Data migration method, device, equipment, medium and product based on trusted execution environment in trusted data space

By performing remote attestation and secure verification in a trusted execution environment, obtaining and transmitting data key communication ciphertext and encrypted data, the security and accessibility issues of data migration in the trusted data space are solved, and seamless migration and secure storage of data between new and old environments are achieved.

CN119416204BActive Publication Date: 2025-10-14LINGSHU TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411564023.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-05
Publication Date
2025-10-14
Estimated Expiration
2044-11-05

AI Technical Summary

Technical Problem

In the trusted data space, existing technologies cannot achieve secure and seamless migration of trusted application data between old and new environments. Especially when migrating data between different virtual machine environments, the security and accessibility of the data cannot be guaranteed.

Method used

By performing remote attestation, secure verification, data key acquisition, and encrypted data transmission within a trusted execution environment, secure data migration between the old and new environments is ensured. This includes sending a remote attestation request to a second trusted application, generating and verifying a remote authentication report, acquiring and transmitting the data key communication ciphertext and encrypted data, and finally storing them in a linked manner.

Benefits of technology

It enables seamless access and use of trusted application data in new and old environments, improves data migration efficiency and storage security, and ensures the security and integrity of data during the migration process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119416204B_ABST
    Figure CN119416204B_ABST
Patent Text Reader

Abstract

The application discloses a data migration method and device based on a trusted execution environment in a trusted data space, equipment, storage and products. The method comprises the following steps: sending a remote proof request to a second trusted application in a second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote proof request; performing a secure and trusted verification on the remote authentication report, and after the verification is passed, sending a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back data key communication ciphertext according to the data key acquisition request; sending an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request; and storing the data key communication ciphertext and the encrypted data. The technical scheme of the application realizes data security migration of the trusted application data, and realizes seamless access and use of the data in the new and old environments.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of data migration, and in particular to a data migration method and device based on a trusted execution environment in a trusted data space, equipment, medium and product. BACKGROUND

[0002] In the use of a trusted data space, as business requirements change, it can be necessary to expand the disk capacity or execution performance and other aspects, to update the version of a trusted application program, or to update the hardware environment, at which point it can be necessary to migrate the data of an existing trusted application program to another virtual machine environment based on a secure chip.

[0003] In the persistent storage of data of a trusted application program in a trusted data space, all of the data stored persistently is encrypted based on the virtual machine environment of the current hardware, taking into account security and trust factors, and the encrypted data cannot be decrypted in other hosts or virtual machine environments. Therefore, when data migration occurs, a secure and trusted data migration method is needed to enable seamless access and use of the data in a new environment. SUMMARY

[0004] The present application provides a data migration method and device based on a trusted execution environment in a trusted data space, equipment, medium and product, to enable secure migration of data of a trusted application program and to enable seamless access and use of the data in a new or old environment.

[0005] According to an aspect of the present application, a data migration method based on a trusted execution environment in a trusted data space is provided, applied to a first trusted application program in a first trusted execution environment, and the method comprises:

[0006] sending a remote attestation request to a second trusted application program in a second trusted execution environment, for the second trusted application program to generate and feed back a remote authentication report based on the remote attestation request;

[0007] performing secure and trusted verification on the remote authentication report, and after verification, sending a data key acquisition request to the second trusted application program, for the second trusted application program to generate and feed back data key communication ciphertext based on the data key acquisition request;

[0008] sending an encrypted data acquisition request to the second trusted application program, for the second trusted application program to generate and feed back encrypted data based on the encrypted data acquisition request;

[0009] performing associated storage on the data key communication ciphertext and the encrypted data.

[0010] According to an aspect of the present application, there is provided a data migration method based on a trusted execution environment in a trusted data space, applied to a second trusted application in a second trusted execution environment, comprising:

[0011] acquiring a remote attestation request sent by a first trusted application in a first trusted execution environment, and generating a remote authentication report according to the remote attestation request;

[0012] feeding back the remote authentication report to the first trusted application for the first trusted application to perform a secure and trusted verification on the remote authentication report, and generating and feeding back a data key acquisition request after the verification is passed;

[0013] generating a data key communication cipher text according to the data key acquisition request, and sending the data key communication cipher text to the first trusted application;

[0014] acquiring an encrypted data acquisition request sent by the first trusted application, and generating encrypted data according to the encrypted data acquisition request;

[0015] sending the encrypted data to the first trusted application for the first trusted application to store the data key communication cipher text and the encrypted data in association.

[0016] According to another aspect of the present application, there is provided a data migration device based on a trusted execution environment in a trusted data space, configured in a first trusted application in a first trusted execution environment, comprising:

[0017] an attestation request sending module, configured to send a remote attestation request to a second trusted application in a second trusted execution environment, for the second trusted application to generate and feed back a remote authentication report based on the remote attestation request;

[0018] a secure verification module, configured to perform a secure and trusted verification on the remote authentication report, and send a data key acquisition request to the second trusted application after the verification is passed, for the second trusted application to generate and feed back a data key communication cipher text according to the data key acquisition request;

[0019] an acquisition request sending module, configured to send an encrypted data acquisition request to the second trusted application, for the second trusted application to generate and feed back encrypted data according to the encrypted data acquisition request;

[0020] a data storage module, configured to store the data key communication cipher text and the encrypted data in association.

[0021] According to another aspect of the present application, there is provided a data migration apparatus based on a trusted execution environment in a trusted data space, configured in a second trusted application in a second trusted execution environment, the apparatus comprising:

[0022] a proof request obtaining module, configured to obtain a remote proof request sent by a first trusted application in a first trusted execution environment, and generate a remote authentication report according to the remote proof request;

[0023] an authentication report feedback module, configured to feed back the remote authentication report to the first trusted application, so that the first trusted application performs a secure and trusted verification on the remote authentication report, and generates and feeds back a data key obtaining request after the verification is passed;

[0024] a key generating module, configured to generate a data key communication cipher text according to the data key obtaining request, and send the data key communication cipher text to the first trusted application;

[0025] a data obtaining module, configured to obtain an encrypted data obtaining request sent by the first trusted application, and generate encrypted data according to the encrypted data obtaining request;

[0026] an encrypted data feedback module, configured to send the encrypted data to the first trusted application, so that the first trusted application stores the data key communication cipher text and the encrypted data in association.

