Verification method, device and equipment for trusted execution environment (TEE) all-in-one machine
By comparing the first verification code of the TEE all-in-one machine with the pre-generated second verification code, the problem of the inability to verify the legitimacy of the all-in-one machine software in the existing technology is solved, thus ensuring the security of the system.
Patent Information
- Application Number
- CN202510288227.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-12-12
AI Technical Summary
In existing technologies, verification methods can only verify that the TEE CPU in the all-in-one machine is a legitimate device from the TEE manufacturer, but cannot verify the legitimacy of the software in the all-in-one machine. This results in users being unable to verify the software when it is intruded or replaced, creating security risks.
The legitimacy of the software is determined by obtaining the first verification information sent by the user equipment of the TEE all-in-one machine, including the first universal unique identifier and the first verification code generated by multiple software files, and comparing it with the target verification information in multiple pre-generated second verification information.
It enables the legality verification of software in TEE all-in-one machines, solves the security risks when software is intruded or replaced, and ensures the security of the system.
Smart Images

Figure CN121125141A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of cloud computing technology, and in particular to a verification method, apparatus and equipment for a Trusted Execution Environment (TEE) appliance. Background Technology
[0002] A Trusted Execution Environment (TEE) is a security technology that provides an isolated execution environment at the hardware level to protect sensitive data and code. TEE creates an isolated region within the processor, ensuring that code executing and data processed within this region is not interfered with or accessed by external software (such as the operating system or other applications). TEE manufacturers (CPU manufacturers) provide verification schemes for users to verify that the CPU device on a server is a legitimate TEE CPU manufactured by that manufacturer.
[0003] System vendors will develop business applications based on TEE capabilities on servers with TEE functionality, launching integrated hardware and software appliances with TEE security features. When users acquire such appliances, existing verification methods can only verify that the TEE CPU within the appliance is a legitimate device from the TEE vendor, but cannot verify the legitimacy of the software within the appliance. This can lead to situations (e.g., during logistics) where the software is compromised or replaced without the user's ability to verify, resulting in system security vulnerabilities. Summary of the Invention
[0004] The purpose of this invention is to provide a verification method, apparatus, and device for a Trusted Execution Environment (TEE) appliance, which solves the problem that existing verification methods can only verify that the TEE CPU in the appliance is a legitimate device from the TEE manufacturer, but cannot verify the legitimacy of the software in the appliance. This leads to the software being compromised or replaced without the user's ability to verify it, causing security risks.
[0005] To achieve the above objectives, embodiments of the present invention provide a verification method for a Trusted Execution Environment (TEE) appliance, wherein the method is applied to a verification server and includes:
[0006] Obtain first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine;
[0007] The first verification code is compared with the second verification code included in the target verification information among a plurality of pre-generated second verification information; wherein, the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier;
[0008] If the first verification code corresponds to the second verification code, it is determined that the software verification on the TEE all-in-one machine has passed;
[0009] Send a verification result to the user equipment; wherein the verification result is used to display the comparison result between the first verification code and the second verification code included in the target verification information.
[0010] Optionally, in the verification method, before comparing the first verification code with the second verification code included in the target verification information among a plurality of pre-generated second verification information, the method further includes:
[0011] The target verification information is matched among multiple second verification information based on the first universal unique identifier, and includes the second universal unique identifier that has the same content as the first universal unique identifier.
[0012] Optionally, the verification method further includes:
[0013] Obtain the hardware identifiers of the multiple TEE all-in-one machines;
[0014] Generate the second universal unique identifier corresponding to each of the multiple TEE all-in-one machines;
[0015] The second verification code is generated based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier.
[0016] Optionally, the verification method, wherein generating the second verification code based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier includes:
[0017] Obtain the software hash value corresponding to each of the aforementioned software files;
[0018] Based on the software hash values corresponding to the multiple software files, a first hash value is obtained using a hash tree method;
[0019] The second verification code is generated based on the hardware identifier hash value, the second universal unique identifier hash value, and the first hash value; wherein the hardware identifier hash value is obtained based on the hardware identifier, and the second universal unique identifier hash value is obtained based on the second universal unique identifier.
