Key negotiation method, intelligent terminal and storage medium

By building a security application module and a key management module in the trusted execution environment of the smart terminal, and using the asymmetric elliptic curve key algorithm to generate a shared key, the problem of sensitive data in the smart terminal is solved and data security is improved.

CN120358016APending Publication Date: 2025-07-22WUXI RONGKA TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510316195.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-17
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In smart terminals, sensitive data such as shared keys are exposed by the open operating system environment, resulting in poor security and vulnerability to attacks.

Method used

The security application module and key management module are built in the trusted execution environment of the smart terminal. The shared key is generated through the key negotiation method to ensure that the key management module and the security chip perform data transmission and negotiation in the trusted execution environment. The public key pair is generated using the asymmetric elliptic curve key algorithm, and the security chip management module is securely transmitted.

Benefits of technology

Effectively reduce the exposure of sensitive data in an open environment, reduce the risk of sensitive data being attacked, and improve data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358016A_ABST
    Figure CN120358016A_ABST
Patent Text Reader

Abstract

The invention discloses a key negotiation method, an intelligent terminal and a storage medium. The key negotiation method is applied to the intelligent terminal, a trusted execution environment is formed in the intelligent terminal, a security application module and a key management module are constructed in the trusted execution environment, and the key management module is connected with a security chip based on the security application module. The key negotiation method comprises the following steps: starting key negotiation, and generating a negotiation instruction; enabling the key management module to access the security chip based on the security application module according to the negotiation instruction, and enabling the security chip to access the key management module based on the security application module; the key management module negotiates a shared key on the basis of the first key, and the security chip negotiates a shared key on the basis of the second key. According to the technical scheme, the situation that the sensitive data are exposed in an open environment can be effectively reduced, attacks received by the sensitive data are reduced, and the security of the sensitive data is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of system architecture, and particularly to a key negotiation method, an intelligent terminal, and a storage medium. Background Art

[0002] An intelligent terminal refers to a type of embedded computer system device. Its architecture framework is consistent with that of an embedded system, but the application scenario is more specific, so its architecture is more detailed. An intelligent terminal usually has the ability to access the Internet and can be equipped with various operating systems to customize various functions according to user needs. Common intelligent terminals include mobile intelligent terminals, in-vehicle intelligent terminals, smart TVs, and wearable devices, etc.

[0003] Currently, a lot of sensitive data such as shared secrets in intelligent terminals is exposed in an open operating system environment, which leads to the vulnerability of the generation process of these sensitive data to attacks and poor security. Summary of the Invention

[0004] Aiming at the defects in the prior art, the present invention provides a key negotiation method that can effectively reduce the exposure of sensitive data in an open environment, reduce the attacks on sensitive data, and improve the security of sensitive data.

[0005] A key negotiation method of the present application, the key negotiation method is applied to an intelligent terminal. The intelligent terminal forms a trusted execution environment, and a security application module and a key management module are built in the trusted execution environment. The key management module is connected to a security chip based on the security application module;

[0006] The key negotiation method includes:

[0007] Start key negotiation to generate a negotiation instruction;

[0008] According to the negotiation instruction, the key management module accesses the security chip based on the security application module, and the security chip accesses the key management module based on the security application module. The key management module negotiates a shared key based on a first key, and the security chip negotiates a shared key based on a second key.

[0009] In one aspect, before the step of enabling the key management module to access the security chip based on the security application module according to the negotiation instruction, it includes:

[0010] According to the negotiation instruction, control the key management module to generate a first key, and at the same time control the security chip to generate a second key;

[0011] Alternatively, a first key is preset in the key management module, and a second key is preset in the security chip.

[0012] In one aspect, the first key is a first public key, and the second key is a second public key;

[0013] The steps for the key management module and the security chip to negotiate a shared key based on the first key and the second key respectively include:

[0014] Generate a first key pair in the key management module, where the first key pair includes a first private key and the first public key, and generate a second key pair in the security chip, where the second key pair includes a second private key and the second public key;

[0015] The security application module obtains the first public key from the key management module, sends the first public key to the security chip, and the security chip generates a shared key based on the first public key and the second private key;

[0016] The security application module obtains the second public key from the security chip, sends the second public key to the key management module, and the key management module generates a shared key based on the second public key and the first private key.

