Data protection method and electronic device
Patent Information
- Application Number
- CN202211165829.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-23
- Publication Date
- 2026-09-22
- Estimated Expiration
- 2042-09-23
AI Technical Summary
[0049]第四方面,本申请提供了一种计算机程序产品,当计算机程序产品在电子设上运行时,使得电子设执行上述第一方面中任一可能的实现方式中提供的一种数据保护方法。
Smart Images

Figure CN117807605B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of data security technology, and in particular to a data protection method and electronic device. Background Technology
[0002] As a hardware-level high-security and trustworthy environment, security chips have strong security against physical attacks and are widely used in devices with high security requirements, such as mobile devices and Internet of Things (IoT) devices.
[0003] Currently, security chips in devices are used to store checksums for verifying user data. When electronic devices use user data, the correctness of the checksums needs to be verified; only if the checksum passes verification can the electronic device use the user data. Further research is needed to improve the security of checksums for user data stored in security chips. Summary of the Invention
[0004] This application provides a data protection method and electronic device that implements a multi-level authentication mechanism within a secure chip. Only after successful authentication can the electronic device use the second user's data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0005] Firstly, this application provides a data protection method, the method comprising:
[0006] The electronic device obtains second user data, a credential of a first counter, and a first verification value of the first user data from a non-secure chip. The credential of the first counter in the non-secure chip is used to obtain a first value of the first counter, and the first verification value and the first value of the first counter are used to verify whether the second user data is the same as the first user data. The electronic device obtains a credential of the first counter from a secure chip. If the credential of the first counter in the non-secure chip and the credential of the first counter in the secure chip are the same, the electronic device obtains the first value of the first counter through the secure chip. The electronic device obtains a second verification value of the second user data based on the second user data and the first value of the first counter through the secure chip. If the first verification value and the second verification value are the same, the electronic device uses the second user data.
[0007] The non-security chip can be a flash chip, a server, or a storage device such as a hard drive; this application does not limit this.
[0008] The first user data refers to the user data previously stored in the electronic device. The second user data is the user data that the electronic device reads from the previously stored first user data. The first user data is stored in a first storage location. Therefore, the second user data can be read from the first storage location.
[0009] If the first checksum and the second checksum are different, it indicates that the attacker may have modified the first user data, for example, by changing the first user data to the second user data, in which case the first user data and the second user data are different. The first user data and the second user data can be stored in the same location.
[0010] If the first check value and the second check value are the same, it means that the second user data is the same as the first user data, and the electronic device uses the second user data, that is, the electronic device uses the first user data.
[0011] This implements a multi-level authentication mechanism within the security chip. Only after successful authentication can the electronic device use the second user data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0012] In conjunction with the first aspect, in one possible implementation, the method further includes: if the credentials for the first counter in the non-secure chip and the credentials for the first counter in the secure chip are different, the electronic device cannot obtain the first value of the first counter from the secure chip. Thus, if an attacker does not know the credentials for the first counter, the credentials for the first counter cannot pass authentication, and the attacker cannot obtain the first value of the first counter, ensuring the security of the first value of the first counter stored in the secure chip.
[0013] In conjunction with the first aspect, one possible implementation also includes: if the first check value and the second check value are different, the electronic device cannot use the second user data.
[0014] Optionally, the security chip can also calculate the verification value of user data based on other factors, including but not limited to one or more of the hardware unique key and device unique ID. Other factors can also be other values, and this application embodiment does not limit them.
[0015] In this way, even if an attacker forges user data, for example, by modifying the first user data into the second user data, the second verification value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first verification value. That is, the verification value of the user data will fail the verification, and the electronic device will not be able to use the forged second user data.
[0016] In conjunction with the first aspect, in one possible implementation, before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the insecure chip, the method further includes: the electronic device storing the first user data, the first verification value of the first user data, and the credentials of the first counter in the insecure chip. The electronic device then stores the first value of the first counter and the credentials of the first counter in the secure chip.
[0017] In this way, the electronic device stores the first value of the first counter in the security chip, ensuring the security of the first value of the first counter and preventing attackers from obtaining the first value of the first counter.
[0018] The electronic device stores the credentials of the first counter in a security chip so that when the electronic device uses the stored user data, it can perform authentication based on the credentials of the first counter. Only when the authentication is successful can the electronic device use the stored user data, thus ensuring the security of the user data stored on the electronic device.
[0019] In conjunction with the first aspect, in one possible implementation, the electronic device stores the credentials of the first counter within a security chip. Specifically, this includes: the electronic device generating the credentials of the first counter through the security chip; and the electronic device storing the credentials of the first counter within the security chip. In this case, the security chip needs to store the credentials of the first counter in a non-security chip or on a server, so that when the electronic device uses the user data, authentication can be performed based on the credentials of the first counter stored in the non-security chip or on the server.
[0020] or,
[0021] The electronic device obtains the credentials of the first counter outside the security chip; the electronic device stores the credentials of the first counter inside the security chip.
[0022] In conjunction with the first aspect, in one possible implementation, the first value of the first counter is obtained based on the initial value and a first preset value of the first counter, wherein the initial value of the counter is randomly generated. This random generation of the initial value of the first counter prevents attackers from obtaining the first value of the first counter through brute-force enumeration, thus avoiding the leakage of the first value of the first counter stored in the security chip and improving the security of the first value of the first counter stored within the security chip.
[0023] In conjunction with the first aspect, in one possible implementation, before the electronic device stores the first value of the first counter in the security chip, the method further includes: the electronic device generating an initial value for the first counter through the security chip. In this way, the initial value of the first counter is generated within the security chip, improving the security of the counter value stored within the security chip.
[0024] In conjunction with the first aspect, in one possible implementation, before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the insecure chip, the method further includes: the electronic device obtaining the first user data, the identifier of the first counter, and the credentials of the first counter stored in the insecure chip from the insecure chip; the electronic device determining the credentials of the first counter stored in the secure chip based on the identifier of the first counter using the secure chip; if the credentials of the first counter in the insecure chip and the credentials of the first counter in the secure chip are the same, the electronic device obtaining the first value of the first counter; the electronic device obtaining the first verification value of the first user data based on the first value of the first counter and the first user data using the secure chip; and the electronic device storing the first verification value of the first user data in the insecure chip. Thus, when the electronic device stores the first user data, a first verification value is generated in the secure chip based on the first user data and the first value of the first counter. After generating the first verification value, the electronic device stores the first verification value in the insecure chip, such as in a flash chip or on a server. In this way, even if an attacker forges user data, for example, by using second user data to replace the first user data, during authentication, the second verification value generated in the security chip based on the second user data and the first value of the first counter will be different from the first verification value, causing the verification to fail and preventing the attacker from forging user data.
[0025] In conjunction with the first aspect, in one possible implementation, after the electronic device uses the second user data, the method further includes: the electronic device acquiring third user data, which is a modified version of the second user data; the electronic device sending the third user data, the credentials of the first counter in the non-secure chip, and the identifier of the first counter to the secure chip; the electronic device acquiring the credentials of the first counter based on the identifier of the first counter through the secure chip; if the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device acquiring the first value of the first counter through the secure chip, and obtaining the second value of the first counter based on the first value and a second preset value; the electronic device obtaining the third verification value of the third user data based on the third user data and the second value of the first counter through the secure chip; and the electronic device storing the third verification value of the third user data in the non-secure chip.
[0026] In other words, after the second user data is authenticated, the electronic device uses the second user data, causing it to change and resulting in third user data. The electronic device needs to store this third user data. When storing the third user data, the electronic device must generate a verification value for the third user data within the security chip, i.e., a third verification value. This is so that when the electronic device uses the third user data later, it can verify whether the third user data is forged based on the verification value.
[0027] Secondly, this application provides an electronic device, comprising: one or more processors, one or more memories, and a display screen; the one or more memories and the display screen are coupled to the one or more processors, the one or more memories being used to store computer program code, the computer program code including computer instructions, and the one or more processors calling the computer instructions to cause the electronic device to execute: obtaining second user data, a credential of a first counter, and a first verification value of the first user data from a non-secure chip; wherein, the credential of the first counter in the non-secure chip is used to obtain a first value of the first counter, and the first verification value and the first value of the first counter are used to verify whether the second user data is the same as the first user data; obtaining a credential of the first counter from a secure chip; if the credential of the first counter in the non-secure chip and the credential of the first counter in the secure chip are the same, obtaining the first value of the first counter through the secure chip; obtaining a second verification value of the second user data through the secure chip based on the second user data and the first value of the first counter; and using the second user data if the first verification value and the second verification value are the same.
[0028] The non-security chip can be a flash chip, a server, or a storage device such as a hard drive; this application does not limit this.
[0029] The first user data refers to the user data previously stored in the electronic device. The second user data is the user data that the electronic device reads from the previously stored first user data. The first user data is stored in a first storage location. Therefore, the second user data can be read from the first storage location.
[0030] If the first checksum and the second checksum are different, it indicates that the attacker may have modified the first user data, for example, by changing the first user data to the second user data, in which case the first user data and the second user data are different. The first user data and the second user data can be stored in the same location.
[0031] If the first check value and the second check value are the same, it means that the second user data is the same as the first user data, and the electronic device uses the second user data, that is, the electronic device uses the first user data.
[0032] This implements a multi-level authentication mechanism within the security chip. Only after successful authentication can the electronic device use the second user data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0033] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: if the credentials for the first counter in the non-secure chip and the credentials for the first counter in the secure chip are different, the first value of the first counter cannot be obtained from the secure chip. Thus, if an attacker does not know the credentials for the first counter, the credentials for the first counter cannot pass authentication, and the attacker cannot obtain the first value of the first counter, ensuring the security of the first value of the first counter stored in the secure chip.
[0034] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: if the first checksum and the second checksum are different, the second user data cannot be used.
[0035] Optionally, the security chip can also calculate the verification value of user data based on other factors, including but not limited to one or more of the hardware unique key and device unique ID. Other factors can also be other values, and this application embodiment does not limit them.
[0036] In this way, even if an attacker forges user data, for example, by modifying the first user data into the second user data, the second verification value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first verification value. That is, the verification value of the user data will fail the verification, and the electronic device will not be able to use the forged second user data.
[0037] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to perform: storing first user data, a first checksum of the first user data, and a credential of the first counter in a non-secure chip; and storing a first value of the first counter and a credential of the first counter in a secure chip.
[0038] In this way, the electronic device stores the first value of the first counter in the security chip, ensuring the security of the first value of the first counter and preventing attackers from obtaining the first value of the first counter.
[0039] The electronic device stores the credentials of the first counter in a security chip so that when the electronic device uses the stored user data, it can perform authentication based on the credentials of the first counter. Only when the authentication is successful can the electronic device use the stored user data, thus ensuring the security of the user data stored on the electronic device.
[0040] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: generating a credential for a first counter via a security chip; and storing the credential for the first counter within the security chip. In this case, the security chip needs to store the credential for the first counter in a non-security chip or on a server, so that when the electronic device uses the user data, authentication can be performed based on the credential for the first counter stored in the non-security chip or on the server.
[0041] or,
[0042] Obtain the credentials for the first counter outside the security chip; store the credentials for the first counter inside the security chip.
[0043] In conjunction with the second aspect, in one possible implementation, the first value of the first counter is obtained based on the initial value and a first preset value of the first counter, wherein the initial value of the counter is randomly generated. This random generation of the initial value of the first counter prevents attackers from obtaining the first value of the first counter through brute-force enumeration, thus avoiding the leakage of the first value of the first counter stored in the security chip and improving the security of the first value of the first counter stored within the security chip.
[0044] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: generating an initial value for a first counter via a security chip. In this way, the initial value of the first counter is generated within the security chip, improving the security of the counter's value stored within the security chip.
