Device and method for computer-aided processing of data
Patent Information
- Application Number
- DE102020116791
- Authority / Receiving Office
- DE · DE
- Patent Type
- Patents
- Current Assignee / Owner
- Filing Date
- 2020-06-25
- Publication Date
- 2025-09-11
- Estimated Expiration
- 2040-06-25
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[0001] Various embodiments relate to a device and a method for computer-aided processing of data.
[0002] In general, in the hierarchical security model, the operating system kernel is protected against user applications. However, the operating system kernel can modify the behavior and data of a user application. Applications can be executed in a trusted execution environment (Texecution Environment), which allows the applications to run protected from the operating system kernel. For example, access by the operating system kernel to the application's behavior and / or data can be restricted. However, attackers can use various methods to gain access to and manipulate trusted execution environments, which can then be used to attack computer systems on which the application is running (for example, using malware). Therefore, it may be necessary to create a trusted execution environment that is protected from tampering.For example, it may be necessary to run an application in a trusted execution environment, where access to the application's behavior and / or data is restricted, preferably prevented, by an operating system kernel.
[0003] US 2020 / 0076804 A1 discloses methods for analyzing applications with the goal of protecting mobile devices. Cryptographic representations in the form of hash values of application information are generated for each application installed on the mobile device. The cryptographic representations can be transmitted to a system external to the device. This makes it possible to determine whether the respective application is permitted to be used within the company. The application information contains the application name, executable code, and a version number.
[0004] US 10 554 643 B2 discloses a method for authenticating a client application by an authorization server. The authorization server transmits a first redirection identifier associated with the client application to a web runtime engine in response to a registration request for registering the client application with the authorization server. Furthermore, the authorization server receives an access request from the client application to access a protected resource stored on a resource server. Furthermore, the authorization server transmits the access request to the resource server via the web runtime engine using a second redirection identifier corresponding to a redirection endpoint of the client application.The second redirection identifier is listened to by the web runtime engine and the client application accesses the protected resource depending on the result of a comparison of the first redirection identifier with the second redirection identifier in the web runtime engine.
[0005] US 7 587 592 B2 discloses a mobile device that can activate Java-AP software. The mobile device receives an ADF from an IP server and receives a security description file (SDF) from a management server (managed by a trusted organization), and receives a JAR file from the IP server using the ADF. The mobile device installs the Java-AP software containing the specified files. The Java-AP obtained by activating the installed Java-AP software operates within the limits described in the security information set in the SDF.
[0006] According to various embodiments, an apparatus and a method for computer-assisted processing of data are provided, by means of which data can be processed in a protected, trusted execution environment. Furthermore, according to various embodiments, an apparatus and a method for computer-assisted processing of data are provided, by means of which a computer system can be protected from manipulation and / or attacks. According to various embodiments, an apparatus and a method for computer-assisted processing of data are provided, by means of which access to the behavior and / or data of an executed application by an operating system kernel is restricted, preferably prevented.
[0007] According to various embodiments, a method for computer-aided formation of a trustworthy execution environment for computer-aided processing of data comprises: providing configuration data of an application, transmitting the configuration data to an authentication service, determining a first application identification, wherein the first application identification is assigned to the application, wherein determining the first application identification comprises receiving an execution request of the application by a start service, wherein the first application identification is determined using the execution request, determining a configuration identification comprising a first authentication identification assigned to the configuration data of the application and a second authentication identification assigned to the authentication service, generating, from the start service,the trusted execution environment, wherein the first authentication identification is assigned to the trusted execution environment, and individualizing the data by means of a second application identification, wherein the second application identification is determined using the first application identification and the configuration identification, and wherein the second application identification is assigned to the application and the configuration data of the application.
[0008] The method having the features of independent claim 1 constitutes a first example.
[0009] An application can be any type of algorithm that can be executed by a processor.
