Data transmission method and device, trusted service management platform and medium
By integrating data transmission modules in the trusted service management platform, a flexible second process is formed, the problem of insufficient data transmission flexibility in the prior art is solved, and a wider adaptability and flexibility to terminal devices are achieved.
Patent Information
- Application Number
- CN202311492162.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-09
- Publication Date
- 2025-05-09
AI Technical Summary
In the prior art, the trusted service management platform lacks flexibility in the data transmission process, resulting in excessive requirements on the data transmission method and device type of terminal equipment.
By determining the set of data transmission instructions included in the first process and corresponding data transmission modules, a set of data transmission modules is formed. Then, part of the data transmission module is integrated to form a second process to achieve flexibility and pluggability of the data transmission process.
It improves the flexibility of data transmission to security chips, reduces the requirements for data transmission methods and equipment types of terminal devices, and supports a wider range of cooperative equipment manufacturers and application scenarios.
Smart Images

Figure CN119966645A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of data security technology, and in particular to a data transmission method, device, trusted service management platform and medium. Background Art
[0002] In actual applications, the trusted service management platform transmits data packets including applications to the security chip through a pre-set fixed and integrated data transmission process. However, the above method is not flexible enough, so it puts forward higher requirements on the data transmission method and device type of the terminal device using the security chip. Summary of the invention
[0003] Based on the above problems, the embodiments of the present application provide a data transmission method, device, trusted service management platform and medium.
[0004] The technical solution provided by the embodiment of the present application is as follows:
[0005] The embodiment of the present application first provides a data transmission method, which is applied to a trusted service management platform; the method includes:
[0006] Determine a data transmission instruction set included in a first process; wherein the first process includes an integrated process for transmitting target data to a security chip provided in a target device;
[0007] Determine a data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain a data transmission module set; wherein the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than a first threshold; m and n are mutually unequal positive integers;
[0008] Integrate at least part of the data transmission modules in the data transmission module set to obtain a second process;
[0009] The target data is transmitted to the security chip based on the second process.
[0010] In some embodiments, the step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes:
[0011] Obtaining device configuration information of the target device;
[0012] At least based on the device configuration information, the at least part of the data transmission module is integrated to obtain the second process.
[0013] In some embodiments, the step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes:
[0014] Obtaining security configuration information of the security chip;
[0015] At least based on the security configuration information, the at least part of the data transmission module is integrated to obtain the second process.
[0016] In some embodiments, the step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes:
[0017] Obtaining input configuration information for the trusted service management platform;
[0018] The second process is obtained by integrating the sequence and / or the startup method of at least part of the data transmission modules based on the input configuration information.
[0019] In some embodiments, the step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes:
[0020] Based on the business processing logic of the target business corresponding to the target data, the jump relationship between at least part of the data transmission modules is conditionally controlled to obtain the second process.
[0021] In some embodiments, the step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes:
[0022] Determine the exception handling mechanism;
[0023] The second process is obtained by integrating at least part of the data transmission module based on the exception handling mechanism.
[0024] In some embodiments, after integrating at least part of the data transmission modules in the data transmission module set to obtain the second process, the method further includes:
[0025] determining a process score of the second process;
[0026] If the process score is less than a second threshold, the second process is adjusted and updated.
[0027] In some embodiments, the adjusting and updating the second process includes:
[0028] If the degree of matching between at least part of the code included in the mth data transmission module and the security configuration information of the security chip is less than or equal to a third threshold, determining an update data transmission module corresponding to the at least part of the code;
[0029] The update data transmission module and the at least part of the data transmission module are integrated to adjust and update the second process.
[0030] In some embodiments, the adjusting and updating the second process includes:
[0031] Obtaining log information whose process score is less than or equal to the second threshold;
[0032] Based on the log information, the data transmission module included in the second process is adjusted and updated.
[0033] In some embodiments, determining the process score of the second process includes:
[0034] Determining a first weight of the mth data transmission module;
[0035] Determining a second weight of at least a portion of the code included in the mth data transmission module; wherein a matching degree between the at least a portion of the code and the security configuration information of the security chip is less than or equal to a third threshold;
[0036] The process score is determined based on the first weight and the second weight.
[0037] In some embodiments, determining the data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain the data transmission module set includes:
[0038] Determine the degree of association between the i-th data transmission instruction and the j-th data transmission instruction in the data transmission instruction set; wherein i and j are mutually different positive integers;
[0039] The i-th data transmission instruction and / or the j-th data transmission instruction are processed based on the association degree to determine a data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction.
[0040] In some embodiments, the processing the i-th data transmission instruction and / or the j-th data transmission instruction based on the association degree to determine the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction includes:
[0041] If the degree of association is greater than or equal to a fourth threshold, the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction are integrated at least based on the degree of association to obtain a data transmission module corresponding to the i-th data transmission instruction and the j-th data transmission instruction.
[0042] In some embodiments, the processing the i-th data transmission instruction and / or the j-th data transmission instruction based on the association degree to determine the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction includes:
[0043] If the degree of association is less than a fourth threshold, the data transmission operations contained in the i-th data transmission instruction are integrated to obtain the i-th data transmission module corresponding to the i-th data transmission instruction, and the data transmission operations contained in the j-th data transmission instruction are integrated to obtain the j-th data transmission module corresponding to the j-th data transmission instruction.
[0044] In some embodiments, the method further comprises:
[0045] The second process is output through the data display module of the trusted service management platform.
[0046] In some embodiments, the method further comprises:
[0047] The data display module of the trusted service management platform outputs status information of transmitting the target data to the security chip based on the second process.
[0048] The embodiment of the present application also provides a data transmission device, which is arranged on a trusted service management platform; the device comprises:
[0049] A determination module, used to determine a set of data transmission instructions included in a first process; wherein the first process includes an integrated process for transmitting target data to a security chip provided in a target device;
[0050] The determination module is further used to determine the data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain a data transmission module set; wherein the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than a first threshold; m and n are mutually unequal positive integers;
[0051] A processing module, used for integrating at least part of the data transmission modules in the data transmission module set to obtain a second process;
[0052] A transmission module is used to transmit the target data to the security chip based on the second process.
[0053] An embodiment of the present application further provides a trusted service management platform, which includes a processor and a memory; a computer program is stored in the memory; when the computer program is executed by the processor, it can execute any of the data transmission methods described above.
[0054] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored; when the computer program is executed by a processor of an electronic device, the data transmission method as described above can be implemented.
[0055] The data transmission method provided in the embodiment of the present application realizes the segmentation of the data transmission instruction level of the first process which is integrated and used to transmit the target data to the security chip set in the target device by determining the data transmission instruction set contained in the first process; and, by determining the data transmission module corresponding to the data transmission instruction in the data transmission instruction, a data transmission module set is obtained, and the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than the first threshold value. Thus, through the above operation, the modular segmentation of the data processing operation indicated by the data transmission instruction contained in the first process with low coupling degree is realized; at the same time, the second process is obtained by integrating at least part of the data transmission modules in the data transmission module set, and the coupling degree between the data transmission modules in the second process is less than the first threshold value, so that the second process can not only include the data processing operation steps and links contained in the first process, but also enable the second process to have flexible pluggable and combinable dynamic characteristics in the dimension of data transmission modules; on this basis, transmitting the target data to the security chip based on the second process can improve the flexibility of transmitting the target data to the security chip.
