Secret key management method, related device and storage medium
By storing and verifying the key credentials of third-party trusted applications in a trusted execution environment, the problem of insufficient security when TA generates and manages keys by itself is solved, and higher key security and cryptographic operation security is achieved.
Patent Information
- Application Number
- CN202510288726.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-05-02
AI Technical Summary
In a Trusted Execution Environment (TEE), third-party trusted applications (TAs) lack unified specifications when generating and managing keys themselves, resulting in a reduction in the security of keys, which in turn affects the security of TAs performing cryptographic operations.
Provide a secret key management method, including storing the key generated by a third-party trusted application request and its key credentials, obtaining and verifying the key credentials in the cryptographic operation request, performing cryptographic operations only when the authorization management information is verified, and feeding the operation results to the third-party trusted application.
By uniformly standardizing the generation and management of keys, the security of keys in TEE is improved, thereby improving the security of TA's cryptographic operations.
Smart Images

Figure CN119921949A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and specifically relates to a key management method, related devices and storage media. Background Art
[0002] In today's information security field, Trusted Execution Environment (TEE) technology has become a core means to protect sensitive data and perform security operations. TEE creates an isolated execution environment in the device's processor to ensure that the code and data running inside it are protected from interference from external attacks. In TEE, the trusted application (TA) is the core component for performing security tasks. It needs to complete a variety of cryptographic operations such as symmetric encryption, asymmetric encryption, digital signatures, and hash calculations to ensure the confidentiality, integrity, and authenticity of the data. Due to the security of TA, client applications (CA) running on a rich execution environment (REE) operating system can call TA through the TEE API to perform cryptographic operations (for example, encrypting encrypted information requested by CA). To achieve these functions, dedicated cryptographic libraries (such as mbedtls) can be integrated into TEE. These libraries are optimized to adapt to the restricted resource environment of TEE. In addition, mainstream TEE frameworks also provide built-in encryption APIs for TA to directly call cryptographic libraries to implement cryptographic operations. However, TAs call cryptographic libraries separately to implement cryptographic operations, resulting in a lack of unified standards for key generation and management. Many TAs fail to adopt adequate protection mechanisms when generating and managing keys on their own, which reduces the security of keys in TEE and further reduces the security of TA's cryptographic operations. Summary of the invention
[0003] In view of the above problems, the present disclosure provides a key management method, related devices and storage media, aiming to improve the security of keys in TEE, and thereby improve the security of TA performing cryptographic operations.
[0004] According to a first aspect of the present disclosure, a key management method applied to a trusted execution environment is provided, the key management method comprising:
[0005] Storing the key generated by the third-party trusted application, and providing the key certificate of the key to the corresponding third-party trusted application, wherein the key certificate includes a key identifier and authorization management information;
[0006] Obtaining a cryptographic operation request sent by a third-party trusted application, wherein the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request;
[0007] If the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorizing the key corresponding to the cryptographic operation request to perform the cryptographic operation;
[0008] The operation result of performing the cryptographic operation on the key corresponding to the cryptographic operation request is fed back to the corresponding third-party trusted application.
[0009] Optionally, after storing the key generated by the request of the third-party trusted application and providing the key certificate of the key to the corresponding third-party trusted application, the key management method further includes:
[0010] Obtaining a key destruction request sent by a third-party trusted application, wherein the key destruction request includes a key credential of a key corresponding to the key destruction request;
[0011] When the identity authentication of the third-party trusted application is qualified and the authorization management information in the key certificate of the key corresponding to the key destruction request is verified to be qualified, the key corresponding to the key destruction request is destroyed.
[0012] Optionally, storing the key generated by the third-party trusted application and providing the key certificate of the key to the corresponding third-party trusted application includes:
[0013] Obtain a key generation request sent by a third-party trusted application;
[0014] When the identity authentication of the third-party trusted application is qualified, a key is generated and a key credential is set for the key;
[0015] The key certificate of the key is fed back to the corresponding third-party trusted application.
[0016] Optionally, the authorization management information includes first authorization management information related to an operating environment and second authorization management information related to a cryptographic operation, and if the authorization management information in a key certificate of a key corresponding to the cryptographic operation request is verified to be qualified, authorizing the cryptographic operation request to perform a cryptographic operation on the key corresponding to the cryptographic operation request includes:
[0017] If the identity authentication of the third-party trusted application is qualified, verifying whether the first authorization management information is qualified;
[0018] When the first authorization management information is verified to be qualified, preparing an operating environment corresponding to the cryptographic operation in the trusted execution environment;
[0019] Verify whether the second authorization management information is qualified, and if the verification is qualified, authorize the cryptographic operation request to perform a cryptographic operation with the corresponding key.
