Security processing method and device under multiple trusted execution environments and electronic equipment

By setting up multiple isolated trusted execution environments in smart electronic devices, the problem of secure application coupling during key management is solved, and the security of the device is improved.

CN120337196AActive Publication Date: 2025-07-18HONOR DEVICE CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202410033321.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-09
Publication Date
2025-07-18
Estimated Expiration
2044-01-09

AI Technical Summary

Technical Problem

In smart electronic devices, different security applications for key management are prone to coupling when running in the same trusted execution environment, resulting in increased security risks.

Method used

By setting up a plurality of isolated trusted execution environments in the electronic device, different security applications for key management are respectively run, including the first trusted execution environment and the second trusted execution environment, and the request is sent to the corresponding trusted application for processing according to the security level of the request.

Benefits of technology

Reduces the coupling phenomenon of different security applications in the key management process and improves the security of electronic devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337196A_ABST
    Figure CN120337196A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a security processing method and device under multiple trusted execution environments and electronic equipment, in the security processing method under the multiple trusted execution environments, after the electronic equipment obtains a first request of a first CA, the electronic equipment sends the first request to a first TA according to a first security level required by the first request, and the first TA sends the first request to the first CA according to the first security level required by the first request; performing security processing on the first request by the first TA; after the electronic equipment obtains a second request of the first CA, the electronic equipment can send the second request to the second TA through the second TEE according to a second security level required by the second request, the second TA carries out security processing on the second request, and the second security level is higher than the first security level. Since the first TEE and the second TEE are two mutually isolated TEEs, different security applications used for key management in the electronic equipment can be operated in the isolated TEEs respectively, the occurrence of a coupling phenomenon is reduced, and the security of the electronic equipment is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of intelligent terminals, and particularly to a security processing method, apparatus, and electronic device in a multi-trusted execution environment. Background Art

[0002] Currently, with the development of communication technologies, intelligent electronic devices are increasingly widely used. To protect user privacy and information security, intelligent electronic devices (such as smartphones and / or tablet computers, etc.) usually include a rich execution environment (REE) and a trusted execution environment (TEE). Among them, the REE is also called a normal execution environment and includes a rich execution environment operating system (REE OS) and client applications (CAs) running on a general-purpose processor. The TEE is also called a secure execution environment and can run a trusted execution environment operating system (TEE OS) to provide reliable security services (such as fingerprint comparison services, password verification services, and / or face comparison services, etc.) for the CAs. These security services can run on the TEE OS in the form of trusted applications (TAs). Summary of the Invention

[0003] The embodiments of the present application provide a security processing method, apparatus, and electronic device in a multi-trusted execution environment. The embodiments of the present application also provide a computer-readable storage medium to implement running different security applications for key management in an isolated trusted execution environment in the electronic device, reducing the coupling phenomenon that occurs when different security applications for key management run in the same trusted execution environment, and improving the security of the electronic device.

[0004] In a first aspect, an embodiment of the present application provides a security processing method in a multi-trusted execution environment, which is applied to an electronic device. The electronic device includes: a rich execution environment, a first trusted execution environment, a second trusted execution environment, and a security element; the rich execution environment includes: a first client application; the first trusted execution environment includes: a first trusted application for key management; the security element includes a second trusted application for key management; the method includes: obtaining a first request of the first client application; according to the first security level required by the first request, sending the first request to the first trusted application, and the first trusted application performs security processing on the first request; obtaining a second request of the first client application; according to the second security level required by the second request, sending the second request to the second trusted application through the second trusted execution environment, and the second trusted application performs security processing on the second request; wherein, the second security level is higher than the first security level.

[0005] In the above security processing method in a multi-trusted execution environment, after the electronic device obtains the first request of the first CA, according to the first security level required by the first request, the first request is sent to the first TA, and the first TA performs security processing on the first request; after the electronic device obtains the second request of the first CA, the electronic device can, according to the second security level required by the second request, send the second request to the second TA through the second TEE, and the second TA performs security processing on the second request, wherein, the second security level is higher than the first security level. Since the first TA runs in the first TEE, and the first TEE and the second TEE are two isolated TEEs, it is possible to implement running different security applications for key management in the electronic device in isolated TEEs respectively, reducing the coupling phenomenon that occurs when different TAs for key management run in the same TEE, and improving the security of the electronic device.

[0006] In one possible implementation, the first request may include a first key generation request; the rich execution environment may further include: a second client application for key management, a third client application for key service, and a fourth client application for key service; thus, obtaining the first request of the first client application in the rich execution environment may be: the second client application obtains the first key generation request of the first client application; according to the first security level required by the first request, sending the first request to the first trusted application, and the first trusted application performs security processing on the first request may be: the second client application sends the first key generation request to the third client application according to the first security level required by the first key generation request; the third client application sends the first key generation request to the first trusted application; the first trusted application generates a first key according to the first key generation request and sends the first key to the third client application.

[0007] In one possible implementation, after the first trusted application generates a first key according to a first key generation request and sends the first key to the third client application, the third client application may send the first key to the second client application; the second client application saves the first key and sends the identifier of the first key to the first client application.

[0008] In one possible implementation, after the second client application saves the first key and sends the identifier of the first key to the first client application, the second client application may obtain a first data encryption request of the first client application; wherein, the first data encryption request carries the first data to be encrypted and the identifier of the first key; the second client application obtains the first key according to the identifier of the first key, and according to the first security level required by the first data encryption request, sends the first key and the first data to the third client application; the third client application sends the first key and the first data to the first trusted application; the first trusted application encrypts the first data with the first key and sends the encrypted first data to the third client application; the third client application sends the encrypted first data to the second client application; the second client application sends the encrypted first data to the first client application.

[0009] In one possible implementation, the second request may include a second key generation request; the first trusted execution environment further includes: a fourth trusted application for trusted communication; the rich execution environment further includes: a second client application for key management, a third client application for key service, and a fourth client application for key service; thus, obtaining the second request of the first client application may be: the second client application obtains the second key generation request of the first client application; according to the second security level required by the second request, sending the second request to the second trusted application through the second trusted execution environment, and the security processing of the second request by the second trusted application may be: the second client application sends the second key generation request to the fourth client application according to the second security level required by the second key generation request; the fourth client application sends the second key generation request to the fourth trusted application; the fourth trusted application establishes a trusted connection with the second trusted execution environment and sends the second key generation request to the second trusted application through the trusted connection; the second trusted application generates a second key according to the second key generation request and sends the second key to the fourth trusted application through the trusted connection.

[0010] In one possible implementation, the second trusted application generates a second key according to a second key generation request, and after sending the second key to the fourth trusted application through the above-mentioned trusted connection, the fourth trusted application sends the second key to the fourth client application; the fourth client application sends the second key to the above-mentioned second client application; the second client application saves the above-mentioned second key and sends the identifier of the above-mentioned second key to the first client application.