[0045] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: obtaining first user data, an identifier of a first counter, and a credential of the first counter stored in the non-secure chip from a non-secure chip; determining the credential of the first counter stored in the secure chip based on the identifier of the first counter using a secure chip; obtaining a first value of the first counter if the credential of the first counter in the non-secure chip and the credential of the first counter in the secure chip are the same; obtaining a first verification value of the first user data based on the first value of the first counter and the first user data using the secure chip; and storing the first verification value of the first user data in the non-secure chip. Thus, when the electronic device stores the first user data, a first verification value is generated in the secure chip based on the first user data and the first value of the first counter. After generating the first verification value, the electronic device stores the first verification value in the non-secure chip, such as in a flash chip or on a server. Therefore, even if an attacker forges user data, for example, by replacing the first user data with second user data, during authentication, the second verification value generated in the secure chip based on the second user data and the first value of the first counter will be different from the first verification value, causing the verification to fail and preventing attackers from forging user data.
[0046] In conjunction with the second aspect, in one possible implementation, one or more processors invoke computer instructions to cause the electronic device to perform the following: after the electronic device uses second user data, it acquires third user data, which is a modified version of the second user data; it sends the third user data, the credentials of the first counter in the non-secure chip, and the identifier of the first counter to the secure chip; the secure chip acquires the credentials of the first counter based on the identifier of the first counter; if the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the secure chip acquires the first value of the first counter, and obtains the second value of the first counter based on the first value and a second preset value; the secure chip obtains the third verification value of the third user data based on the third user data and the second value of the first counter; and the secure chip stores the third verification value of the third user data in the non-secure chip.
[0047] In other words, after the second user data is authenticated, the electronic device uses the second user data, causing it to change and resulting in third user data. The electronic device needs to store this third user data. When storing the third user data, the electronic device must generate a verification value for the third user data within the security chip, i.e., a third verification value. This is so that when the electronic device uses the third user data later, it can verify whether the third user data is forged based on the verification value.
[0048] Thirdly, this application provides a computer-readable storage medium for storing computer instructions that, when executed on an electronic device, cause the electronic device to perform a data protection method provided in any possible implementation of the first aspect above.
[0049] Fourthly, this application provides a computer program product that, when run on an electronic device, causes the electronic device to execute a data protection method provided in any possible implementation of the first aspect above.
[0050] For the beneficial effects of the second to fourth aspects, please refer to the description of the beneficial effects in the first aspect; the embodiments of this application will not be repeated here. Attached Figure Description
[0051] Figures 1-3 Schematic diagrams of several security chips provided in the embodiments of this application;
[0052] Figure 4 A schematic diagram illustrating the storage of a verification value for user data in an electronic device, as provided in an embodiment of this application;
[0053] Figure 5 A schematic diagram illustrating an electronic device verifying the check value of user data, provided in an embodiment of this application;
[0054] Figure 6 A schematic diagram illustrating another electronic device for storing user data verification values, provided in an embodiment of this application.
[0055] Figure 7 A schematic diagram illustrating another electronic device for verifying user data verification values, provided in an embodiment of this application.
[0056] Figure 8 A schematic diagram of the hardware structure of an electronic device 100 provided in an embodiment of this application;
[0057] Figure 9 A schematic diagram of the software structure of an electronic device 100 provided in an embodiment of this application;
[0058] Figure 10 This application provides a schematic flowchart of a method for generating a counter voucher.
[0059] Figure 11 A schematic flowchart illustrating another method for generating a counter's credentials provided in this application embodiment;
[0060] Figure 12 A schematic diagram illustrating how to protect user data and generate a verification value for user data, as provided in an embodiment of this application;
[0061] Figure 13A schematic diagram illustrating a method for verifying the correctness of a checksum value of first user data in a security chip before an electronic device uses first user data, provided in an embodiment of this application;
[0062] Figure 14 A schematic diagram illustrating a method for saving changed second user data provided in an embodiment of this application;
[0063] Figure 15 A flowchart illustrating a data protection method provided in an embodiment of this application;
[0064] Figure 16 This is a schematic flowchart of a data protection device provided in an embodiment of this application. Detailed Implementation
[0065] The technical solutions in the embodiments of this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or," for example, A / B can mean A or B; the word "and / or" in the text is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Furthermore, in the description of the embodiments of this application, "multiple" refers to two or more than two.
[0066] Hereinafter, the terms "first" and "second" are used for descriptive purposes only and should not be construed as implying or suggesting relative importance or implicitly indicating the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of that feature, and in the description of the embodiments of this application, unless otherwise stated, "multiple" means two or more.
[0067] The term "user interface (UI)" used in the following embodiments of this application refers to the medium interface through which an application or operating system interacts and exchanges information with the user. It realizes the conversion between the internal form of information and the form that the user can accept. The commonly used form of user interface is the graphical user interface (GUI), which refers to a user interface related to computer operation that is displayed graphically. It can be visible interface elements such as text, icons, buttons, menus, tabs, text boxes, dialog boxes, status bars, navigation bars, and widgets displayed on the screen of an electronic device.
[0068] First, the technical terms involved in the embodiments of this application will be explained.
[0069] 1. User data verification value
[0070] User data checksums are used to protect the security of user data on electronic devices. Before storing user data, an electronic device generates a checksum and stores it in a non-secure chip. When the electronic device uses user data, it verifies the correctness of the checksum within the secure chip. Only if the verification passes can the electronic device access and use the user data. If the checksum fails, the electronic device cannot access the user data.
[0071] The verification value of user data can be generated based on user data or other parameters, and this application embodiment does not limit this.
[0072] When storing user data, electronic devices also store a checksum for the user data. This checksum allows the electronic device to verify the correctness of the user data. Specifically, before using the user data, the electronic device obtains the separately stored checksum and the checksum calculated from the security chip. If the separately stored checksum and the checksum calculated from the security chip match, the user data checksum verification passes, and the electronic device can then obtain and use the user data. Otherwise, the electronic device cannot obtain or use the user data.
[0073] 2. Security chip
[0074] To ensure the security of the verification values of user data stored in electronic devices and prevent attackers from obtaining these verification values, authentication information is typically stored in a security chip within the electronic device to prevent leakage.
[0075] Security chips take the following forms in electronic devices:
[0076] Form 1: such as Figure 1 As shown, the security chip is located within the built-in security core of the main chip (SOC chip) in the electronic device. It can be a portion of the main chip designated as a security chip, or the security chip can be integrated entirely within the main chip.
[0077] Form 2: such as Figure 2 As shown, the security chip is located in the secure element (SE) of the external SOC chip. The SE is an electronic component that is protected against physical attacks. It contains a microprocessor, storage, and encryption / decryption hardware, and can be used independently.
[0078] Form 3: such as Figure 3 As shown, the security chip is composed of a SOC chip and an external SOC chip's SE, which performs some high-security functions to ensure the high security of the device.
[0079] Security chips can take other forms than the three forms mentioned above, and this application does not limit them in this regard.
[0080] Figure 4 A schematic diagram is shown of an electronic device storing a verification value of user data.
[0081] For example, the validation value of user data can be an adder value.
[0082] Before storing user data, an electronic device increments a counter by 1 and stores the updated counter value in the security chip. When the electronic device uses user data, causing changes to the user data, the counter value is updated (e.g., incremented by 1) before storing the changed user data in the security chip. In other words, the content of the user data and the value of the counter are linked; when the user data changes, the counter value also changes accordingly.
[0083] S401, The electronic device obtains user data.
[0084] The data generated by electronic devices during operation can be referred to as user data.
[0085] For example, user data could be data such as internet data balance, prepaid card balance, or public transport card balance.
[0086] S402, The electronic device obtains the counter value one.
[0087] Before storing user data, the electronic device can obtain the counter value of one.
[0088] S403. The electronic device stores user data and counter value 1 in the non-secure chip and stores counter value 1 in the secure chip.
[0089] For example, an electronic device may store user data and counter values in a non-secure chip, which may be a flash chip.
[0090] Optionally, electronic devices can encrypt and store user data and counter values in an insecure chip.
[0091] Optionally, user data and counter values can be stored in the same area within the insecure chip, or in different areas within the insecure chip; this application does not limit this.
[0092] At the same time, the electronic device also needs to store the counter value into the security chip.
[0093] Figure 5A schematic diagram is shown of an electronic device verifying the checksum of user data.
[0094] based on Figure 4 The method shown is for storing the verification value of user data. Figure 5 A method flow for verifying the verification value of user data is shown.
[0095] S501, The electronic device obtains the counter value 2 from the non-security chip.
[0096] When an electronic device needs to use user data, it must first verify the checksum of the user data.
[0097] First, the electronic device obtains the counter value two from a non-secure chip. For example, the electronic device can obtain the counter value two from a flash chip.
[0098] Because an attacker may modify the counter value stored in the insecure chip, the counter value obtained by the electronic device from the insecure chip may be different from the previously stored counter value.
[0099] S502, The electronic device obtains the counter value three from the security chip.
[0100] Secondly, the electronic device also needs to obtain the counter value from the security chip.
[0101] Because an attacker may modify the counter value stored within the security chip, the counter value obtained by the electronic device from the security chip may be different from the previously stored counter value.
[0102] S503, are counter value two and counter value three the same?
[0103] If counter value two and counter value three are the same, then execute S504. If counter value two and counter value three are different, then execute S505.
[0104] S504. When counter value two and counter value three are the same, the electronic device uses user data.
[0105] If counter value two and counter value three are the same, it means that the attacker has not modified counter value one stored in the security chip, nor has the attacker modified counter value one stored in the non-security chip. Therefore, the electronic device can obtain and use user data.
[0106] S505, Electronic devices cannot use user data.
[0107] If counter value two and counter value three are different, it means that the attacker may have modified counter value one stored in the security chip, or the attacker may have modified counter value one stored in the non-security chip. In this case, the verification value of the user data cannot pass the verification. In order to protect the security of the user data, the electronic device cannot use the user data at this time.
[0108] But from Figure 4 and Figure 5 As can be seen from the illustrated example, if an attacker modifies the value of the counter stored in the security chip, the counter value stored in the security chip will be inconsistent with the counter value stored in the non-security chip, resulting in the verification failing and the electronic device being unable to use the user data.
[0109] Secondly, if an attacker obtains both the stored counter value from the secure chip and the counter value from the non-secure chip, and both verifications pass, then the attacker might forge user data before using it.
[0110] Figure 6 This diagram illustrates another method for storing verification values for user data.
[0111] For example, the verification value of user data can be calculated based on the user data.
[0112] Before storing user data, an electronic device calculates a checksum based on the user data and stores it in the security chip. When the electronic device uses the user data and causes changes to the user data, a new checksum is calculated based on the changed user data before storing it in the security chip. In other words, the content of the user data and the checksum are bound together; when the user data changes, the checksum also changes accordingly.
[0113] S601, The electronic device obtains user data.
[0114] S602, The electronic device obtains the verification value of the user data based on the user data.
[0115] For example, an electronic device can calculate a hash value of user data and use that hash value as a check value.
[0116] Electronic devices can also obtain the verification value of user data based on user data in other ways, and this application embodiment does not limit this.
[0117] S603, The electronic device stores the verification value of the user data in the security chip.
[0118] When an electronic device stores user data, a checksum is stored in a security chip. This checksum can be verified when the user data is used later. If the verification passes, the electronic device is allowed to use the user data.
[0119] Figure 7 This diagram illustrates another type of electronic device that verifies the verification value of user data.
[0120] based on Figure 6 The method shown is for storing the verification value of user data. Figure 7 This paper presents another method for verifying the validation value of user data.
[0121] S701, The electronic device obtains the second verification value of user data from the security chip.
[0122] When an electronic device needs to use user data, it must first verify the checksum of the user data. First, the electronic device obtains the second checksum of the user data from the security chip.
[0123] Because attackers may modify the checksum of user data stored in the security chip, the second checksum of user data obtained by the electronic device from the security chip may be different from the first checksum of the previously stored user data.
[0124] S702, Electronic devices obtain the verification value of user data based on user data.
[0125] Secondly, the electronic device also obtains the verification value three of the user data. For example, the electronic device can calculate the verification value three of the user data based on the user data stored in a non-secure chip.
[0126] Because attackers may modify user data stored in insecure chips, the checksum three calculated by the electronic device based on the user data stored in insecure chips may differ from the checksum one previously calculated based on the user data stored in insecure chips.
