System comprising TEE and SE electronic signature module and electronic signature system thereof
By improving the trust root and signature verification process of TEE system, and using the verification data of the SE electronic signature module, the problem of low security level of the existing TEE system has been solved, and an electronic signature system with a powerful (TEE+SE) architecture has been built, realizing reliable electronic signature applications and security improvements in the entire field.
Patent Information
- Application Number
- CN202510167132.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2019-04-28
- Publication Date
- 2025-05-27
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The security level of the existing TEE system is lower than that of the SE electronic signature module, resulting in the inability to build a powerful (TEE+SE) architecture electronic signature system. The existing TEE system is managed by the manufacturer and lacks third-party certification and supervision.
Improve the trust root of TEE system, use the SE electronic signature module as the trust root component, and regularly update the verification data; improve the verification process, use the verification data in the SE electronic signature module for verification; enable the TEE system to be verified and controlled by an authoritative third party.
The security level of the TEE system has been improved to match it with the SE electronic signature module, and a powerful (TEE+SE) architecture electronic signature system has been built, realizing reliable electronic signature applications in all fields, and significantly improving security.
Smart Images

Figure CN120050046A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of TEE (Trusted Execution Environment) and electronic signature systems, and more specifically, to a "system including TEE" and its SE electronic signature module and electronic signature system. Background Art
[0002] The concept of the present invention originates from the analysis of "integrating an electronic signature system and its applications in mobile phones" and is applicable to all "systems including TEE and their SE electronic signature modules and electronic signature systems".
[0003] In the era of interconnected communication, digital certificates and their electronic signature systems (such as: bank USBKeys) are widely used. At the same time, mobile communication technologies and smartphone technologies have also developed vigorously, and the potential of digital certificates and electronic signature applications based on smartphones is huge.
[0004] However, research has found that existing digital certificate technologies and their electronic signature systems have not been widely and fully applied in mobile phones. Analyzing the reasons, it is mainly because there are still defects in the existing technologies.
[0005] For further analysis, the following first introduces the relevant concepts and principles of the existing technologies:
[0006] 1. TEE and REE
[0007] 1) TEE is the abbreviation of Trusted Execution Environment, and its Chinese meaning is: Trusted Execution Environment, also known as "Secure Execution Environment";
[0008] TEE is a secure execution environment based on ARM TrustZone technology; ARM TrustZone is a technology used by ARM to build the underlying hardware isolation for TEE;
[0009] 2) REE is the abbreviation of Rich Execution Environment, and its Chinese meaning is: Rich Execution Environment, also known as "Normal Execution Environment";
[0010] 3) TEE and REE are two independent system execution environments that exist relatively in the same system, are isolated by hardware technology, have their own independent software systems, are closely related and can communicate with each other; the TEE system can access all areas and resources of the REE system through software configuration, while the REE system cannot access the secure areas and resources set by the TEE system; for example: current mobile phone systems basically include an REE system (i.e., the Android system execution environment) and a TEE system (i.e., a secure execution environment based on ARM TrustZone technology, running software applications with high security requirements, such as: fingerprint, password input, payment, etc.);
[0011] 4) The TEE itself is also a computer system, which is a system composed of a TEE hardware system and a TEE software system; different TEE software systems run on the TEE hardware system to form different TEE systems (for example: in an existing mobile phone system, each node system from the ROM firmware execution to the establishment of the TEE trusted operating system is a "TEE system running different TEE programs");
[0012] 5) The initial TEE system refers to the TEE system automatically established after the TEE system is reset.
[0013] 2. Systems including TEE
[0014] "Systems including TEE" refers to "systems containing the TEE trusted execution environment"; "systems including TEE" definitely also include REE; for example: "mobile phone systems containing TEE".
[0015] 3. Security description of existing TEE systems
[0016] 1) Existing TEE systems are TEE systems in existing "systems including TEE (such as mobile phone systems)", which are secure execution environments based on ARM TrustZone technology and are used to run "software applications with high security requirements";
[0017] 2) Existing TEE systems are started and established in a chained signature verification manner based on the trust root of the existing TEE system; the software programs and "verification data for signature verification operations (such as public keys and Hash values for signature verification)" in the trust root of the existing TEE system are stored in the system ROM memory and cannot be modified; among them, the first-stage signature verification operation during its startup and establishment process is completed by "the firmware in the ROM memory", and the "public key or Hash value for signature verification" used in its signature verification operation is also written into the OTP / efuse memory before the product leaves the factory;
[0018] Among them, the meaning of "signature verification" is: "According to the agreement, use 'agreed verification data (such as public keys or Hash values for signature verification)' to verify 'the loaded program module'; it includes: 'According to the agreement, use 'agreed verification data (such as public keys for signature verification)' to verify 'the electronic signature of the loaded program module'", or 'According to the agreement, use 'agreed verification data (such as Hash values)' to verify 'the Hash value of the loaded program module'";
[0019] Among them, the meaning of "chain signature verification" is: continuous signature verification stage by stage according to the pre-designed stages and processes; for example: the "firmware program in the ROM memory" running in the first stage verifies the "Hash value of the loaded program module" using the "agreed verification data (such as: Hash value)" as agreed. If the verification passes, the execution of the "loaded program module" is started and the second stage is entered; the program running in the second stage, according to the agreement, continues to verify the "electronic signature of the loaded program module" using the "agreed verification data (such as: public key for signature verification)". If the verification passes, the execution of the "loaded program module" is started and the third stage is entered;... and so on continuously to complete the "signature verification process for each pre-designed stage" and establish the TEE system.
