Method and apparatus for secure transmission of image information, and electronic device and server

By deploying an image information verification application module in the REE and digitally signing the images, the problem of insufficient image security in the terminal system framework is solved, ensuring the integrity and security of images captured by the camera.

WO2025261318A1PCT designated stage Publication Date: 2025-12-26VIVO MOBILE COMM CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/101307
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-06-21
Filing Date
2025-06-17
Publication Date
2025-12-26

AI Technical Summary

Technical Problem

Existing terminal system frameworks cannot effectively protect the security of images or videos captured by cameras, posing a risk of attack and failing to guarantee the security of remote camera use.

Method used

The image information verification application module is deployed in the general execution environment REE. It obtains image information by calling the camera hardware module, and digitally signs the image using the image data integrity protection module or the image data signature application module before sending it to the server for verification.

Benefits of technology

It achieves integrity protection of images captured by the camera, prevents information from being tampered with, and improves the security of remote use of the camera.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025101307_26122025_PF_FP_ABST
    Figure CN2025101307_26122025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the technical field of electronic devices. Disclosed are a method and apparatus for secure transmission of image information, and an electronic device and a server. The method for secure transmission of image information is applied to an electronic device, and the electronic device is deployed with a rich execution environment (REE). The method comprises: on the basis of a camera use request message sent by a server, an image information verification application module that runs in an REE invoking a camera hardware module to acquire image information; a target module digitally signing the image information to acquire image signature information, wherein the target module comprises an image data integrity protection module that runs in a camera hardware abstraction layer module in the REE or an image data signature application module that runs in a trusted execution environment (TEE); and the image information verification application module that runs in the REE sending the image signature information and the image information to the server.
Need to check novelty before this filing date? Find Prior Art

Description

Image information secure transmission methods, devices, electronic equipment and servers

[0001] Cross-references to related applications

[0002] This application claims priority to Chinese Patent Application No. 202410812172.2, filed in China on June 21, 2024, the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application belongs to the field of electronic equipment technology, and specifically relates to a method, apparatus, electronic device and server for secure transmission of image information. Background Technology

[0004] With the popularization of smart terminals, the application of camera capabilities on terminals is becoming more and more widespread. For example, cameras are used for remote identity authentication, such as facial recognition and collection of document information. However, the current system framework of terminals is at risk of attacks on images or videos captured by the camera, and cannot guarantee the security of remote use of the camera, nor can it provide integrity protection for the images captured by the camera. Summary of the Invention

[0005] This application provides a method, apparatus, electronic device, and server for secure transmission of image information, which can provide integrity protection for images captured by a camera.

[0006] To solve the above-mentioned technical problems, this application is implemented as follows:

[0007] In a first aspect, embodiments of this application provide a method for secure transmission of image information, applied to an electronic device, wherein the electronic device is equipped with a general execution environment (REE); including:

[0008] The image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server;

[0009] The target module performs a digital signature on the image information to obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0010] The image information verification application module running in REE sends the image signature information and the image information to the server.

[0011] Optionally, the image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server, including at least one of the following:

[0012] When the electronic device is trusted, the image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message;

[0013] The image information verification application module running in REE calls the trusted camera driver module to obtain image information.

[0014] Optionally, if the image information verification application module running in the REE, when the electronic device is trusted, invokes the camera hardware module to obtain image information based on the camera usage request message, the method further includes:

[0015] The image information verification application module running in REE sends the camera usage request message to the client application module running in the camera frame layer of REE;

[0016] If the client application module determines that the authenticity of the image acquired by the camera hardware module needs to be verified based on the camera usage request message, it sends a verification request to the image verification auxiliary trusted application module running in the TEE.

[0017] The client application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE through the image verification assisted trusted application module. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0018] Optionally, the image information verification application module running in the REE, when the electronic device is trusted, invokes the camera hardware module to obtain image information based on the camera usage request message, including:

[0019] When the electronic device is trusted, the image information verification application module running in the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE through the client application module running in the camera framework layer of the REE, based on the camera usage request message.

[0020] The camera hardware abstraction layer module running in the REE sends a photo request message to the camera driver module running in the REE;

[0021] The camera driver module calls the camera hardware module;

[0022] The camera hardware abstraction layer module running in REE acquires image information;

[0023] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0024] Optionally, when the image information verification application module running in the REE, based on the camera usage request message, invokes the camera hardware module to obtain image information, provided the electronic device is trusted, the image information verification application module running in the REE sends the image signature information and the image information to the server, including:

[0025] The image information verification application module running in the REE receives target information sent by the camera hardware abstraction layer module running in the REE through the client application module running in the camera frame layer in the REE. The target information includes image signature information.

[0026] The image information verification application module running in REE sends the target information to the server;

[0027] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0028] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0029] Optionally, the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, including:

[0030] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo-taking request message to the image information verification trusted application module running in the TEE.

[0031] The image information verification trusted application module sends a photo request message to the trusted camera service module running in the TEE;

[0032] The trusted camera service module calls the trusted camera driver module running in the TEE according to the photo-taking request message to initiate a photo-taking request;

[0033] The trusted camera driver module calls the camera hardware module;

[0034] The image information verification trusted application module running in the TEE obtains image information;

[0035] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0036] Optionally, when the image information verification application module running in the REE determines that it needs to call the camera hardware module in a trusted environment, it transmits a photo-taking request message to the image information verification trusted application module running in the TEE, including:

[0037] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo request message through the client application module running in the camera frame layer of the REE.

[0038] The photo request message includes at least one of the following:

[0039] Precision information of the captured image;

[0040] Instructions for taking photos in a trusted environment;

[0041] Information that needs to be photographed;

[0042] Business information.

[0043] Optionally, when the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, the target module digitally signs the image information to obtain image signature information, including:

[0044] The image data signature application module receives a signature request message sent by the image information verification trusted application module running in the TEE. The signature request message includes a hash value obtained based on the image information. The image data signature application module runs in the TEE and / or the security unit SE.

[0045] The image data signature application module digitally signs the hash value using the device private key to obtain image signature information;

[0046] The image data signature application module sends the image signature information to the image information verification trusted application module.

[0047] Optionally, the image information verification application module running in the REE sends the image signature information and the image information to the server, including:

[0048] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0049] The image information verification application module running in REE sends image signature information and image information to the server.

[0050] Optionally, the image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE, including:

[0051] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE through the client application module running in the camera frame layer of the REE.

[0052] Secondly, embodiments of this application provide a method for secure transmission of image information, including:

[0053] Send a camera usage request message to the electronic device;

[0054] Receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0055] The image signature information is verified;

[0056] After successful verification, the image information is processed.

[0057] Optionally, verifying the image signature information includes:

[0058] Verify the validity of the server certificate based on the server's root certificate;

[0059] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0060] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0061] Optionally, receiving image signature information and image information fed back by the image information verification application module running in the REE of the electronic device includes:

[0062] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0063] The target information further includes: image information and parameter information used to generate the signature key; or

[0064] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0065] Optionally, if the target information further includes image information and parameter information used to generate the signature key, then verifying the image signature information includes:

[0066] Verify the validity of the server certificate based on the server's root certificate;

[0067] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0068] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0069] The validity of the image signature information is verified using the signature verification key.

[0070] Optionally, if the target information further includes image information and an image verification certificate, then verifying the image signature information includes:

[0071] Verify the validity of the server certificate based on the server's root certificate;

[0072] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0073] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0074] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0075] Thirdly, embodiments of this application provide an image information secure transmission device applied to an electronic device, wherein the electronic device is equipped with a general execution environment (REE); including:

[0076] The image information verification application module, which runs in REE, is used to call the camera hardware module to obtain image information based on the camera usage request message sent by the server.

[0077] The target module is used to digitally sign the image information and obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0078] The image information verification application module is also used to send the image signature information and the image information to the server.

[0079] Optionally, the image information verification application module is configured to implement at least one of the following:

[0080] When the electronic device is trusted, the image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message;

[0081] The image information verification application module running in REE calls the trusted camera driver module to obtain image information.

[0082] Optionally, when the image information verification application module running in the REE is trusted by the electronic device, and calls the camera hardware module to obtain image information according to the camera usage request message, the image information verification application module is further configured to: send the camera usage request message to the client application module running in the camera frame layer of the REE.

[0083] The client application module is used to send a verification request to the image verification auxiliary trusted application module running in the TEE when it is determined, based on the camera usage request message, that the authenticity of the image acquired by the camera hardware module needs to be verified.

