementation manners, which will not be repeated here.
[0067] In a seventh aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program (which can also be referred to as instructions or code), which, when executed by a data processing apparatus, causes the data processing apparatus to perform the method of the first aspect or any one of its possible implementation manners; or causes the data processing apparatus to perform the method of the second aspect or any one of its possible implementation manners.
[0068] The technical effects of the seventh aspect and any one of its possible implementation manners can refer to the technical effects of the first aspect and any one of its possible implementation manners, which will not be repeated here.
[0069] In an eighth aspect, a computer program product is provided. When the computer program product is run on a data processing apparatus, the data processing apparatus is caused to perform the method of the first aspect or any one of its possible implementation manners; or the data processing apparatus is caused to perform the method of the second aspect or any one of its possible implementation manners.
[0070] The technical effects of the eighth aspect and any one of its possible implementation manners can refer to the technical effects of the first aspect and any one of its possible implementation manners, which will not be repeated here.
[0071] In a ninth aspect, an embodiment of the present application provides a circuit system, which includes processing circuitry configured to perform the method of the first aspect or any one of its possible implementation manners; or the processing circuitry is configured to perform the method of the second aspect or any one of its possible implementation manners.
[0072] The technical effects of the ninth aspect and any one of its possible implementation manners can refer to the technical effects of the first aspect and any one of its possible implementation manners, which will not be repeated here.
[0073] In a tenth aspect, an embodiment of the present application provides a chip system, comprising at least one processor and at least one interface circuit, the at least one interface circuit being configured to perform a transceiving function and send an instruction to the at least one processor, and when the at least one processor executes the instruction, the at least one processor executes the method of the first aspect or any one of the implementation forms of the first aspect; or the at least one processor executes the method of the second aspect or any one of the implementation forms of the second aspect.
[0074] The technical effects of the tenth aspect and any one of the implementation forms of the tenth aspect can refer to the technical effects of the first aspect and any one of the implementation forms of the first aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0075] Figure 1 A schematic diagram of an ARM TrustZone system architecture provided by an embodiment of the present application;
[0076] Figure 2 A schematic diagram of a communication system to which a data processing method provided by an embodiment of the present application is applied;
[0077] Figure 3A A hardware structure schematic of a first device provided by an embodiment of the present application Figure 1 ;
[0078] Figure 3B A hardware structure schematic of a first device provided by an embodiment of the present application Figure 2 ;
[0079] Figure 4 A schematic diagram of a method for establishing a secure connection in a data processing process provided by an embodiment of the present application;
[0080] Figure 5 A schematic diagram of module interaction provided by an embodiment of the present application;
[0081] Figure 6 A schematic diagram of a data processing method provided by an embodiment of the present application Figure 1 ;
[0082] Figure 7 A schematic diagram of a data processing method provided by an embodiment of the present application Figure 2 ;
[0083] Figure 8 A schematic diagram of a data processing method provided by an embodiment of the present application
[0084] Figure 9 A schematic diagram of a data processing method provided by an embodiment of the present application Figure 4 ;
[0085] Figure 10A structural schematic diagram of a first device provided in an embodiment of the present application is shown in FIG. 1.
[0086] Figure 11 A structural schematic diagram of a second device provided in an embodiment of the present application is shown in FIG. 2. DETAILED DESCRIPTION
[0087] The technical solutions in the embodiments of the present application will be described below with reference to the drawings in the embodiments of the present application. In the description of the embodiments of the present application, the terms used in the following embodiments are only for the purpose of describing the specific embodiments and are not intended to be limiting on the present application. As used in the specification and the appended claims of the present application, the singular forms “a,” “an,” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will also be understood that “at least one” and “one or more” as used in the following embodiments refer to one or two or more (including two).
[0088] In the present specification, the reference to “one embodiment” or “some embodiments” etc. means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Thus, the appearances of the phrases “in one embodiment,” “in some embodiments,” “in other embodiments,” “in additional embodiments,” etc. in various places in the specification are not necessarily all referring to the same embodiment, but can refer to one or more but not all embodiments, unless otherwise specifically stated. The terms “comprising,” “including,” “having” and their variants, mean “including but not limited to,” unless otherwise specifically indicated. The term “connected” includes both direct and indirect connections, unless otherwise specifically indicated. “First,” “second,” etc. are used only for descriptive purposes and should not be construed as implying or suggesting relative importance or an ordered ranking of the indicated technical features.
[0089] In the embodiments of the present application, the words “exemplary” or “for example” are used to mean serving as an example, instance, or illustration. Any embodiment or design described in the embodiments of the present application as “exemplary” or “for example” should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of “exemplary” or “for example” is intended to present concepts in a concrete manner.
[0090] In some scenarios, an electronic device (e.g., a mobile phone, a tablet computer, etc.) or a server is provided with a secure environment, such as a trusted execution environment (TEE) or a confidential computing environment, to process private information or secret information in the secure environment to protect the safety of the private information or secret information of an individual or the electronic device.
[0091] As shown in Figure 1 An electronic device based on an ARM TrustZone includes a rich execution environment (REE) and a TEE. The REE, also referred to as a normal execution environment, includes a rich execution environment operating system (REE OS) and a client application (CA) running on a general-purpose processor. The TEE, in the form of a CA, runs on the REE OS in a secure state.
[0092] The capabilities of the CA can be abstracted as Ability, and a CA can have multiple capabilities, i.e., multiple Abilities. An Ability can include a feature ability (FA) and an atomic ability (AA). The FA at the application layer is used to provide the user with the most upper-layer available services of the electronic device. The FA is composed of 1 to N AAs, and the AA provides basic service capabilities for the FA to call. The FA arranges and assembles the AAs to complete the service indicated by the user.
[0093] The TEE, also referred to as a secure execution environment, can run a trusted execution environment operating system (TEE OS) to provide a trusted secure state service (TService, such as secure storage, secure keys, secure encryption and decryption, secure drivers, etc.) for the CA. These secure state services can run on the TEE OS in the form of a trust application (TA) (or a secure state application).
[0094] As shown in Figure 1 To ensure data security, the CA sends an operation request to the TA in a fixed command format after obtaining a service. After the TA parses the command code, it can only process the secure data inside the TEE, which results in the secure data being unable to circulate.
[0095] In addition, the security capability of the TA and the security state service in the TEE is fixed, and the electronic device can only process security data using the security capability in the TEE of the electronic device. If the security capability of the electronic device itself cannot process, the service processing fails.
[0096] In addition, the TA in the TEE cannot run across devices. If the local resources required by the TA are insufficient, the TA cannot be loaded and run, resulting in service failure.
[0097] These problems limit the security operation capability of the TEE and affect the user experience.
[0098] Therefore, the developer proposes to call the security capability of the TEE of other electronic devices based on the REE of the electronic device. For example, Figure 1 As shown in the figure, the electronic device 1 and the electronic device 2 can establish a communication connection of the REE. After the service triggered by the application layer (FA1) of the electronic device 1, it is determined that the security capability in the TEE of the electronic device itself cannot process the current service, and then the service indication is sent to the electronic device 2 for processing through the interaction of the service layer (AA1 and AA2). For example, the electronic device 1 receives a face recognition request, and the TEE of the electronic device does not have face recognition capability. Then, the electronic device 2 collects the face of the user, and the TEE of the electronic device 2 processes the face recognition. Then, the electronic device 2 sends the processing result to the electronic device 1, and the electronic device 1 can respond to the service request of the user.