[0027] According to another aspect of the present application, there is provided an electronic device, comprising:

[0028] at least one processor; and

[0029] a memory connected with the at least one processor in communication; wherein,

[0030] the memory stores a computer program executable by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to perform the data migration method based on a trusted execution environment in a trusted data space according to any one of the embodiments of the present application.

[0031] According to another aspect of the present application, there is provided a computer readable storage medium, storing computer instructions for enabling a processor to perform the data migration method based on a trusted execution environment in a trusted data space according to any one of the embodiments of the present application when executed by the processor.

[0032] According to another aspect of the present application, there is provided a computer program product comprising a computer program which, when executed by a processor, implements the method of data migration based on a trusted execution environment in a trusted data space according to any of the embodiments of the present application.

[0033] The technical scheme of the embodiment of the present application realizes data security migration of trusted application data. The technical scheme of the embodiment requires that the trusted application data is stored by using a random key for encryption, and the data encryption key is stored by using a seal key derived based on the trusted execution environment for encryption, so that only the unsealing and resealing of the trusted application data encryption key is required during data migration, and seamless access and use of the data in the new and old environments are realized.

[0034] It should be understood that the content described in this part is not intended to identify the key or important features of the embodiments of the present application, nor is it used to limit the scope of the present application. Other features of the present application will become apparent from the following description. BRIEF DESCRIPTION OF DRAWINGS

[0035] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the drawings needed in the embodiment description will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.

[0036] Figure 1 is a flow chart of a data migration method based on a trusted execution environment according to the first embodiment of the present application;

[0037] Figure 2 is a flow chart of a data migration method based on a trusted execution environment according to the second embodiment of the present application;

[0038] Figure 3 is a flow chart of a data migration method based on a trusted execution environment according to the third embodiment of the present application;

[0039] Figure 4 is a structural schematic diagram of a data migration device based on a trusted execution environment according to the fourth embodiment of the present application;

[0040] Figure 5 is a structural schematic diagram of a data migration device based on a trusted execution environment according to the fifth embodiment of the present application;

[0041] Figure 6 is a structural schematic diagram of an electronic device implementing the data migration method based on a trusted execution environment according to the embodiment of the present application. DETAILED DESCRIPTION

[0042] In order to better understand the technical scheme of the present application, the technical scheme in the embodiments of the present application will be described clearly and completely below in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of the present application.

[0043] It should be noted that the terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and do not necessarily indicate a specific order or sequence. It should be understood that the data thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application described herein can be implemented in an order other than that illustrated or described herein. In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device including a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to the process, method, product or device.

[0044] Embodiment one

[0045] Figure 1 A flowchart of a data migration method based on a trusted execution environment is provided for the first embodiment of the present application. The present embodiment can be applicable to the case of data migration between trusted applications in the trusted data space under the old and new versions of the secure chip. Specifically, it can be the case of migrating the data of the trusted application from the old environment to the new environment. The method can be performed by a data migration device based on a trusted execution environment. The data migration device based on a trusted execution environment can be realized in the form of hardware and / or software. The data migration device based on a trusted execution environment can be configured in an electronic device to which a first trusted application in a first trusted execution environment belongs.

[0046] As shown in Figure 1 , the method comprises:

[0047] S110, a remote attestation request is sent to a second trusted application in a second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote attestation request.

[0048] S120, the remote authentication report is securely and trustfully verified, and after verification, a data key acquisition request is sent to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext according to the data key acquisition request.

[0049] S130, sending an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request.

[0050] S140, storing the data key communication cipher text and the encrypted data in association.

[0051] The Trusted Execution Environment (TEE) is an independent and secure computing environment designed to protect sensitive data and code. TEE usually exists in the main processor of the device, isolated from the operating system and other applications, to ensure that sensitive operations are not affected by malware or other attacks. This technology is widely used in scenarios that require high security, such as data space, mobile payment, digital rights management, identity verification and password storage. By providing an isolated and secure execution space, TEE technology enhances the overall security and data privacy protection of the device.

[0052] The first trusted execution environment can be a new environment to be received by the migration data; the first trusted application can be an application deployed in the first trusted execution environment; the second trusted execution environment can be an old environment where the encrypted data currently resides, and the data is to be migrated from the environment to other trusted execution environments; the second trusted application can be an application deployed in the first trusted execution environment. It should be noted that the first trusted application and the second trusted application are the same program of the same or different versions deployed in different environments, for example, the first trusted application is V2.0 version of application A, and the second trusted application is V1.0 version of application A.

[0053] Among them, the program of the first trusted application and the second trusted application establishes an SSL (Secure Sockets Layer) network connection for data transmission.

[0054] To ensure the security of data migration, before data migration, the first trusted application of the first trusted execution environment and the second trusted application of the second trusted execution environment perform security verification of the trusted execution environment. Specifically, it can include application integrity verification and application name or type verification.

[0055] For example, the first trusted application sends a remote attestation request to the second trusted application, and the second trusted application generates a remote attestation report according to the remote attestation request after receiving the remote attestation request.

[0056] In a specific embodiment, the second trusted application generates the remote authentication report according to the remote attestation request in the following manner: determining a random number according to the remote attestation request; sending the attestation report request and the random number to the application manager, so that the application manager generates the remote attestation report according to the attestation report request and the random number, and feeds back the remote attestation report to the second trusted application.

[0057] Specifically, the remote attestation request is parsed to obtain the random number; the random number is randomly generated by the first trusted application and is based on the random number to generate the remote attestation request, so that the remote attestation request carries the random number randomly generated by the first trusted application. The second trusted application sends the attestation report request and the random number to the application manager; the application manager obtains the running environment report and the integrity information of the second trusted application and carries the random number, appends the integrity information in the running environment attestation report, signs the report information by using the running environment private key to obtain the remote attestation report, and returns the remote attestation report to the second trusted application; and the second trusted application sends the remote attestation report to the first trusted application.