[0010] Individualizing data using a second application identification can result in data being uniquely assigned based on the second application identification. For example, the data of an application and configuration data of the application can be assigned, and the data of the application and the configuration data of the application can be identified using the second application identification. For example, an instance of an execution environment can be created by means of individualization. An instance can, for example, be uniquely distinguished from other instances of an execution environment.
[0011] The method may further comprise determining an expected application identification. The expected application identification may be determined using the first application identification and the configuration identification. The method may comprise comparing the expected application identification with the second application identification. If the expected application identification corresponds to the second application identification, the method may comprise executing the application using the configuration data. By comparing the expected application identification with the second application identification, for example, a manipulated execution environment can be detected. For example, a change in the application data and / or a change in the application configuration data can be detected.Consequently, this has the effect of preventing the application from running in a modified (e.g., manipulated) execution environment. Accordingly, access to the configuration data from modified execution environments can be prevented, which can, for example, prevent the application from running. The features described in this paragraph, in combination with the first example, form a second example.
[0012] The method may further comprise encrypting the personalized data. The personalized data may be encrypted, for example, using a key. The features described in this paragraph in combination with the first example or the second example constitute a third example.
[0013] Individualizing the data using a second application identification creates an execution environment. The feature described in this paragraph, in combination with one or more of the first through third examples, forms a fourth example.
[0014] Executing the application may include executing the application in the execution environment using the configuration data. The feature described in this paragraph, in combination with the fourth example, constitutes a fifth example.
[0015] The configuration data may include runtime configuration data and / or application configuration data. The features described in this paragraph in combination with one or more of the first example through the fifth example constitute a sixth example.
[0016] The runtime configuration data may include execution environment configuration data. The features described in this paragraph, in combination with the fifth example and the sixth example, constitute a seventh example.
[0017] The runtime configuration data may include file system shield configuration data, network shield configuration data, and / or secret injection configuration data. The secret injection configuration data may include one or more of: at least one symmetric key (e.g., a binary symmetric key), at least one alphanumeric password, at least one asymmetric key pair (e.g., RSA, e.g., elliptic curves, etc.), at least one X509 certificate, user-specific data, etc. The features described in this paragraph in combination with the sixth example or the seventh example constitute an eighth example.
[0018] The application configuration data may include program line arguments and / or environment variables. The features described in this paragraph, in combination with one or more of the sixth through eighth examples, constitute a ninth example.
[0019] Providing application configuration data may include receiving the application configuration data through an authentication service. The features described in this paragraph in combination with one or more of the first through the ninth examples constitute a tenth example.
[0020] Providing application configuration data may further include storing the application configuration data by the authentication service. The features described in this paragraph, in combination with the tenth example, constitute an eleventh example.
[0021] Providing application configuration data may further comprise receiving a first application identification associated with the application by the authentication service. Providing application configuration data may further comprise storing the first application identification in conjunction with the associated application configuration data by the authentication service. The features described in this paragraph in combination with the tenth example or the eleventh example constitute a twelfth example.
[0022] The configuration data can be transmitted by a user to the authentication service. The feature described in this paragraph, combined with the twelfth example, forms a thirteenth example.
[0023] The first application identification can be transmitted by the user to the authentication service in conjunction with the application's configuration data. The feature described in this paragraph, in combination with the twelfth example or the thirteenth, constitutes a fourteenth example.
[0024] Transmitting the configuration data and / or transmitting the first application identification to the authentication service may include the use of a transport-layer security encryption protocol. The features described in this paragraph in combination with the thirteenth example or the fourteenth example constitute a fifteenth example.
[0025] The transport-layer security encryption protocol may include the use of an asymmetric key pair. The feature described in this paragraph, in combination with the fifteenth example, constitutes a sixteenth example.
[0026] The authentication service can be executed in a trusted execution environment. The feature described in this paragraph in combination with one or more of the tenth example through the sixteenth example constitutes a seventeenth example.
[0027] The authentication service may be a centralized authentication service. The feature described in this paragraph, in combination with one or more of the tenth example through the seventeenth example, constitutes an eighteenth example.