[0020] Optionally, in the verification method, obtaining the software hash value corresponding to each software file includes:
[0021] Sort the multiple software files according to their names to obtain multiple sorted software files;
[0022] Perform a hash operation on each of the sorted software files to obtain the software hash value.
[0023] Optionally, the verification method further includes:
[0024] The second universal unique identifier is written into the source code of each of the multiple business software programs to obtain the first code;
[0025] The first code is compiled to obtain multiple software files.
[0026] To achieve the above objectives, embodiments of the present invention provide a verification method for a Trusted Execution Environment (TEE) appliance, which is applied to a user equipment and includes:
[0027] Send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein the first verification information includes a first universally unique identifier and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance.
[0028] Obtain the verification result sent by the verification server; wherein, the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among the multiple second verification information pre-generated by the verification server; the target verification information is verification information including a second universal unique identifier corresponding to the first universal unique identifier.
[0029] Optionally, the verification method further includes:
[0030] Obtain the first universal unique identifier of the TEE all-in-one machine;
[0031] The first verification code is generated based on the first universal unique identifier, the hardware identifier, and the software file.
[0032] Optionally, the verification method, wherein generating the first verification code based on the first universally unique identifier, the hardware identifier, and the software file, includes:
[0033] Obtain the hardware identifier;
[0034] The first hash value is obtained from the software file using a hash tree method.
[0035] The first verification code is generated based on the hardware identifier hash value, the first universally unique identifier hash value, and the first hash value; wherein, the hardware identifier hash value is obtained based on the hardware identifier, and the first universally unique identifier hash value is obtained based on the first universally unique identifier.
[0036] To achieve the above objectives, embodiments of the present invention provide a verification device for a Trusted Execution Environment (TEE) appliance, wherein the device is applied to a verification server and includes:
[0037] The first acquisition module is used to acquire first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine;
[0038] A first processing module is configured to compare the first verification code with a second verification code included in a target verification information among a plurality of pre-generated second verification information; wherein the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier;
[0039] The first determining module is used to determine that the software verification on the TEE all-in-one machine has passed when the first verification code corresponds to the second verification code;
[0040] A first sending module is used to send a verification result to the user equipment; wherein the verification result is used to display a comparison result between the first verification code and the second verification code included in the target verification information.
[0041] To achieve the above objectives, embodiments of the present invention provide a verification device for a Trusted Execution Environment (TEE) appliance, which is applied to user equipment and includes:
[0042] The second sending module is used to send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance.
[0043] The second acquisition module is used to acquire the verification result sent by the verification server, wherein the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among a plurality of second verification information pre-generated by the verification server; the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier.
