Display method and device of trusted user interface, readable storage medium and chip
By setting components connected to the trusted execution environment in the terminal device, detecting and displaying a trusted user interface, the problem that users cannot distinguish the trusted user interface is solved, ensuring payment security and trustworthiness of information input.
Patent Information
- Application Number
- CN202411002359.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-01
- Publication Date
- 2025-09-02
AI Technical Summary
Users are unable to distinguish between trusted user interfaces and untrusted user interfaces, resulting in payments made on the untrusted user interface, causing information and property security issues.
A first element or second element connected to a trusted execution environment is provided in the terminal device, and a trusted user interface is displayed by detecting the operation of the first element or the second element, ensuring that the user can strongly perceive the trustworthiness of the interface and preventing malicious applications from simulating or replacing the interface.
Effectively avoid users completing payments or entering important information on an untrusted user interface, ensuring the security of information input, and preventing problems that users cannot distinguish when illegal interface replacement.
Smart Images

Figure CN120579971A_ABST
Abstract
Description
[0001] This application is a divisional application. The application number of the original application is 202410236267.4, and the original application date is March 1, 2024. The entire content of the original application is incorporated into this application by reference. Technical Field
[0002] The present application relates to the field of information security technology, and in particular to a display method, device, readable storage medium, and chip for a trusted user interface. Background Art
[0003] With the promotion and popularization of smart terminals, mobile payment has become one of the main payment methods for people's daily consumption. While mobile payment brings convenience to users, its security has always been a concern.
[0004] To ensure the security of mobile payments, a trusted user interface (TUI) has been introduced, allowing users to complete payments through the TUI. However, similar untrusted user interfaces (UIs) have emerged. Users cannot distinguish between trusted and untrusted UIs based on the display interface, leading to the possibility of users making payments through untrusted UIs, which in turn poses serious risks to information and property security. Summary of the Invention
[0005] The present application provides a display method, device, readable storage medium and chip for a trusted user interface, which solves the problem in the prior art that users cannot distinguish the trusted user interface, resulting in users making payments on untrusted user interfaces, which in turn causes serious information and property security issues.
[0006] To achieve the above objectives, this application adopts the following technical solutions:
[0007] In a first aspect, a method for displaying a trusted user interface is provided, which is applied to a terminal device, wherein the terminal device includes a rich execution environment (REE), a trusted execution environment (TEE), and a first component, wherein a first application is running in the REE, and the first component is connected to the TEE. The method includes: receiving a first operation on the first application, the first operation being used to request display of the trusted user interface of the first application; in response to the first operation, detecting a second operation through the TEE; wherein the second operation is an operation on the first component, and the second operation is used to display the trusted user interface; after detecting the second operation through the TEE, displaying the trusted user interface.
[0008] The method provided in this embodiment sets a first component connected to a trusted execution environment in a terminal device, and displays a trusted user interface by detecting a second operation corresponding to the first component. That is, the trusted user interface is displayed after the second operation is detected, so that the user has a strong perception of the currently displayed trusted user interface, thereby avoiding the user completing payment or entering important information on an untrusted user interface, thereby ensuring the security of information input.
[0009] In addition, in the method provided in this embodiment, the terminal device detects the second operation through TEE. Therefore, the first element can only be perceived in TEE, and malicious applications on the REE side cannot monitor and perceive the second operation corresponding to the first element. In other words, malicious applications cannot simulate the above-mentioned process of detecting and displaying the trusted user interface, thereby avoiding the problem that the TUI is replaced by an illegal UI and the user cannot distinguish it.
[0010] In one possible implementation, the method further includes: if the second operation is not detected by the TEE, not displaying the trusted user interface.
[0011] In this embodiment, the terminal device does not detect the second operation through TEE, indicating that the first element has not been operated according to the second operation for displaying the trusted user interface. At this time, the trusted user interface is not displayed, thereby preventing the user from completing payment or entering important information on other untrusted user interfaces, thereby ensuring the security of information input.
[0012] In one possible implementation, the first element includes a physical button, the second operation includes the physical button being pressed, and when the physical button is pressed, an interrupt message is sent to the TEE.
[0013] The physical button is a new physical button added on the terminal device side for controlling the display of the trusted user interface. That is, the new physical button is a button other than the original buttons such as the power button and volume button on the terminal device. When the user operates the new physical button in the second operation mode, it is only used to display the trusted user interface and is not used for other purposes.
[0014] Optionally, the newly added button can be one button or multiple buttons. When the newly added button is one button, the second operation includes pressing the dedicated button; if the newly added button is multiple buttons, the second operation includes pressing the multiple buttons in a preset order.
[0015] In one possible implementation, in response to a first operation, detecting a second operation through TEE includes: in response to the first operation, controlling the first application to send a notification message to TEE, where the notification message is used to notify TEE to display a trusted user interface; based on the notification message, monitoring an interrupt message through TEE; if an interrupt message is monitored through TEE, determining that the second operation is detected.
[0016] In some embodiments, the first element is a new physical button on the terminal device side for controlling the display of the trusted user interface, and the first element connects the TEE so that the new physical button is directly connected to the trusted operating system in the TEE. When the user operates the new physical button according to the second operation, the new physical button can directly send an interrupt message to the trusted operating system. In this case, when the trusted operating system in the TEE receives a notification message for notifying the TEE to display the trusted user interface, it can determine whether the second operation is detected by monitoring the interrupt message. If the trusted operating system monitors the interrupt message, it is determined that the second operation is detected. If the trusted operating system does not monitor the interrupt message, it is determined that the second operation is not detected.
[0017] Through the method provided in this embodiment, the newly added physical button is directly connected to the trusted operating system in the TEE, and the TUI is activated only by the newly added physical button. The entire processing flow is simple and direct. Only when the user presses the newly added physical button will the TUI be called up, allowing the user to feel a strong TUI.
[0018] In one possible implementation, the first element includes at least one physical button, and the second operation includes pressing the same physical button of the at least one physical button multiple times, for example, pressing the power button multiple times; or pressing different physical buttons of the at least one physical button in sequence according to the first order, for example, pressing the volume up, volume down, and power button in sequence.
[0019] The at least one physical button is one or more physical buttons originally on the terminal device side, such as a power button, a volume button, etc. Similarly, when the user operates the at least one physical button in the second operation mode, it is only used to display the trusted user interface and is not used for other purposes.
[0020] In one possible implementation, the terminal device also includes a sensor hub, and accordingly, the first component is connected to the TEE, including: the first component is connected to the TEE through the sensor hub, and when the first component is operated, the operation information is sent to the sensor hub, so that the sensor hub generates an operation record based on the operation information.
[0021] The first element may be a newly added physical button on the terminal device side for controlling the display of the trusted user interface, or may be one or more original physical buttons on the terminal device side.
[0022] In one possible implementation, in response to a first operation, a second operation is detected through TEE, including: in response to the first operation, controlling the first application to send a notification message to TEE, the notification message being used to notify TEE to display a trusted user interface; based on the notification message, controlling TEE to send a query message to the sensor hub, the query message being used to instruct the sensor hub to query the operation record of the first element, the operation record being generated by the sensor hub based on the received operation information; when the sensor hub queries the operation record and determines that the operation record is generated by the second operation, controlling the sensor hub to return confirmation information to TEE; if it is identified that TEE has received the confirmation information, it is determined that the second operation is detected.
[0023] Through the method provided in this embodiment, the first component on the terminal device side is connected to the TEE through the sensor hub, and the operation information generated by the first component is directly sent to the sensor hub, so that when the TEE determines to display the trusted user interface, it queries the operation record generated by the first component from the sensor hub. When the operation record is queried and it is determined that the operation record is generated by the second operation, it is determined that the second operation is detected, and then the display of the trusted user interface is controlled.
[0024] In addition, when the first element is at least one physical button originally existing in the terminal device, the method provided by this embodiment can reuse the existing physical buttons without adding new physical buttons, and the TUI is activated when the user operates at least one physical button with the second operation, thereby making the user have a strong perception of the TUI interface, which is conducive to establishing a safe image.
[0025] In a possible implementation, when the first component includes at least one physical button, the at least one physical button is further connected to the REE via a sensor hub.
[0026] In this embodiment, based on the fact that at least one physical button is one or more original physical buttons on the terminal device side, in order not to affect the processing logic of the original one or more physical buttons, the at least one physical button is connected to the TEE through the sensor hub while also being connected to the REE through the sensor hub.
[0027] In one possible implementation, the method further includes: detecting a third operation through a sensor hub; wherein the third operation is an operation on at least one physical key, and the third operation is different from the second operation; after detecting the third operation through the sensor hub, controlling the REE to process operation information corresponding to the third operation.
[0028] The third operation is an operation other than the second operation, i.e., a non-second operation. The sensor hub determines the operation record generated by the received operation information. If it is determined that the operation record does not achieve the second operation, the operation corresponding to the operation record is determined to be the third operation, and the current operation information is transmitted to the REE, so that the REE processes the operation information according to the existing logic of the at least one physical key.
[0029] In this embodiment, the terminal device controls the startup of TUI by reusing existing physical buttons, and the reuse of existing physical buttons will not affect the existing processing logic of the physical buttons themselves. In other words, the processing mechanism used to start TUI will not conflict with the processing mechanism of the current physical buttons themselves, and they are compatible with each other, thereby improving user experience and facilitating the large-scale application of TUI.
[0030] In one possible implementation, after receiving a first operation on a first application, in response to the first operation, and before detecting a second operation through TEE, the method further includes: displaying a first prompt message, where the first prompt message is used to instruct the user to perform the second operation within a first preset time.
[0031] In this embodiment, prompt information is displayed to prompt the user to operate the first element according to the second operation within a specified time, thereby improving the processing efficiency of the terminal device and the user's perception of the trusted user interface.
[0032] In a possible implementation, after the second operation is detected through the TEE, the trusted user interface is displayed, including: after the second operation is detected through the TEE within a second preset time, the trusted user interface is displayed.
[0033] In this implementation, the terminal device detects the second operation within a certain period of time, so as to avoid affecting the processing efficiency of the terminal device due to excessively long detection time.
[0034] Optionally, the method further includes: if a second operation is not detected by TEE within a second preset time, prompting the user that the operation has timed out.
[0035] In a second aspect, a method for displaying a trusted user interface is provided, which is applied to a terminal device, wherein the terminal device includes a rich execution environment (REE), a trusted execution environment (TEE), and a second component, wherein a first application is running in the REE, and the second component is connected to the TEE. The method includes: receiving a first operation on the first application, the first operation being used to request display of the trusted user interface of the first application; in response to the first operation, controlling the display of the trusted user interface through the TEE, and controlling the second component to run in a first mode through the TEE, and when the second component runs in the first mode, being used to uniquely indicate the trusted user interface.
