Decryption method and device, electronic equipment and storage medium
By decrypting the first ciphertext in the second execution environment and obtaining the synthetic key, the problem of user data being unable to be decrypted due to the corruption of the security chip, and the secure recovery of data and the improvement of user experience are achieved.
Patent Information
- Application Number
- CN202311586072.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-24
- Publication Date
- 2025-05-27
AI Technical Summary
When the security chip SE is damaged, even if the user enters the correct lock screen password, he cannot unlock the smart device, and thus cannot decrypt the encrypted user data, resulting in the loss of user data and affecting the user experience.
When it is determined that there is an exception in the first execution environment (such as the security chip SE), the first ciphertext is decrypted using the second execution environment (such as the trusted execution environment TEE), a synthetic key is obtained, and the user data is decrypted based on the synthetic key.
In the case of the first execution environment being damaged, user data can still be restored, data loss can be avoided, user experience can be improved, and user experience can be achieved through software. There is no need to add additional hardware, and the hardware cost is low.
Smart Images

Figure CN120046129A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of data security technologies, and in particular, to a decryption method, apparatus, electronic device, and storage medium. Background Art
[0002] The lock screen password is an important part of the privacy protection and identity authentication of intelligent devices. It combines with File-Base Encrypt (FBE) to provide effective protection for user data. With the development of data security technologies, the lock screen password module has evolved from running in a Trust Execution Environment (TEE) to running on a Secure Element (SE). Since the independent secure chip is physically isolated from execution environments such as TEE and REE (Rich Execution Environment), it can effectively prevent information leakage and significantly improve the security of user data. However, hardware damage is an inevitable problem. When the SE is damaged, even if the user enters the correct lock screen password, the intelligent device cannot be unlocked, and thus the encrypted user data cannot be decrypted, indirectly causing the loss of user data and seriously affecting the user experience. Summary of the Invention
[0003] To overcome the problems in the related art, the present disclosure provides a decryption method, apparatus, electronic device, and storage medium.
[0004] According to a first aspect of an embodiment of the present disclosure, a decryption method is provided, and the method includes:
[0005] Receiving password information;
[0006] When it is determined that the first execution environment is abnormal, decrypting a first ciphertext in a second execution environment to obtain a composite key; wherein, when the user sets the password information, the composite key is encrypted in the first execution environment and the second execution environment to obtain the first ciphertext in the second execution environment;
[0007] Decrypting user data based on the composite key.
[0008] In an exemplary embodiment, the decrypting the first ciphertext in the second execution environment to obtain a composite key includes:
[0009] Obtaining a first key in the second execution environment, where the first key is related to the content of the password information;
[0010] Obtaining the first ciphertext and a second key in the second execution environment, where the second key is not related to the content of the password information;
[0011] Decrypt the first ciphertext based on the first key and the second key to obtain the composite key.
[0012] In an exemplary embodiment, the decrypting the first ciphertext based on the first key and the second key to obtain the composite key includes:
[0013] In the second execution environment, decrypt the first ciphertext using the second key to obtain intermediate information, and decrypt the intermediate information using the first key to obtain the composite key.
[0014] In an exemplary embodiment, the obtaining the first ciphertext and the second key in the second execution environment includes:
[0015] Receive the private key sent by the server, where the private key is the key for decryption in the key pair generated by the server;
[0016] Obtain the third key and the second ciphertext in the second execution environment;
[0017] Decrypt the second ciphertext using the private key to obtain the first ciphertext;
[0018] Decrypt the third key using the private key to obtain the second key.
[0019] In an exemplary embodiment, after decrypting the user data based on the composite key, the method further includes:
[0020] Delete the private key.
[0021] In an exemplary embodiment, the obtaining the first ciphertext and the second key in the second execution environment includes:
[0022] Receive the first ciphertext and the second key sent by the server.
[0023] In an exemplary embodiment, after decrypting the user data based on the composite key, the method further includes:
[0024] Delete the second key and the first ciphertext.
[0025] In an exemplary embodiment, before determining the composite key in the second execution environment, the method further includes:
[0026] Determine that the current user is the actual owner of the electronic device.
[0027] In an exemplary embodiment, when the user sets the password information, the composite key is encrypted in the second execution environment to obtain the first ciphertext in the second execution environment, including:
[0028] Receive the password information;
[0029] Register the password information in the second execution environment to obtain a first key in the second execution environment, where the first key is related to the content of the password information;
[0030] Obtain a second key in the second execution environment, where the second key is not related to the content of the password information;
[0031] Determine the first ciphertext based on the first key, the second key, and the composite key;
[0032] Save the second key and the first ciphertext in the electronic device; or, send the second key and the first ciphertext to the server.
[0033] In an exemplary embodiment, the determining the first ciphertext based on the first key, the second key, and the composite key includes:
[0034] In the second execution environment, encrypt the composite key using the first key to obtain intermediate information, and encrypt the intermediate information using the second key to obtain the first ciphertext.
[0035] In an exemplary embodiment, the method further includes:
[0036] Receive the public key sent by the server, where the public key is the key for encryption in the key pair generated by the server;
[0037] In the second execution environment, encrypt the second key using the public key to obtain a third key;
[0038] Encrypt the first ciphertext using the public key to obtain a second ciphertext;
[0039] Save the third key and the second ciphertext in the electronic device and delete the first ciphertext and the second key; or, send the third key and the second ciphertext to the server and delete the first ciphertext, the second key, the third key, and the second ciphertext.
[0040] In an exemplary embodiment, the first execution environment is a secure element (SE), and the second execution environment is a trusted execution environment (TEE).
[0041] According to a second aspect of the embodiments of the present disclosure, a decryption device is provided, the device comprising:
[0042] An induction module configured to receive password information;
[0043] A first decryption module configured to decrypt a first ciphertext in a second execution environment to obtain a composite key when it is determined that there is an abnormality in the first execution environment; wherein, when the user sets the password information, the composite key is encrypted in the first execution environment and the second execution environment to obtain the first ciphertext in the second execution environment;
[0044] A second decryption module configured to decrypt user data based on the composite key.
