Security management method, apparatus, device, storage medium, and product
By migrating security detection and control logic to a trusted execution environment and utilizing a secure element storage strategy, the vulnerability of rich execution environments to attacks is solved, achieving high security and stability for the terminal.
Patent Information
- Application Number
- CN202410345999.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-25
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2044-03-25
AI Technical Summary
Existing terminal application management solutions are vulnerable to attacks in rich execution environments, resulting in low security. In particular, once the device is rooted, the management software loses control, posing a security risk.
By migrating security detection and control logic to a trusted execution environment, utilizing secure element storage policies, processing detection information through hash functions, querying the latest policies, and executing security control tasks, security is ensured.
Even if the device is rooted, the security control logic still executes in the trusted execution environment and cannot be tampered with, thus improving the security and stability of the dedicated terminal.
Smart Images

Figure CN118821139B_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of information security technology, and in particular relates to a security management method, device, equipment, storage medium and product. Background Technology
[0002] With the arrival of the "Internet+" era, informatization and intelligentization have become trends, and smart terminals such as work phones, learning tablets, smart speakers, and set-top boxes are very common. These terminals may be used for specific purposes in practice, such as tablets as learning aids or smart speakers for announcements in enterprises. In these devices, specific functions need to be customized. In some cases, if the terminal is involved in highly confidential work, it is also necessary to limit its use through technical means, or even to centrally manage dedicated terminals to ensure device security. This involves using a security management platform to distribute, install, and upgrade customized applications, ensuring that dedicated terminals can only install and run secure and reliable applications, thus protecting user and business security.
[0003] Current terminal application management primarily employs two technical solutions: one is based on the interface permissions of enterprise device management systems provided by device manufacturers, developing management software to manage device applications; the other is based on the device administrator permissions and other privileges of the terminal device system, using management software to achieve enterprise management of devices. However, in current solutions, the code for sensitive operations on terminal applications runs on the terminal's main operating system, belonging to a Rich Execution Environment (REE), also known as a general-purpose execution environment. Once someone obtains root privileges on the device, they can completely control the device, having the authority to tamper with or even completely delete various management software running entirely in the REE environment. This would cause the management software to lose control of the terminal, rendering the aforementioned solutions completely ineffective. Therefore, current solutions still pose certain security risks. Summary of the Invention
[0004] In view of one or more of the problems mentioned above, the present invention provides a security management method, apparatus, device, storage medium and product that can enhance the security of terminals.
[0005] In a first aspect, embodiments of this application provide a security management method, the method being applied to a trusted execution module, comprising:
[0006] Receive security detection information sent by the application management service unit running in a rich execution environment;
[0007] Query the security policies related to the security detection information from the security element;
[0008] Based on the security policy corresponding to the security detection information, the application management service unit is sent with disposal information, which includes the security management tasks that the application management service unit needs to perform.
[0009] In some possible implementations, querying the security policy corresponding to the security detection information from the security element includes:
[0010] The security detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information;
[0011] Fingerprint information is determined based on the hash value;
[0012] The latest security policy related to the security detection information is queried from the security element, and the latest security policy includes a fingerprint information set;
[0013] If the fingerprint information is not included in the fingerprint information set, the latest security policy related to the fingerprint information shall be used as the security policy corresponding to the security detection information.
[0014] In some possible implementations, the security detection information includes information about the application to be installed, and the step of processing the security detection information according to a preset hash function to obtain the hash value corresponding to the security detection information includes:
[0015] The installed application information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information;
[0016] The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including:
[0017] The latest security policy related to the installed application information is queried from the security element, and the latest security policy includes a set of installable application fingerprint information.
[0018] In some possible implementations, the security detection information includes runtime environment detection information. The security detection information is processed according to a preset hash function to obtain a hash value corresponding to the security detection information, including:
[0019] The runtime environment detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information;
[0020] The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including:
[0021] The latest security policy related to the operating environment detection information is queried from the security element. The latest security policy includes a set of secure operating environment fingerprint information.
[0022] In some possible implementations, before receiving the security detection information sent by the application management service unit running in a rich execution environment, the method further includes:
[0023] When the trusted execution module is started, the application management service unit is located in the rich execution environment;
[0024] If the application management service unit is not found, an installation command is sent to the rich execution environment module for the rich execution environment module to install the application management service unit in the rich execution environment.
[0025] In some possible implementations, after locating the application management service unit in the rich execution environment, the method further includes:
[0026] If the application management service unit is located, the application management service unit information and device information sent by the rich execution environment module are received.
[0027] Based on the device information, the latest application management service unit file is obtained by querying the security management platform.
[0028] Determine whether the managed application needs to be updated based on the application management service unit information and the latest application management service unit file;
[0029] If the application management service unit needs to be updated, the managed application is updated using the latest application management service unit file.
[0030] In some possible implementations, the method further includes:
[0031] Receive the latest security policies sent by the security management platform;
[0032] Retrieve the security policy stored in the secure element;
[0033] If the security policy in the security element differs from the latest security policy, the security policy stored in the security element shall be updated according to the latest security policy.
[0034] In some possible implementations, after sending the handling information to the application management service unit based on the security policy corresponding to the security detection information, the method further includes:
[0035] Receive the processing result sent by the application management service unit;
[0036] The test report will be determined based on the results of the aforementioned treatment.
[0037] The detection report is sent to the security management platform for the security monitoring platform to verify the detection report.
[0038] Receive control instructions sent by the security control platform, the control instructions including security control tasks;
[0039] The control instruction is sent to the application control service unit so that the application control service unit can perform the security control task.
[0040] Secondly, embodiments of this application provide another security management method, which is applied to a rich execution module, and the method includes:
[0041] Send security detection information to trusted applications running in a trusted execution environment;
[0042] Receive processing information corresponding to the security detection information sent by the trusted application, wherein the processing includes security control tasks;
[0043] The security control task is executed based on the disposal information.
[0044] Thirdly, embodiments of this application provide a security management device, the device comprising:
[0045] The receiving module is used to receive security detection information sent by the application management service unit running in the rich execution environment;
[0046] The query module is used to query security policies related to the security detection information from the security elements;
[0047] The sending module is used to send handling information to the application management service unit based on the security policy corresponding to the security detection information. The handling information includes the security management tasks that the application management service unit needs to perform.
[0048] Fourthly, embodiments of this application provide a security management device, the device including: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the security management method as described above.
[0049] Fifthly, embodiments of this application provide a computer-readable storage medium, characterized in that the computer storage medium stores computer program instructions, which, when executed by a processor, implement the security management method described above.
[0050] Sixthly, embodiments of this application provide a computer program product in which instructions, when executed by a processor of an electronic device, cause the electronic device to perform the security management method described above.
