Data transmission method and related device
By introducing intelligent sensing hubs and multi-layer security environments into electronic devices, safe and efficient data transmission between trusted application TA and intelligent sensing hubs is achieved, and the problem of insufficient communication methods for trusted application TAs is solved, and the security and efficiency of data transmission are improved.
Patent Information
- Application Number
- CN202410110454.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-25
- Publication Date
- 2025-08-01
- Estimated Expiration
- 2044-01-25
AI Technical Summary
In the prior art, the communication methods of trusted applications TA are not rich enough, especially in the lack of effective means for communication methods with intelligent sensing hubs, resulting in low data transmission efficiency and insufficient security.
By introducing an intelligent sensing hub in the electronic device, the target data is transmitted to the intelligent sensing hub using the first trusted application TA, and data transmission is carried out using a multi-layer security environment and a proxy application TA, including encryption and permission verification, to ensure that data is transmitted in a secure environment.
It enriches the communication methods of trusted application TA, improves the security and efficiency of data transmission, and enhances the flexibility and security of data exchange between trusted application TA and intelligent sensing hub.
Smart Images

Figure CN120408622A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of terminal technologies, and in particular, to a data transmission method and related devices. Background Art
[0002] With the rapid development of terminal technologies, how to improve the security of terminals has become increasingly important. Currently, in order to improve the data security of electronic devices, a secure environment such as a trusted execution environment (TEE) is adopted. In the TEE, there is a trusted application (TA) running. A trusted application TA is an application that completes specific functions in the TEE. Since calculations are performed in the TEE, it has relatively high security. Each trusted application TA has one or more corresponding client applications (CAs) in a rich execution environment (REE). In the REE environment, information can be transmitted to the trusted application TA in the TEE environment by calling the interface of the CA, and the corresponding function is completed and then the calculation result is returned.
[0003] However, currently, the communication methods of trusted applications TA are not rich enough. Summary of the Invention
[0004] Embodiments of this application provide a data transmission method and related devices, which are applied to the field of terminal technologies. By transmitting the target data of the first trusted application TA to an intelligent sensor hub (sensorhub), the communication methods of the trusted application TA can be enriched.
[0005] In a first aspect, embodiments of this application propose a data transmission method, which is applied to an electronic device. The electronic device includes a first secure environment TEE, an intelligent sensor hub, a non-secure environment REE, a client application CA running in the non-secure environment REE, and a first trusted application TA running in the first secure environment TEE. The method includes:
[0006] The client application CA indicates first information to the first trusted application TA, and the first information is used to indicate the transmission of the target data of the first trusted application TA; the first trusted application TA can respond to the first information and transmit the target data of the first trusted application TA to the intelligent sensor hub.
[0007] Among them, the electronic device may be deployed with an operating system (OS) or a real-time operating system (RTOS). The security of the rich execution environment (REE) is lower than that of the trusted execution environment (TEE). Therefore, compared with the trusted execution environment (TEE), the rich execution environment (REE) belongs to a non-secure environment, while the trusted execution environment (TEE) belongs to a secure environment. The first information may include a data transmission command. Optionally, the target data stored in the intelligent sensing hub can be used for data comparison or verification.
[0008] Among them, the first information is used to indicate the transmission of the target data of the first trusted application (TA). Optionally, the first information may include a data transmission command. The first trusted application (TA) may be a TA related to the service. Therefore, the trusted application (TA) may also be referred to as a service TA. Optionally, the service TA may be a service TA with certain requirements for data security, such as a face TA. The client (CA) may be a CA related to the first trusted application (TA). For example, if the first trusted application (TA) is a face TA, the client (CA) may be a face CA.
[0009] In the embodiment of the present application, it may be an application in the application layer. When detecting that a function related to the target data is triggered, the client application (CA) is called to indicate the first information to the first trusted application (TA). Exemplarily, for example, when detecting that the function of unlocking the screen is triggered, or the intelligent notification function is triggered, etc., the client (CA) is called to indicate the first information.
[0010] The target data may be data with certain requirements for security and confidentiality, such as at least one of face data, fingerprint data, voiceprint data, and iris data. The target data of the first trusted application (TA) may be stored in the first secure environment (TEE) where the first trusted application (TA) is located.
[0011] In the embodiment of the present application, the client application (CA) indicates the first information to the first trusted application (TA), and then the first trusted application (TA) may transmit the target data to the intelligent sensing hub based on the first information. Thus, the communication between the trusted application (TA) and the intelligent sensing hub can be realized, and in this way, the communication method of the trusted application (TA) can be enriched.
[0012] Combined with the first aspect, in a possible implementation manner, the electronic device further includes a second secure environment (TEE) and a second trusted application (TA) running in the second secure environment (TEE). The first trusted application (TA) transmits the target data of the first trusted application (TA) to the intelligent sensing hub in response to the first information, which may include:
[0013] In response to the first piece of information, the first trusted application TA transmits the target data of the first trusted application TA to the second trusted application TA; the second trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub through the first interface.
[0014] Among them, the second trusted application TA is configured with a first interface connected to the intelligent sensing hub. The second security environment TEE and the first security environment TEE can be different security environment modules.
[0015] In the embodiment of the present application, in response to the first piece of information, the first trusted application TA transmits the target data of the first trusted application TA to the second trusted application TA, and then the second trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub through the first interface. That is, the trusted application TA in one security environment TEE can transmit data through the trusted application TA in another security environment TEE and the intelligent sensing hub. Since the data transmission is preferably carried out through the security environment TEE, in this way, the data transmission security between the trusted application TA and the intelligent sensing hub can be improved.
[0016] In combination with the first aspect, in a possible implementation manner, the electronic device further includes a first proxy application TA running in the first security environment TEE and a second proxy application TA running in the second security environment TEE. The first trusted application TA transmitting the target data of the first trusted application TA to the second trusted application TA may include:
[0017] The first trusted application TA transmits the target data of the first trusted application TA to the first proxy application TA; the first proxy application TA transmits the target data to the second proxy application TA; the second proxy application TA transmits the target data to the second trusted application TA.
[0018] In the embodiment of the present application, the first trusted application TA transmits the target data of the first trusted application TA to the first proxy application TA, then the first proxy application TA transmits the target data to the second proxy application TA, and then the second proxy application TA transmits the target data to the second trusted application TA. That is to say, in this embodiment, between different trusted application TAs, communication can be carried out through their respective corresponding proxy application TAs. Through the proxy application TA, access to the trusted application TA can be controlled and network address conversion can be performed, etc. In this way, the security of mutual access between trusted application TAs can be improved.
[0019] In combination with the first aspect, in a possible implementation manner, before the second proxy application TA transmits the target data to the second trusted application TA, it further includes:
[0020] The second proxy application TA verifies the call permission of the first proxy application TA, and in the case where the call permission verification of the first proxy application TA passes, transmits the target data to the second trusted application TA.
[0021] In an embodiment of the present application, before the second proxy application TA transmits the target data to the second trusted application TA, the second proxy application TA verifies the call permission of the first proxy application TA, and in the case where the call permission verification of the first proxy application TA passes, transmits the target data to the second trusted application TA. That is to say, the second proxy application TA transmits the target data to the intelligent sensing hub through the second trusted application TA only when the first proxy application has the access permission to the second trusted application TA. In this way, the second proxy application TA can selectively open the transmission channel between the intelligent sensing hub for some or all of the trusted application TAs, which can improve the flexibility and security of the communication between the trusted application TAs and the intelligent sensing hub.
[0022] Combined with the first aspect, in a possible implementation manner, the second proxy application TA filters the target data in the case where the call permission verification of the first proxy application TA fails.
[0023] In an embodiment of the present application, in the case where the call permission verification of the first proxy application TA by the second proxy application TA fails, the second proxy application TA filters the target data. In this way, the data transmission security between the trusted application TAs can be improved, and the waste of network resources between the proxy application TA and the trusted application TAs can be reduced.
[0024] Combined with the first aspect, in a possible implementation manner, the first trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub in response to the first information, including:
[0025] The first trusted application TA transmits the target data of the first trusted application TA to the client application CA in response to the first information; the client application CA transmits the target data of the first trusted application TA to the intelligent sensing hub.
