Data transmission method and related apparatus

By directly transmitting data to the sensor control center through the TEE, the problem of data transmission security in terminal devices is solved, avoiding the use of an insecure REE environment, thus achieving higher security and reliability.

CN120408623BActive Publication Date: 2026-05-15HONOR DEVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410114966.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-01-25
Publication Date
2026-05-15
Estimated Expiration
2044-01-25

AI Technical Summary

Technical Problem

Transmitting trusted application (TA) data through a generic execution environment (REE) in terminal devices poses security risks and affects the security of data transmission.

Method used

By transmitting data directly to the sensor hub from the Trusted Execution Environment (TEE), avoiding insecure REE environments, and utilizing indication information between the client application (CA) and the trusted application (TA), data transmission is ensured in a secure environment.

Benefits of technology

This improves the security of data transmission from the TEE to the sensor control center, reduces the risk of data exposure in unsafe environments, and enhances the security and reliability of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120408623B_ABST
    Figure CN120408623B_ABST
Patent Text Reader

Abstract

The embodiment of the application provides a kind of data transmission method and related device, it is related to terminal technical field.The method comprises: client application CA indicates first information to first trusted application TA, first information indicates the target data of transmission first trusted application TA.First trusted application TA responds to first information, and write target data to first memory area, and indicate second information to client application CA, second information is used to indicate target storage address of target data in first memory area, and first memory area is the memory area in trusted execution environment TEE.Client application CA indicates third information to sensor control center, and third information includes second information or address information determined based on second information.Sensor control center determines target storage address based on third information, and obtains target data from first memory area based on target storage address.In this way, the security of data from TEE transmission to sensorhub can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of terminal technology, and in particular to a data transmission method and related apparatus. Background Technology

[0002] With the rapid development of terminal technology, improving terminal security has become increasingly important. Currently, to enhance data security in electronic devices, secure environments, such as Trusted Execution Environments (TEEs), are employed. Within a TEE, trusted applications (TAs) run. A TA is an application within the TEE that performs a specific function. Because computations are performed within the TEE, it offers high security. Each TA has one or more corresponding client applications (CAs) within a Rich Execution Environment (REE). In the REE environment, information can be transmitted to the TEE environment via the CA's interface to execute the TA, complete its corresponding function, and return the computation result.

[0003] In related technologies, it is necessary to transmit data of Trusted Applications (TAs). When transmitting data of Trusted Applications (TAs), the data is mainly transmitted through the REE environment.

[0004] However, transmitting data through an REE environment carries certain security risks. Summary of the Invention

[0005] This application provides a data transmission method and related apparatus, applicable to the field of terminal technology. By transmitting data from a trusted application (TA) to a sensor control center (sensor hub) without passing through a relay exchange (REE), the security of data transmission from the TEE to the sensor hub can be improved.

[0006] In a first aspect, embodiments of this application propose a data transmission method applied to an electronic device, the electronic device including a Trusted Execution Environment (TEE), a sensor control center, a first trusted application (TA) running on the TEE, a general execution environment (REE), and a client application (CA) running on the REE. The method includes:

[0007] The client application (CA) instructs a first trusted application (TA) to transmit target data. In response to the first information, the TA writes the target data to a first memory area and instructs the client application (CA) to transmit second information, indicating the target storage address of the target data within the first memory area, which is a memory area in a Trusted Execution Environment (TEE). The client application (CA) then instructs a third information to the sensor control center, which includes the second information or address information determined based on the second information. The sensor control center determines the target storage address based on the third information and retrieves the target data from the first memory area based on the target storage address.

[0008] Electronic devices can be deployed with an operating system (OS) or a real-time operating system (RTOS). The security of a general-purpose execution environment (REE) is lower than that of a trusted execution environment (TEE). Therefore, compared to a trusted execution environment (TEE), a general-purpose execution environment (REE) is considered an insecure environment, while a trusted execution environment (TEE) is considered a secure environment.

[0009] The first memory area is used to store the target data. Optionally, the storage size of the first memory area generally needs to be greater than or equal to the size of the target data. Specifically, the first memory area can be fixed or dynamically adjusted, and can be set as needed; no limitation is made here. In this embodiment, if the storage size of the first memory area is dynamically adjusted, the first memory area can be dynamically created based on the size of the target data when it is needed to transmit the target data.

[0010] The first trusted application (TA) can be a business-related TA, hence it can also be called a business TA. Optionally, the business TA can be a business TA with certain data security requirements, such as a face recognition TA. The client CA can be a CA related to the first trusted application TA. For example, if the first trusted application TA is a face recognition TA, then the client CA can be a face recognition CA.

[0011] Optionally, the client application CA can indicate the second information to the sensor control center. The sensor control center then determines the target storage address based on the second information and retrieves the target data from the first memory area based on the target storage address. Alternatively, the client application CA can determine the target storage address based on the second information and then transmit the target storage address as third information to the sensor control center. In this case, the sensor control center can directly retrieve the target data from the first memory area based on the target storage address.

[0012] In this embodiment, the client application CA indicates first information to the first trusted application TA. Then, in response to the first information, the first trusted application TA writes target data to the first memory area and indicates second information to the client application CA. Then, the client application CA indicates third information to the sensor control center. The third information includes the second information or address information determined based on the second information. Then, the sensor control center determines the target storage address based on the third information and retrieves the target data from the first memory area based on the target storage address. That is to say, during the process of the target data being transmitted from the trusted application of the TEE to the sensor control center, the target data can bypass the general execution environment REE. This can reduce the insecurity that may be caused by the data passing through the general execution environment REE, thereby improving the security of data transmission from the TEE to the sensor control center.

[0013] In conjunction with the first aspect, in one possible implementation, the data format of the target data includes the content of the target data, and at least one of the first instruction information, the second instruction information, the third instruction information, the fourth instruction information, the fifth instruction information, the sixth instruction information, or the seventh instruction information;

[0014] The first indication information is used to indicate the total length of the target data; the second indication information is used to indicate the version number of the target data; the third indication information is used to indicate the acquisition time of the target data; the fourth indication information is used to indicate the number of target data; the fifth indication information is used to indicate the length of a single target data; the sixth indication information is used to indicate the type of a single target data; and the seventh indication information is used to indicate the hash value of the target data.

[0015] The target data can be in a pre-defined format, allowing the sensor control center to accurately parse and extract its content upon receipt. The target data can contain information requiring security and confidentiality, such as at least one of the following: facial images, fingerprint images, voiceprints, and iris images.

[0016] The target storage address range can be determined based on the total length and target storage address of the target data. The acquisition time refers to the time the target data was collected; the sensor control center can then determine whether the data content has been received before based on the acquisition time. If the data content has been received, it can be ignored. Based on the number and length of target data, each target data point can still be accurately acquired even when there are multiple target data points. The type of target data can be images, processing results, etc. The hash value of the target data can determine how the content is encoded, allowing for decoding using the corresponding decoding method. The version number of the target data can determine which hash algorithm is used to compress the content.

[0017] It should be noted that the number of bytes for the first, second, third, fourth, fifth, sixth, or seventh indication information can be fixed, for example, each indication information occupies 4 bytes. The content of the target data, however, can be of dynamic size. For example, a 640*480 image has a size of 450K (640*480*3 / 2=450K). Another example is a 1024*768 image, which has a size of 1152K (1024*768*3 / 2=1152K).

[0018] For example, one type of business data information format may be as follows:

[0019] Total length of business data: 4 bytes.

[0020] Business data information version number: 4 bytes.

[0021] Business data timestamp: 4 bytes.

[0022] Number of business data: 4 bytes.

[0023] The length of business data 1 is 4 bytes.

[0024] Business data 1 type: 4 bytes (image, processing result, etc.).

[0025] The content of business data 1: XXX bytes (dynamic size, for example, a 640*480 image, the size is 450K (640*480*3 / 2=450K)).

[0026]

[0027] The length of business data N is 4 bytes.

[0028] The type of business data N is 4 bytes.

[0029] The content of business data N: XXX bytes (dynamic size, for example, a 1024*768 image, the size is 1152K (1024*768*3 / 2=1152K)).

[0030] In conjunction with the first aspect, in one possible implementation, the third information includes the second information, which includes a target address index. The sensor control center is configured with a mapping relationship between the address index and the storage address. The sensor control center determines the target storage address based on the third information, including:

[0031] The sensor control center determines the target storage address based on the target address index and mapping relationship.

[0032] The target address index can be used as a handle to determine the target storage address.

[0033] In this embodiment, the target storage address is determined by the sensor control center based on the target address index and mapping relationship. That is, the target storage address is determined on the sensor control center side. In this way, the risk of the target address being leaked in the general execution environment REE can be reduced, thereby improving the security of data storage.

[0034] In conjunction with the first aspect, in one possible implementation, before the sensor control center retrieves the target data from the first memory area based on the target storage address, the following steps are also included:

[0035] The first trusted application (TA) verifies the access permissions of the sensor control center, and if the access permissions of the sensor control center are verified, the sensor control center is allowed to obtain target data from the first memory area.