[0044] To achieve the above objectives, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a program or instructions stored in the memory and executable on the processor; wherein, when the processor executes the program or instructions, it implements the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above, and the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0045] To achieve the above objectives, embodiments of the present invention provide a readable storage medium storing a program or instructions thereon, wherein the program or instructions, when executed by a processor, implement the steps in the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above, and the steps in the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0046] To achieve the above objectives, embodiments of the present invention provide a computer program product, comprising computer instructions that, when executed by a processor, implement the steps of the verification method for the Trusted Execution Environment (TEE) all-in-one machine as described above, and the steps of the verification method for the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0047] The beneficial effects of the above-described technical solution of the present invention are as follows:
[0048] In this embodiment of the invention, a first verification code generated from multiple software files in the first verification information sent by the user equipment of the Trusted Execution Environment (TEE) appliance is compared with a second verification code included in the target verification information of multiple pre-generated second verification information, which includes a second universally unique identifier corresponding to the first universally unique identifier in the first verification information. If the first verification code and the second verification code correspond, the verification is deemed successful, thereby achieving the legality verification of the software in the TEE appliance. This solves the problem of security risks caused by software being intruded or replaced but the user being unable to verify it. Attached Figure Description
[0049] Figure 1 This is a schematic diagram of the verification method applied to the Trusted Execution Environment (TEE) appliance of the verification server according to an embodiment of the present invention;
[0050] Figure 2This is a schematic diagram of the module of the verification method for the Trusted Execution Environment (TEE) all-in-one machine according to an embodiment of the present invention;
[0051] Figure 3 This is one of the flowcharts for the verification server of the verification method of the Trusted Execution Environment (TEE) all-in-one machine described in the embodiments of the present invention;
[0052] Figure 4 This is the second flowchart of the verification server of the verification method for the Trusted Execution Environment (TEE) appliance described in this embodiment of the invention;
[0053] Figure 5 This is a schematic diagram of the hash tree for the verification method of the Trusted Execution Environment (TEE) all-in-one machine described in this embodiment of the invention;
[0054] Figure 6 This is a schematic diagram of the verification method for a Trusted Execution Environment (TEE) all-in-one machine applied to a user equipment according to an embodiment of the present invention;
[0055] Figure 7 This is one of the flowcharts for the user equipment of the verification method of the Trusted Execution Environment (TEE) all-in-one machine described in the embodiments of the present invention;
[0056] Figure 8 The second flowchart of the user equipment verification method of the Trusted Execution Environment (TEE) all-in-one machine described in the embodiments of the present invention;
[0057] Figure 9 This is a schematic diagram of the verification device of the Trusted Execution Environment (TEE) all-in-one machine applied to the verification server, as described in an embodiment of the present invention;
[0058] Figure 10 This is a schematic diagram of the verification device for the Trusted Execution Environment (TEE) all-in-one machine applied to user equipment, as described in an embodiment of the present invention. Detailed Implementation
[0059] To make the technical problems, technical solutions and advantages of the present invention clearer, a detailed description will be given below in conjunction with the accompanying drawings and specific embodiments.
[0060] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of the invention. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification do not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0061] In various embodiments of the present invention, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.
[0062] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0063] In the embodiments provided in this application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined based on A. However, it should also be understood that determining B based on A does not mean determining B solely based on A; B can also be determined based on A and / or other information.
[0064] For ease of understanding, the following describes some aspects of the embodiments of the present invention:
[0065] like Figure 1 As shown in the figure, a verification method for a Trusted Execution Environment (TEE) appliance according to an embodiment of the present invention, wherein the method is applied to a verification server and includes:
[0066] S10, obtain the first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universal unique identifier, and a first verification code generated based on the first universal unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine;
[0067] It should be noted that, as Figure 2 As shown, a verification platform is set up on the verification server, including a verification information database, a verification tool image repository, and a verification web service. The first verification information sent by the user device is received on the verification web service.
[0068] S20, compare the first verification code with the second verification code included in the target verification information among a plurality of pre-generated second verification information; wherein, the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier;
[0069] It should be noted that, in Figure 2 The verification information database stores the second verification information of multiple TEE all-in-one machines. It is necessary to match the first universal identification code in the first verification information with the corresponding second universal unique identification code in the verification information database to determine the target verification information. The first verification code and the second verification code in the target verification information are compared.
[0070] S30, if the first verification code corresponds to the second verification code, it is determined that the software verification on the TEE all-in-one machine has passed;
[0071] It should be noted that since the second verification code generated by the same TEE all-in-one machine on the verification server is generated in the same process as the first verification code generated by the user device after arriving at the customer's location, it is determined that the software on the TEE all-in-one machine has not been hacked or replaced when the first verification code corresponds to the second verification code, and the verification is successful.
[0072] S40, send a verification result to the user equipment; wherein, the verification result is used to display the comparison result between the first verification code and the second verification code included in the target verification information;
[0073] It should be noted that after the first verification code is compared with the second verification code, the comparison result is sent to the user equipment as the verification result.
