Processing method and device and electronic equipment
The problem of encryption and decryption key leakage is solved by using encryption keys in the terminal file system and decrypting keys in a non-secure environment, improving security and protecting user privacy and system security.
Patent Information
- Application Number
- CN202510130643.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-05
- Publication Date
- 2025-05-30
AI Technical Summary
The encryption and decryption keys of files in the terminal file system are cached in a conventional memory environment and have a risk of leakage, which threatens user privacy and system security.
The target encryption key is formed by generating a key for file encryption and decryption in a first operating environment (such as TEE) and encrypting it before exporting to a non-secure domain. Then, the file system information and the target encryption key are transmitted to the third running environment in the second running environment, and the key is decrypted in the environment for encryption and decryption processing.
It effectively avoids the exposure of plaintext keys in non-secure environments, improves the security of encryption and decryption keys, protects user privacy and guarantees system security.
Smart Images

Figure CN120068109A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of data security technology, and particularly relates to a processing method, device, and electronic device. Background Art
[0002] In traditional technology, the encryption and decryption keys of files in the terminal file system are at risk of leakage because they are cached in the conventional memory environment, and it is easy to cause the keys used for encryption and decryption to be maliciously extracted, tampered with, or deleted. As a result, it is difficult for terminals such as mobile phones to protect user privacy and ensure system security, and ultimately the user's privacy and system security will be threatened. Summary of the Invention
[0003] For this reason, the present application discloses the following technical solutions:
[0004] A processing method includes:
[0005] In response to detecting an encryption / decryption request for a first data file, obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in a second operating environment; the target encryption key includes the result of encrypting a first key through a first operating environment; the file system information at least includes the file information of the first data file;
[0006] Transmitting the file system information to a third operating environment in the second operating environment, and transmitting the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key;
[0007] Obtaining the return result of the first operating environment in the third operating environment, the return result at least including the first key obtained by decrypting the target encryption key;
[0008] Using the first key to perform encryption / decryption processing on the first data file corresponding to the file system information in the third operating environment to obtain a second data file;
[0009] Wherein, the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
[0010] Optionally, the encryption / decryption request includes an encrypted storage request for the first data file or a decryption request for the stored first data file.
[0011] Optionally, obtaining the target encryption key in the second operating environment includes:
[0012] Determining the storage path of the first data file;
[0013] Determine a target encryption key that matches the storage path from among the multiple encrypted keys stored in the second operating environment;
[0014] Among them, the multiple encrypted keys include the results of encrypting multiple keys respectively through the first operating environment.
[0015] Optionally, the first operating environment is the operating environment provided by the first hardware, the second operating environment is the operating environment provided by the system software, and the third operating environment is the operating environment provided by the second hardware.
[0016] Optionally, the system software includes an operating system kernel, and the operating system kernel includes a file system, a memory medium driver, and a key manager;
[0017] Obtaining the file system information corresponding to the first data file and the target encryption key for encrypting and decrypting the first data file in the second operating environment includes:
[0018] Obtain the file system information and the target encryption key corresponding to the first data file in the file system;
[0019] Transmitting the file system information to the third operating environment and transmitting the target encryption key to the first operating environment in the second operating environment to request the first operating environment to decrypt the target encryption key includes:
[0020] The file system establishes an association between the target encryption key and the file system information to obtain an association result, and transmits the association result to the memory medium driver;
[0021] The memory medium driver transmits the file system information in the association result to the third operating environment, and transmits the target encryption key in the association result to the key manager;
[0022] The key manager transmits the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key.
[0023] Optionally, the second hardware includes a memory medium encryption / decryption engine, and the file system information further includes an encryption / decryption method;
[0024] Performing encryption and decryption processing on the first data file using the first key in the third operating environment includes:
[0025] The memory medium encryption / decryption engine encrypts or decrypts the first data file using the first key through the encryption / decryption method.
[0026] Optionally, if the encryption / decryption request is an encryption request, the file system information further includes the storage path where the first data file is to be stored. After obtaining the second data file, it further includes:
[0027] Storing the second data file in the storage location indicated by the storage path in the third operating environment.
[0028] Optionally, if the encryption / decryption request is a decryption request, before obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in the second operating environment, it further includes:
[0029] If the first key exists in the third operating environment, decrypt the first data file based on the first key;
[0030] If the first key does not exist in the third operating environment, trigger the step of obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in the second operating environment.