[0058] The first trusted application performs secure and trusted verification on the information in the remote attestation report. Specifically, the first trusted application obtains the environment attestation information from the environment attestation service according to the measurement value in the remote attestation report; requests the relevant certificate from the Hikvision chip CA (Certificate Authority) according to the chip ID (Identification) in the remote attestation report; and performs secure and trusted verification on the information in the remote attestation report according to the environment attestation information and the relevant certificate.

[0059] After the secure and trusted verification on the remote attestation report is passed, the first trusted application sends a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back the data key communication ciphertext according to the data key acquisition request.

[0060] It should be noted that the data encryption keys corresponding to different application data are not the same, for example, the data encryption key corresponding to data a is key A, and the data encryption key corresponding to data b is key B. Therefore, the first trusted application can obtain the data list from the second trusted application before obtaining the data encryption key, and obtain the data encryption key based on the data list and the actual data migration demand of the first trusted application.

[0061] In an optional embodiment, the first trusted application sends a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back the data key communication ciphertext according to the data key acquisition request, including:

[0062] Step a1, sending a data list acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data list according to the data list acquisition request; the data list includes at least one migratable data identifier.

[0063] The first trusted application sends a data list acquisition request to the second trusted application. After receiving the data list acquisition request, the second trusted application performs data retrieval on the data stored in the database to obtain the stored data related to the second trusted application and generates a data list. It should be noted that at least one application data corresponding to each application can be stored in the database of each environment. The second trusted application can generate a data identifier corresponding to each data according to the retrieved data related to the second trusted application, and store the migratable identifier in the data list. Since the data is different, the migratable identifier corresponding to different data is different, and can be used to represent the uniqueness of the data.

[0064] Step a2, generating a data key acquisition request according to the migratable data identifier in the data list.

[0065] The first trusted application generates a data key acquisition request for different data one by one according to the migratable data identifier in the data list and in combination with the actual data migration needs of the first trusted application.

[0066] Step a3, sending a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext according to the data key acquisition request.

[0067] The first trusted application sends a data key acquisition request to the second trusted application one by one. After receiving the data key acquisition request, the second trusted application queries the key from the key storage database, obtains the requested data key communication ciphertext, and feeds back the data key communication ciphertext to the first trusted application.

[0068] It should be noted that in order to ensure the security of key storage in the trusted execution environment, the key is usually stored in an encrypted manner, and the key capable of decryption is usually decrypted based on the virtual machine derived key in the self virtual machine environment, and cannot be decrypted in other environments, thereby ensuring the security of key storage. Therefore, before the second trusted application feeds back the key to the first trusted application, key decryption processing needs to be performed in the self virtual machine environment.

[0069] In one specific embodiment, the second trusted application generates the data key communication ciphertext in the following manner:

[0070] Step b1, obtaining the data key seal ciphertext according to the data key obtaining request by the second trusted application.

[0071] The second trusted application queries the data key seal ciphertext corresponding to the data key obtaining request from the database storing the key according to the data key obtaining request. The data key seal ciphertext can be an encrypted key encrypted based on the self virtual machine derivation key.

[0072] Step b2, the data key seal ciphertext is unsealed based on the seal key derived by the second trusted application based on the device to which the second trusted application belongs, to obtain the data key plaintext.

[0073] The data key plaintext is the data key obtained by the second trusted application decrypting the data key seal ciphertext based on the seal key derived by the second trusted application based on the device to which the second trusted application belongs.

[0074] The second trusted application decrypts the data key seal ciphertext based on the seal key derived by the second trusted application based on the device to which the second trusted application belongs, to obtain the data key plaintext.

[0075] Step b3, the data key plaintext is encrypted based on the communication key previously negotiated with the first trusted execution environment, to obtain the data key communication ciphertext.

[0076] It should be noted that, in order to ensure the security of the key transmission process, the first trusted execution environment and the second trusted execution environment previously negotiate the communication key and store it in their respective environments.

[0077] The second trusted application encrypts the data key plaintext based on the communication key previously negotiated with the first trusted execution environment, to obtain the data key communication ciphertext, and feeds back the data key communication ciphertext to the first trusted application.

[0078] After receiving the data key communication ciphertext, the first trusted application decrypts the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment, to obtain the data key plaintext, and stores the decrypted data key plaintext.

[0079] In order to further improve the storage security of the data key plaintext, after decrypting the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext, the first trusted application further encrypts the data key plaintext based on the seal key derived by the first trusted application based on the device to which the first trusted application belongs, to obtain the data key seal ciphertext, and stores the data key seal ciphertext.

[0080] The first trusted application sends an encrypted data acquisition request to the second trusted application, the second trusted application acquires encrypted data from a database storing the encrypted data according to the encrypted data acquisition request, and sends the acquired encrypted data to the first trusted application. The first trusted application stores the data key seal ciphertext and the encrypted data in association.

[0081] After completing the data migration task from the second trusted execution environment to the first trusted execution environment, the migrated data can be acquired by the related personnel, platform or system with the acquisition right, and the first trusted application of the first trusted execution environment can be initiated to send a data acquisition request.

[0082] In an optional embodiment, after completing the data migration task, the method further comprises:

[0083] Step c1, in response to the data acquisition request, the data key communication ciphertext is decrypted based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext.

[0084] After receiving the data acquisition request, the identity and authority of the request initiator are verified to verify whether the request initiator has the data acquisition authority. If yes, the data key communication ciphertext is decrypted based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext; if not, the request initiator of the data acquisition request is sent a no authority prompt related information.

[0085] Step c2, the encrypted data is decrypted using the data key plaintext to obtain the plaintext data.

[0086] Step c3, the plaintext data is fed back.

[0087] The plaintext data is sent to the request initiator of the data acquisition request.