[0099] It can be seen that in the above method, a function sharing network is essentially formed on the REE side, and the user operation is not convenient. In addition, since the service needs to be processed according to the request of other electronic devices, each security capability needs to be adapted in advance on the REE side, and cannot be automatically perceived according to the required service capability.
[0100] In the above method, the weak device with weak security capability needs to send a processing request to the strong device with strong security capability, and the security operation capability of the weak device itself cannot be fully utilized. In addition, the above method lacks resource sharing, and for scenarios involving security storage and other security resources, the service request cannot be completed.
[0101] Therefore, the embodiment of the present application provides a data processing method. By establishing a connection between different security environments of devices, a security environment sharing network is established, so that different devices can borrow the security capability of other devices through the connection, the processing capability of the security environment of the device is improved, and the user experience is improved.
[0102] Figure 2 A schematic diagram of a communication system to which the data processing method provided by the embodiment of the present application is applied is shown in FIG. 1. Figure 2As shown, the communication system includes a first device 100 and a second device 200. Among them, the number of the second device 200 is one or more.
[0103] Optionally, the first device 100 or the second device 200 can be an electronic device or a server. For example, Figure 2 As shown in (a), the first device 100 is an electronic device (such as a mobile phone), and the second device 200 includes a plurality of electronic devices and a plurality of servers. For example, Figure 2 As shown in (b), the first device 100 is a server, and the second device 200 includes a server and a plurality of electronic devices.
[0104] Optionally, the above-mentioned first device 100 or the second device 200 can be an electronic device or a server based on the ARM TrustZone architecture, or an electronic device or a server based on the ARM Confidential Compute Architecture (Arm CCA) architecture.
[0105] Among them, the security environment configured in the first device 100 or the second device 200 based on the ARM TrustZone architecture is TEE, and the security environment configured in the first device 100 or the second device 200 based on the ARM CCA architecture is a confidential computing environment.
[0106] Optionally, in the case where the first device 100 or the second device 200 is an electronic device, the first device 100 or the second device 200 can be, for example, a terminal device such as a mobile phone, a tablet computer, a notebook computer, a large-screen device, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), a wearable device, an artificial intelligence device, etc. The operating system installed in the first electronic device 100 includes but is not limited to or other operating systems. The specific type of the first device 100 or the second device 200 and the operating system installed therein are not limited in the present application.
[0107] Optionally, in the case where the first device 100 or the second device 200 is a server, the first device 100 or the second device 200 can be a computing device or a network device such as a cloud server or a network server. The first device 100 or the second device 200 can be a server, or a server cluster composed of a plurality of servers, or a cloud computing service center.
[0108] In some embodiments, a communication connection is established between the first device 100 and the second device 200, which can be a wireless communication connection or a wired communication connection. The wireless communication technology for establishing the wireless communication connection includes, but is not limited to, at least one of the following: Bluetooth (BT) (e.g., traditional Bluetooth or Bluetooth Low Energy (BLE)), Wireless Local Area Networks (WLAN) (e.g., Wireless Fidelity (Wi-Fi) network), Near Field Communication (NFC), Zigbee, Frequency Modulation (FM), Infrared (IR), and the like.
[0109] For example, the first device 100 or the second device 200 supports a proximity discovery function. For example, when the first device 100 is close to the second device 200, the first device 100 or the second device 200 can discover each other, and then establish a wireless communication connection such as a Wi-Fi peer-to-peer (P2P) connection, a Bluetooth connection, and the like.
[0110] For another example, the first device 100 or the second device 200 establishes a wireless communication connection through a local area network. For example, the first device 100 or the second device 200 is connected to the same router.
[0111] For another example, the first device 100 or the second device 200 establishes a wireless communication connection through a cellular network, the Internet, and the like. For example, the first device 100 accesses a cellular network through a router, and the second device 200 accesses the Internet through the cellular network. Then, the first device 100 or the second device 200 establishes a wireless communication connection.
[0112] For another example, the first device 100 or the second device 200 can also establish a wireless communication connection through a third-party device in the local area network, such as a router, a gateway, a smart device controller, a server, and the like.
[0113] For another example, the first device 100 establishes a wired communication connection with the second device 200 through a USB interface.
[0114] For example, Figure 3A FIG. 1 shows a structural schematic diagram of the first device 100 as an electronic device.
[0115] The first device 100 can include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, and the like.
[0116] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the first device 100. In other embodiments of the present application, the first device 100 can include more or fewer components than illustrated, or combine certain components, or split certain components, or different arrangement of components. The illustrated components can be implemented in hardware, software, or a combination of software and hardware.
[0117] The processor 110 can include one or more processing units, for example: the processor 110 can include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), and the like. Among them, different processing units can be independent devices, or can be integrated in one or more processors.
[0118] The controller can generate operation control signals according to instruction operation codes and timing signals, and complete the control of fetching instructions and executing instructions.
[0119] The memory in the processor 110 can also be provided for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. The memory can save instructions or data that the processor 110 has just used or repeatedly uses. If the processor 110 needs to use the instructions or data again, it can be directly called from the memory. Avoiding repeated access, reducing the waiting time of the processor 110, thus improving the efficiency of the system.
[0120] In some embodiments, the processor 110 can include one or more interfaces. The interfaces can include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0121] The I2C interface is a bidirectional synchronous serial bus including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 can include multiple sets of I2C bus. The processor 110 can be coupled to a touch sensor, a charger, a flash, a camera 193, etc. through different I2C bus interfaces respectively. For example, the processor 110 can be coupled to a touch sensor through an I2C interface, so that the processor 110 and the touch sensor communicate through the I2C bus interface to realize the touch function of the first device 100.
[0122] The MIPI interface can be used to connect the processor 110 and peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes a camera serial interface (CSI), a display serial interface (DSI), etc. In some embodiments, the processor 110 and the camera 193 communicate through the CSI interface to realize the shooting function of the first device 100. The processor 110 and the display screen 194 communicate through the DSI interface to realize the display function of the first device 100.
[0123] The USB interface 130 is an interface conforming to the USB standard specification, and can be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the first device 100, and can also be used to transmit data between the first device 100 and a peripheral device. It can also be used to connect a headset to play audio through the headset. The interface can also be used to connect other first electronic devices, such as AR devices, etc.
[0124] It can be understood that the interface connection relationship between the modules shown in the embodiments of the present application is only illustrative and does not constitute a structural limitation of the first device 100. In other embodiments of the present application, the first device 100 can also use different interface connection modes or combinations of multiple interface connection modes in the above embodiments.
[0125] The charging management module 140 is used to receive charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 can receive charging input from a wired charger through the USB interface 130. In some wireless charging embodiments, the charging management module 140 can receive wireless charging input through the wireless charging coil of the first device 100. The charging management module 140 can charge the battery 142 while also supplying power to the first electronic device through the power management module 141.
[0126] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140 to supply power to the processor 110, the internal memory 121, the display screen 194, the camera 193, and the wireless communication module 160, etc. The power management module 141 can also be used to monitor parameters such as battery capacity, battery cycle count, battery health status (leakage, impedance), etc. In other embodiments, the power management module 141 can also be disposed in the processor 110. In other embodiments, the power management module 141 and the charging management module 140 can also be disposed in the same device.
[0127] The wireless communication function of the first device 100 can be realized through the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modem processor, and the baseband processor, etc.
[0128] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the first device 100 can be used to cover a single or multiple communication frequency bands. Different antennas can also be multiplexed to improve the utilization rate of the antennas. For example, the antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In other embodiments, the antenna can be used in combination with a tuning switch.