[0051] The above solution operates within a Trusted Execution Environment (TEE). The application management service unit in the general execution environment (GEE) only performs security checks and executes security management tasks. The security management process, based on security policies, runs within the more secure TEE, where specific security policies are stored in tamper-proof secure elements. Most system vulnerabilities target only the GEE, and even with root privileges, one can only gain permissions specific to the GEE, not bypass or modify the TEE. Therefore, even if the application management service unit in the GEE is modified or deleted, the core security management logic still executes within the TEE and cannot be altered. Thus, the above solution enhances the security of dedicated terminals. Attached Figure Description
[0052] The invention can be better understood from the following description of specific embodiments of the invention in conjunction with the accompanying drawings, wherein:
[0053] Other features, objects, and advantages of the invention will become more apparent from the following detailed description of non-limiting embodiments with reference to the accompanying drawings, wherein the same or similar reference numerals denote the same or similar features.
[0054] Figure 1 This is a flowchart illustrating a security management method provided in one embodiment of this application;
[0055] Figure 2 This is a flowchart illustrating a security management method provided in another embodiment of this application;
[0056] Figure 3 This is a schematic diagram of the system startup process for the security management method of this application;
[0057] Figure 4 This is a schematic diagram of the application change handling process for the security management method of this application;
[0058] Figure 5 This is a schematic diagram of the information update process for the security management method of this application;
[0059] Figure 6 This is a schematic diagram of the overall system architecture of this application;
[0060] Figure 7 This is a schematic diagram of the structure of a security management device provided in one embodiment of this application;
[0061] Figure 8This is a schematic diagram of the hardware structure of the security management device provided in the embodiments of this application. Detailed Implementation
[0062] The features and exemplary embodiments of various aspects of the present invention will now be described in detail. Numerous specific details are set forth in the following detailed description to provide a thorough understanding of the invention. However, it will be apparent to those skilled in the art that the invention may be practiced without requiring some of these specific details. The following description of embodiments is merely intended to provide a better understanding of the invention by illustrating examples of the invention. The invention is by no means limited to any specific configurations and algorithms presented below, but covers any modifications, substitutions, and improvements to elements, components, and algorithms without departing from the spirit of the invention. Well-known structures and techniques are not shown in the drawings and the following description in order to avoid unnecessarily obscuring the invention.
[0063] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0064] Rich Execution Environment (REE): Also known as a general-purpose execution environment, it has good openness and scalability, and can provide rich functionality to upper-layer applications. However, because of its open environment, it is vulnerable to malware attacks.
[0065] Trusted Execution Environment (TEE): This environment guarantees computation unaffected by conventional operating systems, hence the term "trusted." It is achieved by creating a small, independently running operating system that directly provides a limited number of services via system calls. The executed code and accessed data are isolated and protected in terms of confidentiality and immutability.
[0066] Trusted Application (TA): A program that runs in a trusted execution environment and is authenticated and trusted.
[0067] Secure Element (SE): A security device used to protect data security and prevent external malicious parsing attacks. It contains encryption and decryption logic circuits.
[0068] With the advent of the "Internet+" era, informatization and intelligentization have become trends. Smart terminals such as work phones, learning tablets, smart speakers, and set-top boxes are ubiquitous, leading to a surge in customized dedicated terminals. This, in turn, threatens user information security and business security. To ensure the data security of dedicated terminals, it is necessary to limit their usage through technical means. In special scenarios with stringent information security requirements, it may even be necessary to centrally manage dedicated terminals to ensure their security. Specifically, a security management platform can be used to distribute, install, and upgrade customized applications, ensuring that dedicated terminals can only install and run secure and reliable applications, thereby protecting user and business security.
[0069] Current terminal application management is mainly achieved through two types of technical solutions:
[0070] One type involves developing management software based on the interface permissions of enterprise device management systems provided by device manufacturers. This software enables management services such as installing, uninstalling, disabling, and prioritizing applications on devices. Examples include Apple's Apple BusinessManager system, Huawei's security-related open API: Mobile Device Management (MDM), and Xiaomi's enterprise service open API, all of which provide developers with corresponding device management capabilities.
[0071] Another type is based on the administrator privileges (DeviceOwner), accessibility features, device manager, auto-start, and installed application list of the terminal device system. Management software enables functions such as automatic authorization, window monitoring, application uninstallation prevention, device screen locking, or disabling power-saving mode to keep the device running. Ultimately, it allows enterprises to manage device screen time and application usage. Examples include Qidi Guoxin's NQSky EMM all-in-one machine, GreenNet Xiaogelei student mobile phone, and Heng'an Jiaxin Sunshine Guardian APP, among other mobile terminal management solutions. The advantage of this type of solution is that it is applicable to most devices and is not limited by hardware manufacturers.
[0072] Existing dedicated endpoint security solutions, through features such as restricting application installation and blocking risky access, offer some level of security protection for dedicated endpoints, but they also harbor security vulnerabilities. The code governing the installation, execution, and uninstallation of applications on the endpoint, or other sensitive operations, runs on the endpoint's main operating system, which, according to the standards organization (Global Platform, GP), is a REE (Remote Access Provider) environment. From the application layer to the operating system layer, the REE system is susceptible to modification and debugging by attackers, presenting a significant attack surface. For example, attackers can exploit known vulnerabilities to gain root privileges and control the operating system, intercepting or modifying instruction execution logic and results. Alternatively, attackers can remove the endpoint management software's certificate or permissions, rendering the software unusable or even uninstalling it.
[0073] In other words, existing technical solutions only operate in REE environments, which have lower security and are vulnerable to attacks. Moreover, once a device is rooted, it faces the threat of an untrusted overall environment, potentially leading to device mismanagement and the loss of important data assets.
[0074] The inventors' research into the aforementioned issues revealed that TEE and SE are becoming increasingly prevalent on mobile devices. Because Android, as an open software platform, is highly vulnerable to malware attacks, Google mandated TEE support for devices starting with Android 7.0. Most CPU manufacturers' products also support Trusted Execution Environments (TEEs). Furthermore, numerous open-source or commercial TEE operating systems have emerged. Regarding SEs, the widespread adoption of mobile payments, especially fingerprint and facial recognition payments, has placed higher demands on user data protection. Most mobile device manufacturers provide hardware-level security services through SEs to ensure customer information security. Since around 2010, the International Organization for Standardization (ISO) has leveraged its influence in the SE field to promote its TEE standards, including the REE-TEE interface, the execution environment of the TA within the TEE, and the interaction between TEE and SE, which have become industry standards. Currently, there are solutions based on Trusted Execution Environments (TEEs) and Secure Element (SEs) on mobile devices for payment, encryption, authentication, and Digital Rights Management (DRM). For example, mobile devices use SEs for standard financial payment authentication, and Apple iPhones use their built-in chips to process and store fingerprints, as well as for encryption. Huawei's TEE OS microkernel, which has obtained the international information technology security assessment standard CC EAL5+ certification, is isolated from open system hardware and independently stores and processes user fingerprints, facial recognition locks, payment passwords, etc. However, it does not employ TEE and SE to improve the security level of its smart terminal management software.