[0020] Among them, the root of trust of the TEE system is the basic trust resource that "is to be used in the process of establishing the TEE system and determines the trustworthiness of the established TEE system", and it is a part of the system; it includes hardware, the firmware program in the ROM memory, and the "verification data for signature verification operations (such as: public key for signature verification and Hash value)".
[0021] Among them, ROM is the abbreviation of Read Only Memory, and its Chinese meaning is: read-only memory; OTP is the abbreviation of One Time Programable (one-time programmable); eFuse memory is a new type of one-time programmable memory; OTP memory and eFuse memory both belong to ROM memory.
[0022] 3) Existing TEE systems are all under the exclusive management and control of the manufacturers of "systems including TEE" (such as: mobile phone manufacturers) and are not open to the outside world.
[0023] 4) The TEE white paper of the international standardization organization Global Platform clearly states that the security level of the TEE system is lower than that of the SE system; therefore, in practice, generally, the "private key for electronic signature" is not established, stored, and applied in the TEE system.
[0024] 4. Electronic signature system
[0025] An electronic signature system is a computer system that can establish, store, and apply the "private key for electronic signature" and can implement electronic signatures; it is generally established using the "SE security chip or SE security chip module with high security characteristics".
[0026] A reliable electronic signature system refers to an electronic signature system that has been certified by a "legally established third-party certification authority" and can implement "reliable electronic signatures". According to the Electronic Signature Law, only "reliable electronic signatures" have legal effect.
[0027] 5. SE and SE System, SE Electronic Signature Module
[0028] 1) SE is the abbreviation of Secure Element, and its Chinese meaning is: secure chip or secure chip module; in this article, it refers to: an SOC chip or integrated circuit module used in the field of electronic signature, with a secure protection design and "integrating functional units such as a CPU, a memory, and an encryption / decryption module".
[0029] Among them, SOC is the abbreviation of SYSTEM ON CHIP, and its Chinese meaning is: system on a chip.
[0030] 2) The SE system is a system that "includes an SE secure chip module and its software system".
[0031] 3) The SE electronic signature module, in this article, refers to an SE system that "can establish, store, and apply the 'private key for electronic signature' and can implement electronic signatures", such as: a bank USBKEY.
[0032] In applications, the SE electronic signature module generally cooperates and matches with "other host computer systems" to jointly complete tasks related to electronic signatures. Therefore, relative to the host computer system, the SE electronic signature module is also called the SE electronic signature module subsystem.
[0033] After being registered and used, the SE electronic signature module generally will not change in other parts except for regularly updating the signature key according to a strict authentication process. It is a relatively fixed-function and secure computer system.
[0034] Referring to the above concepts, the reasons why the "technology of existing electronic signature systems" has not been widely and fully applied in mobile phones are analyzed below; 1. Analysis of the technology of existing electronic signature systems represented by "bank USBKey":
[0035] This type of electronic signature system is established by applying a "SE secure chip with high security characteristics"; its features are: its SE secure chip system comes with a liquid crystal display and button input; the sensitive information to be signed is displayed on the liquid crystal display screen of the USBKey, achieving the effect of what you see is what you sign, eliminating the security loopholes brought by hackers tampering with information; at the same time, its transaction signature can only be realized by the user inputting and confirming on the buttons of the USBKey, enabling the user to control the process of transaction signature.
[0036] The disadvantages of this type of electronic signature system are:
[0037] (1) The display capacity and information volume of the "SE security chip system with built-in liquid crystal display" are small, and its functions are limited. It is only applicable to the "electronic signature applications of a small amount of sensitive information" in the banking industry and cannot be applied to the "electronic signature applications of large texts, pictures, videos, etc.", which limits the application expansion;
[0038] (2) It is not suitable for integration into mobile phones for application; because the "SE security chip system with built-in liquid crystal display and button input" will occupy a large space in the mobile phone, have a great impact on the overall structure layout of the mobile phone, and increase the cost, which is not conducive to the overall sales of the mobile phone;
[0039] Therefore, this type of electronic signature system technology has not been widely applied in existing mobile phones;
[0040] 2. The trust root of the existing mobile phone TEE system and the security level of its TEE system are lower than the security level of the SE electronic signature module (such as: bank USBKey), resulting in the inability to utilize the powerful functions of the existing mobile phone TEE system to make up for the shortcomings of the existing electronic signature system (such as: inability to be applied to the "electronic signature applications of large texts, pictures, videos, etc."), and the inability to combine and build a powerful (TEE + SE) architecture electronic signature system, which restricts the wide application of electronic signature system technology in mobile phones; The following is a specific analysis:
[0041] Referring to the "Security Description of the Existing TEE System" mentioned above, it can be known that:
[0042] (1) The security level of the public key for signature verification in the trust root of the existing TEE system is insufficient.