[0127] S703, Check if check value three and check value two are the same.
[0128] If check value 3 and check value 2 are the same, then execute S704. If check value 3 and check value 2 are different, then execute S705.
[0129] S704. If the check value three and the check value two are the same, the electronic device uses the user data.
[0130] If the third check value and the second check value are the same, it means that the attacker has not modified the check value of the user data stored in the security chip, nor has the attacker modified the user data stored in the non-security chip. Therefore, the electronic device can obtain and use the user data.
[0131] S705, Electronic devices cannot use user data.
[0132] If checksum 3 and checksum 2 are different, it means that the attacker may have modified the checksum of the user data stored in the security chip. The attacker may also have modified the user data stored in a non-security chip. In this case, the checksum of the user data cannot pass the verification. In order to protect the security of the user data, the electronic device cannot use the user data.
[0133] But from Figure 6 and Figure 7 As can be seen from the examples, if an attacker modifies the verification value of the user data stored in the security chip, the verification value of the user data stored in the security chip will be inconsistent with the verification value calculated based on the user data stored in the non-security chip, resulting in the verification failing and the electronic device being unable to use the user data.
[0134] Based on this, the present application provides a data protection method, which includes two parts: application counter, protecting user data, and using user data.
[0135] The application counter includes the following steps:
[0136] Step 1: The electronic device acquires the first user data.
[0137] Step 2: The electronic device obtains the credentials of the first counter and sets the value of the first counter to the first value.
[0138] Optionally, the electronic device can set the value of the first counter to the first value within the security chip, because the security chip has a high security level, thus preventing the leakage of the value of the first counter.
[0139] Step 3: The electronic device stores the credentials of the first counter in the secure chip and also stores the credentials of the first counter in the non-secure chip or in the cloud.
[0140] Protecting user data includes the following steps:
[0141] Step 1: The electronic device sends the first user data and the credentials of the first counter to the security chip.
[0142] Step 2: If the credentials of the first counter sent by the electronic device are the same as those of the first counter stored in the security chip, the electronic device calculates the first verification value based on the first user data and the first value of the first counter.
[0143] Step 3: The electronic device stores the first verification value in a non-secure chip or in the cloud.
[0144] Using user data includes the following steps:
[0145] Step 1: The electronic device sends the second user data, the credentials of the first counter, and the first verification value to the security chip.
[0146] Step 2: If the credentials of the first counter sent by the electronic device are the same as those of the first counter stored in the security chip, the electronic device calculates the second verification value based on the second user data and the first value of the first counter.
[0147] Step 3: If the first and second checksums are the same, the verification is successful, indicating that the first and second user data are identical, meaning the user data has not been altered, and the electronic device can use the first user data. If the first and second checksums are different, the verification fails, indicating that the first and second user data are different, suggesting that an attacker may have altered the first user data, and the electronic device cannot use the first user data.
[0148] This method enables a multi-level authentication mechanism before electronic devices can use user data. User data can only be used after authentication is passed within the security chip, thus preventing attackers from altering user data and protecting its security.
[0149] Figure 8 A schematic diagram of the structure of the electronic device 100 is shown.
[0150] Electronic device 100 may be a mobile phone, tablet computer, desktop computer, laptop computer, handheld computer, notebook computer, ultra-mobile personal computer (UMPC), netbook, as well as cellular phone, personal digital assistant (PDA), augmented reality (AR) device, virtual reality (VR) device, artificial intelligence (AI) device, wearable device, in-vehicle device, smart home device and / or smart city device. The embodiments of this application do not impose any special restrictions on the specific type of electronic device.
[0151] Electronic device 100 may include processor 110, external memory interface 120, internal memory 121, universal serial bus (USB) interface 130, charging management module 140, power management module 141, battery 142, antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, sensor module 180, button 190, motor 191, indicator 192, camera 193, display screen 194, and subscriber identification module (SIM) card interface 195, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0152] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0153] Processor 110 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.
[0154] The controller can generate operation control signals based on the instruction opcode and timing signals to complete the control of instruction fetching and execution.
[0155] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.
[0156] In some embodiments, the processor 110 may include one or more interfaces. Interfaces may include an inter-integrated circuit (I2C) interface, an inter-integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a subscriber identity module (SIM) interface, and / or a universal serial bus (USB) interface, etc.
[0157] The I2C interface is a bidirectional synchronous serial bus, including a serial data line (SDA) and a serial clock line (SCL). In some embodiments, the processor 110 may include multiple I2C buses. The processor 110 can couple to the touch sensor 180K, charger, flash, camera 193, etc., through different I2C bus interfaces. For example, the processor 110 can couple to the touch sensor 180K through the I2C interface, enabling the processor 110 and the touch sensor 180K to communicate through the I2C bus interface, thereby realizing the touch function of the electronic device 100.
[0158] The I2S interface can be used for audio communication. In some embodiments, the processor 110 may include multiple I2S buses. The processor 110 can be coupled to the audio module 170 via the I2S bus to enable communication between the processor 110 and the audio module 170. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the I2S interface to enable the function of answering phone calls through a Bluetooth headset.
[0159] The PCM interface can also be used for audio communication, sampling, quantizing, and encoding analog signals. In some embodiments, the audio module 170 and the wireless communication module 160 can be coupled via the PCM bus interface. In some embodiments, the audio module 170 can also transmit audio signals to the wireless communication module 160 via the PCM interface, enabling the function of answering phone calls through a Bluetooth headset. Both the I2S interface and the PCM interface can be used for audio communication.
[0160] The UART interface is a universal serial data bus used for asynchronous communication. This bus can be a bidirectional communication bus. It converts the data to be transmitted between serial and parallel communication. In some embodiments, the UART interface is typically used to connect the processor 110 and the wireless communication module 160. For example, the processor 110 communicates with the Bluetooth module in the wireless communication module 160 via the UART interface to implement Bluetooth functionality. In some embodiments, the audio module 170 can transmit audio signals to the wireless communication module 160 via the UART interface to enable music playback through Bluetooth headphones.
[0161] The MIPI interface can be used to connect the processor 110 to peripheral devices such as the display screen 194 and the camera 193. The MIPI interface includes a camera serial interface (CSI) and a display serial interface (DSI). In some embodiments, the processor 110 and the camera 193 communicate via the CSI interface to enable the electronic device 100 to capture images. The processor 110 and the display screen 194 communicate via the DSI interface to enable the electronic device 100 to display images.
[0162] The GPIO interface can be configured via software. It can be configured as a control signal or a data signal. In some embodiments, the GPIO interface can be used to connect the processor 110 to a camera 193, a display screen 194, a wireless communication module 160, an audio module 170, a sensor module 180, etc. The GPIO interface can also be configured as an I2C interface, an I2S interface, a UART interface, a MIPI interface, etc.
[0163] USB port 130 is a USB standard compliant interface, specifically a Mini USB port, Micro USB port, USB Type-C port, etc. USB port 130 can be used to connect a charger to charge electronic device 100, and can also be used for data transfer between electronic device 100 and peripheral devices. It can also be used to connect headphones for audio playback. This interface can also be used to connect other electronic devices, such as AR devices.
[0164] It is understood that the interface connection relationships between the modules illustrated in the embodiments of the present invention are merely illustrative and do not constitute a structural limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may also employ different interface connection methods or combinations of multiple interface connection methods as described in the above embodiments.
[0165] The charging management module 140 receives charging input from a charger. The charger can be a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 140 receives charging input from the wired charger via the USB interface 130. In some wireless charging embodiments, the charging management module 140 receives wireless charging input via the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 can also supply power to the electronic device via the power management module 141.
[0166] The power management module 141 connects the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives input from the battery 142 and / or the charging management module 140, providing power to the processor 110, internal memory 121, display screen 194, camera 193, and wireless communication module 160, etc. The power management module 141 can also monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage current, impedance). In some other embodiments, the power management module 141 may also be located within the processor 110. In other embodiments, the power management module 141 and the charging management module 140 may be located in the same device.
[0167] The wireless communication function of electronic device 100 can be realized through antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, modem processor and baseband processor, etc.
[0168] Antenna 1 and antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in electronic device 100 can be used to cover one or more communication frequency bands. Different antennas can also be multiplexed to improve antenna utilization. For example, antenna 1 can be multiplexed as a diversity antenna for a wireless local area network. In some other embodiments, the antennas can be used in conjunction with tuning switches.
[0169] The mobile communication module 150 can provide solutions for wireless communication, including 2G / 3G / 4G / 5G, applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 can receive electromagnetic waves via antenna 1, and perform filtering, amplification, and other processing on the received electromagnetic waves before transmitting them to a modem processor for demodulation. The mobile communication module 150 can also amplify the signal modulated by the modem processor and convert it into electromagnetic waves for radiation via antenna 1. In some embodiments, at least some functional modules of the mobile communication module 150 may be housed in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be housed in the same device.
[0170] The modem processor may include a modulator and a demodulator. The modulator modulates the low-frequency baseband signal to be transmitted into a mid-to-high frequency signal. The demodulator demodulates the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After processing by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs sound signals through an audio device (not limited to speaker 170A, receiver 170B, etc.) or displays images or videos through the display screen 194. In some embodiments, the modem processor may be a separate device. In other embodiments, the modem processor may be independent of the processor 110 and may be housed in the same device as the mobile communication module 150 or other functional modules.
[0171] The wireless communication module 160 can provide solutions for wireless communication applications on the electronic device 100, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), and infrared (IR) technologies. The wireless communication module 160 can be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via antenna 2, performs frequency modulation and filtering of the electromagnetic wave signals, and sends the processed signal to processor 110. The wireless communication module 160 can also receive signals to be transmitted from processor 110, perform frequency modulation and amplification, and convert them into electromagnetic waves for radiation via antenna 2.
[0172] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, enabling electronic device 100 to communicate with networks and other devices via wireless communication technology. The wireless communication technology may include Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Time Division Code Division Multiple Access (TD-SCDMA), Long Term Evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include the Global Positioning System (GPS), the Global Navigation Satellite System (GLONASS), the BeiDou Navigation Satellite System (BDS), the Quasi-Zenith Satellite System (QZSS), and / or satellite-based augmentation systems (SBAS).
[0173] Electronic device 100 implements display functions through a GPU, a display screen 194, and an application processor. The GPU is a microprocessor for image processing, connected to the display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations and for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or modify display information.
[0174] Display screen 194 is used to display images, videos, etc. Display screen 194 includes a display panel. The display panel may be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a miniature LED, a microLED, a quantum dot light-emitting diode (QLED), etc. In some embodiments, electronic device 100 may include one or N displays 194, where N is a positive integer greater than 1.
[0175] Electronic device 100 can perform shooting functions through ISP, camera 193, video codec, GPU, display 194 and application processor.
[0176] The ISP (Image Signal Processor) is used to process data fed back from the camera 193. For example, when taking a picture, the shutter is opened, and light is transmitted through the lens to the camera's photosensitive element. The light signal is converted into an electrical signal, and the camera's photosensitive element transmits the electrical signal to the ISP for processing, transforming it into an image visible to the naked eye. The ISP can also perform algorithmic optimization of image noise, brightness, and skin tone. The ISP can also optimize parameters such as exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.
[0177] Camera 193 is used to capture still images or videos. An object is projected onto a photosensitive element by generating an optical image through the lens. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, which is then passed to an ISP for conversion into a digital image signal. The ISP outputs the digital image signal to a DSP for processing. The DSP converts the digital image signal into image signals in standard RGB, YUV, or other formats. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.
[0178] Digital signal processors (DSPs) are used to process digital signals. Besides digital image signals, they can also process other digital signals. For example, when electronic device 100 selects a frequency, the DSP can perform Fourier transforms on the frequency energy.
[0179] Video codecs are used to compress or decompress digital video. Electronic device 100 may support one or more video codecs. Thus, electronic device 100 can play or record videos in various encoding formats, such as Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.