[0045] According to a third aspect of the embodiments of the present disclosure, an electronic device is provided, comprising:
[0046] A processor;
[0047] A memory for storing processor-executable instructions;
[0048] Wherein, the processor is configured to execute the method described in the first aspect of the embodiments of the present disclosure.
[0049] According to a fourth aspect of the embodiments of the present disclosure, a non-transitory computer-readable storage medium is provided, which when the instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to execute the method described in the first aspect of the embodiments of the present disclosure.
[0050] Adopting the above method of the present disclosure has the following beneficial effects: In the case where the first execution environment is damaged and cannot be unlocked, the user data can still be restored, avoiding data loss, improving the user experience, and moreover, it is implemented by software, without the need to add additional hardware, and the hardware cost is low.
[0051] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present disclosure. BRIEF DESCRIPTION OF THE DRAWINGS
[0052] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present disclosure and used together with the specification to explain the principles of the present disclosure.
[0053] Figure 1 is a flowchart of a decryption method shown according to an exemplary embodiment;
[0054] Figure 2 is a flowchart of a decryption method shown according to an exemplary embodiment;
[0055] Figure 3A It is a schematic diagram of private key decryption shown according to an exemplary embodiment;
[0056] Figure 3B It is a decryption schematic diagram in the second execution environment shown according to an exemplary embodiment;
[0057] Figure 3C It is a decryption schematic diagram in the second execution environment shown according to an exemplary embodiment;
[0058] Figure 3D It is a decryption schematic diagram in the first execution environment shown according to an exemplary embodiment;
[0059] Figure 4 It is a flowchart of an encryption method shown according to an exemplary embodiment;
[0060] Figure 5A It is a schematic diagram of an encryption method shown according to an exemplary embodiment;
[0061] Figure 5B It is a schematic diagram of a public key encryption method shown according to an exemplary embodiment;
[0062] Figure 5C It is a schematic diagram of an encryption method shown according to an exemplary embodiment;
[0063] Figure 6 It is a flowchart of an encryption and decryption method shown according to an exemplary embodiment;
[0064] Figure 7 It is a block diagram of a decryption device shown according to an exemplary embodiment;
[0065] Figure 8 It is a block diagram of an electronic device shown according to an exemplary embodiment. Detailed implementation manners
[0066] Here, the exemplary embodiments will be described in detail, and the examples are shown in the accompanying drawings. When the following description refers to the accompanying drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners consistent with the present disclosure. On the contrary, they are merely examples of devices and methods consistent with some aspects of the present disclosure as detailed in the appended claims.
[0067] In an exemplary embodiment of the present disclosure, to overcome the problem of indirect loss of user data caused by SE damage in the related art, a decryption method is provided, including: receiving password information, and when it is determined that there is an abnormality in the first execution environment, decrypting the first ciphertext in the second execution environment to obtain a composite key, where the composite key is encrypted in the first execution environment and the second execution environment when the user sets the password information to obtain the first ciphertext in the second execution environment, and decrypting the user data based on the composite key. This decryption method can still recover user data when the first execution environment is damaged and cannot be unlocked, avoiding data loss, improving the user experience, and moreover, it is implemented by software, without the need to add additional hardware, and the hardware cost is low.
[0068] In an exemplary embodiment of the present disclosure, a decryption method is provided, Figure 1 which is a flowchart of a decryption method shown according to an exemplary embodiment, as Figure 1 shown, and includes the following steps:
[0069] Step S101, receiving password information;
[0070] Step S102, when it is determined that there is an abnormality in the first execution environment, decrypting the first ciphertext in the second execution environment to obtain a composite key; where the composite key is encrypted in the first execution environment and the second execution environment when the user sets the password information to obtain the first ciphertext in the second execution environment;
[0071] Step S103, decrypting the user data based on the composite key.
[0072] The decryption method in the embodiments of the present disclosure is applied to an electronic device, and the electronic device includes an electronic device with a display screen and a security chip such as a smart phone, a tablet computer, a personal computer, a smart wearable device, a smart home device, and a smart vehicle system.
[0073] In step S101, the password information represents the unlock password entered by the user to unlock the electronic device or certain files or a certain application in the electronic device when the electronic device is in the locked screen state or when certain files or a certain application in the electronic device are in the locked state. The form of the password information can be any form, such as a numeric password, a graphic password, an alphabetic password, a fingerprint password, etc., which is not limited in this disclosure. In the electronic device, the decryption module receives the password information and unlocks the electronic device or certain files or a certain application in the electronic device. In this disclosure, the information locked by the user, such as the information in a certain application or the information in a certain file or the whole machine information, etc., is collectively referred to as user data. In the locked state, the user data is in an encrypted state, and unlocking it means decrypting the user data. It should be noted that the received password information is the correct password information, that is, it matches the password information set by the user. This disclosure does not involve the process of verifying whether the password information is correct.
[0074] In step S102, the first execution environment represents an execution environment with relatively high security and independent of the Trusted Execution Environment (TEE). In this disclosure, the Secure Element (SE) is taken as an example. The second execution environment represents the Trusted Execution Environment (TEE). The security of the Trusted Execution Environment is lower than that of the Secure Element, and the probability of an exception occurring in the Trusted Execution Environment is less than that of the Secure Element. The first execution environment is the main execution environment used by the decryption module in the electronic device, and the second execution environment is the backup execution environment of the decryption module in the electronic device. After receiving the password information input by the user, a preset detection algorithm is used to determine whether there is an abnormality in the first execution environment. If there is an abnormality in the first execution environment, a prompt message is displayed to prompt the user that the first execution environment is abnormal and cannot be unlocked. For example, the prompt message "The secure chip is damaged and cannot be unlocked" is displayed. At this time, the preset detection algorithm is used to determine whether there is an abnormality in the second execution environment. If there is no abnormality in the second execution environment, the conditions for execution in the embodiments of this disclosure are met. If there is an abnormality in the second execution environment, the user data cannot be decrypted anymore; if there is no abnormality in the first execution environment, the user data can be decrypted in the first execution environment.
