Data processing method and device and electronic equipment

By splitting the to-processed data blocks and transmitting them to the second processing module after partially encrypting the first processing module for further encryption and splicing, the problems of low TEE security and low ESE efficiency are solved, and efficient and secure data encryption is achieved.

CN119939625APending Publication Date: 2025-05-06LENOVO (BEIJING) LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411998741.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In the prior art, the security level of TEE is low, which may lead to data leakage by performing encryption and decryption operations in TTE; while ESE is inefficient when encrypting and decrypting operations on longer data streams, resulting in long processing time.

Method used

By splitting the data block to be processed into first data and second data, encrypting the second data using the first data, obtaining the third data, and sending the first data to the second processing module for encryption, obtaining the fourth data, and then splicing the fourth data with the second data to form the processed data block.

Benefits of technology

The security of data transmission between the first processing module and the second processing module is improved, the computing power and time required for encryption operations are reduced, and the efficiency of data encryption is improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119939625A_ABST
    Figure CN119939625A_ABST
Patent Text Reader

Abstract

The invention provides a data processing method and device and electronic device.The method is applied to a first processing module and comprises the steps that a first to-be-processed data block is obtained; the first to-be-processed data block comprises first data and second data; encrypting the second data by using the first data to obtain third data; sending the first data to a second processing module to obtain fourth data obtained by encrypting the first data by the second processing module; splicing the fourth data and the second data to obtain a processed data block corresponding to the first to-be-processed data block; wherein the first processing module and the second processing module are modules with an encryption function and a decryption function.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to but is not limited to the field of data processing technology, and in particular to a data processing method, device and electronic device. Background Art

[0002] In the related technology, encryption and decryption operations of data streams can be implemented through a Trusted Execution Environment (TTE) or an Embedded Secure Element (ESE). However, due to the low security level of TEE, encryption and decryption operations in TTE may lead to data leakage, resulting in low security. At the same time, when encrypting and decrypting data streams through ESE, due to the limited computing power of the low-power microcontroller unit built into ESE, ESE needs to spend a long processing time when performing encryption and decryption operations on longer data streams, resulting in low efficiency. Summary of the invention

[0003] In view of this, the embodiments of the present application at least provide a data processing method, device and electronic device.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] The present application provides a data processing method, which is applied to a first processing module and includes:

[0006] Acquire a first data block to be processed; the first data block to be processed includes first data and second data;

[0007] Encrypt the second data using the first data to obtain third data;

[0008] Sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module;

[0009] The fourth data is concatenated with the second data to obtain a processed data block corresponding to the first data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0010] The present application provides a data processing method, which is applied to a first processing module and includes:

[0011] Acquire a second data block to be processed; the second data block to be processed includes fifth data and sixth data;

[0012] Sending the fifth data to the second processing module to obtain seventh data obtained by the second processing module decrypting the fifth data;

[0013] Decrypting the sixth data with the seventh data to obtain eighth data corresponding to the sixth data;

[0014] The seventh data and the eighth data are concatenated to obtain a processed data block corresponding to the second data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0015] The present application embodiment provides a data processing device, which is applied to a first processing module, and the device includes:

[0016] An acquisition unit, configured to acquire a first data block to be processed; the first data block to be processed includes first data and second data;

[0017] an encryption unit, configured to encrypt the second data using the first data to obtain third data;

[0018] A sending unit, used for sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module;

[0019] The splicing unit is used to splice the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0020] An embodiment of the present application provides an electronic device, the electronic device comprising:

[0021] The processor is used to obtain the first data block to be processed in the trusted execution environment, encrypt the second data using the first data to obtain the third data; and send the first data to the embedded security element; the first data block to be processed includes the first data and the second data;

[0022] The embedded security element is used to encrypt the first data to obtain fourth data; and send the fourth data to the trusted execution environment;

[0023] The processor is further used to concatenate the fourth data with the second data in the trusted execution environment to obtain a processed data block corresponding to the first data block to be processed;

[0024] Among them, the trusted execution environment and the embedded security element are modules with encryption and decryption functions.

[0025] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and are not intended to limit the technical solutions of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] The drawings herein are incorporated into the specification and constitute a part of the specification. These drawings illustrate embodiments consistent with the present application and are used together with the specification to illustrate the technical solution of the present application.

[0027] Figure 1 A schematic diagram of an implementation process of a data processing method provided in an embodiment of the present application Figure 1 ;

[0028] Figure 2 A schematic diagram of an implementation process of a data processing method provided in an embodiment of the present application Figure 2 ;

[0029] Figure 3 A schematic diagram of an implementation process of a data processing method provided in an embodiment of the present application Figure 3 ;

[0030] Figure 4 A schematic diagram of data encryption provided in an embodiment of the present application;

[0031] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application;

[0032] Figure 6 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application Figure 1 ;

[0033] Figure 7 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application Figure 2 ;

[0034] Figure 8 A hardware entity schematic diagram of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0035] In order to make the purpose, technical solutions and advantages of the present application clearer, the technical solutions of the present application are further elaborated in detail below in conjunction with the drawings and embodiments. The described embodiments should not be regarded as limiting the present application. All other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application.

[0036] In the following description, reference is made to “some embodiments”, which describe a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.

[0037] It should be pointed out that the terms "first\second\third" involved in the embodiments of the present application are merely to distinguish similar objects and do not represent a specific ordering of the objects. It can be understood that "first\second\third" can be interchanged in a specific order or sequence where permitted, so that the embodiments of the present application described here can be implemented in an order other than that illustrated or described here.

[0038] It will be understood by those skilled in the art that, unless otherwise defined, all terms (including technical terms and scientific terms) used herein have the same meaning as the general understanding of those skilled in the art in the field to which the embodiments of the present application belong. It should also be understood that terms such as those defined in general dictionaries should be understood to have meanings consistent with the meanings in the context of the prior art, and will not be interpreted with idealized or overly formal meanings unless specifically defined as here.

[0039] ESE is an embedded security chip that provides a secure environment to store and process sensitive data and applications. ESE can be used to perform encryption and decryption operations and securely store data such as keys, certificates, and personal information. It is often used in mobile devices, payment systems, identity authentication, and other applications that require high security. ESE has a built-in low-power microcontroller unit that can handle various encryption and decryption requests. The low-power microcontroller unit provides an isolated operating environment for running security-sensitive applications and operations.

[0040] TEE is a technology that provides a secure execution space, allowing sensitive code and data to run in a protected environment and isolated from the main operating system environment. When using TEE, the processor registers and related memory controllers are isolated from the main operating system. However, with the richness of applications, more and more third-party programs (for example, fingerprints, SecureCamera algorithms, Trust UI, etc.) are added to TEE. Since these third-party programs come from different suppliers, many codes are closed source, which reduces the security level of TEE. Therefore, the security level of TEE is lower than that of ESE.