[0028] The authentication service may be executed on an authentication server. The feature described in this paragraph, in combination with one or more of the tenth example through the eighteenth example, constitutes a nineteenth example.
[0029] Determining the first application identification comprises receiving an execution request for the application from a launch service. Determining the first application identification further comprises determining the first application identification using the execution request from the launch service. The features described in this paragraph in combination with one or more of the tenth example through the nineteenth example form a twentieth example.
[0030] Determining the configuration identification may include transmitting a configuration identification request from a startup service to the authentication service. The configuration identification request may include the first application identification. Determining the configuration identification may include transmitting the configuration identification by the authentication service to the startup service in response to the configuration identification request. Using an authentication service, such as a central authentication service (CAS), may protect a system from man-in-the-middle attacks. The authentication service may, for example, generate the configuration identification, for example, using the configuration data. Consequently, for example, only the authentication service can associate the configuration identification with the configuration data.The features described in this paragraph in combination with the twentieth example constitute a twenty-first example.
[0031] The configuration identification may include a first authentication identification and / or a second authentication identification. The features described in this paragraph in combination with one or more of the tenth example through the twenty-first example constitute a twenty-second example.
[0032] The first authentication identification may be associated with the configuration data associated with the first application identification. The feature described in this paragraph, in combination with the twenty-second example, constitutes a twenty-third example.
[0033] The first authentication identifier may include a random value. The feature described in this paragraph, in combination with the twenty-second example or the twenty-third example, constitutes a twenty-fourth example.
[0034] The second authentication identification can be associated with the authentication service. If the configuration data, and thus, for example, the second authentication identification, is added to the first application identification, a system is protected from communication with a forged authentication service (for example, by means of a man-in-the-middle attack). For example, when communicating with another service, such as a startup service, the authentication service can determine whether it has a second application identification that includes the second authentication identification associated with the authentication service. The feature described in this paragraph in combination with one or more of the twenty-second example to the twenty-fourth example constitutes a twenty-fifth example.
[0035] Communication with the authentication service may include a transport-layer security encryption protocol. The feature described in this paragraph, in combination with one or more of the tenth example through the twenty-fifth example, constitutes a twenty-sixth example.
[0036] The transport-layer security encryption protocol may include the use of an asymmetric key pair with a public key and a private key. The feature described in this paragraph, in combination with the twenty-sixth example, constitutes a twenty-seventh example.
[0037] The second authentication identification may include a certificate associated with the public key. The certificate may include a hash value. The features described in this paragraph, in combination with the twenty-seventh example, constitute a twenty-eighth example.
[0038] Determining the second application identification may include adding the configuration identification to the first application identification. The feature described in this paragraph in combination with one or more of the first example through the twenty-eighth example constitutes a twenty-ninth example.
[0039] The first application identification and the configuration identification can each have a hash value. The second application identification can be determined using the hash value of the first application identification and the hash value of the configuration identification. The features described in this paragraph in combination with one or more of the first example through the twenty-ninth example constitute a thirtieth example.
[0040] The hash value of the first application identification and / or the hash value of the second application identification can be generated using a hash function (also called a hash function). The hash function can be an SHA256 hash function. Due to the use of a hash function, any change to the data and / or configuration data of an application results in a changed hash value. This has the effect of allowing a change to the data and / or configuration data of an application to be detected. The features described in this paragraph, in combination with the thirtieth example, form a thirty-first example.
[0041] Individualizing the data using the second application identification may include individualizing the data using the hash value of the second application identification. The features described in this paragraph in combination with the thirtieth example or the thirty-first example constitute a thirty-second example.
[0042] Creating an execution environment may include creating a pre-state of the execution environment. Creating an execution environment may include creating the execution environment using the pre-state of the execution environment. The features described in this paragraph in combination with one or more of the first example through the thirty-second example constitute a thirty-third example.
[0043] Determining the expected application identification may comprise emulating the creation of an execution environment using the first application identification and the configuration identification. Determining the expected application identification may comprise determining the expected application identification using the emulated execution environment. The features described in this paragraph in combination with one or more of the fourth example through the thirty-third example constitute a thirty-fourth example.