[0017] In one aspect, the steps for generating a first key pair in the key management module include:

[0018] Generate a first key pair in the key management module using an asymmetric elliptic curve key algorithm;

[0019] The steps for generating a second key pair in the security chip include:

[0020] Generate a second key pair in the security chip using the same asymmetric elliptic curve key algorithm.

[0021] In one aspect, a security chip management module is further provided in the trusted execution environment, and the security chip management module is communicatively connected to the security application module and the security chip respectively;

[0022] The steps of enabling the key management module to access the security chip based on the security application module and enabling the security chip to access the key management module based on the security application module according to the negotiation instruction further include:

[0023] According to the negotiation instruction, the key management module accesses the security chip sequentially through the security application module and the security chip management module;

[0024] According to the negotiation instruction, the security chip accesses the key management module through the security chip management module and the security application module in sequence.

[0025] In one aspect, the security application module is Strongbox Service TA, the key management module is Keymint TA, and the security chip management module is SE Service TA.

[0026] In one aspect, a secure transmission key is prefabricated in both the security application module of the trusted execution environment and the security application module of the security chip;

[0027] The key negotiation method further includes:

[0028] The key management module obtains the ROT value and transmits the ROT value to the security application module of the trusted execution environment;

[0029] The security application module of the trusted execution environment encrypts the ROT based on the secure transmission key;

[0030] Write the encrypted ROT value into the security chip.

[0031] In one aspect, the intelligent terminal further forms a rich execution environment, and a Strongbox HAL module and a Keystore module are provided in the rich execution environment;

[0032] The key negotiation method includes:

[0033] The Keystore module calls the Strongbox HAL module;

[0034] The Strongbox HAL module accesses the security application module and the security chip in sequence.

[0035] To solve the above problems, the present application further provides an intelligent terminal, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described above is implemented.

[0036] To solve the above problems, the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method described above is implemented.

[0037] The beneficial effects of the present invention are as follows: The security application module and the key management module are both set in the trusted execution environment, and the attacks received by the first key and the second key can be reduced in the trusted execution environment. At the same time, the process of generating the shared key is also mainly carried out in the trusted execution environment, thereby effectively reducing the situation of being attacked when generating the shared key. It can be seen that the technical solution of the present application can reduce the situation where sensitive data is exposed in the open environment, reduce the attacks received by sensitive data, and improve the security of sensitive data. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. In all the drawings, similar elements or parts are generally identified by similar reference numerals. In the drawings, the elements or parts are not necessarily drawn to scale.

[0039] Figure 1 It is a schematic flow chart of the steps of the key negotiation method in the present application;

[0040] Figure 2 It is a schematic diagram of the steps of the first case of forming the first key and the second key in the key negotiation method of the present application;

[0041] Figure 3 It is a schematic diagram of the steps of the second case of forming the first key and the second key in the key negotiation method of the present application;

[0042] Figure 4 It is a schematic flow chart of the steps of negotiating the shared key in the key negotiation method of the present application;

[0043] Figure 5 It is a schematic flow chart of the steps of generating the first key pair and the second key pair in the key negotiation method of the present application;

[0044] Figure 6 It is a schematic flow chart of the steps of using the security chip management module and the security application module to establish mutual access between the security chip and the key management module in the key negotiation method of the present application;

[0045] Figure 7 It is a schematic flow chart of the steps of writing the ROT value in the key negotiation method of the present application;

[0046] Figure 8 It is a schematic diagram of the business process steps of the security application module in the key negotiation method of the present application.

[0047] Figure 9 It is a schematic diagram of the functional modules of the smart terminal in the key negotiation method of the present application;

[0048] Figure 10 It is a schematic diagram of the key negotiation process in the first case of the key negotiation method in this application;

[0049] Figure 11 It is a schematic diagram of the key negotiation process in the second case of the key negotiation method in this application;

[0050] Figure 12 It is a schematic diagram of the process of writing the ROT value in the key negotiation method in this application;

[0051] Figure 13 It is a schematic diagram of the process of starting the security application module in the key negotiation method in this application. Detailed implementation manners

[0052] Next, embodiments of the technical solution of the present invention will be described in detail with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solution of the present invention, so they are only examples and cannot be used to limit the protection scope of the present invention.