[0074] In this embodiment, the first verification code generated from multiple software files in the first verification information sent by the user equipment of the Trusted Execution Environment (TEE) appliance is compared with the second verification code included in the target verification information of multiple pre-generated second verification information, which includes the second universally unique identifier corresponding to the first universally unique identifier in the first verification information. If the first verification code corresponds to the second verification code, the verification is determined to be successful, thereby achieving the legality verification of the software in the TEE appliance. This solves the problem of security risks caused by software being intruded or replaced but users being unable to verify it.
[0075] Optionally, in the verification method, before comparing the first verification code with the second verification code included in the target verification information among a plurality of pre-generated second verification information, the method further includes:
[0076] The target verification information is matched among multiple second verification information based on the first universal unique identifier, and includes the second universal unique identifier that has the same content as the first universal unique identifier.
[0077] In this embodiment, for a TEE all-in-one machine, the universally unique identifier, i.e., UUID, should remain unchanged. Therefore, during the verification process, the target verification information, which includes the same content as the first universally unique identifier, can be matched among multiple second verification information based on the first universally unique identifier, thereby achieving the purpose of verification.
[0078] Optionally, the verification method further includes:
[0079] Obtain the hardware identifiers of the multiple TEE all-in-one machines;
[0080] Generate the second universal unique identifier corresponding to each of the multiple TEE all-in-one machines;
[0081] The second verification code is generated based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier.
[0082] In this embodiment, such as Figure 4 As shown, for a TEE all-in-one machine, the legitimacy of the TEE CPU can be verified on the relevant website or service provided by the TEE CPU manufacturer based on the hardware identifier (or chip ID) in its CPU (central processing unit). This includes: Step 1.1, obtaining the TEE CPU hardware identifier; and Step 1.2, verifying the CPU through the TEE CPU manufacturer's website. In Step 1.3, a unique UUID is generated, i.e., the second universally unique identifier is generated. In Step 1.6, a comprehensive verification hash code is constructed, i.e., the second verification code is generated based on multiple software files on the TEE all-in-one machine, the hardware identifier, and the second universally unique identifier.
[0083] Optionally, the verification method, wherein generating the second verification code based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier includes:
[0084] Obtain the software hash value corresponding to each of the aforementioned software files;
[0085] Based on the software hash values corresponding to the multiple software files, a first hash value is obtained using a hash tree method;
[0086] The second verification code is generated based on the hardware identifier hash value, the second universal unique identifier hash value, and the first hash value; wherein the hardware identifier hash value is obtained based on the hardware identifier, and the second universal unique identifier hash value is obtained based on the second universal unique identifier.
[0087] In this embodiment, such as Figure 4 As shown, the second verification code is generated by using the first hash value obtained by hashing the first hash value, hardware identifier hash value, and second universal unique identifier hash value, based on the software hash values corresponding to the multiple software files respectively, and completing step 1.6 to construct the overall verification hash code.
[0088] Optionally, in the verification method, obtaining the software hash value corresponding to each software file includes:
[0089] Sort the multiple software files according to their names to obtain multiple sorted software files;
[0090] Perform a hash operation on each of the sorted software files to obtain the software hash value.