[0036] The method provided in this embodiment sets a second component connected to a trusted execution environment in a terminal device. While the terminal device controls the display of a trusted user interface through TEE, it controls the second component to operate in a first mode, so that the user has a strong perception of the trusted user interface, thereby preventing the user from completing payments or entering important information on an untrusted user interface, thereby ensuring the security of information input.
[0037] In addition, in the method provided in this embodiment, the terminal device controls the second component to operate in the first mode through TEE. Therefore, the second component can only be controlled by TEE, and malicious applications on the REE side cannot control the second component, thereby avoiding the problem that the user cannot distinguish when the TUI is replaced by an illegal UI.
[0038] In one possible implementation, the second component is an indication device, and the second component is controlled to operate in a first mode through TEE, including: sending a first indication message to the second component through TEE, where the first indication message is used to instruct the second component to start running; and starting the second component according to the first indication message.
[0039] Among them, the indicating device is a newly added indicating device on the terminal device side for indicating the display of the trusted user interface. When the indicating device is started, it is only used to indicate that the current display interface is the trusted user interface and is not used for other purposes.
[0040] Optionally, the newly added indicator device may be a single indicator device, such as an indicator light; or may be multiple indicator devices, such as two indicator lights, or one indicator light and a speaker. When the newly added indicator device is a single indicator device, the first mode includes activating the indicator device, such as the indicator light being on; when the newly added indicator device is multiple indicator devices, the first mode includes activating all of the multiple indicator devices, such as multiple indicator lights being on simultaneously.
[0041] In one possible implementation, in response to a first operation, a trusted user interface is displayed through TEE control, and a second component is controlled through TEE to operate in a first mode, including: in response to the first operation, controlling the first application to send a notification message to TEE, the notification message being used to notify TEE to display the trusted user interface; according to the notification message, controlling the trusted user interface to be displayed through TEE control, and sending a first indication message to the second component through TEE, the first indication message being used to instruct the second component to operate in the first mode; controlling the second component to operate in the first mode after receiving the first indication message.
[0042] In some embodiments, the second component is a newly added indicator device on the terminal device side for indicating the display of the trusted user interface. The second component is connected to the TEE so that the newly added indicator device is directly connected to the trusted operating system in the TEE. Based on this, when the terminal device controls the second component to operate in the first mode through the TEE, it directly sends a first instruction message to the second component, so that the second component operates in the first mode after receiving the first instruction message.
[0043] The method provided in this embodiment directly connects the newly added indicator device to the trusted operating system in the TEE and starts up with the display of the TUI, making the solution simple and direct. Furthermore, because the newly added indicator device is directly connected to the trusted operating system, malicious applications on the REE side cannot control the newly added indicator device, thus avoiding the problem of the TUI being replaced by an illegal UI and the user being unable to distinguish it.
[0044] In one possible implementation, the second element is at least one indicator device, and the first mode includes the same indicator device in the at least one indicator device operating according to a preset mode, or different indicator devices in the at least one indicator device operating sequentially according to a second order.
[0045] The at least one indicator device is one or more indicator devices originally provided on the terminal device, such as an indicator light, a speaker, etc. Similarly, when the at least one indicator device operates in the first mode, it is only used to indicate that the current display interface is a trusted user interface and is not used for other purposes.
[0046] In a possible implementation, the terminal device further includes a sensor hub, and accordingly, the second component is connected to the TEE, including: the second component is connected to the TEE through the sensor hub.
[0047] In this embodiment, the second element may be a newly added indicating device on the terminal device side for indicating the display of the trusted user interface, or may be one or more original indicating devices on the terminal device side.
[0048] In one possible implementation, in response to a first operation, a trusted user interface is displayed through TEE control, and a second component is controlled through TEE to operate in a first mode, including: in response to the first operation, controlling the first application to send a notification message to TEE, the notification message being used to notify TEE to display the trusted user interface; according to the notification message, controlling the trusted user interface to be displayed through TEE control, and sending first control information to the sensor hub through TEE, the first control information being used to instruct the sensor hub to control the second component to operate in the first mode; controlling the sensor hub to send a first indication message to the second component after receiving the first control information, the first indication message being used to instruct the second component to operate in the first mode; controlling the second component to operate in the first mode after receiving the first indication message.
[0049] Through the method provided in this embodiment, the second component on the terminal device side is connected to the TEE through the sensor hub. When the terminal device displays the trusted user interface, the sensor hub is used to control the second component to operate in the first mode. This method is more universal and easier to expand.
[0050] In a possible implementation, when the second component is at least one indicator device, the at least one indicator device is further connected to the REE via a sensor hub.
[0051] In this embodiment, based on the fact that at least one indicating device is one or more original indicating devices on the terminal device side, in order not to affect the control logic of the original one or more indicating devices, the at least one indicating device is connected to the TEE through the sensor hub while also connecting to the REE through the sensor hub to receive control information of the REE through the sensor hub.
[0052] In one possible implementation, the method further includes: receiving second control information sent by the REE through the sensor hub, the second control information being used to instruct at least one indicating device to operate in a second mode, the second mode being different from the first mode; controlling the sensor hub to send a second indication message to the second element upon receiving the second control information, the second indication message being used to instruct the second element to operate in the second mode; and controlling the second element to operate in the second mode after receiving the second indication message.
[0053] The second mode is a mode other than the first mode, that is, a mode in which the second component operates in a mode other than the first mode.
[0054] In this embodiment, at least one existing indicator device of the terminal device operates in a first mode to indicate the TUI. This fully utilizes the inherent properties of the indicator device, such as frequency, to achieve a "specific flashing frequency indicating the safety interface," making it highly perceptible to the user and fostering a sense of security. Simultaneously, at least one indicator device operating in a second mode can indicate other services, thus achieving multiple uses for a single indicator.
[0055] In one possible implementation, when the second element is at least one indicating device, the method further includes: receiving, through the sensor hub, third control information sent by the REE, where the third control information is used to instruct the sensor hub to control the at least one indicating device to operate in the first mode; and controlling the sensor hub to return an error message to the REE and refuse to control the at least one indicating device to operate in the first mode.
[0056] This approach can prevent malicious applications in the REE from attempting to control at least one indicating device to operate in the first mode.
[0057] In one possible implementation, in response to a first operation, a trusted user interface is displayed through the TEE, and the second component is controlled to operate in the first mode through the TEE, and it also includes: displaying a second prompt information through the TEE, and the second prompt information is used to instruct the user to determine whether the second component is operating in the first mode.
[0058] In this way, the user is reminded to judge the currently displayed interface, and only proceed to the next step when the current displayed interface is determined to be a trusted user interface, such as entering a password or personal security information, thereby avoiding the user completing payment or entering important information on an untrusted user interface, further ensuring the security of information input.
[0059] In a possible implementation, the method further includes: when the trusted user interface exits display, controlling the second component through the TEE to stop operating in the first mode.
[0060] In this embodiment, when the trusted user interface exits the display, it indicates that the display process requiring the trusted user interface has ended. At this time, the terminal device controls the second component through TEE to stop operating in the first mode, thereby preventing the user from completing payment or entering important information on other untrusted user interfaces, thereby ensuring the security of information input.
[0061] It should be noted that in the embodiment of the present application, the first element and the second element on the terminal device side may be different, for example, the first element is a physical button and the second element is an indicator light; or they may be the same, for example, the first element or the second element is a physical button with an indication function.
[0062] In a third aspect, a terminal device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method for displaying a trusted user interface as described in the first aspect or the second aspect is implemented.
[0063] It should be noted that the terminal device provided in this embodiment may include both the first element and the second element. When the terminal device executes the method for displaying the trusted user interface provided in the first aspect or the second aspect of the embodiment of this application, the terminal device may only execute the method shown in the first aspect; or the terminal device may only execute the method shown in the second aspect; or the terminal device may execute both the method shown in the first aspect and the method shown in the second aspect. For example, after the terminal device detects the second operation through the TEE, it displays the trusted user interface and controls the second element to operate in the first mode through the TEE. The specific execution process is shown in the aforementioned embodiment and will not be described in detail in this section.
[0064] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method for displaying a trusted user interface as shown in the first aspect or the second aspect is implemented.
[0065] In a fifth aspect, a chip is provided, comprising a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the method for displaying a trusted user interface as shown in the first aspect or the second aspect is implemented.
[0066] It can be understood that the beneficial effects of the third to fifth aspects mentioned above can be found in the relevant description of the first aspect mentioned above, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] Figure 1A A schematic diagram of an attack scenario provided in an embodiment of the present application;
[0068] Figure 1B A schematic diagram of an attack scenario provided in another embodiment of the present application;
[0069] Figure 2A A schematic diagram of the connection method of the physical buttons provided in one embodiment of the present application;
[0070] Figure 2B A schematic diagram of the connection method of the indicator light provided in one embodiment of the present application;
[0071] Figure 3 A schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application;
[0072] Figure 4 A schematic diagram of the software architecture of a terminal device provided in an embodiment of the present application;
[0073] Figure 5 A schematic flowchart of a method for displaying a trusted user interface provided in Example 1 of this application;
[0074] Figure 6A A schematic diagram of a structure in which a first component is connected to a trusted execution environment according to an embodiment of the present application;
[0075] Figure 6B A schematic diagram of a structure of a first component accessing a trusted execution environment provided in another embodiment of the present application;
[0076] Figure 6C A structural diagram of a first component accessing a trusted execution environment provided by another embodiment of the present application;
[0077] Figure 7 A schematic interactive flow chart of a method for displaying a trusted user interface provided in one embodiment of the present application;
[0078] Figure 8 A schematic diagram of a transfer process according to an embodiment of the present application;
[0079] Figure 9 A schematic diagram of a trusted user interface provided by an embodiment of the present application;
[0080] Figure 10 A schematic interactive flow chart of a method for displaying a trusted user interface provided by another embodiment of the present application;
[0081] Figure 11A A schematic interactive flow chart of an existing logical processing process of at least one physical button provided in an embodiment of the present application;
[0082] Figure 11B A schematic interactive flow chart of a method for displaying a trusted user interface provided in yet another embodiment of the present application;
[0083] Figure 12 A schematic flowchart of a method for displaying a trusted user interface provided in Example 2 of this application;
[0084] Figure 13A A schematic diagram of a structure in which a second component is connected to a trusted execution environment according to an embodiment of the present application;
[0085] Figure 13B A schematic diagram of a structure in which a second component is connected to a trusted execution environment according to another embodiment of the present application;
[0086] Figure 13C A structural diagram of a second component accessing a trusted execution environment provided by another embodiment of the present application;
[0087] Figure 14 A schematic interactive flow chart of a method for displaying a trusted user interface provided in one embodiment of the present application;
[0088] Figure 15 A schematic diagram of a transfer process according to another embodiment of the present application;
[0089] Figure 16 A schematic diagram of a trusted user interface provided by another embodiment of the present application;
[0090] Figure 17 A schematic interactive flow chart of a method for displaying a trusted user interface provided by another embodiment of the present application;
[0091] Figure 18 A schematic interactive flow chart of a method for displaying a trusted user interface provided in yet another embodiment of the present application;
[0092] Figure 19A schematic diagram of the structure of the chip provided in an embodiment of the present application. DETAILED DESCRIPTION
[0093] The technical solutions provided in the embodiments of the present application are described below with reference to the accompanying drawings.