[0075] While some technologies in smart terminal management differ from those in authentication, DRM, and payment, they are still suitable for using TEE and SE for storing and executing security policies. For example, terminal management involves fingerprint verification and encryption / decryption of execution code. This requires ensuring the integrity of the verification code and execution results, maintaining a certain execution speed, and protecting the security of the keys used. TEE, with its fast operating speed and ability to guarantee the integrity and privacy of its internal TA and stored data, is well-suited for executing verification code. On the other hand, SE offers high security and can be used to securely store terminal management policies and execute a small amount of critical logic. TEE and SE can communicate through a secure channel to collaboratively execute terminal management policies.
[0076] Terminal management differs from authentication, DRM, and payment in that terminal management policies are flexible and adaptable, and verification request content is also diverse and unpredictable, requiring proactive monitoring of the terminal environment. Therefore, the application solutions for TEE and SE will differ and require design. Current common payment security solutions cannot be directly migrated to terminal application management scenarios. However, by leveraging mature application management services in REE environments, security checks can be run within the TEE. With only the application management service in the REE environment executing security policies, security detection under the TEE can be guaranteed. Even if the device is rooted, TA detection can detect, recover, and issue alerts, ensuring device and asset security.
[0077] Specifically, embodiments of the security management method proposed in this application can be found by referring to... Figure 1 In this embodiment, the method is applied to a trusted execution module, that is, it runs in a trusted execution environment. This method includes the following steps S101 to S103.
[0078] Step S101: Receive security detection information sent by the application management service unit running in the rich execution environment.
[0079] An Application Management Service Unit (AMS) is a security management program running in a rich execution environment (REF) to manage and control the execution environment of applications. It provides a secure environment that can restrict application access and operations, protecting user data and system resources. Specifically, the AMS can control application execution permissions, access permissions, and operational scope to prevent malicious applications from intruding and causing damage. It can also perform security checks and audits on application code to ensure the application's origin and security. For example, in Android systems, the AMS is typically implemented through permission management to manage application permissions and access control.
[0080] Security detection information can be the detection information obtained after the application management service unit performs active or passive detection on the rich execution environment.
[0081] In its implementation, the application management service unit can scan firmware information and application information to obtain security detection information. This security detection information is then encrypted and transmitted to the trusted execution module via Transport Layer Security (TLS), which receives the security detection information.
[0082] Step S102: Query the security policy related to the security detection information from the security element.
[0083] A security policy can be a set of security requirements, controls, and processes established to ensure information security. Security policies typically involve the configuration of security rules for specific user behaviors within the REE (Real Estate Information System).
[0084] In its implementation, the secure element stores specific policy information, including the dedicated terminal's operating mode, application fingerprint, firmware fingerprint, and specific handling rules. This information is stored using asymmetric encryption to ensure security. Based on security detection information, the specific security policy can be retrieved from the secure element.
[0085] Step S103: Send handling information to the application management service unit based on the security policy corresponding to the security detection information. The handling information includes the security management tasks that the application management service unit needs to perform.
[0086] In the implementation, this information is analyzed and processed according to a predefined security policy. Based on the analysis results, specific security control tasks are obtained, such as deleting specified applications, forcibly shutting down terminals, and disabling certain functions. These security control tasks are then sent to the application management service unit for execution, thus completing the actual security control.
[0087] The above solution operates within a Trusted Execution Environment (TEE). The application management service unit in the general execution environment (GEE) only performs security checks and executes security management tasks. The security management process, based on security policies, runs within the more secure TEE, where specific security policies are stored in tamper-proof secure elements. Most system vulnerabilities target only the GEE, and even with root privileges, one can only gain permissions specific to the GEE, not bypass or modify the TEE. Therefore, even if the application management service unit in the GEE is modified or deleted, the core security management logic still executes within the TEE and cannot be altered. Thus, the above solution enhances the security of dedicated terminals.
[0088] In some implementations, querying the security policy corresponding to the security detection information from the security element includes:
[0089] The security detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information.
[0090] A hash function is a function that transforms an input of arbitrary length into an output of fixed length using a hash algorithm; this output is the hash value. A preset hash function is a pre-defined algorithm used to calculate the hash value of input data.
[0091] In practical implementation, after obtaining the security detection information, a preset hash function, such as MD5, SHA-1, or SHA-256, is used to convert the input information into a unique hash value. The security detection information is then used as input, and the selected hash function is used for computation. This computation process typically involves processing the input information, such as dividing it into fixed-length blocks, adding padding, and then applying a series of iterative hash function iterations to finally obtain a fixed-length hash value.
[0092] Fingerprint information is determined based on the hash value.
[0093] Fingerprint information can be information that represents data characteristics and is used to distinguish different data.
[0094] In practical implementation, a hash function is used to convert information, such as files and data packets, into a unique fingerprint. This fingerprint can be used to identify and verify information. Specifically, after obtaining the hash value, it can be used directly as the fingerprint information, or it can be combined with some security detection information, such as security detection categories, to form the fingerprint information.
[0095] The latest security policy related to the security detection information is queried from the security element, and the latest security policy includes a fingerprint information set.
[0096] In its implementation, the secure element stores security policies, which are continuously updated and maintained to address emerging threats and vulnerabilities. A fingerprint information set is extracted from the latest security policies retrieved. This fingerprint information may be known secure software fingerprints, runtime environment fingerprints, or other specific fingerprints, used for subsequent fingerprint matching and verification. The collected security detection information is compared with the known fingerprint information to determine its security. If a match is successful, the security detection result is considered secure.
[0097] If the fingerprint information is not included in the fingerprint information set, the latest security policy related to the fingerprint information shall be used as the security policy corresponding to the security detection information.
[0098] In a specific implementation, if the fingerprint information set does not include the fingerprint information, it indicates that the state represented by the security detection information is not in the preset security state. Therefore, depending on the situation the fingerprint information addresses, such as unauthorized access, the corresponding processing strategy in the latest security policy, such as a forced system restart, can be used as the security policy corresponding to the security detection information.
[0099] The above-described method of this application converts security detection information into brief fingerprint information, and compares the fingerprint information to facilitate the verification of legitimacy.
[0100] In some implementations, the security detection information includes information about the application to be installed, and the step of processing the security detection information according to a preset hash function to obtain the hash value corresponding to the security detection information includes:
[0101] The application information to be installed is processed according to a preset hash function to obtain the hash value corresponding to the security detection information.