[0043] The existing TEE system is established based on the trust root of the existing TEE system and starts in a chained signature verification manner; among them, the public key for signature verification as the TEE trust root is either directly written into the OTP / efuse (ROM memory) and cannot be modified, or indirectly restricted by the Hash value written into the OTP / efuse (ROM memory) and cannot be modified;
[0044] Because the existing public key for signature verification cannot be modified or updated, the corresponding private key for trusted signature cannot be updated either. In the long run, the private key for trusted signature can be cracked, enabling hackers to forge signatures and deceive trust, thus posing a risk; Therefore, the trust root of the existing mobile phone TEE system and the security level of its TEE system are lower than the security level of the SE electronic signature module (such as: bank USBKey), resulting in the inability to combine and build a (TEE + SE) architecture electronic signature system;
[0045] Meanwhile, when the "TEE system download module" is upgraded, it is impossible to upgrade and update the Hash verification value of the "TEE system download module" in the system ROM module. Only the method of verifying the electronic signature can be used to verify the "new version of the TEE system download module". However, this can only verify the electronic signature and cannot identify the new and old versions because the trust signatures of the new and old versions of the "TEE system download module" will both pass the verification. Therefore, hackers can replace the "new version and its signature" with the "old version and its signature" and still use the vulnerabilities of the old version to attack the system.
[0046] (2) Existing mobile phone TEE systems are all under the exclusive management and control of mobile phone manufacturers, with insufficient credibility and security level.
[0047] Existing TEE systems are started and established in the way of chain signature verification; among them, the signature private keys corresponding to the "public keys for signature verification" are all under the exclusive management and control of mobile phone manufacturers; therefore, the security of existing mobile phone TEE systems is certified and controlled by the mobile phone manufacturers themselves without being certified and controlled by an authoritative third party.
[0048] Therefore, compared with the "SE electronic signature module certified and controlled by an authoritative third party", the existing mobile phone TEE systems have insufficient credibility and security level.
[0049] Based on the above analysis, it can be seen that the defects of existing mobile phone TEE systems and the defects of existing SE electronic signature module technologies have led to the fact that existing electronic signature system technologies cannot be widely and fully applied in mobile phones.
[0050] Based on the above analysis, the present invention provides a new technical solution that can solve the above problems and defects.
[0051] The present invention is an improvement and innovation on the existing technology based on the existing technology. Next, the relevant content of the existing technology will be introduced:
[0052] 1. Hash Algorithm and Hash Digest
[0053] 1) Hash is generally translated as "hash" and can also be directly transliterated as "hash". In this article, its English is directly used.
[0054] 2) The Hash algorithm is an algorithm that maps binary values of any length to binary values of a shorter fixed length, including algorithms such as CRC32, MD5, and SHA1.
[0055] 3) Hash digest. The Hash algorithm maps a binary value of any length into a binary value of a shorter fixed length. This small binary value is called the Hash digest, Hash value, or Hash verification data; it is a unique and extremely compact numerical representation of a piece of data. It is computationally almost impossible to find two different inputs with the same Hash digest. Therefore, the Hash digest of data can be used to verify the integrity of the data.
[0056] 2. Symmetric encryption algorithm and its symmetric key
[0057] A symmetric encryption algorithm is an encryption algorithm in which the encryption key and the decryption key are the same or can be deduced from each other. The key used in a symmetric encryption algorithm is called the symmetric key.
[0058] The encryption key of a symmetric encryption algorithm can be deduced from the decryption key, and at the same time, the decryption key can also be deduced from the encryption key. In most symmetric algorithms, the encryption key and the decryption key are the same.
[0059] 3. Asymmetric encryption algorithm and its asymmetric key pair
[0060] An asymmetric encryption algorithm is an encryption algorithm in which the encryption key and the decryption key are different; such as the RSA algorithm.
[0061] The two keys used in an asymmetric encryption algorithm are the public key and the private key. They are a pair, but it is computationally almost impossible to deduce one from the other, and they are called an asymmetric key pair.
[0062] If data is encrypted using the public key and the algorithm, only the corresponding private key and the algorithm can be used to decrypt it; if data is encrypted using the private key and the algorithm, then only the corresponding public key and the algorithm can be used to decrypt it.
[0063] 4. Digital certificate
[0064] A digital certificate is an electronic signature authentication certificate, which refers to a data message or other electronic record that can prove the connection between the electronic signatory and the electronic signature production data;
[0065] A digital certificate is generally a file containing the public key and the information of the public key owner, electronically signed by a digital certificate certification authority (CA).
[0066] 5. Digital certificate application
[0067] Digital certificate application refers to "applications related to digital certificates", which can be "key pairs for generating digital certificates", "downloading and establishing digital certificates", or "updating digital certificates", etc.
[0068] 6. Electronic signature
[0069] 1) An electronic signature, also known as a digital signature, refers to data contained in or attached to a data message in electronic form that is used to identify the signatory's identity and indicate that the signatory approves the content therein. For example: The sender first calculates a message digest (also known as: HASH digest) for the message according to a predefined HASH algorithm; then encrypts the message digest using the sender's private key and an asymmetric encryption algorithm. The resulting ciphertext is called "the electronic signature of the sender for the message". The electronic signature needs to be bound to the original message and sent to the recipient together.
[0070] 2) Electronic signature production data refers to the characters, codes, and other data used in the process of electronic signature that reliably links the electronic signature with the electronic signatory.
[0071] 3) Electronic signature verification data refers to the data used to verify the electronic signature, including codes, passwords, algorithms, or public keys, etc.
[0072] 4) The verification method of the electronic signature is recorded and described in the digital certificate.
[0073] 7. CA is the abbreviation of Certification Authority, and its Chinese meaning is: Certification Authority; it is a third-party trust institution that adopts public key infrastructure technology, specializes in providing network identity authentication services, is responsible for authenticating, issuing, and managing digital certificates, and has authority and fairness. It is usually also called the Digital Certificate Certification Center.