[0026] In an embodiment of the present application, the first trusted application TA can transmit the target data to the intelligent sensing hub through the client application CA. Generally, there is one or more corresponding client applications CA for a trusted application TA. That is to say, the embodiment of the present application can forward the target data through the existing client application CA. In this way, the convenience of transmitting data between the trusted application TA and the intelligent sensing hub can be improved.
[0027] In combination with the first aspect, in a possible implementation manner, the non-secure environment REE includes the hardware abstraction layer (HAL) service of the intelligent sensing hub. The intelligent sensing hub HAL is configured with a second interface for communicating with the intelligent sensing hub. Then, the client application CA transmits the target data of the first trusted application TA to the intelligent sensing hub HAL, and then the intelligent sensing hub HAL transmits the target data of the first trusted application TA to the intelligent sensing hub through the second interface.
[0028] In combination with the first aspect, in a possible implementation manner, before the first trusted application TA transmits the target data of the first trusted application TA to the client application CA, it further includes:
[0029] The first trusted application TA encrypts the target data of the first trusted application TA to obtain the encrypted target data.
[0030] In the embodiments of the present application, the first trusted application TA can encrypt the target data, so that the security of the target data during transmission to the intelligent sensing hub can be improved.
[0031] In combination with the first aspect, in a possible implementation manner, the client application CA transmits the target data of the first trusted application TA to the intelligent sensing hub, including:
[0032] The client application CA calls the intelligent sensing hub HAL to decrypt the encrypted target data to obtain the decrypted target data, and transmits the decrypted target data to the intelligent sensing hub through the intelligent sensing hub HAL.
[0033] In the embodiments of the present application, the intelligent sensing hub HAL decrypts the target data before transmitting the target data to the intelligent sensing hub. Then, the intelligent sensing hub receives the decrypted target data. In this way, the target data in the intelligent sensing hub can be directly used, improving the efficiency of the intelligent sensing hub in using the target data.
[0034] In combination with the first aspect, in a possible implementation manner, the data transmission method further includes:
[0035] The intelligent sensing hub HAL generates a key and transmits the key to the client application CA; the client application CA transmits the key to the first trusted application TA.
[0036] Correspondingly, the first trusted application TA encrypts the target data of the first trusted application TA, including:
[0037] The first trusted application TA encrypts the target data of the first trusted application TA based on the key.
[0038] Correspondingly, the intelligent sensing hub HAL decrypts the encrypted target data, including:
[0039] The intelligent sensing hub HAL decrypts the encrypted target data based on the key.
[0040] In the embodiment of the present application, encryption and decryption are performed using the key generated by the intelligent sensing hub HAL. Then, the key is transferred between the non-secure environment REE and the secure environment TEE. In this way, the transmission security of the key can be improved, and further the security of encrypting and decrypting the target data can be improved.
[0041] Combined with the first aspect, in a possible implementation manner, the target data includes target biometric data, and the electronic device further includes a settings application running in the non-secure environment REE. The method further includes:
[0042] The settings application responds to the biometric input operation and collects first biometric data through the electronic device. When the non-secure environment REE determines that the first biometric data meets the data quality requirements, it indicates second information to the client application CA. The second information is used to indicate storing the first biometric data. The client application CA responds to the second information and indicates third information and the first biometric data to the first trusted application TA. The third information is used to indicate storing the first biometric data. The first trusted application TA responds to the third information and stores the first biometric data as the target biometric data.
[0043] In the embodiment of the present application, by determining that the first biometric data meets the data quality requirements before allowing the first trusted application TA to store the first biometric data, the effectiveness of the biometric data stored by the first trusted application TA can be improved.
[0044] Combined with the first aspect, in a possible implementation manner, the non-secure environment REE includes the intelligent sensing hub HAL. The method further includes:
[0045] Determine whether the first biometric data meets the data quality requirements through the intelligent sensing hub HAL.
[0046] Combined with the first aspect, in a possible implementation manner, the data transmission method further includes:
[0047] When the non-secure environment REE determines that the first biometric data does not meet the data quality requirements, it extracts and stores the first biometric value based on the first biometric data; the client application CA receives the second biometric data collected by the electronic device; the non-secure environment REE extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value; when the second biometric value matches the first biometric value successfully and the second biometric data meets the data quality requirements, the non-secure environment REE indicates the fourth information to the client application CA, and the fourth information is used to indicate storing the second biometric data; in response to the fourth information, the client application CA indicates the fifth information and the second biometric data to the first trusted application TA, and the fifth information is used to indicate storing the second biometric data; in response to the fifth information, the first trusted application TA stores the second biometric data as the target biometric data.
[0048] In the embodiment of the present application, the intelligent sensing hub HAL extracts the first biometric value based on the first biometric data and stores the first biometric value. Then, even if the first biometric data is not stored, a certain degree of data comparison can be performed, thereby improving the flexibility of data comparison. Exemplarily, if the biometric data is face data, the biometric value is a face feature value; additionally, if the biometric data is fingerprint data, the biometric value is a fingerprint feature value.
[0049] Combined with the first aspect, in a possible implementation, the non-secure environment REE includes the intelligent sensing hub HAL. The secure environment REE extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value, including:
[0050] The intelligent sensing hub HAL extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value. In addition, the non-secure environment REE is pre-integrated with feature comparison algorithms, etc. By performing feature comparison and judgment of data quality requirements through the REE, algorithms can be not configured in the TEE. In this way, the system resources required to create the TEE can be reduced.
[0051] Among them, the intelligent sensing hub HAL can be configured with algorithms for judging whether the data quality requirements are met, algorithms for extracting biometric values, algorithms for comparing biometric values, etc.
[0052] In combination with the first aspect, in a possible implementation, the target data includes target biometric data, and the electronic device further includes a notification application running in the non-secure environment REE. The notification application is configured to enable the intelligent display function. After the first trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub in response to the first information, it further includes:
[0053] When the electronic device receives a message, the intelligent sensing hub compares the biometric data to be compared collected by the electronic device with the target biometric data; when the biometric data to be compared is successfully compared with the target biometric data, the intelligent sensing hub indicates the sixth information to the notification application, or when the biometric data to be compared fails to be compared with the target biometric data, the intelligent sensing hub indicates the seventh information to the notification application. The sixth information is used to indicate the display of the message, and the seventh information is used to indicate the hiding of the message; the notification application displays the message based on the received sixth information, or hides the message based on the received seventh information.
[0054] In the embodiment of the present application, when the electronic device receives a message, the intelligent sensing hub compares the biometric data to be compared collected by the electronic device with the target biometric data, and the message is displayed only when the comparison is successful, that is, when the user in the direction facing the display screen of the electronic device is the target user who entered the biometric data, the electronic device displays the message, thereby improving the privacy of message notification. At the same time, since the intelligent sensing hub stores the target biometric data, the intelligent sensing hub directly compares the biometric data to be compared with the target biometric data, so that it is not necessary to obtain the target biometric data from the TEE again, thereby improving the efficiency of data comparison and further improving the judgment efficiency of whether to display the message.
[0055] Second aspect, an embodiment of the present application provides a data transmission device, which may be an electronic device, or a chip or a chip system within the electronic device. The data transmission device may include a display unit and a processing unit. When the data transmission device is an electronic device, the display unit may be a display screen. The display unit is used to perform the display step so that the electronic device implements a data transmission method described in the first aspect or any possible implementation manner of the first aspect. When the data transmission device is an electronic device, the processing unit may be a processor. The data transmission device may further include a storage unit, and the storage unit may be a memory. The storage unit is used to store instructions, and the processing unit executes the instructions stored in the storage unit so that the electronic device implements a data transmission method described in the first aspect or any possible implementation manner of the first aspect. When the data transmission device is a chip or a chip system within the electronic device, the processing unit may be a processor. The processing unit executes the instructions stored in the storage unit so that the electronic device implements a data transmission method described in the first aspect or any possible implementation manner of the first aspect. The storage unit may be a storage unit within the chip (for example, a register, a cache, etc.), or a storage unit outside the chip within the electronic device (for example, a read-only memory, a random access memory, etc.).
[0056] Third aspect, an embodiment of the present application provides an electronic device, including a processor and a memory. The memory is used to store code instructions, and the processor is used to run the code instructions to execute the method described in the first aspect or any possible implementation manner of the first aspect.
[0057] Fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program or instructions are stored. When the computer program or instructions are run on a computer, the computer is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect.