[0036] In this embodiment, by verifying the access permissions of the sensor control center, and only allowing the sensor control center to obtain target data from the first memory area if the access permission verification is successful, the security of data transmission can be improved.

[0037] In conjunction with the first aspect, in one possible implementation, after the sensor control center obtains the target data from the first memory area based on the target storage address, it further includes:

[0038] The sensor control center acquires the data to be compared; the sensor control center compares the data to be compared with the target data to obtain the data comparison result; the sensor control center writes the data comparison result to the second memory area, which is the memory area in the Trusted Execution Environment (TEE).

[0039] In this embodiment, the sensor control center can not only obtain target data from the Trusted Execution Environment (TEE), but also transmit data comparison results to the TEE, thus enriching the communication methods between the sensor control center and the TEE.

[0040] In one possible implementation, the electronic device also includes a payment application running in a general execution environment (REE) and a second trusted application (TA) running in a trusted execution environment (TEE). The target data includes target biometric data, and the data to be compared includes first biometric data to be compared, which is biometric data collected by the electronic device in response to a payment operation by the payment application.

[0041] Correspondingly, after the sensor control center writes the data comparison results to the second memory area, it also includes:

[0042] The first trusted application (TA) retrieves the data comparison results from the second memory area and transmits the data comparison results to the second trusted application (TA). The second trusted application (TA) then transmits the data comparison results to the payment application; the payment application makes payment or refuses payment based on the data comparison results.

[0043] The second trusted application (TA) can be a payment TA. Optionally, if the data comparison result indicates that the target biometric data and the first biometric data to be compared are successfully matched, the payment application can proceed with the payment; if the data comparison result indicates that the target biometric data and the first biometric data to be compared are unmatched, the payment application can refuse the payment.

[0044] Among them, "payment application" can be used to trigger applications on electronic devices, which can be pre-installed system applications on electronic devices or applications installed by users on electronic devices.

[0045] It should be noted that "payment application" refers to an application with payment functionality, and does not specifically refer to an application that can only perform payment functionality.

[0046] In this embodiment, a first trusted application (TA) obtains the data comparison result from the second memory area, transmits the data comparison result to the second trusted application (TA), and then the second trusted application (TA) transmits the data comparison result to the payment application. The payment application then makes or rejects payment based on the data comparison result, thus improving payment security. Furthermore, since the data comparison result is obtained through the first trusted application (TA) and then transmitted to the second trusted application (TA), the communication interface between the trusted application (TA) and the memory area is reduced. This limits the number of trusted applications (TAs) that can read data from the second memory area, thereby improving the security of data comparison result transmission and ultimately increasing the reliability of the data comparison result.

[0047] In another possible implementation, messages can be displayed or hidden based on data comparison results. For example, the first trusted application (TA) transmits the data comparison results to the notification application through the client CA, and the notification application displays or hides the received messages based on the data comparison results.

[0048] In this embodiment, the data comparison results are transmitted to the client CA through the first trusted application TA. Compared with the data comparison results transmitted from the sensor control center to the client CA through the sensor control center HAL, the data comparison results have fewer transmission links in the insecure environment. This can further improve the transmission security of the data comparison results.

[0049] In conjunction with the first aspect, in one possible implementation, the target data includes target biometric data, the electronic device also includes a settings application running in a general execution environment (REE), and the method further includes:

[0050] The application is configured to respond to biometric data entry operations by collecting first biometric data through an electronic device; the Trusted Execution Environment (TEE) stores the first biometric data as target biometric data if it determines that the first biometric data meets the data quality requirements.

[0051] The "Settings app" can be an application used to trigger biometric data entry. It can be a pre-installed system application on the electronic device or an application installed by the user. Biometric data entry can refer to any operation that triggers the electronic device to collect biometric data, including but not limited to at least one of touch operations (e.g., click operations) and voice control operations. For example, the electronic device's "Settings app" displays a first interface, which includes a biometric data entry control. When the electronic device detects a click operation on the biometric data entry control, the "Settings app" controls the hardware of the electronic device to collect the first biometric data through the framework layer, system layer, and driver layer.

[0052] Biometric data may include, but is not limited to, at least one of the following: facial data, fingerprint data, voiceprint data, and iris data, all of which reflect biometric characteristics. Facial and iris data can be collected via a camera, while voiceprint data can be collected via a fingerprint data acquisition module or a display screen integrated with a fingerprint data acquisition module. Voiceprint data can be collected via a microphone.

[0053] In this embodiment, by ensuring that the first biometric data meets the data quality requirements before allowing the first trusted application (TA) to store the first biometric data, the effectiveness of the biometric data stored by the first trusted application (TA) can be improved. Furthermore, by using a TEE (Technical Environment Execution Environment) to determine whether the data meets the quality requirements, that is, by processing the biometric data within the TEE environment as much as possible, the security of the biometric data can be improved, and the security risks of the biometric data can be reduced.

[0054] In conjunction with the first aspect, in one possible implementation, the first trusted application (TA) determines whether the first biometric data meets the data quality requirements, and the first trusted application (TA) stores the target biometric data.

[0055] In conjunction with the first aspect, in one possible implementation, the data transmission method further includes:

[0056] If the Trusted Execution Environment (TEE) determines that the first biometric data does not meet the data quality requirements, it extracts and stores the first biometric value based on the first biometric data; the TEE acquires the second biometric data collected by the electronic device; the TEE extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value; if the TEE successfully matches the second biometric value with the first biometric value and the second biometric data meets the data quality requirements, it stores the second biometric data as the target biometric data.

[0057] In this embodiment, a first biometric value is extracted and stored based on the first biometric data using a Trusted Execution Environment (TEE). This allows for data comparison to be performed to a certain extent even without storing the first biometric data, thereby improving the flexibility of data comparison. Furthermore, if the second biometric value successfully matches the first biometric value and meets the data quality requirements, the second biometric data is stored. This ensures that the target biometric data can be obtained promptly, enabling the sensor control center to perform data comparison based on the target biometric data.

[0058] In conjunction with the first aspect, in one possible implementation, the Trusted Execution Environment (TEE) extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value, including:

[0059] The first trusted application (TA) extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value.

[0060] In conjunction with the first aspect, in one possible implementation, the target data includes target biometric data, and the electronic device also includes a notification application running in a general execution environment (REE), configured to enable intelligent display functionality. After the sensor control center determines the target storage address based on third information and retrieves the target data from the first memory area based on the target storage address, the implementation further includes:

[0061] Upon receiving a message, the sensor control center compares the second biometric data to be compared with the target biometric data collected by the electronic device. If the comparison between the second biometric data to be compared and the target biometric data is successful, the sensor control center instructs the notification application to provide the eighth information; or if the comparison between the second biometric data to be compared and the target biometric data fails, the sensor control center instructs the notification application to provide the ninth information. The eighth information is used to instruct the display of a message, and the ninth information is used to instruct the hiding of a message. The notification application displays the message based on the received eighth information, or hides the message based on the received ninth information.

[0062] In this embodiment, when the electronic device receives a message, the sensor control center compares the second biometric data to be compared with the target biometric data collected by the electronic device. The message is only displayed if the comparison is successful. That is, the electronic device only displays the message when the user facing the screen of the electronic device is the target user who entered the biometric data, thereby improving the privacy of the message notification. Simultaneously, since the sensor control center stores the target biometric data, it can directly compare the second biometric data with the target biometric data, eliminating the need to retrieve the target biometric data from the TEE. This improves the efficiency of data comparison and, consequently, the efficiency of determining whether to display a message.

[0063] Optionally, the sensor control center can transmit the eighth or ninth information to the notification application from the REE environment.

[0064] In conjunction with the first aspect, in one possible implementation, the client application CA indicates first information to the first trusted application TA, including:

[0065] The client CA obtains the data storage status identifier, and if the data storage status identifier is a first identifier, it indicates the first information to the first trusted application TA. The first identifier is used to indicate that the sensor control center does not store the target data; and / or, the client application CA searches for the target data from the first trusted application TA and the sensor control center respectively, and if the target data is found from the first trusted application TA but not from the sensor control center, it indicates the first information to the first trusted application TA.

[0066] Secondly, embodiments of this application provide a data transmission device, which can be an electronic device, or a chip or chip system within an electronic device. The data transmission device may include a display unit and a processing unit. When the data transmission device is an electronic device, the display unit may be a display screen. The display unit is used to perform display steps to enable the electronic device to implement a data transmission method described in the first aspect or any possible implementation of the first aspect. When the data transmission device is an electronic device, the processing unit may be a processor. The data transmission device may further include a storage unit, which may be a memory. The storage unit is used to store instructions, and the processing unit executes the instructions stored in the storage unit to enable the electronic device to implement a data transmission method described in the first aspect or any possible implementation of the first aspect. When the data transmission device is a chip or chip system within an electronic device, the processing unit may be a processor. The processing unit executes the instructions stored in the storage unit to enable the electronic device to implement a data transmission method described in the first aspect or any possible implementation of the first aspect. The storage unit may be a storage unit within the chip (e.g., a register, cache, etc.), or a storage unit located outside the chip within the electronic device (e.g., a read-only memory, random access memory, etc.).