[0074] 8. Download and establishment means downloading, storing, and applying in the memory of a computer.
[0075] 9. ID data. ID is the abbreviation of identification, and ID data refers to: identification data. Summary of the Invention
[0076] The basic concept of the present invention is as follows: to improve the existing TEE system and enhance the security level of the TEE system; to make the "improved TEE system match the security level of the SE electronic signature module and cooperate to form a powerful electronic signature system with a new (TEE + SE) architecture"; including: (1) improving the trust root of the existing TEE system, that is, using the SE electronic signature module as a trust root component of the TEE system, and transferring and storing the "unchangeable verification data (such as the public key for signature verification) in the existing TEE system trust root for verifying the 'TEE module to be loaded and established'" to the SE electronic signature module that can be connected and communicate with the TEE system and serves as a trust root component of the TEE system, and regularly updating it according to the requirements of security specifications (such as updating the public key for signature verification); (2) improving the signature verification process of the TEE system; by applying the SE electronic signature module and the "verification data (such as the public key for signature verification and Hsah value) in the SE electronic signature module for verifying the 'TEE software module to be loaded and established'" for signature verification, improving the security and reliability of the TEE system established in the "chain signature verification method"; (3) improving the problem that the "existing TEE system has always been under the exclusive management and control of the system manufacturer (such as a mobile phone manufacturer) without third-party certification and supervision"; enabling the "TEE system for electronic signature applications" to be verified and controlled by an "authoritative third party (such as a CA)", improving the security and reliability of the "TEE system for electronic signature applications"; (4) at the same time, the SE electronic signature module connected and communicating with the TEE system also makes corresponding improvements.
[0077] A system including a TEE, its SE electronic signature module, and an electronic signature system disclosed by the present invention can have various different solutions under the overall concept; to completely describe various different solutions under the overall concept of the present invention, the following describes various different solutions of the present invention according to a hierarchical and modular structure.
[0078] 1. The present invention discloses a system including a Trusted Execution Environment (TEE), which includes a Rich Execution Environment (REE) system and a Trusted Execution Environment (TEE) system, and is characterized in that:
[0079] The trust root of the TEE system it contains includes: a TEE hardware system, a system ROM memory firmware program, an SE electronic signature module connected and communicating with the TEE system, and verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established;
[0080] Among them, the TEE system is a TEE system established in a chain signature verification method starting from the system ROM memory firmware program based on the trust root of the TEE system; the security level of the TEE system matches that of the SE electronic signature module of the trust root of the TEE system;
[0081] Among them, the TEE system includes a TEE loading and establishment management module, which is used to manage, verify, and establish the TEE module to be loaded and established;
[0082] The TEE loading and establishment management module obtains the electronic signatures of the TEE module to be loaded and established and its authenticator according to the protocol and process;
[0083] The TEE loading and establishment management module communicates and collaborates with the SE electronic signature module according to the protocol and process, and uses the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of the TEE module to be loaded and established;
[0084] The TEE loading and establishment management module executes the next step according to the protocol agreement based on the verification result of the electronic signature.
[0085] 2. A system including a TEE as described in 1 above, further characterized in that:
[0086] The trust root of the TEE system it includes includes: the TEE hardware system, the system ROM memory firmware program, the SE reliable electronic signature module connected and communicating with the TEE system, and the verification data (such as the public key for signature verification) of the authoritative third party (such as: CA) and the verification data (such as the public key for signature verification) of the system manufacturer (such as: mobile phone manufacturer) stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established;
[0087] Among them, the TEE system is a TEE system established in a chain signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system; the TEE system matches the security level of the SE electronic signature module of the trust root of the TEE system;
[0088] Among them, the TEE system includes a TEE loading and establishment management module, which is used to manage, verify, and establish the TEE module to be loaded and established;
[0089] The TEE loading and establishment management module obtains the electronic signatures of the TEE module to be loaded and established, its authoritative third party (such as: CA), and the system manufacturer (such as: mobile phone manufacturer) according to the protocol and process;
[0090] The TEE loading and establishment management module communicates and collaborates with the SE electronic signature module according to the protocol and process, and uses the verification data of the authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established to respectively verify the electronic signatures of the authoritative third party and the system manufacturer of the TEE module to be loaded and established;
[0091] If the verification of the electronic signature of the authoritative third party and the electronic signature of the system manufacturer fails, the TEE loading and establishment management module rejects the startup and execution of the TEE module to be loaded and established;
[0092] If the verification of the electronic signatures of both the authoritative third party and the system manufacturer passes, the TEE loading and establishment management module continues to execute the next step according to the process.
[0093] 3. The present invention discloses an electronic signature system, which is characterized in that it is an electronic signature system applied to the system including the Trusted Execution Environment (TEE); it includes: the TEE system for the electronic signature application of the electronic signature system and the SE electronic signature module connected and communicating with the TEE system;
[0094] Among them, the trust root of the TEE system for the electronic signature application includes: the TEE hardware system, the system ROM memory firmware program, the SE electronic signature module connected and communicating with the TEE system, and the verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established;
[0095] Among them, the TEE system is a TEE system established in a chained signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system; the TEE system matches the security level of the SE electronic signature module of the trust root of the TEE system; the TEE system and the SE electronic signature module cooperate with each other to jointly complete the tasks of the electronic signature application;
[0096] Among them, the SE electronic signature module includes: the verification data in the trust root of the TEE system for verifying the TEE module to be loaded and established;
[0097] Among them, the SE electronic signature module includes an assistance TEE establishment management module for applying the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established, and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established;
[0098] Among them, the TEE loading and establishment management module communicates and cooperates with the SE electronic signature module and its assistance TEE establishment management module according to the protocol and process, and verifies the electronic signature of the TEE module to be loaded and established by applying the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established.