[0020] Optionally, the first authorization management information includes: a label for indicating a version number and a patch level of a rich execution environment operating system, and / or a label for indicating a version number and a patch level of a trusted execution environment operating system, and in the case where the identity authentication of the third-party trusted application is qualified, verifying whether the first authorization management information is qualified includes:
[0021] If the identity authentication of the third-party trusted application is qualified, verify whether the current actual version number and patch level of the rich execution environment operating system matches the tag value recorded in the first authorization management information; and / or
[0022] When the identity authentication of the third-party trusted application is qualified, it is verified whether the current actual version number and patch level of the trusted execution environment operating system match the tag value recorded in the first authorization management information.
[0023] Optionally, the second authorization management information includes: a label for indicating a boot lock state of the device, and / or a label for indicating that the key will be changed or reinitialized each time the device is restarted, and / or a label for indicating a unique identity of a third-party trusted application, and the verifying whether the second authorization management information is qualified, and if the verification is qualified, authorizing the cryptographic operation request to perform a cryptographic operation on the corresponding key, includes:
[0024] Verifying whether the startup state of the device is locked, and if the startup state of the device is locked, authorizing the cryptographic operation request to perform a cryptographic operation using a corresponding key; and / or
[0025] If the device has been restarted, verify whether the device is in a startup state, and if the device is in a startup state, authorize the cryptographic operation request to perform a cryptographic operation on a key corresponding to the cryptographic operation request; and / or
[0026] Verify whether the identity of the third-party trusted application that sends the cryptographic operation request matches the tag value recorded in the second authorization management information. If they match, authorize the cryptographic operation request to perform a cryptographic operation on the key corresponding to the cryptographic operation request.
[0027] According to a second aspect of the present disclosure, there is provided a key management device applied to a trusted execution environment, the key management device comprising:
[0028] A key generation unit, used to store the key generated by the third-party trusted application, and provide the key certificate of the key to the corresponding third-party trusted application, wherein the key certificate includes a key identifier and authorization management information;
[0029] A cryptographic operation request acquisition unit, configured to acquire a cryptographic operation request sent by a third-party trusted application, wherein the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request;
[0030] an authorization management information verification unit, configured to, if the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorize the key corresponding to the cryptographic operation request to perform the cryptographic operation;
[0031] The operation result feedback unit is used to feed back the operation result of the cryptographic operation performed on the key corresponding to the cryptographic operation request to the corresponding third-party trusted application.
[0032] According to a third aspect of the present disclosure, a trusted execution environment is provided, including:
[0033] A third-party trusted application, used to receive a cryptographic operation request from a client application to call the third-party trusted application to perform a cryptographic operation;
[0034] The service-type trusted application is used to authorize the cryptographic operation request to perform cryptographic operations on the corresponding key according to the steps of any of the methods described above, and to feed back the operation results to the corresponding third-party trusted application.
[0035] According to a fourth aspect of the present disclosure, an electronic device is provided, comprising: a processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the steps of any of the methods described above when executed by the processor.
[0036] According to a fourth aspect of the present disclosure, a storage medium is provided, on which a computer program or instruction is stored, and when the computer program or instruction is executed by a processor, the steps of any of the methods described above are implemented.
[0037] The present disclosure brings the following beneficial effects:
[0038] The key management method provided by the present invention stores the key generated by the request of the third-party trusted application, provides the key certificate of the key to the corresponding third-party trusted application, the key certificate includes the key identifier and authorization management information, obtains the cryptographic operation request sent by the third-party trusted application, the cryptographic operation request includes the key certificate of the key corresponding to the cryptographic operation request, and when the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorizes the cryptographic operation request to perform the cryptographic operation on the key corresponding to the cryptographic operation request, and feeds back the operation result of the cryptographic operation on the key corresponding to the cryptographic operation request to the corresponding third-party trusted application. During the entire life cycle of the key, the key is generated and managed in a unified and standardized manner for all third-party trusted applications, and only the key certificate of the key and the operation result of the cryptographic operation are provided to the third-party trusted application, and the key material is not exposed to the third-party trusted application, which improves the security of the key in the TEE, and further improves the security of the TA performing cryptographic operations.
[0039] Other features and advantages of the present disclosure will be described in the following description, and partly become apparent from the description, or understood by practicing the present disclosure. The purpose and other advantages of the present disclosure are realized and obtained by the structures particularly pointed out in the description and the drawings.