[0044] Emulating the creation of the execution environment may comprise creating an emulated pre-state of the execution environment. Emulating the creation of the execution environment may comprise creating the emulated execution environment using the pre-state of the execution environment and the configuration identification. The features described in this paragraph, in combination with the thirty-third example and the thirty-fourth example, constitute a thirty-fifth example.
[0045] Executing the application in the execution environment using the configuration data may include transmitting a configuration data request from the execution environment service to the authentication service. The configuration data request may include the second application identification. Executing the application in the execution environment may further include, if the expected application identification corresponds to the second application identification, transmitting the configuration data by the authentication service to the execution environment service in response to the configuration data request. Executing the application in the execution environment may include executing the application by means of the execution environment service in the execution environment using the configuration data of the execution environment.The features described in this paragraph in combination with one or more of the fourth example through the thirty-fifth example constitute a thirty-sixth example.
[0046] The method may further comprise, if the expected application identification does not match the second application identification, rejecting the configuration data request. The feature described in this paragraph, in combination with the thirty-sixth example, constitutes a thirty-seventh example.
[0047] The method may further comprise issuing a security warning if the expected application identification does not match the second application identification. The feature described in this paragraph in combination with the thirty-sixth example or the thirty-seventh example constitutes a thirty-eighth example.
[0048] Executing the application in the execution environment using the configuration data may comprise initializing the generated execution environment using the configuration data. Executing the application in the execution environment may further comprise executing the application in the initialized execution environment. The features described in this paragraph in combination with one or more of the thirty-sixth example through the thirty-eighth example constitute a thirty-ninth example.
[0049] Communication with the authentication service may include a transport-layer security encryption protocol. The features described in this paragraph, in combination with one or more of the tenth example through the thirty-ninth example, constitute a fortieth example.
[0050] A transport-layer security encryption protocol may be used for communication between the launch service and the authentication service. The features described in this paragraph, in combination with one or more of the twentieth example through the fortieth example, constitute a forty-first example.
[0051] A transport-layer security encryption protocol may be used for communication between the execution environment service and the authentication service. The transport-layer security encryption protocol may include the use of an asymmetric key pair with a public key and a private key. An attestation procedure may be performed prior to each communication using a transport-layer security encryption protocol. The features described in this paragraph, in combination with one or more of the thirty-sixth example through the forty-first example, constitute a forty-second example.
[0052] A device may be configured to carry out the method according to one or more of the first example to the forty-second example. The device having the features described in this paragraph constitutes a forty-third example.
[0053] A system for computer-aided data processing may comprise a device having the features of the forty-third example. The device may comprise at least one processor. The system may comprise a user interface. The user interface may be configured to receive an input. The at least one processor may be configured to execute the method having the features of the first example to the forty-second example in response to the input received from the user interface. The system having the features described in this paragraph constitutes a forty-fourth example.
[0054] A computer program product can store program instructions which, when executed, perform the method having the features of the first example through the forty-second example. The computer program product having the features described in this paragraph constitutes a forty-fifth example.
[0055] It shows Fig. 1 a device according to various embodiments; Fig. 2 a system according to various embodiments; Fig. 3A illustrates a method for computer-assisted processing of data according to various embodiments; Fig. 3B illustrates a method for computer-assisted processing of data according to various embodiments; Fig. 4A illustrates a detailed method for computer-assisted processing of data according to various embodiments; Fig. 4B illustrates a detailed method for computer-assisted processing of data according to various embodiments.
[0056] In the following detailed description, reference is made to the accompanying drawings, which form a part hereof, and in which is shown by way of illustration specific embodiments in which the invention may be practiced.