[0041] In the related technology, encryption and decryption operations of data streams can be implemented through TTE or ESE. However, due to the low security level of TEE, encryption and decryption operations in TTE may lead to data leakage, and there is a problem of low security. At the same time, when encrypting and decrypting data streams through ESE, due to the limited computing power of the built-in low-power microcontroller unit of ESE, the efficiency will not be affected when encrypting and storing data with a small data size (for example, identity authentication information, etc.) and decrypting and viewing data, but when encrypting and storing photos, videos, audio and other files and decrypting and viewing them, due to the large data size of the encrypted and decrypted data, it takes a long time to encrypt, and when decrypting, because the unencrypted data can only be viewed after decryption, the waiting time is long, which will bring a poor experience. Therefore, ESE needs to spend a long processing time when encrypting and decrypting longer data streams, and there is a problem of low efficiency.

[0042] The embodiment of the present application provides a data processing method, first, obtaining a first data block to be processed including first data and second data; second, using the first data to encrypt the second data to obtain third data, and sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module; finally, splicing the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed. In this way, on the one hand, the split first data block to be processed is first encrypted and then sent to the second processing module, which improves the security of data transmission between the first processing module and the second processing module; on the other hand, compared with transmitting and encrypting the complete first data block to be processed, the data processing method of the present application can complete the encryption of the first data block to be processed by transmitting part of the data of the first data block to be processed between the first processing module and the second processing module, while reducing the computing power required for the encryption operation, it also reduces the time required for the encryption operation, and improves the efficiency of data encryption.

[0043] Figure 1 A schematic diagram of a data processing method provided in an embodiment of the present application Figure 1 , the method is applied to the first processing module, such as Figure 1 As shown, the method includes steps S101 to S104, wherein:

[0044] Step S101, obtaining a first data block to be processed; the first data block to be processed includes first data and second data.

[0045] Here, the first processing module can be any suitable module that can implement this function. The first processing module has functions such as encryption, decryption, and data transmission. In some embodiments, the first processing module can be at least one of TEE, Trusted Platform Module (TPM), etc. TPM is an international standard secure cryptographic processor used for security measurement of computing platforms. It provides functions such as key generation, storage, and encryption, supports multiple encryption algorithms, and ensures the security of data transmission and storage.

[0046] The first data block to be processed refers to a data block that needs to be encrypted. In some embodiments, the number of the first data block to be processed may be at least one. The data size of the first data block to be processed may be any suitable value, for example, 4KB (kilobytes), 5KB, etc. The method for obtaining the first data block to be processed may include but is not limited to: reading the first data block to be processed from the current device, reading the first data block to be processed from the cloud, etc.

[0047] The first data is part of the data in the first data block to be processed. The data size of the first data can be any appropriate value, for example, 32B (bytes), 50B, etc.

[0048] The second data is part of the data in the first data block to be processed. The data size of the second data can be any suitable value, for example, 3.95KB, 3968B, etc. In some embodiments, the data size of the second data is greater than the data size of the first data. The sum of the data size of the second data and the data size of the first data is the data size of the first data block to be processed.

[0049] In some implementations, a data stream to be processed may be obtained, and if the data stream to be processed meets the data condition, the data stream to be processed is split and processed to obtain a first data block to be processed of a target data size, so as to obtain a first data block to be processed. The fact that the data stream to be processed meets the data condition indicates that the data size of the data stream to be processed is greater than the target data size.

[0050] Step S102: Use the first data to encrypt the second data to obtain third data.

[0051] Here, the third data is data obtained after the second data is encrypted. The data size of the third data can be any suitable value, for example, 3.8KB, 3968B, etc. In some embodiments, the data size of the third data can be the same as or different from the data size of the second data.

[0052] The method for encrypting the second data may include but is not limited to: using the first data to encrypt the second data through the Advanced Encryption Standard (AES) algorithm, using the first data to encrypt the second data through the International Data Encryption Algorithm (IDEA), etc. The AES algorithm is a symmetric encryption algorithm used to protect electronic data and supports three different key lengths: 128 bits, 192 bits, and 256 bits. IDEA is a symmetric encryption algorithm that uses the same key for encryption and decryption and uses a 128-bit key.

[0053] In some implementations, the first data may be a binary data object including a key by which the second data may be encrypted.

[0054] Step S103: sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module.

[0055] Here, the second processing module may be any suitable module capable of realizing the function. The first processing module has functions such as encryption, decryption, and data transmission. In some embodiments, the second processing module may be at least one of an ESE, a network encryption chip, and the like.

[0056] The fourth data is data obtained by encrypting the first data by the second processing module. The data size of the fourth data can be any appropriate value, for example, 32B, 64B, etc. In some embodiments, the data size of the fourth data is equal to the data size of the first data.

[0057] In some embodiments, the first processing module includes a preset program, and the first data can be sent to the second processing module through the preset program and a serial peripheral interface (Serial Peripheral Interface, SPI). During implementation, the preset program can be ESE_TA. ESE_TA is a program running in the first processing module, which can manage the interaction between the first processing module and the ESE chip. SPI is a synchronous serial communication interface, mainly used for short-distance communication in embedded systems.

[0058] In some implementations, the second processing module includes a preset function module, and the preset function module is used to perform security operations. The first data can be encrypted by the preset function module to obtain the fourth data.

[0059] In some embodiments, the preset functional module includes: at least one of an encryption and decryption engine, a secure storage area, a processing unit, etc. Among them, the encryption and decryption engine is used to run the encryption and decryption algorithm. The secure storage area is used to store encryption and decryption keys and sensitive data, and the secure storage area is protected by physical and logical means to prevent unauthorized access and tampering. The processing unit is used to coordinate various operations, which may include but are not limited to: at least one of: data reception, processing instruction execution, response generation, etc.

[0060] In some embodiments, data passed into the second processing module is first sent to the processing unit, which can assign tasks to other components in the second processing module based on the passed in data.

[0061] In some implementations, the second processing module may send the fourth data obtained by encrypting the first data to the first processing module via SPI.

[0062] In some embodiments, the first data may be encrypted using a first key to obtain first encrypted data, and then the first encrypted data may be sent to a second processing module, so that the second processing module decrypts the first encrypted data using a second key to obtain the first data. The first key and the second key are a communication key pair between the first processing module and the second processing module.

[0063] Step S104, concatenating the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0064] Here, the processed data block corresponding to the first data block to be processed is a data block that has been subjected to an encryption operation. The number of the processed data blocks may be at least one. In some embodiments, the data size of the processed data block corresponding to the first data block to be processed may be any suitable value, for example, 4KB, 8KB, etc. The data size of the processed data block corresponding to the first data block to be processed may be the same as or different from the data size of the first data block to be processed.

[0065] The method of splicing the fourth data with the second data may include but is not limited to: splicing the fourth data with the second data through a string, splicing the fourth data with the second data through a database, splicing the fourth data with the second data through a file system, etc. For example, by splicing two data blocks using a string connection operator, the fourth data and the second data can be spliced. For another example, in a database, a UNION operation or a CONCAT operation can be used to splice two data blocks, so that the fourth data and the second data can be spliced. For another example, in a file system, a file read and write operation can be used to splice two data blocks, so that the fourth data and the second data can be spliced.