[0180] An NPU (Neural Processing Unit) is a computational processor for neural networks (NNs). By borrowing the structure of biological neural networks, such as the transmission patterns between neurons in the human brain, it can rapidly process input information and continuously learn on its own. NPUs enable intelligent cognitive applications in electronic devices, such as image recognition, facial recognition, speech recognition, and text understanding.
[0181] Internal memory 121 may include one or more random access memory (RAM) and one or more non-volatile memory (NVM).
[0182] Random access memory can include static random-access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM, for example, fifth generation DDR SDRAM is generally called DDR5 SDRAM), etc.
[0183] Non-volatile memory can include disk storage devices and flash memory.
[0184] Flash memory can be classified according to its operating principle, including NOR FLASH, NAND FLASH, 3D NAND FLASH, etc.; according to the level of the storage cell, including single-level cell (SLC), multi-level cell (MLC), triple-level cell (TLC), quad-level cell (QLC), etc.; and according to the storage specification, including universal flash storage (UFS) and embedded multimedia card (eMMC), etc.
[0185] The random access memory can be directly read and written by the processor 110. It can be used to store executable programs (such as machine instructions) of the operating system or other running programs, as well as user and application data.
[0186] Non-volatile memory can also store executable programs and user and application data, and can be pre-loaded into random access memory for direct reading and writing by the processor 110.
[0187] The external memory interface 120 can be used to connect to external non-volatile memory, thereby expanding the storage capacity of the electronic device 100. The external non-volatile memory communicates with the processor 110 through the external memory interface 120 to perform data storage functions. For example, music, video, and other files can be stored in the external non-volatile memory.
[0188] Electronic device 100 can implement audio functions, such as music playback and recording, through audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and application processor.
[0189] The audio module 170 is used to convert digital audio information into analog audio signals for output, and also to convert analog audio input into digital audio signals. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 may be located in the processor 110, or some functional modules of the audio module 170 may be located in the processor 110.
[0190] The speaker 170A, also known as a "loudspeaker," is used to convert audio electrical signals into sound signals. The electronic device 100 can listen to music or make hands-free calls through the speaker 170A.
[0191] The receiver 170B, also known as the "earpiece," is used to convert audio electrical signals into sound signals. When the electronic device 100 answers a telephone call or voice message, the receiver 170B can be brought close to the ear to listen to the voice.
[0192] Microphone 170C, also known as a "microphone" or "voice transducer," is used to convert sound signals into electrical signals. When making a phone call or sending a voice message, the user can speak by bringing their mouth close to microphone 170C, inputting the sound signal into microphone 170C. Electronic device 100 may have at least one microphone 170C. In some embodiments, electronic device 100 may have two microphones 170C, which, in addition to collecting sound signals, can also perform noise reduction. In other embodiments, electronic device 100 may also have three, four, or more microphones 170C, which can collect sound signals, reduce noise, identify the sound source, and perform directional recording, etc.
[0193] The 170D headphone jack is used to connect wired headphones. The 170D headphone jack can be a USB 130 interface or a 3.5mm Open Mobile Terminal Platform (OMTP) standard interface, a CTIA (Cellular Telecommunications Industry Association of the USA) standard interface.
[0194] Pressure sensor 180A is used to sense pressure signals and convert them into electrical signals. In some embodiments, pressure sensor 180A can be disposed on display screen 194. There are many types of pressure sensors 180A, such as resistive pressure sensors, inductive pressure sensors, and capacitive pressure sensors. A capacitive pressure sensor may include at least two parallel plates with conductive material. When force is applied to pressure sensor 180A, the capacitance between the electrodes changes. Electronic device 100 determines the pressure intensity based on the change in capacitance. When a touch operation is applied to display screen 194, electronic device 100 detects the intensity of the touch operation based on pressure sensor 180A. Electronic device 100 can also calculate the touch position based on the detection signal from pressure sensor 180A. In some embodiments, touch operations applied to the same touch position but with different touch operation intensities can correspond to different operation commands. For example, when a touch operation with an intensity less than a first pressure threshold is applied to the SMS application icon, a command to view an SMS is executed. When a touch operation with an intensity greater than or equal to the first pressure threshold is applied to the SMS application icon, a command to create a new SMS is executed.
[0195] The gyroscope sensor 180B can be used to determine the motion attitude of the electronic device 100. In some embodiments, the gyroscope sensor 180B can determine the angular velocity of the electronic device 100 about three axes (i.e., the x, y, and z axes). The gyroscope sensor 180B can be used for image stabilization. For example, when the shutter is pressed, the gyroscope sensor 180B detects the angle of the shake of the electronic device 100, calculates the distance that the lens module needs to compensate based on the angle, and allows the lens to counteract the shake of the electronic device 100 by moving in the opposite direction, thus achieving image stabilization. The gyroscope sensor 180B can also be used in navigation and motion-sensing game scenarios.
[0196] The barometric pressure sensor 180C is used to measure air pressure. In some embodiments, the electronic device 100 calculates altitude using the air pressure value measured by the barometric pressure sensor 180C to assist in positioning and navigation.
[0197] The magnetic sensor 180D includes a Hall sensor. The electronic device 100 can use the magnetic sensor 180D to detect the opening and closing of the flip cover. In some embodiments, when the electronic device 100 is a flip phone, the electronic device 100 can detect the opening and closing of the flip cover using the magnetic sensor 180D. Then, based on the detected opening and closing state of the cover or the flip cover, features such as automatic flip unlocking can be set.
[0198] The 180E accelerometer can detect the magnitude of acceleration of electronic device 100 in various directions (typically three axes). When electronic device 100 is stationary, it can detect the magnitude and direction of gravity. It can also be used to identify the posture of electronic devices and applied to applications such as screen orientation switching and pedometers.
[0199] A distance sensor 180F is used to measure distance. Electronic device 100 can measure distance via infrared or laser. In some embodiments, during a shooting scene, electronic device 100 can utilize the distance sensor 180F to measure distance for rapid focusing.
[0200] The proximity sensor 180G may include, for example, a light-emitting diode (LED) and a light detector, such as a photodiode. The LED may be an infrared LED. The electronic device 100 emits infrared light outward through the LED. The electronic device 100 uses the photodiode to detect infrared reflected light from nearby objects. When sufficient reflected light is detected, it can be determined that there is an object near the electronic device 100. When insufficient reflected light is detected, the electronic device 100 can determine that there is no object near the electronic device 100. The electronic device 100 may use the proximity sensor 180G to detect when a user holds the electronic device 100 close to their ear for a call, so as to automatically turn off the screen to save power. The proximity sensor 180G can also be used in holster mode and pocket mode for automatic unlocking and locking of the screen.
[0201] The ambient light sensor 180L is used to sense the brightness of ambient light. The electronic device 100 can adaptively adjust the brightness of the display screen 194 based on the sensed ambient light brightness. The ambient light sensor 180L can also be used to automatically adjust the white balance when taking pictures. The ambient light sensor 180L can also work with the proximity sensor 180G to detect whether the electronic device 100 is in a pocket to prevent accidental touches.
[0202] The fingerprint sensor 180H is used to collect fingerprints. The electronic device 100 can utilize the characteristics of the collected fingerprints to achieve fingerprint unlocking, accessing application locks, taking photos with fingerprints, answering calls with fingerprints, etc.
[0203] Temperature sensor 180J is used to detect temperature. In some embodiments, electronic device 100 uses the temperature detected by temperature sensor 180J to execute a temperature handling strategy. For example, when the temperature reported by temperature sensor 180J exceeds a threshold, electronic device 100 performs thermal protection by reducing the performance of a processor located near temperature sensor 180J to reduce power consumption. In other embodiments, when the temperature is below another threshold, electronic device 100 heats battery 142 to prevent abnormal shutdown of electronic device 100 due to low temperature. In still other embodiments, when the temperature is below yet another threshold, electronic device 100 boosts the output voltage of battery 142 to prevent abnormal shutdown due to low temperature.
[0204] Touch sensor 180K, also known as a "touch device," can be located on display screen 194. The touch sensor 180K and display screen 194 together form a touchscreen, also known as a "touchscreen." Touch sensor 180K detects touch operations applied to or near it. The touch sensor can transmit the detected touch operation to the application processor to determine the type of touch event. Visual output related to the touch operation can be provided through display screen 194. In other embodiments, touch sensor 180K may also be located on the surface of electronic device 100, in a different position than display screen 194.
[0205] The bone conduction sensor 180M can acquire vibration signals. In some embodiments, the bone conduction sensor 180M can acquire vibration signals from the vibrating bone segments of the human vocal cords. The bone conduction sensor 180M can also contact the human pulse to receive blood pressure signals. In some embodiments, the bone conduction sensor 180M can also be incorporated into headphones to form bone conduction headphones. The audio module 170 can parse the voice signals from the vibrating bone segments of the vocal cords acquired by the bone conduction sensor 180M to realize voice functionality. The application processor can parse heart rate information from the blood pressure signals acquired by the bone conduction sensor 180M to realize heart rate detection functionality.
[0206] Buttons 190 include a power button, volume buttons, etc. Buttons 190 can be mechanical buttons or touch-sensitive buttons. Electronic device 100 can receive button input and generate key signal inputs related to user settings and function control of electronic device 100.
[0207] Motor 191 can generate vibration alerts. Motor 191 can be used for incoming call vibration alerts or for touch vibration feedback. For example, different vibration feedback effects can correspond to touch operations performed on different applications (such as taking photos, playing audio, etc.). Motor 191 can also correspond to different vibration feedback effects for touch operations performed on different areas of the display screen 194. Different application scenarios (such as time reminders, receiving messages, alarm clocks, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also be customized.
[0208] Indicator 192 can be an indicator light, used to indicate charging status, power changes, or to indicate messages, missed calls, notifications, etc.
[0209] The SIM card interface 195 is used to connect a SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to make contact with and separate from the electronic device 100. The electronic device 100 can support one or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 simultaneously. The multiple cards can be of the same or different types. The SIM card interface 195 is also compatible with different types of SIM cards. The SIM card interface 195 is also compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to realize functions such as calls and data communication. In some embodiments, the electronic device 100 uses an eSIM, i.e., an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.
[0210] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This embodiment of the invention uses the layered architecture Android system as an example to exemplify the software structure of electronic device 100. The system of electronic device 100 can also be iOS, HarmonyOS, etc., and this application embodiment does not limit this. Different types of electronic devices 100 may have different systems; this application embodiment uses Android as an example for illustration.
[0211] A layered architecture divides software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into four layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, and the kernel layer. This application does not limit the layering of the software structure of electronic devices. (See also...) Figure 9 In this embodiment of the application, the Android runtime, system libraries, and kernel layer can be considered as a single layer, referred to as the system layer. It should be understood that... Figure 9 It adds a hardware layer to electronic devices on top of the Android system.
[0212] It should be understood that Figure 9 The modules included in each layer shown are those involved in the embodiments of this application. The modules included in each layer below do not constitute a limitation on the structure of the electronic device or the hierarchical deployment of modules (example illustration). For example, an identity authentication information registration module can be deployed in the application layer or the application framework layer. In one embodiment, Figure 9 The modules shown can be deployed individually, or several modules can be deployed together. Figure 9 The module division in the text is one example. In one embodiment, Figure 9 The names of the modules shown are for illustrative purposes only.
[0213] The application layer can include a series of application packages.
[0214] like Figure 9 As shown, the application package may include applications such as camera, gallery, calendar, call, map, navigation, WLAN, Bluetooth, and SMS.
[0215] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.
[0216] like Figure 9 As shown, the application framework layer may include a window manager, content provider, phone manager, resource manager, rollback prevention service module, etc.
[0217] The window manager is used to manage window applications. It can obtain the screen size, determine if a status bar is present, lock the screen, capture screenshots, and verify authentication information, among other things.
[0218] Content providers store and retrieve data, making that data accessible to applications. This data may include videos, images, audio, made and received phone calls, browsing history and bookmarks, phone books, etc.
[0219] The phone manager is used to provide communication functions for electronic device 100. For example, it manages call status (including connection and disconnection).