[0056] In the case where the target data is an installation package or executable code corresponding to any application, the data transmission method provided in the embodiment of the present application can determine a dynamically adjustable, pluggable and flexible transmission process, i.e., a second process, for transmitting the above-mentioned application package or executable code based on the original integrated transmission process, i.e., the first process, of the installation package or executable code corresponding to the application, thereby improving the flexibility of transmitting the above-mentioned application package or executable code; moreover, in the case where the above-mentioned installation package is an executable code, the target device is any device, and the security chip is any security chip, through the above-mentioned process, flexible conversion of the transmission process of any installation package or executable code can be achieved, thereby meeting the actual needs of sending or transmitting the installation package or executable code, reducing the requirements for the data transmission method and device type of the terminal device that applies the security chip, and thus providing technical support for the rapid expansion of the number and scope of cooperative equipment manufacturers. BRIEF DESCRIPTION OF THE DRAWINGS
[0057] Figure 1 A flowchart of a data transmission method provided in an embodiment of the present application;
[0058] Figure 2 A schematic diagram of a window for setting node properties provided in an embodiment of the present application;
[0059] Figure 3 A schematic diagram of a window of an application management platform provided in an embodiment of the present application;
[0060] Figure 4 A schematic diagram of a process for updating the second process provided in an embodiment of the present application;
[0061] Figure 5 A schematic diagram of the structure of a first data transmission module provided in an embodiment of the present application;
[0062] Figure 6 A schematic diagram of the structure of a second data transmission module provided in an embodiment of the present application;
[0063] Figure 7 A schematic diagram of the structure of a third data transmission module provided in an embodiment of the present application;
[0064] Figure 8 A schematic diagram of a window structure output by a data transmission module provided in an embodiment of the present application;
[0065] Fig. 9 A schematic diagram of the structure of a data transmission device provided in an embodiment of the present application;
[0066] Fig.10 A schematic diagram of the structure of the trusted service management platform provided in the embodiment of the present application. DETAILED DESCRIPTION
[0067] The technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application.
[0068] It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0069] As all walks of life pay more and more attention to data security, terminal devices with built-in security chips have been widely used in the field of data processing. At the same time, in order to meet the data management needs of the built-in security chip (Secure Element, SE) of terminal devices, including applications, the data management products provided by the Trusted Service Management (TSM) platform have also been widely used.
[0070] In actual applications, the TSM platform, as a professional system for managing SE and on-chip applications, first needs to achieve technical docking with terminal devices with built-in SE and various IoT management platforms, and then establish a communication connection between the TSM platform and the terminal devices with built-in SE on the basis of the above technical docking, and manage SE and on-chip applications through this communication connection, thereby providing a complete business chain.
[0071] In actual applications, since the TSM platform needs to manage applications of various terminal devices and / or IoT management platforms with built-in SE, the compatibility design of the TSM platform is particularly important. However, the TSM platform in the relevant technology usually follows the industry's unified industry specifications to implement the above application management operations; and the various instructions and business processes in the above application management operation process are fixed integrated process systems. All types of terminal devices and the device configuration status in the IoT management platform need to follow the rules of the above process system to obtain the application management services provided by the TSM platform.
[0072] Therefore, the application management methods in related technologies have increased the technical requirements for terminal devices and IoT platforms with built-in SE, thereby increasing the difficulty of equipment modification for users or manufacturers, extending the equipment modification cycle, and thus having an adverse impact on the promotion of SE.
[0073] Based on the above problems, the embodiments of the present application provide a data transmission method, device, TSM platform and medium.
[0074] The data transmission method provided in the embodiment of the present application is applied to the TSM platform, and the method can be implemented by a processor of the TSM platform. The above-mentioned processor can be at least one of an application-specific integrated circuit (ASIC), a digital signal processor (DSP), a digital signal processing device (DSPD), a programmable logic device (PLD), a field programmable gate array (FPGA), a central processing unit (CPU), a controller, a microcontroller (MCU), and a microprocessor.
[0075] Figure 1 A flow chart of a data transmission method provided in an embodiment of the present application is shown in FIG. Figure 1 As shown, the process may include the following steps:
[0076] Step 101: Determine a data transmission instruction set included in a first process.
[0077] The first process includes an integrated process for transmitting target data to the SE set in the target device.
[0078] In one embodiment, the target device may have a data processing function; illustratively, the target device may include a terminal device or a server device; illustratively, the data processing function may include functions such as data storage, transmission, conversion, and data statistics update.
[0079] In one implementation, the target data may include text data and / or non-text data; illustratively, the non-text data may include picture data, audio data, video data, and the like.
[0080] In one embodiment, the target data may include configuration data and / or executable code data, etc.; exemplarily, the configuration data may include parameters for configuring the SE and / or the target device; exemplarily, the executable code data may include an executable code or executable file corresponding to the application; exemplarily, the above-mentioned application may include a security element application to be set or updated in the SE.
[0081] In one implementation, the first process may include an integrated, fixed, and inseparable data transmission or air transmission process established in accordance with data security transmission specifications.
[0082] In one implementation, the first process may include multiple steps or links, and accordingly, the data transmission instruction in the data transmission instruction set may be used to instruct or trigger the execution of at least one of the above steps or links.
[0083] In one embodiment, the first process may include an integrated process for transmitting any target data, and may also include an integrated overall process for transmitting a specified type of target data.
[0084] In one implementation, the data transmission instruction set may be determined in any of the following ways:
[0085] The operations included in the first process are split to obtain an operation set, and a set of instructions that trigger the operations in the operation set is determined as a data transmission instruction set.
[0086] The sub-services included in the target service corresponding to the target data are analyzed to obtain a set of instructions for triggering the above sub-services, and the set of instructions is determined as a data transmission instruction set.
[0087] Step 102: Determine a data transmission module corresponding to a data transmission instruction in a data transmission instruction set, and obtain a data transmission module set.
[0088] The coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than a first threshold; m and n are different positive integers.
[0089] In one embodiment, any data transmission module in the data transmission module set can execute any atomic single operation included in the first process; illustratively, any data transmission module can respond to any instruction included in the first process in the form of a function or method, and execute the atomic single operation indicated by any of the above instructions.
[0090] In one implementation, the coupling degree between the mth data transmission module and the nth data transmission module is less than a first threshold, which may indicate that operations performed by the modules in the data transmission module are independent of each other.
[0091] In one implementation, the data transmission module in the data transmission module set may be a data preprocessing (Data Preparation, DP) module.
[0092] In one implementation, the data transmission module set may be obtained in any of the following ways:
[0093] An analysis is performed on the action indicated by the mth data transmission instruction in the data transmission instruction set, the execution timing of the above action, the execution condition of the above action, the return result after the execution of the above action, and at least one of the execution process of the above action to obtain an analysis result, and the above analysis result is used as a basis for dividing the code included in the first process, the first process is divided, and then the division result is determined as the mth data transmission module corresponding to the mth data transmission instruction; finally, the first data transmission module to the Mth data transmission module are determined as a data transmission module set; wherein M is the number of data transmission instructions included in the data transmission instruction set.
[0094] An analysis is performed on the action indicated by the mth data transmission instruction in the data transmission instruction set, the execution timing of the above action, the execution condition of the above action, the return result after the execution of the above action, and at least one of the execution process of the above action to obtain an analysis result, and code development is performed based on the above analysis result to obtain the mth code development result corresponding to the mth data transmission instruction, and then the mth code development result is determined as the mth data transmission module; finally, the first data transmission module to the Mth data transmission module are determined as a data transmission module set.
[0095] Step 103: Integrate at least part of the data transmission modules in the data transmission module set to obtain a second process.
