Sensitive word detection method, electronic equipment, readable storage medium and program product

By storing the sensitive word detection program in the trusted execution environment of the terminal device and using a cryptographic algorithm to generate fingerprint values, the problem of the sensitive word library being vulnerable to attacks is solved, and the security and real-time performance of sensitive word detection are achieved.

CN120705859APending Publication Date: 2025-09-26HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410320615.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-03-19
Publication Date
2025-09-26

AI Technical Summary

Technical Problem

When terminal devices perform sensitive word detection, the sensitive word database is easily restored by attackers through offline brute force, which threatens the real-time and security of sensitive word detection.

Method used

The sensitive word detection program and algorithm are stored in a trusted execution environment with a higher security level, the fingerprint value of the sensitive word is generated using a cryptographic algorithm, and an index structure is built in an execution environment with a lower security level to prevent the leakage of the sensitive word library.

Benefits of technology

This effectively prevents the sensitive word library from being restored by attackers, ensures the real-time and security of sensitive word detection, and avoids the index structure from occupying too much memory.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120705859A_ABST
    Figure CN120705859A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of computers, in particular to a sensitive word detection method, electronic equipment, a readable storage medium and a program product, in the method, a message authentication code algorithm and a secret key are stored in a first execution environment in terminal equipment, a first fingerprint value is calculated in the first execution environment with high security, and the first fingerprint value is stored in the electronic equipment; and at least one second fingerprint value is obtained in the index relationship in the second execution environment with low security, and the to-be-detected word is determined as a sensitive word corresponding to a second fingerprint value matched with the first fingerprint value in the at least one second fingerprint value. On the basis, the message authentication code algorithm and the key are stored in the first execution environment with high security, so that the security of the algorithm can be ensured, and the condition that the sensitive word bank is recovered through off-line violent exhaustion is avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a sensitive word detection method, electronic device, readable storage medium, and program product. Background Art

[0002] Terminal devices can use sensitive word detection technology to identify some sensitive words to prevent bad actors from using sensitive words to create malicious incidents.

[0003] For example, when a terminal device automatically generates and displays candidate words based on a built-in input method, it can use sensitive word detection technology to identify sensitive words, ensuring that none of the candidate words displayed to the user are sensitive words. This prevents bad actors from taking screenshots of sensitive words displayed by the input method and maliciously disseminating them to create public opinion. For another example, when a terminal device automatically generates text based on a built-in large model, it can use sensitive word detection technology to identify sensitive words, ensuring that none of the automatically generated text is sensitive words. This prevents bad actors from using text containing sensitive words to maliciously disseminate and create public opinion online.

[0004] At present, when terminal devices detect sensitive words, they can rely on the cloud to complete the detection process, or they can complete the detection directly on the terminal side without relying on the cloud. When relying on the cloud to complete the detection, the terminal device needs to send the word to be detected to the cloud, the cloud will identify the word to be detected, and then feedback the detection results to the terminal. When not relying on the cloud to complete the detection, the terminal device directly uses the storage content that can represent the sensitive word library to detect the word to be detected in order to identify the sensitive word. It is understandable that since the terminal device needs to interact with the cloud when relying on the cloud to complete the detection, the real-time performance is poor. Therefore, in order to improve the real-time performance, the terminal device generally completes the detection directly in the terminal.

[0005] In some embodiments, for the terminal device to complete detection within the terminal: the cloud can configure a hash table that maps index values ​​to sensitive word content based on a hash function in advance, and the terminal device will download the configured hash table from the cloud and build it into the device to directly use the hash table for sensitive word detection.

[0006] However, terminal devices are often fragile and susceptible to various attacks, making it easy for attackers to obtain sensitive word libraries. For example, they can decompile to obtain hash functions and restore the sensitive word library through offline brute force. Specifically, the words to be detected can be constructed in batches, and the obtained hash functions and hash tables can be used to filter out sensitive words from the words to be detected to obtain a sensitive word library. It is understandable that when bad actors obtain the sensitive word library, they can take corresponding measures to bypass sensitive word detection and thus create malicious incidents. Therefore, there is an urgent need for a sensitive word detection method suitable for terminal devices that can prevent the leakage of sensitive word libraries while ensuring the ability to detect sensitive words. Summary of the Invention

[0007] To solve the above problems, embodiments of the present application provide a sensitive word detection method, electronic device, readable storage medium, and program product, which are used to solve the problem of recovering a sensitive word library through offline brute force exhaustive search.

[0008] In a first aspect, an embodiment of the present application provides a sensitive word detection method, which is applied to a terminal device, and the method includes: obtaining a word to be detected; calling a first algorithm stored in a first execution environment to generate a first fingerprint value of the word to be detected, and matching the word to be detected with an index relationship stored in a second execution environment to obtain at least one second fingerprint value, wherein the index relationship includes a correspondence between index values ​​corresponding to multiple sensitive words and multiple second fingerprint values; corresponding to the presence of a second fingerprint value matching the first fingerprint value in at least one second fingerprint value, determining that the word to be detected is a sensitive word; wherein the security level of the first execution environment is higher than the security level of the second execution environment, and the first algorithm is a cryptographic algorithm.

[0009] It is understandable that, because the security level of the first execution environment is higher than that of the second execution environment, the process of storing the first algorithm in the first execution environment and calling the first algorithm stored in the first execution environment to generate the first fingerprint value of the word to be detected is absolutely safe. The first algorithm cannot be obtained by criminals. Therefore, even if bad actors can obtain the index relationship from the second execution environment, they cannot recover the sensitive word library through offline brute force exhaustive methods, thereby ensuring that sensitive word detection can be achieved while preventing the leakage of the sensitive word library. Furthermore, because the index relationship is not stored in the first execution environment, the problem of the index relationship occupying a large amount of space in the first execution environment can be effectively avoided.