[0084] The image verification-assisted trusted application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0085] Optionally, the image information verification application module is further configured to:

[0086] When the electronic device is trusted, based on the camera usage request message, the client application module running in the camera frame layer of the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE.

[0087] The camera hardware abstraction layer module, which runs in the REE, is used to send photo request messages to the camera driver module running in the REE.

[0088] A camera driver module, used to call the camera hardware module;

[0089] The camera hardware abstraction layer module is also used to acquire image information;

[0090] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0091] Optionally, when the image information verification application module running in the REE, under the condition that the electronic device is trusted, calls the camera hardware module to obtain image information according to the camera usage request message, the image information verification application module is further configured to:

[0092] The system receives target information sent by the camera hardware abstraction layer module running in the REE and the client application module running in the camera frame layer of the REE. The target information includes image signature information.

[0093] Send the target information to the server;

[0094] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0095] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0096] Optionally, the image information verification application module is further configured to: when it is determined that the camera hardware module needs to be invoked in a trusted environment, transmit a photo-taking request message to the image information verification trusted application module running in the TEE;

[0097] The image information verification trusted application module is used to send a photo request message to the trusted camera service module running in the TEE;

[0098] The trusted camera service module is used to call the trusted camera driver module running in the TEE according to the photo request message to initiate a photo request.

[0099] A trusted camera driver module is used to call the camera hardware module;

[0100] The image information verification trusted application module is also used to acquire image information;

[0101] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0102] Optionally, the image information verification application module is further configured to: send a photo request message through a client application module running in the camera frame layer of the REE when it is determined that the camera hardware module needs to be invoked in a trusted environment;

[0103] The photo request message includes at least one of the following:

[0104] Precision information of the captured image;

[0105] Instructions for taking photos in a trusted environment;

[0106] Information that needs to be photographed;

[0107] Business information.

[0108] Optionally, when the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, the image data signature application module is used to:

[0109] Receive a signature request message sent by the image information verification trusted application module running in the TEE, the signature request message including: a hash value obtained based on the image information, the image data signature application module running in the TEE and / or the security unit SE;

[0110] The hash value is digitally signed using the device's private key to obtain image signature information;

[0111] The image signature information is sent to the image information verification trusted application module.

[0112] Optionally, the image information verification application module is used for:

[0113] Receive the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0114] Send image signature information and image information to the server.

[0115] Optionally, the image information verification application module is used for:

[0116] The client application module running in the camera frame layer of the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE.

[0117] Fourthly, embodiments of this application provide an electronic device, which is equipped with a general execution environment (REE); including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the above-described secure image information transmission method.

[0118] Fifthly, embodiments of this application provide an image information secure transmission device, comprising:

[0119] The sending module is used to send camera usage request messages to electronic devices;

[0120] The receiving module is used to receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0121] The verification module is used to verify the image signature information;

[0122] The processing module is used to process the image information after the verification is passed.

[0123] Optionally, the verification module is used for:

[0124] Verify the validity of the server certificate based on the server's root certificate;

[0125] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0126] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0127] Optionally, the receiving module is configured to:

[0128] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0129] The target information further includes: image information and parameter information used to generate the signature key; or

[0130] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0131] Optionally, if the target information further includes image information and parameter information used to generate the signature key, the verification module is configured to:

[0132] Verify the validity of the server certificate based on the server's root certificate;

[0133] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0134] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0135] The validity of the image signature information is verified using the signature verification key.

[0136] Optionally, if the target information further includes image information and an image verification certificate, the verification module is used to:

[0137] Verify the validity of the server certificate based on the server's root certificate;

[0138] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0139] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0140] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0141] In a sixth aspect, embodiments of this application provide a server, including a processor, a memory, and a program or instructions stored in the memory and executable on the processor, wherein the program or instructions, when executed by the processor, implement the steps of the above-described secure image information transmission method.

[0142] In a seventh aspect, embodiments of this application provide a readable storage medium storing a program or instructions, which, when executed by a processor, implement the steps of the above-described secure image information transmission method.

[0143] Eighthly, embodiments of this application provide a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the above-described secure image information transmission method.

[0144] In this embodiment, the image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server. The target module digitally signs the image information to obtain image signature information. The image information verification application module running in the REE then sends the image signature information and the image information to the server. This ensures that the electronic device can sign the image information, preventing information from being tampered with, providing integrity protection for the images captured by the camera, and improving the security of remote camera use. Attached Figure Description

[0145] Figure 1 is a flowchart illustrating one of the image information secure transmission methods according to an embodiment of this application;

[0146] Figure 2 is one of the communication architecture diagrams of an embodiment of this application;

[0147] Figure 3 is a schematic diagram of the initialization process for implementation method one;

[0148] Figure 4 is a flowchart illustrating the architecture shown in Figure 2;

[0149] Figure 5 is a second communication architecture diagram of an embodiment of this application;

[0150] Figure 6 is a flowchart illustrating the architecture shown in Figure 5;

[0151] Figure 7 is a second schematic flowchart of the image information secure transmission method according to an embodiment of this application;

[0152] Figure 8 is a schematic diagram of one of the modules of the image information secure transmission device according to an embodiment of this application;

[0153] Figure 9 is a schematic diagram of the structure of an electronic device according to an embodiment of this application;

[0154] Figure 10 is a second schematic diagram of the image information security transmission device according to an embodiment of this application;

[0155] Figure 11 is a schematic diagram of the server structure according to an embodiment of this application. Detailed Implementation

[0156] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0157] The terms "first," "second," etc., used in the specification and claims of this application are used to distinguish similar objects and not to describe a specific order or sequence. It should be understood that such use of data can be interchanged where appropriate so that embodiments of this application can be implemented in orders other than those illustrated or described herein, and the objects distinguished by "first," "second," etc., are generally of the same class and the number of objects is not limited; for example, a first object can be one or more. Furthermore, in the specification and claims, "and / or" indicates at least one of the connected objects, and the character " / " generally indicates that the preceding and following objects are in an "or" relationship.

[0158] The image information secure transmission method, apparatus, electronic device, and server provided in this application will be described in detail below with reference to the accompanying drawings and through specific embodiments and application scenarios.

[0159] As shown in Figure 1, this application embodiment provides a method for secure transmission of image information, applied to an electronic device, wherein the electronic device is equipped with a Rich Execution Environment (REE); the method includes:

[0160] Step 101: The image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server.

[0161] It should be noted that the image information mentioned in the embodiments of this application generally includes: original image data and image attribute information; optionally, the image attribute information includes, but is not limited to, at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0162] Optionally, this image attribute information can be understood as metadata.

[0163] Step 102: The target module digitally signs the image information to obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0164] Step 103: The image information verification application module running in REE sends the image signature information and the image information to the server.

[0165] It should be noted that, in this embodiment of the application, the image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server. The target module digitally signs the image information to obtain image signature information. The image information verification application module running in the REE then sends the image signature information and the image information to the server. This ensures that the electronic device can sign the image information, which can prevent information from being tampered with, provide integrity protection for the images captured by the camera, and improve the security of remote camera use.

[0166] It should be noted that the camera hardware module mentioned in the embodiments of this application can also be simply referred to as a camera.

[0167] Optionally, in one implementation, the image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server, including at least one of the following:

[0168] A11. When the electronic device is trusted, the image information verification application module running in the REE calls the camera hardware module to obtain image information according to the camera usage request message;

[0169] It should be noted that this implementation method is based on the image data integrity protection module in the camera hardware abstraction layer module to sign the image information. Since the image data integrity protection module runs in the REE, there is a risk that the image information may be tampered with. Therefore, before calling the camera hardware module, it is necessary to determine whether the electronic device is trustworthy. Only when the electronic device is trustworthy can it be ensured that the image information acquired by the camera hardware module will not be tampered with.

[0170] A12. The image information verification application module running in REE calls the trusted camera driver module to obtain image information;

[0171] It should be noted that in this case, the image information verification application module directly calls the trusted camera driver module, which runs in a Trusted Execution Environment (TEE). In other words, this implementation method uses the trusted camera driver module to call the camera hardware module, ensuring the security of the call and thus ensuring that the image information acquired by the camera hardware module is not tampered with.

[0172] It should be noted that this application provides two ways to call the camera hardware module, and these two methods are described in detail below.