[0088] The technical scheme of the embodiment of the present application realizes the function of trusted application data migration in the trusted data space based on the trusted virtual machine technology of the security chip, specifically, after the environment verification of the trusted execution environment of both parties, a data key acquisition request is sent to the second trusted application to be migrated, so that the second trusted application generates and feeds back the data key communication ciphertext according to the data key acquisition request; an encrypted data acquisition request is sent to the second trusted application, so that the second trusted application generates and feeds back the encrypted data according to the encrypted data acquisition request, and the data key communication ciphertext and the encrypted data are associatedly stored, thereby improving the data migration efficiency and data storage security. The above technical scheme requires that the trusted application data is stored by using a random key, and then the data encryption key is stored by using a seal key derived based on the trusted execution environment, so that only the unsealing and resealing processing of the trusted application data encryption key is needed during data migration, and seamless access and use of the data in the new and old environments are realized.

[0089] Embodiment two

[0090] Figure 2 A flowchart of a data migration method based on a trusted execution environment is provided for the second embodiment of the present application. The present embodiment can be applicable to the case of data migration between trusted applications in the trusted data space under the new and old versions based on the security chip, and specifically can be the case of migrating the trusted application data from the old environment to the new environment. The method can be performed by a data migration device based on the trusted execution environment, which can be realized in the form of hardware and / or software, and can be configured in the electronic device to which the second trusted application belongs in the second trusted execution environment.

[0091] As shown in the figure, the method comprises: Figure 2

[0092] S210, a remote attestation request sent by a first trusted application in a first trusted execution environment is acquired, and a remote authentication report is generated according to the remote attestation request.

[0093] S220, the remote authentication report is fed back to the first trusted application, so that the first trusted application performs secure and trusted verification on the remote authentication report, and after the verification passes, a data key acquisition request is generated and fed back.

[0094] S230, a data key communication ciphertext is generated according to the data key acquisition request, and the data key communication ciphertext is sent to the first trusted application.

[0095] S240, an encrypted data acquisition request sent by the first trusted application is acquired, and encrypted data is generated according to the encrypted data acquisition request. ​

[0096] S250, sending the encrypted data to the first trusted application for the first trusted application to store the data key communication cipher text and the encrypted data in association.

[0097] The first trusted execution environment can be a new environment to be received with the migration data; the first trusted application can be an application deployed in the first trusted execution environment; the second trusted execution environment can be an old environment where the encrypted data is currently located, and the data is to be migrated from the environment to other trusted execution environments; and the second trusted application can be an application deployed in the first trusted execution environment. It should be noted that the first trusted application and the second trusted application are the same program of the same or different versions deployed in different environments, for example, the first trusted application is a V2.0 version of application A, and the second trusted application is a V1.0 version of application A.

[0098] The program of the first trusted application and the second trusted application establishes an SSL network connection for data transmission.

[0099] For example, the first trusted application sends a remote attestation request to the second trusted application, and the second trusted application generates a remote authentication report according to the remote attestation request after receiving the remote attestation request.

[0100] In an optional embodiment, the remote authentication report is generated according to the remote attestation request, comprising:

[0101] Step d1, determining a random number according to the remote attestation request.

[0102] Step d2, sending the authentication report request and the random number to the application manager, so that the application manager generates the remote authentication report according to the authentication report request and the random number, and feeds back the remote authentication report to the second trusted application.

[0103] Specifically, the remote attestation request is parsed to obtain the random number; the random number is randomly generated by the first trusted application, and the remote attestation request is generated based on the random number, so that the remote attestation request carries the random number randomly generated by the first trusted application. The second trusted application sends the authentication report request and the random number to the application manager; the application manager obtains the running environment report and the integrity information of the second trusted application and carries the random number, attaches the integrity information in the running environment authentication report, signs the report information by using the running environment private key to obtain the remote authentication report, and returns the remote authentication report to the second trusted application; and the second trusted application sends the remote authentication report to the first trusted application.

[0104] The first trusted application performs secure and trusted verification on the information in the remote authentication report. Specifically, the first trusted application acquires environment authentication information from the environment authentication service according to the measurement value in the remote authentication report; requests relevant certificates from the Hikvision chip CA center according to the chip ID in the remote authentication report; and performs secure and trusted verification on the information in the remote authentication report according to the environment authentication information and the relevant certificates.

[0105] After the first trusted application passes the secure and trusted verification on the remote authentication report, the first trusted application sends a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication cipher text according to the data key acquisition request.

[0106] It should be noted that, since the data encryption keys corresponding to different application data are not the same, for example, the data encryption key corresponding to data a is key A, and the data encryption key corresponding to data b is key B, therefore, the first trusted application can acquire a data list from the second trusted application before acquiring the data key, and based on the data list, in combination with the actual data migration needs of the first trusted application, the first trusted application can acquire the data encryption key in a targeted manner.

[0107] In an optional embodiment, according to the data key acquisition request, a data key communication cipher text is generated and sent to the first trusted application, comprising:

[0108] Step e1, acquiring a data list acquisition request sent by the first trusted application, and generating a data list according to the data list acquisition request; the data list includes at least one migratable data identifier.

[0109] The first trusted application sends a data list acquisition request to the second trusted application, and the second trusted application performs data retrieval on the data stored in the database after receiving the data list acquisition request, obtains the stored data related to the second trusted application and generates a data list. It should be noted that, in the database of each environment, there can be at least one application data corresponding to each application. The second trusted application can generate a data identifier corresponding to each data according to the retrieved data related to the second trusted application, and store the migratable identifier in the data list. Since the data is different, the migratable identifier corresponding to different data is different, and can be used to represent the uniqueness of the data.

[0110] Step e2, sending the data list to the first trusted application, so that the first trusted application generates and feeds back a data key acquisition request according to the migratable data identifier in the data list.

[0111] The second trusted application sends a data list to the first trusted application. The first trusted application generates a data key acquisition request for different data one by one according to the migratable data identifier in the data list and in combination with actual data migration needs of the first trusted application.

[0112] Step e3, obtaining the data key seal ciphertext according to the data key acquisition request.

[0113] The second trusted application queries the data key seal ciphertext corresponding to the data key acquisition request from the database storing the key according to the data key acquisition request. The data key seal ciphertext can be an encryption key encrypted based on a virtual machine derived key of the second trusted application.

[0114] Step e4, decrypting the data key seal ciphertext based on the seal key derived from the device to which the second trusted application belongs to obtain the data key plaintext.