[0099] 4. An electronic signature system as described in item 3 above, further characterized in that: it is an electronic signature system applied to the system including the trusted execution environment TEE and verified by an authoritative third party; it includes: a TEE system for electronic signature applications verified by an authoritative third party in the electronic signature system and an SE electronic signature module verified by an authoritative third party and connected to the TEE system for communication;
[0100] Among them, for the TEE system for electronic signature applications verified by an authoritative third party, its trust root includes: a TEE hardware system, a system ROM memory firmware program, an SE reliable electronic signature module connected to the TEE system for communication, and verification data of an authoritative third party and verification data of the system manufacturer stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established;
[0101] Among them, the TEE system is a TEE system established in a chain signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system; the TEE system matches the security level of the SE electronic signature module of the trust root of the TEE system; the TEE system and the SE electronic signature module cooperate with each other to jointly complete the tasks of electronic signature applications;
[0102] Among them, the SE electronic signature module verified by an authoritative third party includes: verification data of an authoritative third party and verification data of the system manufacturer in the trust root of the TEE system for verifying the TEE module to be loaded and established;
[0103] Among them, the SE electronic signature module includes an assisting TEE establishment management module for applying the verification data of an authoritative third party and verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established, and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established;
[0104] Among them, the TEE loading and establishment management module communicates and cooperates with the SE electronic signature module and its assisting TEE establishment management module according to the protocol and process, and applies the verification data of an authoritative third party and verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of an authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established respectively.
[0105] 5. The present invention discloses an SE electronic signature module, which includes: a processor, a memory, and a computer program stored on the memory and executable on the processor, characterized in that:
[0106] The SE electronic signature module can be interconnected and communicate with the TEE system of the "system including TEE", and is the trust root component of the TEE system, used to verify the "TEE module to be loaded and established";
[0107] The SE electronic signature module stores "verification data for verifying the TEE module to be loaded and established";
[0108] At the same time, "the SE electronic signature module and the verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established" serve as the trust root of the TEE system of the "system including TEE", used to verify the "TEE module to be loaded and established";
[0109] It is further characterized in that: the SE electronic signature module includes an "assistant TEE establishment management module", which is used to apply the "verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established", and assist the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established;
[0110] Among them, the TEE loading and establishment management module of the TEE system obtains the TEE module to be loaded and established and its electronic signature according to the protocol and process;
[0111] The TEE loading and establishment management module of the TEE system communicates and collaborates with the SE electronic signature module and its "assistant TEE establishment management module" according to the protocol and process, and uses the verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of the TEE module to be loaded and established;
[0112] The TEE loading and establishment management module executes the next step according to the protocol agreement based on the verification result of the electronic signature.
[0113] 6. An SE electronic signature module as described in item 5 above, which includes: a processor, a memory, and a computer program stored on the memory and executable on the processor. It is further characterized in that:
[0114] The SE electronic signature module stores "verification data of an authoritative third party and verification data of the system manufacturer for verifying the TEE module to be loaded and established";
[0115] At the same time, "the SE electronic signature module and the verification data of an authoritative third party and verification data of the system manufacturer stored in the SE electronic signature module for verifying the TEE module to be loaded and established" serve as the trust root of the TEE system of the "system including TEE", used to verify the "TEE module to be loaded and established";
[0116] It is further characterized in that: the SE electronic signature module includes an "assistant TEE establishment management module" for applying "the verification data of the authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established", and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established;
[0117] Among them, the TEE loading and establishment management module of the TEE system obtains the electronic signature of the authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established according to the protocol and process;
[0118] The TEE loading and establishment management module of the TEE system communicates and cooperates with the SE electronic signature module and its "assistant TEE establishment management module" according to the protocol and process, and applies the verification data of the authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of the authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established respectively;
[0119] If the verification of the electronic signature of the authoritative third party and the electronic signature of the system manufacturer fails, the TEE loading and establishment management module refuses to start and execute the TEE module to be loaded and established;
[0120] If the verification of the electronic signature of the authoritative third party and the electronic signature of the system manufacturer both pass, the TEE loading and establishment management module continues to execute the next step according to the process.