[0102] The information about the application to be installed can be the application's signature or certificate, or other security-related information, or it can be application file data.
[0103] In the specific implementation, the information of the application to be installed is used as the input of a preset hash function to obtain a hash value with a fixed length output.
[0104] The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including:
[0105] The latest security policy related to the installed application information is queried from the security element, and the latest security policy includes a set of installable application fingerprint information.
[0106] In practice, the latest security policies use different sets of installable application fingerprints for different installed applications. Based on the installed application information, the relevant security policies can be found in the latest security policies.
[0107] The above-described method of this application performs security checks on applications during installation, ensuring that users cannot install dangerous or unsafe applications on their terminals.
[0108] In some implementations, the security detection information includes runtime environment detection information. The security detection information is processed according to a preset hash function to obtain a hash value corresponding to the security detection information, including:
[0109] The runtime environment detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information.
[0110] The runtime environment detection information can be related to the running status of the REE, such as the memory status during operation.
[0111] In the specific implementation, the runtime environment detection information is used as the input of a preset hash function to obtain a hash value with a fixed length output.
[0112] The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including:
[0113] The latest security policy related to the operating environment detection information is queried from the security element. The latest security policy includes a set of secure operating environment fingerprint information.
[0114] In practice, the latest security policies employ different security environment fingerprint information sets for different operating environments. Based on the environment detection information, relevant security policies can be found within the latest security policies.
[0115] The above-described method of this application ensures the security of the operating environment in the REE by detecting the operating environment, and prevents security problems caused by tampering with the REE system environment.
[0116] In some implementations, before receiving security detection information sent by the application management service unit running in a rich execution environment, the method further includes:
[0117] When the trusted execution module is started, the application management service unit is located in the rich execution environment.
[0118] In its implementation, the trusted execution module scans the entire rich execution environment to locate the management service unit. This process may involve searching for and identifying relevant components of the application management service unit at different levels, such as system configuration, device drivers, and applications.
[0119] If the application management service unit is not found, an installation command is sent to the rich execution environment module for the rich execution environment module to install the application management service unit in the rich execution environment.
[0120] In the implementation, if the Application Management Service Unit (AML) is not found in the rich execution environment (REM), it indicates that the component may not be installed in the current environment. In this case, an installation command is sent to the REM module, informing it that the AML needs to be installed. Upon receiving the installation command, the REM module begins preparing to install the AML. This may involve downloading relevant components and programs from a preset location or obtaining necessary resources from other sources. Once the installation conditions are met, the REM module begins installing the AML within its REM environment. This process may involve system configuration, driver loading, application startup, and a series of other operations. After installation, the REM module checks whether the AML has been successfully installed and is functioning correctly. If everything is normal, the AML can then take over and control the execution of the application, ensuring system security and stability.
[0121] It is understandable that although the specific security judgment logic runs in the TEE, the application management service unit in the REE still needs to perform security detection and security processing. The above method of this application scans the REE immediately after the trusted execution module starts, and automatically installs the application management service unit if there is no application management service unit in the REE, so as to ensure that the terminal can be properly managed for security.
[0122] In some implementations, after locating the application management service unit in a rich execution environment, the method further includes:
[0123] If the application management service unit is located, the application management service unit information and device information sent by the rich execution environment module are received.
[0124] Application management service unit (AMU) information represents relevant information about the characteristics of the AMU, such as its version number. Specifically, the AMU can be input into a hash function, and the resulting hash value can be used as the AMU information. This type of AMU information can prevent the AMU from being tampered with.
[0125] Device information can be terminal device information related to application operation, such as terminal hardware information and terminal operating system information.
[0126] In practical implementation, if the application management service unit is found, it indicates that the application management service unit has been installed and is running in the environment. At this time, the rich execution environment module will provide relevant information and data. This information may include the version, running status, and configuration information of the application management service unit, as well as the device's hardware information, system version, network status, etc.
[0127] Based on the device information, the latest application management service unit file is obtained by querying the security management platform.
[0128] A security management platform can be a platform that runs in the cloud and performs relevant data updates, releases, and cloud security checks.
[0129] Understandably, different devices and operating systems often use significantly different applications. Therefore, different application management service unit files will exist for different devices and operating systems. The corresponding application management service unit file needs to be located based on the specific device information.
[0130] In practice, the system obtains device hardware information, system version, and other data, and uses this information as query criteria to send a query request to the security management platform. Upon receiving the query request, the security management platform matches and searches based on the query criteria. Once a matching file is found, the platform returns this file as the latest application management service unit file to the query initiator. This file may be a program, library, or data file used to update or replace the existing application management service unit.
[0131] Determine whether the managed application needs to be updated based on the application management service unit information and the latest application management service unit file.
[0132] In practice, after obtaining the information and the latest application management service unit file, the obtained information and file are compared with pre-defined update conditions. These conditions may include version number and functional differences. If the update conditions are met, the management application may need to be updated.
[0133] If the application management service unit needs to be updated, the managed application is updated using the latest application management service unit file.
[0134] In practice, when the application management service unit needs updating, the management application can be updated using the latest application management service unit file. This update process may involve a series of operations such as system configuration, driver loading, and application startup. After the update is complete, the management application can be checked again to ensure it is running normally and to verify the effectiveness of the update.
[0135] The above-described method in this application checks whether the application management service unit in the REE needs to be updated to ensure that it is consistent with the latest application management service unit file, thereby ensuring the security and stability of the system.
[0136] In some implementations, the method further includes:
[0137] Receive the latest security policies sent by the security management platform.
[0138] The latest security strategy can be stored in the security management platform, which is currently the most comprehensive security strategy.
[0139] In practice, the security management platform retrieves the latest security policies based on device information and then sends these policies to the TEE (Technical Equipment Environment). This allows the TEE to obtain the latest security policies. These policies may include information such as security rules, vulnerability fixes, and protective measures specific to a particular device or application.
[0140] Retrieve the security policy stored in the security element.
[0141] In practice, establishing a connection and communication with the secure element is required. This may necessitate the use of specific communication protocols, interfaces, or commands to retrieve stored security policies from the secure element. Then, the security policies retrieved from the secure element are parsed according to predefined specifications or formats. These security policies may include encryption algorithms, key management protocols, and data integrity checks, among others.
[0142] If the security policy in the security element differs from the latest security policy, the security policy stored in the security element shall be updated according to the latest security policy.
[0143] In a practical implementation, the security policy in the secure element can be compared with the version number of the latest security policy, or a hash value can be calculated and compared. Once it is confirmed that the security policies are different, the security policy stored in the secure element can be updated according to the latest security policy.
[0144] The above-described method of this application updates the security policy stored in the security element according to the latest security policy when it is confirmed that the security policy in the security element is different from the latest security policy, so as to improve the security and stability of the system in a timely manner.