[0094] It should be understood that in the description of the embodiments of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in this article is merely a way to describe the association relationship of associated objects, indicating that three relationships can exist, for example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.
[0095] In this embodiment, the terms "first" and "second" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the features. In the description of this embodiment, unless otherwise specified, "plurality" means two or more.
[0096] Mobile payment refers to a service method in which users use terminal devices (such as mobile phones) to pay for the goods or services they consume. While mobile payment brings convenience to users, its security has always been a concern. Mobile payment applications usually run in an open rich execution environment (REE). Rich execution environment REE refers to an open, resource-rich application running environment with low security and is vulnerable to malware attacks, such as sensitive data being stolen, digital copyright being abused, and mobile payment being stolen. The application in REE is also called client application (CA). CA runs on a general-purpose processor such as This open environment provides a channel for information leakage, malware propagation, and man-in-the-middle attacks.
[0097] In some implementations, the attacker can implement a man-in-the-middle attack by controlling the user interface (UI). For example, in an application scenario where a terminal device performs payment or transfer based on user operations, the terminal device needs to display a user interface showing payment details or transfer details to the user, and the user needs to enter a password to complete the payment process. In this case, the attacker can modify the specific content of the payment by controlling the UI, thereby implementing the attack. For example, see Figure 1AAs shown in the figure, the terminal device displays a transfer details page showing the user's intended payment as a transfer of 100 yuan to User A. After the attack, the attacker modifies the transaction through the backend to a transfer of 10,000 yuan to User B. By manipulating the user interface, the user still sees a transfer of 100 yuan to User A. Because the user interface remains unchanged during this process, the user cannot distinguish between a secure and illegitimate interface and clicks "Confirm" to complete the payment process. In this way, the attacker modifies the original transfer transaction from 100 yuan to User A to 10,000 yuan to User B. Without the user being able to identify the secure interface, the attacker's intended payment is altered, creating a financial security issue and causing financial loss.
[0098] In other implementations, attackers can conduct man-in-the-middle attacks by obtaining user input. For example, in a terminal device where an input interface is needed to obtain important user information (such as passwords, confidential personal information, etc.), attackers can directly obtain user input by controlling the user interface, or indirectly guess user input by recording or capturing screenshots, identifying click locations, and thereby obtaining important user information, leading to user information leakage.
[0099] To enhance the security requirements for mobile payments, the Open Mobile Terminal Platform (OMTP) has proposed the concept of a trusted execution environment (TEE). A TEE is a highly secure application runtime environment, offering a higher level of security than an independent real-time (REE) and providing security services for the REE, such as fingerprint entry and verification, and payment verification and authentication. A TEE is an independent runtime environment that runs outside of the REE and is isolated from it, possessing its own independent execution space. Applications within the TEE are custom-built trusted applications (TAs), which can access the TEE's hardware and software resources through the TEE's internal interfaces. However, the CA within the REE cannot directly access the TEE's hardware and software resources. Only after passing TEE identity authentication can the CA within the REE invoke TEE resources or services, such as secure storage and secure display / input, through the TEE's application programming interface (API). In this way, in mobile payment scenarios, if the input and display of sensitive information is involved, the CA on the REE side can call the secure display / input TA in the TEE to display a trusted user interface (TUI) that complies with the GP specification, allowing users to protect their sensitive information through the TUI, such as the input of a personal identification number (PIN) and the confirmation of transaction information. When the TUI pops up, the entire screen display area of the terminal device is taken over by the TEE, and the user interface is configured to a secure state that can only be accessed by the TEE, completely blocking the REE from accessing the display area. For example, the TUI can prevent the displayed information from being attacked by any software or other TA on the REE side, such as screenshots, modifications, etc.; it also provides trusted input capabilities so that the user's input will not be extracted, modified or controlled by any software or other TA on the REE side, thereby preventing the CA in the REE from malicious programs eavesdropping on and stealing user sensitive information.
[0100] From the above, it can be seen that the TUI technology in TEE can prevent the user interface from being controlled, thereby preventing the attacker from modifying the interface information and implementing a man-in-the-middle attack; it can also prevent the attacker from directly obtaining interface data and obtaining important user information, such as the attack method shown in the above embodiment. That is to say, in the mobile payment scenario, as long as the TUI pops up normally, the user interface is set to a secure state that can only be accessed by TEE, and the user can think that the currently displayed user interface is a secure interface. However, before calling TEE, the business logic is running in REE. At this point, if the attacker controls the business application or system, the call to TEE can be blocked, and TUI will not be able to pop up. For example, see Figure 1B As shown in [1], an attacker controls a client application (also known as a business application) or system, preventing the legitimate UI (TUI) from popping up before the business process triggers it. Instead, an illegal interface pops up. In this case, the attacker replaces the TUI with an illegal interface. Users cannot distinguish between the secure and illegal interfaces displayed, so they enter important information on the illegal interface. This allows the attacker to obtain important user information, resulting in user information leakage.
[0101] Based on this, the terminal device can assist the user in identifying the security interface through interface identification or the participation of security hardware.
[0102] In some implementations, the TUI displayed by the terminal device is a display interface with a unique style. For example, the terminal device adds a personalized logo input by the user or generated by the system to the TUI. When the client application displays the TUI, the TUI includes the personalized logo, so that the user can have a strong perception of the TUI.
[0103] In other implementations, the terminal device participates in identifying the TUI through hardware. For example, see Figure 2A As shown in , the physical button is connected to the rich operating system on the REE side, and when the physical button is pressed, the terminal device triggers the rich operating system to broadcast a message. After the client application listens to the broadcast message, it displays the TUI, allowing the user to have a strong sense of the TUI. For another example, see Figure 2B As shown in , the physical output element (e.g., indicator light) is connected to the rich operating system on the REE side, and when the terminal device displays the TUI, the client application calls the system interface to trigger the physical output element, such as lighting up the indicator light or controlling the indicator light to flash at a dedicated frequency to remind the user that the current interface is a safe interface.
[0104] However, the aforementioned implementations also present the risk of being attacked by malicious applications. For example, a uniquely styled TUI could be detected by a malicious application from the REE side, allowing the attacker to replicate an identical, illegal interface. With physical key-assisted identification, when a key is pressed, the rich operating system on the REE side broadcasts a keystroke message that can be monitored by both secure client applications and malicious applications. With physical output element triggering, malicious applications could similarly control the indicator lights, replacing the legitimate TUI interface with a highly imitated illegal interface and then illuminating the indicator lights, a process that is indistinguishable to the user.
[0105] In order to solve the above problems, an embodiment of the present application provides a method for displaying a trusted user interface, which is applied to a terminal device. By setting a first element or a second element connected to a trusted execution environment in the terminal device to start or indicate the trusted user interface, the user has a strong perception of the trusted user interface, thereby avoiding the user completing payment or entering important information on an untrusted user interface, thereby ensuring the security of information input.
[0106] In this application, a terminal device may be a mobile phone, a tablet computer, a computer with wireless transceiver function, a wearable device (such as a smart watch), a smart screen, a vehicle-mounted device, an augmented reality (AR) / virtual reality (VR) device, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), or other terminal devices. The embodiments of this application do not limit the specific type of terminal device.
[0107] Figure 3 Schematic diagram of the hardware structure of a terminal device provided in an embodiment of the present application. The terminal device includes a processor 310, an external memory interface 320, an internal memory 321, a universal serial bus (USB) interface 330, a charging management module 340, a power management module 341, a battery 342, an antenna 1, an antenna 2, a mobile communication module 350, a wireless communication module 360, an audio module 370, a speaker 370A, a receiver 370B, a microphone 370C, a headphone jack 370D, a sensor module 380, a button 390, a motor 391, an indicator 392, a camera 393, a display 394, and a subscriber identification module (SIM) card interface 395.
[0108] It is understood that the structures illustrated in the embodiments of the present application do not constitute specific limitations on the terminal device. In other embodiments of the present application, the terminal device may include more or fewer components than shown, or may combine or separate certain components, or arrange the components differently. The illustrated components may be implemented in hardware, software, or a combination of software and hardware.
[0109] The processor 310 may include one or more processing units, for example: the processor 310 may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a memory, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units can be independent devices or integrated into one or more processors. Among them, the controller can be the nerve center and command center of the terminal device. The controller can generate operation control signals based on the instruction opcode and timing signal to complete the control of instruction fetching and execution.
[0110] Processor 310 may also include a memory for storing instructions and data. In some embodiments, the memory in processor 310 is a cache memory. This memory can store instructions or data that have just been used or are being recycled by processor 310. If processor 310 needs to use the same instruction or data again, it can directly retrieve it from the memory. This avoids duplicate accesses, reduces processor 310 latency, and thus improves system efficiency.
[0111] The charging management module 340 is configured to receive charging input from a charger. The charger can be either a wireless charger or a wired charger. In some wired charging embodiments, the charging management module 340 can receive charging input from the wired charger via the USB interface 330. In some wireless charging embodiments, the charging management module 340 can receive wireless charging input via the terminal device's wireless charging coil. While charging the battery 342, the charging management module 340 can also provide power to the terminal device via the power management module 341.
[0112] The power management module 341 is used to connect the battery 342, the charging management module 340, and the processor 310. The power management module 341 receives input from the battery 342 and / or the charging management module 340 and provides power to the processor 310, the internal memory 321, the external memory, the display 394, the camera 393, and the wireless communication module 360. The power management module 341 can also be used to monitor parameters such as battery capacity, battery cycle count, and battery health status (leakage, impedance), etc.
[0113] The wireless communication function of the terminal device can be implemented through antenna 1, antenna 2, mobile communication module 350, wireless communication module 360, modem processor and baseband processor.
[0114] Antenna 1 and Antenna 2 are used to transmit and receive electromagnetic wave signals. Each antenna in the terminal device can be used to cover a single or multiple communication frequency bands. Different antennas can also be reused to improve antenna utilization. For example, antenna 1 can be reused as a diversity antenna for a wireless local area network. In other embodiments, the antennas can be used in conjunction with a tuning switch.