[0129] The mobile communication module 150 can provide a solution including 2G / 3G / 4G / 5G wireless communication applied to the first device 100. The mobile communication module 150 can include at least one filter, a switch, a power amplifier, a low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves by the antenna 1, and perform filtering, amplification, etc. on the received electromagnetic waves, and transfer the processed electromagnetic waves to the modem processor to be demodulated. The mobile communication module 150 can also amplify signals modulated by the modem processor, and radiate the amplified signals as electromagnetic waves through the antenna 1. In some embodiments, at least part of the functions of the mobile communication module 150 can be provided in the processor 110. In some embodiments, at least part of the functions of the mobile communication module 150 can be provided in the same device as at least part of the modules of the processor 110.
[0130] The modem processor can include a modulator and a demodulator. The modulator is configured to modulate a low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is configured to demodulate a received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. The low-frequency baseband signal processed by the baseband processor is transmitted to the application processor. The application processor outputs a sound signal through an audio device, or displays an image or a video through the display screen 194. In some embodiments, the modem processor can be a separate device. In other embodiments, the modem processor can be provided in the same device as the mobile communication module 150 or other functional modules, independently of the processor 110.
[0131] The wireless communication module 160 can provide a solution for wireless communication applied on the first device 100, including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) network), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR) technology, etc. The wireless communication module 160 can be one or more devices integrated with at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 can also receive signals to be sent from the processor 110, perform frequency modulation and amplification, and convert the signals to electromagnetic wave radiation via the antenna 2.
[0132] In some embodiments, the first device 100 establishes a communication connection with the second device 200 through the mobile communication module 150 or the wireless communication module 160. Subsequently, the first device 100 can interact with the device information through the communication connection between the first device 100 and the second device 200, thereby establishing a secure connection between the security environments of the two devices. Further, based on the secure connection between the security environments, the first device 100 can invoke the security capabilities of the second device 200 to process the data to be processed in the security environment on the first device 100 side.
[0133] In some embodiments, the antenna 1 and the mobile communication module 150 of the first device 100 are coupled, and the antenna 2 and the wireless communication module 160 are coupled, so that the first device 100 can communicate with a network and other devices through wireless communication technology. The wireless communication technology can include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technology, etc. The GNSS can include global positioning system (GPS), global navigation satellite system (GLONASS), beidu navigation satellite system (BDS), quasi-zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).
[0134] The first device 100 implements a display function through a GPU, a display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. The processor 110 can include one or more GPUs that execute program instructions to generate or change display information.
[0135] The display screen 194 is configured to display images, videos, and the like. The display screen 194 includes a display panel. The display panel can be manufactured by using a liquid crystal display (LCD), for example, an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flex light-emitting diode (FLED), a Mini-led, a Micro-led, a Micro-oled, a quantum dot light emitting diode (QLED), and the like. In some embodiments, the first device 100 can include one or N display screens 194, where N is a positive integer greater than 1.
[0136] The camera 193 is configured to capture still images or videos. An object generates an optical image through a lens and projects the optical image to a photosensitive element. The photosensitive element can be a charge coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the optical signal into an electrical signal, and then transmits the electrical signal to an ISP to convert the electrical signal into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into an image signal in a standard format, such as RGB, YUV, and the like. In some embodiments, the first device 100 can include one or N cameras 193, where N is a positive integer greater than 1.
[0137] The external memory interface 120 can be configured to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the first device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement a data storage function. For example, music, video, and the like files can be saved in the external memory card.
[0138] The internal memory 121 can be used to store computer executable program codes including instructions. The internal memory 121 can include a program storage area and a data storage area. The program storage area can store an operating system, at least one application program required by a function (such as a sound playing function, an image playing function, etc.), and the like. The data storage area can store data created during the use of the first device 100 (such as audio data, a phone book, etc.), and the like. In addition, the internal memory 121 can include a high-speed random access memory, and can further include a non-volatile memory such as at least one of a magnetic disk storage device, a flash memory device, a universal flash storage (UFS), and the like. The processor 110 executes various function applications and data processing of the first device 100 by running instructions stored in the internal memory 121 and / or instructions stored in a memory disposed in the processor.
[0139] The audio module 170 is configured to convert digital audio information into an analog audio signal output, and to convert an analog audio input into a digital audio signal. The audio module 170 can also be configured to encode and decode audio signals. In some embodiments, the audio module 170 can be disposed in the processor 110, or some function modules of the audio module 170 can be disposed in the processor 110. The first device 100 can play music, record sound, and the like through the audio module 170. The audio module 170 can include a speaker, a receiver, a microphone, a headset jack, and an application processor, and the like to implement audio functions.
[0140] The sensor module 180 can include a pressure sensor, a gyro sensor, a barometric sensor, a magnetic sensor, an acceleration sensor, a distance sensor, a proximity light sensor, a fingerprint sensor, a temperature sensor, a touch sensor, an ambient light sensor, a bone conduction sensor, and the like.
[0141] The key 190 includes a power key, a volume key, and the like. The key 190 can be a mechanical key. Alternatively, the key 190 can be a touch key. The first device 100 can receive a key input, and generate a key signal input related to user settings and function control of the first device 100.
[0142] The motor 191 can generate a vibration prompt. The motor 191 can be used for incoming call vibration prompt, and can also be used for touch vibration feedback. For example, a touch operation on different applications (such as taking a picture, playing audio, etc.) can correspond to different vibration feedback effects. The motor 191 can also correspond to different vibration feedback effects for touch operations on different regions of the display screen 194. Different application scenarios (such as time reminders, receiving information, alarms, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customizable.
[0143] The indicator 192 can be an indicator light, which can be used to indicate the charging status, the power change, and can also be used to indicate messages, missed calls, notifications, etc.
[0144] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or pulled out of the SIM card interface 195 to realize contact and separation with the first device 100. The first device 100 can support one or N SIM card interfaces, and N is a positive integer greater than 1.
[0145] An exemplary, Figure 3B A structural schematic diagram of the first device 100 as a server is shown.
[0146] The first device 100 includes at least one processor 201, a communication line 202, a memory 203, and at least one communication interface 204. The memory 203 can also be included in the processor 201.
[0147] The processor 201 can be a general central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of programs of the present application.
[0148] The communication line 202 can include a path for transmitting information between the above-mentioned components.
[0149] The communication interface 204 is used for communication with other devices. In the embodiments of the present application, the communication interface can be a module, a circuit, a bus, an interface, a transceiver or other devices capable of realizing the communication function, and is used for communication with other devices. Optionally, when the communication interface is a transceiver, the transceiver can be a separately arranged transmitter, which can be used to send information to other devices. The transceiver can also be a separately arranged receiver, which is used to receive information from other devices. The transceiver can also be a component integrating the functions of sending and receiving information. The specific implementation of the transceiver is not limited in the embodiments of the present application.
[0150] The memory 203 may be a read-only memory (ROM) or other type of static storage device capable of storing static information and instructions, random access memory (RAM) or other type of dynamic storage device capable of storing information and instructions, or electrically erasable programmable read-only memory (EEPROM), compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compressed optical discs, laser discs, optical discs, digital versatile optical discs, Blu-ray discs, etc.), magnetic disk storage media or other magnetic storage devices, or any other medium capable of carrying or storing desired program code in the form of instructions or data structures and accessible by a computer, but not limited thereto. The memory may exist independently and be connected to the processor via communication line 202. The memory may also be integrated with the processor.
[0151] The memory 203 stores computer execution instructions for implementing the solutions of this application, and its execution is controlled by the processor 201. The processor 201 executes the computer execution instructions stored in the memory 203, thereby implementing the data processing method provided in the following embodiments of this application.