[0096] In one embodiment, the second process can be obtained by any of the following methods:
[0097] Based on the execution order of the operations in the first process, at least part of the data transmission modules in the data transmission module set are integrated in terms of the timing dimension, and the integration result is determined as the second process.
[0098] Based on the logical relationship between the data processing operations included in the first process, at least part of the data transmission modules are integrated in terms of the logical relationship, and the integration result is determined as the second process.
[0099] In one implementation, at least part of the data transmission modules included in the second process can be dynamically adjusted according to the target business processing requirements corresponding to the target data.
[0100] In the embodiment of the present application, relative to the integrated and indivisible nature of the first process, the various data transmission modules in the second process can be associated with each other in a dynamic and pluggable manner.
[0101] In one implementation, the second process may be loaded in the TSM platform through at least one of a JAVA program, a Hypertext Transfer Protocol (HTTP) service, and an Application Protocol Data Unit (APDU) stream.
[0102] Step 104: Transmit the target data to the SE based on the second process.
[0103] In one implementation, the TSM platform may load the second process and send the target data to the SE through the second process.
[0104] From the above, it can be seen that the data transmission method provided in the embodiment of the present application realizes the segmentation of the data transmission instruction level of the first process which is integrated and used to transmit the target data to the security chip set in the target device by determining the data transmission instruction set contained in the first process; and, by determining the data transmission module corresponding to the data transmission instruction in the data transmission instruction, a data transmission module set is obtained, and the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than the first threshold value. Thus, through the above operation, a low-coupling modular segmentation of the data processing operation indicated by the data transmission instruction contained in the first process is realized; at the same time, a second process is obtained by integrating at least part of the data transmission modules in the data transmission module set, and the coupling degree between the data transmission modules in the second process is less than the first threshold value, so that the second process can not only include the data processing operation steps and links contained in the first process, but also enable the second process to have flexible, pluggable and combinable dynamic characteristics in the dimension of data transmission modules; on this basis, transmitting the target data to SE based on the second process can improve the flexibility of transmitting the target data to SE.
[0105] In the case where the target data is an installation package or executable code corresponding to any application, through the data transmission method provided in the embodiment of the present application, through the above steps, it is possible to determine a dynamically adjustable, pluggable and flexible transmission process, i.e., the second process, for transmitting the above application package or executable code based on the original integrated transmission process, i.e., the first process, of the installation package or executable code corresponding to the application, thereby improving the flexibility of transmitting the above application package or executable code; moreover, in the case where the above installation package is an executable code, the target device is any device, and the SE is any SE, through the above process, it is possible to achieve flexible conversion of the transmission process of any installation package or executable code, thereby meeting the actual needs of sending or transmitting the installation package or executable code, reducing the requirements for the data transmission method and device type of the terminal device applying the SE, and thus providing technical support for the rapid expansion of the number and scope of cooperative equipment manufacturers.
[0106] Exemplarily, through the data transmission method provided in the embodiments of the present application, a service provider (Service Provider TSM, SP-TSM) platform and a SE-TSM platform can be constructed. Therefore, the data transmission method provided in the embodiments of the present application has wide universality and versatility, and can be applied to the underlying technical support links of large-scale TSM platform systems.
[0107] Based on the above embodiments, the data transmission method provided in the embodiments of the present application integrates at least part of the data transmission modules in the data transmission module set to obtain the second process, which can be implemented in the following manner:
[0108] Step A1: Obtain device configuration information of the target device.
[0109] In one implementation, the device configuration information may include hardware configuration information of the target device. Exemplarily, the hardware configuration information may include at least one of the size of the memory space of the target device, the type of processor, and the type of network card.
[0110] In one embodiment, the device configuration information may include software configuration information of the target device. Exemplarily, the software configuration information may include at least one of the data type or business type processed by the target device, the type of operating system of the target device, and the operating period of the target device.
[0111] Step A2: Based at least on the device configuration information, integrate at least part of the data transmission module to obtain a second process.
[0112] In one embodiment, the second process can be obtained by:
[0113] Based on the data transmission mode of the target device represented by the device configuration information, after integrating at least some data transmission modules to generate target data, at least some data transmission modules for generating and sending data packets are integrated to obtain the second process.
[0114] Based on the service type supported by the target data in the device configuration information, at least some of the data transmission modules are integrated so that at least some of the integrated data modules can convert the target data into data packets corresponding to the above service type, thereby obtaining the second process.
[0115] Exemplarily, taking the calling process in the second flow as an example, the calling request for calling the mth data transmission module may include the following data:
[0116] Seid: SE identifier;
[0117] seInfo: related card information when returning the card, can be empty;
[0118] busParams: the input parameter when starting the second process for the first time. This parameter can include all the business parameters required during the execution of the second process.
[0119] responseAPDUs: SE execution result set;
[0120] responseAPDU: execution result, empty if none;
[0121] commandAPDU: the command actually executed. This parameter includes the expected sw value set expectedSws[] for each command. If this value is not set, the default value is 9000.
[0122] context: global context parameters.
[0123] Exemplarily, the return parameters after the mth data transmission module call ends may include the following data:
[0124] commandAPDUs: command set, can be empty;
[0125] commandAPDU: the command to be executed, including expectedSws[] for each command;
[0126] commandAPDU: the actual executed command;
[0127] expectedSws: the expected sw value set for each instruction. If it is empty, the parameter defaults to 9000;
[0128] finalData: the result of the business processing after the last step is completed;
[0129] newContext: The runtime context parameter newly added during this call, which will be added to the global context parameter.
[0130] As can be seen from the above, the data transmission method provided in the embodiment of the present application, after obtaining the device configuration information of the target device, integrates at least part of the data transmission module based on at least the device configuration information to obtain the second process. In this way, through the above operation, the matching degree between the second process and the device configuration information of the target device can be improved, thereby improving the stability of the second process in transmitting the target data to the SE.
[0131] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, integrating at least part of the data transmission modules in the data transmission module set to obtain the second process can also be implemented in the following manner:
[0132] Obtain security configuration information of the SE; and integrate at least part of the data transmission module based on at least the security configuration information to obtain a second process.
[0133] In one implementation, the security configuration information may include the hardware security configuration status of the SE; illustratively, the hardware security configuration status may include the size and type of the flash memory space in the SE, the type of the microkernel, and the like.
[0134] In one implementation, the security configuration information may include the software security configuration status of the SE; illustratively, the software security configuration status may include at least one of a data processing algorithm, a data encryption algorithm, a security domain configuration method, and a process scheduling strategy configured in the SE.
[0135] In one embodiment, the second process can be obtained by:
[0136] Based on the data decryption algorithm included in the security configuration information, the data transmission modules for encrypting the target data in at least part of the data transmission modules are integrated to obtain the second process.
[0137] Based on the security domain configuration mode in the security configuration information, the data transmission modules related to the security domain application in at least part of the data transmission modules are specifically integrated to obtain the second process.
[0138] From the above, it can be seen that the data transmission method provided in the embodiment of the present application, after obtaining the security configuration information of the SE, obtains the second process by integrating at least part of the data transmission module based on at least the security configuration information, so that the data processing operations included in the second process can meet the actual data processing needs of the SE, thereby increasing the probability of the target data being successfully received and stably processed by the SE.
[0139] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, integrating at least part of the data transmission modules in the data transmission module set to obtain the second process can also be implemented in the following manner:
[0140] Obtain input configuration information for the TSM platform; integrate the sequence and / or startup method of at least part of the data transmission module based on the input configuration information to obtain a second process.