[0075] The Synthetic Password (SP) is used to encrypt and decrypt user data. After encrypting user data with the synthetic password, the user information enters a locked state. When decrypting user data with the synthetic password in the locked state, the user information is unlocked. The synthetic password is randomly generated in the REE when the electronic device is first started and will not change thereafter. To ensure the security of user data, after encrypting user data with the synthetic password, the synthetic password is not directly stored in the electronic device. Instead, the synthetic password is encrypted, and the ciphertext information of the encrypted synthetic password, i.e., the first ciphertext, is stored in the electronic device. When the user sets the password information, the synthetic password is encrypted in the first execution environment and the second execution environment respectively to obtain the encrypted synthetic password in the first execution environment and the encrypted synthetic password in the second execution environment, i.e., the first ciphertext in the second execution environment. When an exception occurs in the first execution environment, the first ciphertext is decrypted in the second execution environment to obtain the synthetic password, so as to decrypt the user data with the synthetic password.
[0076] In step S103, when an exception occurs in the first execution environment and no exception occurs in the second execution environment, after decrypting the first ciphertext in the second execution environment to determine the synthetic password, the synthetic password can be used to decrypt the user data in the REE, so that the user information is in an unlocked state.
[0077] In an exemplary embodiment of the present disclosure, when an exception occurs in the first execution environment, the first ciphertext is decrypted in the second execution environment to determine the synthetic password, and the synthetic password is used to decrypt the user data in the REE. Then, when the main execution environment SE is damaged and cannot be unlocked, the user data can still be restored, avoiding data loss and improving the user experience. Moreover, it is implemented by software, without the need to add additional hardware, and the hardware cost is low.
[0078] In an exemplary embodiment of the present disclosure, a decryption method is provided. Figure 2 It is a flowchart of a decryption method shown according to an exemplary embodiment, as Figure 2 shown, and includes the following steps:
[0079] Step S201, receiving password information;
[0080] Step S202, when it is determined that an exception occurs in the first execution environment, determining that the current user is the actual owner of the electronic device;
[0081] Step S203, obtaining the first key in the second execution environment, where the first key is related to the content of the password information;
[0082] Step S204: Obtain the first ciphertext and the second key in the second execution environment. The second key is not related to the content of the password information.
[0083] Step S205: Decrypt the first ciphertext based on the first key and the second key to obtain the composite key.
[0084] Step S206: Decrypt the user data based on the composite key.
[0085] Among them, for the specific implementation manners of Step S201 and Step S206, refer to Step S101 and Step S103, which will not be elaborated here.
[0086] In Step S202, in order to prevent others from unlocking the information in the electronic device and causing the leakage of user data, when there is an abnormality in the first execution environment, it is necessary to verify whether the current user is the actual owner of the electronic device. For example, by collecting device-related information online, prompting the user to enter purchase information, device accounts, etc., or contacting after-sales maintenance offline, providing purchase information and personal information, etc. The present disclosure does not limit the verification method. In one example, when there is an abnormality in the first execution environment and it cannot be unlocked, a prompt message is displayed to prompt the user that it cannot be unlocked and the reason for the inability to unlock, and prompt the user with corresponding solutions. For example, the prompt message "SE is damaged and cannot be unlocked. Please enter the purchase information" or "SE is damaged and cannot be unlocked. Please contact the after-sales personnel" is displayed. When it is determined that the current user is the actual owner of the electronic device, the user data is decrypted through the second execution environment to improve the security of the user data.
[0087] In Step S203, the first key is generated by the second execution environment and is used to encrypt and decrypt the composite key. The first key is related to the content of the password information, and the first key includes a key and authorization information related to the password information. Based on the received password information, the second execution environment generates the first key, and the first key can be denoted as TEE_KEY.
[0088] In Step S204, the second key is used to encrypt and decrypt the composite key. The second key is not related to the content of the password information, and the second key is a randomly generated key. However, the second key is not randomly generated every time for encryption and decryption, but is randomly generated when the user sets the password information each time, and the second key does not change when the password information does not change, and the password information corresponds to the second key. For example, when the password information is 123456, the second key key1 is randomly generated. When the password information does not change, the second key is always key1. When the password information is changed from 123456 to 111111, the second key also changes, and at this time the second key key2 is randomly generated.
[0089] The second key in the first execution environment is different from the second key in the second execution environment, and the second key in the second execution environment can be recorded as sp_key_blob_b. The first ciphertext represents the ciphertext file of the synthetic key finally obtained after the synthetic key is encrypted in the second execution environment. Since the second key in the first execution environment is different from the second key in the second execution environment, the ciphertext file of the synthetic key in the first execution environment is different from the ciphertext file of the synthetic key in the second execution environment, and the ciphertext file of the synthetic key in the second execution environment, that is, the first ciphertext, can be recorded as spblob_b.
[0090] After encrypting the synthetic key in the second execution environment, the second key and the first ciphertext can be saved in the electronic device, and the first ciphertext and the second key in the second execution environment can be obtained from the memory of the electronic device; or after encrypting the synthetic key in the second execution environment, the second key and the first ciphertext can be sent to the server, and the server can save the second key and the first ciphertext and delete the second key and the first ciphertext in the electronic device to avoid intrusion into the electronic device to obtain the second key and the first ciphertext, thereby causing user data leakage. While restoring user data in the second execution environment, the security level of user data can also be guaranteed.
[0091] In some possible implementations, the first ciphertext and the second key in the second execution environment may be obtained in one of the following two ways:
[0092] The first one includes the following steps:
[0093] S41-1, receiving the private key sent by the server, where the private key is the key used for decryption in the key pair generated by the server.