[0152] Optionally, the computer execution instructions in the embodiments of this application may also be referred to as application code, instructions, computer program or other names, and the embodiments of this application do not specifically limit them.
[0153] In a specific implementation, as one embodiment, the processor 201 may include one or more CPUs, for example... Figure 3B CPU0 and CPU1 in the CPU.
[0154] In a specific implementation, as one example, the first device 100 may include multiple processors, for example... Figure 3B Processors 201 and 207 are described herein. Each of these processors may be a single-core (single-CPU) processor or a multi-core (multi-CPU) processor. A processor here may refer to one or more devices, circuits, and / or processing cores used to process data (e.g., computer program instructions).
[0155] In a specific implementation, as an embodiment, the first device 100 can further include an output device 205 and an input device 206. The output device 205 communicates with the processor 201 and can display information in various ways. For example, the output device 205 can be a liquid crystal display (LCD), a light emitting diode (LED) display device, a cathode ray tube (CRT) display device, or a projector, etc. The input device 206 communicates with the processor 201 and can receive user input in various ways. For example, the input device 206 can be a mouse, a keyboard, a touch screen device, a sensor device, etc.
[0156] The following takes the first device 100 as the first device and the second device 200 as the second device, and the first device and the second device as devices based on the ARM TrustZone architecture as an example to introduce the data processing method provided in the embodiments of the present application in detail. It should be noted that the data processing method of the device based on the ARM CCA architecture can refer to the data processing method described in each of the following embodiments.
[0157] Optionally, Figure 4 A flowchart of a method for establishing a secure connection in a data processing process provided in an embodiment of the present application is shown in FIG. 4. As shown in FIG. 4, the method includes the following steps. Figure 4
[0158] S401, the first device obtains first information of one or more second secure environments through a first connection between the first device and one or more second devices.
[0159] In some embodiments, the first device includes a first secure environment, and the second device includes a second secure environment. The first secure environment or the second secure environment is a TEE based on the ARM TrustZone architecture, or a confidential computing environment based on the ARM CCA, or a secure environment based on other architectures.
[0160] In some embodiments, a first connection is established between the first device and the second device. The first connection is a connection between electronic devices or servers for communication, such as a Wi-Fi connection, a Bluetooth connection, an NFC connection, etc. Before a secure connection between secure environments is established between the first device and one or more second devices, a normal connection (i.e., the first connection) for exchanging device information needs to be established.
[0161] In some embodiments, the first information is a device certificate, for example, including a TEE ID, TEE version information, certificate information of the TEE, TEE OS version information, chip architecture information, supported device type information of the TEE OS, integrity measurement value (such as a signature hash value) of the TEE OS code, TEE OS vendor information, security level, and the like.
[0162] For example, as shown in FIG. 5, Figure 5 As shown in FIG. 5, the first device includes a REE 51 and a TEE 52, and one or more second devices include a target second device, which includes a REE 53 and a TEE 54. The TEE 52 of the first device includes a device certificate management module 521, and the TEE 54 of the target second device also includes a device certificate management module 541. The device certificate management module is used to manage the device certificate.
[0163] Optionally, when the first device determines to establish a secure connection with the target second device, the first device can send a secure connection establishment request to the target second device, and the secure connection establishment request can carry the device certificate of the secure environment of the first device managed by the device certificate management module 521, for interacting the device certificate with the target second device and verifying the security of the secure environment of both parties.
[0164] For example, after the first device establishes a first connection with the target second device, the device certificate management module 521 in the first device can send the device certificate of the first device to the second device through the first connection, and receive the device certificate (such as the first information) of the second device sent by the device certificate management module 541 in the second device through the first connection.
[0165] For another example, after the first device establishes the first connection, the first device does not interact the device certificate (i.e., does not establish a secure connection between the secure environments). Subsequently, in response to an operation of the user indicating to perform a secure service (such as detecting a service that needs to be processed in the TEE side on the REE side), the first device interacts the device certificate with one or more second devices through the first connection.
[0166] For another example, after the first device establishes the first connection, the first device does not interact the device certificate. Subsequently, after the first device detects an operation of the user indicating to perform a secure service, the first device determines that it does not have a security capability to process the secure service. The first device displays an interface prompt information to prompt the user whether the secure service needs to be processed by the security capability of other devices. In response to an operation of the user indicating to call the security capability of other devices, the first device interacts the device certificate with one or more second devices through the first connection.
[0167] S402, the first device determines that one or more second secure environments are secure according to the first information.
[0168] In some embodiments, after the first device obtains the first information of the second device's TEE (such as the device certificate of the second device) through the first connection, it can determine whether the second security environment (i.e. the TEE of the second device) of the second device is secure based on the first information.
[0169] For example, the first device can determine the integrity of the code based on the signature hash value of the first information, and determine that the second security environment has not been modified, thus confirming that the second security environment is secure.
[0170] S403, The first device establishes a secure connection between a first security environment and one or more second security environments.
[0171] In some embodiments, after determining that the second security environment of the second device is secure, the first device can establish a secure connection between its own first security environment and the second security environment of the second device. During the process of the first device determining whether the second security environment is secure, the second device at the other end can also receive the device certificate sent by the first device, thus determining whether the first security environment is secure.
[0172] Therefore, once both the first and second devices have determined that the security environment of the peer device is secure, a secure connection can be established between them within the secure environment.
[0173] For example, such as Figure 5 As shown, after the first device and the target second device exchange device certificates through the first connection, the security environment of the peer device is determined based on the device certificates. Afterwards, the first device can establish a second connection between TEE 52 and TEE 54 (the aforementioned secure connection includes the second connection).
[0174] In other embodiments, if either the first device or the second device determines in step S402 that the security environment in the second device is insecure, then the security authentication can be determined to have failed, and in step S403, the establishment of this security connection can be cancelled.
[0175] In this way, the first and second devices establish a secure connection between the secure environments through the interaction of device certificates. Subsequently, the secure capabilities of other devices can be invoked through the secure connection to achieve the sharing of security capabilities in distributed scenarios.
[0176] In some scenarios, after establishing a secure connection with one or more second devices, a first device can obtain the security capability information of these second devices through this connection. This allows it to determine whether to invoke the security capabilities of other devices to handle security-related tasks. In other words, a secure connection can be used to obtain and send security capability information to other devices. Furthermore, a third device can also be used to invoke the security capabilities of other devices.
[0177] The following describes a process in which the first device calls the security capability of the second security environment of the second device to process data.
[0178] Optionally, Figure 6 A flowchart of a data processing method according to an embodiment of the present application is shown in FIG. 6. Figure 6 As shown in FIG. 6, the method includes the following steps.
[0179] S601, the first device determines a target second security environment including a first security capability from one or more second security environments.
[0180] In some embodiments, the first device has a first connection with one or more second devices. The first device includes a first security environment, and the one or more second devices include one or more second security environments corresponding to the one or more second devices.
[0181] In some embodiments, the TEEs (i.e., security environments) of different devices have the same or different security capabilities. The security capability is the security capability of the system in the security environment (e.g., the security capability of the TEE OS), and the corresponding security capability is provided in the form of a TService.
[0182] Optionally, the TService includes, for example, secure storage, secure key, secure encryption and decryption, secure driver, secure clock, secure peripheral, secure CPU, etc.
[0183] Optionally, the one or more second devices include a target second device, and the target second device includes a target second security environment including the first security capability.
[0184] In some embodiments, after determining the first data to be processed in the first security environment, the first device determines that the security capability in the first security environment of the first device is insufficient to process the first data. The first device needs to call the security capability in the second security environment of the other second device to process or assist in processing the first data. Therefore, the first device needs to determine the target second security environment including the first security capability according to the first security capability that can be used to process the first data to be processed.