[0115] The mobile communication module 350 can provide wireless communication solutions, including 2G / 3G / 4G / 5G, for terminal devices. The mobile communication module 350 may include at least one filter, switch, power amplifier, and low-noise amplifier (LNA). The mobile communication module 350 receives electromagnetic waves from antenna 1, filters and amplifies the received electromagnetic waves, and transmits them to the modem processor for demodulation. The mobile communication module 350 can also amplify the signals modulated by the modem processor and convert them into electromagnetic waves for radiation via antenna 1.
[0116] In some embodiments, at least some functional modules of the mobile communication module 350 may be provided in the processor 310. In some embodiments, at least some functional modules of the mobile communication module 350 may be provided in the same device as at least some functional modules of the processor 310.
[0117] The modem processor may include a modulator and a demodulator. The modulator is used to modulate the low-frequency baseband signal to be transmitted into a medium-high frequency signal. The demodulator is used to demodulate the received electromagnetic wave signal into a low-frequency baseband signal. The demodulator then transmits the demodulated low-frequency baseband signal to the baseband processor for processing. After being processed by the baseband processor, the low-frequency baseband signal is passed to the application processor. The application processor outputs a sound signal through an audio playback device (not limited to the speaker 370A, the receiver 370B, etc.) or displays an image or video through the display screen 394. In some embodiments, the modem processor may be an independent device. In other embodiments, the modem processor may be independent of the processor 310 and be set in the same device as the mobile communication module 350 or other functional modules.
[0118] The wireless communication module 360 can provide wireless communication solutions including wireless local area networks (WLAN) (such as wireless fidelity (Wi-Fi) networks), Bluetooth (BT), global navigation satellite system (GNSS), frequency modulation (FM), near field communication (NFC), infrared (IR), etc., which are applied to terminal devices. The wireless communication module 360 can be one or more devices that integrate at least one communication processing module. The wireless communication module 360 receives electromagnetic waves via the antenna 2, frequency modulates and filters the electromagnetic wave signals, and sends the processed signals to the processor 310. The wireless communication module 360 can also receive the signal to be sent from the processor 310, frequency modulate it, amplify it, and convert it into electromagnetic waves for radiation through the antenna 2.
[0119] The camera 393 is used to capture static images or videos. In some embodiments, the terminal device may include 1 or N cameras 393, where N is a positive integer greater than 1.
[0120] The display screen 394 is used to display images, videos, etc., such as the various device management interfaces in the embodiments of the present application. The display screen 394 includes a display panel. The display panel can be a liquid crystal display (LCD), an organic light-emitting diode (OLED), an active-matrix organic light-emitting diode or an active-matrix organic light-emitting diode (AMOLED), a flexible light-emitting diode (FLED), a MiniLED, a MicroLed, a Micro-oLed, a quantum dot light-emitting diode (QLED), etc. In some embodiments, the terminal device may include one or N display screens 394, where N is a positive integer greater than one.
[0121] External memory interface 320 can be used to connect an external memory card, such as a Micro SD card, to expand the storage capacity of the terminal device. The external memory card communicates with processor 310 via external memory interface 320 to implement data storage functions. For example, files such as music and videos can be stored on the external memory card.
[0122] The internal memory 321 can be used to store computer executable program code, which includes instructions. The processor 310 executes various functional applications and data processing of the terminal device by running the instructions stored in the internal memory 321. The internal memory 321 may include a program storage area and a data storage area. The program storage area may store an operating system and at least one application required for a function (such as a sound playback function, an image playback function, etc.). The data storage area may store data created during the use of the terminal device (such as audio data, a phone book, etc.).
[0123] In addition, the internal memory 321 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, a universal flash storage (UFS), etc.
[0124] The terminal device can implement audio functions through the audio module 370, the speaker 370A, the receiver 370B, the microphone 370C, the headphone jack 370D, and the application processor.
[0125] The audio module 370 is used to convert digital audio signals into analog audio signals for output, and is also used to convert analog audio input into digital audio signals. The audio module 370 can also be used to encode and decode audio signals. In some embodiments, the audio module 370 can be provided in the processor 310, or some functional modules of the audio module 370 can be provided in the processor 310.
[0126] Speaker 370A, also known as a "horn," is used to convert audio electrical signals into sound signals. The terminal device can listen to music or listen to hands-free calls through speaker 370A. For example, the speaker can play the comparison analysis results provided in the embodiments of the present application.
[0127] The receiver 370B, also called the "earpiece", is used to convert audio electrical signals into sound signals. When the terminal device receives a call or voice message, the voice can be heard by placing the receiver 370B close to the human ear.
[0128] Microphone 370C, also known as "microphone" or "microphone", is used to convert sound signals into electrical signals. When making a call or sending a voice message, the user can speak by putting their mouth close to the microphone 370C to input the sound signal into the microphone 370C. The terminal device can be provided with at least one microphone 370C. In other embodiments, the terminal device can be provided with two microphones 370C, which can not only collect sound signals but also realize noise reduction function. In other embodiments, the terminal device can also be provided with three, four or more microphones 370C to realize sound signal collection, noise reduction, and identification of sound sources, and realize directional recording function, etc.
[0129] In some embodiments, the terminal device can receive ultrasonic signals sent by other electronic devices through the microphone 370C, and identify the frequency and reception strength of the ultrasonic signals through the processor 310.
[0130] The headphone jack 370D is used to connect a wired headphone. The headphone jack 370D can be a USB interface 330 or a 3.5mm open mobile terminal platform (OMTP) standard interface or a cellular telecommunications industry association of the USA (CTIA) standard interface.
[0131] The sensor module 380 may include a pressure sensor 380A, a gyroscope sensor 380B, an air pressure sensor 380C, a magnetic sensor 380D, an acceleration sensor 380E, a distance sensor 380F, a proximity light sensor 380G, a fingerprint sensor 380H, a temperature sensor 380J, a touch sensor 380K, an ambient light sensor 380L, a bone conduction sensor 380M, etc.
[0132] Keys 390 include a power button, a volume button, and the like. Keys 390 may be mechanical keys or touch-sensitive keys. The terminal device may receive key inputs and generate key signal inputs related to user settings and function control of the terminal device.
[0133] Motor 391 can generate vibration alerts. Motor 391 can be used for incoming call vibration alerts and touch vibration feedback. For example, touch operations on different applications (such as taking photos, playing audio, etc.) can correspond to different vibration feedback effects. Motor 391 can also correspond to different vibration feedback effects for touch operations on different areas of the display screen 394.
[0134] Indicator 392 can be an indicator light, which can be used to indicate the charging status and power changes of the terminal device, and can also be used to indicate messages, missed calls, notifications, etc.
[0135] SIM card interface 395 is used to connect a SIM card. A SIM card can be connected to and disconnected from the terminal device by inserting or removing it from SIM card interface 395. The terminal device may support one or N SIM card interfaces, where N is a positive integer greater than 1. SIM card interface 395 can support Nano SIM cards, Micro SIM cards, and SIM cards. Multiple cards can be inserted into the same SIM card interface 395 simultaneously. The cards can be of the same or different types.
[0136] Figure 4 Schematic diagram of the software architecture of the terminal device provided in the embodiment of the present application is shown. Figure 4As shown, the terminal device includes a hardware platform 400 and two isolated execution environments running on the hardware platform 400: a rich execution environment (REE) 410 and a trusted execution environment (TEE) 420. Each of the two environments has independent hardware resources and operating systems. Hardware isolation technologies, such as the TrustZone mechanism, can be used to isolate the hardware resources of REE 410 and TEE 420. Virtualization technology can also be used to isolate the operating systems of REE 410 and TEE 420, as well as applications. Thus, the hardware and software resources accessible to TEE 420 are separated from REE 410. Furthermore, TEE 420 imposes very strict restrictions on the data and functions accessible to applications, ensuring that its security level meets specific security requirements. Therefore, TEE 420 is generally considered a secure execution environment. REE 410 is an execution environment outside of TEE 420. Compared to TEE 420, REE 410 is less secure and more vulnerable to attacks. Applications running in REE 410, namely client applications (CA 411), are also considered untrusted.
[0137] The hardware platform 400 of the terminal device includes public peripherals and trusted peripherals. Trusted peripherals include secure elements (SEs) that can only be controlled and accessed by TEE 420, such as secure memory, secure clock, and trusted keyboard. Public peripherals are devices that can be controlled and accessed by the rich operating system (Rich OS) 412 in REE 410.
[0138] The application running in TEE 420 is a trusted application TA 421. TA 421 can provide security-related functions or services to client application CA 411 in REE 410 or other TAs within TEE 420. A trusted operating system (Trusted OS) 422 running in TEE 420 provides TA 421 with a TEE internal interface 423. TA 421 uses TEE internal interface 423 to obtain access to secure resources and services, including but not limited to key injection and management, encryption, secure storage, secure clock, trusted user interface, and trusted keyboard.
[0139] Rich operating system 412 provides more features than trusted operating system 422. Rich operating system 412 is very open and can accept various types of applications, but its security is also lower than trusted operating system 422. Rich operating system 412 can be The CA 411 running in the REE 410 can utilize the external interface 424 provided by the TEE 420 to request security services provided by the TA 421 in the TEE 420. For example, in scenarios such as mobile payments and online banking transfers, if sensitive user information is required to be input or displayed, the client application CA 411 in the REE 410 can use the external interface 424 provided by the TEE 420 to call the TUI and trusted keyboard services on the TEE 420 side to prevent malicious applications on the REE 410 side from eavesdropping and stealing sensitive user information.
[0140] based on Figure 3 The hardware structure of the terminal device shown and Figure 4 The software architecture of the terminal device shown in FIG. An embodiment of the present application provides a method for displaying a trusted user interface, wherein the display of the trusted user interface is determined by an element connected to a trusted execution environment. The following exemplarily explains the method for displaying the trusted user interface provided by the present application through two parts: (1) a first element starting the trusted user interface, and (2) a second element indicating the trusted user interface.
[0141] It should be noted that, in this embodiment, the first element and the second element may be different, for example, the first element is a physical button and the second element is an indicator light; or they may be the same, for example, the first element and the second element are physical buttons with an indication function.
[0142] Example 1: First component starts trusted user interface
[0143] In this embodiment, the way in which the first component starts the trusted user interface means that when the terminal device determines that the trusted user interface needs to be displayed, the trusted user interface is started through the corresponding operation of the first component, so that the user perceives that the currently displayed interface is a secure interface.
[0144] Figure 5 This is a flow chart of a method for displaying a trusted user interface provided by an embodiment of the present application. The method is applied to a terminal device, which includes a rich execution environment (REE), a feasible execution environment (TEE), and a first component. A first application is running in the REE, and the first component is connected to the TEE. Figure 5 As shown, the method includes the following steps S501 to S503.