[0115] The second trusted application decrypts the data key seal ciphertext based on the seal key derived from the device to which the second trusted application belongs to obtain the data key plaintext.

[0116] Step e5, encrypting the data key plaintext based on the communication key previously negotiated with the first trusted execution environment to obtain data key communication ciphertext, and sending the data key communication ciphertext to the first trusted application.

[0117] It should be noted that, in order to ensure the security of the key transmission process, the first trusted execution environment and the second trusted execution environment previously negotiate the communication key and store the communication key in the respective environments.

[0118] The second trusted application encrypts the data key plaintext based on the communication key previously negotiated with the first trusted execution environment to obtain data key communication ciphertext, and feeds back the data key communication ciphertext to the first trusted application.

[0119] After receiving the data key communication ciphertext, the first trusted application decrypts the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext, and stores the decrypted data key plaintext.

[0120] In order to further improve the storage security of the data key plaintext, after decrypting the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext, the method further includes: encrypting the data key plaintext based on the seal key derived from the device to which the first trusted application belongs to obtain the data key seal ciphertext; and storing the data key seal ciphertext.

[0121] The first trusted application sends an encrypted data acquisition request to the second trusted application. The second trusted application acquires encrypted data from a database storing the encrypted data according to the encrypted data acquisition request, and sends the acquired encrypted data to the first trusted application. The first trusted application stores the data key seal ciphertext and the encrypted data in association.

[0122] After completing the data migration task from the second trusted execution environment to the first trusted execution environment, the migrated data can be acquired by a person, platform or system having the acquisition right, and the person, platform or system can initiate a data acquisition request to the first trusted application of the first trusted execution environment.

[0123] In an optional embodiment, after completing the data migration task, the method further comprises:

[0124] Step f1, in response to the data acquisition request, the data key communication ciphertext is decrypted based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext.

[0125] After receiving the data acquisition request, the identity and authority of the request initiator are verified to verify whether the request initiator has the data acquisition authority. If yes, the data key communication ciphertext is decrypted based on the communication key previously negotiated with the second trusted execution environment to obtain the data key plaintext; if no, a no authority prompt related information is sent to the request initiator of the data acquisition request.

[0126] Step f2, the encrypted data is decrypted using the data key plaintext to obtain the plaintext data.

[0127] Step f3, the plaintext data is fed back.

[0128] The plaintext data is sent to the request initiator of the data acquisition request.

[0129] The technical scheme of the embodiment of the present application realizes the function of trusted application data migration of the trusted data space based on the trusted virtual machine technology of the security chip, specifically, after the environment verification of the trusted execution environment of both parties, a data key acquisition request is sent to the second trusted application to be migrated, so that the second trusted application generates and feeds back the data key communication cipher text according to the data key acquisition request; an encrypted data acquisition request is sent to the second trusted application, so that the second trusted application generates and feeds back the encrypted data according to the encrypted data acquisition request, and the data key communication cipher text and the encrypted data are associatedly stored, thereby improving the data migration efficiency and the data storage security. The above technical scheme requires that the trusted application data is stored by using the random key, and then the data encryption key is stored by using the seal key derived based on the trusted execution environment, so that only the unsealing and resealing processing of the trusted application data encryption key is needed during the data migration, and the seamless access and use of the data in the new and old environments are realized.

[0130] Embodiment three

[0131] Figure 3 The flow interaction schematic diagram of the data migration method based on the trusted execution environment provided by the embodiment two of the present application is shown. The embodiment provides a preferred example based on the above embodiment. The first trusted execution environment is a new environment, the second trusted execution environment is an old environment, the purpose is to migrate the data of the second trusted application in the old environment to the new environment, and the specific interaction subjects are the first trusted application in the new environment and the second trusted application in the old environment for the interaction of both parties. As shown in the figure, the specific implementation steps are as follows: Figure 3

[0132] S31, the first trusted application (new environment) sends a remote proof request to the second trusted application (old environment).

[0133] S32, the second trusted application generates a remote authentication report according to the remote proof request.

[0134] Specifically, the second trusted application parses the remote proof request to obtain a random number; the random number is randomly generated by the first trusted application, and the remote proof request is generated based on the random number, so that the random number randomly generated by the first trusted application is carried in the remote proof request. The second trusted application sends an authentication report request and the random number to the application manager; the application manager acquires the running environment report and the integrity information of the second trusted application and carries the random number, attaches the integrity information in the running environment authentication report, signs the report information by using the running environment private key, obtains the remote authentication report, and returns the remote authentication report to the second trusted application.

[0135] ​S33, the second trusted application sends the remote authentication report to the first trusted application.

[0136] S34, the first trusted application performs secure and trusted verification on the remote authentication report, and if the verification is passed, generates a data list acquisition request.

[0137] The first trusted application performs secure and trusted verification on the information in the remote authentication report. Specifically, the first trusted application acquires environment authentication information from the environment authentication service according to the measurement value in the remote authentication report; requests relevant certificates from the Hikvision chip CA (Certificate Authority) according to the chip ID (Identification) in the remote authentication report; and performs secure and trusted verification on the information in the remote authentication report according to the environment authentication information and the relevant certificates.

[0138] S35, the first trusted application sends the data list acquisition request to the second trusted application.

[0139] S36, the second trusted application generates a data list according to the data list acquisition request.

[0140] S37, the second trusted application sends the data list to the first trusted application.

[0141] S38, the first trusted application traverses the data list and generates a data key acquisition request according to the migratable data identifier in the data list.

[0142] S39, the first trusted application sends the data key acquisition request to the second trusted application.

[0143] S310, the second trusted application queries the data key according to the data key acquisition request and acquires the data key seal ciphertext.

[0144] S311, the second trusted application performs unsealing processing on the data key seal ciphertext based on the seal key derived from the device to which the second trusted application belongs, to obtain the data key plaintext.

[0145] S312, the second trusted application encrypts the data key plaintext using a communication key to obtain data key communication ciphertext.

[0146] The communication key is generated by the first trusted execution environment and the second trusted execution environment in advance and is periodically stored in their respective environments.

[0147] S313, the second trusted application sends the data key communication ciphertext to the first trusted application.