[0145] In some implementations, after sending the handling information to the application management service unit based on the security policy corresponding to the security detection information, the method further includes:
[0146] Receive the processing results sent by the application management service unit.
[0147] The handling result can be the information obtained after the application control service unit has executed the security control tasks in the handling information.
[0148] In its implementation, after performing security checks or control operations, the application management service unit generates a response result. This result can be received from the application management service unit through interaction with the rich execution environment module. This result may include the application's execution status, the status of security vulnerability remediation, and system configuration updates.
[0149] The test report will be determined based on the results of the treatment.
[0150] A test report can be information that is extracted from the key information of the treatment results and summarized in a specific form.
[0151] In practice, analysis and judgment are performed based on the handling results, particularly the security detection results or the application's execution status. This process may involve comparing the handling results with preset standards or thresholds, or further processing and calculations on the handling results. Based on the analysis and judgment results, a corresponding detection report is generated.
[0152] The detection report is sent to the security management platform for the security monitoring platform to verify the detection report.
[0153] In practice, the generated detection report is sent to the security management platform. The security monitoring platform can use the data and information in the detection report for verification and further processing. For example, it can generate a corresponding response based on the verification results. This response may include operations such as updating security policies, patching vulnerabilities, and adjusting system configurations to improve the security and stability of the system.
[0154] Receive control instructions sent by the security control platform, the control instructions including security control tasks.
[0155] Control commands can be sent by the security control platform and are instructions to perform specific control over the REE.
[0156] In its implementation, the security management platform generates management instructions containing security management tasks based on the results of security monitoring and preset security policies. These instructions may include tasks such as performing specific security operations, updating security configurations, and initiating security scans. The platform then receives these management instructions.
[0157] The control instruction is sent to the application control service unit so that the application control service unit can perform the security control task.
[0158] In practice, control commands are sent to the application control service unit. Upon receiving the commands, the application control service unit executes corresponding security control tasks based on the command's content. These tasks may include security checks, vulnerability scanning, and behavior monitoring of the target application.
[0159] The above-described method of this application sends control instructions to the application control service unit so that it can execute the corresponding security control tasks, thereby further confirming the processing results in the cloud and issuing control tasks to REE based on the processing results, which can further ensure the security of the system.
[0160] You can refer to this. Figure 2 , Figure 2 This is a flowchart illustrating a device binding method provided in another embodiment of this application.
[0161] As an embodiment of this application, this method is applied to a rich execution module, and the method includes steps S201 to S203.
[0162] Step S201: Send security detection information to the trusted application running in the trusted execution environment.
[0163] In practice, after generating security detection information, the security detection information is sent to a trusted application, and encryption technology can be used to ensure the security of the information during transmission.
[0164] Step S202: Receive the processing information corresponding to the security detection information sent by the trusted application, wherein the processing includes a security control task.
[0165] In the specific implementation, after receiving security detection information, the trusted application analyzes and judges the content of the information, generates corresponding security control tasks, and then adds a data packet containing the handling information. The rich execution module then receives this handling information.
[0166] Step S203: Execute the security control task according to the disposal information.
[0167] In practice, upon receiving disposition information from a trusted application, the system parses and processes it. This process may include analyzing the content of the disposition information and determining the specific operations for the security control tasks to be performed. Based on the content of the disposition information, relevant modules or interfaces can be invoked to execute the security control tasks. This process may involve operations such as patching vulnerabilities, updating security configurations, and restricting certain functions of the application.
[0168] In the above scheme, the application management service unit in the rich execution environment only performs security detection and executes security management tasks. The security management process according to the security policy runs in the more secure trusted execution environment. Most system vulnerabilities only target the general execution environment, and even if root privileges are obtained, only permissions specific to the general execution environment can be acquired; the trusted execution environment cannot be bypassed or modified. Therefore, even if the application management service unit in the general execution environment is changed or deleted, the main security management logic still executes in the trusted execution environment and cannot be altered. Thus, the above scheme can enhance the security of dedicated terminals.
[0169] In some implementation methods, reference may be made to Figure 3 Upon device startup, the management application TA in the TEE is triggered to start, and the application management service unit is initialized in the REE. If the management application is not installed in the REE, the application management service unit is automatically installed. This ensures that the application management service unit exists in the REE at startup, guaranteeing the normal operation of the solution.
[0170] If an Application Management Service Unit (AMS) already exists, it will be activated and report its own information and device information to the TA (Application Management Service Unit). The TA will communicate encrypted with the policy customization platform via a communication protocol, register the device with the security management platform, and query the latest version of the AMS, the latest configuration, and policy information. After retrieving the latest configuration and policy information, it will write it to the SE (Security Entity) for encrypted storage to ensure policy security. Then, based on the AMS version information, it will determine whether the AMS needs to be updated; if so, it will be updated. This ensures that the latest version of the AMS app, the latest configuration, and policy information are queried upon startup, guaranteeing the effectiveness of the security solution.
[0171] The TA (Task Management) application in the TEE (Telecommunications Equipment) can monitor the operational status of the application management service unit in the REE (Remote Application Management Service Unit) in real time. If problems arise in the operation of the application management service unit, appropriate measures can be taken, such as forcibly shutting down the device. This prevents security issues caused by tampering with the application management service unit in the REE.
[0172] After the device starts up and obtains the latest configuration and policy information, it will automatically trigger an environment check. The TA (Application Controller) will notify the application management service unit in the REE (Application Restriction Service) to check the current device operating environment and compare it with the latest policy requirements to confirm whether it meets the policy requirements. After verification, the TA sends relevant handling instructions according to the latest policy, including installing, updating, uninstalling, enabling or disabling certain apps, etc. The application management service unit in the REE executes the TA's instructions and synchronizes the handling results to the TA. The TA generates a detection report and reports it to the policy handling platform. The platform verifies and confirms whether the current situation is consistent with the requirements based on the report. If it is consistent, it requires maintenance; if it is inconsistent, it requires adjustment, thus generating a control instruction, which is then sent to the TA, and the TA then sends it to the REE for execution.
[0173] Furthermore, in the event of application changes, refer to Figure 4 When a user initiates an application installation, use, or uninstallation operation, the REE detects the user's action, synchronizes the user action information with the TEE, generates corresponding fingerprint information, and initiates a query for the latest policy to the SE. The TEE compares and verifies the latest policy to determine whether the user's action is legal, and sends relevant handling instructions according to the handling rules in the policy, such as not interfering with the user's action or blocking the relevant action. After receiving and executing the handling, the REE synchronizes the handling result to the TEE, and the TEE generates an overall detection report and submits it to the security management platform. The platform issues corresponding control instructions based on the detection report, which the TEE receives, parses, and synchronizes with the REE for execution.