[0010] In a possible implementation of the first aspect above, the cryptographic algorithm includes at least one of the following: a message authentication code algorithm, a data encryption standard algorithm, and an advanced encryption standard algorithm.

[0011] It can be understood that the message authentication code algorithm, the data encryption standard algorithm, and the advanced encryption standard algorithm are all algorithms involving keys. According to the security properties of algorithms involving keys, if there is no key, it is difficult to reverse-infer sensitive words from the hash table, so using the aforementioned algorithms to calculate the fingerprint value of sensitive words is more secure.

[0012] In a possible implementation of the first aspect above, the first execution environment includes: a trusted execution environment or a secure element; and the second execution environment includes an open execution environment.

[0013] It can be understood that the security of the trusted execution environment or the secure element is relatively high, and the first execution environment is a trusted execution environment or a secure element, both of which can ensure relatively high security.

[0014] In a possible implementation of the first aspect above, it also includes: receiving a first program and an index relationship sent by a cloud device, wherein the first program includes a first algorithm; storing the first program in a first execution environment, and storing the index relationship in a second execution environment.

[0015] In a possible implementation of the first aspect above, the first program further includes a key corresponding to the first algorithm.

[0016] It can be understood that when the first algorithm is an algorithm involving a key, the first program includes the key corresponding to the first algorithm. At this time, the key will also be stored in the first execution environment, which is safer.

[0017] In a possible implementation of the first aspect, calling a first algorithm stored in a first execution environment to generate a first fingerprint value of a word to be detected includes: running a first program in the first execution environment to calculate the word to be detected to obtain the first fingerprint value.

[0018] It can be understood that the first fingerprint value is obtained by running the first program in the first execution environment. At this time, the first algorithm and the key will not be exposed to an insecure execution environment, thereby ensuring security.

[0019] In a possible implementation of the first aspect above, matching the word to be detected with the index relationship stored in the second execution environment to obtain at least one second fingerprint value includes: using at least one position function to determine at least one index value corresponding to the word to be detected; and determining at least one second fingerprint value corresponding to the at least one index value in the index relationship.

[0020] In a possible implementation of the first aspect above, the index values ​​corresponding to multiple sensitive words in the index relationship are determined based on at least one position function, and the second fingerprint values ​​corresponding to multiple sensitive words in the index relationship are obtained based on the first algorithm.

[0021] In a possible implementation of the first aspect above, the index relationship is stored based on any one of the following methods: a hash table, a dictionary tree.

[0022] In a second aspect, an embodiment of the present application provides an electronic device comprising: a memory for storing instructions, and one or more processors. When the instructions are executed by one or more processors, the processors execute any sensitive word detection method as described in the first aspect and any of the various implementations of the first aspect.

[0023] In a third aspect, an embodiment of the present application provides a computer-readable storage medium having instructions stored thereon, which execute, on an electronic device, any sensitive word detection method as described in the first aspect and any of the various implementations of the first aspect.

[0024] In a fourth aspect, an embodiment of the present application provides a computer program product, which includes: computer program code, which, when the computer program code runs on a computer, enables the computer to execute any sensitive word detection method as described in the first aspect and various implementations of the first aspect.

[0025] Among them, the beneficial effects of the second to fourth aspects can refer to the beneficial effects related to the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 According to some embodiments of the present application, a schematic diagram of a detection scenario is shown;

[0027] Figure 2 According to some embodiments of the present application, a schematic diagram of a process for constructing a hash table is shown;

[0028] Figure 3 According to some embodiments of the present application, a schematic diagram of a specific process of constructing an index structure is shown;

[0029] Figure 4 According to some embodiments of the present application, a schematic diagram of a specific process for performing sensitive word detection is shown;

[0030] Figure 5 According to some embodiments of the present application, a schematic diagram of a system architecture is shown;

[0031] Figure 6A According to some embodiments of the present application, a schematic diagram of a specific construction process using a hash table as an example is shown;

[0032] Figure 6B According to some embodiments of the present application, a schematic diagram of a construction process is shown, taking the index structure as a hash table as an example;

[0033] Figure 7A According to some embodiments of the present application, a schematic diagram of a detection process is shown, taking the index structure as a hash table as an example;

[0034] Figure 7B According to some embodiments of the present application, a schematic diagram of a sensitive word detection process using a hash table is shown;

[0035] Figure 8 According to some embodiments of the present application, a schematic diagram of a device is shown. DETAILED DESCRIPTION

[0036] The illustrative embodiments of the present application include, but are not limited to, a sensitive word detection method, an electronic device, a readable storage medium, and a program product.

[0037] The following describes the embodiments of the present application in conjunction with the accompanying drawings.

[0038] Figure 1 According to some embodiments of the present application, a schematic diagram of a detection scenario is shown. Figure 1 As shown, user KA is using terminal 100 to create text, and when the user uses the input method to input pinyin, the input method application can make predictions and display candidate words. Figure 1 In the middle frame K01, the simplified pinyin corresponding to the user input is "s'g'y'y". At this time, the input method application can intelligently generate and display the candidate words shown in frame K02, such as "1 Romance of the Three Kingdoms 2 Sogou Music Box 3 Three Supply and One Industry". Understandably, if the pop-up candidate words include sensitive words, user KA may take a screenshot and maliciously disseminate them on social media, creating public opinion incidents, for example, to defame the development company of the input method or the manufacturer of the terminal device, resulting in adverse effects.