[0040] In order to make the above-mentioned objectives, features and advantages of the present disclosure more obvious and easy to understand, preferred embodiments are specifically cited below and described in detail with reference to the attached drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] The above and other objects, features and advantages of the present disclosure will become more apparent through the following description of the embodiments of the present disclosure with reference to the accompanying drawings, in which:
[0042] Figure 1 A schematic diagram of the structure of a trusted service system provided according to an embodiment of the present disclosure;
[0043] Figure 2 A schematic diagram of the structure of an intelligent terminal in a trusted service system provided according to an embodiment of the present disclosure;
[0044] Figure 3 A flowchart of a key management method applied to a trusted execution environment provided according to an embodiment of the present disclosure;
[0045] Figure 4 A schematic diagram of a key generation method according to an embodiment of the present disclosure;
[0046] Figure 5 A schematic diagram of a key destruction method according to an embodiment of the present disclosure;
[0047] Figure 6A flowchart of a method for performing cryptographic operations according to an embodiment of the present disclosure is provided;
[0048] Figure 7 A schematic diagram of the structure of a key management device applied to a trusted execution environment provided according to an embodiment of the present disclosure;
[0049] Figure 8 The present invention is a schematic diagram of the structure of an electronic device provided according to an embodiment of the present disclosure. DETAILED DESCRIPTION
[0050] Various embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. In each of the accompanying drawings, the same elements are represented by the same or similar reference numerals. For the sake of clarity, the various parts in the accompanying drawings are not drawn to scale.
[0051] Figure 1 FIG. 2 shows a schematic diagram of a structure of a trusted service system provided according to an embodiment of the present disclosure. Figure 1 As shown, the trusted service system 1000 provided by the embodiment of the present disclosure includes a plurality of mobile terminals 100 and a plurality of third-party service servers 200 connected via a network.
[0052] The third-party service server 200 is a dedicated computer system provided by a service provider (Service Provider, abbreviated as SP) to provide third-party service services to mobile terminals in a network environment. The third-party service server 200 includes but is not limited to a CISC (complex instruction set) architecture server, a RISC (reduced instruction set) architecture server, and an EPIC architecture server. Third-party services include, for example, online banking, online commerce, online education, online voting, etc. It can be understood that the data security of the third-party service server 200 is extremely important.
[0053] The mobile terminal 100 is a communication device that can be used in a mobile state. The mobile terminal 100 includes but is not limited to mobile phones, mobile computers, tablet computers, personal digital assistants (PDAs), media players, smart TVs, smart watches, smart glasses, smart bracelets, smart cars and vehicle-mounted terminals, etc. The mobile terminal 100 supports multiple third-party service providers, that is, multiple third-party service servers 200. In the application scenario of the mobile shield, the mobile terminal 100 is, for example, a smart phone used by a user, the service provider of the third-party service server 200 is, for example, a bank, and the third-party service is, for example, a mobile payment service provided by the bank. Therefore, a dedicated trusted application of the bank needs to be deployed in the mobile phone. The services supported by the dedicated trusted application include: encryption and decryption services, signature verification services, trusted input services, trusted display services, digital certificate management and signature verification functions, etc.
[0054] Figure 2 FIG. 1 is a schematic diagram of the structure of an intelligent terminal in a trusted service system provided according to an embodiment of the present disclosure. Figure 2 As shown, the operating environment of the smart terminal 100 provided in the embodiment of the present disclosure includes a rich execution environment (REE) 110 , a trusted execution environment (TEE) 120 , and a secure element (SE) 130 .
[0055] In some embodiments, REE 110 is the main operating environment of the smart terminal 100, responsible for handling most user interactions and the operation of conventional applications. REE 100 can be divided into user state and kernel state, and a rich execution environment operating system (Rich Operating System, ROS) 111 and a client application (Client Application, CA) 112 are deployed in the user state. ROS 111 is the core operating system of REE 110, such as Android or iOS, responsible for managing resources and applications in the user state. CA 112 is an application that the user interacts directly with, such as various third-party applications (such as banking applications, payment applications, etc.). CA 112 communicates with a third-party trusted application (Trusted Application, TA) 123 in TEE 120 through the TEE client API to implement security functions.