[0220] The file explorer provides applications with various resources, such as localized strings, icons, images, layout files, video files, and more.
[0221] The rollback prevention service module primarily serves as the medium for message transmission between the application and the security chip. Specifically, before the application saves user data, when the application requests a counter, the rollback prevention service module allocates an idle counter to the application, obtains the counter's identifier, and sends the counter's identifier to the security chip.
[0222] Before the application saves user data, the anti-rollback service module sends a counter identifier to the security chip, allowing the security chip to modify and save the counter value. When the electronic device needs to use the user data, it can obtain a verification value for the user data based on the counter value. Only if the verification passes can the electronic device use the user data.
[0223] Optionally, after the user data changes, the corresponding counter value will also change, and the verification value of the changed user data will also change.
[0224] Before an electronic device uses user data, the rollback prevention service module sends a verification value of the user data to the security chip. The security chip then calculates another verification value based on the user data sent by the rollback prevention service module and the counter value. If this verification value matches the previously stored verification value, the verification passes, and the electronic device can use the application data. If the verification value differs from the previously stored verification value, the verification fails, and the user data sent by the rollback prevention service module to the security chip differs from the previously stored user data, suggesting that an attacker may have modified the user data. In this case, the electronic device cannot use the application data.
[0225] Because the Android runtime, system libraries, and kernel layer are considered as one layer in this embodiment, the system layer may include the Android runtime, system libraries, and functional modules in the kernel layer.
[0226] The system layer may include security chips, and the number of security chips may be one or more.
[0227] The security chip is used to store the counter value, the user data verification value, the counter credentials, etc., and performs multi-level authentication based on the counter value, the user data verification value, the counter credentials, etc., to ensure the security of user data.
[0228] For a description of the rollback service module function and the security chip function, please refer to the description in the following embodiments.
[0229] Figure 10 This is a schematic flowchart illustrating a method for generating a counter's credentials, provided in an embodiment of this application.
[0230] Before obtaining the specific value of the counter, the security chip verifies whether the counter credentials stored in the security chip are the same as the received counter credentials. Only if they are the same can the security chip obtain the specific value of the counter.
[0231] Alternatively, the security chip encrypts the counter's value based on its credential, obtaining an encrypted counter value. Before obtaining the actual counter value, the security chip receives the counter's credential. If the security chip can decrypt the encrypted counter value based on the received credential, then it can obtain the actual counter value.
[0232] S1001, The first application obtains the counter's credentials.
[0233] Before the first application saves user data, the first application obtains the counter's credentials. The counter can have one or more credentials.
[0234] Different counters may have different counter credentials, or multiple counters may share the same counter credential. This application does not limit this.
[0235] Optionally, the first application may store the counter's credentials in a non-secure chip, such as a flash chip. Alternatively, the first application may store the counter's credentials in a server. This application does not limit the scope of this embodiment.
[0236] The first application can obtain the counter's credentials through any of the following methods.
[0237] Method 1: The first application obtains the counter's credentials from the server.
[0238] Method 2: The first application obtains the counter's credentials locally from the electronic device.
[0239] Method 3: Before the first application needs to obtain the counter's credentials, the electronic device can prompt the user to enter credentials, which can be used as the counter's credentials.
[0240] The first application can also obtain the counter's credentials through other means, which is not limited in this application embodiment.
[0241] S1002, The first application sends the counter's credentials to the rollback prevention service module.
[0242] S1003, the anti-rollback service module allocates a first counter to the first application and obtains the identifier of the first counter.
[0243] Optionally, the electronic device has multiple different counters pre-installed. After the anti-rollback service module receives the counter credentials sent by the first application, the anti-rollback service module can randomly allocate one of the multiple idle counters as the first counter.
[0244] Optionally, the rollback prevention service module can also allocate multiple counters to the first application simultaneously. For example, the rollback prevention service module can determine the number of counters to allocate to the first application based on the number of credentials for each counter. For instance, if there are credentials for one counter, the rollback prevention service module can allocate one counter to the first application; if there are credentials for three counters, the rollback prevention service module can allocate three different counters to the first application.
[0245] Optionally, the first application may send the number of counters to be allocated along with the counter credentials to the rollback prevention service module. The rollback prevention service module can determine the number of counters to allocate for the first application based on the number of counters to be allocated sent by the first application. For example, if the first application sends one counter to the rollback prevention service module, the rollback prevention service module can allocate one counter for the first application. If the first application sends three counters to the rollback prevention service module, the rollback prevention service module can allocate three counters for the first application. In one possible implementation, the number of counter credentials sent by the first application to the rollback prevention service module is the same as the number of counters to be allocated. For example, if the first application sends one counter to the rollback prevention service module, the number of counter credentials sent by the first application to the rollback prevention service module is also one. If the first application sends three counters to the rollback prevention service module, the number of counter credentials sent by the first application to the rollback prevention service module is also three. In other possible implementations, the number of counter credentials sent by the first application to the anti-rollback service module and the number of counters to be allocated can be different. For example, if the first application sends one counter to the anti-rollback service module, then the number of counter credentials sent by the first application to the anti-rollback service module can be one. If the first application sends three counters to the anti-rollback service module, and the number of counter credentials sent by the first application to the anti-rollback service module is also two, then one counter uses one counter's credentials, and two counters share the credentials of the other counter.
[0246] The rollback prevention service module also needs to record the correspondence between the first application and the first counter. Because the rollback prevention service module can assign counters to multiple different applications, it needs to record the correspondence between each application and each counter.
[0247] Table 1
[0248] First Application First counter Second Application Second counter, third counter Third Application Fourth counter
[0249] Table 1 shows the betting relationships between various applications and counters recorded in the anti-rollback service module. For example, the first application corresponds to the first counter, the second application corresponds to the second and third counters, and the third application corresponds to the fourth counter.
[0250] It should be noted that the anti-rollback service module can also record more or fewer correspondences between applications and counters, and this application embodiment does not limit this.
[0251] Optionally, if the application has not used the counter for a certain period of time (e.g., within one month), the anti-rollback service module can remove the binding relationship between the application and the counter so that the counter can be used by other applications.
[0252] Optionally, after the application is uninstalled, the anti-rollback service module can remove the binding relationship between the application and the counter so that the counter can be used by other applications.
[0253] S1004, the anti-rollback service module sends the identifier of the first counter and the counter's credentials to the security chip.
[0254] After the rollback prevention service module assigns the first counter to the first application, it sends the identifier and credentials of the first counter to the security chip.
[0255] S1005, The security chip sets the initial value of the first counter to the first threshold.
[0256] The initial value of the counter is used to generate count values for different user data when saving different user data.
[0257] Optionally, the first threshold can be randomly generated, meaning the initial value is different for different counters.
[0258] Optionally, the first threshold can also be preset, and the initial value of different counters is the same.
[0259] S1006. The security chip stores the initial value of the first counter and the counter's credentials, and uses the counter's credentials as the credentials of the first counter.
[0260] The security chip stores the initial value and the counter's credentials. This allows it to generate a count value for the user data based on the initial value when saving user data, and then generate a verification value for that user data based on the count value. The counter's credentials are used by the security chip to verify whether the verification value of the user data matches the received counter credentials before it is obtained. If they match, the security chip is allowed to obtain the verification value of the user data; otherwise, it cannot obtain the verification value.
[0261] Table 2
[0262]
[0263] Table 2 shows the initial values and credentials of counters corresponding to different applications stored within a security chip. For example, the first application corresponds to a first counter, the initial value of which is a first threshold, and the credential for the first counter is a first token. The second application corresponds to a second counter and a third counter, the initial value of which is a second threshold, the initial value of which is a third threshold, the credential for which is a second token, and the credential for which is a third token. The third application corresponds to a fourth counter, the initial value of which is a fourth threshold, and the credential for which is a fourth token.
[0264] Optionally, the first threshold, the second threshold, the third threshold, and the fourth threshold are randomly generated. Therefore, the first threshold, the second threshold, the third threshold, and the fourth threshold can be different from each other, or they can be partially the same or all the same. This application does not limit this.
[0265] Optionally, the second token and the third token can be different or the same, and this application embodiment does not limit this.
[0266] Optionally, the first token, the second token, the third token, and the fourth token can be different from each other, partially the same, or all the same. This application embodiment does not limit this.
[0267] Table 3
[0268] First counter First threshold First token Second counter Second threshold Second token Third counter Third threshold Third token Fourth counter Fourth threshold Fourth token
[0269] Table 3 shows the initial values and credentials of counters stored within another type of security chip. Since the anti-rollback service module stores identifiers for counters corresponding to different applications, the security chip does not need to store these identifiers. Instead, it can store only the initial values and credentials of the different counters. For example, the initial value of the first counter is the first threshold, and its credential is the first token. The initial value of the second counter is the second threshold, and its credential is the second token. The initial value of the third counter is the third threshold, and its credential is the third token. The initial value of the fourth counter is the fourth threshold, and its credential is the fourth token.
[0270] Optionally, the first token, the second token, the third token, and the fourth token can be different from each other, partially the same, or all the same. This application embodiment does not limit this.
[0271] S1007, The security chip sends a message to the anti-rollback service module that the counter has been set.
[0272] S1008, the anti-rollback service module sends a message to the first application that the counter has been set.
[0273] Figure 11 A flowchart illustrating another method for generating counter credentials is shown.
[0274] Figure 11 This embodiment is a schematic flowchart of a method for generating a counter credential using a security chip. Figure 10 The embodiment is a schematic flowchart of a method for generating a counter credential in the first application. The security chip has a high security level; therefore, credentials generated within the security chip have even higher security.
[0275] S1101, The first application sends a request to the anti-rollback service module to apply for a counter.
[0276] Optionally, the first application can start sending a request to the anti-rollback service module to apply for a counter after downloading, but before saving user data.
[0277] S1102, the anti-rollback service module allocates a first counter to the first application and obtains the identifier of the first counter.
[0278] For a description of S1102, please refer to... Figure 11 The description of S1003 in the embodiments will not be repeated here.
[0279] S1103, The rollback prevention service module sends the identifier of the first counter to the security chip.
[0280] S1104, The security chip obtains the credentials of the first counter.
[0281] The security chip can obtain the credentials of the first counter in any of the following ways.
[0282] Method 1: The security chip obtains the credentials for the first counter from the server.
[0283] Method 2: The security chip obtains the credentials of the first counter from the local storage of the electronic device.
[0284] Method 3: Before the security chip needs to obtain the credentials for the first counter, the electronic device can prompt the user to enter credentials, which can be used as credentials for the first counter.
[0285] The security chip can also obtain the credentials of the first counter through other means, which is not limited in this application embodiment.
[0286] S1105, The security chip sets the initial value of the first counter to the first threshold.
[0287] The initial value of the counter is used to generate count values for different user data when saving different user data.
[0288] Optionally, the first threshold can be randomly generated, meaning the initial value is different for different counters.
[0289] Optionally, the first threshold can also be preset, and the initial value of different counters is the same.
[0290] Optionally, S1105 can be executed before S1104, and S1105 and S1104 can be executed simultaneously. This application embodiment does not limit this.
[0291] S1106. The security chip stores the initial value of the first counter and the credentials of the first counter.
[0292] For a description of S1106, please refer to... Figure 11 The description of S1006 in the embodiments will not be repeated here.
[0293] S1107, The security chip sends the credentials of the first counter to the rollback prevention service module.
[0294] S1108, the anti-rollback service module sends the credentials of the first counter to the first application.
[0295] Table 4
[0296]
[0297]
[0298] Table 4 shows one or more counter credentials corresponding to one or more applications stored in the insecure chip of an electronic device or in a server. For example, the first application corresponds to a first counter, and the credential for the first counter is a first token. The second application corresponds to a second counter and a third counter, with the credential for the second counter being a second token and the credential for the third counter being a third token. The third application corresponds to a fourth counter, with the credential for the fourth counter being a fourth token.
[0299] Optionally, the second token and the third token can be different or the same, and this application embodiment does not limit this.
[0300] Optionally, the first token, the second token, the third token, and the fourth token can be different from each other, partially the same, or all the same. This application embodiment does not limit this.