[0031] A processing device includes:
[0032] A first acquisition module, configured to, in response to detecting an encryption / decryption request for a first data file, obtain the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in a second operating environment; the target encryption key includes the result of encrypting a first key through a first operating environment; the file system information at least includes the file information of the first data file;
[0033] A transmission module, configured to, in the second operating environment, transmit the file system information to a third operating environment and transmit the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key;
[0034] A second acquisition module, configured to obtain the return result of the first operating environment in the third operating environment, where the return result at least includes the first key obtained by decrypting the target encryption key;
[0035] An encryption / decryption module, configured to, in the third operating environment, perform encryption / decryption processing on the first data file corresponding to the file system information using the first key to obtain a second data file;
[0036] Wherein, the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
[0037] An electronic device, comprising: a first hardware for providing a first operating environment, a system software for providing a second operating environment, and a second hardware for providing a third operating environment; the security of the first operating environment and the third operating environment is higher than that of the second operating environment;
[0038] Wherein, the system software is configured to:
[0039] In response to detecting an encryption / decryption request for a first data file, obtain the file system information corresponding to the first data file, and a target encryption key for encrypting / decrypting the first data file; the target encryption key includes the result of encrypting a first key through the first operating environment; the file system information at least includes the file information of the first data file;
[0040] Transmit the file system information to the third operating environment, and transmit the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key;
[0041] The second hardware is configured to;
[0042] Obtain the return result of the first operating environment, the return result at least includes the first key obtained by decrypting the target encryption key; use the first key to perform encryption / decryption processing on the first data file corresponding to the file system information to obtain a second data file. Description of the Drawings
[0043] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the following will briefly introduce the drawings required for use in the description of the embodiments or related technologies. Obviously, the drawings in the following description are only the embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0044] Figure 1 It is a flowchart of the processing method provided by the present application;
[0045] Figure 2 It is a framework diagram for file encryption / decryption implementation provided by the present application;
[0046] Figure 3 It is a flowchart of transmitting the file system information to the third operating environment and transmitting the target encryption key to the first operating environment provided by the present application;
[0047] Figure 4 It is a composition structure diagram of the processing device provided by the present application;
[0048] Figure 5It is the component structure diagram of the electronic device provided by this application. Detailed implementation manners
[0049] Next, the technical solutions in the embodiments of this application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of this application. Obviously, the described embodiments are only a part of the embodiments of this application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments in this application without creative efforts shall fall within the protection scope of this application.
[0050] The embodiments of this application provide a processing method, device, and electronic device, which are used to solve the problem of easy leakage of the key in the file encryption and decryption scenario of the electronic device, so as to improve the security of the encryption and decryption key, thereby protecting user privacy and ensuring system security. The processing method can be applied to electronic devices in many general or specific computing device environments or configurations, such as: personal computers, server computers, handheld devices or portable devices, tablet devices, multi-processor devices, and so on.
[0051] Refer to Figure 1 As shown in the schematic flowchart of the method, the processing method provided by the embodiments of this application may include the following steps 101 to 104, and these steps will be described in detail below.
[0052] Step 101: In response to detecting an encryption / decryption request for a first data file, obtain the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in a second operating environment.
[0053] The first data file is the file currently to be encrypted or decrypted in the electronic device file system.
[0054] Correspondingly, the encryption / decryption request for the first data file may be an encryption request triggered by a user or a system based on a need to request encryption of the first data file, such as an encryption storage request triggered by an Android application in the user space (User space) to request encrypted storage of the first data file; or the encryption / decryption request for the first data file may also be a decryption request to request decryption of the stored first data file.
[0055] The first operating environment is the operating environment provided by the first hardware, which is a trusted and secure operating environment with hardware-level security protection. The first hardware may include, but is not limited to, a dedicated security processor (such as ARM TrustZone) or a dedicated hardware security module. Optionally, the first operating environment may be a TEE (Trusted Execution Environment), and the TEE can run independently of the operating system and provide hardware-level security protection.
[0056] The second operating environment is the operating environment provided for the system software. Optionally, the system software includes an operating system kernel.
[0057] The security of the first operating environment is higher than that of the second operating environment. The second operating environment is an insecure environment with a risk of key leakage.