[0121] Beneficial effects:
[0122] The technical solution of the present invention can solve the problems that: due to the "low security level of the trust root of the existing TEE system", the "security level of the existing TEE system is lower than that of the SE electronic signature module", and further the "existing TEE system cannot be safely matched with the SE electronic signature module and cannot establish a (TEE+SE) architecture electronic signature system"; at the same time, it can also solve the problems that "the existing TEE system is specifically controlled by the system manufacturer, without third-party supervision, and the security does not meet the standard, cannot be safely matched with the SE electronic signature module, and cannot establish a reliable electronic signature system with a (TEE+SE) architecture";
[0123] In addition, the technical solution of the present invention has a "highly secure TEE system trust root that is securely matched with the SE electronic signature module", enabling the establishment of a "highly secure TEE system that is securely matched with the SE electronic signature module"; at the same time, a powerful and reliable electronic signature system with a (TEE + SE) architecture can be established; at the same time, the powerful functions of the mobile phone TEE system can be utilized to realize reliable electronic signature service applications where what is signed is what is seen across all fields (including: pictures, videos, large text data, etc.). Compared with the "existing electronic signature systems where what is signed is what is seen (such as: bank UKEY, which is only applicable to very small text data)", the functions are significantly more powerful and the security is significantly improved. BRIEF DESCRIPTION OF THE DRAWINGS
[0124] Figure 1 is a schematic structural diagram of the TEE system trust root of the existing "system including TEE"; among them, the "verification data for verifying the TEE software module to be loaded and established" of the TEE system trust root is stored in the system ROM module;
[0125] Figure 2 is a schematic structural diagram of the TEE system trust root of the "system including TEE" of the present invention; it includes: a TEE hardware system, a system ROM memory firmware program, an SE electronic signature module connected and communicating with the TEE system, and verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established;
[0126] Figure 3 is a schematic structural diagram of the electronic signature system for the "system including TEE" of the present invention; it includes: the TEE system for electronic signature applications and an "SE electronic signature module connected and communicating with the TEE system". DETAILED DESCRIPTION OF THE EMBODIMENTS
[0127] The following specific embodiments are given in conjunction with the drawings to further describe the overall concept and specific technical solutions of the present invention:
[0128] Embodiment 1: A mobile phone system, its SE reliable electronic signature module and electronic signature system
[0129] A mobile phone system provided in Embodiment 1 of the present invention includes a REE system (Android system) and a TEE system; the TEE system can interact and communicate with the SE reliable electronic signature module; the SE reliable electronic signature module includes verification data for verifying the TEE module to be loaded and established; it is characterized in that:
[0130] The trust root of the TEE system of the mobile phone includes: the TEE hardware system, the system ROM memory firmware program, the SE reliable electronic signature module connected and communicating with the TEE system, and the verification data stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established, which is equivalent to "the verification data of the authoritative third party and the verification data of the system manufacturer";
[0131] Among them, the TEE system is a "TEE system for running the TEE trusted operating system program" established in a chain signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system (including: the SE electronic signature module and its verification data for verifying the TEE module to be loaded and established); the security level of the TEE system matches that of the SE electronic signature module of the trust root of the TEE system (both are security certified by an authoritative third party);
[0132] Among them, the TEE system includes a TEE loading and establishment management module for managing, verifying, and establishing the "TEE module for electronic signature application" to be loaded and established;
[0133] The TEE loading and establishment management module obtains, according to the protocol and process, the "TEE module for electronic signature application" to be loaded and established and its electronic signature equivalent to "the electronic signature of the authoritative third party and the electronic signature of the system manufacturer";
[0134] The TEE loading and establishment management module communicates and collaborates with the SE electronic signature module according to the protocol and process, and uses the verification data equivalent to "the verification data of the authoritative third party and the verification data of the system manufacturer" in the SE electronic signature module to verify the electronic signature equivalent to "the electronic signature of the authoritative third party and the electronic signature of the system manufacturer" of the "TEE module for electronic signature application" to be loaded and established;
[0135] If the verification of the electronic signature fails, the TEE loading and establishment management module rejects starting and executing the "TEE module for electronic signature application" to be loaded and established;
[0136] If the verification of the electronic signature passes, the TEE loading and establishment management module executes the "TEE module for electronic signature application" according to the process.
[0137] Among them, the "electronic signature equivalent to the 'electronic signatures of the authoritative third party and the system manufacturer'" refers to: the TEE module is sent to the "authenticated trusted server system" after being authenticated and electronically signed by the authoritative third party and the system manufacturer respectively. The authenticated trusted server system verifies the electronic signatures of the authoritative third party and the system manufacturer of the TEE module according to the agreement. If both verifications pass, then "the trusted server system electronically signs the TEE module according to the agreement and outputs the application"; at this time, the electronic signature of the trusted server system for the TEE module is equivalent to the "electronic signatures of the authoritative third party and the system manufacturer of the TEE module" according to the agreement. Therefore, the "electronic signature of the trusted server system for the TEE module" is also called the "electronic signature equivalent to the 'electronic signatures of the authoritative third party and the system manufacturer'".
[0138] Among them, the "verification data equivalent to the'verification data of the authoritative third party and the system manufacturer'" refers to: the verification data of the "electronic signature of the trusted server system for the TEE module" above; this verification data is equivalent to the "verification data of the authoritative third party and the system manufacturer for verifying the 'electronic signatures of the authoritative third party and the system manufacturer'" according to the agreement. Therefore, the "verification data of the 'electronic signature of the trusted server system for the TEE module'" is also called the "verification data equivalent to the'verification data of the authoritative third party and the system manufacturer'".
[0139] Embodiment 1 of the present invention provides an electronic signature system with a mobile phone (TEE + SE) architecture, which includes: the "TEE system for electronic signature application verified by an authoritative third party" of the mobile phone system, and the "SE electronic signature module verified by an authoritative third party and connected to the TEE system for communication".
[0140] Among them, the "TEE system for electronic signature application verified by an authoritative third party" is characterized in that its trust root includes: a TEE hardware system, a system ROM memory firmware program, an SE reliable electronic signature module connected to the TEE system for communication, and verification data stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established, which is equivalent to the "verification data of the authoritative third party and the system manufacturer".