[0091] In this embodiment, after sorting the multiple software files according to their names, a hash value is calculated for each software file (this can be done using commands such as sha256sum in Linux) to obtain the software hash value. These multiple software hash values are then used as leaf nodes to form the bottom layer of the hash tree. Starting from the bottom layer of the hash tree, the software hash values corresponding to every two leaf nodes are concatenated and hashed to generate the second hash value of the corresponding parent node. This process is repeated until only one parent node remains, thereby obtaining the first hash value and constructing a Merkle tree (i.e., the hash tree), completing the process. Figure 4 Step 1.5 involves constructing the Merkle tree for software verification. For example, if the software files reside in a Java microservice system containing four Java files: a.jar, b.jar, c.jar, and d.jar, then the Merkle tree would look like this: Figure 5 As shown, first, a sha256sum operation is performed on the four .jar files to obtain four hash values, h11 to h14. Then, h11 and h12 are concatenated and a sha256 operation is performed again to obtain h21. Similarly, h22 is obtained. Finally, h21 and h22 are concatenated and a sha256 operation is performed to obtain the root of the Merkle tree, h_m (i.e., the first hash value). The hardware identifier and the second universally unique identifier are also subjected to sha256 operations to obtain hash results h_cpu (i.e., the hash value of the hardware identifier) and h_uuid (i.e., the hash value of the second universally unique identifier). h_m is then concatenated, and h = sha256(h_cpu, h_uuid, h_m) is calculated, which is the second verification code, completing the process. Figure 4 In step 1.6, the overall verification hash code is constructed. And in step 1.7, the business software is deployed to the TEE server, and the verification information (i.e., the second verification information) is written to the database (i.e.,...). Figure 2 (Verification information database in the middle).
[0092] Optionally, the verification method further includes:
[0093] The second universal unique identifier is written into the source code of each of the multiple business software programs to obtain the first code;
[0094] The first code is compiled to obtain multiple software files.
[0095] In this embodiment, such as Figure 3 As shown, after obtaining the TEE server, the system vendor compiles and installs the business software, generates verification information (i.e., the second verification information), and writes it to the database (i.e., Figure 2 The verification information database in the database is used to complete the setup of the verification server. Figure 4 As shown, in step 1.4, the UUID is written into the source code of the business software, that is, the second universal unique identifier is written into the source code of each of the multiple business software, the first code is obtained, the business software is compiled, that is, the first code is compiled to obtain multiple software files, in preparation for building the hash tree.
[0096] like Figure 6 As shown, to achieve the above objectives, embodiments of the present invention provide a verification method for a Trusted Execution Environment (TEE) appliance, which is applied to a user equipment and includes:
[0097] A10, send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein, the first verification information includes a generated first universal unique identifier, and a first verification code generated based on the first universal unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance.
[0098] It should be noted that, as Figure 7 As shown, after the user obtains the all-in-one machine, they download the verification tool (i.e., the user's device) from the verification web service of the system manufacturer (i.e., the verification server), and use the verification tool to perform verification. Figure 8 In step 2.5, the UUID (i.e., the first universal unique identifier) and the local overall verification code (i.e., the first verification code) are sent to the verification web service of the system vendor (i.e., the verification server).
[0099] A20, Obtain the verification result sent by the verification server; wherein, the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among the multiple second verification information pre-generated by the verification server; the target verification information is verification information including a second universal unique identifier corresponding to the first universal unique identifier;
[0100] It should be noted that, as Figure 8As shown, in step 2.6, the verification results are obtained and displayed.
[0101] Optionally, the verification method further includes:
[0102] Obtain the first universal unique identifier of the TEE all-in-one machine;
[0103] The first verification code is generated based on the first universal unique identifier, the hardware identifier, and the software file.
[0104] In this embodiment, such as Figure 8 As shown, in step 2.1, the business software interface is called to obtain the UUID (i.e., the first universally unique identifier), that is, to obtain the first universally unique identifier of the TEE all-in-one machine. In step 2.4, the local overall verification code (i.e., the first verification code) is calculated, that is, the first verification code is generated based on the first universally unique identifier, the hardware identifier, and the software file.
[0105] Optionally, the verification method, wherein generating the first verification code based on the first universally unique identifier, the hardware identifier, and the software file, includes:
[0106] Obtain the hardware identifier;
[0107] The first hash value is obtained from the software file using a hash tree method.
[0108] The first verification code is generated based on the hardware identifier hash value, the first universally unique identifier hash value, and the first hash value; wherein, the hardware identifier hash value is obtained based on the hardware identifier, and the first universally unique identifier hash value is obtained based on the first universally unique identifier.