[0039] It is understandable that the input method can use its own built-in or system-provided sensitive word detection function to detect sensitive words, thereby preventing the candidate words that pop up from being illegal information. For example, the terminal 100 can download a sensitive word detection application or content corresponding to a sensitive word library (e.g., a hash table representing sensitive words) from the cloud 200 to implement sensitive word detection, so that sensitive words originally existing in the candidate words intelligently displayed by the input method are filtered out.

[0040] As described in the background art, the terminal device can complete detection within the terminal with the help of a hash table built in the cloud.

[0041] The following is an example of building a hash table with a fixed structure in the cloud. Figure 2 This paper elaborates on the specific process of terminal devices using hash tables to detect sensitive words.

[0042] (1) The cloud 200 constructs a hash table: The cloud 200 initializes a hash table based on the pre-collected sensitive word library, calculates the location of the sensitive word to be stored in the hash table according to the position function, and calculates the fingerprint value of the sensitive word according to the fingerprint function, and then stores the fingerprint value of the sensitive word in the corresponding position of the hash table, thereby constructing a mapping relationship between the index value (i.e., the specific location) and the sensitive word based on the obtained position and fingerprint value. It can be understood that hash functions can be used as position functions and fingerprint functions. Different hash functions can be used in specific applications. The hash function hash1() is used as a position function and the hash function hash2() is used as a fingerprint function as an example to illustrate. Figure 2 The hash table shown has n hash buckets, namely B[1]..., B[i], ...B[n], and each hash bucket has 4 storage units. Figure 2 For the sensitive word X shown in , apply the hash function hash1(X) to get the key of the sensitive word. The key is the location where the sensitive word needs to be stored, assuming it is B[i]. Use the hash function hash2(X) to get the fingerprint value of the sensitive word, and then store the fingerprint value in any storage unit of the hash bucket B[i].

[0043] (2) The terminal 100 uses a hash table to detect sensitive words: The terminal 100 obtains the constructed hash table from the cloud 200 and stores it in the device. It uses a preset position function to calculate the position of the word to be detected in the hash table, and determines whether it is a sensitive word based on the value indexed at the corresponding position in the hash table. For example, for the word to be detected M, according to the preset hash function hash1(M), the position is obtained as B[i], and according to the preset hash function hash2(M), the fingerprint value O1 is obtained. The calculated fingerprint value O1 is then compared with the values ​​stored in the hash bucket B[i] to check whether there are the same fingerprint values. If so, it is determined that the word to be detected is a sensitive word.

[0044] It is understandable that there are many other methods for constructing a hash table and for detecting based on the constructed hash table. For example, the inserted value can be a fixed value (such as 0 or 1, where 1 indicates a sensitive word and 0 indicates a non-sensitive word), or directly a specific sensitive word. Other cases are not described here.

[0045] However, because terminal devices are relatively fragile and have a large attack surface, there is a risk that the hash table could be obtained by an attacker. Furthermore, an attacker could use reverse engineering methods, such as decompiling the program, to obtain the implementation of the hash function that can be used to calculate the location and fingerprint value. Therefore, after obtaining the hash table, the attacker can recover the entire sensitive word library by performing an offline brute force attack. In some implementations, the offline brute force attack process can be specifically as follows: batch construct the words to be tested, use the hash function to calculate the index value, and check whether the words exist in the hash table to recover the entire sensitive word library.

[0046] In some embodiments, in order to ensure that the sensitive word library is not leaked, the terminal 100 can change the storage of the program for sensitive word detection from the original open execution environment (REE) to the trusted execution environment (TEE). For example, when designing at the hardware level, a secure area can be isolated in the processor and used as a TEE, such as The company's TrustZone ensures the confidentiality and integrity of sensitive word detection programs and data.

[0047] Specifically, terminal sensitive word detection based on the trusted execution environment (TEE) can also include the following two processes:

[0048] (1) Cloud 200 builds a sensitive word detection program: Cloud developers compile and build a trusted application (TA), hereinafter referred to as the "TA program", where the TA program has a built-in sensitive word library or a constructed hash table and is configured with a sensitive word detection interface.

[0049] (2) The terminal 100 deploys and uses the detection program: The terminal 100 downloads the TA program from the cloud and stores it in the TEE. During the detection process, the sensitive word detection interface is called to determine whether the word to be detected is a sensitive word.

[0050] It is understandable that since the terminal device stores the detection program for detecting sensitive words in TEE, attackers cannot obtain content related to sensitive words, thereby avoiding the leakage of sensitive words.

[0051] However, as the sensitive word library grows, its memory usage will inevitably increase and eventually exceed the limit. Currently commercially available TEEs all have memory limits, and the memory limits for individual TAs are often even stricter.

[0052] Therefore, in order to solve the problem of ensuring the security of the sensitive word library while having memory limitations in the TEE, this application proposes a sensitive word detection method, in which the cloud can pre-use a cryptographic algorithm involving a key, such as a message authentication code (MAC) algorithm, a data encryption standard (DES) algorithm, an advanced encryption standard (AES) algorithm, etc. as a fingerprint function to process the sensitive word and obtain the fingerprint value corresponding to the sensitive word. Then, an index structure is constructed based on the fingerprint value of each sensitive word obtained. For example, the fingerprint value obtained based on the key and the MAC algorithm is used as the value inserted into the hash table, or the fingerprint value obtained based on the key is used as the value inserted into the dictionary tree, etc., and the index structure can reflect the correspondence between the sensitive word and the fingerprint value obtained using the cryptographic algorithm. In addition, the cryptographic algorithm used to calculate the fingerprint value and its key are compiled into an executable program that can be executed in a first execution environment with a higher security level, such as a TA program that can be executed in the TEE, and sent to the terminal device together with the index structure. At this time, the terminal device stores the index structure in a second execution environment with a lower security level, and stores the executable program including the cryptographic algorithm and its key in a first execution environment with a higher security level, such as a first execution environment with a higher security level such as a TEE or a secure element (SE), to ensure the security of the cryptographic algorithm and the key. The terminal device can then detect sensitive words based on the index structure and the cryptographic algorithm and its key stored in the first execution environment with a higher security level.