[0011] In one possible implementation, after the second client application saves the above-mentioned second key and sends the identifier of the second key to the above-mentioned first client application, the second client application can obtain the second data encryption request of the above-mentioned first client application; wherein, the above-mentioned second data encryption request carries the second data to be encrypted and the identifier of the above-mentioned second key; the second client application obtains the above-mentioned second key according to the identifier of the above-mentioned second key, and according to the second security level required by the second data encryption request, sends the second key and the second data to the fourth client application; the fourth client application sends the above-mentioned second key and the above-mentioned second data to the fourth trusted application; the fourth trusted application sends the second key and the second data to the second trusted application through a trusted connection with the second trusted execution environment; the second trusted application encrypts the second data by using the above-mentioned second key and sends the encrypted second data to the fourth trusted application through the above-mentioned trusted connection, and the fourth trusted application sends the encrypted second data to the fourth client application; the fourth client application sends the encrypted second data to the second client application; the second client application sends the encrypted second data to the first client application.

[0012] In one possible implementation, the first trusted execution environment is implemented based on the processor of the electronic device, and the above-mentioned second trusted execution environment is implemented based on the virtual machine in the above-mentioned electronic device; the first trusted execution environment and the second trusted execution environment are two mutually isolated trusted execution environments.

[0013] In the above implementation, the first TA and the fourth TA run in the first TEE. The fourth TA does not directly access the second TA, but first establishes a trusted connection with the second TEE and accesses the second TA through this trusted connection. Since the first TEE and the second TEE are two mutually isolated TEEs, the occurrence of coupling phenomena can be reduced and the security of the electronic device can be improved.

[0014] In a second aspect, an embodiment of the present application provides a security processing device in a multi-trusted execution environment. The device is included in an electronic device and has the function of implementing the behavior of the electronic device in the first aspect and the possible implementation manners of the first aspect. The function can be implemented by hardware or by hardware executing corresponding software. The hardware or software includes one or more modules or units corresponding to the above functions. For example, a receiving unit, a processing module, a sending module, etc.

[0015] In a third aspect, an embodiment of the present application provides an electronic device, including: one or more processors; a memory; multiple application programs; and one or more computer programs. Wherein the one or more computer programs are stored in the memory, and the one or more computer programs include instructions that, when executed by the electronic device, cause the electronic device to execute the method provided in the first aspect.

[0016] It should be understood that the technical solutions of the second aspect and the third aspect of the embodiments of the present application are consistent with those of the first aspect of the embodiments of the present application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar, and will not be elaborated here.

[0017] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When it runs on a computer, it causes the computer to execute the method provided in the first aspect.

[0018] In a fifth aspect, an embodiment of the present application provides a computer program that, when executed by a computer, is used to execute the method provided in the first aspect.

[0019] In a possible design, the program in the fifth aspect can be stored in whole or in part on a storage medium packaged together with the processor, or can be stored in whole or in part on a memory not packaged together with the processor. Description of the Drawings

[0020] Figure 1 Schematic diagram of the key management process in the electronic device provided by the related art;

[0021] Figure 2 Schematic diagram of the structure of the electronic device provided by an embodiment of the present application;

[0022] Figure 3 Software structure block diagram of the electronic device provided by an embodiment of the present application;

[0023] Figure 4 Schematic diagram of the ARM architecture provided by an embodiment of the present application;

[0024] Figure 5Schematic diagram of the ARM architecture provided by another embodiment of the present application;

[0025] Figure 6 Flowchart of the security processing method in a multi-trusted execution environment provided by an embodiment of the present application;

[0026] Figure 7 Schematic diagram of the implementation of the security processing method in a multi-trusted execution environment provided by an embodiment of the present application;

[0027] Figure 8 Schematic diagram of the ARM architecture provided by still another embodiment of the present application;

[0028] Figure 9 Schematic diagram of the implementation of the security processing method in a multi-trusted execution environment provided by another embodiment of the present application;

[0029] Figure 10 Schematic diagram of the structure of an electronic device provided by another embodiment of the present application. Detailed implementation manners

[0030] The terms used in the implementation part of the present application are only for explaining the specific embodiments of the present application, rather than aiming to limit the present application.

[0031] Figure 1 Schematic diagram of the key management process in an electronic device provided for the related art, as Figure 1 shown, the REE includes a first CA, a second CA for key management, a third CA for key service, and a fourth CA for key service; the TEE includes a first TA for key management and a third TA for proxy service, and the embedded secure element (eSE) of the electronic device includes a second TA for key management.

[0032] Among them, the first CA can be a common client application installed in the electronic device, such as: instant messaging applications, map applications, bank applications, or music playback applications, etc. When the first CA needs to use a key, the first CA can access the first TA in the TEE through the third CA for key service in the REE; or, the first CA can first access the third TA in the TEE through the fourth CA for key service in the REE, and then the third TA accesses the second TA in the eSE through the driver in the TEE. And since the third TA and the driver required to access the second TA both run in the TEE with the first TA, there may be a phenomenon of coupling between the third TA and the driver and the first TA, resulting in certain security risks.

[0033] Based on the above problems, the embodiments of the present application provide a security processing method in a multi-trusted execution environment, which can implement running different security applications for key management in the electronic device in isolated trusted execution environments respectively, reduce the coupling phenomenon that occurs when different security applications for key management run in the same trusted execution environment, and improve the security of the electronic device.

[0034] The security processing method in a multi-trusted execution environment provided by the embodiments of the present application can be applied to an electronic device. Among them, the above-mentioned electronic device can be a smart phone, a tablet computer, a wearable device, a vehicle-mounted device, an augmented reality (AR) / virtual reality (VR) device, a laptop computer, an ultra-mobile personal computer (UMPC), a netbook or a personal digital assistant (PDA), etc.; the embodiments of the present application do not impose any restrictions on the specific type of the electronic device.

[0035] Exemplarily, Figure 2 is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 2 shown, the electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, a sensor module 180, a key 190, a motor 191, an indicator 192, a camera 193, a display screen 194, and a subscriber identification module (SIM) card interface 195, etc. Among them, the sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0036] It can be understood that the structure illustrated in the embodiments of the present application does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than those illustrated, or combine certain components, or split certain components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0037] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.

[0038] The controller may generate operation control signals according to the instruction operation code and timing signals to complete the control of fetching and executing instructions.

[0039] A memory may also be provided in the processor 110 for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory may store the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can be directly called from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system.

[0040] The USB interface 130 is an interface that complies with the USB standard specification. Specifically, it may be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface 130 can be used to connect a charger to charge the electronic device 100, and can also be used for data transmission between the electronic device 100 and peripheral devices. It can also be used to connect headphones to play audio through the headphones. This interface can also be used to connect other electronic devices, such as AR devices, etc.

[0041] It can be understood that the interface connection relationships between the modules illustrated in the embodiments of the present application are only illustrative and do not constitute a structural limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may also adopt different interface connection methods or a combination of multiple interface connection methods in the above embodiments.