[0058] Fifth aspect, an embodiment of the present application provides a computer program product including a computer program. When the computer program is run on a computer, the computer is caused to execute the method described in the first aspect or any possible implementation manner of the first aspect.
[0059] Sixth aspect, the present application provides a chip or a chip system. The chip or the chip system includes at least one processor and a communication interface. The communication interface and the at least one processor are interconnected by a line. The at least one processor is used to run a computer program or instructions to execute the method described in the first aspect or any possible implementation manner of the first aspect. Among them, the communication interface in the chip may be an input / output interface, a pin, a circuit, etc.
[0060] In a possible implementation, the chip or chip system described above in this application further includes at least one memory, and instructions are stored in the at least one memory. The memory can be a storage unit inside the chip, such as a register, cache, etc., or it can be a storage unit of the chip (such as a read-only memory, random access memory, etc.).
[0061] It should be understood that the technical solutions of the second to sixth aspects of this application correspond to those of the first aspect of this application, and the beneficial effects obtained by each aspect and the corresponding feasible implementation manners are similar and will not be elaborated herein. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] Figure 1 It is a schematic diagram of a hardware structure of an electronic device provided by an embodiment of this application;
[0063] Figure 2 It is a schematic diagram of a software structure of an electronic device provided by an embodiment of this application;
[0064] Figure 3A It is a schematic diagram of a trusted application TA transmitting face data to a sensorhub provided by an embodiment of this application;
[0065] Figure 3B It is a schematic diagram of another trusted application TA transmitting face data to a sensorhub provided by an embodiment of this application;
[0066] Figure 4 It is a schematic diagram of a process flow of a data transmission method provided by an embodiment of this application;
[0067] Figure 5 It is a schematic diagram of a process flow of another data transmission method provided by an embodiment of this application;
[0068] Figure 6 It is a schematic diagram of a process flow of another data transmission method provided by an embodiment of this application;
[0069] Figure 7 It is a schematic diagram of a scenario where an electronic device displays a message provided by an embodiment of this application;
[0070] Figure 8 It is a schematic diagram of a scenario where an electronic device hides a message provided by an embodiment of this application;
[0071] Figure 9 It is a schematic diagram of a structure of a chip provided by an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0072] To facilitate a clear description of the technical solutions of the embodiments of this application, the following briefly introduces some terms and technologies involved in the embodiments of this application:
[0073] 1. REE can be called a common execution environment. The rich execution environment operating system (REE OS) on a general-purpose processor and the client application CA can run in REE.
[0074] 2. TEE can be called a secure execution environment and can run a trusted execution environment operating system (TEE OS). TEE can also provide trusted security services (such as fingerprint matching, password verification, face matching, and secure payment services) to the CA. These security services can run in the TEE OS as trusted applications (TA). In some embodiments, TEE can be an execution area built using the secure area of the processor in the terminal device. The trusted execution environment can provide a secure operating environment for services.
[0075] 3. The main functions of the sensorhub include: real-time sensor control to reduce power consumption; connecting and processing data from various sensors; and fusing data from different sensor types to implement functions that require the combined data of multiple sensors. It should be noted that the sensorhub is a low-power processor, also known as a small core. Services processed by the sensorhub can be considered low-power services. For example, facial recognition processing on the sensorhub can be considered low-power facial recognition services.
[0076] 4. Other terms
[0077] In the embodiments of this application, terms such as "first" and "second" are used to distinguish between identical or similar items with substantially the same functions and effects. For example, the terms "first chip" and "second chip" are used solely to distinguish between different chips and do not define their order. Those skilled in the art will understand that terms such as "first" and "second" do not define the quantity or execution order, and do not necessarily define differences.
[0078] It should be noted that in the embodiments of this application, words such as "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design described in this application as "exemplary" or "for example" should not be construed as being preferred or advantageous over other embodiments or designs. Rather, the use of words such as "exemplary" or "for example" is intended to present the relevant concepts in a concrete manner.
[0079] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist simultaneously, and B exists alone, where A and B may be singular or plural. The character " / " generally indicates that the associated objects before and after are in an "or" relationship. "At least one (item)" or its similar expression refers to any combination of these items, including any combination of single item (s) or plural items (s). For example, at least one (item) of a, b, or c may represent: a, b, c, a - b, a - c, b - c, or a - b - c, where a, b, and c may be single or multiple.
[0080] 5. Electronic devices
[0081] The electronic devices in the embodiments of the present application may include handheld devices, vehicle-mounted devices, etc. with data acquisition functions (such as acquiring face data, fingerprint data, voiceprint data, iris data, etc.). For example, some electronic devices are: mobile phones, tablet computers, handheld computers, laptop computers, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grid, wireless terminals in transportation safety, wireless terminals in smart city, wireless terminals in smart home, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication functions, computing devices or other processing devices connected to a wireless modem, vehicle-mounted devices, wearable devices, terminal devices in a 5G network, or terminal devices in a future evolved public land mobile network (PLMN). The embodiments of the present application do not limit this.
[0082] By way of example and not limitation, in the embodiments of the present application, the electronic device may also be a wearable device. A wearable device, also known as a wearable intelligent device, is a general term for devices developed by applying wearable technologies to the intelligent design of daily wear, such as glasses, gloves, watches, clothing, and shoes. A wearable device is a portable device that is either directly worn on the body or integrated into the user's clothing or accessories. A wearable device is not just a hardware device, but also realizes powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable intelligent devices include those with complete functions and large sizes that can realize complete or partial functions without relying on a smartphone, such as smart watches or smart glasses, etc., and those that only focus on a certain type of application function and need to cooperate with other devices such as smartphones, such as various smart bracelets and smart jewelry for physical sign monitoring.
[0083] In addition, in the embodiments of the present application, the electronic device may also be a terminal device in an Internet of Things (IoT) system. The IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technologies, thereby realizing an intelligent network of human-machine interconnection and object-object interconnection.
[0084] The electronic device in the embodiments of the present application may also be referred to as: a terminal device, a user equipment (UE), a mobile station (MS), a mobile terminal (MT), an access terminal, a user unit, a user station, a mobile station, a mobile platform, a remote station, a remote terminal, a mobile device, a user terminal, a terminal, a wireless communication device, a user agent, or a user device, etc.
[0085] In the embodiments of the present application, the electronic device or each network device includes a hardware layer, an operating system layer running on the hardware layer, and an application layer running on the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and a memory (also known as the main memory). The operating system can be any one or more computer operating systems that implement service processing through processes, such as the Linux operating system, the Unix operating system, the Android operating system, the iOS operating system, or the Windows operating system, etc. The application layer includes applications such as a browser, an address book, a word processing software, and an instant messaging software.
[0086] The following embodiments illustrate the scenarios of the present solution by way of example.
[0087] In some example scenarios, an electronic device collects and stores the target face data of a user. When the electronic device needs to be unlocked, the electronic device collects the face data of the user facing the display screen of the electronic device, and compares the target face data with the face data to be verified. If the face data comparison is successful, the electronic device is unlocked; if the face data comparison fails, the electronic device is refused to be unlocked.
[0088] In some other example scenarios, when the electronic device needs to intelligently display the message of a pop-up notification, the face data to be verified is compared with the target face data. If the face data comparison is successful, the message content of the pop-up notification is displayed; if the face data comparison fails, the message of the pop-up notification is hidden.
[0089] In some other example scenarios, when the electronic device needs to perform a payment operation, the face data to be verified is compared with the target face data. If the face data comparison is successful, the payment is made; if the face comparison fails, the payment is refused.
[0090] It can be understood that the solution of this embodiment is not limited to the above scenarios, and the solution of this embodiment of the application can be used in scenarios where data comparison or data verification is required. In addition, the data for comparison is not limited to face data, and can also be biometric data such as fingerprint data, voiceprint data, and iris data, which is not limited here.
[0091] To improve the security of the target face data, the electronic device stores the target face data in the TEE. Then, when data comparison is required, the application processor calls the target data from the TEE, and then performs data comparison. However, the efficiency of calling the target data from the TEE is slow, resulting in slow data comparison efficiency. To ensure the security of the target data and improve the data comparison efficiency at the same time, the target data can be stored in the sensorhub, and the sensorhub can directly compare the stored target data with the data to be verified.