[0094] The server generates a key pair based on any asymmetric encryption algorithm, including a public key and a private key. The public key is used for decryption, and the private key is used for decryption. In order to avoid the security of the received private key, the server can encapsulate the private key and send it down. The electronic device receives the encapsulated private key and then unpacks it, for example, by scanning a QR code to obtain the private key, or obtaining the private key through after-sales personnel.
[0095] S41-2, obtaining a third key and a second ciphertext in the second execution environment.
[0096] The third key represents the key obtained by encrypting the second key using the public key, the second ciphertext represents the ciphertext file obtained by decrypting the first ciphertext using the public key, the third key and the second ciphertext are stored in the electronic device, and the third key and the second ciphertext are obtained from the memory of the electronic device.
[0097] S41-3, use the private key to decrypt the second ciphertext to obtain the first ciphertext.
[0098] S41-4, Use the private key to decrypt the third key to obtain the second key.
[0099] Denote the private key sent by the received server as Sever_pri_key, the second ciphertext as wrap_spblob_b, the third key as wrap_sp_key_blob_b, the second key as sp_key_blob_b, and the first ciphertext as spblob_b. After receiving the private key sent by the server, Figure 3A It is a schematic diagram of private key decryption shown according to an exemplary embodiment. As Figure 3A shown, by using Sever_pri_key to decrypt wrap_sp_key_blob_b and wrap_spblob_b respectively, sp_key_blob_b and spblob_b can be obtained.
[0100] In some embodiments, since the first ciphertext and the second key are both indispensable when obtaining the composite key, the first ciphertext and the second key can be encrypted selectively. Therefore, the above steps S41-2 - S41-4 can be replaced by: Obtain the third key and the first ciphertext, use the private key to decrypt the third key to obtain the second key; or obtain the second key and the second ciphertext, use the private key to decrypt the second ciphertext to obtain the first ciphertext. Among them, the first ciphertext and the third key or the second key and the second ciphertext are stored in the memory of the electronic device. This embodiment can save the decryption time and decryption power consumption of the electronic device without reducing the security.
[0101] In some embodiments, after decrypting the user data based on the composite key, the method further includes: deleting the private key.
[0102] Since the security of the second execution environment is lower than that of the first execution environment, if the second execution environment can always be used to unlock the user data, the security of the user data will be reduced. Therefore, to ensure data security, after unlocking with the private key once, delete the private key in the electronic device to prevent the second execution environment from being able to unlock the user data subsequently.
[0103] Second, receive the first ciphertext and the second key sent by the server.
[0104] Do not store the first ciphertext and the second key in the electronic device, send them to the server for storage. When decrypting, the electronic device sends a request to the server and receives the first ciphertext and the second key sent by the server.
[0105] In an example, the first ciphertext and the second key are directly stored in the server.
[0106] In another example, the first ciphertext and the second key are obtained after the server decrypts the second ciphertext and the third key using the private key, that is, the private key decryption process shown below is performed in the server. Storing the second ciphertext and the third key in the server and decrypting them using the private key by the server can reduce the cost of the electronic device. Figure 3A
[0107] In some embodiments, after decrypting the user data based on the composite key, the method further includes: deleting the second key and the first ciphertext.
[0108] To ensure data security, after unlocking once using the second key and the first ciphertext, the second key and the first ciphertext in the electronic device are deleted to prevent the user data from being unlocked using the second execution environment subsequently.
[0109] In the above two embodiments of obtaining the first ciphertext and the second key in the second execution environment, the electronic device cannot decrypt the user data through the files saved by itself, but needs the server to send the private key or the first ciphertext and the second key, which can ensure that the security is not reduced when unlocking the user data using the second execution environment, safeguard the security level of the user data, that is, improve the security of the second execution environment.
[0110] In step S205, according to the encryption order of the composite key using the first key and the second key, determine the decryption order of the first ciphertext using the first key and the second key, where the encryption order and the decryption order are opposite. For example, if the encryption order is to encrypt using the first key first and then encrypt using the second key, the decryption order is to decrypt using the second key first and then decrypt using the first key. In some possible embodiments, in the second execution environment, decrypt the first ciphertext using the second key to obtain intermediate information, and decrypt the intermediate information using the first key to obtain the composite key.
[0111] In some possible embodiments, the second key includes at least one key. After encrypting the composite key using the first key to obtain intermediate information, determine the decryption order of the at least one key for the first ciphertext according to the encryption order of the at least one key for the intermediate information, decrypt the intermediate information using the at least one key to obtain intermediate information, and then decrypt the intermediate information using the first key to obtain the composite key. In one example, the second key includes two keys, key 1 and key 2. When encrypting, encrypt the intermediate information using key 2 first, and then encrypt the encrypted intermediate information using key 1 to obtain the first ciphertext. Then when decrypting, decrypt the first ciphertext using key 1 first, and then decrypt the decrypted first ciphertext using key 2 to obtain intermediate information.
[0112] In one example, the password information is the lock screen password.Figure 3B It is a decryption schematic diagram in the second execution environment shown according to an exemplary embodiment. As Figure 3B shown, receive the lock screen password input by the user, verify it, determine that there is an abnormality in the first execution environment SE and there is no abnormality in the second execution environment TEE, obtain the first key TEE_KEY, the first ciphertext spblob_b, and the second key sp_key_blob_b in the second execution environment TEE. The first ciphertext and the second key can be stored in the electronic device and obtained from the memory of the electronic device, or can be directly stored in the server and obtained from the server. Perform the first decryption based on the first ciphertext spblob_b and the second key sp_key_blob_b, perform the second decryption based on the first key TEE_KEY, obtain the composite key SP, and decrypt the user data based on the composite key SP, that is, decrypt UserData.