[0057] The term "processor" can be understood as any type of entity that allows the processing of data or signals. The data or signals can, for example, be processed according to at least one (i.e., one or more than one) specific function performed by the processor. A processor can include or be formed from an analog circuit, a digital circuit, a mixed-signal circuit, a logic circuit, a microprocessor, a central processing unit (CPU), a graphics processing unit (GPU), a digital signal processor (DSP), a programmable gate array (FPGA), an integrated circuit, or any combination thereof. Any other type of implementation of the respective functions, which are described in more detail below, can also be understood as a processor or logic circuit.It is understood that one or more of the method steps described in detail herein may be executed (e.g., realized) by a processor through one or more specific functions performed by the processor. The processor may therefore be configured to perform one of the methods described herein or its components for information processing.
[0058] Attackers can use various methods to change, for example, manipulate, the behavior and / or data of an application that is executed, for example, in a trusted execution environment. This can, for example, infect a computer system on which the application is executed with malware. Various embodiments relate to a device and a method for computer-assisted data processing, by means of which manipulation of an executed application is prevented, which can, for example, protect a computer system from manipulation and / or attacks.
[0059] Fig. 1 shows a device 100 according to various embodiments. The device 100 may include a storage device 102. The storage device 102 may include at least one memory. The memory may, for example, be used in the processing performed by a processor. A memory used in the embodiments may be a volatile memory, for example, a DRAM (Dynamic Random Access Memory), or a non-volatile memory, for example, a PROM (Programmable Read-Only Memory), an EPROM (Erasable PROM), an EEPROM (Electrically Erasable PROM), or a flash memory, such as a floating gate memory device, a charge-trapping memory device, an MRAM (Magnetoresistive Random Access Memory), or a PCRAM (Phase Change Random Access Memory). The storage device 102 may be configured to store code (for example, program code) of an application module.The code of the application module can be processed, for example, by a processor to execute an application. The storage device 102 can be configured to store data. The data can, for example, be data associated with an application. The data can, for example, be processed by an application when executed by a processor.
[0060] The device 100 may further include at least one processor 104. As described above, the processor 104 may be any type of circuit, ie, any type of logic-implementing entity. In various embodiments, the processor 104 is configured to execute an application.
[0061] Fig. 2 shows a system 200 according to various embodiments. The system 200 may include the device 100. The system 200 may further include a user interface 202. The user interface 202 may be configured to enable a person, such as a user, to interact with the device 100. For example, the user interface 202 may include an input device. The input device may be configured to receive input from a user. The user interface 202 may be configured to provide the user's input to the device 100. The user's input may, for example, be a request to process data (for example, to execute an application). The processor 104 may be configured to process the request to process data (for example, the request to execute an application).The processor 104 may, for example, be configured to perform one of the methods described below.
[0062] Fig. 3A shows a method 300A for computer-assisted processing of data according to various embodiments. The method 300A may include providing configuration data of an application (in 302). The configuration data may include runtime configuration data and / or application configuration data. The runtime configuration data may include configuration data of an execution environment (e.g., data describing a configuration of an execution environment). The runtime configuration data may include file system shield configuration data, network shield configuration data, and / or secret injection configuration data.The configuration data for a secret injection may include one or more of: at least one symmetric key (e.g., a binary symmetric key), at least one alphanumeric password, at least one asymmetric key pair (e.g., RSA, elliptic curve, etc.), at least one X509 certificate, and / or user-specific data. The user-specific data may be data specified by a user. The application configuration data may include program line arguments and / or environment variables.
[0063] The method 300A may further comprise determining a first application identification (in 304). The first application identification may be associated with the application. The method 300A may further comprise determining a configuration identification (in 306). The configuration identification may be associated with the configuration data of the application. The method 300A may further comprise determining a second application identification (in 308). The second application identification may be determined, for example, using the first application identification and the configuration identification. The second application identification may be determined, for example, by adding the configuration identification to the first application identification. According to various embodiments, the first application identification and the configuration identification may each have a hash value.The hash value of the first application identification and / or the hash value of the configuration identification can be generated, for example, using a hash function (also called a hash function). The hash function can be an SHA256 hash function, for example. The second application identification can be determined, for example, using the hash value of the first application identification and the hash value of the configuration identification. The second application identification can be determined, for example, by adding the hash value of the configuration identification to the hash value of the first application identification.