[0141] In one implementation, the input configuration information may include at least one of the names, execution order, execution conditions, startup methods, and related services or processes of the data transmission modules in at least some of the data transmission modules.
[0142] In one implementation, inputting configuration information may be implemented through a human-machine interaction mechanism or module provided in the TSM platform.
[0143] Figure 2 A schematic diagram of a window for setting node attributes provided in an embodiment of the present application. Figure 2As shown, a user or administrator of the TSM platform can perform setting and editing operations including node name, DP group and DP module through the first window 201 for setting node properties as shown in the figure; exemplarily, the node name may include the name of the node device to which the data transmission module belongs; exemplarily, the DP group may include the group of applications to which the data transmission module belongs, such as the health code identity application shown in the figure; exemplarily, the DP module may include the name of the data transmission module, such as the default key external authentication shown in the figure.
[0144] For example, Figure 2 After the save option in is triggered, the node attributes set in the first window 201 will be saved.
[0145] Figure 3 A schematic diagram of a window of an application management platform provided in an embodiment of the present application. Figure 3 As shown, the vertical list on the left side of the second window 301 displaying the application management platform includes a variety of management options including home page, system management, platform management, TSM card management, TSM application management, TSM service management, DP module management, service group management, service process definition management, service process processing process management and process processing process log management; at least some of the above-mentioned management options may also be listed in the header part of the second window 301; after the above-mentioned service process definition is selected, the service process definition list can be displayed.
[0146] Exemplarily, the service process definition list may include data such as serial number, ID, service group, service name, service category, version number, and operation options as shown in the second window 301; wherein, the serial number may be expressed in the form of a hexadecimal sequence as shown in the figure, the service group may include the Suishen Code Empty Issuance, Digital Currency Hard Wallet, etc. described in the figure, the service name may include Suishen Code Empty Issuance Wrong, Suishen Code Empty Issuance, Write Identity Information, Application Deletion, and Application Installation, etc., the service category may include application installation, application service, and application deletion, etc., the version number may be reflected in the form of a combination of the numbers and "." shown in the figure, and the operation options may include modification and deletion options.
[0147] Exemplarily, if the modification option in the operation options included in any service process is triggered, the editing option list for modifying the service process definition shown at the bottom of the second window 301 can be output; wherein the above-mentioned editable option list can include the service group, service name, service category and version number, etc.
[0148] Exemplarily, the second window 301 may also provide a new service process definition option and a service process page turning option.
[0149] It should be noted that the service process in the second window 301 may be the data transmission module in the aforementioned embodiment, and the service group to which it belongs may be used to describe the specific operations performed by the data transmission module.
[0150] In one implementation, the specific content included in the input configuration information can be determined according to at least one of the target service processing requirements corresponding to the target data, the device configuration information of the target device provided in the aforementioned embodiment, and the security configuration information of the SE.
[0151] As can be seen from the above, the data transmission method provided in the embodiment of the present application, after obtaining the input configuration information for the TSM platform, integrates the sequence and / or startup mode of at least part of the data transmission modules based on the input configuration information to obtain the second process. In this way, through the above operation, the targeted control integration of the sequence and / or startup mode of at least part of the data transmission modules based on the input configuration information is realized, thereby improving the targetedness and controllability of the second process; and by integrating at least part of the data transmission modules based on the input configuration information, the flexibility of the above integration operation can also be improved.
[0152] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, integrating at least part of the data transmission modules in the data transmission module set to obtain the second process can also be implemented in the following manner:
[0153] Based on the business processing logic of the target business corresponding to the target data, conditional control is performed on the jump relationship between at least part of the data transmission modules to obtain the second process.
[0154] In one embodiment, the business processing logic may include at least one of the conditions for jumping between at least some steps and / or links in the target business, whether to repeat the execution, and the judgment rules for the execution results.
[0155] In one embodiment, the second process can be obtained by any of the following methods:
[0156] According to the start and end conditions of the business processing logic, the jump relationship between at least some of the data transmission modules is sorted out so that at least some of the data transmission modules only contain one start module and one end module, thereby reducing the probability of the data transmission modules forming a closed loop, and at least some of the data transmission modules after sorting out are determined as the second process.
[0157] If the business processing logic indicates that a certain data transmission module needs to be repeatedly executed, the calling process of the data transmission module and its adjacent data transmission modules can be controlled by a script. A new data transmission module with the same function can also be created, and the calling relationship between the data transmission modules with the same function can be integrated to obtain the second process.
[0158] Based on the business processing logic, the jump relationship of at least part of the data transmission modules is controlled to reduce uncontrollable multi-branch jumps, thereby obtaining the second process; exemplarily, the multi-branch jump may include switching to data transmission modules F and M at the same time after the data transmission module A is executed, thereby causing the data transmission modules F and M to be activated or started at the same time.
[0159] Based on the business processing logic, the jump conditions between at least some data transmission modules are strictly controlled. For example, if and else must exist at the same time to reduce the probability of causing the data transmission modules F and M to be activated or started at the same time as mentioned above.
[0160] As can be seen from the above, the data transmission method provided in the embodiment of the present application performs conditional control on the jump relationship between at least some data transmission modules based on the business processing logic of the target business corresponding to the target data to obtain the second process. In this way, through the above operation, not only the pertinence and accuracy of the conditional control on the jump relationship between at least some data transmission modules can be improved, but also the consistency between the switching relationship between at least some transmission modules and the business processing logic of the target business can be improved, thereby improving the accuracy of the second process.
[0161] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, integrating at least part of the data transmission modules in the data transmission module set to obtain the second process can also be implemented in the following manner:
[0162] Determine an exception handling mechanism; integrate at least part of the data transmission module based on the exception handling mechanism to obtain a second process.
[0163] In one embodiment, the exception handling mechanism may include a mechanism for handling abnormal events occurring during the execution of at least part of the data transmission module; illustratively, the exception handling mechanism may include whether to start an exception capture mechanism.
[0164] In one embodiment, the second process can be obtained by:
[0165] If the exception handling mechanism includes starting an exception capture mechanism, exception capture code can be added between and / or inside at least some data transmission modules, and when an exception occurs, it can be captured and output to obtain the second process; illustratively, by setting ignore-error to false, exception capture can be triggered or execution can be exited when an exception occurs.
[0166] If the exception handling mechanism includes not starting the exception capture mechanism, ignore-error can be set to true in at least some data transmission modules, so that at least some data transmission modules continue to execute even if an exception occurs during execution, thereby obtaining the second process.
[0167] As can be seen from the above, the data transmission method provided in the embodiment of the present application, after determining the exception handling mechanism, integrates at least part of the data transmission module based on the exception handling mechanism to obtain the second process. In this way, through the above operation, not only can the exception capture efficiency when an exception occurs during the execution of at least part of the data transmission module be improved, but also the robustness of the second process can be improved.
[0168] Based on the above embodiments, the data transmission method provided in the embodiments of the present application may further perform the following steps after integrating at least part of the data transmission modules in the data transmission module to obtain the second process:
[0169] Determine a process score of the second process; if the process score is less than a second threshold, adjust and update the second process.
[0170] Exemplarily, if the process score is greater than or equal to the second threshold, the second process may not be updated.
[0171] In one embodiment, the process score may represent a success rate or a stable state of sending the target data to the SE through the second process.
[0172] In one implementation, the process score may represent a delay status of sending the target data to the SE through the second process.
[0173] In one implementation, a process score less than the second threshold may indicate that the target data cannot be successfully or stably sent to the SE through the second process.