[0067] Thirdly, embodiments of this application provide an electronic device including a processor and a memory, the memory for storing code instructions, and the processor for running the code instructions to perform the methods described in the first aspect or any possible implementation of the first aspect.

[0068] Fourthly, embodiments of this application provide a computer-readable storage medium storing a computer program or instructions that, when executed on a computer, cause the computer to perform the methods described in the first aspect or any possible implementation thereof.

[0069] Fifthly, embodiments of this application provide a computer program product including a computer program, which, when run on a computer, causes the computer to perform the methods described in the first aspect or any possible implementation thereof.

[0070] Sixthly, this application provides a chip or chip system including at least one processor and a communication interface. The communication interface and the at least one processor are interconnected via a circuit. The at least one processor is used to run computer programs or instructions to perform the methods described in the first aspect or any possible implementation of the first aspect. The communication interface in the chip can be an input / output interface, pins, or circuits, etc.

[0071] In one possible implementation, the chip or chip system described above in this application further includes at least one memory storing instructions. The memory can be an internal storage unit of the chip, such as a register or cache, or it can be a storage unit of the chip itself (e.g., read-only memory, random access memory, etc.).

[0072] It should be understood that the second to sixth aspects of this application correspond to the technical solutions of the first aspect of this application, and the beneficial effects achieved by each aspect and the corresponding feasible implementation are similar, and will not be repeated here. Attached Figure Description

[0073] Figure 1 A schematic diagram illustrating a data transmission method provided in an embodiment of this application;

[0074] Figure 2 A schematic diagram of the hardware structure of an electronic device provided in an embodiment of this application;

[0075] Figure 3 A schematic diagram of the software structure of an electronic device provided in an embodiment of this application;

[0076] Figure 4 A schematic diagram illustrating another data transmission method provided in an embodiment of this application;

[0077] Figure 5 A flowchart illustrating a data transmission method provided in an embodiment of this application;

[0078] Figure 6 A flowchart illustrating another data transmission method provided in an embodiment of this application;

[0079] Figure 7 This is a schematic diagram illustrating a scenario where an electronic device displays messages, as provided in an embodiment of this application.

[0080] Figure 8 A schematic diagram illustrating a scenario where an electronic device hides messages, provided as an embodiment of this application.

[0081] Figure 9 This is a schematic diagram of the structure of a chip provided in an embodiment of this application. Detailed Implementation

[0082] To facilitate a clear description of the technical solutions in the embodiments of this application, some terms and technologies involved in the embodiments of this application will be briefly introduced below:

[0083] 1. REE can be called a general execution environment. The general execution environment operating system (REE OS) on a general-purpose processor and the client application CA can run in REE.

[0084] 2. A TEE can be called a secure execution environment, which can run a trusted execution environment operating system (TEE OS). The TEE can also provide trusted security services to CAs (such as fingerprint verification, password verification, facial recognition, and secure payment services), which can run as trusted applications within the TEE OS. In some embodiments, the TEE can be an execution region built using the secure region of the processor in the terminal device. The trusted execution environment can provide a secure operating environment for services.

[0085] 3. The main functions of the sensor control center (sensor hub) include: real-time control of sensors to reduce power consumption; connecting and processing data from various sensors; and fusing data from different types of sensors to achieve functions that require combining data from multiple sensors. It should be noted that the sensor hub is a low-power processor, which can also be understood as a small core. The services processed by the sensor hub can be understood as low-power services. For example, processing facial recognition data on the sensor hub can be understood as low-power facial recognition services.

[0086] 4. Other terms

[0087] In the embodiments of this application, terms such as "first" and "second" are used to distinguish identical or similar items with substantially the same function and purpose. For example, "first chip" and "second chip" are used only to distinguish different chips and do not limit their order of execution. Those skilled in the art will understand that terms such as "first" and "second" do not limit the quantity or execution order, and that "first" and "second" do not necessarily imply that they are different.

[0088] It should be noted that, in the embodiments of this application, the terms "exemplary" or "for example" are used to indicate examples, illustrations, or descriptions. Any embodiment or design scheme described as "exemplary" or "for example" in this application should not be construed as being more preferred or advantageous than other embodiments or design schemes. Specifically, the use of terms such as "exemplary" or "for example" is intended to present the relevant concepts in a specific manner.

[0089] In this application embodiment, "at least one" refers to one or more, and "more than one" refers to two or more. "And / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone, where A and B can be singular or plural. The character " / " generally indicates that the preceding and following related objects are in an "or" relationship. "At least one of the following" or similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b, or c can represent: a, b, c, ab, a--c, bc, or abc, where a, b, and c can be single or multiple.

[0090] 5. Electronic equipment

[0091] The electronic devices in this application embodiment may include handheld devices, vehicle-mounted devices, etc., that have display functions or data acquisition functions. For example, some electronic devices include: mobile phones, tablets, PDAs, laptops, mobile internet devices (MIDs), wearable devices, virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, wireless terminals in smart homes, cellular phones, cordless phones, session initiation protocol (SIP) phones, wireless local loop (WLL) stations, personal digital assistants (PDAs), handheld devices with wireless communication capabilities, computing devices or other processing devices connected to a wireless modem, in-vehicle devices, wearable devices, terminal devices in 5G networks, or future evolution of public land mobile communication networks. Terminal devices in a network (PLMN), etc., are not limited to this in the embodiments of this application.

[0092] By way of example and not limitation, in this embodiment, the electronic device can also be a wearable device. Wearable devices, also known as wearable smart devices, are a general term for devices that utilize wearable technology to intelligently design and develop everyday wearables, such as glasses, gloves, watches, clothing, and shoes. Wearable devices are portable devices that are worn directly on the body or integrated into the user's clothing or accessories. Wearable devices are not merely hardware devices, but also achieve powerful functions through software support, data interaction, and cloud interaction. Broadly speaking, wearable smart devices include those that are feature-rich, large in size, and can achieve complete or partial functions without relying on a smartphone, such as smartwatches or smart glasses, as well as those that focus on a specific type of application function and require the use of other devices such as smartphones, such as various smart bracelets and smart jewelry for vital sign monitoring.

[0093] Furthermore, in this embodiment of the application, the electronic device can also be a terminal device in the Internet of Things (IoT) system. IoT is an important part of the future development of information technology. Its main technical feature is to connect objects to the network through communication technology, thereby realizing an intelligent network of human-machine interconnection and object-to-object interconnection.

[0094] The electronic devices in the embodiments of this application may also be referred to as: terminal equipment, user equipment (UE), mobile station (MS), mobile terminal (MT), access terminal, user unit, user station, mobile station, mobile station, remote station, remote terminal, mobile device, user terminal, terminal, wireless communication equipment, user agent, or user device, etc.

[0095] In this embodiment, the electronic device or various network devices include a hardware layer, an operating system layer running on top of the hardware layer, and an application layer running on top of the operating system layer. The hardware layer includes hardware such as a central processing unit (CPU), a memory management unit (MMU), and memory (also called main memory). The operating system can be any one or more computer operating systems that implement business processing through processes, such as Linux, Unix, Android, iOS, or Windows. The application layer includes applications such as browsers, address books, word processing software, and instant messaging software.

[0096] The following examples illustrate the scenarios for this solution.

[0097] In some example scenarios, electronic devices collect and store the target user's facial data. When the electronic device needs to unlock, it collects the user's facial data facing the device's display screen and compares the target facial data with the facial data to be verified. If the facial data match, the electronic device unlocks; if the facial data match fails, the electronic device is refused to unlock.

[0098] In other example scenarios, when an electronic device needs to intelligently display pop-up notification messages, it compares the face data to be verified with the target face data. If the face data match successfully, the pop-up notification message is displayed; if the face data match fails, the pop-up notification message is hidden.

[0099] In other scenarios, when an electronic device needs to make a payment, the facial data to be verified is compared with the target facial data. If the facial data matches successfully, the payment is made; if the facial data matches unsuccessfully, the payment is rejected.

[0100] It is understood that the solution in this embodiment is not limited to the above scenarios, and the solution in this application embodiment can be used in scenarios that require data comparison or data verification. In addition, the data to be compared is not limited to facial data, but can also be biometric data such as fingerprint data, voiceprint data, and iris data, which are not limited here.

[0101] To improve the security of target facial data, electronic devices store this data in a TEE (Transparent Environment Execution Unit). When data comparison is needed, the application processor retrieves the target data from the TEE for comparison. However, retrieving target data from the TEE is slow, resulting in slow data comparison efficiency. To ensure the security of the target data while improving comparison efficiency, the target data can be stored in a sensor hub, allowing the sensor hub to directly compare the stored target data with the data to be verified.

[0102] Therefore, it is necessary to transmit the target face data of TA to Sensorhub.

[0103] In related technologies, the main methods are as follows: Figure 1 The data transmission method shown indicates that the trusted application (TA) transmits target data to the sensor control center through the CA in the REE and the hardware abstraction layer (HAL) related to the sensor control center.