[0148] S314, the first trusted application sends an encrypted data acquisition request to the second trusted application.

[0149] S315, the second trusted application acquires encrypted data according to the encrypted data acquisition request.

[0150] S316, the second trusted application sends the encrypted data to the first trusted application.

[0151] S317, the first trusted application stores the data key communication ciphertext and the encrypted data in association.

[0152] Optionally, the first trusted application can also store the data key communication ciphertext and the encrypted data separately, and the embodiment is not limited in this regard.

[0153] Embodiment four

[0154] Figure 4 A structure schematic diagram of a data migration device based on a trusted execution environment provided for the fourth embodiment of the application. The data migration device based on a trusted execution environment provided by the embodiment of the application can be applicable to the case of data migration between trusted applications in the trusted data space under the old and new versions of the security chip, and specifically can be the case of migrating the trusted application data from the old environment to the new environment. The data migration device based on a trusted execution environment can be realized in the form of hardware and / or software. The data migration device based on a trusted execution environment can be configured in the first trusted application in the first trusted execution environment, as shown in the figure. Specifically, the device comprises: a proof request sending module 401, a security verification module 402, an acquisition request sending module 403 and a data storage module 404. Among them, Figure 4

[0155] The proof request sending module 401 is configured to send a remote proof request to a second trusted application in a second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote proof request.

[0156] The security verification module 402 is configured to perform security and trusted verification on the remote authentication report, and after the verification is passed, send a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext according to the data key acquisition request.

[0157] The acquisition request sending module 403 is configured to send an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request.

[0158] ​The data storage module 404 is configured to store the data key communication cipher text and the encrypted data in association.

[0159] The technical scheme of the embodiment of the application realizes the function of data migration of the trusted application program in the trusted data space based on the trusted virtual machine technology of the security chip, specifically, after the environment verification of the trusted execution environment of both parties, a data key acquisition request is sent to the second trusted application program to be migrated, so that the second trusted application program generates and feeds back the data key communication cipher text according to the data key acquisition request; an encrypted data acquisition request is sent to the second trusted application program, so that the second trusted application program generates and feeds back the encrypted data according to the encrypted data acquisition request, the data key communication cipher text and the encrypted data are stored in association, and the data migration efficiency and the data storage security are improved. The above technical scheme requires that the data of the trusted application program is stored by using a random key, and the data encryption key is stored by using a seal key derived based on the trusted execution environment, so that only the unsealing and resealing processing of the data encryption key of the trusted application program is needed during data migration, and seamless access and use of the data in the new and old environments are realized.

[0160] Optionally, the security verification module 402 comprises:

[0161] The manifest acquisition unit is configured to send a data manifest acquisition request to the second trusted application program, so that the second trusted application program generates and feeds back a data manifest according to the data manifest acquisition request; the data manifest comprises at least one migratable data identifier.

[0162] The key request generation unit is configured to generate a data key acquisition request according to the migratable data identifier in the data manifest.

[0163] The acquisition request sending unit is configured to send the data key acquisition request to the second trusted application program, so that the second trusted application program generates and feeds back the data key communication cipher text according to the data key acquisition request.

[0164] The data key communication cipher text is generated in the following manner:

[0165] The second trusted application program acquires the data key seal cipher text according to the data key acquisition request.

[0166] The data key seal cipher text is unsealed based on the seal key derived based on the device to which the second trusted application program belongs, to obtain the data key plain text.

[0167] The data key plain text is encrypted based on the communication key pre-negotiated with the first trusted execution environment, to obtain the data key communication cipher text.

[0168] Optionally, the apparatus further comprises:

[0169] a decryption processing module, configured to, in response to the data acquisition request, perform decryption processing on the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment, to obtain data key plaintext;

[0170] a data decryption module, configured to perform decryption processing on encrypted data by using the data key plaintext, to obtain plaintext data;

[0171] a plaintext feedback module, configured to feed back the plaintext data.

[0172] Optionally, the apparatus further comprises:

[0173] a seal ciphertext generation module, configured to, after the decryption processing on the data key communication ciphertext based on the communication key previously negotiated with the second trusted execution environment, to obtain data key plaintext, perform encryption processing on the data key plaintext based on a seal key derived from the device to which the apparatus belongs, to obtain data key seal ciphertext;

[0174] a seal ciphertext storage module, configured to store the data key seal ciphertext.

[0175] The data migration apparatus based on a trusted execution environment provided by the embodiments of the present application can perform the data migration method based on a trusted execution environment provided by any of the embodiments of the present application, and has the corresponding functional modules and beneficial effects of the execution method.

[0176] Embodiment five

[0177] Figure 5 A structural schematic diagram of a data migration apparatus based on a trusted execution environment provided by the fifth embodiment of the present application. The data migration apparatus based on a trusted execution environment provided by the embodiments of the present application can be applicable to the case of data migration between trusted application programs in the trusted data space under the old and new versions based on a security chip. Specifically, it can be the case of migrating trusted application program data from an old environment to a new environment. The data migration apparatus based on a trusted execution environment can be realized in the form of hardware and / or software. The data migration apparatus based on a trusted execution environment can be configured in a second trusted application program in a second trusted execution environment, as shown in the figure. The apparatus specifically comprises: a proof request acquisition module 501, an authentication report feedback module 502, a key generation module 503, a data acquisition module 504, and an encrypted data feedback module 505. Among them, Figure 5

[0178] The proof request acquisition module 501 is configured to acquire a remote proof request sent by a first trusted application program in a first trusted execution environment, and generate a remote authentication report according to the remote proof request.​

[0179] The authentication report feedback module 502 is configured to feed back the remote authentication report to the first trusted application, so that the first trusted application performs secure and trusted verification on the remote authentication report, and generates and feeds back a data key acquisition request after verification is passed;

[0180] The key generation module 503 is configured to generate data key communication ciphertext according to the data key acquisition request, and send the data key communication ciphertext to the first trusted application;

[0181] The data acquisition module 504 is configured to acquire an encrypted data acquisition request sent by the first trusted application, and generate encrypted data according to the encrypted data acquisition request;

[0182] The encrypted data feedback module 505 is configured to send the encrypted data to the first trusted application, so that the first trusted application stores the data key communication ciphertext and the encrypted data in association.