[0173] I. Implementation of A11

[0174] Optionally, in this case, in one implementation, the method further includes:

[0175] The image information verification application module running in REE sends the camera usage request message to the client application module running in the camera frame layer of REE;

[0176] If the client application module determines that the authenticity of the image acquired by the camera hardware module needs to be verified based on the camera usage request message, it sends a verification request to the image verification auxiliary trusted application module running in the TEE.

[0177] The client application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE through the image verification assisted trusted application module. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0178] Optionally, the client application module needs to identify based on the camera usage request message to determine whether it is necessary to verify the authenticity of the image acquired by the camera hardware module. If it is necessary to verify the authenticity of the image acquired by the camera hardware module, a verification request is sent to the image verification auxiliary trusted application module. The image verification auxiliary trusted application module obtains the device security status assessment result from the device security assessment trusted application module based on the verification request.

[0179] It should be noted that the client application module can determine whether to verify the authenticity of the images captured by the camera hardware module based on the business information of the camera. For example, it can predefine which businesses need to verify the authenticity of the images captured by the camera hardware module. When the client application module obtains the business information, it compares it with the predefined businesses. If it belongs to the predefined businesses, it determines that the authenticity of the images captured by the camera hardware module needs to be verified.

[0180] It should be noted that the implementation method of the client application module determining whether to verify the authenticity of the image acquired by the camera hardware module in this application embodiment is merely an example. This application embodiment is not limited to the above-described implementation method, and other implementation methods that can determine whether to verify the authenticity of the image acquired by the camera hardware module also fall within the protection scope of this application embodiment.

[0181] Optionally, in one implementation, the image information verification application module running in the REE, when the electronic device is trusted, invokes the camera hardware module to obtain image information based on the camera usage request message, including:

[0182] Step 11: When the electronic device is trusted, the image information verification application module running in the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE through the client application module running in the camera frame layer of the REE, based on the camera usage request message.

[0183] Step 12: The camera hardware abstraction layer module running in the REE sends a photo request message to the camera driver module running in the REE;

[0184] Step 13: The camera driver module calls the camera hardware module;

[0185] Step 14: The camera hardware abstraction layer module running in REE acquires image information;

[0186] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes, but is not limited to, at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0187] It should be noted that camera hardware module calls are only made when the electronic device is trusted, ensuring the security of camera calls.

[0188] It should be noted that after the camera hardware module acquires the raw image data, it usually stores the raw image data in memory. The camera driver module feeds back the memory address where the raw image data is stored to the camera hardware abstraction layer module. The camera hardware abstraction layer module can directly retrieve the raw image data from memory based on this memory address.

[0189] It should be noted that after the camera hardware abstraction layer module obtains the image information, it needs to sign the image information. Optionally, the image data integrity protection module of the camera hardware abstraction layer module uses a signing key to digitally sign the image information or uses an image verification private key to digitally sign it.

[0190] Optionally, when the image data integrity protection module digitally signs the image information using a signature key, the signature key obtained by the image data integrity protection module is generated by the key management module running in the REE. Optionally, the key management module generates a signature key (symmetric key) based on the server's public key, the device's public key, and the parameter information used to generate the signature key (such as random numbers, timestamps, etc.), and then configures the signature key, the device certificate, and the parameter information used to generate the signature key together into the image data integrity protection module.

[0191] Optionally, when the image data integrity protection module uses the image verification private key for digital signature, the image verification private key obtained by the image data integrity protection module is generated by the key management module running in the REE. The key management module generates a public / private key pair (which can be called the image verification public / private key pair, i.e., including the image verification public key and the image verification private key), uses the device private key to digitally sign the image verification public key to generate an image verification certificate, and then configures the image verification private key and the corresponding image verification certificate together into the image data integrity protection module.

[0192] Optionally, in one implementation, the image information verification application module running in the REE sends the image signature information and the image information to the server, including:

[0193] The image information verification application module running in the REE receives target information sent by the camera hardware abstraction layer module running in the REE through the client application module running in the camera frame layer in the REE. The target information includes image signature information.

[0194] The image information verification application module running in REE sends the target information to the server;

[0195] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0196] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0197] It should be noted that, in order to ensure that the server can successfully verify the digital signature information, the camera hardware abstraction layer module needs to send the information for verifying the digital signature information to the server side for each signature method.

[0198] Optionally, when the target information includes image information and parameter information used to generate the signature key, the specific implementation of the server verifying the image signature information includes:

[0199] Verify the validity of the server certificate based on the server's root certificate;

[0200] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0201] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0202] The validity of the image signature information is verified using the signature verification key.

[0203] Optionally, if the target information further includes image information and an image verification certificate, the specific implementation of the server verifying the image signature information includes:

[0204] Verify the validity of the server certificate based on the server's root certificate;

[0205] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0206] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0207] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0208] It should be noted that after verifying the validity of the image signature information, the server needs to process the image information. Optionally, the processing methods include: further verifying whether the image information meets the access requirements of the business according to the original business logic, such as whether the time and location of the image information are reasonable, whether the image information is taken for the business, whether the captured information is valid, and whether the biometric verification is successful.

[0209] Optionally, in one implementation, the server mentioned in this application embodiment may include: a mobile service server and a key management server; wherein, the mobile service module includes an improved image information verification service module for communicating with the image information verification application module on the electronic device side; the mobile device management server includes: a key management service module for supporting digital signature of image information, preventing image tampering, and identifying whether the image was taken by the claimed electronic device.

[0210] The specific implementation of this method is explained below.

[0211] It should be noted that, as shown in Figure 2, this implementation of the present application mainly involves the following functional modules:

[0212] The image information verification application module for electronic devices defines the required accuracy of the captured images and supports the transmission of image signature information.

[0213] The client application module of the camera frame layer of the electronic device sets camera configuration parameters and supports the transmission of image signature information.

[0214] An image data integrity protection module for electronic devices is used to support digital signatures of image information captured by cameras.

[0215] The key management module of the electronic device supports key management for signing image information captured by the camera, so as to prove to the digital signature verifier that the image information was captured by the claimed electronic device;

[0216] The trusted application module for device security assessment of electronic devices supports the assessment of the security status of electronic devices at any time, such as whether the device has been rooted.

[0217] The image verification auxiliary trusted application module of the electronic device communicates with various modules within the TEE to support the integrity protection of the original image data.

[0218] An improved image information verification service module in a mobile service server is used to support the verification of digital signatures of image information from electronic devices (the image information in this application embodiment includes at least image information captured by a camera and image preview data) to determine whether the image was taken by the claimed electronic device.

[0219] An improved key management service module in the mobile device management server supports digital signatures for image information, prevents image tampering, and identifies whether an image was taken by the claimed electronic device.

[0220] It should be noted that before proceeding with this implementation, initialization of information security and integrity protection based on edge virtualization is required, specifically including:

[0221] The following process is implemented on the electronic device side:

[0222] TEE generates a public / private key pair for the device, encrypts the device private key using the device root key (from the hardware root of trust), and then stores it securely.

[0223] Electronic devices securely send their public key (e.g., based on Transport Layer Security (TLS) or Hypertext Transfer Protocol Secure (HTTPS)) to the mobile device management server, generate a device certificate, and store it securely.

[0224] Electronic devices obtain server certificates and store them securely.

[0225] The key management service module of the mobile device management server implements the following process:

[0226] Generate a public / private key pair for the server and store the server private key in the Hardware Security Module (HSM);

[0227] Generate a server certificate based on the server's public key and send it to the electronic device.

[0228] The specific communication process of the above architecture is shown in Figure 3, and mainly includes:

[0229] As shown in Figure 3, the initialization process of information security integrity protection based on edge virtualization mainly includes:

[0230] Step 31: When the electronic device starts up, the TEE will securely deploy the relevant keys used for signing within the REE. Specifically, the signing key can be deployed to the image data integrity protection module in the following two ways:

[0231] Signature Key Configuration Scheme 1: The key management module generates a signature key (symmetric key) based on the server's public key, the device's public key, and the parameter information used to generate the signature key (such as random numbers, timestamps, etc.). Then, the signature key, the device certificate, and the parameter information used to generate the signature key are configured together in the image data integrity protection module.

[0232] Scheme 2 for signature key configuration: The TEE's key management module generates a public / private key pair (which can be called the image verification public / private key pair), uses the device's private key to digitally sign the image verification public key to generate an image verification certificate, and then configures the image verification private key and the corresponding image verification certificate together into the image data integrity protection module.

[0233] Step 32: Generate the equipment certificate;

[0234] Step 33: Before performing image information signing, the mobile business server and the mobile device management server will synchronize the relevant keys used for signing.