[0092] However, the current communication method of the TA is not rich enough, and there is no communication method between the TA and the sensorhub. Therefore, there is an urgent need for a communication method between the TA and the sensorhub to transmit the target data from the TA to the sensorhub.
[0093] In view of this, the embodiment of the present application provides a data transmission method and related device, which can transmit the target data of the first trusted application (TA) to the intelligent sensor hub (sensorhub), so that the communication method of the trusted application (TA) can be enriched.
[0094] To better understand the embodiment of the present application, the structure of the electronic device in the embodiment of the present application will be introduced below:
[0095] Figure 1 Shows a schematic diagram of the hardware structure of the electronic device 100.
[0096] The electronic device 100 may include a processor 110, an external memory interface 120, an internal memory 121, a universal serial bus (USB) interface 130, a charging management module 140, a power management module 141, a battery 142, an antenna 1, an antenna 2, a mobile communication module 150, a wireless communication module 160, an audio module 170, a speaker 170A, a receiver 170B, a microphone 170C, a headphone interface 170D, a sensor module 180, a button 190, a motor 191, an indicator 192, a camera 193, a display screen 194, a subscriber identification module (SIM) card interface 195, and an intelligent sensing hub 196, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an acceleration sensor 180E, a distance sensor 180F, a proximity light sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.
[0097] It can be understood that the structure schematically shown in the embodiments of the present invention does not constitute a specific limitation on the electronic device 100. In other embodiments of the present application, the electronic device 100 may include more or fewer components than those shown in the figure, or combine certain components, or split certain components, or have different component arrangements. The components shown in the figure may be implemented in hardware, software, or a combination of software and hardware.
[0098] The processor 110 may include one or more processing units. For example, the processor 110 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent devices or integrated in one or more processors.
[0099] The controller can generate operation control signals according to the instruction operation code and timing signals to complete the control of instruction fetching and execution.
[0100] A memory can also be set in the processor 110 to store instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can save the instructions or data that the processor 110 has just used or recycled. If the processor 110 needs to use the instruction or data again, it can be directly called from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves the efficiency of the system. The application processor can be deployed with a REE and a TEE independent of the REE. Optionally, the application processor can include one or two or more TEEs. When including two or more TEEs, they can be the first TEE (TEE1), the second TEE (TEE2), etc., but are not limited to two TEEs.
[0101] In this embodiment, the display screen 194 can be used to display face data, display messages, or collect fingerprint data through a fingerprint collection module provided on the display screen 194, etc. The camera 193 can be used to collect at least one of face data and iris data, etc. The microphone 170C can be used to collect voiceprint data.
[0102] The following embodiments will exemplarily illustrate the working process of the hardware of the electronic device in combination with the scenario of collecting face data.
[0103] The face data and iris data collected by the camera 193, the voiceprint data collected by the microphone 170C, and the fingerprint data collected by hardware such as the display screen 194 can be saved as target data in the TA in the TEE environment, and then the target data is transmitted from the TA in the TEE environment to the intelligent sensing hub 196 and stored in the intelligent sensing hub 196. Then, the intelligent sensing hub 196 can verify the data to be verified based on the target data stored in itself.
[0104] Figure 2 Shows a schematic diagram of the software structure of the electronic device 100.
[0105] The software system of the electronic device 100 can adopt a layered architecture, an event-driven architecture, a microkernel architecture, a microservices architecture, or a cloud architecture. In the embodiments of the present invention, the Android system with a layered architecture is taken as an example to exemplarily illustrate the software structure of the electronic device 100.
[0106] Figure 2It is a software architecture block diagram of the electronic device 100 according to an embodiment of the present invention. The hierarchical architecture in this embodiment can be deployed in the REE. The electronic device may further include multiple TEEs. Trusted applications TA (also known as service TAs) can run in each TEE. Optionally, at least one trusted application TA is configured with a proxy application TA (also known as a proxy TA), and then the trusted application TAs can communicate with each other through the proxy application TA. Exemplarily, the first trusted application TA is configured with the first proxy application TA, and the second trusted application TA is configured with the second proxy application TA. Optionally, data can be shared between the trusted application TA and the proxy application through shared memory.
[0107] The hierarchical architecture divides the software into several layers, and each layer has a clear role and division of labor. The layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into multiple layers, from top to bottom are the application layer, the application framework layer, the Android runtime, the system libraries, the hardware abstraction layer, and the kernel layer.
[0108] The application layer may include a series of application packages.
[0109] As Figure 2 shown, the application packages may include application programs such as the settings application, the notification application, the camera, the gallery, the calendar, the call, the map, the navigation, the WLAN, the Bluetooth, the music, the video, the short message, etc.
[0110] The application framework layer provides application programming interfaces (APIs) and programming frameworks for the application programs in the application layer. The application framework layer includes some predefined functions.
[0111] As Figure 2 shown, the application framework layer may include the window manager, the content provider, the view system, the telephone manager, the resource manager, the notification manager, etc.
[0112] The notification manager enables the application program to display notification information in the status bar, can be used to convey messages of the notification type, can automatically disappear after a short stay without user interaction. For example, the notification manager is used to inform that the download is completed, the message reminder, etc. The notification manager can also be a notification that appears in the system top status bar in the form of a chart or a scroll bar text, such as the notification of a background running application program, and can also be a notification that appears in the form of a dialogue window on the screen. For example, prompting text information in the status bar, emitting a prompt sound, the electronic device vibrating, the indicator light flashing, etc.
[0113] The Android Runtime includes core libraries and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.
[0114] The core libraries consist of two parts: one part is the functional functions that the Java language needs to call, and the other part is the core libraries of Android.
[0115] The application layer and the application framework layer run in the virtual machine. The virtual machine executes the Java files of the application layer and the application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.
[0116] The system libraries can include multiple functional modules. For example: Surface Manager, Media Libraries, 3D graphics processing libraries (such as OpenGL ES), 2D graphics engines (such as SGL), etc.
[0117] The Hardware Abstraction Layer is an interface layer located between the operating system kernel and the upper-layer software, and its purpose is to abstract the hardware. The Hardware Abstraction Layer is an abstract interface for the device kernel driver and is used to implement an application programming interface that provides access to the underlying devices for a higher-level Java API framework. HAL contains multiple library modules, such as the business CA corresponding to the business TA, the intelligent sensor hub HAL, the camera HAL, the display HAL, etc. Among them, the TA can include a face TA, and the face TA corresponds to a face CA.
[0118] Each of these library modules implements an interface for a specific type of hardware component. It can be understood that the intelligent sensor hub HAL can provide an interface to access hardware components such as the sensorhub, the camera HAL can provide an interface for the camera Fwk to access hardware components such as the camera, and the display HAL can provide an interface for the display Fwk to access hardware components such as the display. When the system framework layer API requests access to the hardware of the portable device, the Android operating system will load the library module for this hardware component.
[0119] The kernel layer is the layer between the hardware and the software. The kernel layer at least includes a display driver, a camera driver, an audio driver, and a sensor driver. For example, the camera driver is used to control the camera to collect face data.
[0120] The following embodiments will exemplarily illustrate the working process of the software of the electronic device in combination with the scenario of collecting face data.
[0121] For example, when a touch sensor in a terminal device receives a touch operation, a corresponding hardware interrupt is sent to the kernel layer. The kernel layer processes the touch operation into a raw input event (including information such as touch coordinates, touch force, and timestamp of the touch operation). The raw input event is stored in the kernel layer. The application framework layer obtains the raw input event from the kernel layer and identifies the button corresponding to the input event. Taking this touch operation as a face data entry operation, and taking the virtual button corresponding to this face data entry operation as the face entry virtual button of the "Settings application" as an example, the Settings application calls the interface of the application framework layer, and then starts the display driver by calling the kernel layer to display the function interface for collecting face data, and gives face collection indication information on the function interface. At the same time, it calls the camera access interface in the application framework layer to start the face data collection function of the Settings application, and based on the camera driver in the kernel layer, drives one or more cameras to collect one or more frames of face image data in real time. After the camera collects face data, it can be fed back to the CA through the kernel layer and the system library, and the CA can transmit the face data to the TA, and then the TA can store the face data.
[0122] Then, when the intelligent display function of the "Notification application" is turned on, the CA of the HAL layer is called through the framework layer and the system layer, and the TA is notified through the CA to transmit the face data to the intelligent sensor hub, and then the face data can be stored in the storage area of the intelligent sensor hub.