[0042] The charging management module 140 is configured to receive a charging input from a charger. Herein, the charger may be a wireless charger or a wired charger. In some embodiments of wired charging, the charging management module 140 may receive the charging input from a wired charger through the USB interface 130. In some embodiments of wireless charging, the charging management module 140 may receive the wireless charging input through the wireless charging coil of the electronic device 100. While charging the battery 142, the charging management module 140 may also supply power to the electronic device 100 through the power management module 141.

[0043] The power management module 141 is used to connect the battery 142, the charging management module 140, and the processor 110. The power management module 141 receives the inputs from the battery 142 and / or the charging management module 140, and supplies power to the processor 110, the internal memory 121, the display screen 194, the camera 193, the wireless communication module 160, etc. The power management module 141 may also be used to monitor parameters such as the battery capacity, the number of battery cycles, and the battery health status (leakage, impedance). In some other embodiments, the power management module 141 may also be disposed in the processor 110. In some other embodiments, the power management module 141 and the charging management module 140 may also be disposed in the same device.

[0044] The wireless communication function of the electronic device 100 may be implemented by the antenna 1, the antenna 2, the mobile communication module 150, the wireless communication module 160, the modulation and demodulation processor, and the baseband processor, etc.

[0045] The antenna 1 and the antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the electronic device 100 may be used to cover a single or multiple communication frequency bands. Different antennas may also be multiplexed to improve the utilization rate of the antennas. For example: the antenna 1 may be multiplexed as the diversity antenna of the wireless local area network. In some other embodiments, the antenna may be used in combination with a tuning switch.

[0046] The mobile communication module 150 may provide a solution for wireless communication including 2G / 3G / 4G / 5G, etc., which is applied to the electronic device 100. The mobile communication module 150 may include at least one filter, switch, power amplifier, low noise amplifier (LNA), etc. The mobile communication module 150 may receive electromagnetic waves through the antenna 1, filter, amplify, etc. the received electromagnetic waves, and transmit them to the modulation and demodulation processor for demodulation. The mobile communication module 150 may also amplify the signal modulated by the modulation and demodulation processor and convert it into electromagnetic waves through the antenna 1 for radiation. In some embodiments, at least some functional modules of the mobile communication module 150 may be provided in the processor 110. In some embodiments, at least some functional modules of the mobile communication module 150 and at least some modules of the processor 110 may be provided in the same device.

[0047] The modulation and demodulation processor may include a modulator and a demodulator. Among them, the modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. Subsequently, the demodulator transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is transmitted to the application processor. The application processor outputs a sound signal through an audio device (not limited to the speaker 170A, receiver 170B, etc.), or displays an image or video through the display screen 194. In some embodiments, the modulation and demodulation processor may be an independent device. In other embodiments, the modulation and demodulation processor may be independent of the processor 110 and be provided in the same device as the mobile communication module 150 or other functional modules.

[0048] The wireless communication module 160 may provide solutions for wireless communications applied to the electronic device 100, including wireless local area networks (WLANs) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite systems (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc. The wireless communication module 160 may be one or more devices integrating at least one communication processing module. The wireless communication module 160 receives electromagnetic waves via the antenna 2, performs frequency modulation and filtering processing on the electromagnetic wave signals, and sends the processed signals to the processor 110. The wireless communication module 160 may also receive signals to be sent from the processor 110, perform frequency modulation and amplification on them, and convert them into electromagnetic waves through the antenna 2 for radiation.

[0049] In some embodiments, antenna 1 of electronic device 100 is coupled to mobile communication module 150, and antenna 2 is coupled to wireless communication module 160, such that electronic device 100 can communicate with a network and other devices through wireless communication technologies. The wireless communication technologies may include global system for mobile communications (GSM), general packet radio service (GPRS), code division multiple access (CDMA), wideband code division multiple access (WCDMA), time-division code division multiple access (TD-SCDMA), long term evolution (LTE), BT, GNSS, WLAN, NFC, FM, and / or IR technologies, etc. The GNSS may include global positioning system (GPS), global navigation satellite system (GLONASS), beidou navigation satellite system (BDS), quasi-zenith satellite system (QZSS), and / or satellite based augmentation systems (SBAS).

[0050] Electronic device 100 implements a display function through a GPU, display screen 194, and an application processor, etc. The GPU is a microprocessor for image processing, and is connected to display screen 194 and the application processor. The GPU is used to perform mathematical and geometric calculations for graphics rendering. Processor 110 may include one or more GPUs, which execute program instructions to generate or change display information.

[0051] The display screen 194 is used to display images, videos, etc. The display screen 194 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a Miniled, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the electronic device 100 may include one or N display screens 194, where N is a positive integer greater than 1.

[0052] The electronic device 100 can implement the shooting function through the ISP, the camera 193, the video codec, the GPU, the display screen 194, and the application processor, etc.

[0053] The ISP is used to process the data fed back by the camera 193. For example, when taking a photo, the shutter is opened, and the light passes through the lens and is transmitted to the camera photosensitive element. The light signal is converted into an electrical signal, and the camera photosensitive element transmits the electrical signal to the ISP for processing and converts it into an image visible to the naked eye. The ISP can also perform algorithm optimization on the noise, brightness, and skin color of the image. The ISP can also optimize parameters such as the exposure and color temperature of the shooting scene. In some embodiments, the ISP can be set in the camera 193.

[0054] The camera 193 is used to capture static images or videos. The object generates an optical image through the lens and projects it onto the photosensitive element. The photosensitive element can be a charge-coupled device (CCD) or a complementary metal-oxide-semiconductor (CMOS) phototransistor. The photosensitive element converts the light signal into an electrical signal, and then transmits the electrical signal to the ISP to convert it into a digital image signal. The ISP outputs the digital image signal to the DSP for processing. The DSP converts the digital image signal into an image signal in a standard RGB, YUV, etc. format. In some embodiments, the electronic device 100 may include one or N cameras 193, where N is a positive integer greater than 1.

[0055] The digital signal processor is used to process digital signals. In addition to processing digital image signals, it can also process other digital signals. For example, when the electronic device 100 selects a frequency point, the digital signal processor is used to perform Fourier transform on the frequency point energy, etc.

[0056] The video codec is used to compress or decompress digital videos. The electronic device 100 can support one or more video codecs. In this way, the electronic device 100 can play or record videos in multiple coding formats, such as: Moving Picture Experts Group (MPEG) 1, MPEG2, MPEG3, MPEG4, etc.

[0057] The NPU is a neural-network (NN) computing processor. By learning from the biological neural network structure, such as learning from the transmission pattern between human brain neurons, it can quickly process the input information and can also continuously self-learn. Through the NPU, applications such as intelligent cognition of the electronic device 100 can be realized, such as: image recognition, face recognition, speech recognition, text understanding, etc.