[0185] Based on this, the first device needs to obtain the security capability of the second security environment of each second device, so as to determine the second security environment (i.e., the target second security environment) of part or all of the second devices that are needed.
[0186] Optionally, as shown in FIG. 6, step S601 can include step S701 and step S702. Figure 7
[0187] S701, the first device acquires security capability information.
[0188] In some embodiments, the first device or the second device can generate the security capability information including its own security capability after establishing the secure connection. The security capability information can exist in a file format, such as T-Profile.
[0189] For example, the security capability of the first device includes secure storage, and the first device can determine that the corresponding security capability information includes information such as size and attribute of the storage space.
[0190] For another example, the security capability of the first device includes secure clock, and the first device can determine that the corresponding security capability information includes information of time service.
[0191] For another example, the security capability information of the first device includes information such as size and attribute of the replay protected memory block (RPMB).
[0192] In some embodiments, the first device provides a synchronization interface of T-Profile, through which the first device synchronizes the security capability information with the second device in the communication system.
[0193] For example, the first device can acquire the security capability information (i.e., the first security capability information) of one or more second devices through the secure connection after establishing the secure connection with the one or more second devices through the above-mentioned method. Figure 4 For another example, the first device locally creates a ledger for recording the security capability information, and records the security capability information of the first device (i.e., the second security capability information) and the acquired security capability information of the second device (i.e., the first security capability information) in the ledger. Optionally, the first device or the second device broadcasts its own security capability information according to a preset period, and / or broadcasts the updated security capability information after determining that the security capability is updated. The first device updates the security capability information of the second device recorded in the local ledger after receiving the broadcast information sent by the second device. Then, when determining the security capability of other devices in the communication system, the first device acquires the security capability information from the locally stored ledger.
[0194]
[0195] For example, a center node is arranged in the communication system, and the center node can be used to manage the security capability information of each device in the communication system. The first device and the second device included in the communication system can send their own security capability information to the center node for synchronization. When the first device determines that the security capability of other devices needs to be invoked, the first device can request the center node to obtain the security capability information of the other devices. Optionally, the center node is, for example, an electronic device capable of maintaining communication in the communication system, or an electronic device with strong computing power, or a non-battery device (i.e., a device capable of guaranteeing the working time).
[0196] For example, as shown in FIG. 5, the first device includes a synchronization service module 523 in the TEE 52, and the synchronization service module 523 is used to manage the security capability of the TEE 52, and synchronize the security capability information of other devices in the communication system through a secure connection. The TEE 54 of the target second device includes a synchronization service module 543, and the synchronization service module 543 is used to manage the security capability of the TEE 54, and synchronize the security capability information of other devices in the communication system through a secure connection. Figure 5
[0197] In some embodiments, the first device can obtain the security capability information when the security capability of other devices needs to be invoked. The security capability information includes the security capability of one or more second security environments that have established a secure connection with the first device.
[0198] Optionally, the first device obtains the security capability information of one or more second devices through a secure connection, and / or obtains the security capability information stored locally, and / or obtains the security capability information sent by the center node.
[0199] S702, the first device determines a target second security environment according to the security capability information.
[0200] In some embodiments, the first device can determine the security capability of one or more second security environments through the security capability information after obtaining the security capability information of one or more second devices.
[0201] Optionally, the security capability of one or more second security environments includes the security capability of a secure state application running in one or more second security environments, and / or a secure state service supported by one or more second security environments.
[0202] For example, as shown in FIG. 5, the first device includes a synchronization service module 523 in the TEE 52, and the synchronization service module 523 is used to manage the security capability of the TEE 52, and synchronize the security capability information of other devices in the communication system through a secure connection. The TEE 54 of the target second device includes a synchronization service module 543, and the synchronization service module 543 is used to manage the security capability of the TEE 54, and synchronize the security capability information of other devices in the communication system through a secure connection. Figure 1 The ARM TrustZone architecture shown, the TEE of the electronic device includes a secure state application (TA) and a secure state service (TService), and the secure application and the secure state service have corresponding security capabilities. The first device can determine, according to the acquired security capability information, that the security environment of the second device includes the security capabilities of the secure state application and / or the secure state service.
[0203] It should be noted that, referring to the introduction of the architecture of the above Figure 1 The secure state service can run on the TEE OS in the form of a trusted application (also referred to as a secure state application). That is, the secure state application integrates one or more secure state services, and the security environment of each device can include one or more secure state applications and / or one or more secure state services. Subsequently, the first device calls the security capabilities of the target second device, which can be the secure state application and / or the secure state service in the target second security environment of the target second device for the first security environment of the first device. This will not be described below.
[0204] In some embodiments, after the first device detects the service to be processed, it determines that it does not have the security capability to process the service, or that it only has the security capability to process part of the data of the service, and can distribute the service to the target second security environment of the target second device for processing through the above step S601.
[0205] For example, the first device can acquire the security capability information of other devices in the communication system through the above step S701, and then can determine the security environment configured with the security capability to process the service through the above step S702. In order to facilitate, the first device can send the data corresponding to the service that the first device cannot process to the determined security environment for processing (i.e., performing the following step S602).
[0206] For example, as Figure 5 As shown, the first device determines that the TEE 54 (i.e., the target second security environment) in the target second device has the first security capability to process the data to be processed according to the security capability information acquired by the synchronization service module 523 in the TEE 52 of the first device. For example, the synchronization service module 523 stores a table including the security capability information of all devices in the communication system, and the first device determines that the TEE 54 in the target second device has the required first security capability by looking up the table.
[0207] S602, the first device sends the first data to the target second security environment through the second connection.
[0208] In some embodiments, after determining the target second security environment configured with the first security capability for processing the first data, the first device can send the first data to the target second device including the target second security environment for processing through the second connection.
[0209] In this way, the data processing requirement in the security environment is met, and the user experience is improved.
[0210] S603, the target second device processes the first data through the first security capability to obtain a first processing result.
[0211] In some embodiments, after receiving the first data, the target second device can send the first data to the target second security environment and process the first data through the first security capability.
[0212] Optionally, the first data carries a service tag of the first data, and the target second device can determine the first security capability for processing the first data according to the service tag. Then, the target second device processes the first data through the first security capability in the target second security environment to obtain a first processing result of the first data. The service tag of the first data includes, for example, a security capability to be used, a credential of the security capability, and the like.
[0213] For example, the TEE OS of the target second device can determine the first processing result after processing the first data through the first security capability.
[0214] In some embodiments, the target second security environment of the target second device can also be configured with a permission confirmation module for determining whether the first device has the permission to call the first security capability. For example, the service tag carried in the first data sent by the first device can also include a device identifier of the first device, and the target second device can determine the permission of the first device according to the device identifier. After determining that the first device has the permission to call the first security capability, the target second device processes the obtained first data through the first security capability.
[0215] In some embodiments, the first security capability can be a security capability of a complete security state application in the target second security environment of the target second device, or can be a part of the capability (such as a security state service) of the security state application.
[0216] S604, the first device obtains the first processing result through the second connection.
[0217] In some embodiments, after determining the first processing result, the target second device sends the first processing result from the target second security environment to the first security environment of the first device through the second connection. Correspondingly, the first security environment of the first device receives the first processing result.
[0218] In this way, the security capabilities and security resources of different devices are shared through interaction between the security environments of different devices. Moreover, without pre-adapting the REE (i.e., without customizing the application capabilities on the REE side), the security capabilities of other devices can be adaptively called without user awareness, the user's needs are met, and the user operation difficulty is reduced, on the basis of ensuring data security.