[0123] It can be understood that the method of triggering the CA to notify the TA to transmit the face data to the sensorhub can be set as needed and is not limited herein.
[0124] The following is an illustration with the specific implementation of this application.
[0125] In the embodiment of this application, the methods for the TA to transmit the face data to the sensorhub may include but are not limited to the following methods:
[0126] The first method: As Figure 3A shown, the first trusted application TA in the first secure environment TEE transmits the target data to the intelligent sensor hub through the TA in other secure environments TEE (such as the second trusted application TA in the second secure environment TEE).
[0127] Exemplarily, the first trusted application TA in the first secure environment TEE calls the first proxy application TA to transmit the target data to the second proxy application TA in the second secure environment TEE, and then the second proxy application TA transmits the target data to the storage area of the intelligent sensor hub through the second trusted application TA.
[0128] The second method: As Figure 3BAs shown, the first trusted application TA transmits target data to the intelligent sensing hub through the REE.
[0129] Exemplarily, the first trusted application TA in the first secure environment TEE transmits target data to the client application CA (also known as the service CA) in the REE, and then transmits the target data to the intelligent sensing hub through the intelligent sensing hub HAL.
[0130] Based on any of the above embodiments, the following embodiments respectively illustrate several ways for the first trusted application TA to transmit target data to the intelligent sensing hub.
[0131] The following embodiments first illustrate the case where the first trusted application TA in the first secure environment TEE transmits target data to the intelligent sensing hub through other secure environments.
[0132] Please refer to Figure 4 , Figure 4 , which is a schematic flowchart of another data transmission method provided by the embodiments of the present application. In this embodiment, it is illustrated that the target data includes face data. As Figure 4 shown, the method may include:
[0133] S410. The intelligent sensing hub instructs the client application CA to request face data transmission.
[0134] Among them, the intelligent sensing hub may instruct the client application CA to request face data transmission when the electronic device receives a message, or periodically instruct the client CA to request face data transmission. Optionally, after receiving the target face data, the intelligent sensing hub can be stored in the intelligent sensing hub until the electronic device shuts down.
[0135] S420. The client application CA instructs the first trusted application TA with the first information.
[0136] The steps of this embodiment can refer to the description of S310 and will not be elaborated here.
[0137] S430. In response to the first information, the first trusted application TA transmits the target face data of the first trusted application TA to the first proxy application TA.
[0138] Among them, the first proxy application TA can be understood as an interface for data transmission between the first trusted application TA and the second trusted application TA. The proxy application can monitor and detect information on the network, control access to the internal network, and perform network address translation, etc. In the embodiments of the present application, the proxy application TA can isolate the direct communication between the trusted application TA and the external network, thereby protecting the trusted application TA.
[0139] S440: The first proxy application TA transmits the target face data to the second proxy application TA.
[0140] The second agent application TA may be understood as an interface for data transmission between the second trusted application TA and the first trusted application TA.
[0141] S450: The second agent application TA verifies the calling authority of the first agent application TA.
[0142] S460. When the calling permission of the first proxy application TA is verified to be passed, the second proxy application TA transmits the target face data to the second trusted application TA.
[0143] Wherein, when the first proxy application TA has the permission to call the second trusted application TA, it means that the first proxy application TA can access the second trusted application TA, that is, the first proxy application TA can transmit data to the second trusted application TA.
[0144] Optionally, the second proxy application TA can be configured with a first mapping relationship between the proxy application and the permission, and the first mapping relationship includes the first proxy application TA and the permissions possessed by the first proxy application TA. The second proxy application TA can then verify the calling permissions of the first proxy application TA by querying the first mapping relationship.
[0145] The permissions of the first proxy application TA may include the permission to call the second trusted application TA, or may not include the permission to call the second trusted application TA. The first mapping relationship may be in the form of a pass list or a block list, for example.
[0146] In an embodiment of the present application, the first mapping relationship can be configured in the second security environment TEE to reduce the risk of the first mapping relationship being tampered with. In this way, the accuracy of the verification of the calling permission can be improved, and the security of data transmission can be improved.
[0147] S470 : The second proxy application TA filters the target facial data when the calling permission of the first proxy application TA is not verified.
[0148] Filtering the target facial data may mean not transmitting the target facial data to the second trusted application TA.
[0149] S480. The second trusted application TA transmits the target facial data of the first trusted application TA to the smart sensor hub.
[0150] Among them, the second trusted application TA can be the same or different service TA as the first trusted application TA. For example, assume that the first trusted application TA is a face TA, then the second trusted application can be a face TA or other TA except the face TA.
[0151] It should be noted that the data transmitted between TEEs can be encrypted data or unencrypted data, and there is no restriction here.
[0152] In another possible implementation, in the case where the electronic device is restarted after being powered off, it can also be that after the electronic device is restarted and powered on, the intelligent sensing hub instructs the client CA to request data transmission.
[0153] In one possible implementation, it can also be that the first trusted application TA and the second trusted application TA directly transmit data without going through a proxy application. Then, the first trusted application TA transmits the target face data of the first trusted application TA to the second trusted application TA in response to the first information, and the second trusted application TA transmits the target face data of the first trusted application TA to the intelligent sensing hub. In this way, the data transmission efficiency can be improved.
[0154] In one possible implementation, it can also be that the second proxy application TA directly receives the target face data from the first proxy application TA. In this way, the time required for verifying the call permission can be reduced, and thus the data transmission efficiency can be improved.
[0155] In one possible implementation, the second secure environment TEE includes a first memory area. The second proxy application TA transmits the target face data to the second trusted application TA, including:
[0156] The second proxy application TA writes the target face data into the first memory area, and the second trusted application TA obtains the target face data from the first memory area.
[0157] Among them, the second proxy application TA can write the received target face data into the first memory area. Then, the second trusted application TA can regularly obtain the target face data from the first memory area, and then the second trusted application TA transmits the target face data to the intelligent sensing hub. Among them, the memory area can have a fixed storage space size or a dynamically allocated storage space size. For example, the storage space size of the memory area is dynamically allocated according to the size of the data to be transmitted.
[0158] In an embodiment of the present application, the second proxy application TA writes target face data to the first memory area, and the second trusted application can obtain the target face data from the first memory area. After the second proxy application TA writes one or more target face data within a certain period of time to the first memory area, the second trusted application TA can obtain the one or more written target face data at one time, and then transmit the one or more target face data to the intelligent sensing hub together. In this way, the data transmission efficiency can be improved.
[0159] In another possible implementation, it may also be that the second proxy application TA directly transmits the target face data to the second trusted application TA.
[0160] It should be noted that based on the virtual machine monitor (VMM) and trustzone mechanisms, multiple TEE systems can be supported to run simultaneously. VMM, also known as hypervisor, is an intermediate software layer running between the underlying physical server and the operating system, which allows multiple operating systems and applications to share the hardware.
[0161] Based on any of the above embodiments, the following embodiments illustrate the manner in which the first trusted application TA transmits the target face data to the intelligent sensing hub through the REE.
[0162] Please refer to Figure 5 , Figure 5 which is a schematic flowchart of another data transmission method provided by the embodiment of the present application. As Figure 5 shown, the method may include:
[0163] S510. The electronic device is powered on.
[0164] S520. The intelligent sensing hub HAL generates a key and transmits the key to the client application CA.
[0165] Among them, the key is a parameter that is input in the algorithm for converting plaintext to ciphertext or ciphertext to plaintext. Keys are divided into symmetric keys and asymmetric keys. In this embodiment, the intelligent sensing hub HAL can be configured with various encryption and decryption algorithms. The key in this embodiment can be dynamically allocated to improve the security of data encryption.
[0166] It should be noted that the key can be transmitted regularly to update the key regularly; in addition, it can also be an application at the application layer that, when detecting that a function related to the target face data is triggered, calls the intelligent sensing hub HAL to generate the key and transmit the key.
[0167] S530. The client application CA transmits the key to the first trusted application TA.
[0168] S540. The intelligent sensing hub instructs the client application CA of a face data transmission request.
[0169] Among them, S540 can refer to the description of S410 and will not be elaborated here.
[0170] S550. The client application CA instructs the first trusted application TA of the first information.
[0171] In an embodiment, S540 can refer to the description of any of the above embodiments and will not be elaborated here.