[0104] However, REE is an insecure environment, which exposes the target's facial data to an insecure side, resulting in low security for data transmission.

[0105] In view of this, embodiments of this application provide a data transmission method and related apparatus, which can enable the target data to be transmitted in a secure environment without passing through the REE side when it is necessary to transmit the target data of the Trusted Application (TA) to the sensor control center. This can improve the security of data transmission from the TA in the TEE environment to the sensor control center.

[0106] To better understand the embodiments of this application, the structure of the electronic device of this application is described below:

[0107] Figure 2 A schematic diagram of the hardware structure of the electronic device 100 is shown.

[0108] Electronic device 100 may include processor 110, external memory interface 120, internal memory 121, universal serial bus (USB) interface 130, charging management module 140, power management module 141, battery 142, antenna 1, antenna 2, mobile communication module 150, wireless communication module 160, audio module 170, speaker 170A, receiver 170B, microphone 170C, headphone jack 170D, sensor module 180, button 190, motor 191, indicator 192, camera 193, display screen 194, subscriber identification module (SIM) card interface 195, and sensor control center 196, etc. The sensor module 180 may include a pressure sensor 180A, a gyroscope sensor 180B, a barometric pressure sensor 180C, a magnetic sensor 180D, an accelerometer sensor 180E, a distance sensor 180F, a proximity sensor 180G, a fingerprint sensor 180H, a temperature sensor 180J, a touch sensor 180K, an ambient light sensor 180L, a bone conduction sensor 180M, etc.

[0109] It is understood that the structures illustrated in the embodiments of the present invention do not constitute a specific limitation on the electronic device 100. In other embodiments of this application, the electronic device 100 may include more or fewer components than illustrated, or combine some components, or split some components, or have different component arrangements. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.

[0110] Processor 110 may include one or more processing units, such as application processors (APs), modem processors, graphics processing units (GPUs), image signal processors (ISPs), controllers, video codecs, digital signal processors (DSPs), baseband processors, and / or neural network processing units (NPUs). These different processing units may be independent devices or integrated into one or more processors.

[0111] The controller can generate operation control signals based on the instruction opcode and timing signals to complete the control of instruction fetching and execution.

[0112] The processor 110 may also include a memory for storing instructions and data. In some embodiments, the memory in the processor 110 is a cache memory. This memory can store instructions or data that the processor 110 has just used or that are used repeatedly. If the processor 110 needs to use the instruction or data again, it can retrieve it directly from the memory. This avoids repeated accesses, reduces the waiting time of the processor 110, and thus improves system efficiency. The application processor may be deployed with an REE and a TEE independent of the REE. Optionally, the application processor may include one or more TEEs, which can be set as needed and is not limited here.

[0113] In this embodiment, the display screen 194 can be used to display facial data, display messages, or collect fingerprint data via a fingerprint acquisition module disposed on the display screen 194. The camera 193 can be used to collect at least one of facial data and iris data. The microphone 170C can be used to collect voiceprint data.

[0114] The following examples, using the scenario of collecting facial data, illustrate the workflow of electronic device hardware.

[0115] The face and iris data collected by camera 193, the voiceprint data collected by microphone 170C, and the fingerprint data collected by display screen 194 and other hardware can be saved as target data to TA in TEE environment. Then the target data is transmitted from TA in TEE environment to sensor control center 196 and stored in sensor control center 196. Sensor control center 196 can then verify the data to be verified based on the target data stored in it.

[0116] Figure 3A schematic diagram of the software structure of the electronic device 100 is shown.

[0117] The software system of electronic device 100 can adopt a layered architecture, event-driven architecture, microkernel architecture, microservice architecture, or cloud architecture. This embodiment of the invention uses the layered architecture Android system as an example to exemplify the software structure of electronic device 100.

[0118] Figure 3 This is a software structure block diagram of the electronic device 100 according to an embodiment of the present invention. The layered architecture in this embodiment can be deployed in an REE. The electronic device may also include at least one TEE. Each TEE may run a Trusted Application (TA) (also known as a Service TA). Optionally, the Trusted Application (TA) and the sensor control center can share data through shared memory.

[0119] A layered architecture divides software into several layers, each with a clear role and function. Layers communicate with each other through software interfaces. In some embodiments, the Android system is divided into multiple layers, from top to bottom: the application layer, the application framework layer, the Android runtime and system libraries, the hardware abstraction layer, and the kernel layer.

[0120] The application layer can include a series of application packages.

[0121] like Figure 3 As shown, the application package may include applications such as settings, notifications, payments, camera, gallery, calendar, calling, maps, navigation, WLAN, Bluetooth, music, video, and SMS.

[0122] The application framework layer provides application programming interfaces (APIs) and a programming framework for applications in the application layer. The application framework layer includes some predefined functions.

[0123] like Figure 3 As shown, the application framework layer may include a window manager, content provider, view system, phone manager, resource manager, notification manager, etc.

[0124] The notification manager allows applications to display notifications in the status bar. These notifications can be used to deliver informational messages and can disappear automatically after a short pause, requiring no user interaction. For example, the notification manager can be used to notify users of completed downloads or message alerts. The notification manager can also display notifications as icons or scrolling text in the top status bar, such as notifications from background applications, or as dialog boxes on the screen. Examples include displaying text messages in the status bar, emitting sounds, vibrating electronic devices, and flashing indicator lights.

[0125] The Android Runtime consists of core libraries and a virtual machine. The Android runtime is responsible for the scheduling and management of the Android system.

[0126] The core library consists of two parts: one part is the functionalities that need to be called by the Java language, and the other part is the Android core library.

[0127] The application layer and application framework layer run in a virtual machine. The virtual machine executes the Java files of the application layer and application framework layer as binary files. The virtual machine is used to perform functions such as object lifecycle management, stack management, thread management, security and exception management, and garbage collection.

[0128] System libraries can include multiple functional modules. For example: surface manager, media libraries, 3D graphics processing libraries (e.g., OpenGL ES), 2D graphics engines (e.g., SGL), etc.

[0129] The Hardware Abstraction Layer (HAL) is an interface layer located between the operating system kernel and upper-level software, its purpose being to abstract hardware. The HAL is an abstract interface for device kernel drivers, providing application programming interfaces (APIs) for accessing the underlying device to higher-level Java API frameworks. The HAL contains multiple library modules, such as the business CA corresponding to the business TA, the sensor control center HAL, the camera HAL, and the display HAL. The TA can include a face TA, which corresponds to a face CA. Optionally, data can be transferred between the TA and the hardware layer of the electronic device; for example, a camera can transmit facial data to the TA, or a display can transmit fingerprint data to the TA.

[0130] Each library module implements an interface for a specific type of hardware component. For example, the Sensor Control Center (HAL) provides an interface to access hardware components such as the sensor hub; the Camera HAL provides an interface to the Camera Fireworks (FWK) to access hardware components such as the camera; and the Display HAL provides an interface to the Display Fireworks (FWK) to access hardware components such as the display. When the system framework layer API requires access to the portable device's hardware, the Android operating system loads the library module for that hardware component.

[0131] The kernel layer is the layer between hardware and software. At a minimum, the kernel layer contains display drivers, camera drivers, audio drivers, and sensor drivers. For example, the camera driver controls the camera to capture facial data.

[0132] The following examples, using the scenario of collecting facial data, illustrate the workflow of electronic device software.

[0133] For example, when the touch sensor in the terminal device receives a touch operation, the corresponding hardware interrupt is sent to the kernel layer. The kernel layer processes the touch operation into a raw input event (including touch coordinates, touch pressure, touch operation timestamp, etc.). The raw input event is stored in the kernel layer. The application framework layer obtains the raw input event from the kernel layer and identifies the button corresponding to the input event. Taking the touch operation as a face data enrollment operation, and the virtual button corresponding to the face data enrollment operation as the "Settings Application" face enrollment virtual button as an example, the settings application calls the interface of the application framework layer, and then calls the kernel layer to start the display driver, displaying the function interface for collecting face data, and providing face collection instructions in the function interface. At the same time, it calls the camera access interface in the application framework layer to start the face data collection function of the settings application. Based on the camera driver in the kernel layer, one or more cameras are driven to collect one or more frames of face image data in real time. After the camera collects face data, it can be fed back to the CA through the kernel layer and system library. The CA can transmit the face data to the TA, and the TA can store the face data.

[0134] Then, once the intelligent display function of the "Notification Application" is enabled, the CA of the HAL layer can be called through the framework layer and system layer. The CA then notifies the TA to transmit facial data to the sensor control center, where the facial data can be stored. The data stored in the sensor control center can serve as business data, enabling the sensor control center to perform certain business processes, such as facial data comparison.

[0135] The following description uses the specific implementation of this application as an example.

[0136] In this embodiment of the application, the method by which the TA transmits face data to the sensor hub can be as follows: Figure 4 As shown, data from the security side is transmitted within a secure environment and finally reaches the sensor control center. During data transmission, it can bypass the REE side. The REE side can transmit handles to secure shared memory (referred to as memory) and control commands, and can interact with the TEE through shared memory. The sensor control center can also use business data (such as facial recognition) for business processing (such as facial comparison processing) to obtain data processing results (such as facial comparison results).