[0219] In some scenarios, in order to ensure the security of data transmission between security environments, after determining that the first security capability in the target second security environment of the target second device needs to be used, the first device can negotiate a first key for transmitting data with the target second security environment of the target second device.
[0220] Optionally, as shown in FIG. 8, after step S702, step S801 can be further included. Figure 8
[0221] S801, the first device and the target second device negotiate a first key for data transmission between the first security environment and the target second security environment.
[0222] In some embodiments, in order to ensure the security of communication between security environments, the first device and the target second device need to negotiate a security key for this communication, which is used to encrypt the transmission data in the communication process. Optionally, the first device and the target second device can negotiate the first key through the second connection.
[0223] For example, as shown in FIG. 9, the TEE 52 of the first device includes a distributed key management module 522, and the TEE 54 of the target second device includes a distributed key management module 542, which are respectively used to negotiate and manage the respective security communication keys. After determining that the TEE 54 of the target second device includes the security capability for processing the first data to be processed, the first device can negotiate an encryption key (i.e., the first key) of the second connection through the distributed key management module 522 and the distributed key management module 542. Figure 5 For example, the first key is determined through a public-private key pair. The specific key negotiation method can refer to the prior art, and the embodiments of the present application do not make specific limitations thereto.
[0224]
[0225] In some embodiments, after the first device establishes the secure connection with the one or more second devices in step S403, the first device negotiates with the one or more second devices a security key for encrypting data transmitted over the secure connection. Then, in step S701 of obtaining the security capability information, the security capability information to be transmitted is encrypted by the determined security key. Thus, the security of the security capability information is ensured. That is, step S801 can be performed before step S701.
[0226] In some embodiments, after the first device and the target second device complete the key negotiation between the security environments, the first data transmitted in step S602 and the first processing result transmitted in step S604 are encrypted by the determined first key.
[0227] Optionally, as shown in Figure 8 step S602 can include step S602a, and step S604 can include step S604a.
[0228] S602a, the first device sends the first data encrypted by the first key to the target second security environment through the second connection.
[0229] In some embodiments, after the first device negotiates and determines the first key with the target second device and determines the first data to be processed by the target second device, the first device can encrypt the first data by the first key and send the encrypted first data to the target second security environment of the target second device through the second connection for processing. Correspondingly, after receiving the encrypted first data, the target second device can decrypt the obtained first data according to the first key determined by negotiation.
[0230] S604a, the first device obtains the first processing result encrypted by the first key through the second connection.
[0231] In some embodiments, after the target second device determines the first processing result, the target second device encrypts the first processing result by the first key and sends the encrypted first processing result from the target second security environment to the first security environment of the first device through the second connection. Correspondingly, the first security environment of the first device receives the first processing result and can decrypt the received first processing result according to the first key.
[0232] The following describes the first data to be processed in the first security environment of the first device in the data processing method based on the above Figures 6-8
[0233] In some scenarios, the first device triggers step S701 to acquire the security capability information of other devices in the communication system after detecting the security service to be processed and determining that the security capability of the local side cannot independently process the security service.
[0234] For example, the first device detects the first operation of the user, determines the to-be-processed data of the first service corresponding to the first operation, and determines the first data according to the to-be-processed data of the first service. The first data can be all or part of the data of the first service. The first device determines that the security capability of the first device cannot process the first data, and can acquire the security capability information to determine the device capable of processing the first data.
[0235] For example, the first device is a large-screen device, the large-screen device is installed with a financial product application, and is configured with a corresponding tangible user interface (TUI). The TUI is used to display a security keyboard to receive the password input by the user and the amount of money to be operated. After detecting the password input by the user on the TUI and the amount of money to be operated, the large-screen device determines that the large-screen device does not have the security key capability, and can execute step S701 to acquire the security capability information of other devices in the communication system. Then, the large-screen device determines that the mobile phone (target second device) connected to the large-screen device has the security key capability (i.e., step S702), and can negotiate the first key for the security communication with the mobile phone (i.e., step S801). Then, the large-screen device encrypts the password and the amount of money received by the user through the first key, and sends the encrypted password and the amount of money to the target second security environment of the mobile phone through the second connection (i.e., step S602a). After receiving the key and the amount of money, the mobile phone interacts with the cloud server (such as a bank server) to verify the password, determines whether the transaction of the current amount of money is allowed, and determines the first processing result (i.e., step S603). The mobile phone can send the encrypted first processing result to the large-screen device through the second connection (i.e., step S604a), and the large-screen device determines whether the security verification is passed according to the acquired first processing result, and displays the corresponding processing result.
[0236] For another example, the first device can also determine the first data in the to-be-processed data of the second service in response to the acquired second service.
[0237] For example, the first device is server 1, the first device obtains a request for storing data through a secure storage capability, determines that the local side does not have the secure storage capability, and can execute the above step S701 to obtain the secure capability information of other devices in the communication system. Then, the server 1 determines that the secure environment of the server 2 is configured with the secure storage capability (i.e., step S702), and can negotiate the first key for the secure communication with the server 2 (i.e., step S801). Then, the server 1 sends the storage data encrypted through the first key to the target second secure environment of the server 2 through the second connection (i.e., step S602a). After receiving the storage data, the server 2 can store the storage data through the secure storage capability, and determine the first processing result, such as a response of storage success or failure (i.e., step S603). The server 1 can obtain the first processing result sent by the server 2 (i.e., step S604a), and determine whether the storage is successful.
[0238] For example, the first device is server 1, the first device obtains a request for storing data through a secure storage capability, determines that the local side has the secure storage capability, but the storage space is insufficient. The server 1 can execute the above step S701 to obtain the secure capability information of other devices in the communication system. Then, the server 1 determines that the secure environment of the server 2 is configured with the secure storage capability and the available secure storage space size of the server 2, and determines that the secure environment of the server 3 is configured with the secure storage capability and the available secure storage space size of the server 3 (i.e., step S702). According to the obtained secure capability information, the server 1 determines that the storage data obtained this time needs to be stored through the remaining secure storage space of the server 1, the available secure storage space of the server 2, and the available secure storage space of the server 3, to complete the entire storage service.
[0239] Then, the server 1 can negotiate the key 1 for the secure communication with the server 2, and negotiate the key 2 for the secure communication with the server 3 (i.e., step S801). Then, the server 1 divides the storage data to be stored into data 1 (data to be stored in the local side), data 2 (data to be stored in the server 2), and data 3 (data to be stored in the server 3), encrypts the data 2 through the key 1, and sends the data 2 to the secure environment of the server 2 through the secure connection between the server 1 and the server 2, and encrypts the data 3 through the key 2, and sends the data 3 to the secure environment of the server 3 through the secure connection between the server 1 and the server 3 (i.e., step S602a). After receiving the corresponding data, the server 2 and the server 3 store the data through the secure storage capability, and determine the data storage response (i.e., step S603). The server 1 can obtain the data storage response sent by the server 2 and the server 3 (i.e., step S604a), determine whether the storage is successful, and directly determine whether the data 1 in the local side is stored successfully.
[0240] Thus, by pooling the security capabilities of the various devices, a super TEE is formed from the security environments of the various devices in the communication system. Thus, as long as the super TEE has the security capability to process the data to be processed, the devices in the communication system can process the data to be processed.
[0241] In addition, the security capabilities of the various devices are abstracted, the security service is divided, and the security service is processed by the various devices in cooperation with their own security capabilities, so that the security capabilities of the various devices are fully utilized.