[0064] Method 300A may include individualizing data using the second application identification (at 310). Individualizing data may include, for example, individualizing the application. Individualizing data may include, for example, an integrity measurement. The data may be individualized using the hash value of the second application identification, for example. Individualizing the data using the second application identification may generate an execution environment.
[0065] Fig. 3B shows a method 300B for computer-assisted processing of data according to various embodiments. The method 300B may include the method 300A. The method 300B may further include determining an expected application identification (in 312). The expected application identification may be determined using the first application identification and the configuration identification. The method 300B may further include comparing the expected application identification with the second application identification (in 314). The method 300B may include, if the expected application identification corresponds to the second application identification, executing the application using the configuration data (in 316). The method 300B may include, if the expected application identification does not correspond to the second application identification, not executing the application.Method 300B may include issuing a security warning if the expected application identification does not match the second application identification. Method 300B may further include encrypting the personalized data using a key (e.g., a disposable key).
[0066] Fig. 4A shows a detailed method 400A for computer-assisted processing of data according to various embodiments. The method 400A may be a detailed method of the method 300A. The method 400A may be performed by the system 200. For example, a user 402 may interact with the user interface 202. The at least one processor 104 may implement an authentication service 404. The authentication service 404 may be executed in a trusted execution environment. The authentication service 404 may be a central authentication service (CAS). The authentication service 404 may, for example, be executed on an authentication server. The at least one processor 104 may implement a launch service 406.
[0067] The user 402 can, for example, enter an input for executing an application via the user interface 402. According to various embodiments, configuration data can be provided via the input for executing an application. The configuration data can, as described above, comprise runtime configuration data and / or application configuration data. The configuration data is transmitted (in 410), for example via the user interface (e.g., from the user). The authentication service 404 can receive the application configuration data and can store the application configuration data, for example, in the storage device 102. According to various embodiments, the authentication service 404 can further receive the first application identification (e.g., via the user interface 402) (in 410).The authentication service 404 may be configured to store the first application identification, for example, in the storage device 102. The authentication service 404 may store the first application identification in conjunction with the associated configuration data.
[0068] The configuration data and / or the first application identification may be transmitted using a transport layer security encryption protocol (a TLS encryption protocol). A TLS encryption protocol, as described herein, may use an asymmetric key pair (e.g., comprising a public key and a private key). The respective public keys may, for example, be exchanged between the respective elements described below (e.g., services, e.g., a user interface) before transmitting the respective data (such as the configuration data).
[0069] Launch service 406 may, for example, be launched in response to input from user 402. Launch service 406 may receive an execution request to execute an application (at 412). According to various embodiments, the execution request may be transmitted in response to the input to execute an application by user 402 (e.g., via user interface 202). Launch service 406 may be configured to determine the first application identification using the execution request. For example, the execution request may include the first application identification.
[0070] The launch service 406 may transmit a configuration identification request to the authentication service 404 (at 414). The launch service 406 may transmit the configuration identification request to the authentication service 404 to request a configuration identification from the authentication service 404. The configuration identification request may include the first application identification associated with the application. The requested configuration identification may be an identification (e.g., an identifier) for the application's configuration data.
[0071] The authentication service 404 may be configured to transmit a configuration identification to the launch service 406 in response to the configuration identification request (at 416). The configuration identification comprises a first authentication identification. The first authentication identification is associated with the configuration data associated with the first application identification of the application. The first authentication identification may comprise a random value. The authentication service 404 may be configured to generate a first authentication identification (such as a random value) associated with the configuration data of the application in response to the configuration identification request and to transmit the generated first authentication identification to the launch service 406.The authentication service 404 can be configured to store the first authentication identification in conjunction with the configuration data, for example, in the storage device 102. Illustratively, a random value can be assigned to the configuration data, and the authentication service can store the random value in conjunction with the configuration data. The configuration identification includes a second authentication identification. The second authentication identification is assigned to the authentication service 404. Illustratively, the second authentication identification can include an identifier for the authentication service 404. For example, the second authentication identification can include a certificate of the authentication service.The communication between the launch service 406 and the authentication service 404 may include a transport-layer security encryption protocol as described above, using, for example, an asymmetric key pair (comprising a public key and a private key). The certificate may be associated with the public key of the authentication service 404. The certificate may include a hash value.