[0113] In another example, the password information is the lock screen password. Figure 3C It is a decryption schematic diagram in the second execution environment shown according to an exemplary embodiment. As Figure 3C shown, receive the lock screen password input by the user, verify it, determine that there is an abnormality in the first execution environment SE and there is no abnormality in the second execution environment TEE, send a key request to the server. The server decrypts the second ciphertext wrap_spblob_b and the third key wrap_sp_key_blob_b respectively through the private key Sever_pri_key to obtain the first ciphertext spblob_b and the second key sp_key_blob_b. The server sends the first ciphertext spblob_b and the second key sp_key_blob_b to the electronic device, and the electronic device performs the first decryption based on the first ciphertext spblob_b and the second key sp_key_blob_b. Generate the first key TEE_KEY in the second execution environment TEE based on the lock screen password, then perform the second decryption based on the first key TEE_KEY to obtain the composite key SP, and decrypt the user data based on the composite key SP, that is, decrypt UserData.
[0114] In another example, the password information is the lock screen password. Figure 3D It is a decryption schematic diagram in the first execution environment shown according to an exemplary embodiment. As Figure 3DAs shown, receive the lock screen password input by the user, verify it, determine that there is no abnormality in the first execution environment SE, obtain the third ciphertext spblob_a and the fifth key sp_key_blob_a, and the electronic device performs the first decryption based on the third ciphertext spblob_a and the fifth key sp_key_blob_a. Generate the fourth key SE_KEY in the first execution environment SE based on the lock screen password, and then perform the second decryption based on the fourth key SE_KEY to obtain the synthesis key SP, and decrypt the user data based on the synthesis key SP, that is, decrypt UserData.
[0115] In an exemplary embodiment of the present disclosure, an encryption method is provided. Figure 4 It is a flowchart of an encryption method shown according to an exemplary embodiment, as Figure 4 shown, and includes the following steps:
[0116] Step S401, receive password information;
[0117] Step S402, register the password information in the second execution environment to obtain the first key in the second execution environment, and the first key is related to the content of the password information;
[0118] Step S403, obtain the second key in the second execution environment, and the second key is not related to the content of the password information;
[0119] Step S404, determine the first ciphertext based on the first key, the second key, and the synthesis key;
[0120] Step S405, save the second key and the first ciphertext in the electronic device; or, send the second key and the first ciphertext to the server.
[0121] The encryption method in this embodiment is a process of encrypting the synthesis key in the second execution environment when the user sets the password information, that is, a process of encrypting the synthesis key in the second execution environment when the password information is set for the first time or the password information is changed.
[0122] Receive the password information entered by the user when setting the password information, register the password information in the second execution environment, and generate a first key by the second execution environment according to the password information. The second key is a randomly generated key, and each time the password information is changed, a second key is randomly generated. Randomly generate a composite key, encrypt the composite key with the first key and the second key to obtain a first ciphertext. In one example, in the second execution environment, use the first key to encrypt the composite key to obtain intermediate information, and use the second key to encrypt the intermediate information to obtain the first ciphertext. Save the first ciphertext and the second key in the electronic device, and delete the unencrypted composite key, or send the first ciphertext and the second key to the server, and delete the unencrypted composite key, the first ciphertext and the second key in the local electronic device, so as to use the first ciphertext and the second key to obtain the composite key in the subsequent decryption process.
[0123] In some possible implementation manners, in the second execution environment, use the first key to encrypt the composite key to obtain intermediate information, and use the second key to encrypt the intermediate information to obtain the first ciphertext.
[0124] In one example, the password information is the lock screen password. Figure 5A It is a schematic diagram of an encryption method shown according to an exemplary embodiment, as Figure 5A shown, receive the lock screen password set by the user, register the lock screen password in the second execution environment TEE, generate a first key TEE_KEY related to the lock screen password by the second execution environment TEE, randomly generate a composite key SP, perform the first encryption on the composite key SP with the first key TEE_KEY, randomly generate a second key sp_key_blob_b, and perform the second encryption with the second key sp_key_blob_b to obtain the first ciphertext spblob_b.
[0125] In some possible implementation manners, this embodiment further includes the following steps:
[0126] S4-6, receive the public key sent by the server, and the public key is the key for encryption in the key pair generated by the server.
[0127] Generate a key pair, a public key and a private key, by the server according to any asymmetric encryption algorithm, where the public key is used for encryption. When the server sends the public key to the electronic device, in order to ensure the security of the data, different public keys are sent to different electronic devices.
[0128] S4-7, in the second execution environment, use the public key to encrypt the second key to obtain a third key.
[0129] S4-8, use the public key to encrypt the first ciphertext to obtain a second ciphertext.
[0130] Record the received public key sent by the server as Sever_pub_key, the second ciphertext as wrap_spblob_b, the third key as wrap_sp_key_blob_b, the second key as sp_key_blob_b, and the first ciphertext as spblob_b. After receiving the public key sent by the server, Figure 5B It is a schematic diagram of a public key encryption method shown according to an exemplary embodiment, as Figure 5B shown, by encrypting sp_key_blob_b and spblob_b with Sever_pub_key respectively, wrap_sp_key_blob_b and wrap_spblob_b can be obtained.
[0131] S4-9, save the third key and the second ciphertext in the electronic device, and delete the first ciphertext and the second key; or, send the third key and the second ciphertext to the server, and delete the first ciphertext, the second key, the third key, and the second ciphertext.
[0132] Both the second key and the first ciphertext are TEE-level files, and their security is relatively low. The third key and the second ciphertext are encrypted by the public key sent by the server. Based on the TEE-level files, secondary encryption is performed, which can improve the security level. Even if the TEE-level files are cracked, the synthetic key SP cannot be decrypted, so the security of user data can be ensured.
[0133] In some embodiments, since the second key and the first ciphertext are both indispensable for decrypting the synthetic key, when using the public key for encryption, only the second key or only the first ciphertext can be encrypted to improve the encryption speed.