[0137] Optionally, the payment application, settings application, and notification application can call the face CA through the face FWK to communicate with the face TA or HAL. The sensor control center can transmit the data processing results to the payment TA sequentially through shared memory and the face TA, and the payment TA then transmits the data transmission results to the payment application. Optionally, the face FWK may include the camera FWK.

[0138] The following examples illustrate the specific implementation of TA directly transmitting data to the sensor control center.

[0139] Please see Figure 5 , Figure 5 This is a flowchart illustrating a data transmission method provided in an embodiment of this application. This embodiment uses facial data as the target data and a payment scenario as an example for illustration. Figure 5 The methods shown may include:

[0140] S500, Electronic device powered on.

[0141] S502 and the client application CA search for the target face data from the first trusted application TA and the sensor control center, respectively.

[0142] In this context, the first trusted application TA can be a low-power face TA, and the client application CA can be a low-power face CA.

[0143] In this embodiment, the client application CA searches for target face data from both the first trusted application TA and the sensor control center. If the target face data is found in the first trusted application TA but not in the sensor control center, it indicates that the target face data is stored in the first trusted application TA but has not been transmitted to the sensor control center, and in this case, the transmission of the target face data is triggered. If the target face data is found in both the first trusted application TA and the sensor control center, it indicates that the target face data is stored in the sensor control center, and in this case, the transmission of the target face data does not need to be triggered.

[0144] S504: The client CA determines whether the target face data was found in the first trusted application TA but not in the sensor control center.

[0145] S506, The client application CA indicates the first information to the first trusted application TA.

[0146] Among them, the first information indicates the transmission of the target face data of the first trusted application TA.

[0147] S508, the first trusted application TA responds to the first information by writing the target face data to the shared memory area and instructing the client application CA to provide the second information.

[0148] The second information indicates the target storage address of the target face data in the shared memory area. In other words, the storage location of the target face data can be determined based on the second information. The target storage address can be a logical address or a physical address, etc. Optionally, the target storage address can be the starting address of the target data. The second information indicates the target storage address of the target data, meaning that the location of the target data in the first memory area can be determined based on the second information. Optionally, the second information may include a handle. A handle is an identifier used to identify an object or item, and can be used to describe windows, files, etc. In this embodiment, the handle can be used to indicate the target storage address of the target data in the first memory area. Generally, the reason for establishing a handle stems from the memory management mechanism, namely, virtual addresses. In short, the address of data needs to change, and after the change, it needs to be recorded and managed. Therefore, the system uses a handle to record changes in data addresses.

[0149] The shared memory area is the memory area in the Trusted Execution Environment (TEE).

[0150] S510, the client application CA instructs the sensor control center to send the second information.

[0151] Optionally, the client application CA can send a second message to the sensor control center (HAL) through the sensor control center.

[0152] S512, The sensor control center determines the target storage address based on the second information.

[0153] In this embodiment, the second information includes the target address index. The sensor control center is configured with a mapping relationship between the address index and the storage address. When the sensor control center determines the target storage address based on the third information, it determines the target storage address based on the target address index and the mapping relationship.

[0154] S514, The sensor control center requests the target face data in the shared memory area from the first trusted application (TA).

[0155] S516, The first trusted application (TA) verifies the access permissions of the sensor control center.

[0156] In this embodiment, the first trusted application (TA) can be configured with permissions for the sensor control center. Specifically, the permissions of the sensor control center may or may not include access to the shared memory area, depending on the actual situation, and are not limited here. If the permissions of the sensor control center include access to the shared memory area, then the sensor control center is allowed to access the shared memory area. Optionally, if the permissions of the sensor control center do not include access to the shared memory area, then the steps end here.

[0157] S518. When the sensor control center has permission to access the shared memory area, the first trusted application (TA) allows the sensor control center to obtain the target face data from the shared memory area.

[0158] S520, the sensor control center obtains the target face data from the shared memory area based on the target storage address.

[0159] S522, The sensor control center acquires the face data to be compared.

[0160] In this embodiment, the facial data to be compared can be facial data collected by the camera of an electronic device when a payment operation initiated by a payment application is detected.

[0161] S524. The sensor control center compares the face data to be compared with the target face data to obtain the face data comparison result.

[0162] The data comparison result can indicate the similarity between the data to be compared and the target data, or indicate whether the comparison was successful, such as indicating whether the comparison was successful or failed. Optionally, if the similarity between the data to be compared and the target data is greater than a similarity threshold, the comparison is successful; otherwise, the comparison fails. The similarity threshold can be set as needed, for example, to 80% or 90%, without limitation.

[0163] S526, The sensor control center writes the face data comparison results to the shared memory area.

[0164] It should be noted that the shared memory area where the first trusted application (TA) writes face data and the shared memory area where the sensor control center writes the face data comparison results can be the same or different memory areas. For example, the first trusted application (TA) writes face data to the first memory area, while the sensor control center writes data to the second memory area. Optionally, when the second memory area and the first memory area are different memory areas, the storage space size of the second memory area can be fixed.

[0165] S528, The first trusted application (TA) obtains the face data comparison results from the shared memory area.

[0166] In this embodiment, the first trusted application (TA) can not only write face data to the shared memory area, but also retrieve face data comparison results from the shared memory area. Similarly, the sensor control center can not only retrieve face data from the shared memory area, but also write face data comparison results to the shared memory area. Optionally, after writing the face data comparison results, the sensor control center can notify the first trusted application (TA), and then the first trusted application will retrieve the face data comparison results from the shared memory area.

[0167] Optionally, the sensor control center can transmit the address information of the face data comparison result to the first trusted application TA through the client CA. In this case, the first trusted application TA can obtain the face data comparison result from the shared memory area based on the address information.

[0168] S530: The first trusted application (TA) forwards the face data comparison result to the second trusted application (TA).

[0169] Among them, the second trusted application TA can be the payment TA.

[0170] S532, The second trusted application (TA) transmits the facial data comparison results to the payment application.

[0171] In this embodiment, the payment application can make or refuse payment based on the facial data comparison result. Specifically, if the facial data comparison is successful, payment is made; if the facial data comparison fails, payment is refused.

[0172] In another possible implementation, when the sensor control center instructs the client application CA to request data transmission, the client application CA instructs the first information to the first trusted application TA. Optionally, the sensor control center may instruct the client application CA to transmit the face data, either when the electronic device receives a message or detects a payment operation, periodically, or after the electronic device restarts. This embodiment does not limit the scenario in which the face data transmission request is triggered. Optionally, after receiving the target face data, the sensor control center can store it in the sensor control center until the electronic device is powered off.

[0173] In another possible implementation, the face data comparison results between the face data to be compared and the target face data can also be used for other purposes, such as hiding or displaying messages based on the face data comparison results.

[0174] Please see Figure 6 , Figure 6 This is a flowchart illustrating another data transmission method provided in an embodiment of this application. This embodiment uses face data as the target data and a message notification scenario as an example for illustration. Figure 6 The methods shown may include:

[0175] S600, Electronic device powered on.

[0176] S602 and the client application CA search for the target face data from the first trusted application TA and the sensor control center, respectively.

[0177] S604. The client CA determines whether the target face data can be found in the first trusted application TA, but the target face data cannot be found in the sensor control center.

[0178] S606, The client application CA indicates the first information to the first trusted application TA.

[0179] Among them, the first information indicates the transmission of the target face data of the first trusted application TA.

[0180] S608, the first trusted application TA responds to the first information by writing the target face data to the shared memory area and instructing the client application CA to provide the second information.

[0181] S610, the client application CA instructs the sensor control center to send the second information.

[0182] S612, The sensor control center determines the target storage address based on the second information.

[0183] S614. The sensor control center requests the target face data in the shared memory area from the first trusted application (TA).

[0184] S616, The first trusted application (TA) verifies the access permissions of the sensor control center.

[0185] S618. When the sensor control center has permission to access the shared memory area, the first trusted application (TA) allows the sensor control center to obtain the target face data from the shared memory area.

[0186] S620, the sensor control center obtains the target face data from the shared memory area based on the target storage address.

[0187] S622, The sensor control center acquires the face data to be compared.

[0188] S624. The sensor control center compares the face data to be compared with the target face data to obtain the face data comparison result.

[0189] S626, The sensor control center writes the face data comparison results to the shared memory area.

[0190] S628, The first trusted application (TA) obtains the face data comparison results from the shared memory area.

[0191] The descriptions of S600-S628 can be referenced from those of S500-S528, and will not be repeated here.

[0192] S630, the first trusted application TA transmits the face data comparison results to the client CA.

[0193] S632, The client CA transmits the face data comparison results to the notification application.

[0194] In this embodiment, the notification application can display or hide messages based on the facial data comparison results. Specifically, if the facial data comparison is successful, the message is displayed; if the facial data comparison fails, the message is hidden.

[0195] In another possible implementation, the client CA can transmit either eighth or ninth information to the notification application based on the face data comparison results. The eighth information indicates a display message, while the ninth information indicates a hidden message.