[0058] The external memory interface 120 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the electronic device 100. The external memory card communicates with the processor 110 through the external memory interface 120 to implement the data storage function. For example, files such as music and videos are saved in the external memory card.

[0059] The internal memory 121 can be used to store computer-executable program code, and the executable program code includes instructions. The internal memory 121 can include a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, image playback function, etc.). The data storage area can store data created during the use of the electronic device 100 (such as audio data, phone book, etc.). In addition, the internal memory 121 can include high-speed random access memory and can also include non-volatile memory, such as at least one disk storage device, flash memory device, universal flash storage (UFS), etc. The processor 110 executes various functional applications and data processing of the electronic device 100 by running the instructions stored in the internal memory 121 and / or the instructions stored in the memory provided in the processor.

[0060] The electronic device 100 can implement audio functions through the audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, and the application processor, etc. For example, music playback, recording, etc.

[0061] The audio module 170 is used to convert digital audio information into an analog audio signal for output, and is also used to convert an analog audio input into a digital audio signal. The audio module 170 can also be used for encoding and decoding audio signals. In some embodiments, the audio module 170 can be disposed in the processor 110, or some functional modules of the audio module 170 can be disposed in the processor 110.

[0062] The speaker 170A, also known as the "loudspeaker", is used to convert an audio electrical signal into a sound signal. The electronic device 100 can listen to music or hands-free calls through the speaker 170A.

[0063] The receiver 170B, also known as the "earpiece", is used to convert an audio electrical signal into a sound signal. When the electronic device 100 answers a call or a voice message, the user can listen to the voice by bringing the receiver 170B close to the ear.

[0064] The microphone 170C, also known as the "microphone" or "transmitter", is used to convert a sound signal into an electrical signal. When making a call or sending a voice message, the user can speak by bringing the mouth close to the microphone 170C to input the sound signal into the microphone 170C. The electronic device 100 can be provided with at least one microphone 170C. In some other embodiments, the electronic device 100 can be provided with two microphones 170C, which can not only collect sound signals but also implement a noise reduction function. In some other embodiments, the electronic device 100 can also be provided with three, four or more microphones 170C to implement functions such as collecting sound signals, noise reduction, identifying the sound source, and implementing a directional recording function.

[0065] The headphone jack 170D is used to connect a wired headphone. The headphone jack 170D can be a USB interface 130, or a 3.5mm open mobile terminal platform (OMTP) standard interface, or a cellular telecommunications industry association of the USA (CTIA) standard interface.

[0066] The keys 190 include a power-on key, volume keys, etc. The keys 190 can be mechanical keys or touch keys. The electronic device 100 can receive key inputs to generate key signal inputs related to the user settings and function controls of the electronic device 100.

[0067] The motor 191 can generate vibration prompts. The motor 191 can be used for incoming call vibration prompts and also for touch vibration feedback. For example, touch operations applied to different applications (such as taking pictures, playing audio, etc.) can correspond to different vibration feedback effects. For touch operations applied to different regions of the display screen 194, the motor 191 can also correspond to different vibration feedback effects. Different application scenarios (such as time reminder, receiving messages, alarm clock, games, etc.) can also correspond to different vibration feedback effects. The touch vibration feedback effect can also support customization.

[0068] The indicator 192 can be an indicator light and can be used to indicate the charging state, power change, and can also be used to indicate messages, missed calls, notifications, etc.

[0069] The SIM card interface 195 is used to connect the SIM card. The SIM card can be inserted into or removed from the SIM card interface 195 to achieve contact and separation from the electronic device 100. The electronic device 100 can support 1 or N SIM card interfaces, where N is a positive integer greater than 1. The SIM card interface 195 can support Nano SIM cards, Micro SIM cards, SIM cards, etc. Multiple cards can be inserted into the same SIM card interface 195 at the same time. The types of the multiple cards can be the same or different. The SIM card interface 195 can also be compatible with different types of SIM cards. The SIM card interface 195 can also be compatible with external memory cards. The electronic device 100 interacts with the network through the SIM card to implement functions such as calls and data communication. In some embodiments, the electronic device 100 uses an eSIM, that is, an embedded SIM card. The eSIM card can be embedded in the electronic device 100 and cannot be separated from the electronic device 100.

[0070] The software composition of the above electronic device can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservices architecture, or a cloud architecture. Here, the software structure of the electronic device is described by taking the layered architecture as an example.

[0071] Figure 3This is a software structure block diagram of an electronic device provided by an embodiment of the present application. The layered architecture divides the software system into several layers, and each layer has a clear role and division of labor. Communication between layers is achieved through software interfaces. In some embodiments, the software system can be divided into four layers, from top to bottom: the application layer (applications), the application framework layer (application framework), the system layer, and the kernel layer (kernel). It should be understood that the execution environment in the electronic device 100 includes REE and TEE, and applications and operating systems (Operating System, OS) can run independently under TEE and REE. At the same time, in each layer of the software structure, there are software components that can run in TEE and REE respectively, which will be described one by one below:

[0072] The application layer may include a series of applications. According to the execution environment, these applications can be divided into ordinary applications (REE APP) and trusted applications (trusted application, TA). Among them, REE APP is an APP that runs under REE, such as APPs for calendar, memo, map, navigation, video, payment, or chat, etc.; REE APP can also be referred to as CA. TA is an APP that runs under TEE. Compared with REE, TEE can provide a more secure space for the execution of data and code and ensure their confidentiality and integrity. Therefore, TEE can be used to run APPs with higher security requirements.

[0073] It should be noted that TA can be an independent APP, for example: a wallet application. Or, TA can also not be an independent APP, but be embedded in the REE APP to implement a certain function in the REE APP. For example, if the REE APP is a banking APP, the transfer function in the banking APP needs to be implemented by the banking service TA. That is to say, when the banking APP is running and the transfer function is triggered to enter, the banking service TA will be triggered to run. Obviously, the banking service TA can be understood as an APP embedded in the REE APP.

[0074] The application framework layer provides application programming interfaces (application programming interface, API) and programming frameworks for the applications in the application layer. Exemplarily, the application framework layer includes various services that support the running of applications, such as: Bluetooth service and / or camera service, etc. Similarly, according to the execution environment, the application framework layer includes services that support the running of REE APP and services that support the running of TA.

[0075] The system layer may include an OS running under the REE (which can be denoted as the general operating system REE OS), such as systems like Android, iOS, Linux, etc., and an OS running under the TEE (which can be denoted as the trusted operating system TEE OS). It should be understood that the OS may include system libraries, such as media libraries, 3D graphics processing libraries (e.g., OpenGLES), etc. The media library supports the playback and recording of various common audio and video formats, as well as static image files, etc. The media library can support various audio and video coding formats, such as JPG, PNG, etc. The 3D graphics processing library is used to implement 3D graphics drawing, image rendering, composition, and layer processing, etc.