[0174] In one implementation, the process score may be determined by any of the following methods:
[0175] In the process of sending the target data through the second process, statistics are collected on abnormal events that occur in the above process, and the statistical results are determined as the process score.
[0176] The process of sending target data through the second process is simulated in the TSM platform, and statistics are collected on indicators such as anomalies, delay jitter, and stability that occur in the above simulation process. Then, the statistical results are determined as the process score.
[0177] In one implementation, adjusting and updating the second process may be implemented in any of the following ways:
[0178] The data transmission modules included in the second process are sequentially adjusted, thereby adjusting and updating the second process.
[0179] The jump relationship between the data transmission modules included in the second process is adjusted, so as to adjust and update the second process.
[0180] The data transmission module included in the second process is replaced and updated, thereby adjusting and updating the second process.
[0181] Based on the adjustment instruction input to the TSM platform, the second process is adjusted and updated.
[0182] As can be seen from the above, the data transmission method provided in the embodiment of the present application, after determining the process score of the second process, if the process score is less than the second threshold, adjusts and updates the second process. In this way, not only is strict control of the operation of adjusting and updating the second process achieved, but also targeted adjustment and update of the second process can be achieved, thereby improving the targetedness and accuracy of the adjustment and update.
[0183] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, adjusting and updating the second process can be implemented by the following steps:
[0184] Step B1: If the matching degree between at least part of the code included in the mth data transmission module and the security configuration information of the SE is less than or equal to a third threshold, determine an updated data transmission module corresponding to at least part of the code.
[0185] Exemplarily, if the degree of matching between at least part of the code included in the mth data transmission module and the security configuration information of the SE is greater than a third threshold, it may be determined not to update the data transmission module.
[0186] In one implementation, updating the data transmission module may include correcting at least a portion of the code in the mth data transmission module whose matching degree with the security configuration information is less than or equal to a third threshold to obtain a code set.
[0187] In one implementation, the result that the matching degree is less than or equal to the third threshold value may be determined during the execution of the second process, or may be determined in the TSM platform through software simulation.
[0188] In one implementation, updating the data transmission module may be determined in the following manner:
[0189] Based on the security configuration information, the operations that need to be performed on at least part of the above code are corrected or changed, and the above correction or change results are determined as an updated data transmission module.
[0190] In one embodiment, the degree of match between at least part of the code and the security configuration information is less than or equal to a third threshold, which may indicate that the operation to be performed by at least part of the code does not completely match the security policy contained in the security configuration information. For example, at least part of the code includes an operation to create a security domain, but the security configuration information indicates that the SE does not support the creation of a dynamic security domain.
[0191] Step B2: Integrate and update the data transmission module and at least part of the data transmission module to adjust and update the second process.
[0192] In one implementation, updating the second process may be achieved in the following manner:
[0193] According to the data transmission relationship between at least part of the code and the mth data transmission module, a switching script is constructed between the mth data transmission module and its adjacent data transmission modules and the update data transmission module, and based on the update data transmission module and at least part of the data transmission module integrated in the switching script, the order and / or startup method between the corresponding modules in the second process are updated.
[0194] Figure 4 A schematic diagram of a process for updating the second process provided in an embodiment of the present application, such as Figure 4 As shown, the method may include the following steps:
[0195] Step 401, start.
[0196] Step 402: sort out the SE application empty sending business process.
[0197] Exemplarily, the application of the air-sending service process may include the first process in the aforementioned embodiment.
[0198] Step 403: Split the sub-business instruction flow.
[0199] Exemplarily, the sub-service instruction process may include the data transmission instruction set in the aforementioned embodiment.
[0200] Step 404: Dynamically adjust the sub-service instruction flow.
[0201] Exemplarily, a data transmission module set corresponding to a data transmission instruction set may be determined, and based on the jump relationship between sub-business instruction flows, at least some of the data transmission modules in the data transmission module set may be integrated to achieve dynamic adjustment of the sub-business instruction flows.
[0202] Exemplarily, the sub-business instruction flow can also be dynamically adjusted by adjusting the jump order between at least some data transmission modules, or by determining the updated data transmission module associated with the mth data transmission module where the exception occurs, and integrating at least some data transmission modules and the updated data transmission module.
[0203] Step 405: Load the instructions into the system.
[0204] Exemplarily, the system may include a TSM platform.
[0205] Exemplarily, loading the instruction into the system may include simulating loading the second process in the running space of the TSM platform, or executing an operation of transmitting the target data to the SE based on the second process.
[0206] Step 406: Assemble the sub-business instruction flows.
[0207] Exemplarily, the execution order of at least some of the data transmission modules may be assembled based on the jump relationship between at least some of the data transmission modules included in the second process.
[0208] Step 407: Execute the application empty send operation.
[0209] Exemplarily, the application here may be an executable code corresponding to the application program, that is, the target data in the aforementioned embodiment.
[0210] Exemplarily, the application empty launch operation may be simulated and executed in the TSM platform, or the application empty launch operation may be executed based on the second process.
[0211] Step 408: Determine whether the empty transmission operation is successful.
[0212] Exemplarily, if the empty transmission operation is unsuccessful, step 409 is executed; if the empty transmission operation is successful, step 410 is executed.
[0213] Step 409: Check the command log.
[0214] Exemplarily, if the empty send operation is unsuccessful, the cause of the failure can be checked through the instruction log output by the exception capture mechanism included in the second process, and step 404 can be continued.
[0215] Step 410, end.
[0216] Through the above process, the determination and dynamic adjustment process of the sub-business instruction empty sending process are completely realized.
[0217] From the above, it can be seen that in the data transmission method provided by the embodiment of the present application, if the matching degree between at least part of the code contained in the mth data transmission module in the second process and the security configuration information of the security chip is less than or equal to the third threshold, then the update data transmission module corresponding to at least part of the code is determined, and the update data transmission module and at least part of the data transmission module are integrated to adjust and update the second process. In this way, through the above operation, the dynamic, targeted and real-time adjustment and update of the second process is realized, thereby realizing the dynamic adjustment of the second process, so that the second process can meet the diverse data transmission needs.
[0218] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, adjusting and updating the second process can be implemented in the following manner:
[0219] Obtain log information whose process score is less than a second threshold; and adjust and update the data transmission module included in the second process based on the log information.
[0220] In one embodiment, the log information may include the code status of the data transmission module or the code block in the data transmission module that causes the process score to be less than the second threshold; exemplarily, the above-mentioned code status may include exceptions occurring during the code execution, the number of resources occupied by the code execution, and the input and output data during the code execution.
[0221] In one implementation, adjusting and updating the data transmission module included in the second process may be implemented in the following manner:
[0222] Based on the anomaly contained in the log information, the data transmission module to be adjusted is determined from the second process, and the data transmission module to be adjusted in the second process is optimized or replaced, thereby adjusting and updating the data transmission module contained in the second process.
[0223] From the above, it can be seen that the data transmission method provided in the embodiment of the present application, after obtaining log information whose process score is less than or equal to the second threshold, can improve the pertinence and accuracy of the adjustment and update of the data transmission module included in the second process by adjusting and updating the data transmission module included in the second process based on the log information, thereby enabling targeted dynamic adjustment and update of the second process.
[0224] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, determining the process score of the second process can be achieved by the following steps:
[0225] Step C1: Determine a first weight of the mth data transmission module.
[0226] In one implementation, the first weight may represent the importance of the service sub-process or the executed operation corresponding to the mth data transmission module.
[0227] In one implementation, the first weight may be determined or adjusted according to a business processing requirement of a target business corresponding to the target data.