[0301] In this way, the first application can obtain the credentials of the first counter, so that before the electronic device uses the user data in the first application, it can send the credentials of the first counter to the security chip. Only if the credentials of the first counter stored in the security chip are the same as the credentials of the first counter sent by the first application, can the electronic device use the user data in the first application.
[0302] Optionally, the first application may store the credentials of the first counter in a non-secure chip, such as a flash chip. Alternatively, the first application may store the credentials of the first counter in a server. This application does not limit the scope of this embodiment.
[0303] Figure 12 This is a schematic diagram illustrating how to protect user data and generate a verification value for user data, as provided in an embodiment of this application.
[0304] When user data changes, the counter value in the SE (Security Controller) will also change when the electronic device stores the changed user data. Therefore, the checksum of the changed user data will also change accordingly.
[0305] S1201, The first application obtains the first user data.
[0306] For example, the first user data could be the remaining amount of internet data, such as 30GB of remaining internet data.
[0307] S1202, The first application sends the credentials of the first user data and the first counter to the rollback prevention service module.
[0308] In other words, before saving the first user data, the first application will select one or more counters from the previously requested counters to generate credentials for the first user data. For example, the first application can select the first counter from the previously requested counters.
[0309] The electronic device's insecure chip or the server stores credentials for one or more counters that the first application previously requested. The first application can select the credentials for the first counter from the credentials of the one or more counters so that a verification value for the first user data can be generated.
[0310] After obtaining the credentials for the first counter, the first application sends the first user data and the credentials for the first counter to the rollback prevention service module.
[0311] S1203, The rollback prevention service module obtains the identifier of the first counter.
[0312] After receiving the first user data and the credentials of the first counter sent by the first application, the rollback prevention service module obtains the identifier of the first counter.
[0313] S1204, the anti-rollback service module sends the identifier of the first counter, the first user data, and the credentials of the first counter to the security chip.
[0314] S1205, The security chip determines the credentials of the first counter stored in the security chip based on the identifier of the first counter.
[0315] As shown in Tables 2 and 3, the security chip stores credentials for multiple counters.
[0316] After the security chip receives the identifier of the first counter, the first user data, and the credentials of the first counter sent by the anti-rollback service module, the security chip can obtain the credentials of the first counter from within the security chip based on the identifier of the first counter.
[0317] S1206. If the security chip determines that the credentials of the first counter sent by the anti-rollback service module are the same as those of the first counter stored in the security chip, the security chip obtains the initial value of the first counter.
[0318] The security chip can only obtain the initial value of the first counter if the credentials of the first counter sent by the security chip and the first counter sent by the anti-rollback service module are the same. In this way, an attacker cannot obtain the initial value of the first counter without knowing the credentials of the first counter.
[0319] S1207. Add a first preset value to the initial value of the first counter, and the security chip obtains the first value of the first counter.
[0320] The first preset value can be a fixed value or a random number; this application embodiment does not limit this.
[0321] S1208, the security chip calculates the first verification value based on the first value of the first counter and the first user data.
[0322] In one possible implementation, the security chip can calculate a first value of a first counter and an HMAC value of the first user data, and use the HMAC value as a first check value.
[0323] Optionally, the security chip may also calculate a first verification value based on other factors, the first value of the first counter, and the first user data. These other factors include, but are not limited to, one or more of the following: a hardware unique key and a device unique ID.
[0324] In this way, the first checksum is calculated based on the value of the first counter and the first user data. Before the electronic device can use the first user data, it must pass the first checksum verification. If either the value of the first counter or any data in the first user data changes, the first checksum verification will fail, and the electronic device will be unable to use the first user data. This prevents attackers from tampering with the first user data, thus improving the security of the electronic device's use of the first user data.
[0325] Optionally, S1207 and S1208 can also be replaced with S1207B as follows.
[0326] S1207B: The security chip calculates the first verification value based on the initial value of the first counter and the first user data.
[0327] Optionally, the security chip may also calculate the first verification value based on other factors, the initial value of the first counter, and the first user data. These other factors include, but are not limited to, one or more of the following: a hardware unique key and a device unique ID.
[0328] S1209, The security chip sends the first verification value to the anti-rollback service module.
[0329] S1210, the anti-rollback service module sends the first verification value to the first application.
[0330] Optionally, the first application may store the first verification value in a non-secure chip, such as a flash chip. Alternatively, the first application may store the first verification value in a server. This application does not limit the scope of the embodiments.
[0331] Table 5
[0332]
[0333] Table 5 provides an example of the verification values corresponding to different user data. For instance, in the first application, there is first user data and third user data. The verification value for the first user data is the first verification value, and the verification value for the third user data is the third verification value. The first user data and the third user data are different.
[0334] Optionally, the first check value, the second check value, and the third check value can be completely different, partially the same, or all the same. This application does not limit this.
[0335] Optionally, in some embodiments, the verification value corresponding to the first user data will also change after the first user data changes.
[0336] Optionally, before an electronic device uses the first user data, the correctness of the checksum of the first user data must be verified in the security chip. Only after the checksum of the first user data passes verification can the electronic device use the first user data. This prevents attackers from forging user data.
[0337] Figure 13 A schematic diagram illustrates a method for verifying the correctness of a checksum value of first user data in a security chip before the electronic device uses the first user data.
[0338] S1301, The first application sends the second user data, the credentials of the first counter, and the first verification value to the rollback prevention service module.
[0339] Before the first application needs to use the first user data that was saved previously, it must first verify the correctness of the verification value of the first user data.
[0340] In some embodiments, an attacker may modify previously saved first user data. For example, the first user data may be remaining internet data, such as 30GB of remaining internet data. To increase the remaining internet data, an attacker may modify it to 100GB; this 100GB remaining internet data can be referred to as second user data.
[0341] Optionally, the credentials and the first verification value of the first counter can be obtained by the first application from the local machine or from the server. This application embodiment does not limit this.
[0342] S1302, The rollback prevention service module obtains the identifier of the first counter.
[0343] After receiving the second user data, the credentials of the first counter, and the first verification value sent by the first application, the anti-rollback service module obtains the identifier of the first counter.
[0344] S1303, the anti-rollback service module sends the identifier of the first counter, the second user data, the credentials of the first counter, and the first verification value to the security chip.
[0345] S1304, The security chip determines the credentials of the first counter stored in the security chip based on the identifier of the first counter.
[0346] As shown in Tables 2 and 3, the security chip stores credentials for multiple counters.
[0347] After the security chip receives the identifier of the first counter, the first user data, and the credentials of the first counter sent by the anti-rollback service module, the security chip can obtain the credentials of the first counter from within the security chip based on the identifier of the first counter.
[0348] S1305. If it is determined that the credentials of the first counter are the same as those of the first counter stored in the security chip, the security chip obtains the first value of the first counter.
[0349] The security chip can only obtain the first value of the first counter if the credentials of the first counter sent by the security chip and the first counter sent by the anti-rollback service module are the same. In this way, without knowing the credentials of the first counter, the attacker cannot obtain the first value of the first counter, nor can the attacker tamper with the value of the first counter, thus ensuring the accuracy of the counter values stored in the security chip.
[0350] S1306, the security chip calculates the second verification value based on the first value of the first counter and the second user data.
[0351] In one possible implementation, the security chip can calculate a first value of a counter and an HMAC value of the second user data, and use the HMAC value as the first check value.
[0352] Optionally, the security chip can also calculate a second verification value based on other factors, the first value of the first counter, and the second user data. These other factors include, but are not limited to, one or more of the following: a hardware unique key and a device unique ID.
[0353] It should be noted that the algorithms and parameter types for calculating the first and second check values are the same.
[0354] S1307. If the first check value and the second check value are the same, the security chip can confirm that the second user data is the same as the first user data.
[0355] If the first checksum and the second checksum are the same, it means that the second user data is the same as the first user data, that is, no attacker has changed the first user data stored in the insecure chip.
[0356] If an attacker modifies the first user data and obtains the second user data, and the first user data is different from the second user data, then the second check value calculated by the security chip based on the second user data and the first value of the first counter is different from the first check value previously stored in the security chip.
[0357] For example, the first checksum can be a first HMAC value obtained based on a first value of a first counter and first user data. The second checksum can be a second HMAC value obtained based on the first value of the first counter and second user data. If the first HMAC value and the second HMAC value are the same, the security chip can confirm that the second user data is the same as the first user data.
[0358] If an attacker modifies the first user data and obtains the second user data, and the first user data is different from the second user data, then the HMAC value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first HMAC value previously stored in the security chip.
[0359] If the security chip can confirm that the second user data is identical to the first user data, it means that the attacker has not altered the first user data stored in the non-security chip. Therefore, the first application uses the second user data.
[0360] S1308, the security chip sends a verification pass message to the anti-rollback service module.
[0361] S1309, The rollback prevention service module sends a verification pass message to the first application.
[0362] S1310, In response to the verification pass message, the first application uses the second user data.
[0363] If the second user data is confirmed to be identical to the first user data, the security chip sends a verification pass message to the first application. In response to the verification pass message, the first application can use the second user data.
[0364] If the security chip determines that the second user data differs from the first user data, it will not send a verification pass message to the first application. Therefore, without receiving a verification pass message, the first application cannot use the second user data.
[0365] Optionally, in some embodiments, if the second user data changes after the electronic device uses it, the electronic device also needs to save the changed second user data. When saving the changed second user data, the counter value corresponding to the changed second user data stored in the security chip will change. The security chip will calculate a third checksum based on the changed second user data and the corresponding counter value, and save the third checksum within the security chip. Simultaneously, the third checksum also needs to be saved in a non-security chip or on a server.
[0366] Depend on Figure 13 As can be seen from the examples, the first application can only use the second user data if the second user data is the same as the first user data, so the second user data is the first user data.
[0367] For example, the first user data and the second user data can be the remaining amount of internet data, such as 30GB. After the user uses the second user data, the second user data changes, for example, the changed second user data becomes 10GB. The electronic device needs to save the changed second user data.
[0368] Figure 14 This is a schematic diagram illustrating a method for saving changed second user data, as provided in an embodiment of this application.
[0369] S1401, Obtain the changed second user data.
[0370] In some embodiments, the modified second user data may also be referred to as third user data.
[0371] S1402, The first application sends the changed second user data and the credentials of the first counter to the rollback prevention service module.
[0372] In the first application, the credential of the first counter is used when saving the first user data. Therefore, the credential of the first counter can also be used when saving the changed second user data. In other embodiments, credentials of other counters can also be used when saving the changed second user data, and this application embodiment does not limit this. This application embodiment takes the continued use of the credential of the first counter when saving the changed second user data as an example for illustration.
[0373] S1403, The rollback prevention service module obtains the identifier of the first counter.
[0374] After receiving the changed second user data and the credentials of the first counter, the rollback prevention service module obtains the identifier of the first counter.
[0375] S1404, the rollback prevention service module sends the identifier of the first counter, the changed second user data, and the credentials of the first counter to the security chip.
[0376] S1405, The security chip determines the credentials of the first counter stored in the security chip based on the identifier of the first counter.
[0377] As shown in Tables 2 and 3, the security chip stores credentials for multiple counters.
[0378] After the security chip receives the identifier of the first counter, the changed second user data, and the credentials of the first counter sent by the anti-rollback service module, the security chip can obtain the credentials of the first counter from within the security chip based on the identifier of the first counter.
[0379] S1406, The security chip determines that the credentials of the first counter are the same as those of the first counter stored in the security chip, and obtains the first value of the first counter.
[0380] The security chip can only obtain the first value of the first counter if the credentials of the first counter sent by the security chip and the first counter sent by the anti-rollback service module are the same. This prevents an attacker from obtaining the first value of the first counter without knowing its credentials, and also prevents the attacker from modifying the value of the first counter. This ensures the accuracy of the counter values stored in the security chip.
[0381] S1407. Add a second preset value to the first value of the first counter, and the security chip obtains the second value of the first counter.
[0382] The second preset value can be a fixed value or a random number; this application embodiment does not limit this.