[0058] For the file encryption and decryption application scenario of an electronic device, in implementation, the encryption and decryption requests for the data files in the electronic device can be detected. Once the encryption and decryption requests for the first data file are detected, first, two types of information corresponding to the first data file are obtained in the second operating environment such as the operating system kernel. One type is the file system information corresponding to the first data file, and the other type is the target encryption key used to encrypt and decrypt the first data file, so as to complete the response to the encryption and decryption requests based on these two types of information.
[0059] Optionally, the operating system kernel further includes a file system, a memory medium driver, and a key manager. In response to detecting the encryption and decryption requests for the first data file, specifically, the file system information and the target encryption key corresponding to the first data file can be obtained in the file system of the second operating environment.
[0060] Among them, the file system information corresponding to the first data file at least includes the file information of the first data file. The file information of the first data file may include, but is not limited to, the file name, file content, file attributes (such as read-only or read-write attributes), target storage path, etc. of the first data file.
[0061] Optionally, the file system information corresponding to the first data file, in addition to including the file information of the first data file, may also include the encryption and decryption method to be adopted by the first data file, such as the encryption and decryption method characterized by a specific encryption and decryption algorithm, etc.
[0062] If the encryption / decryption request for the first data file is an encryption request, such as an encrypted storage request, the target storage path is the path where the first data file is to be stored. For example, if an encrypted storage request indicating that a certain word file received by WeChat is to be encrypted and stored in a folder on the D drive is detected, then the target storage path is the storage path corresponding to that folder on the D drive; if the encryption / decryption request for the first data file is a decryption request, the target storage path is the currently stored path corresponding to the first data file.
[0063] The target encryption key for encrypting / decrypting the first data file includes the result of encrypting the first key through the first operating environment. For example, the encryption key obtained by encrypting the first key through the TEE.
[0064] In the traditional technology, for the encryption / decryption requirements of files in the terminal file system, specifically, a key is first generated from the trusted secure environment TEE, and then the key generated in the TEE is obtained in the user layer and added / registered to a non-secure domain such as the operating system kernel. After a series of file system processes are performed on the key by the operating system kernel (for example, binding specific file system information to the key so that the operating system knows the corresponding specific storage path and the method / algorithm to be used for encryption / decryption when processing files later), the key is finally passed to the memory medium driver and then injected into the memory medium encryption / decryption engine (Inline Crypto Engine, ICE), and then the ICE encrypts / decrypts the file based on the injected key.
[0065] In the above process, from the user layer to the kernel stage, the secret key is hosted in a non-secure domain, and there is a risk of leakage or malicious extraction. No matter how the operating system strengthens the corresponding access control permissions in this process, problems such as when the system is cold restarted, or there are vulnerabilities in the file system driver and the memory medium driver, etc., will always make the key face the problem of leakage or malicious exploitation, which in turn threatens user privacy and system security.
[0066] To solve the above technical problems, after generating the key S (plaintext key) for file encryption / decryption in the first operating environment such as the TEE in the embodiment of the present application, before exporting the key to the non-secure domain, the key is encrypted in the first operating environment such as the TEE. For example, another hardware key K is used to encrypt the key S to obtain the encrypted key S' (the key in the ciphertext form corresponding to S), and finally the encrypted key S' is provided to the non-secure domain, such as provided to the second operating environment such as the operating system kernel, so that the non-plaintext key S' is hosted in the non-secure second operating environment instead of the original plaintext key S, to avoid exposing the plaintext key S in the non-secure domain.
[0067] Based on this, the first hardware for providing the first operating environment, such as the first hardware for implementing the TEE, can be designed to include a key generator with a key generation function and an encryption / decryption module with an encryption / decryption function for keys. The functions of the key generator and the encryption / decryption module can be implemented, but are not limited to, by a dedicated security processor or a dedicated security module.
[0068] In addition, a disk management program, such as an Andriod disk management program, can be built and run in the second operating environment, and an interaction function between the second operating environment and the first operating environment can be provided based on the disk management program. For example, based on the disk management program, the TEE is requested to generate a key in the second operating environment, and the encryption key (such as S' corresponding to S) corresponding to the generated key is exported from the TTE to the second operating environment, etc.
[0069] Each file system type has a specific key format, type, and number. The usage requirements of the key are associated and bound to the specific file system information corresponding to the file, such as the path node information, file name, file content, file attributes, etc. of the EXT4 / F2FS and other file systems corresponding to the file. Different path nodes usually have certain rules to specify which key to use and in what way to perform encryption / decryption.