[0134] In some embodiments, to further improve security, after decrypting the synthetic key, when encrypting the synthetic key again next time, the server reissues a public key, which is different from the public key used in the previous encryption, to avoid the first execution environment from having an exception again.
[0135] In an example, the password information is the lock screen password. Figure 5C It is a schematic diagram of an encryption method shown according to an exemplary embodiment, as Figure 5CAs shown, when the user inputs the set lock screen password, the password information is registered in the first execution environment SE and the second execution environment TEE respectively, and the composite key is encrypted in the first execution environment SE and the second execution environment TEE respectively. In the first execution environment SE, the first execution environment SE generates a key SE_KEY related to the password information. In the second execution environment TEE, the second execution environment TEE generates a first key TEE_KEY related to the lock screen password. A composite key SP is randomly generated, and the user data is encrypted with the composite key SP, that is, encrypt UserData. In the first execution environment SE, the composite key SP is encrypted for the first time with the key SE_KEY, a key sp_key_blob_a is randomly generated, and the second encryption is performed with the key sp_key_blob_a to obtain the ciphertext spblob_a. In the second execution environment TEE, the composite key SP is encrypted for the first time with the first key TEE_KEY, a second key sp_key_blob_b is randomly generated, and the second encryption is performed with the second key sp_key_blob_b to obtain the first ciphertext spblob_b. Thus, the composite key can be decrypted in the first execution environment and the second execution environment respectively.
[0136] In an exemplary embodiment of the present disclosure, encrypting the composite key in the second execution environment can prevent the composite key from being used to decrypt user data in the second execution environment when there is an abnormality in the first execution environment and unlocking fails, avoid data loss, improve the user experience, and moreover, it is implemented by software, without the need to additionally increase hardware, and the hardware cost is low.
[0137] In an exemplary embodiment of the present disclosure, an encryption and decryption method is provided. Figure 6 It is a flowchart of an encryption and decryption method shown according to an exemplary embodiment, as Figure 6 shown, including the following steps:
[0138] Step S601, receiving the password information set by the user;
[0139] Encrypt the composite key SP in the first execution environment SE, and execute steps S602 - S605; encrypt the composite key SP in the second execution environment TEE, and execute steps S606 - S609;
[0140] Step S602, registering the password information in the first execution environment SE to obtain a fourth key SE_KEY in the first execution environment SE;
[0141] Step S603, obtaining a fifth key sp_key_blob_a in the first execution environment SE;
[0142] Step S604: Determine the third ciphertext spblob_a based on the fourth key SE_KEY, the fifth key sp_key_blob_a, and the synthetic key SP;
[0143] The synthetic key SP is randomly generated in the REE.
[0144] Step S605: Save the fifth key sp_key_blob_a and the third ciphertext spblob_a in the electronic device;
[0145] Step S606: Register password information in the second execution environment TEE to obtain the first key TEE_KEY in the second execution environment TEE;
[0146] Step S607: Obtain the second key sp_key_blob_b in the second execution environment TEE;
[0147] Step S608: Determine the first ciphertext spblob_b based on the first key TEE_KEY, the second key sp_key_blob_b, and the synthetic key SP;
[0148] The synthetic key SP is randomly generated in the REE.
[0149] Step S609: Save the second key sp_key_blob_b and the first ciphertext spblob_b in the electronic device or send them to the server;
[0150] Step S610: Receive the password information input by the user;
[0151] Step S611: Determine whether there is an abnormality in the first execution environment SE;
[0152] If it is determined that there is no abnormality in the first execution environment SE, execute steps S611 - S613; if it is determined that there is an abnormality in the first execution environment SE, execute steps S614 - S617;
[0153] Step S612: Obtain the fourth key SE_KEY in the first execution environment SE;
[0154] Step S613: Obtain the fifth key sp_key_blob_a and the third ciphertext spblob_a in the first execution environment SE;
[0155] Step S614: Decrypt the third ciphertext spblob_a based on the fourth key SE_KEY and the fifth key sp_key_blob_a to obtain the synthetic key SP;
[0156] Step S615: Determine that the current user is the actual owner of the electronic device;
[0157] Step S616: Obtain the first key TEE_KEY in the second execution environment TEE;
[0158] Step S617: Obtain the first ciphertext spblob_b and the second key sp_key_blob_b in the second execution environment TEE;
[0159] Step S618: Decrypt the first ciphertext spblob_b based on the first key TEE_KEY and the second key sp_key_blob_b to obtain the synthesis key SP;
[0160] Step S619: Decrypt the user data based on the synthesis key SP.
[0161] For the specific implementation manners in each step, refer to the above respective embodiments, which will not be elaborated herein.
[0162] In an exemplary embodiment of the present disclosure, a decryption device is provided. Figure 7 It is a block diagram of a decryption device shown according to an exemplary embodiment, as Figure 7 shown. The decryption device includes:
[0163] An induction module 701, configured to receive password information;
[0164] A first decryption module 702, configured to decrypt the first ciphertext in the second execution environment when it is determined that there is an abnormality in the first execution environment to obtain a synthesis key; wherein, when the user sets the password information, the synthesis key is encrypted in the first execution environment and the second execution environment to obtain the first ciphertext in the second execution environment;
[0165] A second decryption module 703, configured to decrypt the user data based on the synthesis key.
[0166] In an exemplary embodiment, the first decryption module 702 is further configured to:
[0167] Obtain the first key in the second execution environment, where the first key is related to the content of the password information;
[0168] Obtain the first ciphertext and the second key in the second execution environment, where the second key is not related to the content of the password information;
[0169] Decrypt the first ciphertext based on the first key and the second key to obtain a determined synthesis key.
[0170] In an exemplary embodiment, the first decryption module 702 is further configured to:
[0171] In the second execution environment, use the second key to decrypt the first ciphertext to obtain intermediate information, and use the first key to decrypt the intermediate information to obtain the composite key.