[0174] During this process, the SE encrypted storage security policy, one-way read and write and encrypted communication between TEE and SE effectively prevents the policy from being tampered with, ensuring the security and reliability of the application management policy. At the same time, the application management service runs in TEE, ensuring the security and trustworthiness of the management service operating environment, and ensuring the security and effectiveness of the overall application management.
[0175] To ensure the timeliness of security measures, the configurations and policies in security elements need to be updated. There are three possible update trigger mechanisms: default triggering at system startup; triggering when the platform issues an update command; polling the platform for configuration information every 11 hours; and polling for the latest policy information every 5 hours.
[0176] When the security management platform issues update commands, configuration and policy update commands can be issued to individual devices or in batches according to categories. See reference... Figure 5 Specifically, when a configuration update is triggered, the communication module of the TA in the TEE is called to interact with the policy platform, obtain the latest configuration and policy information, and compare it with the configuration and policy information stored in the SE. If there are updates, the configuration and policy configuration information in the SE will be updated.
[0177] If it is a policy update, the runtime environment detection will be automatically triggered. The TA notifies the application management service in REE to detect the current runtime environment and compare it with the latest policy requirements. Based on the latest policy, relevant handling instructions are sent. After the application management service in REE executes the instructions, it will synchronize the handling results to the TA to generate a detection report and synchronize it with the platform. The platform generates management instructions based on the report and synchronizes them with the TA for execution.
[0178] Additionally, you can refer to Figure 6 , Figure 6 This is a schematic diagram of the overall architecture of the proposed solution. The TA runs within the TEE, while the SE stores configuration and policy information for application management. All pre-application management services run within the REE environment. The TA needs to communicate directly with the security management platform server to perform some collaborative operations. For authentication during cloud communication between the TA and the security management platform server, a shared key can be used between the TA's communication module and the security management platform server, employing authentication and encryption methods such as RSA and AES. Additionally, during TA initialization within the TEE, a separate public-private key pair for the SE may be generated and saved to the security management platform server; this public-private key can then be used for authentication.
[0179] Specifically, the TA installed in the TEE security environment contains five major modules: communication module, runtime environment detection module, configuration update module, policy update module, and policy handling module.
[0180] Communication module: mainly realizes communication and interaction with the security management platform, REE and SE modules. Communication uses TSL protocol for transmission, and can ensure stable heartbeat and real-time reliable interaction through long / short connection modes.
[0181] The runtime environment detection module employs two main detection methods: First, the TA performs basic environment detection, including terminal hardware information, application management software information in the REE, and file information. Second, it invokes the runtime environment detection module within the application management section of the REE to perform a shallow scan to obtain local runtime information such as firmware and application information for the customized terminal; a deep scan of the file directory system, such as the application installation directory and firmware directory, detects application fingerprints, firmware fingerprints, specific file fingerprints, and information about the application itself managed by the REE. After generating fingerprints from the scan results, fingerprint verification is performed based on the current policy information read from the SE. The policy handling module is then invoked to handle the issue based on the verification results and policy handling rules. The detection triggering mechanism includes five types: detection after automatic startup, detection triggered upon receiving a push notification, detection triggered after a policy update, detection triggered by platform instructions, and periodic detection, ensuring runtime environment security.
[0182] Configuration Update Module: The TA (Task Manager) has a default configuration for the operating mechanism. Configuration updates are triggered in three ways: first, by default at system startup; second, when the platform issues an update command; and third, at a fixed periodic interval with the platform (configurable, e.g., polling every 11 hours). When a configuration update is triggered, the communication module is invoked to interact with the policy platform, obtain the latest configuration information, and compare it with the configuration information stored in the SE (Search Engine). If there are updates, the configuration information in the SE is updated.
[0183] Policy Update Module: The TA (Task Controller) has a pre-defined default policy configuration. Configuration updates are triggered in three ways: first, by default at system startup; second, when the platform issues an update command; and third, at a fixed periodic interval with the platform (configurable, e.g., polling every 5 hours). When an update is triggered, the communication module is invoked to interact with the platform, obtain the latest policy information, and compare it with the policy information in the SE (Search Engine). If there is an update, the policy configuration information in the SE is updated, and a runtime environment check is triggered to query whether the current environment meets the latest policy requirements and whether any necessary actions need to be taken.
[0184] Policy handling module: After completing environmental detection and policy comparison verification, it generates a detection report with relevant verification results and reports it to the security management platform. It accepts management instructions from the platform and performs operations on relevant applications, including but not limited to installation, update or uninstallation, as well as enabling or disabling.
[0185] The application management service installed in the REE environment is mainly for communication with the TA in the TEE and to assist the TA in environmental monitoring and policy handling. The relevant module functions are as follows.
[0186] Communication module: mainly to realize communication and interaction with TA in TEE. Communication can use TSL encryption transmission to ensure the authenticity and reliability of the interaction.
[0187] The runtime environment detection module receives TA commands and scans firmware and application information. Simultaneously, it monitors the REE runtime environment in real time, including requests for firmware updates, application installation, updates, uninstallation, startup, or shutdown. When the REE runtime environment changes, it interacts with the TA. The runtime environment detection module in the TA generates a fingerprint based on the REE information and verifies it using the policy information from the SE. If the verification passes, it returns an allow command to the REE; if the verification fails, it returns the corresponding handling rule.
[0188] Policy handling module: Based on the handling rules transmitted by the TA, perform corresponding operations such as application installation, update or uninstallation, as well as enabling or disabling.
[0189] SE primarily receives two types of information pushed by TA: configuration information and policy information that need to be stored. To ensure information security, it only supports one-way read and write operations by TA for updates, and the information is stored in asymmetric encrypted form to ensure security.
[0190] Configuration information: This includes basic configuration information, such as the application management service version and publisher, communication protocol and key, polling cycle for configuration and policy updates, and address for long-term connection to the security management platform.
[0191] Policy information: This includes the operating mode of the dedicated terminal, such as blacklists and whitelists, application fingerprints, firmware fingerprints, and handling rules, such as prohibiting installation, forcibly uninstalling, and prohibiting use.
[0192] The technical solution in this application is based on a terminal-wide application management service deployment architecture using TEE and SE, which differs from deploying application management services only in REE. The hardware-level security of TEE and SE ensures the stability and security of the application management service. Upon receiving a policy update command, TEE initiates a policy comparison and update in SE, and performs runtime environment checks based on the latest policy to ensure the overall system's security and compliance.
[0193] When the system starts up, TA will check whether the application management service in REE is running normally. Otherwise, it will trigger the installation and update of the application management service in REE. Even when the device is offline, TA will still run according to the initialization policy to ensure the security of the dedicated terminal.