[0242] It should be noted that the division of the first device for the service to be processed can refer to the prior art, and the embodiments of the present application will not be specifically described. For example, the first device can divide the service according to its own security capability, security storage resource and the like. For example, the large-screen device determines to collect the password by itself, and the password is verified by the mobile phone. For another example, the server 1 divides the data to be stored, and determines that the data is stored by the server 1, the server 2 and the server 3 respectively.
[0243] In some embodiments, in the step S604a, the target second device deletes the first key after sending the first processing result. Correspondingly, the first device deletes the first key after obtaining the first processing result.
[0244] Thus, the first device needs to re-negotiate the key for this communication with the determined target second device each time the security capability of the other device needs to be called, so as to avoid key leakage and affect the security of data transmission.
[0245] For example, after the first device deletes the first key, the second service is obtained, and the second data of the second service to be processed is determined. Then, the first device determines that the target second security environment of the target second device includes the second security capability, and the second security capability can be used to process the second data to be processed in the first security environment. Then, the first device negotiates a second key for data transmission between the first security environment and the target second security environment with the target second device through the second connection, and the second key is used to encrypt the second data and the second processing result corresponding to the second data.
[0246] In some embodiments, after the first device determines that the second device exits the communication system, the security capability information of the second device in the security information can be deleted. For example, after the first device disconnects the first connection between the target second device including the target second security environment, the security capability of the target second security environment of the target second device in the security capability information can be deleted.
[0247] For example, Figure 9As shown, after the first device accesses to the communication system (e.g., joins the network) including the second device, the first device establishes a secure connection between the first security environment of the first device and the second security environment of the second device. Then, the first device generates its own security capability information, and sends the security capability information to the other second device through the secure connection, and synchronizes the security capability information of the other second device through the secure connection, thereby completing the synchronization of the security capability information of the device in the network.
[0248] After the second device in the communication system exits the communication system (e.g., exits the network), the second device synchronously broadcasts its own exit information, and the first device can synchronously delete the security capability information of the device that exits the network. In addition, the device that exits the network can also delete the security capability information of the other devices in the communication system stored locally.
[0249] It can be understood that after the first device disconnects the first connection with the target second device, the second connection between the security environments of the two devices is automatically disconnected.
[0250] In this way, the synchronization and update of the security capability information in the communication system are ensured, and the security capability information of the device that does not access the communication system is avoided to be included in the synchronized security capability information, so that the calling of the security capability of the device by the other devices fails.
[0251] The data processing method provided by the embodiments of the present application is described in detail above. Figures 4-9 The first device and the second device provided by the embodiments of the present application are described in detail below. Figure 10 and Figure 11 The first device and the second device provided by the embodiments of the present application are described in detail below.
[0252] In a possible design, Figure 10 a structure diagram of the first device provided by the embodiments of the present application. As shown in Figure 10 , the first device 1000 can include a transceiver unit 1001 and a processing unit 1002. The first device 1000 can be used to implement the functions of the first device involved in the above method embodiments. The first device is an electronic device or a server.
[0253] Optionally, the transceiver unit 1001 is configured to support the first device 1000 to perform S401 and S403 in the method embodiment; and / or, is configured to support the first device 1000 to perform S602 and S604 in the method embodiment; and / or, is configured to support the first device 1000 to perform S701 in the method embodiment; and / or, is configured to support the first device 1000 to perform S801, S602a and S604a in the method embodiment. Figure 4 Figure 6 Figure 7 Figure 8
[0254] Optionally, the processing unit 1002 is configured to support the execution of the first device 1000. Figure 4 S402 in the middle; used to support the execution of the first device 1000 Figure 6 S601 in the middle; and / or, and / or, for supporting the execution of the first device 1000 Figure 7 S702 in the middle.
[0255] The transceiver unit may include a receiving unit and a transmitting unit, and may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or transceiver module. The operation and / or function of each unit in the first device 1000 are respectively to implement the corresponding flow of the data processing method described in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional unit, and for the sake of brevity, it will not be repeated here.
[0256] Optionally, Figure 10 The first device 1000 shown may also include a storage unit ( Figure 10 (not shown in the image), this storage unit stores a program or instruction. When the transceiver unit 1001 and the processing unit 1002 execute the program or instruction, it causes... Figure 10 The first device 1000 shown can perform the data processing method described in the above method embodiments.
[0257] Figure 10 The technical effects of the first device 1000 shown can be referred to the technical effects of the data processing method described in the above method embodiments, and will not be repeated here.
[0258] In addition to being in the form of the first device 1000, the technical solutions provided in this application may also be functional units or chips in the first device, or devices used in conjunction with the first device.
[0259] In one possible design, Figure 11 This is a schematic diagram of the structure of the second device provided in an embodiment of this application. Figure 11 As shown, the second device 1100 may include a transceiver unit 1101 and a processing unit 1102. The second device 1100 can be used to implement the functions of the second device involved in the above method embodiments. The second device is an electronic device or a server.
[0260] Optionally, the transceiver unit 1101 is used to support the second device 1100 in performing [operations]. Figure 4 S401 and S403 in the above; and / or, for supporting the execution of the second device 1100 Figure 6 S602 and S604 in the above; and / or, for supporting the execution of the second device 1100 Figure 8 S801, S602a and S604a.
[0261] Optionally, the processing unit 1102 is used to support the execution of the second device 1100. Figure 6 S603 in the middle.
[0262] The transceiver unit may include a receiving unit and a transmitting unit, and may be implemented by a transceiver or transceiver-related circuit components, and may be a transceiver or transceiver module. The operation and / or function of each unit in the second device 1100 are respectively to implement the corresponding flow of the data processing method described in the above method embodiments. All relevant content of each step involved in the above method embodiments can be referred to the functional description of the corresponding functional unit, and for the sake of brevity, it will not be repeated here.
[0263] Optionally, Figure 11 The second device 1100 shown may also include a storage unit ( Figure 11 (not shown in the image), this storage unit stores a program or instruction. When the transceiver unit 1101 and the processing unit 1102 execute the program or instruction, it causes... Figure 11 The second device 1100 shown can perform the data processing method described in the above method embodiments.
[0264] Figure 11 The technical effects of the second device 1100 shown can be referred to the technical effects of the data processing method described in the above method embodiments, and will not be repeated here.
[0265] In addition to being in the form of a second device 1100, the technical solutions provided in this application may also be functional units or chips in the second device, or devices used in conjunction with the second device.
[0266] This application also provides a chip system, including: a processor coupled to a memory, the memory being used to store programs or instructions, wherein when the program or instructions are executed by the processor, the chip system implements the methods in any of the above method embodiments.
[0267] Optionally, the chip system may contain one or more processors. These processors can be implemented in hardware or software. When implemented in hardware, the processor can be a logic circuit, an integrated circuit, etc. When implemented in software, the processor can be a general-purpose processor, implemented by reading software code stored in memory.
[0268] Optionally, the memory in the chip system can also be one or more. The memory can be integrated with the processor, or can be arranged separately from the processor, and the embodiments of the present application are not limited. Exemplarily, the memory can be a non-transient processor, for example, a read-only memory (ROM), which can be integrated on the same chip as the processor, or can be arranged separately on different chips, and the embodiments of the present application do not make specific limitations on the type of memory and the arrangement of the memory and the processor.
[0269] Exemplarily, the chip system can be a field programmable gate array (FPGA), can be an application specific integrated circuit (ASIC), can also be a system on chip (SoC), can also be a central processing unit (CPU), can also be a network processor (NP), can also be a digital signal processing circuit (DSP), can also be a micro controller unit (MCU), can also be a programmable logic device (PLD) or other integrated chip.