[0235] The specific communication process is shown in Figure 4, and mainly includes:

[0236] Step 401: The server's image information verification service module sends a camera usage request message to the REE image information verification application module of the electronic device, requesting the electronic device to take pictures of the required information (such as face, ID card, etc.) to provide image information for verification of the business.

[0237] Step 402: The image information verification application module of the REE of the electronic device sends a photo-taking request message to the client application module of the camera frame layer of the REE of the electronic device. The message contains (but is not limited to): the resolution of the image to be captured, the information to be captured, business information, etc.

[0238] Step 403: The client application module of the camera frame layer of the REE of the electronic device recognizes that the photo request message needs to verify the authenticity of the photo information of the electronic device, and requests the image verification auxiliary trusted application module of the TEE of the electronic device to verify the security status of the device.

[0239] Step 404: The image verification-assisted trusted application module of the electronic device's TEE obtains the device security status assessment result from the device security assessment trusted application module of the electronic device's TEE.

[0240] Step 405: The image verification auxiliary trusted application module of the electronic device's TEE returns the device security status assessment result to the client application module of the camera frame layer of the electronic device's REE.

[0241] Step 406: The client application module of the camera frame layer of the electronic device determines whether the electronic device is currently trustworthy based on the security status assessment result; if the electronic device is secure and trustworthy, it sends a request to take a picture message to the camera hardware abstraction layer module of the electronic device's REE. The message contains at least the camera parameters and business information corresponding to the required image resolution.

[0242] Step 407: The camera hardware abstraction layer module of the REE of the electronic device sends a photo capture request message to the camera driver module of the REE of the electronic device. The message contains at least the camera parameters defined in the previous step.

[0243] Step 408: The camera driver module of the REE of the electronic device obtains raw image data from the camera hardware module, which may also include preview data, etc.

[0244] Step 409: The camera driver module of the REE of the electronic device returns the raw image data to the camera hardware abstraction layer module of the REE of the electronic device.

[0245] Step 410: The image data integrity protection module of the camera hardware abstraction layer module of the electronic device performs digital signature on the image information, including the original image data and image attribute information. The signature key has been configured when the electronic device is started.

[0246] Step 411: The REE camera hardware abstraction layer module of the electronic device returns information to the client application module of the REE camera frame layer of the electronic device. The specific information returned is as follows:

[0247] For the first signature key configuration scheme, the message contains: image information, image signature information, other image information, device certificate, and parameter information used to generate the signature key (such as random number, timestamp, etc.);

[0248] For the second signature key configuration scheme, the message contains: image information, image signature information, other image information, device certificate, and image verification certificate;

[0249] Step 412: The client application module of the camera frame layer of the electronic device's REE returns image information and signature information to the image information verification application module of the electronic device's REE.

[0250] Step 413: The image information verification application module of the REE of the electronic device obtains some additional information (such as device information, service information, address information, etc.);

[0251] Step 414: The image information verification application module of the REE of the electronic device returns additional information, image information and corresponding signature information to the image information verification service module of the server. These returned information will be protected by existing security protocols (such as TLS, HTTPS), such as encrypting the message to prevent the information from being stolen during transmission and protecting the integrity of the message to prevent the information from being tampered with during transmission.

[0252] Step 415: After receiving the returned message, the server's image information verification service module performs verification and processing operations, specifically including the following operations:

[0253] Verification operation:

[0254] For the first signature key configuration scheme:

[0255] Verify the validity of the server certificate based on the server's root certificate;

[0256] Based on the server certificate, verify whether the device certificate (containing the device public key) is valid;

[0257] A signature verification key is generated based on the private key of the mobile service server, the public key of the device, and other parameters (such as random numbers, timestamps, etc.).

[0258] Based on the signature verification key, verify whether the image signature information is valid or has been tampered with.

[0259] For the second scheme of signature key configuration:

[0260] Verify the validity of the server certificate based on the server's root certificate;

[0261] Verify the validity of the device certificate based on the server certificate.

[0262] Based on the device certificate, verify whether the image verification certificate is valid;

[0263] Based on the image verification certificate, verify whether the image signature information is valid or has been tampered with.

[0264] Processing steps:

[0265] If the signature of the image information is valid or has not been tampered with, further verification is performed according to the original business logic to determine whether the image information meets the business access requirements, such as whether the time and location of the image shooting are reasonable, whether the image information was taken for the business, whether the certificate information is valid, and whether the biometric verification is successful.

[0266] I. Implementation method of A12

[0267] Optionally, in this case, in one implementation, the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, including:

[0268] Step 21: When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo-taking request message to the image information verification trusted application module running in the TEE.

[0269] Step 22: The image information verification trusted application module sends a photo request message to the trusted camera service module running in the TEE;

[0270] It should be noted that in this case, a trusted camera service module is added to the trusted camera driver module. Both the trusted camera service module and the trusted camera driver module are located in the TEE.

[0271] Step 23: The trusted camera service module calls the trusted camera driver module running in the TEE according to the photo-taking request message to initiate a photo-taking request;

[0272] Step 24: The trusted camera driver module calls the camera hardware module;

[0273] Step 25: The trusted application module for image information verification running in the TEE obtains image information;

[0274] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes, but is not limited to, at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0275] It should be noted that after the camera hardware module acquires image information, it usually stores the image information in memory. The trusted camera driver module feeds back the memory address where the image information is stored to the trusted image information verification trusted application module through the trusted camera service module. The trusted image information verification trusted application module can directly retrieve the image information from memory based on this memory address.

[0276] Further optionally, in one implementation, when the image information verification application module running in the REE determines that it needs to call the camera hardware module in a trusted environment, it transmits a photo-taking request message to the image information verification trusted application module running in the TEE, including:

[0277] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo request message through the client application module running in the camera frame layer of the REE.

[0278] It should be noted that the image information verification application module needs to identify the camera usage request message to determine whether it is necessary to call the camera hardware module in a trusted environment. If it is necessary to call the camera hardware module in a trusted environment, it needs to send a photo request message to the client application module of the camera framework layer. The client application module of the camera framework layer determines that it is necessary to take a photo in a trusted environment based on the photo request message, and then forwards the photo request message to the image information verification trusted application module.

[0279] It should be noted that the image information verification application module can determine whether it is necessary to call the camera hardware module in a trusted environment based on the business information of the camera. For example, it can predefine which businesses need to call the camera hardware module in a trusted environment. When the image information verification application module obtains the business information, it compares it with the predefined businesses. If it belongs to the predefined businesses, it determines that the business needs to call the camera hardware module in a trusted environment.

[0280] It should be noted that the implementation method of the image information verification application module in this application embodiment to determine whether it is necessary to call the camera hardware module in a trusted environment is merely an example. This application embodiment is not limited to the above-described implementation method. Other implementation methods that can determine whether it is necessary to call the camera hardware module in a trusted environment are also within the protection scope of this application embodiment.

[0281] The photo request message includes at least one of the following:

[0282] A11. Image resolution information;

[0283] A12. Instructions for taking photos in a trusted environment;

[0284] It should be noted that taking photos in a trusted environment can be understood as taking photos using the hardware isolation method of TEE. Under this condition, no application on the REE side can tamper with the information captured by the camera.

[0285] A13. Information that needs to be photographed;

[0286] It should be noted that the information that needs to be photographed includes, but is not limited to, the user's facial features and ID photo.

[0287] A14. Business Information;

[0288] Optionally, this business information includes, but is not limited to, business name and business attributes.

[0289] Optionally, in one implementation, when the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, the target module digitally signs the image information to obtain image signature information, including:

[0290] The image data signature application module receives a signature request message sent by the image information verification trusted application module running in the TEE. The signature request message includes a hash value obtained based on the image information. The image data signature application module runs in the TEE and / or in a Secure Element (SE).

[0291] The image data signature application module digitally signs the hash value using the device private key to obtain image signature information;

[0292] The image data signature application module sends the image signature information to the image information verification trusted application module.

[0293] It should be noted that by digitally signing the hash value through the image data signature application module running in the TEE and / or SE, the server can verify whether the sent image information has been tampered with, thus ensuring the reliability of the sent information.

[0294] Optionally, in one implementation, the image data signature application module includes a key management module, which runs in a TEE or SE. Optionally, in another implementation, in one case, the image data signature application module includes a key management trusted application module and a key management module, both of which run in a TEE or SE; in another case, the key management trusted application module runs in a TEE, and the key management module runs in an SE. Optionally, in this case, the specific implementation of the image data signature application module running in the target object digitally signing the hash value using the device private key to obtain image signature information includes:

[0295] The trusted application module for key management sends the signature request message to the key management module;

[0296] The key management module digitally signs the hash value based on the device's private key to obtain image signature information.