[0183] The technical scheme of the embodiment of the application realizes the function of trusted application data migration in a trusted data space based on the trusted virtual machine technology of a security chip. Specifically, after environment verification of a trusted execution environment of both parties, a data key acquisition request is sent to a second trusted application to be migrated, so that the second trusted application generates and feeds back data key communication ciphertext according to the data key acquisition request. An encrypted data acquisition request is sent to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request. The data key communication ciphertext and the encrypted data are stored in association, which improves the data migration efficiency and data storage security. The above technical scheme requires that the trusted application data is stored by using a random key, and the data encryption key is stored by using a seal key derived based on the trusted execution environment. Therefore, only the unsealing and resealing of the trusted application data encryption key are required during data migration, which realizes seamless access and use of data in new and old environments.

[0184] Optionally, the key generation module 503 comprises:

[0185] The inventory request acquisition unit is configured to acquire a data inventory acquisition request sent by the first trusted application, and generate a data inventory according to the data inventory acquisition request. The data inventory comprises at least one migratable data identifier.

[0186] The inventory sending unit is configured to send the data inventory to the first trusted application, so that the first trusted application generates and feeds back a data key acquisition request according to the migratable data identifier in the data inventory.

[0187] a seal key obtaining unit, configured to obtain a data key seal cipher text according to the data key obtaining request;

[0188] a key unsealing unit, configured to perform unsealing processing on the data key seal cipher text based on a seal key derived by a device to which the key unsealing unit belongs, to obtain data key plain text;

[0189] a communication cipher sending unit, configured to perform encryption processing on the data key plain text based on a communication key pre-agreed with the first trusted execution environment, to obtain data key communication cipher text, and send the data key communication cipher text to the first trusted application.

[0190] Optionally, the attestation request obtaining module 501 comprises:

[0191] a random number generating unit, configured to determine a random number according to the remote attestation request;

[0192] a random number sending unit, configured to send the authentication report request and the random number to the application manager, so that the application manager generates a remote authentication report according to the authentication report request and the random number, and feeds back the remote authentication report to the second trusted application.

[0193] The data migration apparatus based on the trusted execution environment provided in the embodiments of the present application can execute the data migration method based on the trusted execution environment provided in any of the embodiments of the present application, and has the corresponding function modules and beneficial effects of the execution method.

[0194] Embodiment six

[0195] Figure 6 A structural schematic diagram of an electronic device 60 that can be used to implement embodiments of the present application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown herein, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the present application described and / or claimed in this document.

[0196] As Figure 6As shown, the electronic device 60 includes at least one processor 61, and a memory, such as a read-only memory (ROM) 62, a random access memory (RAM) 63, etc., communicatively connected to the at least one processor 61, where the memory stores computer programs executable by the at least one processor. The processor 61 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 62 or loaded from the storage unit 68 into the random access memory (RAM) 63. Various programs and data required for the operation of the electronic device 60 can also be stored in the RAM 63. The processor 61, the ROM 62, and the RAM 63 are connected to each other through a bus 64. An input / output (I / O) interface 65 is also connected to the bus 64.

[0197] Various components in the electronic device 60 are connected to the I / O interface 65, including an input unit 66, such as a keyboard, a mouse, etc., an output unit 67, such as various types of displays, a speaker, etc., a storage unit 68, such as a magnetic disk, an optical disk, etc., and a communication unit 69, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 69 allows the electronic device 60 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0198] The processor 61 can be various general and / or special purpose processing components with processing and computing capabilities. Some examples of the processor 61 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 61 performs various methods and processes described above, such as the data migration method based on the trusted execution environment.

[0199] In some embodiments, the data migration method based on the trusted execution environment can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 68. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 60 via the ROM 62 and / or the communication unit 69. When the computer program is loaded onto the RAM 63 and executed by the processor 61, one or more steps of the data migration method based on the trusted execution environment described above can be performed. Alternatively, in other embodiments, the processor 61 can be configured to perform the data migration method based on the trusted execution environment by any other appropriate means, such as by means of firmware.

[0200] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0201] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions defined in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.

[0202] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0203] To provide for interaction with a user, the systems and techniques described here can be implemented on an electronic device having a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the electronic device. Other kinds of devices can be used to provide for interaction with a user as well; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form, including acoustic, speech, or tactile input.

[0204] The systems and techniques described here can be implemented in a computing system that includes a back end component (e.g., as a data server), or that includes a middleware component (e.g., an application server), or that includes a front end component (e.g., a user computer having a graphical user interface or a Web browser through which a user can interact with an implementation of the systems and techniques described here), or any combination of such back end, middleware, or front end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0205] The computing system can include clients and servers. A client and server are generally remote from each other and typically interact through a communication network. The relationship of client and server arises by virtue of computer programs running on the respective computers and having a client-server relationship to each other. A server can be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system, to solve the defects of large management difficulty and weak business scalability in traditional physical host and VPS service.

[0206] It should be understood that the various forms of flow shown above can be re-ordered, added to, or deleted from without departing from the scope of the present disclosure. For example, the steps recited in the present disclosure can be executed in parallel, executed in sequence, or executed in a different order, as long as the desired results of the present disclosure are achieved, and the present disclosure is not limited herein.

[0207] The specific embodiments described above are not intended to be limiting, and persons skilled in the art will appreciate that various modifications, combinations, sub-combinations and alternatives can be made to the specific embodiments without departing from the spirit and principles of the disclosure. Accordingly, the disclosure is not limited to the specific embodiments described above, but only by the scope of the appended claims.