[0066] In some embodiments, the first processing module and the second processing module are different modules, and the safety level of the second processing module is higher than the safety level of the first processing module.

[0067] In an embodiment of the present application, first, a first data block to be processed including first data and second data is obtained; secondly, the first data is used to encrypt the second data to obtain third data, and the first data is sent to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module; finally, the fourth data and the second data are spliced ​​to obtain a processed data block corresponding to the first data block to be processed. In this way, on the one hand, the split first data block to be processed is first encrypted and then sent to the second processing module, which improves the security of data transmission between the first processing module and the second processing module; on the other hand, compared with transmitting and encrypting the complete first data block to be processed, the data processing method of the present application can complete the encryption of the first data block to be processed by transmitting part of the data of the first data block to be processed between the first processing module and the second processing module, which reduces the computing power required for the encryption operation and the time required for the encryption operation, thereby improving the efficiency of data encryption.

[0068] In some implementations, the following steps may be performed when acquiring the first data block to be processed, that is, step S101 may include step S11 and step S12, wherein:

[0069] Step S11, obtaining the data stream to be processed.

[0070] Here, the data stream to be processed refers to the data stream that needs to be encrypted. The data size of the data stream to be processed can be any suitable value, for example, 500KB, 1.5MB (megabytes), etc. The method for obtaining the data stream to be processed may include but is not limited to: reading the data stream to be processed from the current device, reading the data stream to be processed from the cloud, etc.

[0071] In some implementations, the sum of the data sizes of at least one first data block to be processed is the data size of the data stream to be processed.

[0072] In some implementations, the data stream to be processed may be split to obtain a first data block to be processed.

[0073] In some embodiments, a target data stream sent by a third processing module may be received to obtain a data stream to be processed. The third processing module is configured to determine the transmission data from the stored data when a target operation is detected. The target operation is an operation indicating encryption of the target data stream.

[0074] In some implementations, at least two processed data blocks may be spliced ​​to obtain a processed data stream corresponding to the data stream to be processed, and the processed data stream may be sent to the third processing module.

[0075] Step S12, if the data stream to be processed meets the data condition, split the data stream to be processed to obtain a first data block to be processed of the target data size; wherein, the data stream to be processed meets the data condition, indicating that the data size of the data stream to be processed is greater than the target data size.

[0076] Here, the data condition is a condition for determining whether to split the data stream to be processed. The data condition can be any suitable condition, for example, greater than the target data size, etc. The target data size can be any suitable value, for example, 4KB, 8KB, etc.

[0077] Exemplarily, the data size of the data stream to be processed is 10 KB, the target data size is 4 KB, and the data condition is greater than the target data size. At this time, it can be determined that the data stream to be processed meets the data condition.

[0078] Methods for splitting the data stream to be processed may include but are not limited to: splitting the data stream to be processed by diversion, splitting the data stream to be processed by preset tools, etc. For example, diversion is a method of dividing a data stream into multiple sub-streams, usually based on the hash value of the key, and the data stream can be evenly distributed to multiple sub-streams to split the data stream to be processed. For another example, the preset tools may include but are not limited to: SplitCap, Wireshark, etc. SplitCap is a network traffic analysis tool that can split the data stream to be processed according to standards such as IP address, quintuple or MAC address. Wireshark is a network protocol analysis tool that provides a variety of ways to merge, filter and cut data streams, and can split the data stream to be processed.

[0079] In some implementations, if the data stream to be processed is split to obtain initial data blocks having a target initial data block whose data size is smaller than the target data size, the target initial data block is padded to obtain a first data block to be processed of a first data size.

[0080] In some implementations, if the data stream to be processed does not meet the data condition, the data stream to be processed is sent to the second processing module.

[0081] In some implementations, the characteristic information corresponding to the data stream to be processed may be sent to the second processing module to obtain the target key obtained by the second processing module processing the characteristic information. In implementation, the characteristic information may be the same as or different from the characteristic information of the device performing the encryption and decryption operation.

[0082] In some implementations, when performing an encryption operation, a key corresponding to the characteristic information of the device performing the encryption and decryption operation may be used as a target key corresponding to the data stream to be processed. For example, a key corresponding to the fingerprint information of the device performing the encryption and decryption operation may be used as a target key corresponding to the data stream to be processed.

[0083] In an implementation manner of the present application, when the data size of the acquired data stream to be processed is larger than the target data size, the data stream to be processed is split and processed to obtain a first data block to be processed of the target data size. Compared with using the entire data stream for encryption, encrypting the data in data blocks reduces the time required for the encryption operation and improves the efficiency of data encryption.

[0084] In some implementations, the method provided in the embodiments of the present application may further include step S105, wherein:

[0085] Step S105 , if the initial data blocks obtained by splitting the data stream to be processed have a target initial data block whose data size is smaller than the target data size, padding is performed on the target initial data block to obtain a first data block to be processed with a first data size.

[0086] Here, the initial data block is a data block obtained by splitting the data stream to be processed. The data size of the initial data block can be any suitable value, for example, 2KB, 4KB, etc. In some embodiments, the number of the initial data blocks can be at least one. The number of the initial data blocks and the number of the first data blocks to be processed can be the same.

[0087] In some implementations, the data size of the initial data block may be the same as or different from the data size of the first to-be-processed data block.

[0088] The target initial data block refers to a data block whose data size is the target data size. The target data size can be any suitable value, for example, 4KB, 8KB, etc. The first data size can be any suitable value, for example, 4KB, 8KB, etc. In some embodiments, the target data size and the first data size can be the same.

[0089] The method of filling the target initial data block may include but is not limited to: filling the target initial data block through the Public Key Cryptography Standards (PKCS), filling the target initial data block through the prediction model, etc. For example, PKCS is a set of public key cryptography standards, which may include at least one of PKCS#1, PKCS#5, PKCS#7, PKCS#8, etc. For another example, the prediction model has a data filling function, and the target initial data block can be filled through the prediction model. The prediction model may include but is not limited to: regression model, decision tree, random forest, etc.

[0090] In an implementation manner of the present application, a target initial data block whose data size is smaller than the target data size is padded to obtain a first data block to be processed of a first data size, so that the first data block to be processed has the same data size, thereby being able to adopt a unified process when performing encryption operations on the first data block to be processed, thereby improving the efficiency of data encryption.

[0091] In some implementations, the method provided in the embodiments of the present application may further include step S106, wherein:

[0092] Step S106: If the data stream to be processed does not meet the data condition, the data stream to be processed is sent to the second processing module.

[0093] Here, the data condition may be any suitable condition, for example, greater than a target data size, etc. The target data size may be any suitable value, for example, 4 KB, 8 KB, etc.