[0196] In another possible implementation, the client CA can obtain the data storage status identifier and, if the data storage status identifier is a first identifier, indicate the first information to the first trusted application TA. The first identifier is used to indicate that the sensor control center does not store the target data.

[0197] The data storage status identifier can be stored in the Sensor Control Center (HAL). Optionally, the starting identifier for the data storage status identifier can be a first identifier. When the Sensor Control Center stores the target data, it indicates this information to the HAL, or the First Trusted Application (TA) transmits a message to the HAL via the Client Application (CA). In this case, the HAL updates the first identifier to a second identifier, indicating that the Sensor Control Center has stored the target data. Therefore, if the client obtains the second identifier as the data storage status identifier, it can know that the Sensor Control Center has stored the target data, and thus avoids triggering the transmission of the target data, preventing duplicate transmission of the target data to the Sensor Control Center.

[0198] In this embodiment, the client CA obtains the data storage status identifier, and when the data storage status identifier is a first identifier, it indicates first information to the first trusted application TA. The first identifier is used to indicate that the sensor control center does not store the target data; and / or, the client application CA searches for the target data from the first trusted application TA and the sensor control center respectively, and when the target data is found from the first trusted application TA but not from the sensor control center, it indicates first information to the first trusted application TA. In this way, the transmission of the target data can be triggered in a timely manner so that the sensor control center can use the target data for comparison when needed.

[0199] Understandably, by using data storage status identifiers and searching for target data from the first trusted application (TA) and the sensor control center respectively, the triggering accuracy of target data transmission can be improved, thereby reducing the ineffective use of communication resources.

[0200] In another possible implementation, the client CA could determine the address information based on the second information and then transmit the address information to the sensor control center. In this way, the sensor control center can directly obtain the target face data based on the address information. It's understandable that by having the sensor control center determine the target's storage address based on the second information, this address determination is also performed in a secure environment, thus improving the security of the address information and consequently, the security of data transmission.

[0201] In another possible implementation, the sensor control center could directly obtain face data from the shared memory area without verifying the sensor control center's permissions, which would improve data transmission efficiency.

[0202] Understandably, verifying access permissions to the sensor control center can improve the security of data transmission.

[0203] In another possible implementation, a second trusted application (TA) could obtain the face data comparison results from the shared memory area. This would improve the efficiency of obtaining the face data comparison results, thereby improving the efficiency of payment.

[0204] It is understandable that by obtaining the face data comparison result from the shared memory area through a first trusted application (TA), and then transmitting the face data comparison result from the first trusted application (TA) to a second trusted application (TA), the number of trusted application (TA) writing or retrieving data from the shared memory area can be reduced, thereby improving the security of data transmission. In this embodiment, the face data to be compared can be face data collected by the camera when the electronic device receives a message.

[0205] For example, if the comparison between the face data to be compared and the target face data is successful, the sensor control center indicates the eighth piece of information to the notification application; or if the comparison fails, it indicates the ninth piece of information to the notification application. The eighth piece of information is used to indicate a display message, and the ninth piece of information is used to indicate a hide message. The notification application displays the message based on the received eighth piece of information, or hides the message based on the received ninth piece of information.

[0206] In this embodiment, messages can be hidden or displayed based on the comparison results between the face data to be compared and the target face data, which can improve the security of message notifications.

[0207] It should be noted that the facial data used to determine whether to make a payment can be understood as the first facial data, while the facial data used to determine whether to display a message can be understood as the second facial data.

[0208] In another possible implementation, after the sensor control center acquires the target face data, it can perform other processing, not limited to face data comparison. For example, the sensor control center can store the target face data so that when the face data is needed, the application processor can retrieve it from the sensor control center. This is not limited here.

[0209] In another possible implementation, biometric data such as fingerprint data, voiceprint data, and iris data can be used, not limited to facial data. Furthermore, other target data, such as usage data generated when a user uses an electronic device, can also be used, without limitation.

[0210] In the above embodiments, the data transmission method of this scheme is described under the condition that the target data is already stored in the first trusted execution environment (TEE).

[0211] Therefore, the following embodiments, based on any of the above embodiments, explain how the target data is collected and how the target data is stored in the first trusted execution environment (TEE).

[0212] In this embodiment, the application is configured to respond to the face registration operation by collecting first face data through the camera of the electronic device, and then transmitting the face data to the first trusted application TA through the interface between the camera and the first trusted application TA.

[0213] The First Trusted Application (TA) comprises a face recognition algorithm module 1, a face recognition algorithm module 2, and a face data storage module. After acquiring face data, the TA uses the algorithm configured in face recognition algorithm module 1 to determine whether the face data meets quality requirements. If the face data meets the quality requirements, it is stored in the face data storage module. This allows the face data to be read from the storage module and written to a shared memory area when face data needs to be transmitted to the sensor control center. If the face data does not meet the quality requirements, face recognition algorithm module 2 extracts the first biometric value based on the first biometric data and stores it in the face data storage module.

[0214] Then, when the camera collects the second biometric data, it transmits the second biometric data to the TEE. The face recognition algorithm module 2 extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value. If the match is successful, the face recognition algorithm module 1 determines whether the second face data meets the quality requirements. If the face recognition algorithm module 1 determines that the second face data meets the quality requirements, the second face data is stored in the face data storage module.

[0215] The data quality requirements for different types of facial data can be different or the same. For example, for facial data, the data quality requirement could be that the facial data is complete and there are no issues such as blinking that could affect recognition. For fingerprint data, the data quality requirement could be that 90% of the fingerprint is captured and the fingerprint data is clear. These requirements can be set according to the actual situation and are not limited here.

[0216] The first facial feature value can reflect the face to a certain extent and can be used as a benchmark facial feature value for comparison, for example, by comparing it with the second facial feature value. In other words, the first and second facial data belong to the same user, but the second facial data has better data quality. For example, facial feature values ​​can indicate the contour features, facial features, etc. If it is fingerprint data, the corresponding fingerprint feature value can indicate parts of the fingerprint, etc.

[0217] Optionally, since the complete first face data cannot be reconstructed based on the first face feature value, this approach can both compare the second face feature value of the second face data to confirm the legitimacy of the second face data and reduce the risk of leakage of the first face data due to the leakage of the first face feature value.

[0218] The second facial data can be collected periodically, or when the electronic device detects the presence of a living being, or when the electronic device detects a trigger operation related to facial data collection (such as unlocking or payment).

[0219] In another possible implementation, it is also possible to choose not to perform matching between the first and second facial feature values, or not to determine whether the second facial data meets the data quality requirements.

[0220] It is understood that, in the embodiments of this application, the target face data can also be replaced with other data, such as at least one of fingerprint data, voiceprint data, and iris data. The target data may also include data other than biometric data, such as non-biometric data, which is not limited herein. The above embodiments illustrate the transmission of target data between the TEE and the sensor control center. The following embodiments, based on any of the above embodiments, illustrate how the sensor control center uses the target data for comparison.

[0221] Scenario 1: The electronic device is recording user A's facial data. If the electronic device receives a message, the first thing it will do is detect that user A is using the device, and then display the message, such as... Figure 7 As shown.

[0222] In the second moment, if the electronic device detects that user B is using the device, or if the electronic device detects that user A is using the device, but users B and C are also present next to user A, then the electronic device hides the message, such as... Figure 8 As shown.

[0223] In this embodiment, the notification application is configured to enable the smart display function. Specifically, when the electronic device receives a message, it calls the sensor control center to compare the biometric data to be compared with the target biometric data collected by the electronic device. If the comparison between the biometric data to be compared and the target biometric data is successful, the sensor control center indicates the eighth information to the notification application; or if the comparison between the biometric data to be compared and the target biometric data fails, it indicates the ninth information to the notification application. The eighth information is used to indicate the display message, and the ninth information is used to indicate the hiding message. The notification application displays the message based on the received eighth information, or hides the message based on the received ninth information.

[0224] In the third moment, if the electronic device detects user A again, it can then display the message again.

[0225] In the fourth step, if the electronic device detects a message clearing operation, it will no longer make a judgment on whether to hide or display the message.

[0226] Here, "display message" can refer to showing the message content in plaintext. Therefore, a message can mean either no notification or a notification that exists but whose content is not displayed. The sensor control center can be configured with a data comparison algorithm.

[0227] It should be noted that the acquisition and storage of target facial data can be described in any of the above embodiments, and will not be repeated here.

[0228] It should be noted that the sensor control center can also compare the face data to be compared with the target face data collected by the electronic device in real time, so that the electronic device can quickly obtain the feature data comparison results when it receives a message, and then determine whether to display the message.

[0229] Scenario 2: The electronic device records user A's facial data. At the fifth moment, the electronic device detects a payment operation. At this time, the sensor control center, based on the target facial data, detects that the person initiating the payment operation is user A, and then responds to the payment operation to complete the payment.

[0230] At the sixth moment, the electronic device detects a payment operation. At this time, the sensor control center detects, based on the target's facial data, that the person initiating the payment operation is user B, and therefore refuses to respond to the payment operation, thus refusing to pay.