Claims

1. A data migration method based on a trusted execution environment in a trusted data space, characterized in that: A first trusted application program applied in the first trusted execution environment includes: Sending a remote attestation request to a second trusted application in the second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote attestation request; Performing security and trustworthy verification on the remote attestation report, and after passing the verification, sending a data list acquisition request to the second trusted application, so that the second trusted application generates and returns a data list according to the data list acquisition request; the data list includes at least one migratable data identifier; Generate a data key acquisition request based on the migratable data identifier in the data list; Sending the data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext according to the data key acquisition request; Sending an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request; storing the data key communication ciphertext and the encrypted data in association with each other; The data key communication ciphertext is generated as follows: The second trusted application obtains the data key seal ciphertext according to the data key acquisition request; Decrypting the data key ciphertext based on the sealing key derived from the device to which it belongs to obtain the data key plaintext; Based on the communication key pre-negotiated with the first trusted execution environment, the data key plaintext is encrypted to obtain a data key communication ciphertext.

2. The method according to claim 1, characterized in that The method further comprises: In response to the data acquisition request, decrypting the data key communication ciphertext based on the communication key pre-negotiated with the second trusted execution environment to obtain the data key plaintext; Decrypting the encrypted data using the data key plaintext to obtain plaintext data; The plaintext data is fed back.

3. The method according to claim 2, characterized in that After decrypting the data key communication ciphertext based on the communication key pre-negotiated with the second trusted execution environment to obtain the data key plaintext, the method further includes: Encrypt the data key plaintext based on the sealing key derived from the device to which it belongs to obtain the data key sealing ciphertext; The data key seal ciphertext is stored.

4. A data migration method based on a trusted execution environment in a trusted data space, characterized in that: The second trusted application program applied in the second trusted execution environment includes: Obtaining a remote attestation request sent by a first trusted application in a first trusted execution environment, and generating a remote authentication report based on the remote attestation request; Feedback the remote authentication report to the first trusted application, so that the first trusted application can perform security and trustworthiness verification on the remote authentication report, and after the verification is successful, generate and feedback a data key acquisition request; Obtaining a data list acquisition request sent by the first trusted application, and generating a data list according to the data list acquisition request; the data list includes at least one migratable data identifier; Sending the data list to the first trusted application, so that the first trusted application generates and feeds back a data key acquisition request based on the migratable data identifier in the data list; Obtaining the data key seal ciphertext according to the data key acquisition request; Decrypting the data key ciphertext based on the sealing key derived from the device to which it belongs to obtain the data key plaintext; Encrypting the data key plaintext based on the communication key pre-negotiated with the first trusted execution environment to obtain data key communication ciphertext, and sending the data key communication ciphertext to the first trusted application; Obtaining an encrypted data acquisition request sent by the first trusted application, and generating encrypted data according to the encrypted data acquisition request; The encrypted data is sent to the first trusted application so that the first trusted application can associate and store the data key communication ciphertext with the encrypted data.

5. The method according to claim 4, characterized in that Generating a remote authentication report according to the remote attestation request includes: Determining a random number based on the remote attestation request; An authentication report request and the random number are sent to the application manager, so that the application manager generates a remote authentication report according to the authentication report request and the random number, and feeds the remote authentication report back to the second trusted application.

6. A data migration device based on a trusted execution environment in a trusted data space, characterized in that: A first trusted application configured in a first trusted execution environment includes: an attestation request sending module, configured to send a remote attestation request to a second trusted application in a second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote attestation request; a security verification module, configured to perform security and trustworthiness verification on the remote authentication report, and, upon passing the verification, send a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext based on the data key acquisition request; an acquisition request sending module, configured to send an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request; A data storage module, used for storing the data key communication ciphertext and the encrypted data in association; Among them, the security verification module includes: a list acquisition unit, configured to send a data list acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data list according to the data list acquisition request; the data list includes at least one migratable data identifier; a key request generating unit, configured to generate a data key acquisition request according to the migratable data identifier in the data list; an acquisition request sending unit, configured to send the data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back a data key communication ciphertext according to the data key acquisition request; The data key communication ciphertext is generated as follows: The second trusted application obtains the data key seal ciphertext according to the data key acquisition request; Decrypting the data key ciphertext based on the sealing key derived from the device to which it belongs to obtain the data key plaintext; Based on the communication key pre-negotiated with the first trusted execution environment, the data key plaintext is encrypted to obtain a data key communication ciphertext.

7. A data migration device based on a trusted execution environment in a trusted data space, characterized in that: The second trusted application configured in the second trusted execution environment includes: an attestation request obtaining module, configured to obtain a remote attestation request sent by a first trusted application in a first trusted execution environment, and generate a remote authentication report according to the remote attestation request; an authentication report feedback module, configured to feed back the remote authentication report to the first trusted application, so that the first trusted application can perform security and trustworthiness verification on the remote authentication report, and generate and feed back a data key acquisition request after the verification is passed; a key generation module, configured to generate a data key communication ciphertext according to the data key acquisition request, and send the data key communication ciphertext to the first trusted application; a data acquisition module, configured to acquire the encrypted data acquisition request sent by the first trusted application, and generate encrypted data according to the encrypted data acquisition request; an encrypted data feedback module, configured to send the encrypted data to the first trusted application, so that the first trusted application can associate and store the data key communication ciphertext with the encrypted data; The key generation module includes: a list request obtaining unit, configured to obtain a data list obtaining request sent by the first trusted application, and generate a data list according to the data list obtaining request; the data list includes at least one migratable data identifier; a list sending unit, configured to send the data list to the first trusted application, so that the first trusted application generates and feeds back a data key acquisition request based on the migratable data identifier in the data list; A seal key acquisition unit, configured to acquire the data key seal ciphertext according to the data key acquisition request; A key deseal unit is used to deseal the data key ciphertext based on the sealing key derived from the device to which it belongs, to obtain the data key plaintext; The communication ciphertext sending unit is used to encrypt the data key plaintext based on the communication key pre-negotiated with the first trusted execution environment to obtain the data key communication ciphertext, and send the data key communication ciphertext to the first trusted application.

8. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the data migration method based on a trusted execution environment in a trusted data space as described in any one of claims 1-3 and / or 4-5.

9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the data migration method based on a trusted execution environment in a trusted data space according to any one of claims 1-3 and / or 4-5 when executed.

10. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the data migration method based on a trusted execution environment in a trusted data space according to any one of claims 1-3 and / or 4-5.

Citation Information

Patent Citations

  • Remote proving method and system for trusted application in data space

    CN118784359A