[0094] Exemplarily, the data size of the data stream to be processed is 2KB, the target data size is 4KB, and the data condition is greater than the target data size. At this time, it can be determined that the data stream to be processed does not meet the data condition.

[0095] In some embodiments, the first processing module includes a preset program, and the data stream to be processed can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0096] In the implementation manner of the present application, when the data stream to be processed does not meet the data condition, the data stream to be processed is sent to the second processing module, which simplifies the processing steps of the data stream to be processed and improves the efficiency of the data processing method.

[0097] In some implementations, the following steps may be performed when obtaining the data stream to be processed, that is, step S11 includes step S111, wherein:

[0098] Step S111, receiving the target data stream sent by the third processing module to obtain the data stream to be processed; wherein the third processing module is used to determine the transmission data from the stored data when a target operation is detected; the target operation is an operation indicating encryption of the target data stream.

[0099] Here, the third processing module may be any suitable module capable of implementing the function. The third processing module has functions such as detecting operation and transmitting data. In some embodiments, the third processing module may be at least one of an application processor (AP), a communication processor (CP), etc. The AP is mainly responsible for running an operating system, a user interface, and various application programs. The CP is responsible for processing network-related communication tasks, which may include but are not limited to telephone calls, SMS sending and receiving, data transmission, etc.

[0100] The target operation refers to an operation performed on the third processing module, indicating that the target data stream is encrypted. In some embodiments, the target operation may be an operation such as adding a picture, video, file, etc. to the privacy space. The target operation may be any suitable operation, such as a click operation, a long press operation, a sliding operation, etc. The third processing module may determine the transmission data from the stored data according to the detected target operation. The transmission data may be the target data stream.

[0101] In some implementations, the third processing module may create a shared memory through a secure memory (SM), thereby sending the target data stream to the first processing module through the shared memory. SM is a hardware security technology that can create a private memory area protected by software and hardware technologies, so that external applications cannot access the content therein without permission.

[0102] In some embodiments, the third processing module can send the target data stream to the first processing module through a message passing interface. For example, the third processing module can use a remote procedure call (RPC) protocol mechanism. In this way, the third processing module sends a message to the first processing module, and the first processing module returns the result after processing.

[0103] In some implementations, the first processing module may use the received target data stream as the data stream to be processed to obtain the data stream to be processed.

[0104] In an embodiment of the present application, by receiving the target data stream sent by the third processing module to obtain the data stream to be processed, the data stream to be processed can be obtained from the third processing module, thereby realizing the transmission of the unencrypted data stream, so that the first processing module can perform encryption operations on the data.

[0105] In some implementations, the method provided in the embodiments of the present application may further include step S107, wherein:

[0106] Step S107: splice at least two processed data blocks to obtain a processed data stream corresponding to the data stream to be processed, and send the processed data stream to the third processing module.

[0107] Here, the number of the processed data blocks may be at least one. In some implementations, the data size of the processed data block may be any suitable value, for example, 4KB, 8KB, etc.

[0108] In some embodiments, the method of splicing at least two processed data blocks may include but is not limited to: splicing at least two processed data blocks through a string, splicing at least two processed data blocks through a database, splicing at least two processed data blocks through a file system, etc.

[0109] The method of sending the processed data stream to the third processing module may include but is not limited to: sending the processed data stream to the third processing module through shared memory, sending the processed data stream to the third processing module through a secure channel, sending the processed data stream to the third processing module through a message passing interface, etc. For example, the third processing module may create a shared memory area through SM, and the first processing module sends the processed data stream to the shared memory area, so that the third processing module can obtain the processed data stream in the shared memory area. For another example, a secure channel can be established between the third processing module and the first processing module, and the secure channel can be used for data transmission between the third processing module and the first processing module, so that the first processing module can send the processed data stream to the third processing module through the secure channel.

[0110] In some embodiments, after the first processing module sends the processed data stream to the third processing module, the third processing module stores the data stream of the processed data stream. Since the processed data stream is encrypted data, what is saved is the encrypted data. The encrypted data can be saved as undecrypted data in the third processing module, thereby improving data security.

[0111] In some embodiments, after the first processing module sends the processed data stream to the third processing module, the first processing module and the third processing module can overwrite the data stream to be processed based on the processed data stream, that is, in the first processing module and the third processing module, only the processed data stream is saved but not the data stream to be processed.

[0112] In an embodiment of the present application, a processed data stream corresponding to the data stream to be processed is obtained by splicing at least two processed data blocks, and the processed data stream is sent to a third processing module, thereby realizing the transmission of the encrypted data stream, so that the third processing module completes the encryption operation on the data.

[0113] In some implementations, the data stream to be processed has characteristic information for identity authentication. The method provided in the embodiment of the present application may further include step S108, wherein:

[0114] Step S108: sending the characteristic information corresponding to the data stream to be processed to the second processing module, so as to obtain the target key obtained by the second processing module by processing the characteristic information.

[0115] Here, the feature information may include but is not limited to: fingerprint, password, pattern, face, etc. In some embodiments, the data size of the feature information may be any suitable value, for example, 4KB, 2KB, etc.

[0116] In some implementations, a data stream to be processed may have at least one corresponding feature information, and the at least one feature information is stored in the data stream to be processed in the form of a field.

[0117] In some implementations, the characteristic information corresponding to the data stream to be processed may be characteristic information of a device performing encryption and decryption operations, or characteristic information collected when performing encryption and decryption operations. The characteristic information collected when performing encryption and decryption operations may be the same as or different from the characteristic information of the device performing encryption and decryption operations.

[0118] In some implementations, the first processing module includes a preset program, and the characteristic information corresponding to the data stream to be processed can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0119] The target key refers to the key used when encrypting and decrypting the data stream to be processed. In some implementations, the second processing module may perform hash value conversion on the feature information to obtain the target key corresponding to the feature information.

[0120] In some embodiments, the characteristic information is used to allow the second processing module to determine the target key used when encrypting and decrypting the data stream to be processed, so the characteristic information may not be included in the data stream to be processed. The characteristic information may be sent to the second processing module separately. At the same time, since the data size of the characteristic information is small, the characteristic information does not need to be split and can be sent directly to the second processing module.

[0121] In an implementation manner of the present application, characteristic information corresponding to the data stream to be processed is sent to the second processing module, so that the second processing module processes the characteristic information to obtain a target key. In this way, a key is added to the data stream to be processed when performing an encryption operation. At the same time, the characteristic information needs to be verified when performing a decryption operation, thereby improving the security of the data stream.

[0122] In some implementations, the method provided in the embodiment of the present application may further include step S109, and the following steps may be performed when sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module, that is, the "sending the first data to the second processing module" in step S103 may include step S131, wherein:

[0123] Step S109: encrypt the first data using the first key to obtain first encrypted data.

[0124] Here, the first key refers to the key in the communication key pair located in the first processing module. The key is a parameter used to encrypt and decrypt data. In some embodiments, the first key can be any suitable number of bits, for example, 128 bits, 192 bits, 256 bits, etc.