[0270] It should be understood that each step in the above method embodiments can be completed by integrated logic circuits of hardware in the processor or instructions in the form of software. The method steps disclosed in combination with the embodiments of the present application can be directly embodied as hardware processor execution, or executed by a combination of hardware and software modules in the processor.
[0271] The embodiments of the present application also provide a computer readable storage medium, which stores a computer program. When the computer program is run on a computer, the computer is caused to execute the above related steps to implement the data processing method in the above embodiments.
[0272] The embodiments of the present application also provide a computer program product. When the computer program product is run on a computer, the computer is caused to execute the above related steps to implement the data processing method in the above embodiments.
[0273] In addition, the embodiments of the present application also provide an apparatus. The apparatus can be specifically a component or a module, and the apparatus can include one or more processors and memories connected thereto. The memories are used to store computer programs. When the computer programs are executed by the one or more processors, the apparatus executes the data processing method in the above method embodiments.
[0274] Among them, the device, computer readable storage medium, computer program product or chip provided by the embodiments of the present application are used to execute the corresponding method provided above. Therefore, the beneficial effects that can be achieved are referred to the beneficial effects of the corresponding method provided above, which will not be described here.
[0275] The steps of the methods or algorithms described in connection with the disclosure of the embodiments of the present application can be implemented in hardware, or by a processor executing software instructions. The software instructions can be composed of corresponding software modules, which can be stored in a random access memory (RAM), a flash memory, a read only memory (ROM), an erasable programmable ROM (EPROM), an electrically EPROM (EEPROM), a register, a hard disk, a mobile hard disk, a compact disc read only memory (CD-ROM), or any other form of storage medium well known in the art. An exemplary storage medium is coupled to the processor, so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be an integral part of the processor. The processor and the storage medium can be located in an application specific integrated circuit (ASIC).
[0276] From the above description of the embodiments, those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of functional modules is taken as an example. In actual application, the above functions can be completed by different functional modules according to needs; that is, the internal structure of the device is divided into different functional modules to complete all or part of the functions described above. The specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiments, which will not be described here.
[0277] In several embodiments provided in the present application, it should be understood that the disclosed method can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the modules or units is only a logical function division, and actual implementation can have another division manner; for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the coupling or direct coupling or communication connection between the displayed or discussed mutual ones can be indirect coupling or communication connection through some interfaces, modules or units, which can be electrical, mechanical or other forms.
[0278] In addition, each functional unit in each embodiment of the present application can be integrated in one processing unit, or each unit can exist physically, or two or more units can be integrated in one unit. The integrated unit can be realized in the form of hardware or in the form of a software functional unit.
[0279] The computer readable storage medium includes, but is not limited to, any one of the following: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media capable of storing program codes.
[0280] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto, any change or replacement within the technical scope disclosed in the present application should be covered in the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A data processing method, characterized by, The method is applied to a first device, the first device establishes a first connection with one or more second devices, the first device comprises a first security environment, the one or more second devices comprise one or more second security environments corresponding to the one or more second devices, and the method comprises: receiving, through the first connection, first information of the one or more second security environments sent by the one or more second devices; determining that the one or more second security environments are secure according to the first information; establishing a secure connection between the first security environment and the one or more second security environments respectively; determining a target second security environment comprising a first security capability in the one or more second security environments, wherein the first security capability is used to process first data to be processed in the first security environment; sending the first data to the target second security environment through a second connection, wherein the second connection is a connection between the first security environment and the target second security environment in the secure connection; receiving a first processing result of the first data through the second connection, wherein the first processing result is a processing result generated by processing the first data through the first security capability.
2. The method of claim 1, wherein, The determining of the target second security environment comprising the first security capability in the one or more second security environments comprises: obtaining first security capability information through the secure connection, wherein the first security capability information comprises security capabilities comprised by the one or more second security environments; and determining the target second security environment according to the first security capability information.
3. The method of claim 2, wherein, Before the sending of the first data to the target second security environment through the second connection, the method further comprises: negotiating, with a target second device comprising the target second security environment, a first key for data transmission between the first security environment and the target second security environment, wherein the first key is used to encrypt the first data and the first processing result transmitted through the second connection.
4. The method of claim 3, wherein, The method further comprises: deleting the first key.
5. The method of claim 4, wherein, The method further comprises: determining that the target second security environment comprises a second security capability used to process second data to be processed in the first security environment; negotiating, with the target second device, a second key for data transmission between the first security environment and the target second security environment, wherein the second key is used to encrypt the second data and a second processing result corresponding to the second data transmitted through the second connection.
6. The method of claim 1, wherein, The method further comprises: sending, to the one or more second devices through the secure connection, second security capability information of security capabilities comprised by the first security environment.
7. The method according to any one of claims 2 to 6, characterized in that, The obtaining of the first security capability information comprises: obtaining the first security capability information stored locally; and / or obtaining the first security capability information sent by a center node.
8. The method of claim 7, wherein, The method further comprises: sending, to the center node, second security capability information of security capabilities comprised by the first security environment.
9. The method according to any one of claims 2-6, characterized in that, The method further comprises: disconnecting the first connection with a target second device comprising a target second security environment of the target second security environment; deleting security capability information of the target second security environment of the target second device in the first security capability information.
10. The method according to any one of claims 1 to 6, characterized in that, The security capability of the one or more second security environments comprises: security capability of a secure state application running in the one or more second security environments, and / or security state service supported by the one or more second security environments.
11. The method according to any one of claims 1 to 6, characterized in that, The first security environment or the second security environment is a trusted execution environment (TEE) or a confidential computing environment.
12. A data processing method, characterized by, The method is applied to a second device, the second device has established a first connection with a first device, the second device comprises a second security environment, the first device comprises a first security environment, and the method comprises: sending first information of the second security environment to the first device through the first connection, the first information indicating that the second security environment is secure; establishing a second connection between the first security environment and the second security environment; receiving first data sent by the first security environment in the first device through the second connection, the first data being to-be-processed data in the first security environment; processing the first data through a first security capability to obtain a first processing result; sending the first processing result to the first security environment through the second connection.
13. The method of claim 12, wherein, Before the second security environment in the second device receives the first data sent by the first security environment in the first device through the second connection, the method further comprises: negotiating a first key for data transmission between the first security environment and the second security environment with the first device, the first key being used to encrypt the first data and the first processing result.
14. The method according to claim 12 or 13, characterized in that, Before the first data is processed through the first security capability, the method further comprises: determining that the first device has the permission to call the first security capability.
15. The method of claim 12 or 13, wherein, The first data carries a service tag corresponding to the first data; before the first data is processed through the first security capability to obtain the first processing result, the method further comprises: determining the first security capability corresponding to the service tag according to the service tag.
16. A data processing apparatus, characterized by: comprise: a processor and a memory, the memory being coupled to the processor, the memory being used to store computer readable instructions, when the processor reads the computer readable instructions from the memory, the data processing apparatus executes the method of any one of claims 1-11; or, the data processing apparatus executes the method of any one of claims 12-15.
17. A computer readable storage medium characterized by: The computer readable storage medium comprises a computer program, when the computer program runs on the data processing apparatus, the data processing apparatus executes the method of any one of claims 1-11; or, the data processing apparatus executes the method of any one of claims 12-15.
18. A computer program product, characterised in that, When the computer program product is run on a computer, it causes the computer to perform the method of any one of claims 1-11; or, it causes the computer to perform the method of any one of claims 12-15.
Citation Information
Patent Citations
Data processing method and electronic equipment
CN111371849A
Distributed key management for trusted execution environments
US20200304319A1