[0076] The kernel layer is the layer between hardware and software. The kernel layer may include hardware drivers such as display drivers, touch screen drivers, camera drivers, audio drivers, sensor drivers, Bluetooth drivers, etc., which are used to drive the hardware to work. Similarly, corresponding to the two execution environments, the above hardware drivers can also be divided into two types.

[0077] Furthermore, the processor of the electronic device 100 generally can adopt the advanced RISC machine (ARM) architecture. Since the instruction set used by ARM is the reduced instruction set computing (RISC), complex instructions are avoided, mainly with logical control, and microcode control is used less or not at all. Thus, the system on chip (SOC) can be small in size and low in power consumption, which is very suitable for small electronic devices.

[0078] Figure 4 Schematic diagram of the ARM architecture provided for an embodiment of this application, as Figure 4 shown, the ARM architecture may include 4 exception levels (EL), from EL0 to EL3. For ELn (n is an integer greater than or equal to 0), the larger n is, the greater the privilege level of software execution. The execution at the EL0 level is called unprivileged execution. And, the larger n is, the higher the usage permission for the resources in the electronic device 100 is.

[0079] In EL0, applications in the application layer, such as REE APP and TA, are running, and various services provided in the application framework layer to support the running of applications, such as general application services and security application services, are also running. In EL1, the OS in the system layer, such as REE OS and TEE OS, is running, and hardware drivers in the kernel layer, such as general application drivers and security application drivers, are also running. In EL2, the virtual machine monitor (Hypervisor) is running. The Hypervisor can create virtual machines, and each virtual machine has an independent operating system (i.e., the OS running in each virtual machine), and can run APPs independently, save data, etc. EL3 supports the conversion between the secure state and the non-secure state. For example, the Secure Monitor is running in EL3.

[0080] Figure 5 Schematic diagram of the ARM architecture provided for another embodiment of the present application, as Figure 5 shown, the electronic device 100 includes REE and also includes two TEEs, which can be respectively called the first TEE and the second TEE. Among them, the first TEE can be implemented based on the processor 110 of the electronic device 100. ARM integrates the TrustZone technology with the Coretex-A processor to provide a platform that can support the first TEE and security-aware applications and security services. The first TEE, as a trusted execution environment in the electronic device 100, can provide trusted applications for the REE side.

[0081] The second TEE can be implemented based on a virtual machine (i.e., the virtual machine monitor in the EL2 layer of the ARM framework). The second TEE, as another trusted execution environment in the electronic device 100, can provide trusted applications for the REE side. It should be noted that in the embodiments of the present application, the second TEE and the first TEE are two mutually isolated trusted execution environments.

[0082] For ease of understanding, the following embodiments of the present application will use an electronic device with the Figures 2 to 5 shown structure, in combination with the accompanying drawings and application scenarios, to specifically elaborate on the security processing method under multiple trusted execution environments provided by the embodiments of the present application.

[0083] Figure 6 Flowchart of the security processing method under multiple trusted execution environments provided for an embodiment of the present application. This security processing method can be applied to the electronic device 100. Refer to Figure 5, the electronic device 100 may include: REE, a first TEE, a second TEE, and a secure element (eSE); among them, the above REE may include: a first CA; the first TEE may include: a first TA for key management; the second TEE may include: a third TA for proxy services. In addition, the above secure element includes a second TA for key management. It should be noted that the secure element (eSE) is not shown in Figure 5 is not shown.

[0084] As Figure 6 shown, the above security processing method in a multi-trusted execution environment may include:

[0085] Step 601, the electronic device 100 obtains a first request from the first CA.

[0086] Step 602, the electronic device 100 sends the first request to the first TA according to the first security level required by the first request, and the first TA performs security processing on the first request.

[0087] Step 603, the electronic device 100 obtains a second request from the first CA.

[0088] Step 604, the electronic device 100 sends the second request to the second TA through the second TEE according to the second security level required by the second request, and the second TA performs security processing on the second request. Among them, the second security level is higher than the first security level.

[0089] Among them, steps 601 to 602 and steps 603 to 604 may be executed successively or in parallel. This embodiment does not limit the execution order of steps 601 to 602 and steps 603 to 604, but Figure 6 is shown by taking steps 601 to 602 being executed before steps 603 to 604 as an example.

[0090] It should be noted that the first security level and the second security level in this embodiment do not mean that there can only be two security levels for requests in the electronic device 100. The first security level may represent a category of security levels, and the second security level may also represent a category of security levels. It's just that the security level represented by the first security level is lower than the security level represented by the second security level.

[0091] In the above security processing method in a multi-trusted execution environment, after the electronic device 100 obtains a first request from a first CA, according to the first security level required by the first request, the first request is sent to a first TA, and the first TA performs security processing on the first request; after the electronic device 100 obtains a second request from the first CA, the electronic device 100 may, according to the second security level required by the second request, send the second request to a second TA through a second TEE, and the second TA performs security processing on the second request, where the second security level is higher than the first security level. Since the first TA runs in a first TEE, and the first TEE and the second TEE are two mutually isolated TEEs, different security applications for key management in the electronic device 100 can be run in isolated TEEs respectively, reducing the coupling phenomenon that occurs when different TAs for key management run in the same TEE, and improving the security of the electronic device 100.

[0092] Figure 7 FIG. is a schematic diagram of the implementation of the security processing method in a multi-trusted execution environment provided by an embodiment of the present application. As Figure 7 shown, the REE may further include: a second CA for key management, a third CA for key service, and a fourth CA for key service.

[0093] In some examples, the first request may be a first key generation request. In this way, step 601 may be: the second CA obtains a first key generation request from the first CA; step 602 may be: the second CA, according to the first security level required by the first key generation request, sends the first key generation request to the third CA, and the third CA sends the first key generation request to the first TA, and the first TA generates a first key according to the first key generation request and sends the first key to the third CA. Specifically, when the first CA generates the first key generation request, it will determine to use the first TA to process the first key generation request according to the first security level required by the first key generation request. Thus, the first CA may carry an identifier processed by the first TA in the first key generation request. After the second CA obtains the first key generation request, it may determine that the first TA is to process the first key generation request according to the identifier carried in the first key generation request. Then, the second CA sends the first key generation request to the third CA, and the third CA sends the first key generation request to the first TA.

[0094] Further, after the first TA generates a first key according to the first key generation request and sends the first key to the third CA, the third CA sends the first key to the second CA, and the second CA saves the first key and sends an identifier of the first key to the first CA.

[0095] Further, after the second CA saves the first key and sends the identifier of the first key to the first CA, the second CA may also obtain a first data encryption request from the first CA; wherein, the first data encryption request carries the first data to be encrypted and the identifier of the first key; then, the second CA obtains the first key according to the identifier of the first key, and according to the first security level required by the first data encryption request, sends the first key and the first data to the third CA; the third CA sends the first key and the first data to the first TA; the first TA encrypts the first data with the first key and sends the encrypted first data to the third CA; the third CA sends the encrypted first data to the second CA; the second CA sends the encrypted first data to the first CA.