[0109] In this embodiment, such as Figure 8 As shown, in step 2.2, the TEE CPU hardware identifier is obtained, i.e., the hardware identifier is obtained. The method of generating the first verification code is the same as the method of generating the second verification code by the verification server. In step 2.3, the local software verification Merkle tree is calculated, i.e., a hash tree is used to obtain the first hash value based on the software file; in step 2.2, the local overall verification code is calculated, i.e., the first verification code is generated based on the hardware identifier hash value, the first universal unique identifier hash value, and the first hash value.
[0110] According to the verification method of the Trusted Execution Environment (TEE) appliance, if a malicious intermediary copies the business software from a TEE appliance, installs it on another TEE server, and then provides it to the end user, the TEE CPU hardware identifier on the new TEE server will be different from the original machine. This will cause the h_cpu (i.e., the hash value of the hardware identifier) to be incorrect, resulting in an incorrect local overall verification code (i.e., the first verification code), and verification will fail. If the business software in a TEE appliance is tampered with, the h_m (i.e., the first hash value) will be incorrect, resulting in an incorrect local overall verification code (i.e., the first verification code), and verification will fail. It can be seen that, in addition to the CPU hardware verification by the TEE CPU manufacturer, this embodiment of the invention provides system manufacturers with a method to verify the legitimacy of the software in their TEE appliances. Using both methods simultaneously can further improve the security of the TEE appliance.
[0111] like Figure 9 As shown, to achieve the above objectives, embodiments of the present invention provide a verification device for a Trusted Execution Environment (TEE) appliance, wherein the device is applied to a verification server and includes:
[0112] The first acquisition module 901 is used to acquire first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine.
[0113] The first processing module 902 is used to compare the first verification code with the second verification code included in the target verification information among a plurality of pre-generated second verification information; wherein, the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier;
[0114] The first determining module 903 is used to determine that the software verification on the TEE all-in-one machine has passed when the first verification code corresponds to the second verification code;
[0115] The first sending module 904 is used to send a verification result to the user equipment; wherein the verification result is used to display the comparison result between the first verification code and the second verification code included in the target verification information.
[0116] like Figure 10 As shown, to achieve the above objectives, embodiments of the present invention provide a verification device for a Trusted Execution Environment (TEE) all-in-one machine, which is applied to user equipment and includes:
[0117] The second sending module 1001 is used to send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein the first verification information includes a generated first universal unique identifier, and a first verification code generated based on the first universal unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance.
[0118] The second acquisition module 1002 is used to acquire the verification result sent by the verification server; wherein, the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among the multiple second verification information pre-generated by the verification server; the target verification information is verification information including a second universal unique identifier corresponding to the first universal unique identifier.
[0119] Optionally, the verification device further includes:
[0120] The second processing module is configured to match the target verification information, which includes the same content as the first universal unique identifier, among a plurality of second verification information based on the first universal unique identifier.
[0121] Optionally, the verification device further includes:
[0122] The third acquisition module is used to acquire the hardware identifiers of the multiple TEE all-in-one machines;
[0123] The first generation module is used to generate the second universal unique identification code corresponding to each of the multiple TEE all-in-one machines;
[0124] The second generation module is used to generate the second verification code based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier.
[0125] Optionally, in the verification apparatus, the second generation module includes:
[0126] The first acquisition unit is used to acquire the software hash value corresponding to each of the software files;
[0127] The second acquisition unit is used to acquire the first hash value by using a hash tree method based on the software hash values corresponding to the multiple software files respectively.
[0128] The first generation unit is configured to generate the second verification code based on the hardware identifier hash value, the second universally unique identifier hash value, and the first hash value; wherein the hardware identifier hash value is obtained based on the hardware identifier, and the second universally unique identifier hash value is obtained based on the second universally unique identifier.
[0129] Optionally, in the verification apparatus, the first acquisition unit includes:
[0130] The first acquisition component is used to sort the multiple software files according to their names and acquire the multiple sorted software files.