[0172] In an exemplary embodiment, the first decryption module 702 is further configured to:
[0173] Receive the private key sent by the server, where the private key is the key for decryption in the key pair generated by the server;
[0174] Obtain the third key and the second ciphertext in the second execution environment;
[0175] Use the private key to decrypt the second ciphertext to obtain the first ciphertext;
[0176] Use the private key to decrypt the third key to obtain the second key.
[0177] In an exemplary embodiment, after decrypting the user data based on the composite key, the first decryption module 702 is further configured to:
[0178] Delete the private key.
[0179] In an exemplary embodiment, the first decryption module 702 is further configured to:
[0180] Receive the first ciphertext and the second key sent by the server.
[0181] In an exemplary embodiment, after decrypting the user data based on the composite key pair, the first decryption module 702 is further configured to:
[0182] Delete the second key and the first ciphertext.
[0183] In an exemplary embodiment, before determining the composite key in the second execution environment, the first decryption module 702 is further configured to:
[0184] Determine that the current user is the actual owner of the electronic device.
[0185] In an exemplary embodiment, the decryption device further includes an encryption module 704, which is configured to, when the user sets password information, perform encryption on the composite key in the second execution environment to obtain the first ciphertext in the second execution environment; the encryption module 704 is further configured to:
[0186] Receive the password information;
[0187] Register the password information in the second execution environment to obtain the first key in the second execution environment, where the first key is related to the content of the password information;
[0188] Obtain a second key in a second execution environment, where the second key is not related to the content of the password information;
[0189] Determine a first ciphertext based on the first key, the second key, and the composite key;
[0190] Save the second key and the first ciphertext in the electronic device; or, send the second key and the first ciphertext to the server.
[0191] In an exemplary embodiment, the encryption module 704 is further configured to:
[0192] In the second execution environment, use the first key to encrypt the composite key to obtain intermediate information, and use the second key to encrypt the intermediate information to obtain the first ciphertext.
[0193] In an exemplary embodiment, the encryption module 704 is further configured to:
[0194] Receive a public key sent by the server, where the public key is the key for encryption in the key pair generated by the server;
[0195] In the second execution environment, use the public key to encrypt the second key to obtain a third key;
[0196] Use the public key to encrypt the first ciphertext to obtain a second ciphertext;
[0197] Save the third key and the second ciphertext in the electronic device, and delete the first ciphertext and the second key; or, send the third key and the second ciphertext to the server, and delete the first ciphertext, the second key, the third key, and the second ciphertext.
[0198] In an exemplary embodiment, the first execution environment is a secure element (SE), and the second execution environment is a trusted execution environment (TEE).
[0199] Regarding the device in the above embodiments, the specific manners in which each module performs operations have been described in detail in the embodiments related to the method, and will not be elaborated here.
[0200] Figure 8 It is a block diagram of an electronic device 800 shown according to an exemplary embodiment.
[0201] Refer to Figure 8 , the electronic device 800 may include one or more of the following components: a processing component 802, a memory 804, a power component 806, a multimedia component 808, an audio component 810, an input / output (I / O) interface 812, a sensor component 814, and a communication component 816.
[0202] The processing component 802 generally controls the overall operation of the electronic device 800, such as operations associated with display, telephone calls, data communication, camera operations, and recording operations. The processing component 802 may include one or more processors 820 to execute instructions to complete all or part of the steps of the above-described methods. In addition, the processing component 802 may include one or more modules to facilitate the interaction between the processing component 802 and other components. For example, the processing component 802 may include a multimedia module to facilitate the interaction between the multimedia component 808 and the processing component 802.
[0203] The memory 804 is configured to store various types of data to support the operation of the electronic device 800. Examples of such data include instructions for any application or method operating on the electronic device 800, contact data, phone book data, messages, pictures, videos, and the like. The memory 804 may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk, or optical disk.
[0204] The power component 806 provides power to various components of the electronic device 800. The power component 806 may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the electronic device 800.
[0205] The multimedia component 808 includes a screen that provides an output interface between the electronic device 800 and the user. In some embodiments, the screen may include a liquid crystal display (LCD) and a touch panel (TP). If the screen includes a touch panel, the screen may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touches, swipes, and gestures on the touch panel. The touch sensors may sense not only the boundaries of the touch or swipe actions but also detect the duration and pressure associated with the touch or swipe operations. In some embodiments, the multimedia component 808 includes a front camera and / or a rear camera. When the electronic device 800 is in an operating mode, such as a shooting mode or a video mode, the front camera and / or the rear camera may receive external multimedia data. Each of the front camera and the rear camera may be a fixed optical lens system or have focal length and optical zoom capabilities.
[0206] The audio component 810 is configured to output and / or input audio signals. For example, the audio component 810 includes a microphone (MIC), which is configured to receive external audio signals when the electronic device 800 is in an operating mode, such as a call mode, a recording mode, and a voice recognition mode. The received audio signals can be further stored in the memory 804 or transmitted via the communication component 816. In some embodiments, the audio component 810 further includes a speaker for outputting audio signals.
[0207] The I / O interface 812 provides an interface between the processing component 802 and a peripheral interface module, and the peripheral interface module may be a keyboard, a click wheel, buttons, etc. These buttons may include, but are not limited to: a home button, a volume button, a power button, and a lock button.
[0208] The sensor component 814 includes one or more sensors for providing an assessment of various aspects of the status of the electronic device 800. For example, the sensor component 814 can detect the on / off state of the electronic device 800, the relative positioning of components, such as the display and keypad of the electronic device 800. The sensor component 814 can also detect a change in the position of the electronic device 800 or a component of the electronic device 800, the presence or absence of user contact with the electronic device 800, the orientation or acceleration / deceleration of the electronic device 800, and the temperature change of the electronic device 800. The sensor component 814 can include a proximity sensor configured to detect the presence of nearby objects without any physical contact. The sensor component 814 can also include a light sensor, such as a CMOS or CCD image sensor, for use in imaging applications. In some embodiments, the sensor component 814 can further include an acceleration sensor, a gyroscope sensor, a magnetic sensor, a pressure sensor, or a temperature sensor.