[0053] It is understandable that since the index structure is constructed based on a cryptographic algorithm with a key, and the key and the cryptographic algorithm are stored in the first execution environment with a higher security level, it is definitely safe. Therefore, in the absence of the key and the cryptographic algorithm, it is impossible to understand the specific meaning of the value in the index structure. Therefore, even if the bad guys can obtain the index structure and know the fingerprint value corresponding to the word to be detected in the index structure, such as the hash table, they cannot determine whether the word to be detected is a sensitive word based on the fingerprint value in the position, and thus cannot restore the hash table through an offline brute force attack. In addition, since only the key and the cryptographic algorithm need to be stored in the first execution environment with a higher security level, and the memory occupied by the key and the cryptographic algorithm in the first execution environment with a higher security level is small, the problem of insufficient memory is avoided.

[0054] For example, a specific sensitive word detection method can be: after the terminal device obtains the word to be detected, it indexes it in the obtained index structure according to the index value corresponding to the word to be detected; and, calls the TA program interface, uses the MAC algorithm and key stored in the TEE to generate a fingerprint value corresponding to the word to be detected; compares the fingerprint value obtained by the TA program to see whether the same fingerprint value exists in the fingerprint value indexed in the index structure. If the same fingerprint value exists, it is determined that the word to be detected is a sensitive word, otherwise it is not a sensitive word.

[0055] It is understandable that in other embodiments, a cryptographic algorithm with a key may not be used, and an algorithm with a higher complexity may be used, and the cryptographic algorithm may be stored in the first execution environment, which can still achieve similar security functions as using a cryptographic algorithm with a key.

[0056] It is understood that the terminal 100 includes, but is not limited to, a mobile phone, a tablet computer, an in-vehicle device, an augmented reality (AR) / virtual reality (VR) device, an ultra-mobile personal computer (UMPC), a netbook, a personal digital assistant (PDA), a server, a server cluster, etc., and is not limited here. The cloud 200 in this application is a cloud server.

[0057] Figure 3 According to the embodiment of the present application, a specific process diagram of constructing an index structure to obtain the index value corresponding to the sensitive word and the index relationship corresponding to the fingerprint value is shown. It is understandable that a cloud device or other terminal device with higher security can be used as the execution subject, which is not required here. The specific process is as follows:

[0058] S301, obtaining sensitive words.

[0059] S302: Generate a fingerprint value corresponding to the sensitive word according to a cryptographic algorithm.

[0060] In some embodiments, a cryptographic algorithm is used as a fingerprint function to generate a fingerprint value corresponding to a sensitive word.

[0061] The cryptographic algorithm can be an authentication algorithm for data authentication or an encryption algorithm. The cryptographic algorithm can also use a cryptographic algorithm involving a key or an algorithm not involving a key. It is understood that when a cryptographic algorithm involves a key, the generated fingerprint value can be more secure.

[0062] For example, the cryptographic algorithm may be a message authentication code (MAC) algorithm, a data encryption standard (DES) algorithm, an advanced encryption standard (AES) algorithm, etc., which will not be described in detail here.

[0063] S303: Obtain the index value corresponding to the sensitive word according to a preset position function.

[0064] It is understandable that the preset location function can be a variety of functions, such as a hash function, a search function in a dictionary tree, a search function in a skip list, etc., which will not be described in detail here.

[0065] In some embodiments, sensitive words are calculated according to a preset position function to obtain at least one index value.

[0066] For example, the position function may include multiple (e.g., 2) functions for calculating the position. Accordingly, corresponding to a sensitive word, there will be one or more index values. At least one of the one or more index values ​​includes the fingerprint value corresponding to the sensitive word. For details, please refer to the description in Figure 6 below, which will not be repeated here.

[0067] S304: insert the fingerprint value into the index structure according to the index value and the preset insertion rule.

[0068] It is understandable that the index structure can reflect the correspondence between sensitive words and fingerprint values. In some implementations, the index structure may include, but is not limited to, a hash table, a dictionary tree, etc. Among them, the hash table includes a hash table with a fixed structure, and also includes a hash table with a non-fixed structure, such as a hash table obtained by combining other algorithms, such as a hash table obtained by combining a Bloom filter and a cuckoo filter, etc. As long as the index structure can find the fingerprint value corresponding to the sensitive word according to the index value, it is within the scope of protection of this application and will not be described in detail here.

[0069] In some embodiments, after obtaining an index value, the fingerprint value is inserted into the position corresponding to the index value.

[0070] In some embodiments, after obtaining multiple index values, the fingerprint value is inserted into the position corresponding to the index value according to a preset insertion rule. For example, the fingerprint value can be inserted into any empty position among the multiple index values. For another example, the fingerprint value can be inserted according to the insertion method corresponding to the cuckoo algorithm. The specific insertion method is not described in detail here.

[0071] It is understandable that one index value may correspond to one fingerprint value, or one index value may correspond to multiple fingerprint values. Figure 2 As shown, a hash bucket corresponds to an index value, and a hash bucket can store multiple fingerprint values.