[0053] It should be noted that unless otherwise specified, the technical terms or scientific terms used in this application should have the ordinary meaning understood by those skilled in the art to which the present invention belongs.

[0054] As Figure 1 and Figure 9 shown, the key negotiation method is applied to an intelligent terminal, and the intelligent terminal can be a mobile intelligent terminal, a vehicle-mounted intelligent terminal, a smart TV, a wearable device, etc. The intelligent terminal includes a main board and functional devices connected to the main board. The main board is also called the mainboard, systemboard, or motherboard, and is one of the most basic and important components of a computer. The main board is generally a rectangular circuit board on which the main circuit system of the computer is installed to control the switch interface.

[0055] TEE (Trusted Execution Environment) provides a trusted execution environment based on TrustZone technology. TrustZone technology divides the working state of the central processing unit into a normal mode and a secure mode. The Rich Execution Environment (REE) runs in the normal mode, and the TEE runs in the secure mode. The TEE is an operating environment constructed based on a hardware isolation mechanism and is independent of other areas of the system. The TEE creates a secure environment through hardware technology to ensure the security of the code and data running in it and prevent attackers from accessing or tampering with them. The TEE provides protection and isolation for peripheral hardware resources and is widely used in payments, identity authentication, content protection, etc. TA (Trusted Application), the acronym for Trusted Application, runs on the TEE environment.

[0056] In the trusted execution environment, a secure application module and a key management module are built. The key management module is connected to the secure chip based on the secure application module. The key negotiation process of this application is usually started after the hardware system of the smart terminal is manufactured and the operating system is installed at the manufacturer's end. When manufacturing the smart terminal, the first key and the second key are pre-stored in the key management module and the secure chip respectively.

[0057] The key negotiation method includes:

[0058] Step S10, start key negotiation and generate a negotiation instruction; starting key negotiation can be carried out when the smart terminal is powered on and started.

[0059] Step S20, according to the negotiation instruction, make the key management module access the secure chip based on the secure application module, and make the secure chip access the key management module based on the secure application module. The key management module negotiates a shared key based on the first key, and the secure chip negotiates a shared key based on the second key. The first key and the second key are the basis for generating the shared key respectively. The key management module and the secure application module add mutual access sub-modules. It can be seen that realizing the mutual access between the key management module and the secure application module enables the transfer of data between them.

[0060] Among them, the secure application module is Strongbox Service TA, the key management module is Keymint TA, and the secure chip management module is SE Service TA.

[0061] Further, it should be noted that the intelligent terminal system modules have changed from the original Keymint HAL module, Strongbox HAL module, SE HAL module, Keymint TA module, SE Sevice TA module to the Keymint HAL module, Strongbox HAL module, SE HAL module, Keymint TA module, Strongbox Service TA, and SE Service TA modules, that is, a Strongbox Service TA module is newly added to the TEE system.

[0062] In this embodiment, both the security application module and the key management module are set in the trusted execution environment, and in the trusted execution environment, the attacks received by the first key and the second key can be reduced. At the same time, the process of generating the shared key is also mainly carried out in the trusted execution environment, thereby effectively reducing the situation of being attacked when generating the shared key. It can be seen that the technical solution of this application can reduce the situation where sensitive data is exposed in the open environment, reduce the attacks received by sensitive data, and improve the security of sensitive data.

[0063] In an embodiment of the present application, before the step of enabling the key management module to access the security chip based on the security application module according to the negotiation instruction, the first key and the second key are first formed, and there can be two situations for the generation process of the first key and the second key. Specifically, it includes:

[0064] As Figure 2 shown, the first situation is: controlling the key management module to generate the first key according to the negotiation instruction, and at the same time controlling the security chip to generate the second key; that is to say, the first key and the second key are generated when the key negotiation is started.

[0065] As Figure 3 shown, the second situation is: the first key is pre-set in the key management module, and the second key is pre-set in the security chip. Before the key negotiation is started, or rather, when the intelligent terminal is manufactured, the first key and the second key are pre-stored in the key management module and the security chip. The process of generating the first key and the second key again later is reduced.