[0297] It should be noted that when the key management trusted application module and the key management module are running in different environments, the key management module running in the SE needs to digitally sign the hash value.

[0298] Optionally, in one implementation, the image information verification application module running in the REE sends the image signature information and the image information to the server, including:

[0299] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0300] The image information verification application module running in REE sends image signature information and image information to the server.

[0301] Further optionally, in one implementation, the image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE, including:

[0302] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE through the client application module running in the camera frame layer of the REE.

[0303] It should be noted that after obtaining the image signature information, the image information verification trusted application module needs to first send the signature information and image information to the client application module of the camera frame layer. The client application module then sends the signature information and image information to the image information verification application module, which in turn sends them to the server. Optionally, the image information verification application module can also obtain some additional information (such as device information, service information, address information, etc.) and send this additional information along with the signature information and image information to the server. It should also be noted that the information sent by the image information verification application module to the server needs to be protected by existing security protocols (such as Transport Layer Security (TLS) and Hypertext Transfer Protocol Secure (HTTPS)). This includes encrypting the message to prevent it from being stolen during transmission and protecting its integrity to prevent it from being tampered with during transmission.

[0304] Optionally, after receiving the information sent by the image information verification application module, the server needs to verify the image signature information, and after the verification is successful, process the image information.

[0305] Optionally, in one implementation, the specific implementation of the server verifying the image signature information includes:

[0306] Verify the validity of the server certificate based on the server's root certificate;

[0307] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0308] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0309] It should be noted that after verifying the validity of the signature, the server needs to process the image information. Optionally, the processing methods include: further verifying whether the image information meets the access requirements of the business according to the original business logic, such as whether the time and location of the image information are reasonable, whether the image information is taken for the business, whether the captured information is valid, and whether the biometric verification is successful.

[0310] Optionally, in one implementation, the server mentioned in this application embodiment may include: a mobile service server and a mobile device management server; wherein, the mobile service server includes an improved image information verification service module for communicating with the image information verification application module on the electronic device side; the mobile device management server includes: a certificate management module for generating a server public / private key pair, storing the server private key in a hardware security module (HSM), and generating a server certificate based on the server public key and sending it to the electronic device.

[0311] It should be noted that this application scenario involves driving the camera hardware module to take pictures in a hardware-isolated manner via a TEE; and then processing the captured image information in a virtualized environment using software isolation (such as face detection / interactive judgment, ID photo area selection, compression, etc.); finally, digitally signing the processed image information based on the TEE's key management; and finally, sending the image information and its digital signature together to the server. Any tampering during image information transmission will cause the digital signature verification on the server to fail, thus achieving security protection for the entire link of image information acquisition by the electronic device, namely, ensuring the integrity and security of the entire process from trusted camera driving to obtaining trusted image information and finally transmitting it to the server.

[0312] The specific implementation of the embodiments of this application is described below.

[0313] It should be noted that, as shown in Figure 5, this implementation method mainly involves the following functional modules:

[0314] The image information verification application module for electronic devices defines the required accuracy of the captured images and supports the transmission of image signature information.

[0315] The client application module of the camera frame layer of electronic devices sets camera configuration parameters and supports the transmission of image signature information;

[0316] The trusted camera service module and trusted camera driver module of the electronic device support driving the camera to take pictures in a hardware isolated manner. In this case, no application on the REE side has the right to access camera resources, thereby reducing the attack of malicious applications on the REE side when taking pictures.

[0317] The image information verification trusted application module of the electronic device communicates with other modules of the TEE and supports hardware isolation for capturing images and digital signature and other related operations.

[0318] The image data signature application module for electronic devices supports digital signatures of image information to prove to the digital signature verifier that the image information was taken by the claimed electronic device.

[0319] The improved image information verification service module of the mobile business server supports the verification of digital signatures of image information from electronic devices to determine whether the image was taken by the claimed electronic device.

[0320] The certificate management module in the mobile device management server is used to support digital signatures of image information, prevent image tampering, and identify whether the image was taken by the claimed electronic device.

[0321] The specific communication process is shown in Figure 6, and mainly includes:

[0322] Step 601: The server's image information verification service module sends a camera usage request message to the REE image information verification application module of the electronic device, requesting the electronic device to take pictures of the required information (such as face, ID card, etc.) to provide image information for verification of the business.

[0323] Step 602: The image information verification application module of the REE of the electronic device recognizes that the photo needs to be taken in a trusted environment and forwards the photo request message to the client application module of the camera frame layer of the REE of the electronic device. The message contains (but is not limited to): the required image resolution, instructions to take the photo in a trusted environment (i.e., the hardware isolation method of the TEE, under which no application on the REE side can tamper with the information captured by the camera), the information to be captured, business information, etc.

[0324] Step 603: The client application module of the camera frame layer of the REE of the electronic device recognizes that the photo-taking request message needs to be processed in a trusted environment, and forwards the photo-taking request message to the image information verification trusted application module of the TEE of the electronic device. The message contains at least the camera parameters and business information corresponding to the required image resolution.

[0325] Step 604: The image information verification trusted application module of the electronic device's TEE sends a photo request message to the trusted camera service module of the electronic device's TEE. The message contains at least the camera parameters defined in the previous step.

[0326] Step 605: The trusted camera service module of the electronic device's TEE sends a photo request message to the trusted camera driver module of the electronic device's TEE. The message contains at least the camera parameters defined in the previous step.

[0327] Step 606: The trusted camera driver module of the TEE of the electronic device enables the hardware camera function and takes pictures of the required information in a hardware-isolated manner according to the received camera parameters. In this step, a lot of interactive information is omitted, such as liveness detection and face comparison when facial recognition is performed, and verification of the shooting range and clarity of the ID photo when taking ID photos.

[0328] Step 607: The trusted camera driver module of the electronic device's TEE returns the captured image information (such as image data and preview data acquired by the camera) to the trusted camera service module of the electronic device's TEE.

[0329] Step 608: The trusted camera service module of the electronic device's TEE returns the original image data to the trusted application module for image information verification of the electronic device's TEE.

[0330] Step 609: The image information verification trusted application module of the electronic device's TEE processes the obtained raw image data, such as obtaining the time and location of the image capture, and then performs a hash calculation on the image information that needs to be returned to the server, including the raw image data and image attribute information (such as the time and location of the capture, device information (such as the operating system (OS) version, device model, etc.), and the business information of this access (such as name, attributes, etc.)) to obtain a hash value.

[0331] Step 610: The trusted application module for verifying the image information of the electronic device's TEE sends a signature request message to the image data signature application module of the electronic device's TEE. This message contains the hash value calculated in the previous step.

[0332] Step 611: The image data signature application module of the electronic device's TEE uses the device's private key to digitally sign the hash value;

[0333] Step 612: The image data signature application module of the electronic device's TEE returns image signature information to the trusted application module for image information verification of the electronic device's TEE.

[0334] Step 613: The image information verification trusted application module of the electronic device's TEE returns image information and corresponding image signature information to the client application module of the camera frame layer of the electronic device's REE.

[0335] Step 614: The client application module of the camera frame layer of the electronic device's REE returns image information and corresponding image signature information to the image information verification application module of the electronic device's REE.

[0336] Step 615: The image information verification application module of the REE of the electronic device obtains some additional information (such as device information, service information, address information, etc.);

[0337] Step 616: The image information verification application module of the REE of the electronic device returns additional information, image information and corresponding image signature information to the image information verification service module of the server. These returned information will be protected for integrity according to existing security protocols (such as TLS, HTTPS), such as encrypting the message to prevent the information from being stolen during transmission and protecting the integrity of the message to prevent the information from being tampered with during transmission.

[0338] Step 617: After receiving the returned message, the server's image information verification service module performs verification and processing operations, specifically including the following operations:

[0339] Verify the validity of the server certificate based on the server's root certificate;

[0340] Verify the validity of the device certificate based on the server certificate.

[0341] Based on the device certificate, verify whether the image signature information of the image information is valid or has been tampered with;

[0342] If the image signature information is valid or has not been tampered with, further verification is performed based on the original business logic to determine whether the image information meets the business's access requirements, such as whether the time and location of the image shooting are reasonable, whether the image information was taken for the specific business, whether the identification information is valid, and whether the biometric verification was successful.