[0172] S560. In response to the first information, the first trusted application TA encrypts the target face data of the first trusted application TA based on a key to obtain the encrypted target face data.
[0173] S570. The first trusted application TA transmits the encrypted target face data to the client application CA.
[0174] S580. The client application CA invokes the intelligent sensing hub HAL.
[0175] S590. The intelligent sensing hub HAL decrypts the encrypted target face data based on a key to obtain the decrypted target face data.
[0176] S600. The intelligent sensing hub HAL transmits the decrypted target face data to the intelligent sensing hub.
[0177] In a possible implementation, it may also be that there is no need to encrypt the target face data. That is to say, in the embodiments of the present application, it may be that the first trusted application TA transmits the unencrypted target face data to the client application CA, and then the client application CA transmits the unencrypted target face data to the intelligent sensing hub.
[0178] In another possible implementation, it may also be that the intelligent sensing hub HAL and the first trusted application TA are pre-configured with a key, then the first trusted application TA can encrypt the data based on the pre-configured key, and the intelligent sensing hub HAL can decrypt the data based on the pre-configured key.
[0179] In another possible implementation, it may also be that other modules decrypt the data. For example, the intelligent sensing hub decrypts the received data.
[0180] In a possible implementation, the first secure environment TEE includes a second memory area, and the second memory area is used to store the target face data of the first trusted application TA. The first trusted application TA transmits the target face data of the first trusted application TA to the intelligent sensing hub in response to the first information, including:
[0181] The first trusted application TA writes the target face data into the second memory area in response to the first information, and the target face data stored in the second memory area is used for transmission to the intelligent sensing hub.
[0182] In the embodiments of the present application, the target face data can be stored in the second memory area for management, and the first trusted application TA can store multiple target face data in the second memory area, so as to read multiple target face data from the second memory area at one time. In addition, since the second memory area is located in the first secure environment TEE, the storage security of the target face data is also guaranteed.
[0183] It should be noted that if the first trusted application TA transmits the target face data to the second trusted application TA through the first proxy application TA, the first proxy application TA obtains the data from the second memory area.
[0184] It can be understood that the first data transmission path of the second secure environment TEE and the second data transmission path of the non-secure environment REE can exist simultaneously, so as to improve the success rate of data transmission.
[0185] It should be noted that the trigger condition for the target face data to be transmitted from the first secure environment TEE to the intelligent sensing hub can also be that the intelligent sensing hub requests the first trusted application TA to transmit when it needs to perform data comparison or verification tasks. Exemplarily, the intelligent sensing hub transmits a request to the client CA through the intelligent sensing hub HAL, and the client CA instructs the first information to the first trusted application TA based on the request.
[0186] In the above embodiments, the data transmission method of the present solution is described under the condition that the target data has been stored in the first secure environment TEE.
[0187] Therefore, in the following embodiments, on the basis of any of the above embodiments, the situation of how the target data is collected and how the target data is stored in the first secure environment TEE is described.
[0188] Please refer to Figure 6 , Figure 6Schematic flowchart of another data transmission method provided by an embodiment of this application. In this embodiment, it is exemplified that the target data includes biometric data. Biometric data may include, but is not limited to, at least one of face data, fingerprint data, voiceprint data, and iris data, etc., which can reflect biometric characteristics. Among them, face data and iris data can be collected by a camera, and voiceprint data can be collected by a fingerprint data collection module or a display screen integrated with a fingerprint data collection module, etc. Voiceprint data can be collected by a microphone.
[0189] As Figure 6 shown, the method may include:
[0190] S602. The settings application transmits a data collection request to the data collection module of the electronic device in response to a face entry operation.
[0191] Among them, the "settings application" can be used to trigger the application for face entry, which can be a system application pre-installed on the electronic device or an application program installed by the user on the electronic device. The face entry operation can refer to an operation that triggers the electronic device to collect face data, including but not limited to at least one of touch operations (such as click operations) and voice control operations. Exemplarily, the "settings application" of the electronic device displays a first interface, and the first interface includes a face entry button. When the electronic device detects a click operation on the face entry button, the "settings application" controls the hardware of the electronic device to collect the first face data through the framework layer, system layer, driver layer, etc.
[0192] S604. The data collection module starts and collects the first face data in response to the data collection request.
[0193] In another possible implementation, the data collection module can be started periodically or in real time so that face data can be quickly collected when needed.
[0194] S606. The data collection module transmits the first face data to the intelligent sensing hub HAL through the client application CA.
[0195] S608. The intelligent sensing hub HAL determines whether the first face data meets the data quality requirements.
[0196] Among them, the data quality requirements corresponding to different face data can be different or the same. Exemplarily, taking face data as an example, the data quality requirements can be that the face data is complete and there is no situation such as blinking that affects recognition. Taking fingerprint data as an example, the data quality requirements can be that 90% of the complete fingerprint is collected and the fingerprint data is clear, etc., which can be set according to the actual situation and are not limited here.
[0197] When the intelligent sensing hub HAL determines that the first face data meets the data quality requirements, it indicates the second information to the client application CA.
[0198] Among them, the second information is used to indicate the storage of the first face data. Optionally, the second information may include a data storage indication.
[0199] S612: In response to the second information, the client application CA indicates the third information and the first face data to the first trusted application TA.
[0200] Among them, the third information is used to indicate the storage of the first face data. Optionally, the third information may include a data storage indication.
[0201] S614: In response to the third information, the first trusted application TA stores the first face data as the target face data.
[0202] S616: When the intelligent sensing hub HAL determines that the first face data does not meet the data quality requirements, it extracts and stores the first face feature value based on the first face data.
[0203] Among them, the first face feature value can reflect the face to a certain extent and can be used as a reference face feature value for comparison, such as comparing with the second face feature value. In other words, the first face data and the second face data belong to the face data of the same user, and the data quality of the second face data is better. Exemplarily, the face feature value can indicate the contour features, facial features, etc. of the face. If it is fingerprint data, the corresponding fingerprint feature value can indicate parts of the fingerprint.
[0204] Optionally, the complete first face data cannot be restored based on the first face feature value. In this way, it can not only compare the second face feature value of the second face data to confirm the legality of the second face data, but also reduce the risk of leakage of the first face data caused by storing the first face feature value in the non-secure environment REE.
[0205] It should be noted that in this embodiment, when it is determined that the first face data does not meet the data quality requirements, the first face data may or may not be stored, which can be set according to needs.
[0206] S618: The data acquisition module is started and the second face data is acquired.
[0207] Among them, the second face data can be collected periodically, or can be collected when the electronic device detects the presence of a living being, or can also be collected when the electronic device detects relevant trigger operations related to face data collection (such as unlocking operations, payment operations). After the electronic device collects the second face data, it transmits the second face data to the client application CA.
[0208] It should be noted that regardless of whether the first face data is stored, the second face data can continue to be collected.
[0209] Optionally, if the first face data is stored, the data quality between the second face data and the first face data can be compared. If the data quality of the second face data is higher, the second face data is stored.
[0210] S620. The data collection module transmits the second face data to the intelligent sensing hub HAL through the client application CA.
[0211] S622. The intelligent sensing hub HAL extracts the second face feature value based on the second face data, and matches the second face feature value with the first face feature value.
[0212] Among them, the matching can be to perform feature comparison. When the similarity between the face feature values is greater than the similarity threshold, it can be considered that the matching is successful, otherwise the matching fails.
[0213] S624. When the second face feature value matches the first face feature value successfully, the intelligent sensing hub HAL determines whether the second face data meets the data quality requirements.
[0214] S626. When the second face data meets the data quality requirements, the intelligent sensing hub HAL indicates the fourth information to the client application CA.
[0215] Among them, the fourth information is used to indicate storing the second face data. In this embodiment, the intelligent sensing hub HAL indicates the fourth information to the client application CA only when the second face feature value matches the first face feature value successfully and the second face data meets the data quality requirements.
[0216] It should be noted that if the second face feature value does not match the first face feature value successfully, or the second face data does not meet the data quality requirements, the second face data is filtered.
[0217] S628. In response to the fourth information, the client application CA indicates the fifth information and the second face data to the first trusted application TA.
[0218] Among them, the fifth information is used to indicate storing the second face data.
[0219] The S630, the first trusted application TA stores the second face data as the target face data in response to the fifth piece of information.