[0066] As Figure 4 and Figure 10 shown, in an embodiment of the present application, the first key is the first public key, and the second key is the second public key;

[0067] The steps for the key management module and the security chip to negotiate the shared key respectively based on the first key and the second key include:

[0068] Step S210, generate a first key pair in the key management module, the first key pair includes a first private key and a first public key, and generate a second key pair in the security chip, the second key pair includes a second private key and a second public key; define the first key pair as (K1_pub, K1_priv), the first public key as K1_pub, and the first private key as K1_priv. Define the second key pair as (K2_pub, K2_priv), the second public key as K2_pub, and the second private key as K2_priv.

[0069] Step S220, the security application module obtains the first public key from the key management module, sends the first public key to the security chip, and the security chip generates a shared key based on the first public key and the second private key; the shared key generated by the security chip is (K1_pub, K2_priv).

[0070] Step S230, the security application module obtains the second public key from the security chip, sends the second public key to the key management module, and the key management module generates a shared key based on the second public key and the first private key. The shared key generated by the key management module is (K2_pub, K1_priv). Since the first key pair and the second key pair are generated using the same algorithm, it can be understood that the shared keys generated based on the first key pair and the second key pair can be mutually verified. A ShareSecret (shared key) is formed in the intelligent terminal, and the shared key is mainly used to ensure the security of data transmission. In mobile application development, a shared key is a key shared among multiple applications or devices, used to encrypt and decrypt information to ensure that only entities with the key can read the information.

[0071] As Figure 5 shown, in an embodiment of the present application, the step of generating the first key pair in the key management module includes:

[0072] Step S211, generate the first key pair in the key management module using an asymmetric elliptic curve key algorithm; for example, use the ECC P256 key algorithm in the key management module to complete the generation of the first key pair.

[0073] The step of generating the second key pair in the security chip includes:

[0074] Step S212, generate the second key pair in the security chip using the same asymmetric elliptic curve key algorithm. The ECC P256 key algorithm is also used in the security chip to complete the generation of the second key pair. This can ensure that the corresponding generated shared keys can be mutually verified.

[0075] As Figure 6As shown in the figure, in an embodiment of the present application, a security chip management module is further provided in the trusted execution environment. The security chip management module is respectively communicatively connected to the security application module and the security chip;

[0076] The steps of enabling the key management module to access the security chip based on the security application module and enabling the security chip to access the key management module based on the security application module according to the negotiation instruction further include:

[0077] Step S201, the key management module accesses the security chip through the security application module and the security chip management module in sequence according to the negotiation instruction; thereby forming an effective data transmission channel. For example, the first public key can be transmitted to the security chip through the security application module and the security chip management module in sequence.

[0078] Step S202, the security chip accesses the key management module through the security chip management module and the security application module in sequence according to the negotiation instruction. The second public key can be transmitted to the key management module through the security chip management module and the security application module in sequence.

[0079] To further elaborate on the above technical solution, the following is an example:

[0080] As Figure 10 shown, the first case:

[0081] 1. During the production process of the device, prefabricate keys in StrongBox SE (K2_pub, K2_priv) and TEEKeymint TA (K1_pub, K1_priv).

[0082] 2. When the device starts up, TEE Keymint TA directly accesses the SE through TEE Strongbox Service TA, and verifies whether both parties have the same key and negotiates the same key through the share secret process.

[0083] Specifically, the process of generating the Strongbox production line share secret is as follows:

[0084] (1). Strongbox Service TA obtains the public key K1_pub from TEE Keymint TA. StrongboxService TA sends K1_pub to StrongBox SE through SE Service TA. StrongBox SE uses a key negotiation algorithm, such as ECDH, to calculate the shared secret share secret using (K2_priv, K1_pub).

[0085] (2), StrongBox SE sends {K2_pub} to Strongbox Service TA.

[0086] (3), Strongbox Service TA passes {K2_pub} to TEE Keymint TA. TEE Keymint TA uses the same key negotiation algorithm as StrongBox SE, such as ECDH, to calculate the shared secret share secret using (K1_priv, K2_pub).

[0087] As Figure 11 shown, the second case:

[0088] 1. During the production process of the device, there is no need to pre - install keys in StrongBox SE (K2_pub, K2_priv) and TEEKeymint TA (K1_pub, K1_priv).

[0089] 2. When the device starts up, TEE Keymint TA and StrongBox SE each generate a public - private key pair, and verify whether both parties have the same key and negotiate the same key through the share secret process.