[0072] It is understandable that the execution order of S301 to S304 is only an example. In other embodiments, other execution orders may be adopted, and some steps may be split or combined, which is not limited here.

[0073] It is understandable that after the index structure is constructed and the index relationship is obtained, the cryptographic algorithm, or the cryptographic algorithm and the corresponding key are compiled into a first program that can be used in the first execution environment. It is understandable that the compilation process of the first program can be carried out simultaneously with the process of constructing the index structure, or it can be completed after the index structure is constructed, or before, which is not required here. When the terminal device receives the first program and the index structure (i.e., the index relationship), they are stored in the first execution environment and the second execution environment respectively.

[0074] Figure 4 According to an embodiment of the present application, a schematic diagram of a specific process for detecting sensitive words based on a cryptographic algorithm stored in a first execution environment and an index relationship stored in a second execution environment is shown. It is understood that the terminal device that needs to perform sensitive word detection is the execution subject. The specific process includes the following steps:

[0075] S401, obtaining a word to be detected.

[0076] S402: Calling a first algorithm stored in a first execution environment to generate a first fingerprint value of a word to be detected, wherein the first algorithm is a cryptographic algorithm.

[0077] It is understandable that the cryptographic algorithm can refer to the description of S302 above and will not be elaborated here.

[0078] In some embodiments, when a first algorithm and a key involved in the first algorithm are stored in a first execution environment, when the terminal device calls the first algorithm stored in the first execution environment to calculate a fingerprint value, the first algorithm will use the key to calculate the fingerprint value of the word to be detected, thereby generating a first fingerprint value of the word to be detected.

[0079] In some implementations, a first program is called according to a first external program interface, a word to be detected is input into a first execution environment, and the first program in the first execution environment is run to calculate a first fingerprint value.

[0080] S403: Match the word to be detected with the index relationship stored in the second execution environment to obtain at least one second fingerprint value, wherein the index relationship includes a correspondence between index values ​​corresponding to multiple sensitive words and multiple second fingerprint values.

[0081] In some embodiments, the index value of the word to be detected is calculated using the position function previously used in constructing the index structure, and then the index is indexed in the index structure according to the index value to obtain at least one second fingerprint value. It is understood that one index value can correspond to multiple fingerprint values ​​or one fingerprint value.

[0082] S404: corresponding to the presence of a second fingerprint value matching the first fingerprint value in the at least one second fingerprint value, determining that the word to be detected is a sensitive word.

[0083] In some embodiments, at least one second fingerprint value is matched with the first fingerprint value. If there is a second fingerprint value matching the first fingerprint value in the at least one second fingerprint value, the word to be detected is determined to be a sensitive word; otherwise, it is not a sensitive word.

[0084] It is understandable that the execution order of S401 to S404 is only an example. In other embodiments, other execution orders may be adopted, and some steps may be split or combined, which is not limited here.

[0085] It is understandable that in other embodiments, in order to more conveniently understand the present application, the following is a specific introduction taking the cryptographic algorithm involving the key used as the MAC algorithm as an example, taking the first execution environment with a higher security level supported by the terminal device as the TEE as an example, and taking the index relationship as the expression of the hash table as an example. Among them, the client (ie, terminal device) and cloud server (ie, cloud) modes are introduced as examples. The cloud has a sensitive word library, which is responsible for the construction of the hash table and sends it to the terminal device after the construction is completed. The terminal device supports TEE, receives the hash table and TA program from the cloud, and detects sensitive words on the terminal device. For example, Figure 5 According to an embodiment of the present application, a system architecture is shown. The system includes a cloud 200 and a terminal 100, and the terminal 100 includes a TEE. At this time, the terminal 100 receives a hash table and a TA program sent from the cloud 200, stores the TA program in the TEE, and stores the index structure in the REE, thereby performing sensitive word detection based on the TA program and the hash table.

[0086] Figure 6A According to the embodiment of the present application, a schematic diagram of a specific construction process using a hash table as an example is shown. The process is described using the cloud 200 as an example. It is understandable that in other embodiments, it can also be constructed for other terminal devices, which is not required here. The specific process is as follows:

[0087] S601, determine the hash table structure to be used and the corresponding location function, and initialize the hash table to be empty.

[0088] In some embodiments, a cuckoo hash table combined with a cuckoo filter is selected as the hash table structure. Assuming that there are at most n sensitive words in the sensitive word library, the number of hash buckets in the hash table is configured to be m, where m=2 t ,definition Each bucket can hold four fingerprint values, and all buckets are initially empty. It is understood that when a cuckoo filter is used as a hash table, multiple hash functions can be used to map elements to one or more locations in the hash table. It is understood that in other embodiments, other hash table structures can be used, and different numbers of hash buckets and storage space sizes in each bucket can be configured, without limitation here.

[0089] S602: Determine the message authentication code algorithm and position function to be used, and initialize the key for creating the message authentication code.

[0090] It can be understood that the message authentication code algorithm may include but is not limited to a hash message authentication code (HMAC), a cipher blockchaining message authentication code (CBC-MAC) algorithm, and the like.

[0091] In some embodiments, the HMAC algorithm is selected as the message authentication code algorithm for fingerprint value calculation. A 256-bit string can be randomly generated as the key.

[0092] S603: Calculate the fingerprint value of each sensitive word according to the message authentication code algorithm and the key, and calculate the index value of the corresponding sensitive word according to the position function.