[0056] In some embodiments, TEE 120 is a secure environment isolated from REE 110, providing higher security and isolation, and is used to process sensitive data and perform security-related operations. TEE 120 can also be divided into user mode and kernel mode. A trusted execution environment operating system (Trusted Operating System, TOS) 121, a third-party TA 123, and a service-type TA (also known as TEE enhanced key library service-type trusted application, referred to as ETCS ServiceTA in English) 123 are deployed in the user mode, and a cryptographic library (such as mbedtls) 124 is deployed in the kernel mode. TOS 121 is the core operating system of TEE 120, responsible for managing resources and applications in TEE 120. Third-party TA 123 is a security application running in TEE 120, corresponding to CA 112 in REE 110. The main function of service-type TA 122 is to be responsible for the authorization management, verification and execution of cryptographic operations of keys, and to provide support for various cryptographic algorithm libraries in TEE, and can generate and manage keys in a unified and standardized manner for all third-party TA 123. In some embodiments, a service-type binary interface library (Service Lib) is also provided in TEE 120. The service-type binary interface library provides a binary interface in the form of a static library, which is mainly used to transfer the service request of the third-party TA 123 to the service-type TA 122 and pass the corresponding data. In some embodiments, the third-party TA 123 can receive a cryptographic operation request from CA 112 to call the third-party TA 123 to perform a cryptographic operation. It can be understood that cryptographic operations can include security-related tasks, such as encryption and decryption services, signature verification services, trusted input services, trusted display services, digital certificate management and signature verification functions. The service-type TA 122 can authorize the cryptographic operation request to perform a cryptographic operation on the corresponding key according to the key management method provided in the embodiment of the present disclosure, and feed back the operation results to the corresponding third-party TA 123.
[0057] In some embodiments, the cryptography library 124 is a library that provides encryption and decryption functions to support security operations in TEE 120. The cryptography library 124 can provide a variety of encryption algorithms, such as AES, RSA, ECC, etc., to ensure the security and integrity of data. In some embodiments, SE 130 is an independent security chip or module that provides hardware-level security protection. SE 130 is generally used to store and process high-security data, such as private keys, certificates, etc. SE 130 interacts with TEE 120 through a secure communication interface to achieve a higher level of security.
[0058] Figure 3FIG. 1 is a flow chart of a key management method applied to a trusted execution environment according to an embodiment of the present disclosure. The key management method in the embodiment of the present disclosure may be executed by the service-type TA 122. Figure 3 As shown, the key management method includes:
[0059] In step S310, the key generated by the third-party trusted application is stored, and a key certificate of the key is provided to the corresponding third-party trusted application, wherein the key certificate includes a key identifier and authorization management information.
[0060] In some embodiments, the service-type TA 122 obtains a key generation request sent by the third-party TA 123, generates a key, sets a key credential for the key, and feeds back the key credential of the key to the corresponding third-party TA 123 when the identity authentication of the third-party TA 123 is qualified. For example, the service-type TA 122 can use the client identity authentication mechanism (client Identity) provided by TOS 121 to safely and reliably verify the identity of the caller, thereby enhancing the security of the system. In some embodiments, the key credential of the key includes a key identifier and authorization management information. It can be understood that the key identifier is used to identify the key. The authorization management information is used to limit the operating environment and specific cryptographic operation steps of the cryptographic operation corresponding to the cryptographic operation request executed in TEE 120.
[0061] In some embodiments, the service-type TA 122 obtains a key destruction request sent by the third-party TA 123, wherein the key destruction request includes a key certificate of a key corresponding to the key destruction request. If the identity authentication of the third-party TA 123 is qualified and the authorization management information in the key certificate of the key corresponding to the key destruction request is verified to be qualified, the key corresponding to the key destruction request is destroyed, for example, the key corresponding to the key destruction request is deleted in a secure storage area.
[0062] In step S320, a cryptographic operation request sent by a third-party trusted application is obtained, where the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request.
[0063] In some embodiments, after receiving the cryptographic operation request from CA 112 to call the third-party TA 123 to perform a cryptographic operation, the third-party TA 123 may send the cryptographic operation request (e.g., encrypting the encrypted information requested to be encrypted by CA 112) to the service-type TA 122. It is understandable that cryptographic operations may include security-related tasks, such as encryption and decryption services, signature verification services, trusted input services, trusted display services, digital certificate management, and signature verification functions. In some embodiments, after the service-type TA 122 obtains the cryptographic operation request sent by the third-party TA 123, it may extract the key identifier and authorization management information of the corresponding key from the key certificate.
[0064] In step S330, if the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, the cryptographic operation request is authorized to perform the cryptographic operation on the key corresponding to the cryptographic operation request.
[0065] In some embodiments, the authorization management information includes first authorization management information related to the operating environment and second authorization management information related to the cryptographic operation. When the identity authentication of the third-party TA 123 is qualified, the service-type TA 122 verifies whether the first authorization management information is qualified, and when the first authorization management information is verified to be qualified, prepares the operating environment corresponding to the cryptographic operation in the TEE 120, verifies whether the second authorization management information is qualified, and when the verification is qualified, authorizes the cryptographic operation request to perform the cryptographic operation corresponding to the key.