[0072] The launch service 406 may be configured to generate an execution environment (in 418) in response to receiving the configuration identification (e.g., the first authentication identification and / or the second authentication identification). According to various embodiments, the first authentication identification (e.g., the random value) may be uniquely assigned to the execution environment (e.g., a first authentication identification is assigned to exactly one execution environment). For example, a plurality of execution environments may be generated for a plurality of applications using method 400A, wherein each execution environment of the plurality of execution environments may be uniquely assigned a first authentication identification (e.g., a bijective assignment of the plurality of execution environments and the plurality of first authentication identifications).This has the effect, for example, that the authentication service 404 can uniquely assign a first authentication identification to an execution environment of the plurality of execution environments.
[0073] The launch service 406 can enable the generated execution environment to access, for example, system functions. The launch service 406 can be configured to determine a second application identification (in 420). The second application identification can be associated with the generated execution environment. The launch service 406 can determine the second application identification, for example, using the first application identification and the configuration data. The second application identification can be determined, for example, by adding the configuration identification to the first application identification. According to various embodiments, the first application identification and the configuration identification can each have a hash value.The hash value of the first application identification and / or the hash value of the configuration identification can be generated, for example, using a hash function (also called a hash function). The hash function can be, for example, an SHA256 hash function. The second application identification can be determined, for example, using the hash value of the first application identification and the hash value of the configuration identification. The second application identification can be determined, for example, by adding the hash value of the configuration identification to the hash value of the first application identification. Illustratively, the second application identification can be an identifier of the execution environment generated in 418. Illustratively, the second application identification can define a behavior of an application and / or configuration data of the application.
[0074] For example, the data can be personalized using the second application identification. The second application identification is clearly assigned to an application and the application's configuration data.
[0075] Fig. 4B illustrates a detailed method 400B for computer-assisted processing of data according to various embodiments. Method 400B may include method 400A, wherein the at least one processor 104 may further implement an execution environment service 408.
[0076] The start service 406 can be configured to start the execution environment service 408. The start service 406 can, for example, be configured to start the execution environment service 408 in response to the creation of the execution environment. According to various embodiments, the execution environment service 408 can be executed in the execution environment. The configuration data is required to execute the application in the execution environment. The execution environment service 408 can, for example, perform an attestation with the authentication service 404. The execution environment service 408 can, for example, transmit the second application identification of the created execution environment to the authentication service 404 during the attestation.
[0077] For example, an execution environment may be created by creating a pre-state of the execution environment and creating the execution environment using the pre-state.
[0078] The authentication service 404 may be configured to emulate an execution environment. For example, the authentication service 404 may include an emulation module that may be configured to emulate an execution environment. The authentication service 404 may be configured to generate an emulated pre-state of an execution environment (in 422). The emulated pre-state may be associated with the execution environment generated in 418. The emulated pre-state may be generated using the first application identification. The authentication service 404 may be configured to generate an emulated execution environment using the emulated pre-state of the execution environment and the configuration identification associated with the first application identification of the application. The authentication service 404 may be configured to determine an expected application identification (in 424).The authentication service 404 may determine the expected application identification using the emulated execution environment. The expected application identification may be associated with the emulated execution environment. The expected application identification may be a hash value of the emulated execution environment.
[0079] The authentication service 404 may determine the expected application identification in response to transmitting the configuration identification (at 414) to the launch service 406. The authentication service 404 may determine the expected application identification in response to communication between the execution environment service 408 and the authentication service 404.