[0228] Step C2: Determine a second weight of at least part of the code included in the mth data transmission module.
[0229] The degree of matching between at least part of the code and the security configuration information of the SE is less than or equal to a third threshold.
[0230] In one embodiment, the second weight may include the importance of the operation performed by the code contained in the data transmission module corresponding to the log information in the execution process of the target business corresponding to the target data; illustratively, the second weight can be determined based on the above importance.
[0231] Step C3: Determine the process score based on the first weight and the second weight.
[0232] In one implementation, the process score may be determined by taking a weighted statistical average of the first weight and the second weight.
[0233] Exemplarily, taking the mth data transmission module and the nth data transmission module in the second process as an example, the process scores corresponding to the mth data transmission module and the nth data transmission module can be determined by formula (1):
[0234] A=bc+de (1)
[0235] Among them, A is the process score corresponding to the mth data transmission module and the nth data transmission module, b and d can be the first weights of the mth data transmission module and the nth data transmission module respectively, and c and e are the second weights of at least part of the code corresponding to the mth data transmission module and the nth data transmission module respectively.
[0236] From the above, it can be seen that the data transmission method provided in the embodiment of the present application determines the process score based on the first weight and the second weight after determining the first weight of the mth data transmission module in the second process and the second weight of at least part of the code contained in the mth data transmission module, wherein the degree of match between at least part of the code and the security configuration information of the SE is less than or equal to the third threshold. In this way, through the above operation, the weight of the code contained in the mth data transmission module can be finely characterized through the first weight and the second weight; and based on the first weight and the second weight, the score of the mth data transmission module in the second process can be finely and accurately characterized.
[0237] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, determining the data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain the data transmission module set can be implemented by the following steps:
[0238] Step D1: Determine the degree of association between the i-th data transmission instruction and the j-th data transmission instruction in the data transmission instruction set.
[0239] Here, i and j are positive integers that are different from each other.
[0240] In one embodiment, the degree of association may include the closeness of the association between the i-th data transmission instruction and the j-th data transmission instruction in the time dimension and / or the processing result dimension; exemplarily, the association in the time dimension may include whether the j-th data transmission instruction is triggered depending on the end time of the execution of the i-th data transmission instruction; exemplarily, the association in the processing result dimension may include whether the j-th data transmission instruction is dependent on at least part of the results output during the execution of the i-th data transmission instruction.
[0241] In one embodiment, the above correlation degree can be determined by:
[0242] The time sequence and / or the dependency of the input and output parameter dimensions of the i-th data transmission instruction and the j-th data transmission instruction during the execution process are analyzed to determine the degree of association.
[0243] Step D2: Process the ith data transmission instruction and / or the jth data transmission instruction based on the degree of association, and determine the data transmission module corresponding to the ith data transmission instruction and / or the jth data transmission instruction.
[0244] In one implementation, the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction may be determined in the following manner:
[0245] There may be an association relationship between the degree of association and the module determination strategy. After determining the above-mentioned degree of association, the target module determination strategy may be determined from the above-mentioned association relationship based on the matching relationship between the currently determined degree of association and the degree of association in the above-mentioned association relationship. Then, based on the target module determination strategy, the operations performed by the i-th data transmission instruction and / or the j-th data transmission instruction may be modularly processed to obtain the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction.
[0246] From the above, it can be seen that the data transmission method provided in the embodiment of the present application, after determining the degree of association between the i-th data transmission instruction and the j-th data transmission instruction in the data transmission instruction set, determines the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction by processing the i-th data transmission instruction and / or the j-th data transmission instruction based on the degree of association. In this way, since the degree of association can reflect the closeness of the association relationship between the operations executed by the i-th data transmission instruction and the j-th data transmission instruction, the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction is determined based on the degree of association, so that the operation performed by the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction can be consistent with the degree of association between the instructions executed by the i-th data transmission instruction and the j-th data transmission instruction.
[0247] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, the i-th data transmission instruction and / or the j-th data transmission instruction are processed based on the degree of association, the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction is determined, and a data transmission module set is obtained, which can be implemented in the following manner:
[0248] If the correlation degree is greater than or equal to the fourth threshold, the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction are integrated at least based on the correlation degree to obtain the data transmission modules corresponding to the i-th data transmission instruction and the j-th data transmission instruction.
[0249] Exemplarily, if the correlation degree is less than the fourth threshold, the operation of integrating the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction based on the correlation degree may not be performed.
[0250] In one embodiment, the degree of association is greater than or equal to the fourth threshold, which can indicate that the degree of coupling between the data transmission operations performed by the i-th data transmission instruction and the j-th data transmission instruction is relatively high. At this time, the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction are integrated to achieve overall integrated processing of the above-mentioned data transmission operations with a relatively high degree of coupling.
[0251] Figure 5 This is a schematic diagram of the structure of the first data transmission module provided in the embodiment of the present application. Figure 5As shown, the first data transmission module 501 may include three data processing steps corresponding to the three data transmission instructions in the data transmission instruction set: selecting a security domain and initiating initialization 502, SCP02 default key external authentication 503, and installing an application 504, and may also include a start 505 and an end 506 for encapsulating the above three data processing steps; wherein the degree of association between the above three data transmission instructions may be greater than or equal to a fourth threshold.
[0252] Figure 6 A schematic diagram of the structure of the second data transmission module provided in the embodiment of the present application, such as Figure 6 As shown, the second data transmission module 601 may include three data processing steps corresponding to the three data transmission instructions in the data transmission instruction set: selecting a security domain and initiating initialization 602, SCP02 default key external authentication 603, and installation and deletion 604, and may also include a start 605 and an end 606 for encapsulating the above three data processing steps; wherein the degree of association between the above three data transmission instructions may be greater than or equal to a fourth threshold.
[0253] From the above, it can be seen that in the data transmission method provided in the embodiment of the present application, the degree of correlation is greater than or equal to the fourth threshold, which can characterize that the coupling degree between the data transmission operations performed by the i-th data transmission instruction and the j-th data transmission instruction is relatively high. At this time, the data transmission operations contained in the i-th data transmission instruction and the j-th data transmission instruction are integrated, and the overall integration processing of the above-mentioned data transmission operations with a relatively high coupling degree can be realized, thereby improving the stability and security of the above-mentioned data transmission module when transmitting target data to SE.
[0254] Based on the foregoing embodiment, in the data transmission method provided in the embodiment of the present application, the i-th data transmission instruction and / or the j-th data transmission instruction are processed based on the degree of association, and the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction is determined, which can also be implemented in the following manner:
[0255] If the degree of association is less than the fourth threshold, the data transmission operations contained in the i-th data transmission instruction are integrated to obtain the i-th data transmission module corresponding to the i-th data transmission instruction, and the data transmission operations contained in the j-th data transmission instruction are integrated to obtain the j-th data transmission module corresponding to the j-th data transmission instruction.
[0256] Exemplarily, if the degree of association is greater than or equal to the fourth threshold, the data transmission operations respectively contained in the i-th data transmission instruction and the j-th data transmission instruction can be integrated through the method provided in the above-mentioned embodiment to obtain the data transmission module corresponding to the i-th data transmission operation and the j-th data transmission operation.
[0257] In one embodiment, the degree of correlation is less than the fourth threshold, which can indicate that the coupling degree between the data transmission operations performed by the i-th data transmission instruction and the j-th data transmission instruction is low. At this time, the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction are integrated respectively, which can improve the flexibility of dynamic combination and adjustment between various data transmission modules.