[0070] Based on this, in implementation, for a specific file system, the required key can be requested from the first operating environment such as the TEE through the disk management program according to actual needs. For example, assuming that different disks of the current file system need to use different keys and different encryption / decryption methods to encrypt and decrypt files respectively, the disk management program can request the TEE to generate the corresponding key S for each disk, and export the encryption key S' corresponding to each key S from the TEE and add / register it to the second operating environment to save the encryption keys corresponding to the keys required for each disk in the second operating environment, such as specifically saving the correspondence information between the disk identifier of each disk and the encryption key.
[0071] For this implementation manner, in this step, in response to detecting an encryption / decryption request for the first data file, when obtaining the target encryption key for encrypting / decrypting the first data file, the storage path of the first data file can be specifically determined, and the target encryption key matching the storage path can be determined from the multiple encryption keys stored in the second operating environment. Among them, the multiple encryption keys include the results of encrypting multiple keys through the first operating environment respectively.
[0072] Exemplarily, specifically, the to-be-stored path or the already-stored path of the first data file indicated by the encryption / decryption request may be parsed, and the target disk corresponding to the to-be-stored path / already-stored path may be determined. On this basis, based on the correspondence information between the disk identifiers and the encryption keys of each disk saved in the second operating environment, the target encryption key corresponding to the target disk may be determined and read.
[0073] Step 102: In the second operating environment, transmit the file system information to the third operating environment, and transmit the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key.
[0074] The third operating environment is the operating environment provided by the second hardware. The third operating environment also has security guarantees at the hardware level, and its security is higher than that of the second operating environment.
[0075] Optionally, the second hardware includes a memory medium encryption / decryption engine, and the third operating environment may correspondingly be the operating environment provided by the memory medium encryption / decryption engine. The memory medium encryption / decryption engine can only write (WRITE) and cannot read (READ) in terms of circuit configuration, that is, any software module or instruction cannot access the memory medium encryption / decryption engine.
[0076] After obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in the second operating environment, such as in the file system of the operating system kernel, with reference to Figure 2 the shown file encryption / decryption implementation framework diagram, the file system information can be transmitted to the third operating environment, and the target encryption key can be transmitted to the first operating environment through Figure 3 the shown processing steps:
[0077] Step 301: The file system establishes an association between the target encryption key and the file system information to obtain an association result, and transmits the association result to the memory medium driver.
[0078] For example, associate the target encryption key with the file name, file content, file attributes, target storage path of the first data file, and the encryption / decryption method to be used.
[0079] Optionally, when establishing the association between the target encryption key and the file system information, a corresponding key identifier or association identifier may also be assigned to it, such as a key number or an association number, etc., and the key identifier or association identifier is used as a component of the association result.
[0080] For the case where different disks need to use different key pairs to encrypt and decrypt files respectively, an associated identifier or key identifier corresponding to the target encryption key can be assigned based on the disk corresponding to the target storage path (to-be-stored path or already-stored path) of the first data file. For example, assume that the electronic device has three disks, namely C, D, and E. If the target storage path of the first data file corresponds to disk C, a key identifier numbered 1 can be assigned to it. If it corresponds to disk D, a key identifier numbered 2 can be assigned to it. If it corresponds to disk E, a key identifier numbered 3 can be assigned to it.
[0081] Step 302, the memory medium driver transmits the file system information in the association result to the third operating environment, and transmits the target encryption key in the association result to the key manager.
[0082] Specifically, the memory medium driver can transmit the file system information in the association result to the memory medium encryption / decryption engine.
[0083] Optionally, the memory medium encryption / decryption engine contains multiple registers for storing keys. When the memory medium driver transmits the file system information in the association result to the memory medium encryption / decryption engine, the target register used for the encryption / decryption requirement of the first data file corresponding to the file system information can be specified based on the associated identifier / key identifier. Subsequently, by injecting the plaintext key obtained after decrypting the target encryption key, that is, the first key, into the target register, the matching between the first data file and the first key it needs to use can be achieved.
[0084] For example, if the associated identifier / key identifier is numbered 0 (the corresponding target storage path belongs to disk C), register X is specified for it. If the associated identifier / key identifier is numbered 1 (the corresponding target storage path belongs to disk D), register Y is specified for it. If the associated identifier / key identifier is numbered 2 (the corresponding target storage path belongs to disk E), register Z is specified for it, etc. In the case of a small number of registers, different associated identifiers / key identifiers can correspond to the same register. During the encryption / decryption process, based on the replacement principle, the new plaintext key can replace the historical plaintext key written in the corresponding register.