[0125] The first encrypted data refers to data obtained by encrypting the first data. The data size of the first encrypted data may be any suitable value, for example, 32B, 64B, etc. In some implementations, the data size of the first encrypted data may be the same as the data size of the first data.

[0126] In some implementations, the first processing module may encrypt the first data using the first key through an encryption algorithm, which may include but is not limited to AES, IDEA, and the like.

[0127] In some implementations, when the first key is used to encrypt the first data, an encryption mode needs to be selected, which may include but is not limited to at least one of an electronic codebook mode, a cipher block chaining mode, a Galois / counter mode, and the like.

[0128] Step S131, sending the first encrypted data to the second processing module, so that the second processing module uses the second key to decrypt the first encrypted data to obtain the first data; wherein the first key and the second key are a communication key pair between the first processing module and the second processing module.

[0129] Here, the second key refers to the key in the communication key pair located in the second processing module. In some embodiments, the second key can be any suitable number of bits, for example, 128 bits, 192 bits, 256 bits, etc. The number of bits of the second key can be the same as the number of bits of the first key.

[0130] In some embodiments, the communication key pair between the first processing module and the second processing module is symmetric, that is, the first key and the second key are symmetric.

[0131] In some implementations, the second processing module may use a second key to decrypt the first encrypted data through a decryption algorithm to obtain the first data. The decryption algorithm may include but is not limited to: AES, IDEA, etc.

[0132] In some implementations, the first processing module includes a preset program, and the first encrypted data can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0133] In an embodiment of the present application, the first data is encrypted by a first key, so that the second processing module uses the second key to decrypt the first encrypted data to obtain the first data, thereby improving the security of data transmission between the first processing module and the second processing module. At the same time, since the data transmission between the first processing module and the second processing module is secure, even if the data is intercepted during the encryption process, the original first data cannot be obtained due to the lack of a communication key pair between the first processing module and the second processing module, thereby further improving the security of the data.

[0134] Based on the above embodiments, the embodiments of the present application also provide a data processing method. Figure 2 A schematic diagram of a data processing method provided in an embodiment of the present application Figure 2 , the method is applied to the first processing module, such as Figure 2 As shown, the method includes steps S201 to S204, wherein:

[0135] Step S201, obtaining a second data block to be processed; the second data block to be processed includes fifth data and sixth data.

[0136] Here, the first processing module may be at least one of TEE, TPM, etc.

[0137] The second data block to be processed refers to a data block that needs to be decrypted. In some embodiments, the number of the second data block to be processed may be at least one. The data size of the second data block to be processed may be any suitable value, for example, 4KB, 5KB, etc. The method for obtaining the second data block to be processed may include but is not limited to: reading the second data block to be processed from the current device, reading the second data block to be processed from the cloud, etc.

[0138] The fifth data is part of the data in the second to-be-processed data block. The data size of the fifth data can be any appropriate value, for example, 32B (bytes), 50B, etc.

[0139] The sixth data is part of the data in the second data block to be processed. The data size of the sixth data can be any suitable value, for example, 3.95KB, 3968B, etc. In some embodiments, the data size of the sixth data is greater than the data size of the fifth data. The sum of the data size of the sixth data and the data size of the fifth data is the data size of the second data block to be processed.

[0140] Step S202: Send the fifth data to the second processing module to obtain seventh data obtained by decrypting the fifth data by the second processing module.

[0141] Here, the second processing module may be any suitable module capable of realizing the function. In some implementations, the second processing module may be at least one of an ESE, a network encryption chip, and the like.

[0142] The seventh data is data obtained by decrypting the fifth data. The data size of the seventh data may be any appropriate value, for example, 32B, 64B, etc. In some implementations, the data size of the seventh data is the same as the data size of the fifth data.

[0143] In some embodiments, in actual application scenarios, in response to receiving an operation to view a file in a privacy space, the first processing module can obtain the data stream corresponding to the second data block to be processed from the third processing module, and perform decryption operations through the first processing module and the second processing module to obtain an unencrypted data stream.

[0144] In some embodiments, after the first processing module sends the fifth data to the second processing module, the second processing module needs to make a judgment based on the key corresponding to the currently collected feature information and the target key corresponding to the undecrypted data stream. When the key corresponding to the currently collected feature information and the target key corresponding to the undecrypted data stream are the same, it is determined that the identity information verification is passed. Only then will the second processing module decrypt the fifth data, so that the first processing module obtains the seventh data obtained by the second processing module decrypting the fifth data.

[0145] In some implementations, the first processing module includes a preset program, and the fifth data can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0146] In some implementations, the second processing module includes a preset function module, and the preset function module is used to perform security operations. The fifth data can be decrypted by the preset function module to obtain the seventh data.

[0147] In some implementations, the preset functional module includes at least one of: an encryption / decryption engine, a secure storage area, a processing unit, and the like.

[0148] In some implementations, the second processing module may send the seventh data obtained by decrypting the fifth data to the first processing module via SPI.

[0149] Step S203: decrypt the sixth data with the seventh data to obtain eighth data corresponding to the sixth data.

[0150] Here, the eighth data is the data obtained after the sixth data is decrypted. The data size of the eighth data may be any suitable value, for example, 3.8KB, 3968B, etc. In some implementations, the data size of the eighth data may be the same as or different from the data size of the sixth data.

[0151] The method for decrypting the sixth data may include but is not limited to: using the seventh data to decrypt the sixth data through the AES algorithm, using the seventh data to decrypt the sixth data through IDEA, etc.

[0152] Step S204, concatenating the seventh data and the eighth data to obtain a processed data block corresponding to the second data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0153] Here, the processed data block corresponding to the second data block to be processed is a data block that has been decrypted. The number of the processed data blocks may be at least one. In some embodiments, the data size of the processed data block corresponding to the second data block to be processed may be any suitable value, for example, 4KB, 8KB, etc. The data size of the processed data block corresponding to the second data block to be processed may be the same as or different from the data size of the second data block to be processed.

[0154] The method of splicing the seventh data and the eighth data may include but is not limited to: splicing the seventh data and the eighth data through a character string, splicing the seventh data and the eighth data through a database, splicing the seventh data and the eighth data through a file system, etc.

[0155] In some embodiments, the first processing module and the second processing module are different modules, and the safety level of the second processing module is higher than the safety level of the first processing module.

[0156] In an embodiment of the present application, on the one hand, the sixth data of the second data block to be processed is decrypted with the seventh data, thereby improving the security of data transmission between the first processing module and the second processing module; on the other hand, compared with transmitting and decrypting the complete second data block to be processed, the data processing method of the present application can complete the decryption of the second data block to be processed by transmitting part of the data of the second data block to be processed between the first processing module and the second processing module, which not only reduces the computing power required for the decryption operation, but also reduces the time required for the decryption operation, thereby improving the efficiency of data decryption.