[0258] Figure 7 A schematic diagram of the structure of the third data transmission module provided in the embodiment of the present application, such as Figure 7 As shown, the third data transmission module 701 may include a start 702, write identity information 703 and an end 704; wherein, the write identity information 703 may correspond to an instruction in the data transmission instruction set for triggering the write identity information, and the degree of association between the instruction and other instructions may be less than a fourth threshold value. Therefore, the third data transmission module 701 may only include a single link of the write identity information 703.
[0259] From the above, it can be seen that in the data transmission method provided in the embodiment of the present application, if the degree of association is less than the fourth threshold, the data transmission operations contained in the i-th data transmission instruction and the j-th data transmission instruction are respectively integrated to obtain the data transmission modules corresponding to the i-th data transmission instruction and the j-th data transmission instruction respectively. In this way, through the above operation, by making full use of the fact that the degree of association between the i-th data transmission instruction and the j-th data transmission instruction is less than the fourth threshold, the coupling degree between the data transmission modules corresponding to the i-th data transmission instruction and the j-th data transmission instruction respectively can be reduced.
[0260] Based on the above embodiments, the data transmission method provided in the embodiments of the present application may also perform the following operations:
[0261] The second process is output through the data display module of the TSM platform.
[0262] In one implementation, the data display module may include a data display device; illustratively, the data display device may include a display screen.
[0263] In one implementation, the data display module can present the second process visually and intuitively through a graphical component layout technology, thereby facilitating professional and technical personnel to achieve efficient and fast business customization.
[0264] In one implementation, the data output module may include a software module specifically used to display the second process; illustratively, the software module may include a canvas module.
[0265] Figure 8 Schematic diagram of the window structure output by the data transmission module provided in the embodiment of the present application. Figure 8 As shown, the five data processing steps included in the first data transmission module 501 can be displayed in the second window 301, and the above data processing steps can be represented in the form of icons and texts; exemplarily, the loading option 801 of the second process can also be displayed in the second window 301, wherein the loading option 801 can include options such as start, APDU, JAVA loading, conditions and end; exemplarily, the conditions can include the conditions for loading the first data transmission module.
[0266] It can be seen from the above that in the data transmission method provided in the embodiment of the present application, the second process is output through the data display module of the TSM platform, so that the second process can be represented intuitively and figuratively.
[0267] Based on the foregoing embodiment, the data transmission method provided in the embodiment of the present application may further include the following steps:
[0268] Through the data display module of the TSM platform, the status information of transmitting the target data to the SE based on the second process is output.
[0269] In one implementation, the status information may include text identifiers or icon information of data transmission modules that are in an activated state, an unactivated state, or have been executed in the second process; illustratively, the above text identifiers may include the names of the data transmission modules.
[0270] In one implementation, the status information may include log information during the execution of the second process; illustratively, the log information may include exception information.
[0271] As can be seen from the above, the data transmission method provided in the embodiment of the present application outputs the state information of the target data transmitted to the SE based on the second process through the data display module of the TSM platform. In this way, through the above operation, the dynamic real-time and intuitive display of the execution process of the second process is realized, thereby improving the state tracking effect of the execution progress of the second process.
[0272] Based on the above embodiments, the present application also provides a data transmission device. Fig. 9 A schematic diagram of the structure of a data transmission device provided in an embodiment of the present application is shown in FIG. Fig. 9 As shown, the data transmission device 9 may include:
[0273] The determination module 901 is used to determine a data transmission instruction set included in a first process; wherein the first process includes an integrated process for transmitting target data to a security chip provided in a target device;
[0274] The determination module 901 is further used to determine the data transmission module corresponding to the data transmission instruction in the data transmission instruction set, and obtain the data transmission module set; wherein the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than the first threshold; m and n are mutually unequal positive integers;
[0275] A processing module 902 is used to integrate at least part of the data transmission modules in the data transmission module set to obtain a second process;
[0276] The transmission module 903 is used to transmit the target data to the security chip based on the second process.
[0277] In some embodiments, the data transmission device 9 may further include an acquisition module for acquiring device configuration information of the target device;
[0278] The processing module 902 is used to integrate at least part of the data transmission module based on at least the device configuration information to obtain a second process.
[0279] In some embodiments, the acquisition module is used to obtain security configuration information of the security chip;
[0280] The processing module 902 is used to integrate at least part of the data transmission module based on at least the security configuration information to obtain a second process.
[0281] In some embodiments, an acquisition module is used to obtain input configuration information for a trusted service management platform;
[0282] The processing module 902 is used to integrate the sequence and / or the start-up method of at least part of the data transmission modules based on the input configuration information to obtain a second process.
[0283] In some embodiments, the processing module 902 is used to conditionally control the jump relationship between at least some data transmission modules based on the business processing logic of the target business corresponding to the target data to obtain the second process.
[0284] In some embodiments, the determination module 901 is used to determine an exception handling mechanism;
[0285] The processing module 902 is used to integrate at least part of the data transmission module based on the exception handling mechanism to obtain a second process.
[0286] In some embodiments, the determination module 901 is used to determine a process score of the second process;
[0287] The processing module 902 is used to adjust and update the second process if the process score is less than the second threshold.
[0288] In some embodiments, the determination module 901 is configured to determine an update data transmission module corresponding to at least a portion of the code if the degree of match between at least a portion of the code included in the mth data transmission module and the security configuration information of the security chip is less than or equal to a third threshold;
[0289] The processing module 902 is used to integrate and update the data transmission module and at least a part of the data transmission module to adjust and update the second process.
[0290] In some embodiments, the acquisition module is used to acquire log information whose process score is less than or equal to the second threshold;
[0291] The processing module 902 is used to adjust and update the data transmission module included in the second process based on the log information.
[0292] In some embodiments, the determination module 901 is used to determine the first weight of the mth data transmission module; determine the second weight of at least part of the code contained in the mth data transmission module; determine the process score based on the first weight and the second weight; wherein the degree of match between at least part of the code and the security configuration information of the security chip is less than or equal to a third threshold.
[0293] In some embodiments, the determination module 901 is used to determine the degree of association between the i-th data transmission instruction and the j-th data transmission instruction in the data transmission instruction set; wherein i and j are positive integers that are different from each other;
[0294] The determination module 901 is further configured to process the ith data transmission instruction and / or the jth data transmission instruction based on the degree of association, and determine the data transmission module corresponding to the ith data transmission instruction and / or the jth data transmission instruction.
[0295] In some embodiments, the processing module 902 is used to integrate the data transmission operations contained in the i-th data transmission instruction and the j-th data transmission instruction at least based on the degree of association if the degree of association is greater than or equal to a fourth threshold, to obtain a data transmission module corresponding to the i-th data transmission instruction and the j-th data transmission instruction.
[0296] In some embodiments, the processing module 902 is used to integrate the data transmission operations included in the i-th data transmission instruction to obtain the i-th data transmission module corresponding to the i-th data transmission instruction, and integrate the data transmission operations included in the j-th data transmission instruction to obtain the j-th data transmission module corresponding to the j-th data transmission instruction if the degree of association is less than a fourth threshold.
[0297] In some embodiments, the data transmission device 9 may further include a data display module for outputting the second process.
[0298] In some embodiments, the data display module is used to output status information of transmitting the target data to the security chip based on the second process.