[0085] When the memory medium driver transmits the target encryption key in the association result to the key manager, it can specifically transmit the key identifier / association identifier and the target encryption key to the key manager together, so that after decrypting the target encryption key to obtain the first key in plaintext form subsequently, it supports injecting the first key into the corresponding register in the memory medium encryption / decryption engine, such as the target register, based on the key identifier / association identifier, so as to match the data file to be encrypted / decrypted with the corresponding plaintext key in the memory medium encryption / decryption engine. For example, matching the first data file with the first key, thereby avoiding the phenomenon of key confusion in the multi-file encryption / decryption scenario.
[0086] Step 303, the key manager transmits the target encryption key to the first running environment to request the first running environment to decrypt the target encryption key.
[0087] Specifically, the key manager can transmit the key identifier / association identifier and the target encryption key to the first running environment together to request the first running environment to decrypt the target encryption key.
[0088] After the first running environment receives the information transmitted by the memory medium driver, it can decrypt the target encryption key in the received information. Exemplarily, with reference to Figure 2 , specifically, it can use the encryption / decryption module in the first running environment such as TEE (such as Figure 2 's encryption / decryption module), and decrypt the target encryption key through the corresponding key, such as the key K described above, to obtain the original plaintext key corresponding to the target encryption key, that is, the first key.
[0089] Among them, the key used for encrypting / decrypting the key, such as the key K, always works in the first running environment such as TEE at any stage, so the non-secure domain (such as Android or Linux kernel) will not be able to intercept it, thus ensuring the security of this key, and correspondingly further ensuring the security of the key used for encrypting / decrypting the data file.
[0090] After decrypting the target encryption key to obtain the original plaintext key corresponding to the target encryption key, that is, the first key, the first running environment can transmit the target encryption key to the memory medium encryption / decryption engine. Optionally, as Figure 2 shown, a memory medium encryption / decryption engine driver can also be designed in the first running environment. After the encryption / decryption module in the first running environment decrypts the target encryption key to obtain the first key, the first key is injected into the memory medium encryption / decryption engine through the memory medium encryption / decryption engine driver.
[0091] The memory medium encryption / decryption engine driver can specifically inject the first key into the target register corresponding to the associated identifier / key identifier in the memory medium encryption / decryption engine based on the associated identifier / key identifier corresponding to the target encryption key.
[0092] Step 103: Obtain the return result of the first operating environment in the third operating environment, where the return result at least includes the first key obtained by decrypting the target encryption key.
[0093] After obtaining the original plaintext key corresponding to the target encryption key, that is, the first key, by decrypting the target encryption key, the third operating environment can correspondingly obtain the return result of the first operating environment. Exemplarily, for example, the target register in the memory medium encryption / decryption engine can obtain the first key injected by the first operating environment.
[0094] Step 104: Use the first key in the third operating environment to perform encryption / decryption processing on the first data file corresponding to the file system information to obtain a second data file.
[0095] After obtaining the first key, the first key can be used in the third operating environment to perform encryption processing or decryption processing on the first data file that matches the encryption / decryption request. Among them, for the first data file to be encrypted / decrypted, specifically, based on the target register specified for it in the memory medium encryption / decryption engine, the matching between the first data file and the first key it needs to use can be realized, so as to perform the required encryption / decryption processing on the first data file based on the first key.
[0096] Optionally, the file system information corresponding to the first data file further includes an encryption / decryption method. Specifically, in the storage medium encryption / decryption engine, the first data file can be encrypted or decrypted using the first key through the encryption / decryption method.
[0097] Among them, if the encryption / decryption request for the first data file is an encryption request, such as an encrypted storage request, then the encryption / decryption method is specifically an encryption method. In this case, the first data file can be encrypted using the first key according to the encryption method, so as to obtain the corresponding encrypted data file, that is, the second data file, and the second data file can be stored in the storage location indicated by the storage path to be stored in the file system information in the memory medium in the third operating environment.
[0098] If the encryption / decryption request for the first data file is a decryption request, the encryption / decryption method is specifically a decryption method. In this case, the first data file can be decrypted using the first key according to the decryption method, and the corresponding decrypted data file, that is, the second data file, can be obtained for use by the user layer.