[0157] In some implementations, the second data block to be processed has a corresponding data stream to be processed, and the data stream to be processed includes characteristic information for identity authentication. When the fifth data is sent to the second processing module to obtain the seventh data obtained by the second processing module decrypting the fifth data, the following steps may be performed, that is, step S202 may include step S21, wherein:

[0158] Step S21, sending the fifth data to the second processing module, so as to obtain seventh data obtained by the second processing module by decrypting the fifth data when the characteristic information of the data stream to be processed matches the characteristic information currently collected.

[0159] Here, the data stream to be processed has corresponding feature information, and the feature information may include but is not limited to: fingerprint, password, pattern, face, etc. In some embodiments, the data size of the feature information may be any suitable value, for example, 4KB, 2KB, etc.

[0160] The currently collected feature information refers to the feature information collected when performing the decryption operation. The currently collected feature information may include but is not limited to: fingerprints, passwords, patterns, faces, etc. In some embodiments, the feature information of the data stream to be processed is in the same form as the currently collected feature information.

[0161] In some implementations, the feature information of the data stream to be processed matches the feature information currently collected, which means that the feature information of the data stream to be processed and the feature information currently collected meet a preset condition. The preset condition may include, but is not limited to: greater than a similarity threshold, identical, etc. The similarity threshold may be any suitable value, for example, 85%, 95%, etc.

[0162] In some implementations, the characteristic information of the data stream to be processed and the characteristic information currently collected can be converted into hash values ​​respectively to obtain the target key corresponding to the characteristic information of the data stream to be processed and the key corresponding to the characteristic information currently collected. When the target key corresponding to the characteristic information of the data stream to be processed is the same as the key corresponding to the characteristic information currently collected, it is determined that the characteristic information of the data stream to be processed matches the characteristic information currently collected, that is, the identity information verification is passed.

[0163] In some implementations, the first processing module includes a preset program, and the fifth data can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0164] In the implementation manner of the present application, the fifth data is decrypted by the second processing module only when the characteristic information of the data stream to be processed matches the characteristic information currently collected, thereby improving data security during the decryption operation.

[0165] Based on the above embodiments, the application of the data processing method provided in the embodiments of the present application in actual scenarios is described below, taking the first processing module as TEE, the second processing module as ESE, and the third processing module as AP processor as an example.

[0166] ESE is an embedded security chip that provides a secure environment to store and process sensitive data and applications. ESE can be used to perform encryption and decryption operations and securely store data such as keys, certificates, and personal information. It is often used in mobile devices, payment systems, identity authentication, and other applications that require high security. ESE has a built-in low-power microcontroller unit that can handle various encryption and decryption requests. The low-power microcontroller unit provides an isolated operating environment for running security-sensitive applications and operations.

[0167] TEE is a technology that provides a secure execution space, allowing sensitive code and data to run in a protected environment and isolated from the main operating system environment. When using TEE, the processor registers and related memory controllers are isolated from the main operating system. However, with the richness of applications, more and more third-party programs (for example, fingerprints, SecureCamera algorithms, Trust UI, etc.) are added to TEE. Since these third-party programs come from different suppliers, many codes are closed source, which reduces the security level of TEE. Therefore, the security level of TEE is lower than that of ESE.

[0168] In the related technology, encryption and decryption operations of data streams can be implemented through TTE or ESE. However, due to the low security level of TEE, encryption and decryption operations in TTE may lead to data leakage, and there is a problem of low security. At the same time, when encrypting and decrypting data streams through ESE, due to the limited computing power of the built-in low-power microcontroller unit of ESE, the efficiency will not be affected when encrypting and storing data with a small data size (for example, identity authentication information, etc.) and decrypting and viewing data, but when encrypting and storing photos, videos, audio and other files and decrypting and viewing them, due to the large data size of the encrypted and decrypted data, it takes a long time to encrypt, and when decrypting, because the unencrypted data can only be viewed after decryption, the waiting time is long, which will bring a poor experience. Therefore, ESE needs to spend a long processing time when encrypting and decrypting longer data streams, and there is a problem of low efficiency.

[0169] The embodiment of the present application provides a data processing method, first, obtaining a first data block to be processed including first data and second data; second, using the first data to encrypt the second data to obtain third data, and sending the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module; finally, splicing the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed. In this way, on the one hand, the split first data block to be processed is first encrypted and then sent to the second processing module, which improves the security of data transmission between the first processing module and the second processing module; on the other hand, compared with transmitting and encrypting the complete first data block to be processed, the data processing method of the present application can complete the encryption of the first data block to be processed by transmitting part of the data of the first data block to be processed between the first processing module and the second processing module, while reducing the computing power required for the encryption operation, it also reduces the time required for the encryption operation, and improves the efficiency of data encryption.

[0170] Figure 3 A schematic diagram of an implementation process of a data processing method provided in an embodiment of the present application Figure 3 ,like Figure 3 As shown, the method includes steps S301 to S308, wherein:

[0171] Step S301, when the AP detects the target operation, it determines the transmission data from the stored data and sends the data stream to be processed to the TEE;

[0172] Step S302, TEE determines whether the data size of the data stream to be processed is greater than the target data size;

[0173] Here, if yes, go to step S303, otherwise, go to step S304.

[0174] Step S303, splitting the data stream to be processed, and if there is a target initial data block whose data size is smaller than the target data size, filling the target initial data block to obtain a first data block to be processed with a first data size;

[0175] Step S304, taking the data stream to be processed as the first data block to be processed;

[0176] Step S305, TEE uses the first data to encrypt the second data to obtain third data;

[0177] Step S306: TEE encrypts the first data using the first key to obtain first encrypted data;

[0178] Step S307, TEE sends the first encrypted data to ESE;

[0179] Step S308, the ESE decrypts the first encrypted data using the second key to obtain the first data;

[0180] Step S309: ESE encrypts the first data to obtain fourth data, and sends the fourth data to TEE;

[0181] Step S310, TEE concatenates the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed;

[0182] In step S311, the TEE concatenates at least two processed data blocks to obtain a processed data stream corresponding to the data stream to be processed, and sends the processed data stream to the AP.

[0183] Figure 4 A schematic diagram of data encryption provided in an embodiment of the present application, such as Figure 4 As shown, where:

[0184] In the first data block 41 to be processed with a data size of 4KB, TEE 42 uses the first data 411 to encrypt the second data to obtain the third data 412, TEE 42 sends the first data 411 to ESE 43, ESE43 encrypts the first data 411 to obtain the fourth data, and further, another first data block 44 to be processed can be encrypted according to the same process.