[0131] The second acquisition component is used to perform a hash operation on each of the sorted software files to obtain the software hash value.
[0132] Optionally, the verification device further includes:
[0133] The fourth acquisition module is used to write the second universal unique identifier into the source code of each of the multiple business software programs to obtain the first code;
[0134] The fifth acquisition module is used to compile the first code and acquire multiple software files.
[0135] Optionally, the verification device further includes:
[0136] The sixth acquisition module is used to acquire the first universal unique identifier of the TEE all-in-one machine;
[0137] The third generation module is used to generate the first verification code based on the first universal unique identifier, the hardware identifier, and the software file.
[0138] Optionally, in the verification apparatus, the third generation module includes:
[0139] The third acquisition unit is used to acquire the hardware identifier;
[0140] The fourth acquisition unit is used to obtain the first hash value based on the software file using a hash tree method;
[0141] The second generation unit is used to generate the first verification code based on the hardware identifier hash value, the first universally unique identifier hash value, and the first hash value; wherein the hardware identifier hash value is obtained based on the hardware identifier, and the first universally unique identifier hash value is obtained based on the first universally unique identifier.
[0142] It should be noted that the apparatus provided in this embodiment of the invention can implement all the method steps implemented in the above method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0143] To achieve the above objectives, embodiments of the present invention provide an electronic device, including: a processor, a memory, and a program or instructions stored in the memory and executable on the processor; wherein, when the processor executes the program or instructions, it implements the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above, and the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0144] To achieve the above objectives, embodiments of the present invention provide a readable storage medium storing a program or instructions thereon, wherein the program or instructions, when executed by a processor, implement the steps in the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above, and the steps in the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0145] It should be further noted that the terminals described in this specification include, but are not limited to, smartphones, tablets, etc., and many of the functional components described are referred to as modules in order to emphasize the independence of their implementation.
[0146] In this embodiment of the invention, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0147] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0148] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0149] To achieve the above objectives, embodiments of the present invention provide a computer program product, comprising computer instructions that, when executed by a processor, implement the steps of the verification method for the Trusted Execution Environment (TEE) all-in-one machine as described above, and the steps of the verification method for the Trusted Execution Environment (TEE) all-in-one machine as described above.
[0150] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of the invention. Therefore, the invention should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make the invention complete and convey the scope of the invention to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0151] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A verification method for a Trusted Execution Environment (TEE) appliance, characterized in that, Applied to the verification server, including: Obtain first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine; The first verification code is compared with the second verification code included in the target verification information among a plurality of pre-generated second verification information; wherein, the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier; If the first verification code corresponds to the second verification code, it is determined that the software verification on the TEE all-in-one machine has passed; Send a verification result to the user equipment; wherein the verification result is used to display the comparison result between the first verification code and the second verification code included in the target verification information.
2. The verification method according to claim 1, characterized in that, Before comparing the first verification code with the second verification code included in the target verification information among a plurality of pre-generated second verification information, the method further includes: The target verification information is matched among multiple second verification information based on the first universal unique identifier, and includes the second universal unique identifier that has the same content as the first universal unique identifier.
3. The verification method according to claim 1, characterized in that, The method further includes: Obtain the hardware identifiers of the multiple TEE all-in-one machines; Generate the second universal unique identifier corresponding to each of the multiple TEE all-in-one machines; The second verification code is generated based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier.
4. The verification method according to claim 3, characterized in that, The second verification code is generated based on multiple software files on each TEE all-in-one machine, the hardware identifier, and the second universal unique identifier, including: Obtain the software hash value corresponding to each of the aforementioned software files; Based on the software hash values corresponding to the multiple software files, a first hash value is obtained using a hash tree method; The second verification code is generated based on the hardware identifier hash value, the second universal unique identifier hash value, and the first hash value; wherein the hardware identifier hash value is obtained based on the hardware identifier, and the second universal unique identifier hash value is obtained based on the second universal unique identifier.