[0099] There are a large number of software components in the second operating environment formed by operating system kernels such as Android or Linux kernels, and they can directly manipulate files and paths. That is, they can extract the keys used for file encryption / decryption and export them to malicious applications. However, the first operating environment such as the TEE security environment has the characteristic of hardware isolation. Its memory environment and storage environment are isolated from the conventional operating system. Malicious programs cannot directly extract keys from the first operating environment such as the TEE, and the TEE does not provide any software or hardware export interfaces for plaintext keys, so it is trustworthy and secure. In addition, the third operating environment formed by the second hardware such as the memory medium encryption / decryption engine is also secure, and it does not provide any software or hardware export interfaces for plaintext keys.
[0100] In view of the above characteristics of different operating environments, the processing method provided in the embodiments of the present application not only provides a key generation function in the secure and trustworthy first operating environment, but also provides an encryption / decryption function for the key. On this basis, in response to the encryption / decryption requirements of the data file in the non-secure second operating environment, a ciphertext key (that is, an encrypted key obtained by encrypting the key) rather than a plaintext key is provided to the second operating environment to support the file system in the second operating environment to perform a series of file system-related processes on the key, and before injecting the key into the third operating environment such as the memory medium encryption / decryption engine for encrypting / decrypting the data file in the second operating environment, the encrypted key in ciphertext form is sent back to the first operating environment such as the TEE for decryption, and the plaintext key obtained after decryption, such as the first key, is directly passed by the first operating environment such as the TEE to the secure and trustworthy third operating environment. Thus, the present application avoids exposing the plaintext key in the non-secure second operating environment, and the plaintext key only circulates between secure and trustworthy hardware environments, and the non-secure domain cannot intercept the plaintext key. Therefore, the present application effectively solves the problem of key leakage in the file encryption / decryption scenario of electronic devices, can improve the security of the encryption / decryption key, protect user privacy, and ensure system security.
[0101] In an optional embodiment, if the encryption / decryption request is a decryption request, the processing method provided in the present application may further include the following processing before obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in the second operating environment in response to detecting the decryption request for the first data file:
[0102] 11) If the first key is available in the third operating environment, decrypt the first data file based on the first key;
[0103] 12) If the first key is not available in the third operating environment, trigger the step of obtaining the file system information corresponding to the first data file and the target encryption key for encrypting and decrypting the first data file in the second operating environment.
[0104] In response to detecting a decryption request for the first data file, it can first be determined whether the first key for decrypting the first data file is available in the third operating environment. For example, specifically determine whether the first key is available in the memory medium encryption and decryption engine.
[0105] Among them, if the first key is available in the memory medium encryption and decryption engine, the memory medium encryption and decryption engine can decrypt the first data file based on the first decryption. Conversely, if the first key is not available in the memory medium encryption and decryption engine, the step of obtaining the file system information corresponding to the first data file and the target encryption key for encrypting and decrypting the first data file in the second operating environment, and subsequent related steps 102 - 104 can be triggered to implement the decryption process of the first data file through these processing steps.
[0106] For the decryption request for the first data file, in this embodiment, by first determining whether the first key is available in the third operating environment, and in the case of availability, directly decrypting the first data file based on the first key in the third operating environment, the decryption efficiency of the first data file can be effectively improved and the time consumption can be reduced. And regardless of whether the first key for decrypting the first data is available in the third operating environment, the decryption process of the first data file will not expose the first key to the non - secure domain, thus overcoming the risk of leakage of the file encryption and decryption key, and effectively protecting user privacy and ensuring the security of the system.
[0107] Corresponding to the above - mentioned processing method, an embodiment of the present application further provides a processing device. Refer to Figure 4 the following composition structure diagram. The processing device includes:
[0108] A first acquisition module 401, configured to obtain the file system information corresponding to the first data file and the target encryption key for encrypting and decrypting the first data file in the second operating environment in response to detecting an encryption and decryption request for the first data file; the target encryption key includes the result of encrypting the first key through the first operating environment; the file system information at least includes the file information of the first data file;
[0109] The transmission module 402 is configured to transmit the file system information to the third operating environment and transmit the target encryption key to the first operating environment in the second operating environment, so as to request the first operating environment to decrypt the target encryption key;
[0110] The second acquisition module 403 is configured to obtain the return result of the first operating environment in the third operating environment, and the return result at least includes the first key obtained by decrypting the target encryption key;
[0111] The encryption and decryption module 404 is configured to perform encryption and decryption processing on the first data file corresponding to the file system information using the first key in the third operating environment to obtain a second data file;
[0112] Wherein, the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
[0113] In an optional embodiment, the encryption and decryption request includes an encryption storage request for the first data file or a decryption request for the stored first data file.