[0090] Specifically, the process of generating share secret in the Strongbox production line is as follows:

[0091] (1), Strongbox Service TA obtains the public key K1_pub from TEE Keymint TA: TEE Keymint TA generates a temporary public - private key pair, such as the key pair K1 (K1_pub, K1_priv) generated by the ECC P - 256 curve. StrongboxService TA sends K1_pub to StrongBox SE through SE Service TA.

[0092] (2), StrongBox SE uses the same algorithm (possibly including curve parameters) as TEE Keymint TA to generate a temporary public - private key pair, such as the key pair K2 (K2_pub, K2_priv) generated by the ECC P256 curve.

[0093] (3), StrongBox SE uses the key negotiation algorithm, such as ECDH, to calculate the shared secret share secret using (K2_priv, K1_pub).

[0094] (4), StrongBox SE sends {K2_pub} to Strongbox Service TA.

[0095] (5), Strongbox Service TA passes {K2_pub} to TEE Keymint TA. TEE Keymint TA uses the same key negotiation algorithm as StrongBox SE, such as ECDH, and calculates the shared secret key share secret using (K1_priv, K2_pub).

[0096] As Figure 7 and Figure 12 shown, in an embodiment of the present application, a secure transmission key is prefabricated in both the secure application module of the trusted execution environment and the secure application module of the secure chip;

[0097] The key negotiation method further includes:

[0098] Step S11, the key management module obtains the ROT value and transmits the ROT value to the secure application module of the trusted execution environment; ROT (Root of Trust), this ROT value is used when the user generates a key and is bound to the generation process. Ensure that each device has a unique key, that is, encrypted data can only be decrypted into the correct plaintext by the key of this device.

[0099] Step S12, the secure application module of the trusted execution environment encrypts the ROT based on the secure transmission key;

[0100] Step S13, write the encrypted ROT value into the secure chip.

[0101] Compared with the existing design, its writing process is exposed in the ordinary environment, that is, exposed in the rich execution environment, and is easily implanted with applications or attacked, with poor security. Through the above solution, the ROT value writing is executed in the trusted execution environment, which guarantees the security of the data. At the same time, through the Keymint TA and Strongbox Service TA modules, the SE Sevice TA directly interacts, the data transmission path is shorter, and the key negotiation process is more efficient.

[0102] As Figure 8 and Figure 13 shown, in an embodiment of the present application, the smart terminal also forms a rich execution environment, and a Strongbox HAL module and a Keystore module are set in the rich execution environment; the Keystore module is a key library, the StrongboxHAL module. The Strongbox HAL module aims to simplify the use of hardware components and is used to communicate with various hardware devices.

[0103] The key negotiation method includes:

[0104] Step S1, the Keystore module calls the Strongbox HAL module;

[0105] Step S2, the Strongbox HAL module sequentially accesses the security application module and the security chip. When the Strongbox Service TA module is set, the data flow for the Keystore module to access the security chip becomes shorter, and it can be directly connected to the security chip under the TEE. Compared with the prior art, the path to access the security chip through the OMA API is shorter, and the performance is effectively improved.

[0106] On the one hand, this solution can improve the transmission security of the ROT value and simultaneously enhance the security of the key negotiation process between the TEE and the security chip; on the other hand, the transmission path of the ROT value and the path of the key negotiation process between the TEE Keymint and the security chip are relatively shortened, and the performance is effectively improved.

[0107] This application also provides a key negotiation system. The key negotiation system is applied to an intelligent terminal. The intelligent terminal forms a trusted execution environment. A security application module and a key management module are built in the trusted execution environment. The key management module is connected to the security chip based on the security application module. A first key is prefabricated in the key management module, and a second key is prefabricated in the security chip. The key negotiation system includes: a startup module and a negotiation module.

[0108] The startup module is used to start key negotiation and generate a negotiation instruction; starting key negotiation can be performed when the intelligent terminal is powered on and started.

[0109] The negotiation module is used to cause the key management module to access the security chip based on the security application module according to the negotiation instruction, and cause the security chip to access the key management module based on the security application module; the key management module and the security chip negotiate a shared key respectively based on the first key and the second key.