[0209] The communication component 816 is configured to facilitate communication between the electronic device 800 and other devices in a wired or wireless manner. The electronic device 800 can access a wireless network based on communication standards, such as WiFi, 2G, or 3G, or a combination thereof. In an exemplary embodiment, the communication component 816 receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component 816 further includes a near field communication (NFC) module to facilitate short-range communication. For example, the NFC module can be implemented based on radio frequency identification (RFID) technology, infrared data association (IrDA) technology, ultra-wideband (UWB) technology, Bluetooth (BT) technology, and other technologies.
[0210] In an exemplary embodiment, the electronic device 800 may be implemented by one or more application specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components for performing the above method.
[0211] In an exemplary embodiment, a non-transitory computer-readable storage medium including instructions is also provided, such as a memory 804 including instructions, and the above instructions can be executed by a processor 820 of the electronic device 800 to complete the above method. For example, the non-transitory computer-readable storage medium may be a ROM, a random access memory (RAM), a CD-ROM, a magnetic tape, a floppy disk, and an optical data storage device, etc.
[0212] A non-transitory computer-readable storage medium, when the instructions in the storage medium are executed by a processor of an electronic device, enables the electronic device to execute a decryption method, and the method includes any of the above methods.
[0213] Those skilled in the art will readily conceive of other embodiments of the present disclosure after considering the specification and practicing the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of the present disclosure, which follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not disclosed herein. The specification and embodiments are only to be regarded as exemplary, and the true scope and spirit of the present disclosure are pointed out by the following claims.
[0214] It should be understood that the present disclosure is not limited to the exact structures described above and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present disclosure is only limited by the appended claims.
Claims
1. A decryption method, characterized in that, the method includes: Receiving password information; When it is determined that there is an abnormality in the first execution environment, decrypting the first ciphertext in the second execution environment to obtain a composite key; wherein, when the user sets the password information, the composite key is encrypted in the first execution environment and the second execution environment to obtain the first ciphertext in the second execution environment; Decrypting user data based on the composite key.
2. The decryption method according to claim 1, characterized in that, the decrypting the first ciphertext in the second execution environment to obtain a composite key includes: Obtaining a first key in the second execution environment, the first key being related to the content of the password information; Obtaining a first ciphertext and a second key in the second execution environment, the second key being not related to the content of the password information; Based on the first key and the second key, decrypting the first ciphertext to obtain the composite key.
3. The decryption method according to claim 2, characterized in that, the decrypting the first ciphertext based on the first key and the second key to obtain the composite key includes: In the second execution environment, decrypting the first ciphertext using the second key to obtain intermediate information, and decrypting the intermediate information using the first key to obtain the composite key.
4. The decryption method according to claim 2, characterized in that, the obtaining the first ciphertext and the second key in the second execution environment includes: Receiving a private key sent by a server, the private key being the key for decryption in the key pair generated by the server; Obtaining a third key and a second ciphertext in the second execution environment; Decrypting the second ciphertext using the private key to obtain the first ciphertext; Decrypting the third key using the private key to obtain the second key.
5. The method according to claim 4, characterized in that, after decrypting the user data based on the composite key, the method further includes: Deleting the private key.
6. The decryption method according to claim 2, characterized in that, the obtaining the first ciphertext and the second key in the second execution environment includes: Receiving the first ciphertext and the second key sent by the server.
7. The method according to claim 6, characterized in that, after decrypting the user data based on the composite key, the method further includes: Deleting the second key and the first ciphertext.
8. The method according to claim 1, characterized in that, before determining the composite key in the second execution environment, the method further includes: Determining that the current user is the actual owner of the electronic device.
9. The method according to claim 1, characterized in that, when the user sets the password information, the composite key is encrypted in the second execution environment to obtain the first ciphertext in the second execution environment, including: Receiving password information; Register the password information in the second execution environment to obtain a first key in the second execution environment, where the first key is related to the content of the password information; Obtain a second key in the second execution environment, where the second key is not related to the content of the password information; Determine a first ciphertext based on the first key, the second key, and the composite key; Save the second key and the first ciphertext in the electronic device; or send the second key and the first ciphertext to the server.
10. The method according to claim 9, wherein, The determining the first ciphertext based on the first key, the second key, and the composite key includes: In the second execution environment, encrypt the composite key using the first key to obtain intermediate information, and encrypt the intermediate information using the second key to obtain the first ciphertext.
11. The method according to claim 9, wherein, The method further includes: Receive a public key sent by the server, where the public key is the key for encryption in the key pair generated by the server; In the second execution environment, encrypt the second key using the public key to obtain a third key; Encrypt the first ciphertext using the public key to obtain a second ciphertext; Save the third key and the second ciphertext in the electronic device and delete the first ciphertext and the second key; or send the third key and the second ciphertext to the server and delete the first ciphertext, the second key, the third key, and the second ciphertext.
12. The method according to claim 1, wherein, The first execution environment is a secure element (SE), and the second execution environment is a trusted execution environment (TEE).
13. A decryption device, wherein, The device includes: An induction module configured to receive password information; A first decryption module configured to decrypt a first ciphertext in a second execution environment when it is determined that there is an abnormality in the first execution environment to obtain a composite key; wherein, when the user sets the password information, the composite key performs encryption in the first execution environment and the second execution environment to obtain the first ciphertext in the second execution environment; A second decryption module configured to decrypt user data based on the composite key.
14. An electronic device, wherein, includes: A processor; A memory for storing processor-executable instructions; wherein, the processor is configured to execute the method according to any one of claims 1-12.
15. A non-transitory computer-readable storage medium, wherein, When the instructions in the storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method according to any one of claims 1-12.