[0141] Among them, the "TEE system for electronic signature applications verified by an authoritative third party" is a TEE system established in a chain signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system; the security level of the TEE system matches that of the SE electronic signature module in the trust root of the TEE system; the TEE system and the SE electronic signature module cooperate with each other to jointly complete the tasks of electronic signature applications.
[0142] Among them, the SE electronic signature module includes: verification data in the trust root of the TEE system for verifying the TEE module to be loaded and established.
[0143] Among them, the SE electronic signature module includes an assisting TEE establishment management module for applying the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established, and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established.
[0144] Among them, the TEE loading and establishment management module communicates and cooperates with the SE electronic signature module and its assisting TEE establishment management module according to protocols and processes, and verifies the electronic signature of the TEE module to be loaded and established by using the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established.
[0145] Embodiment 1 provides an SE electronic signature module, which includes: a processor, a memory, and a computer program stored on the memory and executable on the processor, and is characterized in that:
[0146] The SE electronic signature module can be connected and communicate with the mobile phone TEE system, and is a trust root component of the TEE system for verifying the "TEE module to be loaded and established".
[0147] The SE electronic signature module stores "verification data for verifying the TEE module to be loaded and established".
[0148] At the same time, the "SE electronic signature module and the verification data for verifying the TEE module to be loaded and established stored in the SE electronic signature module" serve as the trust root of the mobile phone TEE system for verifying the "TEE module to be loaded and established".
[0149] It is further characterized in that: the SE electronic signature module includes an "assisting TEE establishment management module" for applying the "verification data in the SE electronic signature module for verifying the TEE module to be loaded and established", and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established.
[0150] Among them, the TEE loading and establishment management module of the TEE system obtains the TEE module to be loaded and established and its electronic signature according to the protocol and process;
[0151] The TEE loading and establishment management module of the TEE system communicates and collaborates with the SE electronic signature module and its "assist TEE establishment management module" according to the protocol and process, and uses the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of the TEE module to be loaded and established;
[0152] If the verification of the electronic signature fails, the TEE loading and establishment management module rejects the start of the execution of the TEE module to be loaded and established;
[0153] If the verification of the electronic signature passes, the TEE loading and establishment management module continues to execute the next step according to the process.
[0154] The above is only a preferred embodiment of the present application and is not intended to limit the present application; any modifications, equivalent replacements, improvements, etc. made within the spirit and principle of the present application shall be included within the scope of protection of the present application.
Claims
1. A system including a Trusted Execution Environment (TEE), which includes a Rich Execution Environment (REE) system and a Trusted Execution Environment (TEE) system, Characterized in that: The trust root of the TEE system it contains includes: a TEE hardware system, a system ROM memory firmware program, an SE electronic signature module connected and communicating with the TEE system, and verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established; Wherein, the TEE system is a TEE system established in a chained signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system (including: the SE electronic signature module and the verification data therein for verifying the TEE module to be loaded and established); the TEE system matches the security level of the SE electronic signature module of the trust root of the TEE system; Wherein, the TEE system includes a TEE loading and establishment management module for managing, verifying, and establishing the TEE module to be loaded and established; The TEE loading and establishment management module obtains the electronic signature of the TEE module to be loaded and established and its certifying party according to the protocol and process; The TEE loading and establishment management module communicates and collaborates with the SE electronic signature module according to the protocol and process, and verifies the electronic signature of the TEE module to be loaded and established by using the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established; The TEE loading and establishment management module executes the next step according to the protocol agreement based on the verification result of the electronic signature.
2. A system including a TEE as described in claim 1, Further characterized in that: The trust root of the TEE system it contains includes: a TEE hardware system, a system ROM memory firmware program, an SE reliable electronic signature module connected and communicating with the TEE system, and verification data of an authoritative third party and verification data of the system manufacturer stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established; Wherein, the TEE system is a TEE system established in a chained signature verification manner starting from the system ROM memory firmware program based on the trust root of the TEE system; the TEE system matches the security level of the SE electronic signature module of the trust root of the TEE system; Wherein, the TEE system includes a TEE loading and establishment management module for managing, verifying, and establishing the TEE module to be loaded and established; The TEE loading and establishment management module obtains the electronic signature of the authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established according to the protocol and process; The TEE loading and establishment management module communicates and collaborates with the SE electronic signature module according to the protocol and process, and respectively verifies the electronic signature of the authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established by using the verification data of the authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established; If the verification of the electronic signature of the authoritative third party and the electronic signature of the system manufacturer fails, the TEE loading and establishment management module rejects the startup and execution of the TEE module to be loaded and established. If the verification of the electronic signature of the authoritative third party and the electronic signature of the system manufacturer both pass, the TEE loading and establishment management module continues to execute the next step according to the process.