[0110] In the key negotiation system of this embodiment, both the security application module and the key management module are set in the trusted execution environment, and the attacks received by the first key and the second key can be reduced in the trusted execution environment. At the same time, the process of generating the shared key is also mainly carried out in the trusted execution environment, thereby effectively reducing the situation of being attacked when generating the shared key. It can be seen that the technical solution of this application can reduce the situation of sensitive data being exposed in the open environment, reduce the attacks received by the sensitive data, and improve the security of the sensitive data.

[0111] The present application also provides an intelligent terminal, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the above-mentioned method is implemented.

[0112] For the specific embodiments and beneficial effects of the intelligent terminal in the present application, refer to the above-mentioned key negotiation method, which will not be elaborated here.

[0113] The present application also provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned method is implemented.

[0114] For the specific embodiments and beneficial effects of the computer-readable storage medium in the present application, refer to the above-mentioned key negotiation method, which will not be elaborated here.

[0115] Finally, it should be noted that: the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that: they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention, and they should all be covered by the scope of the claims and the description of the present invention.

Claims

1. A key negotiation method, characterized in that, The key negotiation method is applied to an intelligent terminal, which has a trusted execution environment. A security application module and a key management module are built in the trusted execution environment. The key management module is connected to a security chip based on the security application module; The key negotiation method includes: Start key negotiation to generate a negotiation instruction; According to the negotiation instruction, the key management module accesses the security chip based on the security application module, and the security chip accesses the key management module based on the security application module. The key management module negotiates a shared key based on a first key, and the security chip negotiates a shared key based on a second key.

2. The key negotiation method according to claim 1, wherein Before the step of enabling the key management module to access the security chip based on the security application module according to the negotiation instruction, it includes: Controlling the key management module to generate a first key according to the negotiation instruction, and at the same time controlling the security chip to generate a second key; Alternatively, preset the first key in the key management module and preset the second key in the security chip.

3. The key negotiation method according to claim 1, characterized in that, The first key is a first public key, and the second key is a second public key; The step of the key management module and the security chip negotiating a shared key based on the first key and the second key respectively includes: Generate a first key pair in the key management module, the first key pair includes a first private key and the first public key, and generate a second key pair in the security chip, the second key pair includes a second private key and the second public key; The security application module obtains the first public key from the key management module, sends the first public key to the security chip, and the security chip generates a shared key based on the first public key and the second private key; The security application module obtains the second public key from the security chip, sends the second public key to the key management module, and the key management module generates a shared key based on the second public key and the first private key.

4. The key negotiation method according to claim 3, wherein, The step of generating a first key pair in the key management module includes: Generate a first key pair in the key management module using an asymmetric elliptic curve key algorithm; The step of generating a second key pair in the security chip includes: Generate a second key pair in the security chip using the same asymmetric elliptic curve key algorithm.

5. The key negotiation method according to claim 1, wherein A security chip management module is also set in the trusted execution environment. The security chip management module is communicatively connected to the security application module and the security chip respectively; The step of enabling the key management module to access the security chip based on the security application module according to the negotiation instruction, and enabling the security chip to access the key management module based on the security application module, further includes: According to the negotiation instruction, the key management module accesses the security chip sequentially through the security application module and the security chip management module; According to the negotiation instruction, the security chip accesses the key management module sequentially through the security chip management module and the security application module.

6. The key negotiation method according to claim 5, wherein The security application module is StrongboxService TA, the key management module is Keymint TA, and the security chip management module is SE Service TA.

7. The key negotiation method according to claim 1, characterized in that, A secure transmission key is prefabricated in both the security application module of the trusted execution environment and the security application module of the security chip; The key negotiation method further includes: The key management module obtains the ROT value and transmits the ROT value to the security application module of the trusted execution environment; The security application module of the trusted execution environment encrypts the ROT based on the secure transmission key; The encrypted ROT value is written into the security chip.

8. The key negotiation method according to claim 1, characterized in that The intelligent terminal further forms a rich execution environment, and a Strongbox HAL module and a Keystore module are provided in the rich execution environment; The key negotiation method includes: The Keystore module calls the Strongbox HAL module; The Strongbox HAL module sequentially accesses the security application module and the security chip.

9. An intelligent terminal, characterized in that, The intelligent terminal includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the method described in any one of claims 1 to 8 is implemented.

10. A computer-readable storage medium storing a computer program, where when the computer program is executed by a processor, the method described in any one of claims 1 to 8 is implemented.