[0093] In some embodiments, a 256-bit key and a message of any length (i.e., a sensitive word) are used as HMAC inputs. A 256-bit string (i.e., an authentication code) is generated, and then a preset bit position of the generated authentication code, such as 64 bits, is extracted as a fingerprint value. Furthermore, a hash function may be involved in the position function, and the SHA256 algorithm may be selected as a specific hash function for position calculation. The position function may calculate one or more index values ​​corresponding to the sensitive word, i.e., corresponding to a specific hash bucket identifier. The number of specific index values ​​is determined by the configuration of the position function and is not limited herein.

[0094] In some embodiments, the fingerprint value of a sensitive word can be calculated using the following formula (1):

[0095] f(x)=HMAC(x,key)[1:64] Formula (1)

[0096] Where f(x) represents the fingerprint value of the sensitive word x, HMAC() is the hash message authentication code algorithm, key is the key, and [1:64] indicates the selection of the first 64 bits of data.

[0097] In some embodiments, the index value of the sensitive word that needs to be inserted into the hash table can be calculated using the following formula (2) and formula (3), respectively:

[0098] h1(x)=SHA256(x)[1:t] Formula (2)

[0099] h2(x)=h1(x)⊕(SHA256(f(x))[1:t]) Formula (3)

[0100] Where ⊕ represents a bit-by-bit XOR operation: 0⊕0=0, 0⊕1=1, 1⊕0=1, and 1⊕1=0. t represents the selection of the first t bits of data, where t is a positive integer. For example, t is 64.

[0101] It can be understood that the index value of the sensitive word x is calculated according to formula (2) and formula (3) respectively, and two index values ​​are obtained.

[0102] For the sensitive word X1, calculate the fingerprint function f(X1) and obtain the fingerprint value;

[0103] Use the hash function to calculate the bucket index value, i1 = h1 (X1), i2 = h2 (X1).

[0104] Specifically, the fingerprint value of the sensitive word X1 can be calculated according to the above formula (1) to obtain the fingerprint value f x1 ; The bucket index value of the sensitive word X1 can be calculated according to the above formula (2) and the above formula (3) respectively, and the obtained values ​​are i1=h1(X1) and i2=h2(X1).

[0105] S604: Based on the obtained index value, the fingerprint value of the sensitive word is inserted into the hash table.

[0106] In some embodiments, after calculating at least one index value using the position function, the corresponding position in the hash table is found, and the calculated fingerprint value is inserted into the hash table according to the following cuckoo algorithm:

[0107] (1) Check the i1th bucket in the hash table. If the bucket is not full, put the fingerprint value f x1 , the insertion is completed. Otherwise, go to (2);

[0108] (2) Check the i2th bucket in the hash table. If the bucket is not full, put the fingerprint value f x1 , the insertion is completed. Otherwise, go to (3);

[0109] (3) Randomly select a bucket from i1 and i2, and let the selected bucket be i. In the i-th bucket, randomly select a fingerprint value from it and delete it from the bucket, and then put the fingerprint value fx1 into it.

[0110] (4) Let the deleted fingerprint value be f d , let the fingerprint value f next =f d ,i next =i, set the counter ctr=0, and delete the fingerprint value f d Re-insert into the hash table as follows:

[0111] Calculate i alt =i next ⊕SHA256(f next )[1:t]. If i alt The corresponding bucket is not full, so f next Insert, the insertion is completed. Otherwise, in i alt In the corresponding bucket, randomly select a fingerprint value and delete it from the bucket, then replace the fingerprint value f next Put it in. Let the deleted fingerprint value be f d' Let f next =f d' ,i next =i alt , ctr=ctr+1. If ctr is less than 500, repeat the insertion operation, otherwise go to (5);

[0112] (5) Increase the number of buckets m=m*2, rebuild the hash table, and recalculate the positions of all fingerprint values, including the fingerprint values ​​originally placed, and place them in the rebuilt hash table.

[0113] It is understandable that the execution order of S601 to S604 described above is only an example. In other embodiments, other execution orders may be adopted, and some steps may be split or combined, which is not limited here.

[0114] It is understood that after the hash table is constructed, the message authentication code algorithm and its key are compiled into a TA program. It is understood that compiling into a TA program can be performed simultaneously with the process of constructing the hash table, or after or before the hash table is constructed, which is not required here.

[0115] Figure 6B According to the embodiment of the present application, a schematic diagram of the construction process is shown, taking the index structure as a hash table as an example. Figure 6B As shown, the message authentication code algorithm obtains the fingerprint value corresponding to the sensitive word X based on the input sensitive word X and the key. Then, the position function can be used to calculate the index value to obtain the position where the sensitive word X needs to be inserted in the hash table. The fingerprint value corresponding to the sensitive word X is then inserted into the calculated hash bucket, thereby obtaining a hash table that represents the correspondence between sensitive words and fingerprint values.

[0116] Figure 7A According to an embodiment of the present application, a schematic diagram of a detection process is shown, taking the index structure as a hash table as an example. The execution subject of this process can be the terminal 100, and the specific process is as follows:

[0117] S701, using the position function, calculate the index value of the word to be detected.

[0118] In some embodiments, the word to be detected is calculated according to the position function shown in the above formula (2) and formula (3) to obtain index value 1 and index value 2 respectively.

[0119] S702: Obtain at least one fingerprint value A from a hash table according to the index value.

[0120] In some embodiments, index value 1 and index value 2 correspond to bucket index value j1 and bucket index value j2 in the hash table respectively, and the fingerprint value in the hash table is indexed according to index value 1 and index value 2. For example, fingerprint values ​​A1, A2, A3, and A4 are found in the hash bucket corresponding to index value 1, and fingerprint values ​​A5, A6, and A7 are found in the hash bucket corresponding to index value 2.