3. An electronic signature system Characterized in that: It is an electronic signature system applied to the system including the Trusted Execution Environment (TEE); it includes: the TEE system for the electronic signature application of the electronic signature system and the SE electronic signature module connected and communicating with the TEE system. Among them, for the TEE system for the electronic signature application, its root of trust includes: the TEE hardware system, the system ROM memory firmware program, the SE electronic signature module connected and communicating with the TEE system, and the verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established. Among them, the TEE system is a TEE system established in a chained signature verification manner starting from the system ROM memory firmware program based on the root of trust of the TEE system; the TEE system matches the security level of the SE electronic signature module in the root of trust of the TEE system; the TEE system and the SE electronic signature module cooperate with each other to jointly complete the tasks of the electronic signature application. Among them, the SE electronic signature module includes: the verification data in the root of trust of the TEE system for verifying the TEE module to be loaded and established. Among them, the SE electronic signature module includes an assisting TEE establishment management module for applying the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established, and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established. Among them, the TEE loading and establishment management module communicates and cooperates with the SE electronic signature module and its assisting TEE establishment management module according to the protocol and process, and applies the verification data in the SE electronic signature module for verifying the electronic signature of the TEE module to be loaded and established to verify the electronic signature of the TEE module to be loaded and established.
4. An electronic signature system according to claim 3 Further characterized in that: It is an electronic signature system applied to the system including the Trusted Execution Environment (TEE) and verified by an authoritative third party; it includes: the TEE system for the electronic signature application of the electronic signature system verified by an authoritative third party and the SE electronic signature module connected and communicating with the TEE system and verified by an authoritative third party. Among them, for the TEE system for electronic signature applications verified by an authoritative third party, its root of trust includes: a TEE hardware system, a system ROM memory firmware program, an SE reliable electronic signature module connected and communicating with the TEE system, and verification data of an authoritative third party and verification data of the system manufacturer stored in the SE reliable electronic signature module for verifying the TEE module to be loaded and established; Among them, the TEE system is a TEE system established in a chain signature verification manner starting from the system ROM memory firmware program based on the root of trust of the TEE system; the TEE system matches the security level of the SE electronic signature module in the root of trust of the TEE system; the TEE system and the SE electronic signature module cooperate with each other to jointly complete the tasks of electronic signature applications; Among them, the SE electronic signature module verified by an authoritative third party includes: verification data of an authoritative third party and verification data of the system manufacturer in the root of trust of the TEE system for electronic signature applications for verifying the TEE module to be loaded and established; Among them, the SE electronic signature module includes an assisting TEE establishment management module for applying the verification data of an authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established, and assisting the TEE loading and establishment management module of the TEE system to manage and verify the TEE module to be loaded and established; Among them, the TEE loading and establishment management module of the TEE system communicates and cooperates with the SE electronic signature module and its assisting TEE establishment management module according to protocols and processes, and applies the verification data of an authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of an authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established respectively.
5. An SE electronic signature module, which includes: a processor, a memory, and a computer program stored on the memory and executable on the processor, characterized in that: the SE electronic signature module can be connected and communicate with the TEE system of the "system including TEE", and is a root of trust component of the TEE system for verifying the "TEE module to be loaded and established"; the SE electronic signature module stores "verification data for verifying the TEE module to be loaded and established"; At the same time, "the SE electronic signature module and the verification data stored in the SE electronic signature module for verifying the TEE module to be loaded and established" serve as the root of trust of the TEE system of the "system including TEE" for verifying the "TEE module to be loaded and established"; It is further characterized in that: the SE electronic signature module includes an "assistant TEE establishment management module" for applying "the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established" to assist the TEE loading and establishment management module of the TEE system in managing and verifying the TEE module to be loaded and established; Among them, the TEE loading and establishment management module of the TEE system obtains the TEE module to be loaded and established and its electronic signature according to the protocol and process; The TEE loading and establishment management module of the TEE system communicates and cooperates with the SE electronic signature module and its "assistant TEE establishment management module" according to the protocol and process, and applies the verification data in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of the TEE module to be loaded and established; The TEE loading and establishment management module executes the next step according to the protocol agreement based on the verification result of the electronic signature; 6. A SE electronic signature module according to claim 5, wherein it includes: a processor, a memory, and a computer program stored on the memory and executable on the processor, and it is further characterized in that: the SE electronic signature module stores "the verification data of an authoritative third party and the verification data of the system manufacturer for verifying the TEE module to be loaded and established"; At the same time, "the SE electronic signature module and the verification data of an authoritative third party and the verification data of the system manufacturer stored in the SE electronic signature module for verifying the TEE module to be loaded and established" serve as the trust root of the TEE system of the "system including TEE" for verifying the "TEE module to be loaded and established"; It is further characterized in that: the SE electronic signature module includes an "assistant TEE establishment management module" for applying "the verification data of an authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established" to assist the TEE loading and establishment management module of the TEE system in managing and verifying the TEE module to be loaded and established; Among them, the TEE loading and establishment management module of the TEE system obtains the TEE module to be loaded and established and its electronic signature of an authoritative third party and the electronic signature of the system manufacturer according to the protocol and process; The TEE loading and establishment management module of the TEE system communicates and cooperates with the SE electronic signature module and its "assistant TEE establishment management module" according to the protocol and process, and applies the verification data of an authoritative third party and the verification data of the system manufacturer in the SE electronic signature module for verifying the TEE module to be loaded and established to verify the electronic signature of an authoritative third party and the electronic signature of the system manufacturer of the TEE module to be loaded and established respectively; If the verification of the electronic signature of an authoritative third party and the electronic signature of the system manufacturer fails, the TEE loading and establishment management module rejects the startup and execution of the TEE module to be loaded and established; If the verification of both the electronic signature of the authoritative third party and the electronic signature of the system manufacturer passes, the TEE loading and establishment management module is loaded and the next step is continued according to the process.