[0096] For example, in the above embodiment, the first CA may be a wallet application. When a user first uses the "open the door" function in the wallet application, the wallet application needs to generate a key. When generating the first key generation request, the wallet application determines that the security level required for the "open the door" function is relatively low. Therefore, the wallet application determines that the first TA processes the first key generation request according to the first security level required for the "open the door" function, so that the wallet application can carry the identifier processed by the first TA in the first key generation request. After the second CA obtains the first key generation request, it can determine that the first TA processes the first key generation request according to the identifier carried in the first key generation request. Then, the second CA sends the first key generation request to the third CA, and the third CA sends the first key generation request to the first TA. The first TA generates a first key for the "open the door" function according to the first key generation request and sends the first key to the third CA. The third CA sends the first key to the second CA, the second CA saves the first key, and sends the identifier of the first key to the first CA.

[0097] When the user subsequently uses the "open the door" function in the wallet application, the wallet application needs to encrypt the first data to be sent. Similarly, when generating the first data encryption request, the wallet application determines that the security level required for the "open the door" function is relatively low. Therefore, the wallet application determines that the first TA processes the first data encryption request according to the first security level required for the "open the door" function, so that the wallet application can carry the identifier processed by the first TA in the first data encryption request.

[0098] After the second CA obtains the first data encryption request of the wallet application, it can determine that the first TA processes the first key generation request according to the identifier carried in the first data encryption request. After the second CA obtains the first key according to the identifier of the first key, it sends the first key and the first data to the third CA; the third CA sends the first key and the first data to the first TA; the first TA encrypts the first data with the first key and sends the encrypted first data to the third CA; the third CA sends the encrypted first data to the second CA; the second CA sends the encrypted first data to the wallet application.

[0099] In some examples, the second request may be a second key generation request; in this way, step 603 may be: the second CA obtains the second key generation request of the first CA; step 604 may be: the second CA sends the second key generation request to the fourth CA according to the second security level required by the second key generation request, and the fourth CA sends the second key generation request to the second TA through the third TA. The second TA generates the second key according to the second key generation request and sends the second key to the fourth CA through the third TA. Specifically, when the first CA generates the second key generation request, it will determine to use the second TA to process the second key generation request according to the second security level required by the second key generation request, so that the first CA can carry the identifier processed by the second TA in the second key generation request. After the second CA obtains the second key generation request, it can determine that the second TA processes the second key generation request according to the identifier carried in the second key generation request. Therefore, the second CA sends the second key generation request to the fourth CA, and the fourth CA sends the second key generation request to the second TA through the third TA.

[0100] Further, after the second TA generates the second key according to the second key generation request and sends the second key to the fourth CA through the third TA, the fourth CA may also send the second key to the second CA. The second CA saves the second key and sends the identifier of the second key to the first CA.

[0101] Further, after saving the second key in the second CA and sending the identifier of the second key to the first CA, the second CA can also obtain a second data encryption request from the first CA; wherein, the second data encryption request carries the second data to be encrypted and the identifier of the second key; then, the second CA obtains the second key according to the identifier of the second key, and according to the second security level required by the second data encryption request, sends the second key and the second data to the fourth CA; the fourth CA sends the second key and the second data to the second TA through the third TA; the second TA encrypts the second data with the second key, sends the encrypted second data to the fourth CA through the third TA, the fourth CA sends the encrypted second data to the second CA, and the second CA sends the encrypted second data to the first CA.

[0102] In addition, it should be noted that in the above example, the third TA implements a proxy service, and can establish a secure connection with the second TA through the secure application driver in the second TEE, so as to realize the interaction between the fourth CA and the second TA.

[0103] Still taking the first CA as the wallet application as an example, when the user first uses the "payment" function in the wallet application, the wallet application needs to generate a key. When generating the second key generation request, the wallet application determines that the security level required by the "payment" function is relatively high. Therefore, the wallet application determines that the second TA processes the second key generation request according to the second security level required by the "payment" function, so that the wallet application can carry the identifier processed by the second TA in the second key generation request. After obtaining the above second key generation request, the second CA can determine that the second TA processes the second key generation request according to the identifier carried in the second key generation request. Then, the second CA sends the above second key generation request to the fourth CA, and the fourth CA sends the above second key generation request to the second TA through the third TA. The second TA generates a second key for the "payment" function according to the second key generation request, and sends the second key to the fourth CA through the third TA. The fourth CA sends the second key to the second CA, the second CA saves the second key, and sends the identifier of the second key to the first CA.

[0104] When the user subsequently uses the "payment" function in the wallet application, the wallet application needs to encrypt the second data to be sent. Similarly, when generating the second data encryption request, the wallet application determines that the security level required by the "payment" function is relatively high. Therefore, the wallet application determines that the second TA processes the second data encryption request according to the second security level required by the "payment" function, so that the wallet application can carry the identifier processed by the second TA in the second data encryption request.

[0105] After the second CA obtains the second data encryption request of the wallet application, it can determine that the second TA processes the second data encryption request according to the identifier carried in the second data encryption request. After the second CA obtains the second key according to the identifier of the second key, it sends the second key and the second data to the fourth CA; the fourth CA sends the second key and the second data to the second TA through the third TA; the second TA encrypts the second data with the second key and sends the encrypted second data to the fourth CA through the third TA; the fourth CA sends the encrypted second data to the second CA; the second CA sends the encrypted second data to the wallet application.

[0106] In this embodiment, the first TA runs in the first TEE, the third TA and the security application driver run in the second TEE, and the first TEE and the second TEE are two mutually isolated TEEs. Thus, different security applications for key management in the electronic device 100 can be run in the isolated TEEs respectively, reducing the coupling phenomenon that occurs when different TAs for key management run in the same TEE and improving the security of the electronic device 100.

[0107] Figure 8 Schematic diagram of the ARM architecture provided for another embodiment of the present application. Compared with Figure 5 the shown ARM architecture, the difference is that the second TEE does not include the third TA but only includes the security application driver, and the first TEE includes the first TA for key management and the fourth TA for trusted communication.

[0108] Next, Figure 8 the security processing method under the shown ARM architecture will be introduced. Refer to Figure 9 , Figure 9 which is a schematic diagram of the implementation of the security processing method in a multi-trusted execution environment provided for another embodiment of the present application. Figure 9 In , the REE further includes: the second CA for key management, the third CA for key service, and the fourth CA for key service;

[0109] Figure 9 The processing of the first request in the shown embodiment is the same as that in Figure 7 the shown embodiment, and will not be elaborated here.

[0110] In some examples, the second request may be a second key generation request; in this way, step 603 may be: the second CA obtains the second key generation request of the first CA; step 604 may be: the second CA sends the second key generation request to the fourth CA according to the second security level required by the second key generation request; the fourth CA sends the second key generation request to the fourth TA, the fourth TA establishes a trusted connection with the second TEE, and sends the second key generation request to the second TA through the above-mentioned trusted connection; the second TA generates a second key according to the second key generation request and sends the second key to the fourth TA through the above-mentioned trusted connection.