[0066] In some embodiments, the first authorization management information includes: a tag EK_TAG_REE_OS_VERSION for indicating the version number of the rich execution environment operating system and a tag EK_TAG_REE_OS_PATCH_LEVEL for indicating the patch level, and / or a tag EK_TAG_TEE_OS_VERSION for indicating the version number of the trusted execution environment operating system and a tag EK_TAG_TEE_OS_PATCH_LEVEL for indicating the patch level. It should be noted that EK_TAG_REE_OS_VERSION indicates the version of the rich execution environment operating system that the key corresponding to the cryptographic operation request requires and depends on when performing cryptographic operations. The key can only be used to perform cryptographic operations under the version of the rich execution environment operating system represented by EK_TAG_REE_OS_VERSION, which can ensure the compatibility and security of the rich execution environment operating system. It should be noted that EK_TAG_REE_OS_PATCH_LEVEL indicates the patch level of the rich execution environment operating system that the key corresponding to the cryptographic operation request requires and relies on when performing cryptographic operations. The key can only be used for cryptographic operations at the patch level of the rich execution environment operating system represented by EK_TAG_REE_OS_PATCH_LEVEL, which helps to ensure the consistency and security of cryptographic operations at different patch levels. It should be noted that EK_TAG_TEE_OS_VERSION indicates the version of the trusted execution environment operating system that the key corresponding to the cryptographic operation request requires and relies on when performing cryptographic operations. The key can only be used for cryptographic operations at the version of the trusted execution environment operating system represented by EK_TAG_TEE_OS_VERSION, which can ensure the compatibility and security of the trusted execution environment operating system. It should be noted that EK_TAG_TEE_OS_PATCH_LEVEL indicates the patch level of the trusted execution environment operating system that the key corresponding to the cryptographic operation request requires and relies on when performing cryptographic operations. The key can only be used for cryptographic operations at the patch level of the trusted execution environment operating system represented by EK_TAG_TEE_OS_PATCH_LEVEL, which helps ensure the security of the trusted execution environment that performs cryptographic operations and that it has been patched to the latest level.
[0067] In some embodiments, when the first authorization management information includes EK_TAG_REE_OS_VERSION and EK_TAG_REE_OS_PATCH_LEVEL, the service-type TA 122 verifies whether the current actual version number and patch level of the rich execution environment operating system match the tag value recorded in the first authorization management information (i.e., EK_TAG_REE_OS_VERSION and EK_TAG_REE_OS_PATCH_LEVEL) when the identity authentication of the third-party TA 123 is qualified. If they match, the first authorization management information (i.e., EK_TAG_REE_OS_VERSION and EK_TAG_REE_OS_PATCH_LEVEL) is confirmed to be qualified. This can ensure that the corresponding key can only be executed under a specific operating system version and security patch, avoiding security vulnerabilities caused by malicious rollback or environment tampering. In some embodiments, when the first authorization management information includes EK_TAG_TEE_OS_PATCH_LEVEL and EK_TAG_TEE_OS_PATCH_LEVEL, the service-type TA 122 verifies whether the current actual version number and patch level of the trusted execution environment operating system matches the tag value recorded in the first authorization management information (i.e., EK_TAG_TEE_OS_PATCH_LEVEL and EK_TAG_TEE_OS_PATCH_LEVEL) when the identity authentication of the third-party TA 123 is qualified. If they match, it is confirmed that the first authorization management information (i.e., EK_TAG_TEE_OS_PATCH_LEVEL and EK_TAG_TEE_OS_PATCH_LEVEL) is qualified. When each cryptographic operation is executed, the consistency of the current trusted execution environment and the preset tags in the first authorization management information will be dynamically verified. If it is detected that the operating environment does not meet the requirements, the relevant cryptographic operation will be automatically rejected to ensure that the key operation is always performed in a trusted environment.
[0068] In some embodiments, the second authorization management information includes: a tag EK_TAG_DEVICE_BOOT_LOCKED for indicating the boot lock state of the device, and / or a tag EK_TAG_PER_BOOT_LIMITED for indicating that the key will be changed or reinitialized after each device restart, and / or a tag EK_TAG_UTA_UUID for indicating the unique identity of a third-party trusted application. It should be noted that the terminal device may take certain security measures when booting, such as locking the boot program to prevent unauthorized booting, ensuring that the device is started in a trusted environment and preventing attacks. EK_TAG_DEVICE_BOOT_LOCKED indicates that the key corresponding to the cryptographic operation request is only valid when the boot of the device is locked (for example, hardware encryption protection measures have been taken when the device is started). It should be noted that EK_TAG_PER_BOOT_LIMITED indicates that the key corresponding to the cryptographic operation request is subject to each device startup limit, that is, the key will be changed or reinitialized after each device restart, which helps to enhance the security of the device in different startup cycles. It should be noted that EK_TAG_UTA_UUID (Universally Unique Identifier) identifies the unique third party TA123 associated with the key corresponding to the cryptographic operation request, indicating that the key is limited to the use of the third party TA 123 specified by the tag.