[0220] In a possible implementation, it can also be directly storing the first face data.
[0221] In a possible implementation, it can also be that other modules in the non-secure environment REE are used to judge unmet data quality requirements, extract face feature values, and match between face feature values, etc.
[0222] In another possible implementation, it can also be chosen not to match between the first face feature value and the second face feature value, or not to judge whether the second face data meets the data quality requirements.
[0223] It can be understood that in the embodiments of the present application, the target face data can also be replaced with other data, such as at least one of fingerprint data, voiceprint data, and iris data, etc.
[0224] It can be understood that the target data can also include data other than biometric data, such as non-biometric data, which is not limited herein.
[0225] The above embodiments illustrate the transmission of the target data between the TEE and the intelligent sensing hub. The following embodiments illustrate the scenario of how the intelligent sensing hub uses the target data for comparison based on any of the above embodiments.
[0226] Scenario 1: If the face data of user A is entered into the electronic device, then at this time, if the electronic device receives a message, at the first moment, if the electronic device detects that the user using the electronic device is user A, then the message is displayed, as Figure 7 shown.
[0227] At the second moment, if the electronic device detects that the user using the electronic device is user B, or if the electronic device detects that the user using the electronic device is user A, but there are also user B and user C beside user A, then the electronic device hides the message, as Figure 8 shown.
[0228] In this embodiment, the notification application is configured to enable the intelligent display function. Specifically, when the electronic device receives a message, the intelligent sensing hub is called to compare the biometric data to be compared collected by the electronic device with the target biometric data; when the biometric data to be compared is successfully compared with the target biometric data, the intelligent sensing hub indicates the sixth information to the notification application, or when the biometric data to be compared fails to be compared with the target biometric data, the intelligent sensing hub indicates the seventh information to the notification application. The sixth information is used to indicate the display of the message, and the seventh information is used to indicate the hiding of the message; the notification application displays the message based on the received sixth information, or hides the message based on the received seventh information.
[0229] At the third moment, if the electronic device detects user A again, the electronic device can display the message again at this time.
[0230] At the fourth moment, if the electronic device detects a message clearing operation, it will no longer make a judgment on message hiding or display.
[0231] Among them, displaying the message may mean displaying the content of the message in plain text. Therefore, the message may mean not prompting the message notification, or prompting that there is a message notification but the content of the message is not displayed. The intelligent sensing hub can be configured with a data comparison algorithm.
[0232] It should be noted that the acquisition and storage of the target face data can be referred to the description of any of the above embodiments, and will not be elaborated here.
[0233] It should be noted that the intelligent sensing hub can also compare the face data to be compared collected by the electronic device with the target face data in real time, so that when the electronic device receives a message, it can quickly obtain the feature data comparison result, and then determine whether to display the message.
[0234] The technical solutions of the present application will be described in detail below with specific embodiments. These specific embodiments can be implemented independently or in combination with each other. For the same or similar concepts or processes, they may not be elaborated in some embodiments.
[0235] Among them, the data transmission method provided by the embodiment of the present application includes:
[0236] The client application CA indicates the first information to the first trusted application TA. In response to the first information, the first trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub.
[0237] Among them, the first information is used to indicate the target data for transmitting the first trusted application TA. Optionally, the first information may include a data transmission command. The first trusted application TA may be a TA related to the service, so the trusted application TA may also be referred to as the service TA. Optionally, the service TA may be a service TA with certain requirements for data security, such as a face TA. The client CA may be a CA related to the first trusted application TA. For example, if the first trusted application TA is a face TA, the client CA may be a face CA.
[0238] In the embodiment of the present application, when it is detected that a function related to the target data is triggered, the client application CA is called to indicate the first information to the first trusted application TA. Exemplarily, for example, when it is detected that the function of unlocking the screen is triggered, or the intelligent notification function is triggered, etc., the client CA is called to indicate the first information.
[0239] The target data may be data with certain requirements for security and confidentiality, such as at least one of face data, fingerprint data, voiceprint data, and iris data. The target data of the first trusted application TA may be stored in the first secure environment TEE where the first trusted application TA is located.
[0240] In the embodiment of the present application, the client application CA indicates the first information to the first trusted application TA, and then the first trusted application TA may transmit the target data to the intelligent sensing hub based on the first information, so that communication between the trusted application TA and the intelligent sensing hub can be realized, and in this way, the communication methods of the trusted application TA can be enriched.
[0241] The embodiment of the present application may refer to Figure 4 the relevant descriptions and will not be elaborated here.
[0242] In the embodiment of the present application, the manner in which the first trusted application TA sends the target data to the intelligent sensing hub may refer to the description of any of the above embodiments and will not be elaborated here.
[0243] It should be noted that it may also be that the first trusted application TA directly transmits data to the intelligent sensing hub.
[0244] In a possible implementation manner, the electronic device further includes a second secure environment TEE and a second trusted application TA running in the second secure environment TEE. The first trusted application TA responds to the first information and transmits the target data of the first trusted application TA to the intelligent sensing hub, which may include:
[0245] The first trusted application TA responds to the first information and transmits the target data of the first trusted application TA to the second trusted application TA; the second trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub through the first interface.
[0246] The data transmission method of this embodiment can refer to Figure 4 The relevant description is not repeated here.
[0247] In another possible implementation, the first trusted application TA transmits target data of the first trusted application TA to the smart sensor hub in response to the first information, including:
[0248] In response to the first information, the first trusted application TA transmits target data of the first trusted application TA to the client application CA; and the client application CA transmits the target data of the first trusted application TA to the smart sensor hub.
[0249] In the embodiments of this application, please refer to Figure 5 The relevant description is not repeated here.
[0250] It should be noted that the module names involved in the embodiments of the present application can be defined as other names as long as the functions of each module can be achieved, and there is no specific restriction on the names of the modules.
[0251] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of the present application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.
[0252] The data transmission method according to the embodiment of the present application has been described above. The following describes the apparatus for performing the above method provided by the embodiment of the present application. Those skilled in the art will appreciate that the method and apparatus can be combined and referenced with each other, and the relevant apparatus provided by the embodiment of the present application can perform the steps in the above-mentioned list sorting method.
[0253] The data transmission method provided in the embodiment of the present application can be applied to electronic devices with communication functions. The electronic devices include terminal devices. The specific device form of the terminal device can refer to the above related descriptions and will not be repeated here.
[0254] An embodiment of the present application provides a terminal device, which includes: a processor and a memory; the memory stores computer-executable instructions; the processor executes the computer-executable instructions stored in the memory, so that the terminal device executes the above method.
[0255] like Figure 9This is a schematic structural diagram of a chip provided by an embodiment of the present application. The chip 900 includes one or more (including two) processors 901, a communication line 902, a communication interface 903, and a memory 904.
[0256] In some embodiments, the memory 904 stores the following elements: executable modules or data structures, or subsets thereof, or extended sets thereof.
[0257] The methods described in the embodiments of the present application above can be applied to the processor 901 or implemented by the processor 901. The processor 901 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above methods can be completed by the integrated logic circuit in the hardware of the processor 901 or by instructions in software form. The above-mentioned processor 901 may be a general-purpose processor (e.g., a microprocessor or a conventional processor), a digital signal processor (DSP), an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate, transistor logic devices, or discrete hardware components. The processor 901 can implement or execute the various processing-related methods, steps, and logic block diagrams disclosed in the embodiments of the present application.
[0258] The steps of the methods described in combination with the embodiments of the present application can be directly implemented by a hardware decoding processor or implemented by a combination of hardware and software modules in the decoding processor. Among them, the software module can be located in a mature storage medium in the art such as a random access memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable read-only memory (EEPROM). This storage medium is located in the memory 904, and the processor 901 reads the information in the memory 904 and combines its hardware to complete the steps of the above methods.
[0259] The processor 901, the memory 904, and the communication interface 903 can communicate with each other through the communication line 902.
[0260] In the above embodiments, the instructions stored in the memory for the processor to execute can be implemented in the form of a computer program product. Among them, the computer program product can be pre-written in the memory or downloaded and installed in the memory in software form.
[0261] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the above method is implemented. The methods described in the above embodiments can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. If implemented in software, the functions can be stored on or transmitted over a computer-readable medium as one or more instructions or codes. The computer-readable medium can include a computer storage medium and a communication medium, and can also include any medium that can transfer a computer program from one place to another. The storage medium can be any target medium accessible by a computer.