[0231] The technical solutions of this application will be described in detail below with specific embodiments. These specific embodiments can be implemented independently or in combination with each other. Identical or similar concepts or processes may not be described again in some embodiments.

[0232] The data transmission method provided in this embodiment may include:

[0233] The client application (CA) instructs a first trusted application (TA) to transmit target data. In response to the first information, the TA writes the target data to a first memory area and instructs the client application (CA) to transmit second information, indicating the target storage address of the target data within the first memory area, which is a memory area in a Trusted Execution Environment (TEE). The client application (CA) then instructs a third information to the sensor control center, which includes the second information or address information determined based on the second information. The sensor control center determines the target storage address based on the third information and retrieves the target data from the first memory area based on the target storage address.

[0234] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0235] In one possible implementation, the data format of the target data includes the content of the target data, and at least one of the first instruction information, the second instruction information, the third instruction information, the fourth instruction information, the fifth instruction information, the sixth instruction information, or the seventh instruction information.

[0236] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0237] In another possible implementation, the target data could include the content of the target data but exclude instruction information, etc.

[0238] In one possible implementation, the third information could include the second information, which in turn includes the target storage index. This allows the sensor control center to determine the target storage address based on the target address index and the mapping relationship. Alternatively, the second information could include index information used to determine the target storage index, allowing the target storage index to be determined based on the index information, and then the target storage address to be determined based on the target storage index.

[0239] In another possible implementation, the third information could include address information determined based on the second information, such as a target storage address, so that the sensor control center can directly obtain the target storage address. Optionally, in this embodiment, the step of determining the address information based on the second information can be performed in the first trusted application (TA) or in the REE, that is, the address information is transmitted to the sensor control center through the REE.

[0240] It is understandable that if the REE needs to determine the address information, it can refer to the method used by the sensor control center to determine the address information, which will not be elaborated here.

[0241] In one possible implementation, before the sensor control center retrieves the target data from the first memory area based on the target storage address, the following is also included:

[0242] The first trusted application (TA) verifies the access permissions of the sensor control center, and if the access permissions of the sensor control center are verified, the sensor control center is allowed to obtain target data from the first memory area.

[0243] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0244] In another possible implementation, access permissions for the sensor control center can be verified by other modules (e.g., REE). In this embodiment, the first trusted application (TA) can obtain the identifier of the sensor control center and then transmit the identifier to the sensor control center (HAL). The HAL can then verify the access permissions of the first trusted application. The HAL then transmits the verification result to the first trusted application (TA) via the CA, allowing the TA to determine whether the sensor control center has access permissions to the first memory area.

[0245] In one possible implementation, after the sensor control center retrieves the target data from the first memory area based on the target storage address, the following is also included:

[0246] The sensor control center acquires the data to be compared; the sensor control center compares the data to be compared with the target data to obtain the data comparison result; the sensor control center writes the data comparison result to the second memory area, which is the memory area in the Trusted Execution Environment (TEE).

[0247] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0248] In another possible implementation, the second memory area can be a memory area in the RRE.

[0249] In one possible implementation, after the sensor control center writes the data comparison results to the second memory area, the following is also included:

[0250] The first trusted application (TA) retrieves the data comparison results from the second memory area and transmits the data comparison results to the second trusted application (TA); the second trusted application (TA) transmits the data comparison results to the payment application; the payment application makes payment or refuses payment based on the data comparison results.

[0251] In this embodiment, reference can be made to, as follows: Figure 5The relevant descriptions of the embodiments shown are not repeated here.

[0252] In another possible implementation, the first trusted application (TA) can write the data comparison result to other memory areas (such as memory areas in the REE), and then the payment application can write the data comparison result from the memory areas in the REE.

[0253] In one possible implementation, the electronic device, when acquiring target biometric data, may include:

[0254] In response to a biometric data entry operation, the application collects first biometric data via an electronic device. The REE (Generic Execution Environment), upon determining that the first biometric data meets data quality requirements, instructs the client application CA (Client Application) to provide fourth information, which instructs the storage of the first biometric data. In response to the fourth information, the client application CA instructs the first trusted application TA (Trusted Application) to provide fifth information and the first biometric data, with the fifth information instructing the storage of the first biometric data. In response to the fifth information, the first trusted application TA stores the first biometric data as the target biometric data.

[0255] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0256] In another possible implementation, the electronic device may determine whether the current conditions meet specific conditions. If they do, it may trigger the collection of biometric data, such as when the electronic device is currently idle or when the electronic device is being activated for the first time.

[0257] In one possible implementation, the sensor control center (HAL) determines whether the first biometric data meets the data quality requirements.

[0258] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0259] In another possible implementation, other modules can be used to determine whether the first biometric data meets the data quality requirements, for example, by using the camera driver in the kernel layer.

[0260] In one possible implementation, after acquiring biometric data once, the following is also included:

[0261] If the REE determines that the first biometric data does not meet the data quality requirements, it extracts and stores the first biometric value based on the first biometric data; the client application CA receives the second biometric data collected by the electronic device; the REE extracts the second biometric value based on the second biometric data and matches the second biometric value with the first biometric value; if the REE successfully matches the second biometric value with the first biometric value and the second biometric data meets the data quality requirements, it instructs the client application CA to provide sixth information, which instructs the storage of the second biometric data; in response to the sixth information, the client application CA instructs the first trusted application TA to provide seventh information and the second biometric data, which instructs the storage of the second biometric data; in response to the seventh information, the first trusted application TA stores the second biometric data as the target biometric data.

[0262] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0263] In one possible implementation, the sensor control center (HAL) extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value.

[0264] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0265] In another possible implementation, the steps of extracting the second biometric value based on the second biometric data and matching the second biometric value with the first biometric value can be performed by other modules, or the steps of extracting the second biometric value based on the second biometric data and matching the second biometric value with the first biometric value can be performed by different modules.

[0266] In one possible implementation, after the sensor control center determines the target storage address based on third information and retrieves the target data from the first memory area based on the target storage address, the following steps are also included:

[0267] Upon receiving a message, the sensor control center compares the second biometric data to be compared with the target biometric data collected by the electronic device. If the comparison between the second biometric data to be compared and the target biometric data is successful, the sensor control center instructs the notification application to provide the eighth information; or if the comparison between the second biometric data to be compared and the target biometric data fails, the sensor control center instructs the notification application to provide the ninth information. The eighth information is used to instruct the display of a message, and the ninth information is used to instruct the hiding of a message. The notification application displays the message based on the received eighth information, or hides the message based on the received ninth information.

[0268] In this embodiment, reference can be made to, as follows: Figure 5 The relevant descriptions of the embodiments shown are not repeated here.

[0269] In another possible implementation, the message can be displayed directly without comparing biometric data.

[0270] It should be noted that the data (information) transmission flow in this embodiment can be implemented through the interface between configuration modules. Information such as the first information and the first instruction information may include fields or commands. Fields or commands may include, but are not limited to, numbers, symbols, strings formed by multiple numbers, strings formed by multiple symbols, or strings formed by a mixture of symbols.

[0271] It should be noted that the module names involved in the embodiments of this application can all be defined as other names, as long as they can achieve the function of each module, and no specific restrictions are placed on the module names.

[0272] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in the embodiments of this application are all information and data authorized by the user or fully authorized by all parties. Furthermore, the collection, use and processing of related data must comply with the relevant laws, regulations and standards of the relevant countries and regions, and corresponding operation entry points are provided for users to choose to authorize or refuse.

[0273] The data transmission method of the embodiments of this application has been described above. The apparatus for executing the above method provided in the embodiments of this application is described below. Those skilled in the art will understand that the methods and apparatus can be combined and referenced with each other, and the related apparatus provided in the embodiments of this application can execute the steps in the above list sorting method.

[0274] The transmission method provided in this application can be applied to electronic devices with communication functions. The electronic devices include terminal devices, and the specific device form of the terminal devices can be referred to the above-described related descriptions, which will not be repeated here.

[0275] This application provides a terminal device, which includes a processor and a memory; the memory stores computer execution instructions; the processor executes the computer execution instructions stored in the memory, causing the terminal device to perform the above-described method.

[0276] like Figure 9 This is a schematic diagram of a chip structure provided in an embodiment of this application. The chip 900 includes one or more processors 901, a communication line 902, a communication interface 903, and a memory 904.

[0277] In some implementations, memory 904 stores elements such as executable modules or data structures, or subsets thereof, or extended sets thereof.

[0278] The methods described in the embodiments of this application can be applied to, or implemented by, processor 901. Processor 901 may be an integrated circuit chip with signal processing capabilities. During implementation, each step of the above methods can be completed by integrated logic circuits in the hardware of processor 901 or by instructions in software form. Processor 901 may be a general-purpose processor (e.g., a microprocessor or conventional processor), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gates, transistor logic devices, or discrete hardware components. Processor 901 can implement or execute the various processing-related methods, steps, and logic block diagrams disclosed in the embodiments of this application.