[0114] In an optional embodiment, when the first acquisition module 401 obtains the target encryption key in the second operating environment, it is specifically configured to:
[0115] Determine the storage path of the first data file;
[0116] Determine the target encryption key that matches the storage path from multiple encryption keys stored in the second operating environment;
[0117] Wherein, the multiple encryption keys include the results of encrypting multiple keys by the first operating environment respectively.
[0118] In an optional embodiment, the first operating environment is an operating environment provided by a first piece of hardware, the second operating environment is an operating environment provided by system software, and the third operating environment is an operating environment provided by a second piece of hardware.
[0119] In an optional embodiment, the system software includes an operating system kernel, and the operating system kernel includes a file system, a memory medium driver, and a key manager;
[0120] The first acquisition module 401 is specifically configured to: obtain the file system information and the target encryption key corresponding to the first data file in the file system;
[0121] The transmission module 402 is specifically configured to:
[0122] The file system establishes an association between the target encryption key and the file system information, obtains an association result, and transmits the association result to the memory medium drive;
[0123] The memory medium drive transmits the file system information in the association result to the third operating environment, and transmits the target encryption key in the association result to the key manager;
[0124] The key manager transmits the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key.
[0125] In an alternative embodiment, the second hardware includes a memory medium encryption / decryption engine, and the file system information further includes an encryption / decryption method;
[0126] The encryption / decryption module 404 is specifically configured to:
[0127] The memory medium encryption / decryption engine encrypts or decrypts the first data file using the first key through the encryption / decryption method.
[0128] In an alternative embodiment, if the encryption / decryption request is an encryption request, the file system information further includes a storage path to be stored for the first data file;
[0129] The device further includes a storage processing module, configured to store the second data file in the storage location indicated by the storage path to be stored in the third operating environment.
[0130] In an alternative embodiment, the device further includes a determination and control module, configured to: in the case where the encryption / decryption request is a decryption request, determine whether the first key is available in the third operating environment; if the first key is available in the third operating environment, control the decryption of the first data file based on the first key; if the first key is not available in the third operating environment, trigger the process of obtaining the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file in the second operating environment.
[0131] The embodiment of the present application further provides an electronic device. Refer to Figure 5 the composition structure diagram of the shown electronic device. The electronic device includes a first hardware 10 for providing a first operating environment, a system software 20 for providing a second operating environment, and a second hardware 30 for providing a third operating environment; the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
[0132] Among them, the system software is used for:
[0133] In response to detecting an encryption / decryption request for a first data file, obtain the file system information corresponding to the first data file and the target encryption key for encrypting / decrypting the first data file; the target encryption key includes the result of encrypting a first key through a first operating environment; the file system information at least includes the file information of the first data file.
[0134] Transmit the file system information to a third operating environment and transmit the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key.
[0135] The second hardware is used for;
[0136] Obtain the return result of the first operating environment, the return result at least includes the first key obtained by decrypting the target encryption key; use the first key to perform encryption / decryption processing on the first data file corresponding to the file system information to obtain a second data file.
[0137] The system software includes an operating system kernel, and the operating system kernel includes a file system, a memory medium driver, and a key manager. The second hardware includes a memory medium encryption / decryption engine.
[0138] It should be noted that the various embodiments in this specification are all described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.
[0139] For the convenience of description, when describing the above system or device, it is divided into various modules or units according to functions for separate description. Of course, when implementing the present application, the functions of each unit can be realized in the same or multiple software and / or hardware.
[0140] From the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of the present application, in essence, or the part that makes a creative contribution, can be embodied in the form of a software product. The computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in various embodiments or some parts of the embodiments of the present application.
[0141] Finally, it should also be noted that in this text, relational terms such as first, second, third, and fourth are used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprising", "including", or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article, or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the said element.
[0142] The above are only the preferred embodiments of the present application. It should be pointed out that for those of ordinary skill in the art, without departing from the principle of the present application, several improvements and modifications can be made, and these improvements and modifications should also be regarded as the protection scope of the present application.