[0262] In a possible implementation, the computer-readable medium may include RAM, ROM, a compact disc read-only memory (CD-ROM), or other optical disc storage, a magnetic disk storage, or other magnetic storage device, or any other medium targeted to carry the required program code in the form of instructions or data structures and accessible by a computer. Moreover, any connection is properly termed a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, Digital Subscriber Line (DSL), or wireless technologies such as infrared, radio, and microwave, then the coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of the medium. As used herein, disk and optical disc include optical disc, laser disc, optical disc, Digital Versatile Disc (DVD), floppy disk, and Blu-ray disc, where disks typically reproduce data magnetically, while optical discs utilize lasers to optically reproduce data. Combinations of the above should also be included within the scope of computer-readable media.
[0263] The embodiments of the present application provide a computer program product. The computer program product includes a computer program. When the computer program is run, the computer is caused to execute the above method.
[0264] The embodiments of the present application are described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to the embodiments of the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams, and combinations of flows and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processing unit of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable devices to generate a machine, such that the instructions executed by the processing unit of the computer or other programmable data processing device generate means for implementing the processes Figure 1An apparatus for a process or processes and / or functions specified in one or more blocks Figure 1 An apparatus for the functions specified in one or more blocks
[0265] In the above specific embodiments, the object, technical solution and beneficial effects of the present invention have been further described in detail. It should be understood that the above are only specific embodiments of the present invention and are not used to limit the protection scope of the present invention. Any modifications, equivalent replacements, improvements, etc. made on the basis of the technical solution of the present invention shall be included in the protection scope of the present invention.
Claims
1. A data transmission method, characterized in that, Applied to an electronic device, the electronic device includes a first trusted execution environment (TEE), an intelligent sensing hub, a non-secure environment (REE), a client application (CA) running in the non-secure environment REE, and a first trusted application (TA) running in the first trusted execution environment TEE. The method includes: The client application CA instructs the first trusted application TA with first information, where the first information is used to indicate the transmission of target data of the first trusted application TA; In response to the first information, the first trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub.
2. The method according to claim 1, wherein The electronic device further includes a second trusted execution environment TEE and a second trusted application TA running in the second trusted execution environment TEE. The first trusted application TA transmitting the target data of the first trusted application TA to the intelligent sensing hub in response to the first information includes: In response to the first information, the first trusted application TA transmits the target data of the first trusted application TA to the second trusted application TA; The second trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub.
3. The method according to claim 2, wherein The electronic device further includes a first proxy application TA running in the first trusted execution environment TEE and a second proxy application TA running in the second trusted execution environment TEE. The first trusted application TA transmitting the target data of the first trusted application TA to the second trusted application TA includes: The first trusted application TA transmits the target data of the first trusted application TA to the first proxy application TA; The first proxy application TA transmits the target data to the second proxy application TA; The second proxy application TA transmits the target data to the second trusted application TA.
4. The method according to claim 3, characterized in that, Before the second proxy application TA transmits the target data to the second trusted application TA, it further includes: The second proxy application TA verifies the call permission of the first proxy application TA, so as to transmit the target data to the second trusted application TA when the call permission verification of the first proxy application TA passes.
5. The method according to any one of claims 1-4, characterized in that, The first trusted application TA transmitting the target data of the first trusted application TA to the intelligent sensing hub in response to the first information includes: In response to the first information, the first trusted application TA transmits the target data of the first trusted application TA to the client application CA; The client application CA transmits the target data of the first trusted application TA to the intelligent sensing hub.
6. The method according to claim 5, wherein Before the first trusted application TA transmits the target data of the first trusted application TA to the client application CA, it further includes: The first trusted application TA encrypts the target data of the first trusted application TA to obtain encrypted target data; The non-secure environment REE further includes an intelligent sensing hub HAL. The client application CA transmitting the target data of the first trusted application TA to the intelligent sensing hub includes: The client application CA invokes the intelligent sensing hub HAL to decrypt the encrypted target data to obtain the decrypted target data; The intelligent sensing hub HAL transmits the decrypted target data to the intelligent sensing hub.
7. The method according to claim 6, wherein The method further includes: The intelligent sensing hub HAL generates a key and transmits the key to the client application CA; The client application CA transmits the key to the first trusted application TA; The first trusted application TA encrypts the target data of the first trusted application TA, including: The first trusted application TA encrypts the target data of the first trusted application TA based on the key; The intelligent sensing hub HAL decrypts the encrypted target data, including: The intelligent sensing hub HAL decrypts the encrypted target data based on the key.
8. The method according to any one of claims 1 to 7, characterized in that The target data includes target biometric data, and the electronic device further includes a settings application running in the non-secure environment REE. The method further includes: The settings application, in response to a biometric entry operation, collects first biometric data through the electronic device; When the non-secure environment REE determines that the first biometric data meets the data quality requirements, it indicates second information to the client application CA, where the second information is used to indicate storing the first biometric data; The client application CA, in response to the second information, indicates third information and the first biometric data to the first trusted application TA, where the third information is used to indicate storing the first biometric data; The first trusted application TA, in response to the third information, stores the first biometric data as the target biometric data.
9. The method according to claim 8, wherein The non-secure environment REE includes the intelligent sensing hub HAL. The method further includes: Determine whether the first biometric data meets the data quality requirements through the intelligent sensing hub HAL.
10. The method according to claim 8 or 9, characterized in that The method further includes: When the non-secure environment REE determines that the first biometric data does not meet the data quality requirements, it extracts and stores the first biometric feature value based on the first biometric data; The client application CA receives the second biometric data collected by the electronic device; The non-secure environment REE extracts a second biometric feature value based on the second biometric data and matches the second biometric feature value with the first biometric feature value; When the second biometric feature value matches the first biometric feature value and the second biometric data meets the data quality requirements, the non-secure environment REE indicates fourth information to the client application CA, where the fourth information is used to indicate storing the second biometric data; The client application CA, in response to the fourth information, indicates fifth information and the second biometric data to the first trusted application TA, where the fifth information is used to indicate storing the second biometric data; In response to the fifth piece of information, the first trusted application TA stores the second biometric data as target biometric data.
11. The method according to claim 10, wherein The non-secure environment REE includes the intelligent sensing hub HAL. The secure environment REE extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value, including: The intelligent sensing hub HAL extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value.
12. The method according to any one of claims 1-11, characterized in that, The target data includes target biometric data. The electronic device further includes a notification application running in the non-secure environment REE. The notification application is configured to enable an intelligent display function. After the first trusted application TA transmits the target data of the first trusted application TA to the intelligent sensing hub in response to the first piece of information, it further includes: When the electronic device receives a message, the intelligent sensing hub compares the biometric data to be compared collected by the electronic device with the target biometric data; The intelligent sensing hub indicates a sixth piece of information to the notification application when the biometric data to be compared matches the target biometric data, or indicates a seventh piece of information to the notification application when the biometric data to be compared does not match the target biometric data. The sixth piece of information is used to indicate displaying the message, and the seventh piece of information is used to indicate hiding the message; The notification application displays the message based on the received sixth piece of information or hides the message based on the received seventh piece of information.
13. An electronic device, characterized in that, The electronic device includes: one or more processors and a memory; the memory is coupled to the one or more processors. The memory is used to store computer program code, and the computer program code includes computer instructions. The one or more processors call the computer instructions to cause the electronic device to execute the method according to any one of claims 1 to 12.
14. A chip system, characterized in that, The chip system is applied to an electronic device. The chip system includes one or more processors, and the one or more processors are used to call computer instructions to cause the electronic device to execute the method according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer instructions. When the computer instructions run on an electronic device, they cause the electronic device to execute the method according to any one of claims 1 to 12.
16. A computer program product, characterized in that, The computer program product includes computer program code. When the computer program code runs on an electronic device, it causes the electronic device to execute the method according to any one of claims 1 to 12.
Citation Information
Patent Citations
Safety control method in TEE and device thereof, equipment and storage medium
CN113645045A
Data transmission method and device
CN115080975A
Payment method and electronic equipment
CN116485403A
Securely routing sensor data from sensors to a trusted execution environment (TEE)
US20170180386A1
Electronic device providing electronic payment function and operation method thereof
WO2016137300A1