[0145] S501: A terminal device receives a first operation on a first application, where the first operation is used to request display of a trusted user interface of the first application.
[0146] The first application is an application running in the REE, such as a banking app or a payment application. Typically, some functions in the first application that do not require security (such as user registration, information query, and business details display) can be executed in the REE. When functions that require security (such as entering payment passwords or personal identity information) need to be implemented, a trusted application (TA) that implements the corresponding function can be launched in the TEE. This trusted application (TA) includes a trusted user interface (TUI).
[0147] The first operation is an operation on the display interface of the first application, used to control the display of the trusted user interface of the first application. After detecting the first operation, the client application CA in the first application uses the external interface provided by the TEE to request the security service provided by the trusted application TA in the TEE, namely, to request the display of the trusted user interface TUI in the trusted application TA.
[0148] S502: The terminal device detects a second operation through the TEE in response to the first operation; wherein the second operation is an operation on the first element, and the second operation is used to display a trusted user interface.
[0149] The first element may be a physical button newly added to the terminal device, or may be at least one physical button inherent in the terminal device itself.
[0150] In some embodiments, the first element is a new physical button in the terminal device. For example, the new physical button can be a dedicated button for launching the TUI, or a sensor device, such as a fingerprint sensor. That is, in this embodiment, the new physical button has no other functional uses and is only used to launch the trusted user interface. In this case, the second operation can be the pressing of the new physical button.
[0151] In one implementation of this embodiment, see Figure 6A As shown, the first element connecting to the TEE includes: the newly added physical button is directly connected only to the trusted operating system in the TEE. When the newly added physical button is pressed, an interrupt message is sent only to the trusted operating system. At this time, the terminal device detecting the second operation through the TEE can be: the terminal device monitors the interrupt message through the trusted operating system, and if the interrupt message is monitored by the trusted operating system, it is determined that the second operation has been detected.
[0152] In another implementation of this embodiment, see Figure 6BAs shown, the first element connected to the TEE includes: the newly added physical button is connected to the trusted operating system in the TEE only through the operation record judgment module in the sensor hub (also known as the smart sensor hub). Among them, the sensor hub is configured in the terminal device for connecting and processing data from various sensor devices. It runs neither in the REE nor in the TEE. Its execution environment is a relatively safe operating environment and is isolated from the REE and TEE. When the newly added physical button is pressed, only the operation information (or key information) is sent to the operation record judgment module in the sensor hub, so that the operation record judgment module in the sensor hub generates an operation record based on the received operation information. At this time, the terminal device detects the second operation through TEE: the terminal device controls the trusted operating system in TEE to send a query message to the operation record judgment module in the sensor hub, and when the operation record judgment module in the sensor hub queries the operation record and determines that the operation record is generated by the second operation, the operation record judgment module in the sensor hub is controlled to return confirmation information to the trusted operating system; if the terminal device recognizes that the trusted operating system has received the confirmation information, it is determined that the second operation has been detected.
[0153] In other embodiments, the first element is at least one physical button inherent to the terminal device, such as a power button, a volume button, etc. In this case, the second operation includes pressing the same physical button of the at least one physical button multiple times, such as pressing the power button multiple times; or pressing different physical buttons of the at least one physical button in sequence according to the first order, such as pressing the volume up, volume down, and power button in sequence.
[0154] In one implementation of this embodiment, see Figure 6C As shown, the first element connected to the TEE includes: the at least one physical button is connected to the trusted operating system in the TEE through the operation record judgment module in the sensor hub. After the at least one physical button is operated, the operation information is sent to the operation record judgment module in the sensor hub, so that the operation record judgment module in the sensor hub generates an operation record based on the operation information and determines whether the operation record is generated by the second operation, or determines whether there is an operation record of the second operation based on the operation information. It can be considered that in this embodiment, the operation record generated by the operation record judgment module in the sensor hub according to the received operation information corresponding to the second operation is an operation record of the key combination.
[0155] In this embodiment, the process of the terminal device detecting the second operation through TEE can be seen in Figure 6B The detection process in the embodiment shown is not described in detail in this embodiment.
[0156] S503: After detecting the second operation through the TEE, the terminal device displays a trusted user interface.
[0157] After the terminal device detects the second operation through the TEE, it indicates that the first element has been operated according to the second operation for uniquely controlling the display of the trusted user interface. At this time, the terminal device controls the display of the trusted user interface. In this way, the user can have a strong perception of the trusted user interface.
[0158] Optionally, if the terminal device does not detect the second operation through TEE, it indicates that the first element has not been operated in accordance with the second operation used to uniquely control the display of the trusted user interface. At this time, the trusted user interface is controlled not to be displayed, thereby preventing the user from completing payment or entering important information on other untrusted user interfaces, thereby ensuring the security of information input.
[0159] In this embodiment, the first component can be connected to the TEE directly through a trusted operating system, or it can be connected to the TEE through a keystroke log determination module in a sensor hub. Regardless of the connection method, the first component can only be sensed within the TEE, and malicious applications on the REE side cannot monitor and perceive the second operation of the first component and the generated operation log.
[0160] The following describes in detail the display method of the trusted user interface provided in this example in combination with different ways of connecting the first component to the TEE.
[0161] Figure 7 A schematic flow chart of a method for displaying a trusted user interface provided in an embodiment of the present application, involving a newly added physical button through Figure 6A The connection method shown is to start the trusted user interface process by adding a physical button when connecting to TEE. Figure 7 As shown, the method includes the following steps S701 to S705.
[0162] S701: A first application sends a first notification to a trusted application, where the first notification is used to instruct the trusted application to start running.
[0163] It should be understood that under normal circumstances, the trusted operating system in the TEE will enter a dormant state if it is not called within a preset time, and thus will not be able to perceive the operation information sent by the first component. Specifically, the operation information can be an interrupt message. Therefore, before the first application determines to call the trusted application in the TEE, it needs to first send a first notification to the trusted application in the TEE, so that the trusted operating system starts running after receiving the first notification.
[0164] In some embodiments, when the first application determines that a function with security requirements needs to be implemented, such as starting a transfer process or starting a process of obtaining user personal sensitive information, the first application sends a first notification to the trusted application.
[0165] Optionally, after receiving the first notification, the trusted application returns a confirmation message to the first application, where the confirmation message is used to indicate that the trusted application has started running.
[0166] S702, the first application sends a notification message to the trusted application in response to the first operation, and displays a first prompt message, wherein the notification message is used to instruct the trusted application to send a request message to the trusted operating system requesting to display a trusted user interface, and the first prompt message is used to instruct the user to press a newly added physical button.
[0167] In some embodiments, the first prompt information is used to instruct the user to press the newly added physical button within the first preset time. For example, taking the first application as a bank APP, in the transfer process of the bank APP, see Figure 8 As shown in Figure (a), the bank APP responds to the user clicking the first operation of the operation control in the transfer interface, and determines that it needs to call Figure 8 In the trusted user interface shown in Figure (b), a first prompt message is displayed on the display interface of the terminal device, and the first prompt message is used to instruct the user to press the newly added physical button within the first preset time. Figure 9 As shown in , the first prompt information may be “Please press the TUI startup dedicated key within X seconds to start the trusted user interface for entering a password”.
[0168] After the first prompt message is displayed on the terminal device, the user can operate the newly added physical button within the first preset time indicated in the first prompt message.
[0169] S703: After receiving the notification message, the trusted application sends a request message to the trusted operating system, where the request message is used to request the trusted operating system to display a trusted user interface.
[0170] S704: After receiving the request message, the trusted operating system detects a second operation.
[0171] In some embodiments, when a newly added physical button detects a user operation, it generates an interrupt and sends an interrupt message to the trusted operating system. After receiving the interrupt message, the trusted operating system generates an operation record based on the interrupt message. In this case, after receiving the request message, the trusted operating system queries the operation record and, upon finding the operation record, determines that the second operation has been detected.
[0172] In other embodiments, when the newly added physical button detects a user operation, an interrupt occurs and an interrupt message is sent to the trusted operating system. After receiving the request message, the trusted operating system monitors the interrupt message; if the interrupt message is monitored, it determines that the second operation has been detected.
[0173] During specific implementation, a timeout detection mechanism can also be set in this step, that is, if the trusted operating system queries the operation record or monitors the interrupt message within the second preset time (for example, 3 seconds or 5 seconds) from the time the request message is received, it is determined that the second operation is detected and the operation record or message record is cleared, and then step S705 is executed, otherwise the business process is terminated and the user is prompted with the corresponding reason. For example, if the second operation is not detected within the second preset time, the user is prompted that the operation has timed out. Among them, the second preset time can be set as needed by each first application when setting up the corresponding trusted application in the TEE, such as bank APP1 sets the second preset time to 3 seconds, and bank APP2 sets the second preset time to 5 seconds; it can also be a time period preset in the trusted operating system itself. Regardless of which first application is targeted, the second preset time is the same time period, such as 3 seconds. In actual applications, it can be set according to specific needs, and this embodiment does not limit this.
[0174] S705 : After detecting the second operation, the trusted operating system controls display of the trusted user interface.
[0175] After the trusted operating system detects the second operation, it indicates that the newly added physical key has been pressed. At this time, the trusted operating system controls the display of the trusted user interface.
[0176] In some embodiments, a trusted user interface is used to obtain the user's payment password. After the user enters the password through the input box displayed in the trusted user interface, the trusted operating system sends the password to the trusted application. The trusted application encrypts the password and returns the encrypted password to the first application, so that the first application completes the corresponding business process based on the received password ciphertext, such as payment or transfer.
[0177] In this embodiment, the newly added physical button of the terminal device is directly connected to the trusted operating system in the TEE, and the TUI is activated only by the newly added physical button, making the entire processing flow simple and direct. The TUI is only activated when the user presses the newly added physical button, allowing the user to perceive a strong TUI. Because the newly added physical button is only perceived in the trusted operating environment, malicious applications on the REE side cannot be informed of the operation event of the newly added physical button being pressed, thereby preventing the TUI from being replaced by an illegal UI without the user being able to distinguish it, which is conducive to the large-scale application of TUI and establishes a secure image.
[0178] Figure 10 A schematic flow chart of a method for displaying a trusted user interface provided in another embodiment of the present application, involving a newly added physical button through Figure 6B The connection method shown is to start the trusted user interface process by adding a physical button when connecting to TEE. Figure 10 As shown, the method includes the following steps S1001 to S1006.
[0179] S1001, the first application sends a notification message to the trusted application in response to the first operation, and displays a first prompt message, wherein the notification message is used to instruct the trusted application to send a request message to the trusted operating system requesting to display a trusted user interface, and the first prompt message is used to instruct the user to press a newly added physical button.