[0185] Based on the above embodiments, the present application also provides an electronic device, Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown in FIG. Figure 5 As shown, the electronic device 500 includes a processor 501 and an embedded security element 502, wherein:

[0186] The processor 501 is used to obtain the first data block to be processed in the trusted execution environment, encrypt the second data using the first data to obtain the third data; and send the first data to the embedded security element; the first data block to be processed includes the first data and the second data;

[0187] The embedded security element 502 is used to encrypt the first data to obtain fourth data; and send the fourth data to the trusted execution environment;

[0188] The processor 501 is further configured to concatenate the fourth data with the second data in the trusted execution environment to obtain a processed data block corresponding to the first data block to be processed;

[0189] Among them, the trusted execution environment and the embedded security element are modules with encryption and decryption functions.

[0190] Here, the processor may be any suitable processor, for example, AP, TPM, MCU, etc.

[0191] In some implementations, the processor may obtain the first data block to be processed in the trusted execution environment by calling an interface of the TEE.

[0192] The method for encrypting the second data may include, but is not limited to: using the first data to encrypt the second data through the AES algorithm, using the first data to encrypt the second data through the international data encryption algorithm IDEA, etc.

[0193] In some embodiments, the processor includes a preset program, and the first data can be sent to the second processing module through the preset program and SPI. During implementation, the preset program can be ESE_TA.

[0194] The method of splicing the fourth data with the second data may include but is not limited to: splicing the fourth data with the second data through a character string, splicing the fourth data with the second data through a database, splicing the fourth data with the second data through a file system, etc.

[0195] In an embodiment of the present application, first, the processor obtains a first data block to be processed including first data and second data; secondly, the processor uses the first data to encrypt the second data to obtain third data, and sends the first data to the embedded security element to obtain fourth data obtained by encrypting the first data by the embedded security element; finally, the processor splices the fourth data with the second data in a trusted execution environment to obtain a processed data block corresponding to the first data block to be processed. In this way, on the one hand, the split first data block to be processed is first encrypted and then sent to the second processing module, which improves the security of data transmission between the first processing module and the second processing module; on the other hand, compared with transmitting and encrypting the complete first data block to be processed, the electronic device of the present application can complete the encryption of the first data block to be processed by transmitting part of the data of the first data block to be processed between the first processing module and the second processing module, which reduces the computing power required for the encryption operation and the time required for the encryption operation, thereby improving the efficiency of data encryption.

[0196] Based on the above embodiment, the embodiment of the present application further provides a data processing device, which is applied to the first processing module. Figure 6 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application Figure 1 ,like Figure 6 As shown, the data processing device 600 includes an acquisition unit 601, an encryption unit 602, a sending unit 603 and a splicing unit 604, wherein:

[0197] The acquisition unit 601 is used to acquire a first data block to be processed; the first data block to be processed includes first data and second data;

[0198] An encryption unit 602, configured to encrypt second data using first data to obtain third data;

[0199] The sending unit 603 is used to send the first data to the second processing module to obtain fourth data obtained by encrypting the first data by the second processing module;

[0200] The concatenation unit 604 is used to concatenate the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

[0201] In some embodiments, the acquisition unit 601 is also used to acquire the data stream to be processed; if the data stream to be processed meets the data condition, the data stream to be processed is split and processed to obtain a first data block to be processed of the target data size; wherein, the data stream to be processed meets the data condition, indicating that the data size of the data stream to be processed is greater than the target data size.

[0202] In some embodiments, the data processing device 600 also includes a filling unit, which is used to fill the target initial data block to obtain a first data block to be processed with a first data size if the initial data blocks obtained by splitting the data stream to be processed have a target initial data block whose data size is smaller than the target data size.

[0203] In some implementations, the sending unit 603 is further configured to send the data stream to be processed to the second processing module if the data stream to be processed does not meet the data condition.

[0204] In some embodiments, the acquisition unit 601 is also used to receive the target data stream sent by the third processing module to obtain the data stream to be processed; wherein the third processing module is used to determine the transmission data from the stored data when a target operation is detected; the target operation is an operation indicating encryption of the target data stream.

[0205] In some implementations, the splicing unit 604 is further configured to splice at least two processed data blocks to obtain a processed data stream corresponding to the data stream to be processed, and send the processed data stream to the third processing module.

[0206] In some implementations, the data stream to be processed includes characteristic information for identity authentication, and the sending unit 603 is further used to send the characteristic information corresponding to the data stream to be processed to the second processing module to obtain a target key obtained by the second processing module by processing the characteristic information.

[0207] In some embodiments, the encryption unit 602 is further used to encrypt the first data using the first key to obtain the first encrypted data; the sending unit 603 is further used to send the first encrypted data to the second processing module, so that the second processing module decrypts the first encrypted data using the second key to obtain the first data; wherein the first key and the second key are a communication key pair between the first processing module and the second processing module.

[0208] Based on the above embodiment, the embodiment of the present application further provides a data processing device, which is applied to the first processing module. Figure 7 A schematic diagram of the structure of a data processing device provided in an embodiment of the present application Figure 2 ,like Figure 7 As shown, the data processing device 700 includes a second acquisition unit 701, a second sending unit 702, a decryption unit 703, and a second splicing unit 704, wherein:

[0209] The second acquisition unit 701 is used to acquire a second data block to be processed; the second data block to be processed includes fifth data and sixth data;

[0210] The second sending unit 702 is used to send the fifth data to the second processing module to obtain seventh data obtained by the second processing module decrypting the fifth data;

[0211] A decryption unit 703, configured to decrypt the sixth data using the seventh data to obtain eighth data corresponding to the sixth data;

[0212] A second splicing unit 704 is used to splice the seventh data and the eighth data to obtain a processed data block corresponding to the second data block to be processed;

[0213] The first processing module and the second processing module are modules with encryption and decryption functions.

[0214] In some embodiments, the second data block to be processed has a corresponding data stream to be processed, and the data stream to be processed includes characteristic information for identity authentication. The second sending unit 702 is also used to send the fifth data to the second processing module, so as to obtain the seventh data obtained by the second processing module by decrypting the fifth data when the characteristic information of the second data block to be processed matches the characteristic information currently collected.

[0215] The description of the above electronic device and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the embodiments of the electronic device and device of the present application, please refer to the description of the method embodiments of the present application for understanding.

[0216] It should be noted here that the description of the various embodiments above tends to emphasize the differences between the various embodiments, and the same or similar aspects can be referenced to each other. The description of the above device, storage medium, computer program and computer program product embodiments is similar to the description of the above method embodiment, and has similar beneficial effects as the method embodiment. For technical details not disclosed in the embodiments of the device, storage medium, computer program and computer program product of this application, please refer to the description of the method embodiment of this application for understanding.

[0217] It should be noted that in the embodiment of the present application, if the above method is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the embodiment of the present application is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium, including a number of instructions to enable an electronic device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a U disk, a mobile hard disk, a read-only memory (ROM), a disk or an optical disk. In this way, the embodiment of the present application is not limited to any specific combination of hardware and software.

[0218] An embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory stores a computer program that can be run on the processor, and the processor implements the above method when executing the computer program.

[0219] The embodiment of the present application provides a computer-readable storage medium on which a computer program is stored, and the computer program implements the above method when executed by a processor. The computer-readable storage medium may be transient or non-transient.