[0111] Further, after the second TA generates a second key according to the second key generation request and sends the second key to the fourth TA through the above-mentioned trusted connection, the fourth TA sends the second key to the fourth CA, and the fourth CA sends the second key to the second CA; the second CA saves the second key and sends the identifier of the second key to the first CA.

[0112] Further, after the second CA saves the second key and sends the identifier of the second key to the first CA, the second CA may also obtain the second data encryption request of the first CA; wherein, the second data encryption request carries the second data to be encrypted and the identifier of the second key; the second CA obtains the second key according to the identifier of the second key, and according to the second security level required by the second data encryption request, sends the second key and the second data to the fourth CA; the fourth CA sends the second key and the second data to the fourth TA, and the fourth TA sends the second key and the second data to the second TA through the trusted connection with the second TEE; the second TA encrypts the second data with the second key and sends the encrypted second data to the fourth TA through the above-mentioned trusted connection, the fourth TA sends the encrypted second data to the fourth CA, the fourth CA sends the encrypted second data to the second CA, and the second CA sends the encrypted second data to the first CA.

[0113] In addition, it should be noted that in the above example, the fourth TA establishing a trusted connection with the second TEE may be: the fourth TA shakes hands with the security application driver in the second TEE to establish a trusted connection between the fourth TA and the second TEE.

[0114] Still taking the first CA's wallet application as an example for illustration, when a user first uses the "Payment" function in the wallet application, the wallet application needs to generate a key. When generating the second key generation request, the wallet application determines that the security level required for the "Payment" function is relatively high. Therefore, according to the second security level required for the "Payment" function, the wallet application determines that the second TA will process this second key generation request. Thus, the wallet application can carry the identifier processed by the second TA in the second key generation request. After obtaining the above second key generation request, the second CA can determine that the second TA will process this second key generation request according to the identifier carried in the second key generation request. Then, the second CA sends the above second key generation request to the fourth CA, and the fourth CA sends the above second key generation request to the fourth TA. The fourth TA establishes a trusted connection with the second TEE and sends the second key generation request to the second TA through the above trusted connection. The second TA generates a second key for the "Payment" function according to the second key generation request and sends the second key to the fourth TA through the above trusted connection. The fourth TA sends the second key to the fourth CA, the fourth CA sends the second key to the second CA, the second CA saves the second key and sends the identifier of the second key to the first CA.

[0115] When the user subsequently uses the "Payment" function in the wallet application, the wallet application needs to encrypt the second data to be sent. Similarly, when generating the second data encryption request, the wallet application determines that the security level required for the "Payment" function is relatively high. Therefore, according to the second security level required for the "Payment" function, the wallet application determines that the second TA will process this second data encryption request. Thus, the wallet application can carry the identifier processed by the second TA in the second data encryption request.

[0116] After obtaining the second data encryption request of the wallet application, the second CA can determine that the second TA will process this second data encryption request according to the identifier carried in the second data encryption request. After the second CA obtains the above second key according to the identifier of the second key, it sends the second key and the second data to the fourth CA; the fourth CA sends the second key and the second data to the fourth TA, and the fourth TA sends the second key and the second data to the second TA through the trusted connection with the second TEE; the second TA encrypts the second data with the second key and sends the encrypted second data to the fourth TA through the above trusted connection, and the fourth TA sends the encrypted second data to the fourth CA; the fourth CA sends the encrypted second data to the second CA; the second CA sends the encrypted second data to the wallet application.

[0117] In this embodiment, the first TA and the fourth TA run in the first TEE. The fourth TA does not directly access the second TA. Instead, it first establishes a trusted connection with the second TEE and accesses the second TA through this trusted connection. Since the first TEE and the second TEE are two mutually isolated TEEs, the occurrence of coupling phenomena can be reduced, and the security of the electronic device 100 can be improved.

[0118] In the above embodiment, taking key generation and data encryption as examples, the security processing method under multiple trusted execution environments provided by the embodiments of the present application is described. It can be understood that for security processing requests such as data decryption and / or signature verification, the processing flow is the same as the above process and will not be elaborated here.

[0119] In addition, it should be noted that in the description of the above embodiments, the first request and the second request are requests from the same CA. In practical applications, the first request and the second request can also be requests from different CAs, and the processing flow remains unchanged.

[0120] It can be understood that some or all of the steps or operations in the above embodiments are only examples. The embodiments of the present application can also perform other operations or various deformations of the operations. In addition, the various steps can be executed in different orders presented in the above embodiments, and it is possible not to execute all the operations in the above embodiments.

[0121] It can be understood that in order for the electronic device to implement the above functions, it includes the corresponding hardware and / or software modules for executing each function. Combining the algorithm steps of each example described in the embodiments disclosed in the present application, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application in combination with the embodiments, but such implementation should not be considered to exceed the scope of the present application.

[0122] This embodiment can divide the electronic device into functional modules according to the above method embodiments. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one module. The above integrated module can be implemented in the form of hardware. It should be noted that the division of modules in this embodiment is illustrative, only a logical function division, and there can be other division methods in actual implementation.

[0123] Figure 10 This is a schematic structural diagram of an electronic device provided in another embodiment of the present application. In the case of dividing each functional module corresponding to each function, Figure 10 A possible composition schematic diagram of the electronic device 1000 involved in the above embodiment is shown, asFigure 10 As shown, the electronic device 1000 may include: a receiving unit 1001, a processing unit 1002, and a transmitting unit 1003;

[0124] Among them, the processing unit 1002 may be used to support the electronic device 1000 to execute steps 601 to 604, and / or for other processes of the technical solutions described in the embodiments of the present application.

[0125] It should be noted that all relevant contents of each step involved in the method embodiments of the present application can be cited in the function descriptions of the corresponding functional modules, and will not be elaborated here.

[0126] The electronic device 1000 provided in this embodiment is used to execute the above-mentioned security processing method in a multi-trusted execution environment, and thus can achieve the same effect as the above method.

[0127] It should be understood that the electronic device 1000 may correspond to Figure 2 the electronic device 100 shown. Among them, the functions of the receiving unit 1001 and the transmitting unit 1003 may be implemented by Figure 2 the processor 110, antenna 1, and mobile communication module 150 in the electronic device 100 shown, and / or, implemented by the processor 110, antenna 2, and wireless communication module 160; the function of the processing unit 1002 may be implemented by Figure 2 the processor 110 in the electronic device 100 shown.

[0128] In the case of adopting an integrated unit, the electronic device 1000 may include a processing module, a storage module, and a communication module.

[0129] Among them, the processing module may be used to control and manage the actions of the electronic device 1000. For example, it may be used to support the electronic device 1000 to execute the steps performed by the above-mentioned receiving unit 1001, processing unit 1002, and transmitting unit 1003. The storage module may be used to support the electronic device 1000 to store program codes, data, etc. The communication module may be used to support the communication of the electronic device 1000 with other devices.