[0194] During the relevant security testing process, in order to confirm the legality of the operation, when the application management service in REE detects the application operation, it will synchronize the application package name, signature and related operation information to TA. TA will read the security policy in SE for verification and analysis, and generate operation instructions such as allow or block. The application management service in REE will send the instruction execution result back to TA, and TA will generate a detection report and synchronize it with the platform for secondary verification to ensure the overall terminal operation security.
[0195] Compared to existing technologies, where application management services are installed within the REE environment and corresponding configurations and application management policies are also stored on the REE, making them highly susceptible to tampering, especially when the device system has vulnerabilities, the technical solution of this application encrypts and stores configurations and application management policies in the SE, communicating only unidirectionally with the application management service TA in the TEE, resulting in higher security. Furthermore, application management services running on the REE operating system have low stability, typically only gaining device manager permissions through permission requests, making them easily uninstalled or having critical permissions revoked, especially during factory resets or system reinstalls. In contrast, the application management service TA in this application runs in the TEE, which has an independent operating system. Even if the REE operating system is reinstalled, it is unlikely to affect applications in the TEE, effectively ensuring the stability of the application management service.
[0196] Based on the security management method provided in the above embodiments, this application also provides specific implementation methods of the security management device. Please refer to the following embodiments.
[0197] First see Figure 7 The security management device 700 provided in this application embodiment includes the following modules:
[0198] The receiving module 701 is used to receive security detection information sent by the application management service unit running in the rich execution environment;
[0199] Query module 702 is used to query security policies related to the security detection information from security elements;
[0200] The sending module 703 is used to send disposal information to the application management service unit based on the security policy corresponding to the security detection information. The disposal information includes the security management tasks that the application management service unit needs to perform.
[0201] The above solution operates within a Trusted Execution Environment (TEE). The application management service unit in the general execution environment (GEE) only performs security checks and executes security management tasks. The security management process, based on security policies, runs within the more secure TEE, where specific security policies are stored in tamper-proof secure elements. Most system vulnerabilities target only the GEE, and even with root privileges, one can only gain permissions specific to the GEE, not bypass or modify the TEE. Therefore, even if the application management service unit in the GEE is modified or deleted, the core security management logic still executes within the TEE and cannot be altered. Thus, the above solution enhances the security of dedicated terminals.
[0202] As one implementation of this application, the query module 702 is further configured to query the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set. The security management device 700 may also include:
[0203] The processing module is used to process the security detection information according to a preset hash function to obtain the hash value corresponding to the security detection information;
[0204] The processing module is also used to determine fingerprint information based on the hash value;
[0205] The processing module is further configured to, when the fingerprint information set does not include the fingerprint information, use the latest security policy related to the fingerprint information as the security policy corresponding to the security detection information.
[0206] The above method in this embodiment converts security detection information into fingerprint information, which facilitates the verification of legitimacy.
[0207] As one implementation of this application, the processing module is further configured to process the installed application information according to a preset hash function to obtain the hash value corresponding to the security detection information; the query module 702 is further configured to query the latest security policy related to the installed application information from the security element, wherein the latest security policy includes a set of installable application fingerprint information.
[0208] The above-described method in this embodiment can control application changes in a rich execution environment and ensure terminal security.
[0209] As one implementation of this application, the processing module is further configured to process the runtime environment detection information according to a preset hash function to obtain a hash value corresponding to the security detection information. The query module 702 is further configured to query the latest security policy related to the runtime environment detection information from the security element, wherein the latest security policy includes a secure runtime environment fingerprint information set.
[0210] The above-described method in this embodiment can detect the runtime environment in a rich execution environment and prevent the runtime environment from being tampered with.
[0211] As one implementation of this application, the query module 702 is further configured to locate the application management service unit in the rich execution environment when the trusted execution module is started. The security management device 700 may also include:
[0212] The installation module is used to send an installation command to the rich execution environment module when the application management service unit is not found, so that the rich execution environment module can install the application management service unit in the rich execution environment.
[0213] The above-described method in this embodiment automatically detects and installs the application management service unit when the terminal is started, thus avoiding the inability to perform security management due to the lack of the application management service unit.
[0214] As one implementation of this application, the receiving module 701 is further configured to receive the application management service unit information and device information sent by the rich execution environment module when the application management service unit is found; the querying module 702 is further configured to query the security management platform to obtain the latest application management service unit file based on the device information; the processing module is further configured to determine whether the managed application needs to be updated based on the application management service unit information and the latest application management service unit file. The security management device 700 may further include:
[0215] The update module is used to update the managed application using the latest application management service unit file when the application management service unit needs to be updated.
[0216] The above-described method in this embodiment ensures that the version of the management and control service unit is up-to-date by detecting the management and control service unit, thus guaranteeing the timeliness and effectiveness of security management and control.
[0217] In one implementation of this application, the receiving module 701 is further configured to receive the latest security policy sent by the security management platform; the updating module is further configured to update the security policy stored in the security element according to the latest security policy when the security policy in the security element differs from the latest security policy. The security management device 700 may further include:
[0218] The acquisition module is used to retrieve the security policies stored in the security element.
[0219] The above-described method in this embodiment ensures the timely updating of the security policy by updating the security policy in the security element.
[0220] In one implementation of this application, the receiving module 701 is further configured to receive the processing result sent by the application management service unit; the processing module is further configured to determine a detection report based on the processing result; the sending module 703 is further configured to send the detection report to the security management platform for the security monitoring platform to verify the detection report; the receiving module 701 is further configured to receive the management instruction sent by the security management platform, the management instruction including a security management task; the sending module 703 is further configured to send the management instruction to the application management service unit for the application management service unit to execute the security management task.
[0221] The above-described method in this embodiment further enhances the security of the terminal by performing a secondary check on the security management platform.
[0222] Figure 8 A schematic diagram of the hardware structure of the security management device provided in an embodiment of this application is shown.
[0223] The security management device may include a processor 801 and a memory 802 storing computer program instructions.
[0224] Specifically, the processor 801 may include a central processing unit (CPU), an application-specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0225] Memory 802 may include mass storage for data or instructions. For example, and not limitingly, memory 802 may include a hard disk drive (HDD), floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or Universal Serial Bus (USB) drive, or a combination of two or more of these. Where appropriate, memory 802 may include removable or non-removable (or fixed) media. Where appropriate, memory 802 may be internal or external to the integrated gateway disaster recovery device. In a particular embodiment, memory 802 is non-volatile solid-state memory.
[0226] Memory may include read-only memory (ROM), random access memory (RAM), disk storage media devices, optical storage media devices, flash memory devices, and electrical, optical, or other physical / tangible memory storage devices. Therefore, typically, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the security management method according to any embodiment of this disclosure.
[0227] The processor 801 implements any of the security management methods described in the above embodiments by reading and executing computer program instructions stored in the memory 802.