[0343] It should be noted that cloud service providers currently invest significant resources in developing mobile applications and deploying them on electronic devices to verify the authenticity of images captured by these devices. However, since images captured by cameras can be tampered with or replaced at levels below the application layer (such as the framework, system kernel, and hardware layer) on the electronic device side, cloud service providers expect electronic device manufacturers to provide end-to-end integrity protection for image information. This application proposes two possible solutions to improve the integrity protection capabilities of image information captured by electronic devices, given the limited capabilities of electronic devices. This aims to enhance the accuracy of image information verification and save costs for cloud service providers.

[0344] As shown in Figure 7, at least one embodiment of this application also provides a method for secure transmission of image information, including:

[0345] Step 701: Send a camera usage request message to the electronic device;

[0346] Step 702: Receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0347] Step 703: Verify the image signature information;

[0348] Step 704: After verification, the image information is processed.

[0349] Optionally, verifying the image signature information includes:

[0350] Verify the validity of the server certificate based on the server's root certificate;

[0351] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0352] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0353] Optionally, receiving image signature information and image information fed back by the image information verification application module running in the REE of the electronic device includes:

[0354] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0355] The target information further includes: image information and parameter information used to generate the signature key; or

[0356] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0357] Optionally, if the target information further includes image information and parameter information used to generate the signature key, then verifying the image signature information includes:

[0358] Verify the validity of the server certificate based on the server's root certificate;

[0359] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0360] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0361] The validity of the image signature information is verified using the signature verification key.

[0362] Optionally, if the target information further includes image information and an image verification certificate, then verifying the image signature information includes:

[0363] Verify the validity of the server certificate based on the server's root certificate;

[0364] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0365] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0366] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0367] It should be noted that all server-side descriptions in the above embodiments are applicable to embodiments of the image information security transmission method applied to the server, and can achieve the same technical effect, so they will not be repeated here.

[0368] As shown in Figure 8, at least one embodiment of this application also provides an image information secure transmission device, applied to an electronic device, wherein the electronic device is equipped with an REE; the device includes:

[0369] The image information verification application module 801 runs in REE and is used to call the camera hardware module to obtain image information based on the camera usage request message sent by the server.

[0370] Target module 802 is used to digitally sign the image information and obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0371] The image information verification application module 801 is also used to send the image signature information and the image information to the server.

[0372] Optionally, the image information verification application module is configured to implement at least one of the following:

[0373] When the electronic device is trusted, the image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message;

[0374] The image information verification application module running in REE calls the trusted camera driver module to obtain image information.

[0375] Optionally, when the image information verification application module running in the REE is trusted by the electronic device, and calls the camera hardware module to obtain image information according to the camera usage request message, the image information verification application module is further configured to: send the camera usage request message to the client application module running in the camera frame layer of the REE.

[0376] The client application module is used to send a verification request to the image verification auxiliary trusted application module running in the TEE when it is determined, based on the camera usage request message, that the authenticity of the image acquired by the camera hardware module needs to be verified.

[0377] The image verification-assisted trusted application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0378] Optionally, the image information verification application module is further configured to:

[0379] When the electronic device is trusted, based on the camera usage request message, the client application module running in the camera frame layer of the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE.

[0380] The camera hardware abstraction layer module, which runs in the REE, is used to send photo request messages to the camera driver module running in the REE.

[0381] A camera driver module, used to call the camera hardware module;

[0382] The camera hardware abstraction layer module is also used to acquire image information;

[0383] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0384] Optionally, when the image information verification application module running in the REE, under the condition that the electronic device is trusted, calls the camera hardware module to obtain image information according to the camera usage request message, the image information verification application module is further configured to:

[0385] The system receives target information sent by the camera hardware abstraction layer module running in the REE and the client application module running in the camera frame layer of the REE. The target information includes image signature information.

[0386] Send the target information to the server;

[0387] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0388] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0389] Optionally, the image information verification application module is further configured to: when it is determined that the camera hardware module needs to be invoked in a trusted environment, transmit a photo-taking request message to the image information verification trusted application module running in the TEE;

[0390] The image information verification trusted application module is used to send a photo request message to the trusted camera service module running in the TEE;

[0391] The trusted camera service module is used to call the trusted camera driver module running in the TEE according to the photo request message to initiate a photo request.

[0392] A trusted camera driver module is used to call the camera hardware module;

[0393] The image information verification trusted application module is also used to acquire image information;

[0394] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0395] Optionally, the image information verification application module is further configured to: send a photo request message through a client application module running in the camera frame layer of the REE when it is determined that the camera hardware module needs to be invoked in a trusted environment;

[0396] The photo request message includes at least one of the following:

[0397] Precision information of the captured image;

[0398] Instructions for taking photos in a trusted environment;

[0399] Information that needs to be photographed;

[0400] Business information.

[0401] Optionally, when the image information verification application module running in the REE calls the trusted camera driver module to obtain image information, the image data signature application module is used to:

[0402] Receive a signature request message sent by the image information verification trusted application module running in the TEE, the signature request message including: a hash value obtained based on the image information, the image data signature application module running in the TEE and / or the security unit SE;

[0403] The hash value is digitally signed using the device's private key to obtain image signature information;

[0404] The image signature information is sent to the image information verification trusted application module.

[0405] Optionally, the image information verification application module is used for:

[0406] Receive the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0407] Send image signature information and image information to the server.

[0408] Optionally, the image information verification application module is used for:

[0409] The client application module running in the camera frame layer of the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE.

[0410] It should be noted that this device embodiment corresponds to the above method, and all implementation methods in the above method embodiment are applicable to this device embodiment and can achieve the same technical effect.

[0411] The image information secure transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG1 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0412] This application embodiment also provides an electronic device, the electronic device having an REE deployed thereon; including a processor and a communication interface, the processor being used for:

[0413] The image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server;

[0414] The target module performs a digital signature on the image information to obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0415] The image information verification application module running in REE sends the image signature information and the image information to the server.

[0416] Optionally, the processor is configured to implement at least one of the following:

[0417] The image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server, including at least one of the following:

[0418] When the electronic device is trusted, the image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message;

[0419] The image information verification application module running in REE calls the trusted camera driver module to obtain image information.

[0420] Optionally, when the image information verification application module running in the REE, based on the camera usage request message, calls the camera hardware module to obtain image information, provided that the electronic device is trusted, the communication interface is used for:

[0421] The image information verification application module running in REE sends the camera usage request message to the client application module running in the camera frame layer of REE;

[0422] If the client application module determines that the authenticity of the image acquired by the camera hardware module needs to be verified based on the camera usage request message, it sends a verification request to the image verification auxiliary trusted application module running in the TEE.

[0423] The client application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE through the image verification assisted trusted application module. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0424] Optionally, the communication interface is used for:

[0425] When the electronic device is trusted, the image information verification application module running in the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE through the client application module running in the camera framework layer of the REE, based on the camera usage request message.

[0426] The camera hardware abstraction layer module running in the REE sends a photo request message to the camera driver module running in the REE;

[0427] The camera driver module calls the camera hardware module;

[0428] The camera hardware abstraction layer module running in REE acquires image information;

[0429] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0430] Optionally, when the image information verification application module running in the REE, based on the camera usage request message, calls the camera hardware module to obtain image information, provided that the electronic device is trusted, the communication interface is used for:

[0431] The image information verification application module running in the REE receives target information sent by the camera hardware abstraction layer module running in the REE through the client application module running in the camera frame layer in the REE. The target information includes image signature information.

[0432] The image information verification application module running in REE sends the target information to the server;

[0433] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0434] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0435] Optionally, the communication interface is used for:

[0436] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo-taking request message to the image information verification trusted application module running in the TEE.

[0437] The image information verification trusted application module sends a photo request message to the trusted camera service module running in the TEE;

[0438] The trusted camera service module calls the trusted camera driver module running in the TEE according to the photo-taking request message to initiate a photo-taking request;

[0439] The trusted camera driver module calls the camera hardware module;

[0440] The image information verification trusted application module running in the TEE obtains image information;

[0441] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0442] Optionally, the communication interface is used for:

[0443] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo request message through the client application module running in the camera frame layer of the REE.

[0444] The photo request message includes at least one of the following:

[0445] Precision information of the captured image;

[0446] Instructions for taking photos in a trusted environment;

[0447] Information that needs to be photographed;

[0448] Business information.