[0180] S1002: After receiving the notification message, the trusted application sends a request message to the trusted operating system. The request message is used to request the trusted operating system to display a trusted user interface.
[0181] S1003: After receiving the request message, the trusted operating system sends a query message to the operation record determination module. The query message is used to instruct the operation record determination module to query the operation record of the newly added physical key.
[0182] In some embodiments, the trusted operating system sets a timer logic and sends a query message to the operation record determination module at regular intervals before the timer expires, thereby querying the operation records of the newly added physical keys in a cyclic query manner.
[0183] In this embodiment, the newly added physical button in the terminal device directly communicates with the operation record determination module in the Sensor Hub. Therefore, when a user presses the newly added physical button, the newly added physical button only sends operation information, such as a keystroke message, to the operation record determination module in response to the user operation. After receiving the keystroke message, the operation record determination module generates and stores the operation record based on the keystroke message. Based on this, after receiving the query message sent by the trusted operating system, the operation record determination module detects the second operation by querying the operation record.
[0184] S1004: When the operation record determination module finds the operation record and determines that the operation record is generated by the second operation, it returns confirmation information to the trusted operating system.
[0185] In this embodiment, if the operation record determination module queries an operation record and determines that the operation record is generated by the second operation (because in this embodiment, the newly added physical button is only connected to the operation record determination module, the operation record can only be generated by the second operation), it is determined that the second operation is detected and the operation record is cleared. Then, a confirmation message is returned to the trusted operating system, and the confirmation message is used to indicate that the second operation has been detected. If no operation record is queried, no confirmation message is returned.
[0186] Optionally, during specific implementation, a timeout detection mechanism may also be set in this step, that is, if the operation record is found within a third preset time (for example, 3 seconds or 5 seconds) from the time the query message is received, the operation record judgment module determines that the second operation is detected and clears the operation record, and then returns confirmation information to the trusted operating system; otherwise, the business process is terminated and the user is prompted with the corresponding reason, such as prompting the user that the operation has timed out.
[0187] S1005: The trusted operating system receives the confirmation information and determines that the second operation is detected.
[0188] If the trusted operating system does not receive the confirmation information, it is determined that the second operation is not detected.
[0189] S1006: After detecting the second operation, the trusted operating system controls display of the trusted user interface.
[0190] In this embodiment, after receiving confirmation information from the operation record determination module, the trusted operating system indicates that the second operation has been detected. At this point, the trusted operating system controls the pop-up of a trusted user interface, such as a TUI that prompts the user to enter a password or obtain a PIN code. After the user enters the corresponding information into the input box displayed in the trusted user interface, the trusted operating system sends this information to the trusted application, which then returns it to the first application, allowing the first application to complete the corresponding business process, such as payment or transfer, based on the received information.
[0191] In this embodiment, the newly added physical button of the terminal device is connected to the trusted execution environment through the operation record judgment module in the Sensor Hub. The operation information generated by the newly added physical button is directly sent to the operation record judgment module, so that the trusted operating system can query the operation record generated by the newly added physical button from the operation record judgment module when determining to display the trusted user interface. When the operation record is queried, it is determined that the second operation is detected, and then the display of the trusted user interface is controlled.
[0192] In this embodiment, by Figure 7 and Figure 10The one-click trusted user interface (TUI) approach shown in Figure 2 triggers and invokes the TUI only after the user presses a newly added physical button. This prevents the TUI from being replaced by an illicit UI and preventing the user from distinguishing it. This ensures that users have a strong sense of security and helps establish a secure image. Furthermore, the operation information generated by the newly added physical button is sent to the operation record judgment module in the Sensor Hub for query by the trusted operating system. This approach is more versatile and easily scalable, facilitating large-scale application of TUI.
[0193] The above is a process of starting the trusted user interface through a physical button newly added on the terminal device side. The following describes a process of starting the trusted user interface through at least one physical button inherent in the terminal device.
[0194] It should be noted that in this embodiment, since the first element is at least one physical key inherent to the terminal device, this at least one physical key is also connected to the rich operating system in the REE via the operation record determination module in the sensor hub. The terminal device is able to detect a third operation through the operation record determination module. This third operation is also an operation on the at least one physical key, but is different from the second operation. After the operation record determination module in the sensor hub detects the third operation, the terminal device controls the rich operating system to process the operation information of the third operation according to the existing logic of the at least one physical key.
[0195] For example, in some application scenarios, see Figure 11A As shown, when at least one physical key is pressed, the at least one physical key receives the user's key operation and sends the operation information of the key operation to the operation record judgment module; the operation record judgment module judges whether the current operation has achieved the second operation based on the operation record generated by the operation information, that is, whether the current operation mode causes the special key combination for starting the TUI to occur. If so, it indicates that the current operation has achieved the second operation, then the identification information for indicating that the second operation has been achieved is stored, and the subsequent query message sent by the trusted operating system is waited for; if not, it indicates that the second operation has not been achieved, and the operation record is generated by a third operation, then the current operation information is passed to the rich operating system, so that the rich operating system processes the operation information according to the existing logic of at least one physical key. For example, if the user presses the volume up key, the rich operating system sends a key broadcast based on the operation information of the volume up key, and the system application that controls the volume adjustment turns up the volume after listening to the key broadcast; if the user presses the power key, the rich operating system turns off the screen according to the operation information of the power key.
[0196] Figure 11B A schematic flow chart of a method for displaying a trusted user interface provided in another embodiment of the present application, involving at least one physical button through Figure 6CThe connection method shown is to start the trusted user interface process by at least one physical button when connected to the TEE. Figure 11B As shown, the method includes the following steps S1101 to S1106.
[0197] S1101, the first application sends a notification message to the trusted application in response to the first operation, and displays a first prompt message, wherein the notification message is used to instruct the trusted application to send a request message to the trusted operating system requesting to display a trusted user interface, and the first prompt message is used to instruct the user to operate at least one physical key according to the first operation mode.
[0198] Exemplarily, the first prompt message may be “Please press the volume up, volume down, and power buttons in sequence within X seconds to start the trusted user interface for entering a password.”
[0199] S1102: After receiving the notification message, the trusted application sends a request message to the trusted operating system, where the request message is used to request the trusted operating system to display a trusted user interface.
[0200] S1103: After receiving the request message, the trusted operating system sends a query message to the operation record determination module. The query message is used to instruct the operation record determination module to query the operation record of at least one physical key.
[0201] S1104: When the operation record determination module finds the operation record and determines that the operation record is generated by the second operation, it returns confirmation information to the trusted operating system.
[0202] In this embodiment, based on the fact that at least one physical button on the terminal device side is an external component inherent to the terminal device itself, when the user presses the at least one physical button, the operation record judgment module needs to judge the key message after receiving at least one key message sent by the at least one physical button to determine whether the at least one physical button is generated by the second operation. As described in the aforementioned embodiment, when the first element is at least one physical button inherent to the terminal device itself, the first operation mode includes pressing the same physical button of the at least one physical button multiple times, or pressing different physical buttons of the at least one physical button in sequence according to the first order. In other words, the operation record judgment module needs to judge whether the at least one physical button generates an operation record of the key combination.
[0203] In some embodiments, the operation record judgment module can determine whether to generate an operation record of a key combination based on the reception time of the at least one key message. For example, if two key messages sent by the power key are received within 2 seconds, it is determined that an operation record of a key combination is generated; or if key messages sent by the volume up, volume down and power key are received respectively within 2 seconds, it is determined that an operation record of a key combination is generated.
[0204] The operation record determination module determines the operation record generated by the received operation information to determine whether the second operation is achieved, and stores identification information indicating that the second operation is achieved when the second operation is achieved.
[0205] After receiving the query message from the trusted operating system, the operation record determination module detects the second operation by searching for and identifying the presence of identification information indicating that the second operation has been performed. If the identification information is found, it determines that the second operation has been detected and clears the operation record. It then returns a confirmation message to the trusted operating system, indicating that the second operation has been detected. If no identification information is found, no confirmation message is returned, or an error report is returned with the user's notification of the reason, such as an operation timeout.
[0206] S1105: The trusted operating system receives the confirmation information and determines that the second operation is detected.
[0207] If the trusted operating system does not receive the confirmation information, it is determined that the second operation is not detected.
[0208] S1106: After detecting the second operation, the trusted operating system controls display of the trusted user interface.
[0209] This embodiment controls the launch of the TUI by recording the key combination operation generated by at least one physical key inherent to the terminal device. This reuses existing physical keys, eliminating the need for new physical keys. This provides a strong user perception and helps establish a secure image. Furthermore, the dedicated key combination used to launch the TUI is only perceived by trusted applications within the Trusted Execution Environment (TEE). Malicious applications on the REE side are unaware of the occurrence of this key combination event. By pressing the dedicated key combination, the user triggers and invokes the TUI, preventing the TUI from being replaced by an illicit UI and the user from being unable to distinguish it. Furthermore, the key message generated by the at least one physical key is directly transmitted to the Sensor Hub, and the dedicated key combination for launching the TUI is only queried by the trusted operating system. This approach is more versatile and easier to scale, facilitating the large-scale deployment of the TUI. Furthermore, in this embodiment, reusing existing physical keys does not affect the existing processing logic of the physical keys themselves. In other words, the processing mechanism used to launch the TUI does not conflict with the processing mechanism of the existing physical keys themselves, and they are mutually compatible.
[0210] Example 2: The second element indicates a trusted user interface
[0211] In this embodiment, the second element indicates the trusted user interface in a manner that, when the terminal device displays the trusted user interface, a synchronous notification of the indicating device is used to make the user aware that the currently displayed interface is a secure interface.
[0212] Figure 12 A method for displaying a trusted user interface provided in an embodiment of the present application is applied to a terminal device, the terminal device including a rich execution environment (REE), an executable environment (TEE), and a second component, wherein a first application is running in the REE and the second component is connected to the TEE. Figure 12 As shown, the method includes the following steps S1201 to S1202.
[0213] S1201: A terminal device receives a first operation on a first application, where the first operation is used to request display of a trusted user interface of the first application.
[0214] In this embodiment, the specific content of step S1201 refers to the content of the aforementioned step S501, which will not be described in detail in this embodiment.
[0215] S1202, in response to the first operation, the terminal device controls the display of the trusted user interface through TEE, and controls the second component to operate in the first mode through TEE. When the second component operates in the first mode, it is used to uniquely indicate the trusted user interface.
[0216] The second element may be a newly added indicator in the terminal device, or may be at least one indicator inherent in the terminal device itself.