[0299] Based on the above embodiments, the present application also provides a TSM platform. Fig.10 A schematic diagram of the structure of the trusted service management platform provided in the embodiment of the present application, such as Fig.10 As shown, the TSM platform 10 may include a processor 1001 and a memory 1002 ; wherein the memory 1002 stores a computer program, and when the computer program is executed by the processor 1001 , the data transmission method provided in any of the previous embodiments can be implemented.
[0300] The above-mentioned processor can be at least one of ASIC, DSP, DSPD, PLD, FPGA, CPU, controller, microcontroller, and microprocessor.
[0301] The above-mentioned memory can be a volatile memory (volatile memory), such as a random access memory (Random Access Memory, RAM); or a non-volatile memory (non-volatile memory), such as a read-only memory (Read-Only Memory, ROM), flash memory, a hard disk drive (Hard Disk Drive, HDD) or a solid state drive (SSD); or a combination of the above types of memory, and provide instructions and data to the processor.
[0302] Based on the foregoing embodiments, an embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor of an electronic device, the data transmission method provided in any of the previous embodiments can be implemented.
[0303] The above description of various embodiments tends to emphasize the differences between the various embodiments. The same or similar aspects can be referenced to each other, and for the sake of brevity, they will not be repeated herein.
[0304] The methods disclosed in the various method embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments.
[0305] The features disclosed in the various product embodiments provided in this application can be arbitrarily combined without conflict to obtain new product embodiments.
[0306] The features disclosed in the various method or device embodiments provided in this application can be arbitrarily combined without conflict to obtain new method embodiments or device embodiments.
[0307] It should be noted that the above-mentioned computer-readable storage medium can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory (Flash Memory), a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM) and other memories; it can also be various electronic devices including one or any combination of the above-mentioned memories, such as mobile phones, computers, tablet devices, personal digital assistants, etc.
[0308] It should be noted that, in this article, the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the sentence "comprises a ..." does not exclude the existence of other identical elements in the process, method, article or device including the element.
[0309] The serial numbers of the above-mentioned embodiments of the present application are for description only and do not represent the advantages or disadvantages of the embodiments.
[0310] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus necessary general hardware nodes, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.
[0311] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0312] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.
[0313] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.
[0314] The above are only preferred embodiments of the present application, and are not intended to limit the patent scope of the present application. Any equivalent structure or equivalent process transformation made using the contents of the present application specification and drawings, or directly or indirectly applied in other related technical fields, are also included in the patent protection scope of the present application.
Claims
1. A data transmission method, characterized in that: The method is applied to a trusted service management platform; the method comprises: Determine a data transmission instruction set included in a first process; wherein the first process includes an integrated process for transmitting target data to a security chip provided in a target device; Determine a data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain a data transmission module set; wherein the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than a first threshold; m and n are mutually unequal positive integers; Integrate at least part of the data transmission modules in the data transmission module set to obtain a second process; The target data is transmitted to the security chip based on the second process.
2. The method according to claim 1, characterized in that The step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes: Obtaining device configuration information of the target device; At least based on the device configuration information, the at least part of the data transmission module is integrated to obtain the second process.
3. The method according to claim 1, characterized in that The step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes: Obtaining security configuration information of the security chip; At least based on the security configuration information, the at least part of the data transmission module is integrated to obtain the second process.
4. The method according to claim 1, characterized in that: The step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes: Obtaining input configuration information for the trusted service management platform; The second process is obtained by integrating the sequence and / or the startup method of at least part of the data transmission modules based on the input configuration information.
5. The method according to claim 1, characterized in that: The step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes: Based on the business processing logic of the target business corresponding to the target data, the jump relationship between at least part of the data transmission modules is conditionally controlled to obtain the second process.
6. The method according to claim 1, characterized in that The step of integrating at least part of the data transmission modules in the data transmission module set to obtain a second process includes: Determine the exception handling mechanism; The second process is obtained by integrating at least part of the data transmission module based on the exception handling mechanism.
7. The method according to claim 1, characterized in that After integrating at least part of the data transmission modules in the data transmission module set to obtain the second process, the method further includes: determining a process score of the second process; If the process score is less than a second threshold, the second process is adjusted and updated.
8. The method according to claim 7, characterized in that The adjusting and updating the second process includes: If the degree of matching between at least part of the code included in the mth data transmission module and the security configuration information of the security chip is less than or equal to a third threshold, determining an update data transmission module corresponding to the at least part of the code; The update data transmission module and the at least part of the data transmission module are integrated to adjust and update the second process.
9. The method according to claim 7, characterized in that: The adjusting and updating the second process includes: Obtaining log information whose process score is less than or equal to the second threshold; Based on the log information, the data transmission module included in the second process is adjusted and updated.
10. The method according to claim 7, characterized in that The determining the process score of the second process includes: Determining a first weight of the mth data transmission module; Determining a second weight of at least a portion of the code included in the mth data transmission module; wherein a matching degree between the at least a portion of the code and the security configuration information of the security chip is less than or equal to a third threshold; The process score is determined based on the first weight and the second weight.
11. The method according to claim 1, characterized in that The determining of the data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain the data transmission module set includes: Determine the degree of association between the i-th data transmission instruction and the j-th data transmission instruction in the data transmission instruction set; wherein i and j are mutually different positive integers; The i-th data transmission instruction and / or the j-th data transmission instruction is processed based on the association degree to determine a data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction.
12. The method according to claim 11, characterized in that The processing of the i-th data transmission instruction and / or the j-th data transmission instruction based on the association degree to determine the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction includes: If the degree of association is greater than or equal to a fourth threshold, the data transmission operations included in the i-th data transmission instruction and the j-th data transmission instruction are integrated at least based on the degree of association to obtain a data transmission module corresponding to the i-th data transmission instruction and the j-th data transmission instruction.
13. The method according to claim 11, characterized in that The processing of the i-th data transmission instruction and / or the j-th data transmission instruction based on the association degree to determine the data transmission module corresponding to the i-th data transmission instruction and / or the j-th data transmission instruction includes: If the degree of association is less than a fourth threshold, the data transmission operations contained in the i-th data transmission instruction are integrated to obtain the i-th data transmission module corresponding to the i-th data transmission instruction, and the data transmission operations contained in the j-th data transmission instruction are integrated to obtain the j-th data transmission module corresponding to the j-th data transmission instruction.
14. The method according to any one of claims 1 to 13, characterized in that: The method further comprises: The second process is outputted through the data display module of the trusted service management platform.
15. The method according to any one of claims 1 to 13, characterized in that: The method further comprises: The data display module of the trusted service management platform outputs status information of transmitting the target data to the security chip based on the second process.
16. A data transmission device, characterized in that: The device is arranged on a trusted service management platform; the device comprises: A determination module, used to determine a set of data transmission instructions included in a first process; wherein the first process includes an integrated process for transmitting target data to a security chip provided in a target device; The determination module is further used to determine the data transmission module corresponding to the data transmission instruction in the data transmission instruction set to obtain a data transmission module set; wherein the coupling degree between the mth data transmission module and the nth data transmission module in the data transmission module set is less than a first threshold; m and n are mutually unequal positive integers; A processing module, used for integrating at least part of the data transmission modules in the data transmission module set to obtain a second process; A transmission module is used to transmit the target data to the security chip based on the second process.
17. A trusted service management platform, characterized in that: The trusted service management platform includes a processor and a memory; a computer program is stored in the memory; when the computer program is executed by the processor, it can execute the data transmission method as described in any one of claims 1 to 15.
18. A computer-readable storage medium, characterized in that: The storage medium stores a computer program; when the computer program is executed by a processor of an electronic device, the data transmission method according to any one of claims 1 to 15 can be implemented.