[0220] The embodiment of the present application provides a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and when the computer program is read and executed by a computer, some or all of the steps in the above method are implemented. The computer program product can be implemented specifically by hardware, software or a combination thereof. In an optional embodiment, the computer program product is embodied as a computer storage medium, and in another optional embodiment, the computer program product is embodied as a software product, such as a software development kit (Software Development Kit, SDK) and the like.

[0221] It should be noted that Figure 8 A schematic diagram of a hardware entity of an electronic device provided in an embodiment of the present application, as shown in the figure, the hardware entity of the electronic device 800 includes: a processor 801, a communication interface 802, a memory 803, a trusted execution environment 804 and an embedded security element 805, wherein:

[0222] The processor 801 generally controls the overall operation of the electronic device 800 .

[0223] The communication interface 802 enables the electronic device to communicate with other terminals or servers through a network.

[0224] The memory 803 is configured to store instructions and applications executable by the processor 801, and can also cache data to be processed or processed by the processor 801 and each module in the electronic device 800 (for example, image data, audio data, voice communication data, and video communication data), which can be implemented by flash memory (FLASH) or random access memory (Random Access Memory, RAM). Data transmission can be performed between the processor 801, the communication interface 802, and the memory 803 through the bus 806.

[0225] It should be noted here that the description of the above storage medium and device embodiments is similar to the description of the above method embodiments, and has similar beneficial effects as the method embodiments. For technical details not disclosed in the storage medium and device embodiments of this application, please refer to the description of the method embodiments of this application for understanding.

[0226] It should be understood that "one embodiment" or "an embodiment" mentioned throughout the specification means that specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in one or more embodiments in any suitable manner. It should be understood that in various embodiments of the present application, the size of the serial number of each step / process mentioned above does not mean the order of execution, and the execution order of each step / process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiment of the present application. The serial numbers of the embodiments of the present application mentioned above are for description only and do not represent the advantages and disadvantages of the embodiments.

[0227] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.

[0228] In the several embodiments provided in the present application, it should be understood that the disclosed devices and methods can be implemented in other ways. The device embodiments described above are only schematic. For example, the division of the units is only a logical function division. There may be other division methods in actual implementation, such as: multiple units or components can be combined, or can be integrated into another system, or some features can be ignored or not executed. In addition, the coupling, direct coupling, or communication connection between the components shown or discussed can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be electrical, mechanical or other forms.

[0229] The units described above as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units; they may be located in one place or distributed on multiple network units; some or all of the units may be selected according to actual needs to achieve the purpose of the present embodiment.

[0230] In addition, all functional units in the embodiments of the present application may be integrated into one processing unit, or each unit may be a separate unit, or two or more units may be integrated into one unit; the above-mentioned integrated units may be implemented in the form of hardware or in the form of hardware plus software functional units.

[0231] A person of ordinary skill in the art can understand that: all or part of the steps of implementing the above-mentioned method embodiment can be completed by hardware related to program instructions, and the aforementioned program can be stored in a computer-readable storage medium. When the program is executed, it executes the steps of the above-mentioned method embodiment; and the aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, read-only memories, magnetic disks or optical disks.

[0232] Alternatively, if the above-mentioned integrated unit of the present application is implemented in the form of a software function module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can essentially or in other words, the part that contributes to the relevant technology can be embodied in the form of a software product, which is stored in a storage medium and includes a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as mobile storage devices, ROMs, magnetic disks, or optical disks.

[0233] The above is only an implementation method of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application.

Claims

1. A data processing method, applied to a first processing module, comprising: Obtaining a first data block to be processed; The first data block to be processed includes first data and second data; Encrypt the second data using the first data to obtain third data; Sending the first data to a second processing module to obtain fourth data obtained by encrypting the first data by the second processing module; concatenating the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed; The first processing module and the second processing module are modules with encryption and decryption functions.

2. According to the method of claim 1, the obtaining of the first data block to be processed comprises: Get the data stream to be processed; If the data stream to be processed meets the data condition, split the data stream to be processed to obtain the first data block to be processed of the target data size; The fact that the data stream to be processed meets the data condition represents that the data size of the data stream to be processed is greater than the target data size.

3. The method according to claim 2, further comprising: If the initial data blocks obtained by splitting the data stream to be processed include a target initial data block whose data size is smaller than the target data size, the target initial data block is padded to obtain the first data block to be processed of a first data size.

4. The method according to claim 2, further comprising: If the data stream to be processed does not meet the data condition, the data stream to be processed is sent to the second processing module.

5. The method according to claim 2, wherein obtaining the data stream to be processed comprises: Receive the target data stream sent by the third processing module to obtain the data stream to be processed; wherein the third processing module is used to determine the transmission data from the stored data when a target operation is detected; the target operation is an operation indicating encryption of the target data stream.

6. The method according to claim 2, further comprising: At least two of the processed data blocks are spliced ​​to obtain a processed data stream corresponding to the data stream to be processed, and the processed data stream is sent to a third processing module.

7. The method according to any one of claims 1 to 6, further comprising: Encrypt the first data using a first key to obtain first encrypted data; The sending the first data to the second processing module includes: Sending the first encrypted data to the second processing module, so that the second processing module decrypts the first encrypted data using a second key to obtain the first data; The first key and the second key are a communication key pair between the first processing module and the second processing module.

8. A data processing method, applied to a first processing module, the method comprising: Obtaining a second data block to be processed; The second data block to be processed includes fifth data and sixth data; Sending the fifth data to the second processing module to obtain seventh data obtained by the second processing module decrypting the fifth data; Decrypting the sixth data with the seventh data to obtain eighth data corresponding to the sixth data; splicing the seventh data and the eighth data to obtain a processed data block corresponding to the second data block to be processed; The first processing module and the second processing module are modules with encryption and decryption functions.

9. A data processing device, applied to a first processing module, comprising: An acquisition unit, used for acquiring a first data block to be processed; The first data block to be processed includes first data and second data; an encryption unit, configured to encrypt the second data using the first data to obtain third data; a sending unit, configured to send the first data to a second processing module, so as to obtain fourth data obtained by encrypting the first data by the second processing module; A splicing unit is used to splice the fourth data with the second data to obtain a processed data block corresponding to the first data block to be processed; wherein the first processing module and the second processing module are modules with encryption and decryption functions.

10. An electronic device, comprising: The processor is configured to, after obtaining the first data block to be processed in the trusted execution environment, encrypt the second data using the first data to obtain the third data; and sending the first data to an embedded secure element; The first data block to be processed includes first data and second data; The embedded security element is used to encrypt the first data to obtain fourth data; and send the fourth data to the trusted execution environment; The processor is further configured to concatenate the fourth data with the second data in the trusted execution environment to obtain a processed data block corresponding to the first data block to be processed; The trusted execution environment and the embedded security element are modules with encryption and decryption functions.