[0217] It should be noted that, in this embodiment, when the terminal device does not display the trusted user interface, it does not control the second component to operate in the first mode.
[0218] In some embodiments, the second element is a newly added indicator device in the terminal device, such as a dedicated TUI indicator light or a dedicated TUI audio player. In other words, the newly added indicator device is only used to indicate the trusted user interface and is not used for other indications. In this case, the first mode includes the newly added indicator device being activated, such as the dedicated TUI indicator light being illuminated.
[0219] In one implementation of this embodiment, see Figure 13A As shown, the second element connected to the TEE includes: the newly added indicator device is directly connected only to the trusted operating system in the TEE. When the terminal device controls the display of the trusted user interface through the TEE, the newly added indicator device is controlled to start and run synchronously.
[0220] In another implementation of this embodiment, see Figure 13B As shown, the second element connecting to the TEE includes: the newly added indicator device is connected to the trusted operating system in the TEE only through the indicator device judgment module in the sensor hub. When the terminal device displays the trusted user interface through the TEE control, the indicator device judgment module in the sensor hub controls the newly added indicator device to start and run synchronously.
[0221] In other embodiments, the second element is at least one indicator device inherent to the terminal device, such as a flashlight, a speaker, etc. In this case, the first mode includes the same indicator device in the at least one indicator device operating according to a preset mode, for example, controlling the flashlight to flash at a preset frequency and controlling the speaker to play audio at a preset frequency; or different indicator devices in the at least one indicator device operating sequentially according to a second sequence, for example, controlling the flashlight to flash once and then controlling the speaker to play audio once, etc.
[0222] In one implementation of this embodiment, see Figure 13C As shown, the first element connected to the TEE includes: at least one indicator device is connected to the trusted operating system in the TEE through the indicator device judgment module in the sensor hub. When the terminal device controls the display of the trusted user interface through the TEE, the indicator device judgment module in the sensor hub controls the at least one indicator device to operate in a first mode. The first mode is different from the existing operating mode of the at least one indicator device itself, and is an operating process that is different from other operating modes. When the first mode is running, it is only used to indicate the trusted user interface.
[0223] In this embodiment, the second component can be connected to the TEE directly through the trusted operating system, or it can be connected to the TEE through the indicator device judgment module in the sensor hub. Regardless of the connection method, the second component can only be controlled by the trusted operating system in the TEE, and malicious applications on the REE side cannot control the second component.
[0224] The following is a detailed explanation of the display method of the trusted user interface provided in this example in combination with different ways of connecting the second component to the TEE.
[0225] Figure 14 A schematic flow chart of a method for displaying a trusted user interface provided in an embodiment of the present application, involving a newly added indicating device through Figure 13A When the connection method shown is connected to TEE, the trusted user interface process is indicated by the newly added indicator device. Figure 14 As shown, the method includes the following steps S1401 to S1405.
[0226] S1401: In response to a first operation, a first application sends a notification message to a trusted application. The notification message is used to instruct the trusted application to send a request message to a trusted operating system requesting display of a trusted user interface.
[0227] S1402: After receiving the notification message, the trusted application sends a request message to the trusted operating system. The request message is used to request the trusted operating system to display a trusted user interface.
[0228] S1403: After receiving the request message, the trusted operating system controls the display of the trusted user interface and sends a first indication message to the newly added indication device. The first indication message is used to instruct the newly added indication device to start running.
[0229] For example, taking the first application as a bank APP, in the transfer process of the bank APP, see Figure 15 As shown in Figure (a), the bank APP responds to the user clicking the first operation of the operation control in the transfer interface and displays the following Figure 15 The trusted user interface shown in Figure (b) is displayed, and while displaying the trusted user interface, a first indication message is sent to a newly added indication device to instruct it to start running, for example, a first indication message is sent to the TUI dedicated indicator light to instruct the TUI dedicated indicator light to light up, or a first indication message is sent to the TUI dedicated audio player to instruct the TUI dedicated audio player to play sound.
[0230] Optionally, when displaying the trusted user interface, the trusted operating system displays a second prompt message on the trusted user interface, wherein the second prompt message is used to instruct the user to determine whether the newly added indicator device is running in the first mode, that is, to start running. Figure 16 As shown, the second prompt message may be "Please note that if the security indicator light is on, it indicates that this is a security interface."
[0231] In this embodiment, the trusted user interface can be a TUI that asks the user to enter a password or a TUI that obtains a PIN code. After the user enters the corresponding information through the input box displayed in the trusted user interface, the trusted operating system sends the information to the trusted application, which returns it to the first application, so that the first application can complete the corresponding business process based on the received information.
[0232] S1404: After receiving the first indication message, the newly added indication device starts to operate.
[0233] The newly added indication device starts running after receiving the first indication message. For example, the TUI dedicated indicator light lights up after receiving the first indication message; or the TUI dedicated audio player plays a sound after receiving the first indication message.
[0234] S1405: The trusted operating system exits displaying the trusted user interface in response to the fourth operation, and controls the newly added indicating device to be turned off.
[0235] The fourth operation may be that the user clicks on an operation control to close the trusted user interface, or the user clicks on a completed operation control after completing an input operation on the trusted user interface.
[0236] In some embodiments, when the user closes the trusted user interface, the trusted operating system sends a control message to the newly added indicator device to control the indicator device to close, that is, to stop running in the first mode.
[0237] In other embodiments, after recognizing that the user has completed the input operation in the trusted user interface, the trusted operating system exits the display of the trusted user interface and controls the newly added indicator device to shut down by sending a control message to the newly added indicator device, that is, stops running in the first mode.
[0238] In this embodiment, a newly added indicator on the terminal device indicates the TUI. This newly added indicator activates as the TUI is displayed, preventing the TUI from being replaced by an unauthorized UI and obscuring it for the user, thus facilitating the widespread adoption of TUIs. This "one-light-indicates-safe-interface" approach provides a strong user experience and fosters a sense of security. Furthermore, because this newly added indicator is directly connected to the trusted operating system, malicious applications on the REE side cannot control it, resulting in a simple and straightforward solution.
[0239] Figure 17 A schematic flow chart of a method for displaying a trusted user interface provided in another embodiment of the present application, involving a newly added indicating device through Figure 13B When the connection method shown is connected to TEE, the trusted user interface process is indicated by the newly added indicator device. Figure 17 As shown, the method includes the following steps S1701 to S1707.
[0240] S1701: In response to a first operation, a first application sends a notification message to a trusted application. The notification message is used to instruct the trusted application to send a request message to a trusted operating system requesting display of a trusted user interface.
[0241] S1702: After receiving the notification message, the trusted application sends a request message to the trusted operating system. The request message is used to request the trusted operating system to display a trusted user interface.
[0242] S1703, after receiving the request message, the trusted operating system controls the display of the trusted user interface and sends first control information to the indicating device determination module. The first control information is used to instruct the indicating device determination module to control the newly added indicating device to start running.
[0243] Optionally, when displaying the trusted user interface, the trusted operating system displays a second prompt message on the trusted user interface, where the second prompt message is used to instruct the user to determine whether the newly added indicating device is started and running.
[0244] S1704: After receiving the first control information, the indicator device determination module sends a first indication message to the newly added indicator device. The first indication message is used to instruct the newly added indicator device to start running.
[0245] S1705: After receiving the first indication message, the newly added indication device starts to operate.
[0246] S1706: In response to the fourth operation, the trusted operating system exits displaying the trusted user interface and sends instruction information to the indicator device determination module. The instruction information is used to instruct the indicator device determination module to control the newly added indicator device to be turned off.
[0247] S1707: After receiving the indication information, the indication device determination module controls the newly added indication device to be turned off.
[0248] In this embodiment, the TUI is indicated by a newly added indicator device. This newly added indicator device is connected to the trusted execution environment via the indicator device determination module in the Sensor Hub. The indicator device determination module is only connected to the trusted operating system and the newly added indicator device. Therefore, it can only receive control information from the trusted operating system to control the shutdown or startup of the indicator device. In other words, the newly added indicator device can only be controlled by the trusted operating system through the Sensor Hub. Malicious applications on the REE side cannot communicate with it and therefore cannot control the newly added indicator device. This solution is more universal and easier to expand.
[0249] Figure 18 A schematic flow chart of a method for displaying a trusted user interface provided in another embodiment of the present application, involving at least one indicating device through Figure 13C When the connection method shown is connected to the TEE, the process of indicating the trusted user interface through at least one indicating device. Figure 18 As shown, the method includes the following steps S1801 to S1807.
[0250] S1801: In response to a first operation, the first application sends a notification message to the trusted application. The notification message is used to instruct the trusted application to send a request message to the trusted operating system requesting display of a trusted user interface.
[0251] S1802: After receiving the notification message, the trusted application sends a request message to the trusted operating system. The request message is used to request the trusted operating system to display a trusted user interface.
[0252] S1803: After receiving the request message, the trusted operating system controls the display of the trusted user interface and sends first control information to the indicating device determination module. The first control information is used to instruct the indicating device determination module to control at least one indicating device to operate in a first mode.
[0253] S1804: After receiving the first control information, the indicating device determination module sends a first indication message to at least one indicating device, where the first indication message is used to instruct the at least one indicating device to operate in a first mode.
[0254] S1805: After receiving the first indication message, at least one indication device operates in the first operation mode.
[0255] Exemplarily, the indicating device judgment module sends a first indication message to the indicator light to instruct the indicator light to flash at a preset frequency, for example, flashing 3 to 5 times per second, or flashing once every second, for a total of three flashes; or the indicating device judgment module sends a first indication message to the speaker to instruct the speaker to play audio of a preset frequency, or the indicating device judgment module sends a first indication message to the indicator light and the speaker to instruct the indicator light to control the speaker to play audio once after flashing once, etc.
[0256] It should be noted that in this embodiment, since the second component is at least one indicator device inherent to the terminal device itself, and the at least one indicator device is connected to the rich operating system through the indicator device judgment module, the indicator device judgment module can also receive the second control information sent by the rich operating system and control the at least one indicator device to perform a corresponding operation based on the second control information. Based on this, when the indicator device judgment module controls the at least one indicator device based on the received control information, it first determines the source of the control information. If the control information comes from the trusted operating system, the control information is the first control information, and the at least one indicator device is controlled to operate in the first mode based on the first control information; if the control information comes from the rich operating system, the control information is the second control information, and the at least one indicator device is controlled to operate in the second mode based on the second control information, for example, controlling the indicator light to flash or controlling the speaker to play a sound. The second mode is an operating mode other than the first mode, that is, the second component operates in a mode other than the first mode, which is different from the first mode. It can also be understood that the second mode is an existing operating mode of the at least one indicator device.