[0279] The steps of the method described in the embodiments of this application can be directly implemented by a hardware decoding processor, or implemented by a combination of hardware and software modules in the decoding processor. The software modules can be located in mature storage media in the art, such as random access memory, read-only memory, programmable read-only memory, or electrically erasable programmable read-only memory (EEPROM). This storage medium is located in memory 904, and processor 901 reads the information in memory 904 and, in conjunction with its hardware, completes the steps of the above method.

[0280] The processor 901, memory 904 and communication interface 903 can communicate with each other via communication line 902.

[0281] In the above embodiments, the instructions stored in the memory for execution by the processor can be implemented in the form of a computer program product. This computer program product can be pre-written into the memory, or it can be downloaded and installed into the memory as software.

[0282] This application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, it implements the methods described above. The methods described in the above embodiments can be implemented wholly or partially by software, hardware, firmware, or any combination thereof. If implemented in software, the functionality can be stored as one or more instructions or code on or transmitted over the computer-readable medium. The computer-readable medium can include computer storage media and communication media, and can also include any medium that can transfer a computer program from one place to another. The storage medium can be any target medium accessible by a computer.

[0283] In one possible implementation, a computer-readable medium may include RAM, ROM, compact disc read-only memory (CD-ROM) or other optical disc storage, disk storage or other magnetic storage devices, or any other medium targeted to carry or to store the required program code in the form of instructions or data structures, and accessible by a computer. Furthermore, any connection is appropriately referred to as a computer-readable medium. For example, if software is transmitted from a website, server, or other remote source using coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave, then coaxial cable, fiber optic cable, twisted pair, DSL, or wireless technologies such as infrared, radio, and microwave are included in the definition of medium. As used herein, disks and optical discs include optical discs, laser discs, optical discs, Digital Versatile Discs (DVDs), floppy disks, and Blu-ray discs, where disks typically reproduce data magnetically, while optical discs optically reproduce data using lasers. Combinations of the above should also be included within the scope of computer-readable media.

[0284] This application provides a computer program product, which includes a computer program that, when run, causes a computer to perform the above-described method.

[0285] This application describes embodiments of methods, apparatus (systems), and computer program products according to embodiments of this application with reference to flowchart illustrations and / or block diagrams. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processing unit of a general-purpose computer, special-purpose computer, embedded processor, or other programmable device to produce a machine, such that the instructions, which execute via the processing unit of the computer or other programmable data processing device, generate instructions for implementing the flowchart illustrations. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0286] The above specific embodiments further illustrate the purpose, technical solution, and beneficial effects of the present invention. It should be understood that the above are merely specific embodiments of the present invention and are not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc., made on the basis of the technical solution of the present invention should be included within the scope of protection of the present invention.

Claims

1. A data transmission method, characterized in that, Applied to an electronic device, the electronic device including a Trusted Execution Environment (TEE), a sensor control center, a first trusted application (TA) running on the TEE, a general execution environment (REE), and a client application (CA) running on the REE, the method includes: The client application CA indicates first information to the first trusted application TA, and the first information indicates the target data to be transmitted to the first trusted application TA. In response to the first information, the first trusted application (TA) writes the target data to the first memory area and instructs the client application (CA) with second information, which is used to indicate the target storage address of the target data in the first memory area, and the first memory area is the memory area in the trusted execution environment (TEE). The client application CA indicates third information to the sensor control center, the third information including the second information or address information determined based on the second information; The sensor control center determines the target storage address based on the third information, and retrieves the target data from the first memory area based on the target storage address; Wherein, the client application CA instructs the first information to the first trusted application TA, including: The client application CA obtains a data storage status identifier, and if the data storage status identifier is a first identifier, it indicates first information to the first trusted application TA, whereby the first identifier indicates that the sensor control center does not store the target data; and / or, The client application CA searches for the target data from both the first trusted application TA and the sensor control center. If the target data is found in the first trusted application TA but not in the sensor control center, the client application CA indicates first information to the first trusted application TA.

2. The method according to claim 1, characterized in that, The data format of the target data includes the content of the target data, and at least one of the following: first indication information, second indication information, third indication information, fourth indication information, fifth indication information, sixth indication information, or seventh indication information; The first indication information is used to indicate the total length of the target data; The second indication information is used to indicate the version number of the target data; The third indication information is used to indicate the acquisition time of the target data; The fourth indication information is used to indicate the number of target data; The fifth indication information is used to indicate the length of one of the target data; The sixth indication information is used to indicate the type of the target data; The seventh indication information is used to indicate the hash value of the target data.

3. The method according to claim 1 or 2, characterized in that, The third information includes the second information, which includes a target address index. The sensor control center is configured with a mapping relationship between address indexes and storage addresses. The sensor control center determines the target storage address based on the third information, including: The sensor control center determines the target storage address based on the target address index and the mapping relationship.

4. The method according to claim 1 or 2, characterized in that, Before the sensor control center retrieves the target data from the first memory area based on the target storage address, the method further includes: The first trusted application (TA) verifies the access permissions of the sensor control center, and if the access permissions of the sensor control center are verified, the sensor control center is allowed to obtain the target data from the first memory area.

5. The method according to claim 1 or 2, characterized in that, After the sensor control center obtains the target data from the first memory area based on the target storage address, the method further includes: The sensor control center acquires the data to be compared. The sensor control center compares the data to be compared with the target data to obtain the data comparison result; The sensor control center writes the data comparison result to the second memory area, which is the memory area in the Trusted Execution Environment (TEE).

6. The method according to claim 5, characterized in that, The electronic device also includes a payment application and a notification application running in the general execution environment REE, and a second trusted application TA running in the trusted execution environment TEE. The notification application is configured to enable smart display function. The target data includes target biometric data. The data to be compared includes first biometric data to be compared. The first biometric data to be compared is biometric data collected by the electronic device in response to the payment application in response to a payment operation. After the sensor control center writes the data comparison result to the second memory area, the process further includes: The first trusted application TA obtains the data comparison result from the second memory area and transmits the data comparison result to the second trusted application TA. The second trusted application (TA) transmits the data comparison result to the payment application; The payment application makes or rejects payment based on the data comparison results; or, The first trusted application (TA) transmits the data comparison result to the notification application through the client application (CA); The notification application displays or hides the received message based on the data comparison results.

7. The method according to any one of claims 1-2 and 6, characterized in that, The target data includes target biometric data, the electronic device further includes a settings application running in the general execution environment (REE), and the method further includes: The application is configured to respond to biometric input operations and collect first biometric data through electronic devices; If the Trusted Execution Environment (TEE) determines that the first biometric data meets the data quality requirements, it will store the first biometric data as the target biometric data.

8. The method according to claim 7, characterized in that, The method further includes: The first trusted application (TA) determines whether the first biometric data meets the data quality requirements, and stores the target biometric data through the first trusted application (TA).

9. The method according to claim 8, characterized in that, The method further includes: If the Trusted Execution Environment (TEE) determines that the first biometric data does not meet the data quality requirements, the first biometric value is extracted and stored based on the first biometric data. The Trusted Execution Environment (TEE) acquires the second biometric data collected by the electronic device; The Trusted Execution Environment (TEE) extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value. If the second biometric value successfully matches the first biometric value and the second biometric data meets the data quality requirements, the Trusted Execution Environment (TEE) stores the second biometric data as the target biometric data.

10. The method according to claim 9, characterized in that, The Trusted Execution Environment (TEE) extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value, including: The first trusted application (TA) extracts a second biometric value based on the second biometric data and matches the second biometric value with the first biometric value.

11. The method according to any one of claims 1-2, 6, 8-10, characterized in that, The target data includes target biometric data. The electronic device also includes a notification application running in the general execution environment (REE), which is configured to enable smart display functionality. After the sensor control center determines the target storage address based on the third information and retrieves the target data from the first memory area based on the target storage address, the device further includes: Upon receiving the message, the sensor control center compares the second biometric data to be compared collected by the electronic device with the target biometric data. If the second biometric data to be compared is successfully compared with the target biometric data, the sensor control center will indicate an eighth message to the notification application, or if the second biometric data to be compared fails to be compared with the target biometric data, the sensor control center will indicate a ninth message to the notification application. The eighth message is used to indicate that the message is displayed, and the ninth message is used to indicate that the message is hidden. The notification application may display the message based on the received eighth information, or hide the message based on the received ninth information.

12. An electronic device, characterized in that, The electronic device includes: one or more processors and memory; The memory is coupled to the one or more processors, the memory being used to store computer program code, the computer program code including computer instructions, the one or more processors invoking the computer instructions to cause the electronic device to perform the method as described in any one of claims 1 to 11.

13. A chip system, characterized in that, The chip system is applied to an electronic device, the chip system including one or more processors, the one or more processors being used to invoke computer instructions to cause the electronic device to perform the method as described in any one of claims 1 to 11.

14. A computer-readable storage medium, characterized in that, The computer-readable storage medium includes computer instructions that, when executed on an electronic device, cause the electronic device to perform the method as described in any one of claims 1 to 11.

15. A computer program product, characterized in that, The computer program product includes computer program code that, when run on an electronic device, causes the electronic device to perform the method as described in any one of claims 1 to 11.