[0121] S703: Run the message authentication code algorithm and key in the TEE to generate the fingerprint value B of the word to be detected.

[0122] In some embodiments, the TA program interface in the TEE is called, the word to be detected is input into the TA program, and the fingerprint value B is calculated internally according to the message authentication code algorithm and key built into the TEE according to formula (1) shown above, and output from the TEE for subsequent judgment in the REE.

[0123] S704: Determine whether there is a fingerprint value equal to fingerprint value B in at least one fingerprint value A.

[0124] If yes, proceed to S705; otherwise, proceed to S706.

[0125] For example, if any fingerprint value among fingerprint values ​​A1, A2, A3, A4, A5, A6, and A7 is the same as fingerprint value B, the word to be detected is determined to be a sensitive word, and the process proceeds to S705; otherwise, the word to be detected is not a sensitive word, and the process proceeds to S706.

[0126] S705: Determine whether the word to be detected is a sensitive word.

[0127] S706: Determine whether the word to be detected is a sensitive word.

[0128] It is understandable that the execution order of S701 to S706 is only an example. In other embodiments, other execution orders may be adopted, and some steps may be split or combined, which is not limited here.

[0129] For example, Figure 7B According to an embodiment of the present application, a schematic diagram of a sensitive word detection process using a hash table is shown. Figure 7B As shown, the TEE in the terminal device stores a message authentication code algorithm and a key. On the one hand, the terminal device calculates a fingerprint value B in the TEE with high security. On the other hand, it obtains at least one fingerprint value A through a hash table in an execution environment with low security. The obtained fingerprint values ​​are matched and the detection result is obtained according to the matching situation.

[0130] Figure 8 A schematic structural diagram of a device is shown according to an embodiment of the present application.

[0131] It can be understood that the device 800 can be any electronic device that can detect sensitive words or construct index relationships, for example, it can include but is not limited to mobile phones, tablet computers, vehicle-mounted equipment, augmented reality (AR) / virtual reality (VR) devices, ultra-mobile personal computers (UMPC), netbooks, personal digital assistants (PDA), servers, server clusters, etc., without limitation here.

[0132] like Figure 8 As shown, apparatus 800 may include one or more processors 801, also referred to as processing units, which may implement certain control functions. Processor 801 may be a general-purpose processor or a dedicated processor. For example, it may be a baseband processor or a central processing unit. The baseband processor may be used to process communication protocols and communication data, while the central processing unit may be used to control a communication device, such as a base station, baseband chip, terminal, terminal chip, DU, or CU, etc., execute software programs, and process data in the software programs.

[0133] In an optional design, the processor 801 may also store instructions and / or data 803, and the instructions and / or data 803 can be executed by the processor so that the device 800 performs the method described in the above method embodiment.

[0134] In another alternative design, processor 801 may include a transceiver unit for implementing receiving and transmitting functions. For example, the transceiver unit may be a transceiver circuit, an interface, or an interface circuit. The transceiver circuit, interface, or interface circuit for implementing the receiving and transmitting functions may be separate or integrated. The transceiver circuit, interface, or interface circuit may be used for reading and writing code / data, or may be used for transmitting or delivering signals.

[0135] In another possible design, the apparatus 800 may include a circuit that can implement the functions of sensitive word detection or index relationship construction in the aforementioned method embodiment.

[0136] Optionally, the device 800 may include one or more memories 802, on which instructions / data 804 may be stored. The instructions may be executed on a processor, causing the device 800 to perform the method described in the above method embodiment. Optionally, the memory may also store data. Optionally, the processor may also store instructions and / or data. The processor and memory may be provided separately or integrated. For example, the corresponding relationship described in the above method embodiment may be stored in the memory or in the processor.

[0137] Optionally, the apparatus 800 may further include a transceiver 805 and / or an antenna 806. The processor 801 may be referred to as a processing unit, and controls the apparatus 800. The transceiver 805 may be referred to as a transceiver unit, a transceiver, a transceiver circuit, a transceiver device, an interface, an interface circuit, or a transceiver module, and is configured to implement transceiver functions.

[0138] Optionally, the apparatus 800 in the embodiment of the present application may be used to execute the embodiment of the present application. Figure 3 、 Figure 4 、 Figure 6A as well as Figure 7A The method described in .

[0139] According to the method provided in the embodiments of the present application, the present application also provides a computer program product, which includes: computer program code, when the computer program code is run on a computer, enables the computer to implement the steps performed by the device 800 in any one of the above embodiments.

[0140] According to the method provided in the embodiments of the present application, the present application also provides a computer-readable medium, which stores program code. When the program code runs on a computer, the computer implements the steps performed by the device 800 in any of the above embodiments.

[0141] The various embodiments disclosed in this application can be implemented in hardware, software, firmware, or a combination of these implementation methods. The embodiments of the present application can be implemented as a computer program or program code executed on a programmable system, which includes at least one processor, a storage system (including volatile and non-volatile memory and / or storage elements), at least one input device, and at least one output device.

[0142] Program code can be applied to input instructions to perform the functions described herein and generate output information. The output information can be applied to one or more output devices in a known manner. For purposes of this application, a processing system includes any system having a processor such as, for example, a digital signal processor (DSP), a microcontroller, an application specific integrated circuit (ASIC), or a microprocessor.

[0143] Program code can be implemented with a high-level programming language or an object-oriented programming language to communicate with the processing system. Where necessary, program code can also be implemented in assembly language or machine language. In fact, the mechanism described in this application is not limited to the scope of any particular programming language. In either case, the language can be a compiled language or an interpreted language.