Claims
1. A processing method comprising: In response to detecting an encryption / decryption request for a first data file, obtaining, in a second operating environment, file system information corresponding to the first data file and a target encryption key for encrypting / decrypting the first data file; the target encryption key includes a result of encrypting the first key by the first operating environment; The file system information at least includes file information of the first data file; transmitting the file system information to a third operating environment in the second operating environment, and transmitting the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key; Obtaining, in the third operating environment, a return result of the first operating environment, wherein the return result at least includes the first key obtained by decrypting the target encryption key; Using the first key in the third operating environment to encrypt and decrypt the first data file corresponding to the file system information to obtain a second data file; Among them, the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
2. The processing method according to claim 1, wherein the encryption / decryption request comprises an encryption / storage request for the first data file, or a decryption request for the stored first data file.
3. The processing method according to claim 1, obtaining the target encryption key in the second operating environment, comprising: Determining a storage path of the first data file; Determining a target encryption key matching the storage path from a plurality of encryption keys stored in the second operating environment; The multiple encryption keys include results of encrypting the multiple keys respectively through the first operating environment.
4. The processing method according to claim 1, wherein the first operating environment is an operating environment provided by first hardware, the second operating environment is an operating environment provided by system software, and the third operating environment is an operating environment provided by second hardware.
5. The processing method according to claim 4, wherein the system software comprises an operating system kernel, and the operating system kernel comprises a file system, a storage medium driver, and a key manager; The obtaining, in the second operating environment, file system information corresponding to the first data file and a target encryption key used for encrypting and decrypting the first data file includes: Obtaining file system information and a target encryption key corresponding to the first data file in the file system; The second operating environment transmits the file system information to the third operating environment, and transmits the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key, including: The file system establishes an association between the target encryption key and the file system information, obtains an association result, and transmits the association result to the storage medium drive; The storage medium driver transmits the file system information in the association result to the third operating environment, and transmits the target encryption key in the association result to the key manager; The key manager transmits the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key.
6. The processing method according to claim 4, wherein the second hardware includes a storage medium encryption and decryption engine, and the file system information further includes an encryption and decryption method; The encrypting and decrypting the first data file using the first key in the third operating environment includes: The storage medium encryption and decryption engine uses the first key to encrypt or decrypt the first data file through the encryption and decryption method.
7. The processing method according to claim 1, if the encryption / decryption request is an encryption request, the file system information also includes a path to be stored of the first data file, and after obtaining the second data file, further comprising: In the third operating environment, the second data file is stored in the storage location indicated by the path to be stored.
8. The processing method according to claim 1, if the encryption / decryption request is a decryption request, before obtaining, in the second operating environment, file system information corresponding to the first data file and a target encryption key for encrypting / decrypting the first data file, further comprising: If the third operating environment has the first key, decrypting the first data file based on the first key; If the third operating environment does not have the first key, the step of obtaining file system information corresponding to the first data file and a target encryption key for encrypting and decrypting the first data file in the second operating environment is triggered.
9. A processing device comprising: A first acquisition module, configured to, in response to detecting an encryption and decryption request for a first data file, obtain, in a second operating environment, file system information corresponding to the first data file and a target encryption key for encrypting and decrypting the first data file; the target encryption key includes a result of encrypting the first key by the first operating environment; The file system information at least includes file information of the first data file; a transmission module, configured to transmit the file system information to a third operating environment in the second operating environment, and transmit the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key; A second acquisition module, configured to obtain a return result of the first operating environment in the third operating environment, wherein the return result at least includes the first key obtained by decrypting the target encryption key; An encryption and decryption module, configured to use the first key to perform encryption and decryption processing on the first data file corresponding to the file system information in the third operating environment to obtain a second data file; Among them, the security of the first operating environment and the third operating environment is higher than the security of the second operating environment.
10. An electronic device, comprising: First hardware for providing a first operating environment, system software for providing a second operating environment, and second hardware for providing a third operating environment; The security of the first operating environment and the third operating environment is higher than the security of the second operating environment; The system software is used for: In response to detecting an encryption / decryption request for a first data file, obtaining file system information corresponding to the first data file and a target encryption key for encrypting / decrypting the first data file; the target encryption key includes a result of encrypting the first key by a first operating environment; the file system information includes at least file information of the first data file; transmitting the file system information to a third operating environment, and transmitting the target encryption key to the first operating environment to request the first operating environment to decrypt the target encryption key; The second hardware is used for: Obtaining a return result of the first operating environment, the return result at least including the first key obtained by decrypting the target encryption key; using the first key to encrypt and decrypt the first data file corresponding to the file system information to obtain a second data file.