[0069] In some embodiments, when the second authorization management information includes EK_TAG_DEVICE_BOOT_LOCKED, the service TA 122 verifies whether the boot state of the device is locked, and if the boot state of the device is locked, the service TA 122 authorizes the cryptographic operation request to perform the cryptographic operation on the corresponding key. In some embodiments, when the second authorization management information includes EK_TAG_PER_BOOT_LIMITED, the service TA 122 verifies whether the device is in the boot state if the device has been restarted, and if the device is in the boot state, the service TA 122 authorizes the cryptographic operation request to perform the cryptographic operation on the corresponding key. In some embodiments, when the second authorization management information includes EK_TAG_UTA_UUID, the service TA 122 verifies whether the identity of the third party TA 123 that sends the cryptographic operation request matches the tag value recorded in the second authorization management information (i.e., EK_TAG_UTA_UUID), and if they match, the service TA 122 authorizes the cryptographic operation request to perform the cryptographic operation on the corresponding key.
[0070] It is understandable that the authorization management information can be expanded and configured. For example, the authorization management information can also include a tag for recording the number of times the key performs cryptographic operations and a tag indicating the hardware device required and relied on by the key corresponding to the cryptographic operation request when performing the cryptographic operation. It supports key authorization management by binding different tags, and can flexibly adjust the key authorization policy according to different usage scenarios. The authorization management mechanism can provide fine-grained control over a single key to ensure that the use of the key does not exceed the authorized scope, thereby greatly improving the flexibility and configurability of key management.
[0071] In step S340, the result of performing the cryptographic operation on the key corresponding to the cryptographic operation request is fed back to the corresponding third-party trusted application.
[0072] In some embodiments, the service-type TA 122 feeds back the operation result of the cryptographic operation on the key corresponding to the cryptographic operation request to the corresponding third-party TA 123. It can be understood that during the entire life cycle of the key, the service-type TA 122 uniformly and standardizedly generates and manages the key for all third-party TAs 123, and only provides the key certificate of the key and the operation result of the cryptographic operation to the third-party TA 123, and the key material is not exposed to the third-party TA 123, which improves the security of the key in the TEE, and further improves the security of the TA performing cryptographic operations.
[0073] Figure 4 FIG. 1 is a flow chart of a key generation method according to an embodiment of the present disclosure. The key generation method in the embodiment of the present disclosure may be executed by the service-type TA 122. Figure 4 As shown, the key generation method includes:
[0074] In step S410 , a key generation request sent by the third party TA 123 is received.
[0075] In step S420, it is verified whether the identity of the third party TA 123 is qualified. If qualified, step S430 is executed. If not qualified, the process ends.
[0076] In step S430, a key is generated and a key credential is set for the key.
[0077] In step S440 , the key certificate of the key is fed back to the corresponding third party TA 123 .
[0078] Since the specific process of key generation has been described in detail above, it will not be repeated here.
[0079] Figure 5FIG. 1 is a flow chart of a key destruction method provided according to an embodiment of the present disclosure. The key destruction method in the embodiment of the present disclosure may be executed by the service-type TA 122. Figure 5 As shown, the key destruction method includes:
[0080] In step S510, a key destruction request sent by the third party TA 123 is obtained, where the key destruction request includes a key certificate of a key corresponding to the key destruction request.
[0081] In step S520, it is verified whether the identity of the third party TA 123 is qualified. If qualified, step S530 is executed. If not qualified, the process ends.
[0082] In step S530, it is verified whether the authorization management information in the key certificate of the key corresponding to the key destruction request is qualified. If qualified, step S540 is executed. If not qualified, the process ends.
[0083] In step S540, the key corresponding to the key destruction request is destroyed, for example, the key corresponding to the key destruction request is deleted in the secure storage area.
[0084] Since the specific process of key destruction has been described in detail above, it will not be repeated here.
[0085] Figure 6 FIG. 1 is a flow chart of a method for performing cryptographic operations according to an embodiment of the present disclosure. The method for performing cryptographic operations in the embodiment of the present disclosure may be performed by the service-type TA 122. Figure 6 As shown, the method for performing cryptographic operations includes:
[0086] In step S610, a cryptographic operation request sent by the third party TA 123 is obtained, where the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request.
[0087] In step S620, it is verified whether the identity of the third party TA 123 is qualified. If qualified, step S630 is executed. If not qualified, the process ends.