[0383] The second preset value can be the same as the first preset value, or it can be different from the first preset value. This application does not limit this.
[0384] S1408, the security chip calculates the third verification value based on the second value of the first counter and the changed second user data.
[0385] In one possible implementation, the security chip can calculate a second value of a counter and the HMAC value of the changed second user data, and use the HMAC value as a third check value.
[0386] Optionally, the security chip can also calculate a third verification value based on other factors, the second value of the first counter, and the changed second user data. These other factors include, but are not limited to, one or more of the following: a hardware unique key and a device unique ID.
[0387] S1409, The security chip sends a third verification value to the rollback prevention service module.
[0388] S1410, The rollback prevention service module sends the third verification value to the first application.
[0389] Optionally, the first application may store the third verification value in a non-secure chip, such as a flash chip. Alternatively, the first application may store the third verification value in a server. This application does not limit the scope of this embodiment.
[0390] Figure 15 This is a flowchart illustrating a data protection method provided in an embodiment of this application.
[0391] S1501, The electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the non-secure chip.
[0392] The first user data refers to the user data previously stored in the electronic device. The second user data is the user data that the electronic device reads from the previously stored first user data. The first user data is stored in a first storage location. Therefore, the second user data can be read from the first storage location.
[0393] If the first checksum and the second checksum are different, it indicates that the attacker may have modified the first user data, for example, by changing the first user data to the second user data, in which case the first user data and the second user data are different. The first user data and the second user data can be stored in the same location.
[0394] If the first check value and the second check value are the same, it means that the second user data is the same as the first user data, and the electronic device uses the second user data, that is, the electronic device uses the first user data.
[0395] S1502, The electronic device obtains the credentials for the first counter from the security chip.
[0396] In one possible implementation, the electronic device stores the credentials of the first counter within a security chip. Specifically, this includes: the electronic device generating the credentials of the first counter through the security chip; and the electronic device storing the credentials of the first counter within the security chip. In this case, the security chip needs to store the credentials of the first counter in a non-security chip or on a server, so that when the electronic device uses the user data, authentication can be performed based on the credentials of the first counter stored in the non-security chip or on the server.
[0397] or,
[0398] The electronic device obtains the credentials of the first counter outside the security chip; the electronic device stores the credentials of the first counter inside the security chip.
[0399] S1503. If the credentials of the first counter in the non-security chip and the credentials of the first counter in the security chip are the same, the electronic device obtains the first value of the first counter through the security chip.
[0400] The non-security chip can be a flash chip, a server, or a storage device such as a hard drive; this application does not limit this.
[0401] In one possible implementation, the method further includes: if the credentials for the first counter in the non-secure chip and the credentials for the first counter in the secure chip are different, the electronic device cannot obtain the first value of the first counter from the secure chip. Thus, if an attacker does not know the credentials for the first counter, the credentials for the first counter cannot pass authentication, and the attacker cannot obtain the first value of the first counter, ensuring the security of the first value of the first counter stored in the secure chip.
[0402] In conjunction with the first aspect, one possible implementation also includes: if the first check value and the second check value are different, the electronic device cannot use the second user data.
[0403] Optionally, the security chip can also calculate the verification value of user data based on other factors, including but not limited to one or more of the hardware unique key and device unique ID. Other factors can also be other values, and this application embodiment does not limit them.
[0404] In this way, even if an attacker forges user data, for example, by modifying the first user data into the second user data, the second verification value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first verification value. That is, the verification value of the user data will fail the verification, and the electronic device will not be able to use the forged second user data.
[0405] In one possible implementation, the first value of the first counter is obtained based on its initial value and a first preset value, wherein the initial value of the counter is randomly generated. This random generation of the initial value of the first counter prevents attackers from obtaining its first value through brute-force enumeration, thus avoiding the leakage of the first value of the first counter stored in the security chip and improving the security of the first value of the first counter stored within the security chip.
[0406] In one possible implementation, before the electronic device stores the first value of the first counter in the security chip, the method further includes: the electronic device generating an initial value for the first counter via the security chip. In this way, the initial value of the first counter is generated within the security chip, improving the security of the counter value stored within the security chip.
[0407] S1504. The electronic device obtains a second verification value of the second user data based on the second user data and the first value of the first counter through the security chip; if the first verification value and the second verification value are the same, the electronic device uses the second user data.
[0408] Secure chips and non-secure chips can communicate via I2C or SPI bus to exchange data.
[0409] This implements a multi-level authentication mechanism within the security chip. Only after successful authentication can the electronic device use the second user data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0410] In one possible implementation, before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the insecure chip, the method further includes: the electronic device storing the first user data, the first verification value of the first user data, and the credentials of the first counter in the insecure chip. The electronic device then stores the first value of the first counter and the credentials of the first counter in the secure chip.
[0411] In this way, the electronic device stores the first value of the first counter in the security chip, ensuring the security of the first value of the first counter and preventing attackers from obtaining the first value of the first counter.
[0412] The electronic device stores the credentials of the first counter in a security chip so that when the electronic device uses the stored user data, it can perform authentication based on the credentials of the first counter. Only when the authentication is successful can the electronic device use the stored user data, thus ensuring the security of the user data stored on the electronic device.
[0413] In one possible implementation, before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the non-secure chip, the method further includes: the electronic device obtaining the first user data, the identifier of the first counter, and the credentials of the first counter stored in the non-secure chip from the non-secure chip; the electronic device determining the credentials of the first counter stored in the secure chip based on the identifier of the first counter using the secure chip; if the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device obtaining the first value of the first counter; the electronic device obtaining the first verification value of the first user data based on the first value of the first counter and the first user data using the secure chip; and the electronic device storing the first verification value of the first user data in the non-secure chip. Thus, when the electronic device stores the first user data, a first verification value is generated in the secure chip based on the first user data and the first value of the first counter. After generating the first verification value, the electronic device stores the first verification value in the non-secure chip, such as in a flash chip or on a server. In this way, even if an attacker forges user data, for example, by using second user data to replace the first user data, during authentication, the second verification value generated in the security chip based on the second user data and the first value of the first counter will be different from the first verification value, causing the verification to fail and preventing the attacker from forging user data.
[0414] In one possible implementation, after the electronic device uses the second user data, the method further includes: the electronic device acquiring third user data, which is a modified version of the second user data; the electronic device sending the third user data, the credentials of the first counter in the non-secure chip, and the identifier of the first counter to the secure chip; the electronic device acquiring the credentials of the first counter based on the identifier of the first counter through the secure chip; if the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device acquiring the first value of the first counter through the secure chip, and obtaining the second value of the first counter based on the first value and a second preset value; the electronic device obtaining the third verification value of the third user data based on the third user data and the second value of the first counter through the secure chip; and the electronic device storing the third verification value of the third user data in the non-secure chip.
[0415] In other words, after the second user data is authenticated, the electronic device uses the second user data, causing it to change and resulting in third user data. The electronic device needs to store this third user data. When storing the third user data, the electronic device must generate a verification value for the third user data within the security chip, i.e., a third verification value. This is so that when the electronic device uses the third user data later, it can verify whether the third user data is forged based on the verification value.
[0416] This application also provides an electronic device, comprising: one or more processors, one or more memories, and a display screen; the one or more memories and the display screen are coupled to the one or more processors, the one or more memories being used to store computer program code, the computer program code including computer instructions, and the one or more processors calling the computer instructions to cause the electronic device to execute: obtaining second user data, a credential of a first counter, and a first verification value of the first user data from a non-secure chip; wherein, the credential of the first counter in the non-secure chip is used to obtain a first value of the first counter, and the first verification value and the first value of the first counter are used to verify whether the second user data is the same as the first user data; obtaining a credential of the first counter from a secure chip; if the credential of the first counter in the non-secure chip and the credential of the first counter in the secure chip are the same, obtaining the first value of the first counter through the secure chip; obtaining a second verification value of the second user data through the secure chip based on the second user data and the first value of the first counter; and using the second user data if the first verification value and the second verification value are the same.
[0417] The non-security chip can be a flash chip, a server, or a storage device such as a hard drive; this application does not limit this.
[0418] The first user data refers to the user data previously stored in the electronic device. The second user data is the user data that the electronic device reads from the previously stored first user data. The first user data is stored in a first storage location. Therefore, the second user data can be read from the first storage location.
[0419] If the first checksum and the second checksum are different, it indicates that the attacker may have modified the first user data, for example, by changing the first user data to the second user data, in which case the first user data and the second user data are different. The first user data and the second user data can be stored in the same location.
[0420] If the first check value and the second check value are the same, it means that the second user data is the same as the first user data, and the electronic device uses the second user data, that is, the electronic device uses the first user data.
[0421] This implements a multi-level authentication mechanism within the security chip. Only after successful authentication can the electronic device use the second user data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0422] In one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: if the credentials for the first counter in the non-secure chip and the credentials for the first counter in the secure chip are different, the first value of the first counter cannot be obtained from the secure chip. Thus, if an attacker does not know the credentials for the first counter, the credentials for the first counter cannot pass authentication, and the attacker cannot obtain the first value of the first counter, ensuring the security of the first value of the first counter stored in the secure chip.
[0423] In one possible implementation, one or more processors call computer instructions to cause the electronic device to execute: if the first checksum and the second checksum are different, the second user data cannot be used.
[0424] Optionally, the security chip can also calculate the verification value of user data based on other factors, including but not limited to one or more of the hardware unique key and device unique ID. Other factors can also be other values, and this application embodiment does not limit them.
[0425] In this way, even if an attacker forges user data, for example, by modifying the first user data into the second user data, the second verification value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first verification value. That is, the verification value of the user data will fail the verification, and the electronic device will not be able to use the forged second user data.
[0426] In one possible implementation, one or more processors invoke computer instructions to cause the electronic device to: store first user data, a first checksum of the first user data, and a credential of a first counter in a non-secure chip; and store a first value of the first counter and a credential of the first counter in a secure chip.
[0427] In this way, the electronic device stores the first value of the first counter in the security chip, ensuring the security of the first value of the first counter and preventing attackers from obtaining the first value of the first counter.
[0428] The electronic device stores the credentials of the first counter in a security chip so that when the electronic device uses the stored user data, it can perform authentication based on the credentials of the first counter. Only when the authentication is successful can the electronic device use the stored user data, thus ensuring the security of the user data stored on the electronic device.
[0429] In one possible implementation, one or more processors invoke computer instructions to cause the electronic device to: generate a credential for a first counter via a security chip; and store the credential for the first counter within the security chip. In this case, the security chip needs to store the credential for the first counter in a non-security chip or on a server, so that when the electronic device uses the user data, authentication can be performed based on the credential for the first counter stored in the non-security chip or on the server.
[0430] or,
[0431] Obtain the credentials for the first counter outside the security chip; store the credentials for the first counter inside the security chip.
[0432] In one possible implementation, the first value of the first counter is obtained based on its initial value and a first preset value, wherein the initial value of the counter is randomly generated. This random generation of the initial value of the first counter prevents attackers from obtaining its first value through brute-force enumeration, thus avoiding the leakage of the first value of the first counter stored in the security chip and improving the security of the first value of the first counter stored within the security chip.
[0433] In one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: generating an initial value for a first counter via a security chip. In this way, the initial value of the first counter is generated within the security chip, improving the security of the counter's value stored within the security chip.
[0434] In one possible implementation, one or more processors invoke computer instructions to cause the electronic device to execute: obtaining first user data, an identifier of a first counter, and a credential of the first counter stored in the non-secure chip from a non-secure chip; determining the credential of the first counter stored in the secure chip based on the identifier of the first counter using a secure chip; obtaining a first value of the first counter if the credential of the first counter in the non-secure chip and the credential of the first counter in the secure chip are the same; obtaining a first verification value of the first user data based on the first value of the first counter and the first user data using the secure chip; and storing the first verification value of the first user data in the non-secure chip. Thus, when the electronic device stores the first user data, a first verification value is generated in the secure chip based on the first user data and the first value of the first counter. After generating the first verification value, the electronic device stores the first verification value in the non-secure chip, such as in a flash chip or on a server. Therefore, even if an attacker forges user data, for example, by replacing the first user data with second user data, during authentication, the second verification value generated in the secure chip based on the second user data and the first value of the first counter will be different from the first verification value, causing the verification to fail and preventing attackers from forging user data.