[0449] Optionally, the communication interface is used for:

[0450] The image data signature application module receives a signature request message sent by the image information verification trusted application module running in the TEE. The signature request message includes a hash value obtained based on the image information. The image data signature application module runs in the TEE and / or the security unit SE.

[0451] The processor is used by the image data signature application module to digitally sign the hash value using the device private key to obtain image signature information.

[0452] The image data signature application module sends the image signature information to the image information verification trusted application module.

[0453] Optionally, the communication interface is used for:

[0454] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0455] The image information verification application module running in REE sends image signature information and image information to the server.

[0456] Optionally, the communication interface is used for:

[0457] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE through the client application module running in the camera frame layer of the REE.

[0458] Preferably, this application embodiment also provides an electronic device, which deploys a virtual machine and a target object. The target object includes a TEE and / or SE, and includes a processor, a memory, and a program or instructions stored in the memory and executable on the processor. When the program or instructions are executed by the processor, they implement the various processes of the above-described monitoring method embodiment and achieve the same technical effect. The terminal can be the image information security transmission device shown in FIG8. Specifically, FIG9 is a schematic diagram of the hardware structure of an electronic device implementing an embodiment of this application.

[0459] The electronic device 900 includes, but is not limited to, at least some of the following components: a radio frequency unit 901, a network module 902, an audio output unit 903, an input unit 904, a sensor 905, a display unit 906, a user input unit 907, an interface unit 908, a memory 909, and a processor 910.

[0460] Those skilled in the art will understand that the electronic device 900 may also include a power supply (such as a battery) for powering various components. The power supply can be logically connected to the processor 910 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system. The electronic device structure shown in Figure 9 does not constitute a limitation on the electronic device. The electronic device may include more or fewer components than shown, or combine certain components, or have different component arrangements, which will not be elaborated here.

[0461] It should be understood that, in this embodiment, the input unit 904 may include a graphics processor 9041 and a microphone 9042. The graphics processor 9041 processes image data of still images or videos obtained by an image capture device (such as a camera) in video capture mode or image capture mode. The display unit 906 may include a display panel 9061, which may be configured in the form of a liquid crystal display, an organic light-emitting diode, or the like. The user input unit 907 includes at least one of a touch panel 9071 and other input devices 9072. The touch panel 9071 is also called a touch screen. The touch panel 9071 may include two parts: a touch detection device and a touch controller. Other input devices 9072 may include, but are not limited to, physical keyboards, function keys (such as volume control buttons, power buttons, etc.), trackballs, mice, and joysticks, which will not be described in detail here.

[0462] In this embodiment, after receiving downlink data from the access network device, the radio frequency unit 901 can transmit it to the processor 910 for processing; in addition, the radio frequency unit 901 can send uplink data to the network-side device. Typically, the radio frequency unit 901 includes, but is not limited to, antennas, amplifiers, transceivers, couplers, low-noise amplifiers, duplexers, etc.

[0463] The memory 909 can be used to store software programs or instructions, as well as various data. The memory 909 may primarily include a first storage area for storing programs or instructions and a second storage area for storing data. The first storage area may store the operating system, application programs or instructions required for at least one function (such as sound playback, image playback, etc.). Furthermore, the memory 909 may include volatile memory or non-volatile memory, or both. The non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory can be random access memory (RAM), static random access memory (SRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM), and direct memory bus RAM (DRRAM). The memory 909 in the embodiments of this application includes, but is not limited to, these and any other suitable types of memory.

[0464] Processor 910 may include one or more processing units; optionally, processor 910 integrates an application processor and a modem processor, wherein the application processor mainly handles operations involving the operating system, user interface, and applications, and the modem processor mainly handles wireless communication signals, such as a baseband processor. It is understood that the aforementioned modem processor may also not be integrated into processor 910.

[0465] The processor is used for:

[0466] The image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server;

[0467] The target module performs a digital signature on the image information to obtain image signature information. The target module includes an image data integrity protection module in the camera hardware abstraction layer module running in the REE or an image data signature application module running in the Trusted Execution Environment (TEE).

[0468] The image information verification application module running in REE sends the image signature information and the image information to the server.

[0469] Optionally, the processor is configured to implement at least one of the following:

[0470] The image information verification application module running in the REE calls the camera hardware module to obtain image information based on the camera usage request message sent by the server, including at least one of the following:

[0471] When the electronic device is trusted, the image information verification application module running in REE calls the camera hardware module to obtain image information based on the camera usage request message;

[0472] The image information verification application module running in REE calls the trusted camera driver module to obtain image information.

[0473] Optionally, when the image information verification application module running in the REE, based on the camera usage request message, calls the camera hardware module to obtain image information, provided that the electronic device is trusted, the communication interface is used for:

[0474] The image information verification application module running in REE sends the camera usage request message to the client application module running in the camera frame layer of REE;

[0475] If the client application module determines that the authenticity of the image acquired by the camera hardware module needs to be verified based on the camera usage request message, it sends a verification request to the image verification auxiliary trusted application module running in the TEE.

[0476] The client application module obtains the device security status assessment result from the device security assessment trusted application module running in the TEE through the image verification assisted trusted application module. The device security status assessment result is used to indicate whether the electronic device is trusted or untrustworthy.

[0477] Optionally, the communication interface is used for:

[0478] When the electronic device is trusted, the image information verification application module running in the REE sends a photo-taking request message to the camera hardware abstraction layer module running in the REE through the client application module running in the camera framework layer of the REE, based on the camera usage request message.

[0479] The camera hardware abstraction layer module running in the REE sends a photo request message to the camera driver module running in the REE;

[0480] The camera driver module calls the camera hardware module;

[0481] The camera hardware abstraction layer module running in REE acquires image information;

[0482] The image information includes: the raw image data acquired by the camera hardware module and the image attribute information generated by the camera hardware abstraction layer module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0483] Optionally, when the image information verification application module running in the REE, based on the camera usage request message, calls the camera hardware module to obtain image information, provided that the electronic device is trusted, the communication interface is used for:

[0484] The image information verification application module running in the REE receives target information sent by the camera hardware abstraction layer module running in the REE through the client application module running in the camera frame layer in the REE. The target information includes image signature information.

[0485] The image information verification application module running in REE sends the target information to the server;

[0486] Wherein, when the image data integrity protection module digitally signs the image information using a signature key, the target information further includes: image information and parameter information used to generate the signature key; or

[0487] When the image data integrity protection module uses the image verification private key for digital signature, the target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0488] Optionally, the communication interface is used for:

[0489] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo-taking request message to the image information verification trusted application module running in the TEE.

[0490] The image information verification trusted application module sends a photo request message to the trusted camera service module running in the TEE;

[0491] The trusted camera service module calls the trusted camera driver module running in the TEE according to the photo-taking request message to initiate a photo-taking request;

[0492] The trusted camera driver module calls the camera hardware module;

[0493] The image information verification trusted application module running in the TEE obtains image information;

[0494] The image information includes: the original image data collected by the camera hardware module and the image attribute information generated by the image information verification trusted application module. The image attribute information includes at least one of the following: the name of the service that triggered the shooting, the shooting location, the shooting time, and the shooting device model.

[0495] Optionally, the communication interface is used for:

[0496] When the image information verification application module running in the REE determines that it is necessary to call the camera hardware module in a trusted environment, it sends a photo request message through the client application module running in the camera frame layer of the REE.

[0497] The photo request message includes at least one of the following:

[0498] Precision information of the captured image;

[0499] Instructions for taking photos in a trusted environment;

[0500] Information that needs to be photographed;

[0501] Business information.

[0502] Optionally, the communication interface is used for:

[0503] The image data signature application module receives a signature request message sent by the image information verification trusted application module running in the TEE. The signature request message includes a hash value obtained based on the image information. The image data signature application module runs in the TEE and / or the security unit SE.

[0504] The processor is used by the image data signature application module to digitally sign the hash value using the device private key to obtain image signature information.

[0505] The image data signature application module sends the image signature information to the image information verification trusted application module.

[0506] Optionally, the communication interface is used for:

[0507] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE;

[0508] The image information verification application module running in REE sends image signature information and image information to the server.

[0509] Optionally, the communication interface is used for:

[0510] The image information verification application module running in the REE receives the image signature information and image information sent by the image information verification trusted application module running in the TEE through the client application module running in the camera frame layer of the REE.