[0088] In step S630, it is verified whether the first authorization management information is qualified. If the first authorization management information is qualified, step S640 is executed. If it is not qualified, the process ends.
[0089] In step S640 , an operating environment corresponding to the cryptographic operation is prepared in TEE 120 .
[0090] In step S650, it is verified whether the second authorization management information is qualified. If the verification is qualified, step S660 is executed. If the verification is unqualified, the process ends.
[0091] In step S660, the cryptographic operation request is authorized to perform a cryptographic operation on the corresponding key.
[0092] In step S670 , the result of performing the cryptographic operation on the key corresponding to the cryptographic operation request is fed back to the corresponding third party TA 123 .
[0093] Since the specific process of performing cryptographic operations has been described in detail above, it will not be repeated here.
[0094] Figure 7 FIG. 1 shows a schematic diagram of a key management device for a trusted execution environment according to an embodiment of the present disclosure. The key management device may be located in TEE 120. Figure 7 As shown, the key management device 700 includes a key generation unit 710, a cryptographic operation request acquisition unit 720, an authorization management information verification unit 730 and an operation result feedback unit 740.
[0095] The key generation unit 710 is used to store the key generated by the third-party trusted application and provide the key certificate of the key to the corresponding third-party trusted application. The key certificate includes a key identifier and authorization management information.
[0096] The cryptographic operation request acquisition unit 720 is used to acquire a cryptographic operation request sent by a third-party trusted application, wherein the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request.
[0097] The authorization management information verification unit 730 is used to authorize the cryptographic operation request to perform a cryptographic operation on the key corresponding to the cryptographic operation request if the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified.
[0098] The operation result feedback unit 740 is used to feed back the operation result of performing the cryptographic operation on the key corresponding to the cryptographic operation request to the corresponding third-party trusted application.
[0099] Since the specific process of key management has been described in detail above, it will not be repeated here.
[0100] The present disclosure also provides an electronic device, such as Figure 8As shown, it includes a memory 820, a processor 810, and a program stored in the memory 820 and executable on the processor 810. When the program is executed by the processor 810, each process of each embodiment of the above method can be implemented, and the same technical effect can be achieved. To avoid repetition, it will not be described here.
[0101] Those skilled in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by controlling related hardware through instructions, and the instructions can be stored in a computer-readable storage medium and loaded and executed by a processor. To this end, the embodiments of the present disclosure also provide a storage medium, on which a computer program or instruction is stored, and when the computer program or instruction is executed by the processor, each process of each embodiment of the above method can be implemented.
[0102] Since the instructions stored in the storage medium can execute the steps in the method provided in the embodiment of the present disclosure, the beneficial effects that can be achieved by the method provided in the embodiment of the present disclosure can be achieved. For details, please refer to the previous embodiment, which will not be repeated here. The specific implementation of each of the above operations can be referred to the previous embodiment, which will not be repeated here.
[0103] In summary, according to the embodiments of the present disclosure, the key generated by the request of the third-party trusted application is stored, and the key certificate of the key is provided to the corresponding third-party trusted application, the key certificate includes a key identifier and authorization management information, and the cryptographic operation request sent by the third-party trusted application is obtained, the cryptographic operation request includes the key certificate of the key corresponding to the cryptographic operation request, and when the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, the cryptographic operation request is authorized to perform a cryptographic operation on the key corresponding to the cryptographic operation request, and the operation result of the cryptographic operation on the key corresponding to the cryptographic operation request is fed back to the corresponding third-party trusted application. During the entire life cycle of the secret key, the key generation and management are performed uniformly and standardized for all third-party trusted applications, and only the key certificate of the key and the operation result of the cryptographic operation are provided to the third-party trusted application, and the key material is not exposed to the third-party trusted application, which improves the security of the key in the TEE, and further improves the security of the TA performing cryptographic operations.
[0104] Finally, it should be noted that: Obviously, the above embodiments are only examples for clearly illustrating the present disclosure, and are not intended to limit the implementation methods. For ordinary technicians in the relevant field, other different forms of changes or modifications can be made based on the above description. It is not necessary and impossible to list all the implementation methods here. The obvious changes or modifications derived from this are still within the scope of protection of the present disclosure.
Claims
1. A key management method applied to a trusted execution environment, the key management method comprising: Storing the key generated by the third-party trusted application, and providing the key certificate of the key to the corresponding third-party trusted application, wherein the key certificate includes a key identifier and authorization management information; Obtaining a cryptographic operation request sent by a third-party trusted application, wherein the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request; If the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorizing the key corresponding to the cryptographic operation request to perform the cryptographic operation; The operation result of performing the cryptographic operation on the key corresponding to the cryptographic operation request is fed back to the corresponding third-party trusted application.