[0130] Among them, the processing module may be a processor or a controller, which may implement or execute various exemplary logic blocks, modules, and circuits described in combination with the disclosure of the present application. The processor may also be a combination that implements computing functions, such as a combination including one or more microprocessors, a combination of a digital signal processing (DSP) and a microprocessor, and so on. The storage module may be a memory. The communication module may specifically be a device such as a radio frequency circuit, a Bluetooth chip, and / or a Wi-Fi chip for interacting with other electronic devices.

[0131] In one embodiment, when the processing module is a processor and the storage module is a memory, the electronic device 1000 involved in this embodiment may be a device with Figure 2 the structure shown.

[0132] The embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. When it runs on a computer, the computer is made to execute the method provided by the embodiment of the present application Figures 6 to 9 shown.

[0133] The embodiment of the present application also provides a computer program product, which includes a computer program. When it runs on a computer, the computer is made to execute the method provided by the embodiment of the present application Figures 6 to 9 shown.

[0134] In the embodiment of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent the situation where A exists alone, A and B exist simultaneously, or B exists alone. Where A and B may be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, and c may represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c may be single or multiple.

[0135] Those of ordinary skill in the art can realize that the units and algorithm steps described in the embodiments disclosed herein can be implemented by a combination of electronic hardware, computer software, and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. A professional technician can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0136] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the systems, devices, and units described above can refer to the corresponding processes in the foregoing method embodiments, and will not be repeated here.

[0137] In several embodiments provided by the present application, if any function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs.

[0138] As described above, the foregoing are only specific implementation manners of the present application. Any person skilled in the art within the technical scope disclosed by the present application can easily think of changes or substitutions, which should all be covered by the protection scope of the present application. The protection scope of the present application shall be subject to the protection scope of the claims.

Claims

1. A security processing method in a multi-trusted execution environment, characterized in that, Applied to an electronic device, the electronic device includes: a rich execution environment, a first trusted execution environment, a second trusted execution environment, and a security element; the rich execution environment includes: a first client application; the first trusted execution environment includes: a first trusted application for key management; the security element includes a second trusted application for key management; the method includes: Obtain a first request of the first client application; According to a first security level required by the first request, send the first request to the first trusted application, and perform security processing on the first request by the first trusted application; Obtain a second request of the first client application; According to a second security level required by the second request, send the second request to a second trusted application through the second trusted execution environment, and perform security processing on the second request by the second trusted application; wherein, the second security level is higher than the first security level.

2. The method according to claim 1, wherein The first request includes a first key generation request; The rich execution environment further includes: a second client application for key management, a third client application for key service, and a fourth client application for key service; The obtaining of the first request of the first client application in the rich execution environment includes: The second client application obtains the first key generation request of the first client application; The sending of the first request to the first trusted application according to the first security level required by the first request, and the performing of security processing on the first request by the first trusted application includes: The second client application sends the first key generation request to the third client application according to the first security level required by the first key generation request; The third client application sends the first key generation request to the first trusted application; The first trusted application generates a first key according to the first key generation request, and sends the first key to the third client application.

3. The method according to claim 2, wherein After the first trusted application generates a first key according to the first key generation request and sends the first key to the third client application, it further includes: The third client application sends the first key to the second client application; The second client application saves the first key, and sends an identifier of the first key to the first client application.

4. The method according to claim 3, characterized in that After the second client application saves the first key and sends the identifier of the first key to the first client application, it further includes: The second client application obtains a first data encryption request of the first client application; wherein, the first data encryption request carries first data to be encrypted and the identifier of the first key; The second client application obtains the first key according to the identifier of the first key, and sends the first key and the first data to the third client application according to the first security level required by the first data encryption request; The third client application sends the first key and the first data to the first trusted application; The first trusted application encrypts the first data using the first key and sends the encrypted first data to the third client application; The third client application sends the encrypted first data to the second client application; The second client application sends the encrypted first data to the first client application.

5. The method according to claim 1, wherein The second request includes a second key generation request; The first trusted execution environment further includes: a fourth trusted application for trusted communication; the rich execution environment further includes: a second client application for key management, a third client application for key services, and a fourth client application for key services; The obtaining of the second request from the first client application includes: The second client application obtains the second key generation request from the first client application; According to the second security level required by the second request, sending the second request through the second trusted execution environment to a second trusted application, and the security processing of the second request by the second trusted application includes: The second client application sends the second key generation request to the fourth client application according to the second security level required by the second key generation request; The fourth client application sends the second key generation request to the fourth trusted application; The fourth trusted application establishes a trusted connection with the second trusted execution environment and sends the second key generation request to the second trusted application through the trusted connection; The second trusted application generates a second key according to the second key generation request and sends the second key to the fourth trusted application through the trusted connection.

6. The method according to claim 5, wherein After the second trusted application generates a second key according to the second key generation request and sends the second key to the fourth trusted application through the trusted connection, it further includes: The fourth trusted application sends the second key to the fourth client application; The fourth client application sends the second key to the second client application; The second client application saves the second key and sends the identifier of the second key to the first client application.

7. The method according to claim 6, wherein After the second client application saves the second key and sends the identifier of the second key to the first client application, it further includes: The second client application obtains a second data encryption request from the first client application; wherein, the second data encryption request carries the second data to be encrypted and the identifier of the second key; The second client application obtains the second key according to the identifier of the second key, and according to the second security level required by the second data encryption request, sends the second key and the second data to the fourth client application; The fourth client application sends the second key and the second data to the fourth trusted application; The fourth trusted application sends the second key and the second data to the second trusted application through the trusted connection with the second trusted execution environment; The second trusted application encrypts the second data using the second key, and sends the encrypted second data to the fourth trusted application through the trusted connection; The fourth trusted application sends the encrypted second data to the fourth client application; The fourth client application sends the encrypted second data to the second client application; The second client application sends the encrypted second data to the first client application.

8. The method according to any one of claims 1-7, characterized in that, The first trusted execution environment is implemented based on the processor of the electronic device, and the second trusted execution environment is implemented based on a virtual machine in the electronic device; the first trusted execution environment and the second trusted execution environment are two mutually isolated trusted execution environments.

9. An electronic device, characterized in that, Comprising: One or more processors; A memory; Multiple application programs; And one or more computer programs, wherein the one or more computer programs are stored in the memory, and the one or more computer programs include instructions that, when executed by the electronic device, cause the electronic device to execute the method according to any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, and when it runs on a computer, it causes the computer to execute the method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Secure mobile terminal electronic authentication method and system

    CN106506472A

  • One-time password (OTP) generation method and system based on safety element

    CN108616352A

  • Key management method, key management device and computing equipment

    CN113821835A

  • Service processing method and related device

    CN115017486A

  • Security architecture system, security management method, computing device and readable storage medium

    CN115618328A