[0435] Figure 16 This is a schematic flowchart of a data protection device provided in an embodiment of this application.
[0436] In one possible implementation, the device 1600 may include an acquisition unit 1601, a processing unit 1602, and a storage unit 1603. The device 1600 can be used to perform... Figure 15 An example of a data protection method is shown.
[0437] The acquisition unit 1601 is used to acquire second user data, a credential of the first counter, and a first verification value of the first user data from the non-secure chip; wherein, the credential of the first counter in the non-secure chip is used to acquire the first value of the first counter, and the first verification value and the first value of the first counter are used to verify whether the second user data is the same as the first user data.
[0438] The acquisition unit 1601 is also used to acquire the credentials of the first counter from within the security chip.
[0439] The acquisition unit 1601 is also used to acquire the first value of the first counter through the security chip when the credentials of the first counter in the non-security chip and the credentials of the first counter in the security chip are the same.
[0440] The processing unit 1602 is used to obtain a second verification value of the second user data based on the second user data and the first value of the first counter through the security chip.
[0441] The processing unit 1602 is also configured to use the second user data if the first check value and the second check value are the same.
[0442] The non-security chip can be a flash chip, a server, or a storage device such as a hard drive; this application does not limit this.
[0443] The first user data refers to the user data previously stored in the electronic device. The second user data is the user data that the electronic device reads from the previously stored first user data. The first user data is stored in a first storage location. Therefore, the second user data can be read from the first storage location.
[0444] If the first checksum and the second checksum are different, it indicates that the attacker may have modified the first user data, for example, by changing the first user data to the second user data, in which case the first user data and the second user data are different. The first user data and the second user data can be stored in the same location.
[0445] If the first check value and the second check value are the same, it means that the second user data is the same as the first user data, and the electronic device uses the second user data, that is, the electronic device uses the first user data.
[0446] This implements a multi-level authentication mechanism within the security chip. Only after successful authentication can the electronic device use the second user data, ensuring the security of user data stored on the electronic device and preventing attackers from forging user data.
[0447] In one possible implementation, the acquisition unit 1601 is further configured to prevent the acquisition of the first value of the first counter from the secure chip if the credentials for the first counter in the non-secure chip and the credentials for the first counter in the secure chip are different. Thus, if an attacker does not know the credentials for the first counter, the credentials for the first counter cannot pass authentication, and the attacker cannot obtain the first value of the first counter, ensuring the security of the first value of the first counter stored in the secure chip.
[0448] In one possible implementation, the acquisition unit 1601 is also used to determine if the second user data cannot be used when the first check value and the second check value are different.
[0449] Optionally, the security chip can also calculate the verification value of user data based on other factors, including but not limited to one or more of the hardware unique key and device unique ID. Other factors can also be other values, and this application embodiment does not limit them.
[0450] In this way, even if an attacker forges user data, for example, by modifying the first user data into the second user data, the second verification value calculated by the security chip based on the second user data and the first value of the first counter will be different from the first verification value. That is, the verification value of the user data will fail the verification, and the electronic device will not be able to use the forged second user data.
[0451] In one possible implementation, before the acquisition unit 1601 acquires the second user data, the credential of the first counter, and the first verification value of the first user data from the non-secure chip, the storage unit 1603 is used to store the first user data, the first verification value of the first user data, and the credential of the first counter in the non-secure chip, and to store the first value of the first counter and the credential of the first counter in the secure chip.
[0452] In this way, the electronic device stores the first value of the first counter in the security chip, ensuring the security of the first value of the first counter and preventing attackers from obtaining the first value of the first counter.
[0453] The electronic device stores the credentials of the first counter in a security chip so that when the electronic device uses the stored user data, it can perform authentication based on the credentials of the first counter. Only when the authentication is successful can the electronic device use the stored user data, thus ensuring the security of the user data stored on the electronic device.
[0454] In one possible implementation, storage unit 1603 is specifically used to generate a credential for the first counter via the security chip and store the credential for the first counter within the security chip. In this case, the security chip needs to store the credential for the first counter in a non-security chip or on a server, so that when the electronic device uses the user data, authentication can be performed based on the credential for the first counter stored in the non-security chip or on the server.
[0455] Alternatively, storage unit 1603 is specifically used to obtain the credentials of the first counter outside the security chip; and to store the credentials of the first counter inside the security chip.
[0456] In one possible implementation, the first value of the first counter is obtained based on its initial value and a first preset value, wherein the initial value of the counter is randomly generated. This random generation of the initial value of the first counter prevents attackers from obtaining its first value through brute-force enumeration, thus avoiding the leakage of the first value of the first counter stored in the security chip and improving the security of the first value of the first counter stored within the security chip.
[0457] In one possible implementation, before the storage unit 1603 stores the first value of the first counter in the security chip, the processing unit 1602 is further configured to generate an initial value for the first counter via the security chip. In this way, the initial value of the first counter is generated within the security chip, improving the security of the counter value stored within the security chip.
[0458] In one possible implementation, before the acquisition unit 1601 acquires the second user data, the credentials of the first counter, and the first verification value of the first user data from the insecure chip, the acquisition unit 1601 is further configured to acquire the first user data, the identifier of the first counter, and the credentials of the first counter stored in the insecure chip from the insecure chip; the processing unit 1602 is further configured to determine the credentials of the first counter stored in the secure chip based on the identifier of the first counter using the secure chip; the acquisition unit 1601 is further configured to acquire the first value of the first counter if the credentials of the first counter in the insecure chip and the credentials of the first counter in the secure chip are the same; the processing unit 1602 is further configured to obtain the first verification value of the first user data based on the first value of the first counter and the first user data using the secure chip; and the storage unit 1603 is further configured to store the first verification value of the first user data in the insecure chip. Thus, when the electronic device stores the first user data, a first verification value is generated in the secure chip based on the first user data and the first value of the first counter. After generating the first verification value, the electronic device stores the first verification value in the insecure chip, such as in a flash chip or on a server. In this way, even if an attacker forges user data, for example, by using second user data to replace the first user data, during authentication, the second verification value generated in the security chip based on the second user data and the first value of the first counter will be different from the first verification value, causing the verification to fail and preventing the attacker from forging user data.
[0459] In one possible implementation, after the processing unit 1602 uses the second user data, the acquisition unit 1601 is further configured to acquire third user data, which is the modified second user data; the processing unit 1602 is further configured to send the third user data, the credentials of the first counter in the non-secure chip, and the identifier of the first counter to the secure chip; the processing unit 1602 is further configured to acquire the credentials of the first counter based on the identifier of the first counter through the secure chip; the acquisition unit 1601 is further configured to acquire the first value of the first counter through the secure chip if the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same; the processing unit 1602 is further configured to acquire the second value of the first counter based on the first value and a second preset value; the processing unit 1602 is further configured to acquire the third verification value of the third user data through the secure chip based on the third user data and the second value of the first counter; the storage unit 1603 is further configured to store the third verification value of the third user data in the non-secure chip.
[0460] In other words, after the second user data is authenticated, the electronic device uses the second user data, causing it to change and resulting in third user data. The electronic device needs to store this third user data. When storing the third user data, the electronic device must generate a verification value for the third user data within the security chip, i.e., a third verification value. This is so that when the electronic device uses the third user data later, it can verify whether the third user data is forged based on the verification value.
[0461] This application provides a computer-readable storage medium for storing computer instructions, which, when executed on an electronic device, cause the electronic device to perform... Figure 15 This illustrates a data protection method.
[0462] This application provides a computer program product that, when run on an electronic device, causes the electronic device to perform... Figure 15 This illustrates a data protection method.
[0463] The various embodiments of this application can be combined arbitrarily to achieve different technical effects.
[0464] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof. When implemented in software, it can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium accessible to a computer or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state disk (SSD)).
[0465] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.
[0466] In summary, the above description is merely an embodiment of the technical solution of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made according to the disclosure of the present invention should be included within the scope of protection of the present invention.
Claims
1. A data protection method, characterized in that, The method includes: The electronic device obtains second user data, a credential of a first counter, and a first verification value of the first user data from a non-secure chip; wherein, the credential of the first counter in the non-secure chip is used to obtain a first value of the first counter, and the first verification value and the first value of the first counter are used to verify whether the second user data is the same as the first user data; The electronic device obtains the credentials for the first counter from within the security chip; If the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device obtains the first value of the first counter through the secure chip; The electronic device obtains a second verification value of the second user data based on the second user data and a first value of the first counter through the security chip; If the first verification value and the second verification value are the same, the electronic device uses the second user data.
2. The method according to claim 1, characterized in that, The method further includes: If the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are different, the electronic device cannot obtain the first value of the first counter from the secure chip.
3. The method according to claim 1 or 2, characterized in that, The method further includes: If the first verification value and the second verification value are different, the electronic device cannot use the second user data.
4. The method according to claim 1 or 2, characterized in that, Before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the non-secure chip, the method further includes: The electronic device stores the first user data, the first verification value of the first user data, and the credentials of the first counter in the non-secure chip; The electronic device stores the first value of the first counter and the credentials of the first counter within the security chip.
5. The method according to claim 4, characterized in that, The electronic device stores the credentials of the first counter within the security chip, specifically including: The electronic device generates credentials for the first counter via the security chip; The electronic device stores the credentials of the first counter within the security chip; or, The electronic device obtains the credentials for the first counter outside the security chip; The electronic device stores the credentials of the first counter within the security chip.
6. The method according to any one of claims 1-2 or 5, characterized in that, The first value of the first counter is obtained based on the initial value of the first counter and a first preset value, wherein the initial value of the first counter is randomly generated.
7. The method according to claim 6, characterized in that, Before the electronic device stores the first value of the first counter within the security chip, the method further includes: The electronic device generates the initial value of the first counter through the security chip.
8. The method according to claim 5, characterized in that, Before the electronic device obtains the second user data, the credentials of the first counter, and the first verification value of the first user data from the non-secure chip, the method further includes: The electronic device obtains the first user data, the identifier of the first counter, and the credentials of the first counter stored in the non-secure chip from the non-secure chip; The electronic device determines the credentials of the first counter stored in the security chip based on the identifier of the first counter through the security chip; If the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device obtains the first value of the first counter; The electronic device obtains the first verification value of the first user data based on the first value of the first counter and the first user data through the security chip; The electronic device stores the first verification value of the first user data in the non-secure chip.
9. The method according to any one of claims 1-2, 5, or 7-8, characterized in that, After the electronic device uses the second user data, the method further includes: The electronic device acquires third user data, which is the modified second user data. The electronic device sends the third user data, the credentials of the first counter in the non-secure chip, and the identifier of the first counter to the secure chip; The electronic device obtains the credentials of the first counter based on the identifier of the first counter through the security chip; When the credentials of the first counter in the non-secure chip and the credentials of the first counter in the secure chip are the same, the electronic device obtains the first value of the first counter through the secure chip, and obtains the second value of the first counter based on the first value and the second preset value of the first counter. The electronic device obtains a third verification value of the third user data based on the third user data and a second value of the first counter through the security chip; The electronic device stores the third verification value of the third user data in the non-secure chip.
10. An electronic device, characterized in that, The electronic device includes: one or more processors, one or more memories, and a display screen; the one or more memories and the display screen are coupled to the one or more processors, the one or more memories are used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the electronic device to perform the method according to any one of claims 1-9.
11. A computer-readable storage medium, characterized in that, Used to store computer instructions, which, when executed on an electronic device, cause the electronic device to perform the method described in any one of claims 1-9.
12. A computer program product, characterized in that, When the computer program product is run on an electronic device, it causes the electronic device to perform the method described in any one of claims 1-9.
Citation Information
Patent Citations
Data processing method and apparatus, and system chip
CN113168477A
KR20210090295A