2. The key management method according to claim 1, wherein: After storing the key generated by the third-party trusted application and providing the key certificate of the key to the corresponding third-party trusted application, the key management method further includes: Obtaining a key destruction request sent by a third-party trusted application, wherein the key destruction request includes a key credential of a key corresponding to the key destruction request; When the identity authentication of the third-party trusted application is qualified and the authorization management information in the key certificate of the key corresponding to the key destruction request is verified to be qualified, the key corresponding to the key destruction request is destroyed.
3. The key management method according to claim 1, wherein: The storing of the key generated by the third-party trusted application and providing the key certificate of the key to the corresponding third-party trusted application includes: Obtain a key generation request sent by a third-party trusted application; When the identity authentication of the third-party trusted application is qualified, a key is generated and a key credential is set for the key; The key certificate of the key is fed back to the corresponding third-party trusted application.
4. The key management method according to claim 1, wherein: The authorization management information includes first authorization management information related to the operating environment and second authorization management information related to the cryptographic operation, and if the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorizing the cryptographic operation request to perform the cryptographic operation on the key corresponding to the cryptographic operation request includes: If the identity authentication of the third-party trusted application is qualified, verifying whether the first authorization management information is qualified; When the first authorization management information is verified to be qualified, preparing an operating environment corresponding to the cryptographic operation in the trusted execution environment; Verify whether the second authorization management information is qualified, and if the verification is qualified, authorize the cryptographic operation request to perform a cryptographic operation with the corresponding key.
5. The key management method according to claim 4, wherein: The first authorization management information includes: a label for indicating a version number and a patch level label of a rich execution environment operating system, and / or a label for indicating a version number and a patch level label of a trusted execution environment operating system, and in the case where the identity authentication of the third-party trusted application is qualified, verifying whether the first authorization management information is qualified includes: If the identity authentication of the third-party trusted application is qualified, verify whether the current actual version number and patch level of the rich execution environment operating system matches the tag value recorded in the first authorization management information; and / or When the identity authentication of the third-party trusted application is qualified, it is verified whether the current actual version number and patch level of the trusted execution environment operating system match the tag value recorded in the first authorization management information.
6. The key management method according to claim 4, wherein: The second authorization management information includes: a label for indicating a boot lock state of the device, and / or a label for indicating that the key will be changed or reinitialized after each device restart, and / or a label for indicating a unique identity of a third-party trusted application, and the verifying whether the second authorization management information is qualified, and if the verification is qualified, authorizing the cryptographic operation request to perform a cryptographic operation on the corresponding key, including: Verifying whether the startup state of the device is locked, and if the startup state of the device is locked, authorizing the cryptographic operation request to perform a cryptographic operation using a corresponding key; and / or If the device has been restarted, verify whether the device is in a startup state, and if the device is in a startup state, authorize the cryptographic operation request to perform a cryptographic operation on a key corresponding to the cryptographic operation request; and / or Verify whether the identity of the third-party trusted application that sends the cryptographic operation request matches the tag value recorded in the second authorization management information. If they match, authorize the cryptographic operation request to perform a cryptographic operation on the key corresponding to the cryptographic operation request.
7. A key management device applied to a trusted execution environment, the key management device comprising: A key generation unit, used to store the key generated by the third-party trusted application, and provide the key certificate of the key to the corresponding third-party trusted application, wherein the key certificate includes a key identifier and authorization management information; A cryptographic operation request acquisition unit, configured to acquire a cryptographic operation request sent by a third-party trusted application, wherein the cryptographic operation request includes a key certificate of a key corresponding to the cryptographic operation request; an authorization management information verification unit, configured to, if the authorization management information in the key certificate of the key corresponding to the cryptographic operation request is verified to be qualified, authorize the key corresponding to the cryptographic operation request to perform the cryptographic operation; The operation result feedback unit is used to feed back the operation result of the cryptographic operation performed on the key corresponding to the cryptographic operation request to the corresponding third-party trusted application.
8. A trusted execution environment, comprising: A third-party trusted application, used to receive a cryptographic operation request from a client application to call the third-party trusted application to perform a cryptographic operation; A service-type trusted application is used to authorize a cryptographic operation request to perform a cryptographic operation on a corresponding key according to the steps of the method according to any one of claims 1 to 6, and to feed back the operation result to a corresponding third-party trusted application.
9. An electronic device, comprising: A processor, a memory, and a program stored in the memory and executable on the processor, wherein the program implements the steps of the method according to any one of claims 1 to 6 when executed by the processor.
10. A storage medium having a computer program or instruction stored thereon, wherein the computer program or instruction, when executed by a processor, implements the steps of the method according to any one of claims 1 to 6.