[0257] In some application scenarios, the rich operating system may send third control information to the indicator device determination module to instruct at least one indicator device to operate in the first mode. When the indicator device determination module receives the third control information from the rich operating system and determines that the third control information comes from the rich operating system rather than the trusted operating system, it refuses to execute the corresponding operation and returns an error report to the rich operating system. This approach can prevent malicious applications in the rich execution environment from attempting to control at least one indicator device to operate in the first mode.
[0258] Optionally, when displaying the trusted user interface, the trusted operating system displays second prompt information on the trusted user interface, where the second prompt information is used to instruct the user to determine whether at least one indicating device operates in the first mode.
[0259] S1806: In response to the fourth operation, the trusted operating system exits displaying the trusted user interface and sends instruction information to the indicator device determination module. The instruction information is used to instruct the indicator device determination module to control at least one indicator device to stop operating in the first mode.
[0260] S1807: After receiving the indication information, the indication device determination module controls at least one indication device to stop operating in the first mode.
[0261] In this embodiment, at least one indicator device inherent to the terminal device is used to indicate the TUI in accordance with the operating state of the first mode, making full use of the inherent properties of the indicator device, such as frequency, and "a specific flashing frequency indicates a security interface", which makes the user feel strongly and helps to establish a security image. At least one indicator device appears with the TUI at a dedicated flashing frequency, thereby preventing the TUI from being replaced by an illegal UI and the user from being unable to distinguish, which is conducive to the large-scale application of TUI. In addition, the other frequencies of the at least one indicator device can indicate other services, realizing multiple uses of one light. The trusted operating system controls the at least one indicator device through the Sensor Hub, making the solution more universal and easier to expand. Malicious applications on the REE side cannot enable the dedicated flashing frequency.
[0262] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0263] An embodiment of the present application also provides a terminal device, which includes a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it is configured to execute the method for displaying a trusted user interface shown in the above-mentioned embodiments.
[0264] The present application also provides a chip. Figure 19 As shown, the chip includes a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the display method of the trusted user interface in the above-mentioned embodiments is implemented.
[0265] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the method for displaying a trusted user interface provided in the above embodiments is implemented.
[0266] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a terminal device, the terminal device implements the display method of the trusted user interface provided in the above embodiments.
[0267] It should be understood that the processor mentioned in the embodiments of the present application may be a central processing unit (CPU), or may be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc.
[0268] It should also be understood that the memory mentioned in the embodiments of the present application may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), or a flash memory. The volatile memory may be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct rambus RAM (DR RAM).
[0269] In the embodiments provided in this application, the division of each framework or module is merely a logical function division. In actual implementation, there may be other division methods, for example, multiple frameworks or modules can be combined or integrated into another system, or some features can be ignored or not executed.
[0270] In addition, the functional modules in the various embodiments of the present application may be integrated into a processing module, or each module may exist physically separately, or two or more modules may be integrated into a single module. The above-mentioned integrated modules may be implemented in the form of hardware or software functional modules.
[0271] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0272] References to "one embodiment" or "some embodiments" in this specification mean that a particular feature, structure, or characteristic described in conjunction with that embodiment is included in one or more embodiments of the present application. Thus, phrases such as "in one embodiment," "in some embodiments," "in other embodiments," and "in other embodiments" appearing in various places in this specification do not necessarily refer to the same embodiment, but rather mean "one or more but not all embodiments," unless otherwise specifically emphasized. The terms "including," "comprising," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.
[0273] The above-described embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. These modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present application, and should all be included in the scope of protection of the present application.
Claims
1. A method for displaying a trusted user interface, characterized in that: Applied to a terminal device, the terminal device includes a rich execution environment (REE), a trusted execution environment (TEE), and a first component, wherein a first application runs in the REE, and the first component connects the TEE and the REE, the method comprising: receiving a first operation on the first application, where the first operation is used to request display of a trusted user interface of the first application; In response to the first operation, the TEE detects a second operation, and the REE detects a third operation; wherein the second operation is an operation on the first element, the second operation is used to display the trusted user interface, and the third operation is an operation on the first element, and the third operation is different from the second operation; After the TEE detects the second operation, displaying the trusted user interface; After the REE detects the third operation, the REE is controlled to process operation information corresponding to the third operation.
2. The method according to claim 1, characterized in that The first element includes a physical button, the second operation includes the physical button being pressed, and when the physical button is pressed, an interrupt message is sent to the TEE.
3. The method according to claim 2, characterized in that In response to the first operation, detecting, by the TEE, a second operation includes: In response to the first operation, controlling the first application to send a notification message to the TEE, where the notification message is used to notify the TEE to display the trusted user interface; According to the notification message, monitoring the interrupt message through the TEE; If the interrupt message is monitored through the TEE, it is determined that the second operation is detected.
4. The method according to claim 1, wherein The first element includes at least one physical key, and the second operation includes pressing the same physical key of the at least one physical key multiple times, or pressing different physical keys of the at least one physical key in sequence according to a first order.
5. The method according to claim 2 or 4, characterized in that The terminal device further includes a sensor hub. Accordingly, the first component is connected to the TEE, including: The first component is connected to the TEE via the sensor hub. When the first component is operated, the first component sends operation information to the sensor hub, so that the sensor hub generates an operation record according to the operation information.
6. The method according to claim 5, characterized in that In response to the first operation, detecting, by the TEE, a second operation includes: In response to the first operation, controlling the first application to send a notification message to the TEE, where the notification message is used to notify the TEE to display the trusted user interface; According to the notification message, control the TEE to send a query message to the sensor hub, wherein the query message is used to instruct the sensor hub to query an operation record of the first component, where the operation record is generated by the sensor hub based on the received operation information; When the sensor hub queries the operation record and determines that the operation record is generated by the second operation, controlling the sensor hub to return confirmation information to the TEE; If it is identified that the TEE receives the confirmation information, it is determined that the second operation is detected.
7. The method according to claim 6, characterized in that When the first component includes at least one physical button, the at least one physical button is further connected to the REE via the sensor hub.
8. The method according to claim 7, characterized in that The REE detects the third operation, including: The third operation is detected by the sensor hub.
9. The method according to any one of claims 1 to 4, 6 to 8, characterized in that After receiving the first operation on the first application and before detecting, by the TEE, a second operation in response to the first operation, the method further includes: A first prompt message is displayed, where the first prompt message is used to instruct the user to perform the second operation within a first preset time.
10. The method according to any one of claims 1 to 4, 6 to 8, characterized in that: After detecting the second operation through the TEE, displaying the trusted user interface includes: After the second operation is detected by the TEE within a second preset time, the trusted user interface is displayed.
11. A method for displaying a trusted user interface, characterized in that: Applied to a terminal device, the terminal device includes a rich execution environment (REE), a trusted execution environment (TEE), and a second component, wherein a first application runs in the REE and the second component is connected to the TEE, the method comprising: receiving a first operation on the first application, where the first operation is used to request display of a trusted user interface of the first application; In response to the first operation, the trusted user interface is displayed through the TEE control, and the second component is controlled by the TEE to operate in a first mode. When the second component operates in the first mode, it is used to uniquely indicate the trusted user interface.
12. The method according to claim 11, characterized in that The second component is an indicator device, and controlling the second component to operate in the first mode through the TEE includes: Sending a first instruction message to the second component through the TEE, where the first instruction message is used to instruct the second component to start running; The second component is started according to the first instruction message.
13. The method according to claim 11 or 12, characterized in that In response to the first operation, controlling, through the TEE, displaying the trusted user interface, and controlling, through the TEE, the second component to operate in a first mode, includes: In response to the first operation, controlling the first application to send a notification message to the TEE, where the notification message is used to notify the TEE to display the trusted user interface; According to the notification message, controlling display of the trusted user interface through the TEE, and sending a first instruction message to the second component through the TEE, where the first instruction message is used to instruct the second component to operate in the first mode; The second component is controlled to operate according to the first mode after receiving the first instruction message.
14. The method according to claim 11, characterized in that The second element is at least one indicator device, and the first mode includes the same indicator device in the at least one indicator device operating according to a preset mode, or different indicator devices in the at least one indicator device operating sequentially according to a second order.
15. The method according to claim 12 or 14, characterized in that The terminal device further includes a sensor hub. Accordingly, the second component is connected to the TEE, including: The second component is connected to the TEE via the sensor hub.
16. The method according to claim 15, characterized in that In response to the first operation, controlling, through the TEE, displaying the trusted user interface, and controlling, through the TEE, the second component to operate in a first mode, includes: In response to the first operation, controlling the first application to send a notification message to the TEE, where the notification message is used to notify the TEE to display the trusted user interface; According to the notification message, controlling display of the trusted user interface through the TEE, and sending first control information to the sensor hub through the TEE, where the first control information is used to instruct the sensor hub to control the second component to operate according to the first mode; controlling the sensor hub to send a first instruction message to the second component after receiving the first control information, wherein the first instruction message is used to instruct the second component to operate according to the first mode; The second component is controlled to operate according to the first mode after receiving the first instruction message.
17. The method according to claim 16, characterized in that When the second component is at least one indicator device, the at least one indicator device is further connected to the REE via the sensor hub.
18. The method according to claim 17, characterized in that The method further comprises: receiving, through the sensor hub, second control information sent by the REE, wherein the second control information is used to instruct the at least one indicating device to operate in a second mode, the second mode being different from the first mode; controlling the sensor hub to send a second instruction message to the second component upon receiving the second control information, wherein the second instruction message is used to instruct the second component to operate according to the second mode; The second component is controlled to operate in the second mode after receiving the second indication message.
19. The method according to any one of claims 16 to 18, characterized in that When the second element is at least one indicating device, the method further includes: receiving, through the sensor hub, third control information sent by the REE, wherein the third control information is used to instruct the sensor hub to control the at least one indicating device to operate according to the first mode; The sensor hub is controlled to return error information to the REE, and refuses to control the at least one indicating device to operate according to the first mode.
20. The method according to any one of claims 11, 12, 14, 16 to 18, characterized in that: In response to the first operation, displaying the trusted user interface through the TEE, and controlling the second component to operate in the first mode through the TEE, further includes: Second prompt information is displayed through the TEE, where the second prompt information is used to instruct a user to determine whether the second component operates according to the first mode.
21. The method according to any one of claims 11, 12, 14, 16 to 18, characterized in that The method further comprises: When the trusted user interface exits display, the second component is controlled by the TEE to stop operating in the first mode.
22. A terminal device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the method according to any one of claims 1 to 21 when executing the computer program.
23. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the method according to any one of claims 1 to 21 is implemented.
24. A chip, characterized in that: The chip includes a processor and a memory, wherein a computer program is stored in the memory, and when the computer program is executed by the processor, the method according to any one of claims 1 to 21 is implemented.