[0144] In some cases, the disclosed embodiments may be implemented in hardware, firmware, software, or any combination thereof. The disclosed embodiments may be implemented as instructions carried or stored on one or more temporary or non-temporary machine-readable (e.g., computer-readable) storage media, which may be read and executed by one or more processors. For example, the instructions may be distributed over a network or through other computer-readable media. Therefore, a machine-readable medium may include any mechanism for storing or transmitting information in a form readable by a machine (e.g., a computer), including but not limited to floppy disks, optical disks, optical discs, read-only memories (CD-ROMs), magneto-optical disks, read-only memories (ROMs), random access memories (RAMs), erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic or optical cards, flash memory, or a tangible machine-readable memory for transmitting information (e.g., carrier waves, infrared signals, digital signals, etc.) using the Internet in electrical, optical, acoustic, or other forms of propagation signals. Therefore, a machine-readable medium includes any type of machine-readable medium suitable for storing or transmitting electronic instructions or information in a form readable by a machine (e.g., a computer).

[0145] In the accompanying drawings, some structural or method features are shown in a particular arrangement and / or order. However, it should be understood that such a particular arrangement and / or order may not be required. Rather, in some embodiments, these features may be arranged in a manner and / or order different from that shown in the illustrative drawings. In addition, the inclusion of a structural or method feature in a particular figure does not imply that such feature is required in all embodiments, and in some embodiments, such features may not be included or may be combined with other features.

[0146] It should be noted that the units / modules mentioned in the various device embodiments of the present application are all logical units / modules. Physically, a logical unit / module can be a physical unit / module, or a part of a physical unit / module, or can be implemented as a combination of multiple physical units / modules. The physical implementation of these logical units / modules themselves is not the most important. The combination of functions implemented by these logical units / modules is the key to solving the technical problems raised by this application. In addition, in order to highlight the innovative part of this application, the above-mentioned device embodiments of this application do not introduce units / modules that are not closely related to solving the technical problems raised by this application. This does not mean that other units / modules do not exist in the above-mentioned device embodiments.

[0147] It should be noted that in the examples and description of this patent, relational terms such as first and second are merely used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. Without further restriction, an element defined by the phrase "comprising a" does not exclude the presence of other identical elements in the process, method, article or device comprising the element. Although the present application has been illustrated and described with reference to certain preferred embodiments of the present application, it should be understood by those skilled in the art that various changes can be made thereto in form and detail without departing from the scope of the present application.

Claims

1. A sensitive word detection method, applied to a terminal device, characterized in that: The method comprises: Get the word to be detected; Calling a first algorithm stored in a first execution environment to generate a first fingerprint value of the word to be detected, and Matching the word to be detected with an index relationship stored in the second execution environment to obtain at least one second fingerprint value, wherein the index relationship includes a correspondence between index values ​​corresponding to multiple sensitive words and multiple second fingerprint values; Corresponding to the presence of a second fingerprint value matching the first fingerprint value in the at least one second fingerprint value, determining that the word to be detected is a sensitive word; The security level of the first execution environment is higher than the security level of the second execution environment, and the first algorithm is a cryptographic algorithm.

2. The method according to claim 1, characterized in that The cryptographic algorithm includes at least one of the following: Message Authentication Code Algorithm, Data Encryption Standard Algorithm, Advanced Encryption Standard Algorithm.

3. The method according to claim 1, characterized in that The first execution environment includes: a trusted execution environment or a secure element; The second execution environment includes an open execution environment.

4. The method according to claim 1, wherein Also includes: receiving a first program and the index relationship sent by a cloud device, wherein the first program includes the first algorithm; The first program is stored in the first execution environment, and the index relationship is stored in the second execution environment.

5. The method according to claim 4, characterized in that The first program also includes a key corresponding to the first algorithm.

6. The method according to claim 5, characterized in that The calling of a first algorithm stored in a first execution environment to generate a first fingerprint value of the word to be detected includes: The first program is run in the first execution environment to calculate the word to be detected to obtain the first fingerprint value.

7. The method according to claim 6, characterized in that The step of matching the word to be detected with the index relationship stored in the second execution environment to obtain at least one second fingerprint value includes: Determine at least one index value corresponding to the word to be detected using at least one position function; Determine the at least one second fingerprint value corresponding to the at least one index value in the index relationship.

8. The method according to claim 7, characterized in that The index values ​​corresponding to the multiple sensitive words in the index relationship are determined based on the at least one position function, and the second fingerprint values ​​corresponding to the multiple sensitive words in the index relationship are obtained based on the first algorithm.

9. The method according to claim 1, characterized in that The index relationship is stored based on any of the following methods: Hash table, dictionary tree.

10. The method according to claim 1, wherein: The terminal device matches the word to be detected with the index relationship stored in the second execution environment in the second execution environment to obtain at least one second fingerprint value; as well as The terminal device determines, in the second execution environment, whether there is a second fingerprint value matching the first fingerprint value in the at least one second fingerprint value.

11. An electronic device, characterized in that: include: a memory for storing instructions; A processor, configured to execute the instructions to implement the sensitive word detection method according to any one of claims 1 to 10.

12. A readable storage medium, characterized in that: The readable medium stores instructions, and when the instructions are executed on the electronic device, the electronic device executes the sensitive word detection method according to any one of claims 1 to 10.

13. A computer program product, characterized in that The computer program product includes: a computer program code, which, when executed on a computer, enables the computer to execute the sensitive word detection method according to any one of claims 1 to 10.