[0228] In one example, the security management device may also include a communication interface 803 and a bus 810. Wherein, for example... Figure 8 As shown, the processor 801, memory 802, and communication interface 803 are connected through bus 810 and complete communication with each other.
[0229] The communication interface 803 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0230] Bus 810 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not limitingly, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Enhanced Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), HyperTransport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 810 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, any suitable bus or interconnect is contemplated herein.
[0231] Furthermore, in conjunction with the security management methods described in the above embodiments, this application embodiment can provide a computer storage medium for implementation. This computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the security management methods described in the above embodiments.
[0232] However, it should be clarified that the present invention is not limited to the specific configurations and processes described above and shown in the figures. Furthermore, for the sake of brevity, detailed descriptions of known methods and techniques are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of the present invention is not limited to the specific steps described and shown, and those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of the present invention.
[0233] The functional blocks shown in the above-described structural diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this invention are programs or code segments used to perform the required tasks. The programs or code segments can be stored on a machine-readable medium or transmitted over a transmission medium or communication link via data signals carried in a carrier wave. "Machine-readable medium" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, ROM, flash memory, erasable ROM (EROM), floppy disks, CD-ROMs, optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0234] This invention can be implemented in other specific forms without departing from its spirit and essential characteristics. For example, the algorithm described in a particular embodiment can be modified without departing from the basic spirit of the invention. Therefore, the present embodiments are to be regarded as exemplary rather than limiting in all respects, and the scope of the invention is defined by the appended claims rather than the foregoing description, and all changes falling within the meaning and scope of the claims and their equivalents are thus included within the scope of the invention.
[0235] Those skilled in the art will understand that the above embodiments are exemplary and not restrictive. Different technical features appearing in different embodiments can be combined to achieve beneficial effects. Based on a study of the drawings, specification, and claims, those skilled in the art should be able to understand and implement other variations of the disclosed embodiments. In the claims, the term "comprising" does not exclude other means or steps; the indefinite article "a" does not exclude a plurality; the terms "first" and "second" are used to identify names and not to indicate any particular order. No reference numerals in the claims should be construed as limiting the scope of protection. The functionality of multiple parts appearing in the claims can be implemented by a single hardware or software module. The appearance of certain technical features in different dependent claims does not mean that these technical features cannot be combined to achieve beneficial effects.
Claims
1. A security management method, wherein the method is applied to a trusted execution module, characterized in that, The method includes: Receive security detection information sent by the application management service unit running in a rich execution environment; Query the security policies related to the security detection information from the security element; Based on the security policy corresponding to the security detection information, the system sends handling information to the application management service unit. The handling information includes the security management tasks that the application management service unit needs to perform. The system receives the handling results sent by the application management service unit, determines a detection report based on the handling results, and sends the detection report to the security management platform for the security management platform to verify the detection report. The system receives management instructions sent by the security management platform, the management instructions including security management tasks, and sends the management instructions to the application management service unit for the application management service unit to execute the security management tasks.
2. The safety management method according to claim 1, characterized in that, The step of querying the security policy related to the security detection information from the security element includes: The security detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information; Fingerprint information is determined based on the hash value; The latest security policy related to the security detection information is queried from the security element, and the latest security policy includes a fingerprint information set; If the fingerprint information is not included in the fingerprint information set, the latest security policy related to the fingerprint information shall be used as the security policy corresponding to the security detection information.
3. The safety management method according to claim 2, characterized in that, The security detection information includes installed application information. The step of processing the security detection information according to a preset hash function to obtain the hash value corresponding to the security detection information includes: The installed application information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information; The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including: The latest security policy related to the installed application information is queried from the security element, and the latest security policy includes a set of installable application fingerprint information.
4. The safety management method according to claim 2, characterized in that, The security detection information includes runtime environment detection information. The security detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information, including: The runtime environment detection information is processed according to a preset hash function to obtain the hash value corresponding to the security detection information; The step of querying the latest security policy related to the security detection information from the security element, wherein the latest security policy includes a fingerprint information set, including: The latest security policy related to the operating environment detection information is queried from the security element. The latest security policy includes a set of secure operating environment fingerprint information.
5. The safety management method according to claim 4, characterized in that, Before receiving the security detection information sent by the application management service unit running in the rich execution environment, the method further includes: When the trusted execution module is started, the application management service unit is located in the rich execution environment; If the application management service unit is not found, an installation command is sent to the rich execution environment module for the rich execution environment module to install the application management service unit in the rich execution environment.
6. The safety management method according to claim 5, characterized in that, After locating the application management service unit in the rich execution environment, the method further includes: If the application management service unit is located, the application management service unit information and device information sent by the rich execution environment module are received. Based on the device information, the latest application management service unit file is obtained by querying the security management platform. Determine whether the application management service unit needs to be updated based on the application management service unit information and the latest application management service unit file; If the application management service unit needs to be updated, the application management service unit is updated using the latest application management service unit file.
7. The safety management method according to claim 4, characterized in that, The method further includes: Receive the latest security policies sent by the security management platform; Retrieve the security policy stored in the secure element; If the security policy in the security element differs from the latest security policy, the security policy stored in the security element shall be updated according to the latest security policy.
8. A security management method, wherein the method is applied to a rich execution module, characterized in that, The method includes: Send security detection information to a trusted application running in a trusted execution environment, wherein the trusted execution environment is implemented by the trusted execution module as described in claim 1; Receive processing information corresponding to the security detection information sent by the trusted application, wherein the processing information includes security control tasks; The security control task is executed based on the disposal information.
9. A safety management device, characterized in that, The device includes: The receiving module is used to receive security detection information sent by the application management service unit running in the rich execution environment, and is also used to receive the processing results sent by the application management service unit, and is also used to receive management instructions sent by the security management platform, the management instructions including security management tasks; The processing module is used to determine the test report based on the processing result; The query module is used to query security policies related to the security detection information from the security elements; The sending module is configured to send handling information to the application management service unit based on the security policy corresponding to the security detection information. The handling information includes the security management tasks that the application management service unit needs to perform. The module is also configured to send the detection report to the security management platform for the security management platform to verify the detection report. Furthermore, the module is configured to send the management instruction to the application management service unit for the application management service unit to execute the security management tasks.
10. A safety management device, characterized in that, The device includes: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement the security management method as described in any one of claims 1-8.
11. A computer-readable storage medium, characterized in that, The computer storage medium stores computer program instructions, which, when executed by a processor, implement the security management method as described in any one of claims 1-8.
12. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs the security management method as described in any one of claims 1-8.
Citation Information
Patent Citations
Application upgrade management system and method for terminal equipment
CN108874419A
Application program management and control method, device and apparatus
CN109977676A
Operating system kernel mandatory access control method and system based on TEE extension
CN111400723A