5. The verification method according to claim 4, characterized in that, The step of obtaining the software hash value corresponding to each of the software files includes: Sort the multiple software files according to their names to obtain multiple sorted software files; Perform a hash operation on each of the sorted software files to obtain the software hash value.
6. The verification method according to claim 3, characterized in that, The method further includes: The second universal unique identifier is written into the source code of each of the multiple business software programs to obtain the first code; The first code is compiled to obtain multiple software files.
7. A verification method for a Trusted Execution Environment (TEE) appliance, characterized in that, Applied to user equipment, including: Send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein the first verification information includes a first universally unique identifier and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance. Obtain the verification result sent by the verification server; wherein, the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among the multiple second verification information pre-generated by the verification server; the target verification information is verification information including a second universal unique identifier corresponding to the first universal unique identifier.
8. The verification method according to claim 7, characterized in that, The method further includes: Obtain the first universal unique identifier of the TEE all-in-one machine; The first verification code is generated based on the first universal unique identifier, the hardware identifier, and the software file.
9. The verification method according to claim 8, characterized in that, The first verification code is generated based on the first universally unique identifier, the hardware identifier, and the software file, including: Obtain the hardware identifier; The first hash value is obtained from the software file using a hash tree method. The first verification code is generated based on the hardware identifier hash value, the first universally unique identifier hash value, and the first hash value; wherein, the hardware identifier hash value is obtained based on the hardware identifier, and the first universally unique identifier hash value is obtained based on the first universally unique identifier.
10. A verification device for a Trusted Execution Environment (TEE) all-in-one machine, characterized in that, Applied to the verification server, including: The first acquisition module is used to acquire first verification information sent by the user equipment of the Trusted Execution Environment (TEE) all-in-one machine; wherein, the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE all-in-one machine, and multiple software files of the TEE all-in-one machine; A first processing module is configured to compare the first verification code with a second verification code included in a target verification information among a plurality of pre-generated second verification information; wherein the target verification information is verification information including a second universally unique identifier corresponding to the first universally unique identifier; The first determining module is used to determine that the software verification on the TEE all-in-one machine has passed when the first verification code corresponds to the second verification code; A first sending module is used to send a verification result to the user equipment; wherein the verification result is used to display a comparison result between the first verification code and the second verification code included in the target verification information.
11. A verification device for a Trusted Execution Environment (TEE) all-in-one machine, characterized in that, Applied to user equipment, including: The second sending module is used to send first verification information to the verification server of the Trusted Execution Environment (TEE) appliance; wherein the first verification information includes a generated first universally unique identifier, and a first verification code generated based on the first universally unique identifier, the hardware identifier of the TEE appliance, and the software file of the TEE appliance. The second acquisition module is used to acquire the verification result sent by the verification server; wherein, the verification result is used to display the comparison result between the first verification code in the first verification information and the second verification code included in the target verification information among a plurality of second verification information pre-generated by the verification server; the target verification information is verification information including a second universal unique identifier corresponding to the first universal unique identifier.
12. An electronic device, comprising: A processor, a memory, and a program or instructions stored in the memory and executable on the processor; characterized in that, when the processor executes the program or instructions, it implements the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described in any one of claims 1-6, and the verification method of the Trusted Execution Environment (TEE) all-in-one machine as described in any one of claims 7-9.
13. A readable storage medium having a program or instructions stored thereon, characterized in that, When the program or instructions are executed by the processor, they implement the steps in the verification method of the Trusted Execution Environment (TEE) appliance as described in any one of claims 1-6, and the steps in the verification method of the Trusted Execution Environment (TEE) appliance as described in any one of claims 7-9.
14. A computer program product, characterized in that, The method includes computer instructions that, when executed by a processor, implement the steps of the verification method for a Trusted Execution Environment (TEE) appliance as described in any one of claims 1-6, and the steps of the verification method for a Trusted Execution Environment (TEE) appliance as described in any one of claims 7-9.