[0080] The execution environment service 408 may transmit a configuration data request to the authentication service 404 to request the application's configuration data (at 426). The configuration data request may, for example, include the second application identification. According to various embodiments, the authentication service 404 may determine the expected application identification in response to the transmission of the configuration data request. The communication between the execution environment service 408 and the authentication service 404 may include a transport-layer security encryption protocol as described above.
[0081] The authentication service 404 may be configured to compare the expected application identification with the second application identification (in 428).
[0082] The authentication service 404 can be configured to transmit the application's configuration data to the execution environment service 408 in response to the configuration data request (in 430) if the expected application identification corresponds to the second application identification. The authentication service 404 can be configured to reject the configuration data request of the execution environment service 408 if the expected application identification does not correspond to the second application identification. The authentication service 404 can be configured to issue a security warning, for example, to the user 402 via the user interface 202, if the expected application identification does not correspond to the second application identification.
[0083] The execution environment service 408 may be configured to execute the application in the execution environment using the received configuration data. The execution environment service 408 may be configured to initialize the execution environment created in 418 (in 432).
[0084] The execution environment service 408 may be configured to initialize the execution environment generated in 418 using the configuration data, for example, in response to receiving the configuration data from the authentication service 404. The execution environment service 408 may be configured to execute the application in the initialized execution environment (in 434). According to various embodiments, an execution environment generated in 418 may continue to be modified, and an initialized execution environment may no longer be modified.
Claims
[1] Method for computer-aided formation of a trustworthy execution environment for computer-aided processing of data, the method comprising: • Providing configuration data of an application; • Transmitting the configuration data to an authentication service; • Determining a first application identification, wherein the first application identification is associated with the application, wherein determining the first application identification comprises receiving an execution request of the application by a launch service, wherein the first application identification is determined using the execution request; • Determining a configuration identification comprising a first authentication identification associated with the configuration data of the application and a second authentication identification associated with the authentication service; • Creating, from the startup service, the trusted execution environment, wherein the first authentication identification is associated with the trusted execution environment; and • Individualizing the data by means of a second application identification, wherein the second application identification is determined using the first application identification and the configuration identification, and wherein the second application identification is assigned to the application and the configuration data of the application. [2] The method of claim 1, further comprising: • Determining an expected application identification using the first application identification and the configuration identification; • Comparing the expected application identification with the second application identification; • if the expected application identification corresponds to the second application identification, execute the application using the configuration data. [3] The method of claim 2, wherein determining the expected application identification comprises: • Emulating the creation of an execution environment using the first application identification and the configuration identification; • Determine the expected application identification using the emulated execution environment. [4] The method of claim 3, wherein emulating the creation of the execution environment comprises: • Creating an emulated pre-state of the execution environment; • Creating the emulated execution environment using the previous state of the execution environment and the configuration identification. [5] The method of claim 2, wherein executing the application comprises executing the application in the execution environment using the configuration data. [6] Method according to one of claims 1 to 5, wherein determining the second application identification comprises: Add the configuration identification to the first application identification. [7] Method according to one of claims 1 to 6, wherein the first application identification and the configuration identification each have a hash value; and wherein the second application identification is determined using the hash value of the first application identification and the hash value of the configuration identification. [8] Method according to claim 7, wherein the hash value of the first application identification and / or the second application identification is generated using a hash function. [9] Method according to claim 7 or 8, wherein individualizing the data by means of the second application identification comprises: Individualize the data using the hash value of the second application identification. [10] Apparatus arranged to carry out the method according to any one of claims 1 to 9. [11] System for computer-aided processing of data, comprising: • The device of claim 10, wherein the device comprises at least one processor; • a user interface configured to receive input; • wherein the at least one processor is configured to execute the method according to any one of claims 1 to 9 in response to the input received from the user interface. [12] A computer program product storing program instructions which, when executed, carry out the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
US000010554643B2
Systems and Methods for Security Analysis of Applications on User Mobile Devices While Maintaining User Application Privacy
US20200076804A1
Distribution method, distribution system, and terminal device
US7587592B2