[0511] As shown in Figure 10, at least one embodiment of this application also provides an image information secure transmission device, comprising:

[0512] The sending module 1001 is used to send a camera usage request message to the electronic device;

[0513] The receiving module 1002 is used to receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0514] Verification module 1003 is used to verify the image signature information;

[0515] The processing module 1004 is used to process the image information after the verification is passed.

[0516] Optionally, the verification module 1003 is used for:

[0517] Verify the validity of the server certificate based on the server's root certificate;

[0518] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0519] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0520] Optionally, the receiving module 1002 is configured to:

[0521] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0522] The target information further includes: image information and parameter information used to generate the signature key; or

[0523] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0524] Optionally, if the target information further includes image information and parameter information used to generate the signature key, the verification module 1003 is used to:

[0525] Verify the validity of the server certificate based on the server's root certificate;

[0526] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0527] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0528] The validity of the image signature information is verified using the signature verification key.

[0529] Optionally, if the target information further includes image information and an image verification certificate, the verification module 1003 is used to:

[0530] Verify the validity of the server certificate based on the server's root certificate;

[0531] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0532] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0533] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0534] It should be noted that this device embodiment corresponds to the above method, and all implementation methods in the above method embodiment are applicable to this device embodiment and can achieve the same technical effect.

[0535] The image information secure transmission device provided in this application embodiment can implement the various processes implemented in the method embodiment of FIG7 and achieve the same technical effect. To avoid repetition, it will not be described again here.

[0536] This application embodiment also provides a server, including a processor and a communication interface, wherein the communication interface is used for:

[0537] Send a camera usage request message to the electronic device;

[0538] Receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0539] The processor is used to verify the image signature information;

[0540] After successful verification, the image information is processed.

[0541] Optionally, the processor is configured to:

[0542] Verify the validity of the server certificate based on the server's root certificate;

[0543] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0544] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0545] Optionally, the communication interface is used for:

[0546] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0547] The target information further includes: image information and parameter information used to generate the signature key; or

[0548] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0549] Optionally, if the target information further includes image information and parameter information used to generate the signature key, the processor is configured to:

[0550] Verify the validity of the server certificate based on the server's root certificate;

[0551] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0552] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0553] The validity of the image signature information is verified using the signature verification key.

[0554] Optionally, if the target information further includes image information and an image verification certificate, the processor is configured to:

[0555] Verify the validity of the server certificate based on the server's root certificate;

[0556] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0557] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0558] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0559] As shown in Figure 11, this application embodiment also provides a server, including a processor 1100, a transceiver 1110, a memory 1120, and a program stored in the memory 1120 and executable on the processor 1100; wherein, the transceiver 1110 is connected to the processor 1100 and the memory 1120 through a bus interface, and the transceiver 1110 is used to receive and send data under the control of the processor 1100.

[0560] In Figure 11, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 1100 and memory represented by memory 1120. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 1110 may be multiple components, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, user interface 1130 may also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.

[0561] The processor 1100 is responsible for managing the bus architecture and general processing, and the memory 1120 can store the data used by the processor 1100 when performing operations.

[0562] Optionally, the processor 1100 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.

[0563] The processor executes any of the methods described in the embodiments of this application according to the obtained executable instructions by calling a computer program stored in memory. The processor and memory may also be physically separated.

[0564] The processor is configured to read the computer program from the memory and perform the following operations:

[0565] Send a camera usage request message to the electronic device;

[0566] Receive image signature information and image information fed back by the image information verification application module running in the REE of the electronic device;

[0567] The image signature information is verified;

[0568] After successful verification, the image information is processed.

[0569] Optionally, the processor is configured to read the computer program in the memory and perform the following operations:

[0570] Verify the validity of the server certificate based on the server's root certificate;

[0571] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0572] If the device certificate is valid, verify the validity of the image signature information based on the device certificate.

[0573] Optionally, the processor is configured to read the computer program in the memory and perform the following operations:

[0574] The system receives target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information;

[0575] The target information further includes: image information and parameter information used to generate the signature key; or

[0576] The target information also includes: image information and image verification certificate, wherein the image verification certificate is generated by digitally signing the image verification public key based on the device private key.

[0577] Optionally, if the target information further includes image information and parameter information used to generate the signature key, the processor is configured to read the computer program in the memory and perform the following operations:

[0578] Verify the validity of the server certificate based on the server's root certificate;

[0579] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0580] If the device certificate is valid, a signature verification key is generated based on the server private key, the device public key, and the parameter information.

[0581] The validity of the image signature information is verified using the signature verification key.

[0582] Optionally, if the target information further includes image information and an image verification certificate, the processor is configured to read the computer program in the memory and perform the following operations:

[0583] Verify the validity of the server certificate based on the server's root certificate;

[0584] If the server certificate is valid, verify the validity of the device certificate based on the server certificate.

[0585] If the device certificate is valid, verify the validity of the image verification certificate based on the device certificate.

[0586] If the image verification certificate is valid, verify the validity of the image signature information based on the image verification certificate.

[0587] This application also provides a readable storage medium storing a program or instructions. When the program or instructions are executed by a processor, they implement the various processes of the above-described image information secure transmission method embodiments and achieve the same technical effects. To avoid repetition, they will not be described again here.

[0588] The readable storage medium can be non-volatile or non-transient. The readable storage medium can include computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0589] This application also provides a computer program / program product, which is stored in a storage medium and executed by at least one processor to implement the various processes of the above-described image information secure transmission method embodiments, and can achieve the same technical effect. To avoid repetition, it will not be described again here.

[0590] The embodiments of this application have been described above with reference to the accompanying drawings. However, this application is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make many other forms under the guidance of this application without departing from the spirit and scope of the claims, and all of these forms are within the protection scope of this application.

Claims

1. An image information secure transmission method applied to an electronic device, wherein the electronic device is deployed with a general-purpose execution environment (REE); the method comprises: an image information verification application module running in the REE calling a camera hardware module to obtain image information according to a camera use request message sent by a server; a target module performing digital signature on the image information to obtain image signature information, wherein the target module comprises an image data integrity protection module running in a camera hardware abstraction layer module in the REE or an image data signature application module running in a trusted execution environment (TEE); the image information verification application module running in the REE sending the image signature information and the image information to the server.

2. The method of claim 1, wherein, The image information verification application module running in the REE calling the camera hardware module to obtain image information according to a camera use request message sent by a server comprises at least one of the following: The image information verification application module running in the REE calling the camera hardware module to obtain image information according to the camera use request message in the case that the electronic device is trusted. The image information verification application module running in the REE calling a trusted camera driver module to obtain image information.

3. The method of claim 2, wherein, In the case that the image information verification application module running in the REE calls the camera hardware module to obtain image information according to the camera use request message in the case that the electronic device is trusted, the method further comprises: The image information verification application module running in the REE sending the camera use request message to a client application module running in a camera framework layer in the REE; The client application module sending a verification request to an image verification auxiliary trusted application module running in the TEE in the case that the client application module determines that the authenticity of image collected by the camera hardware module needs to be verified according to the camera use request message; The client application module obtaining a device security state evaluation result from a device security evaluation trusted application module running in the TEE through the image verification auxiliary trusted application module, wherein the device security state evaluation result is used to indicate that the electronic device is trusted or untrusted.

4. The method of claim 2 or 3, wherein, The image information verification application module running in the REE calling the camera hardware module to obtain image information according to the camera use request message in the case that the electronic device is trusted comprises: The image information verification application module running in the REE sending a photograph request message to a camera hardware abstraction layer module running in the REE through a client application module running in a camera framework layer in the REE according to the camera use request message in the case that the electronic device is trusted; The camera hardware abstraction layer module running in the REE sending the photograph request message to a camera driver module running in the REE; The camera driver module calling the camera hardware module; The camera hardware abstraction layer module running in the REE obtaining image information; The image information includes image original data collected by the camera hardware module and image attribute information generated by the camera hardware abstraction layer module, and the image attribute information includes at least one of a service name triggering photographing, a photographing position, a photographing time, and a photographing device model.

5. The method according to any one of claims 2-4, wherein, In a case where the image information verification application module running in the REE calls the camera hardware module to obtain image information according to the camera use request message in a case where the electronic device is trusted, the image information verification application module running in the REE sends the image signature information and the image information to the server, and the sending includes: The image information verification application module running in the REE receives target information sent by a client application module running in the camera framework layer of the REE through the camera hardware abstraction layer module running in the REE, and the target information includes image signature information. The image information verification application module running in the REE sends the target information to the server. In a case where the image data integrity protection module digitally signs the image information by using a signature key, the target information further includes image information and parameter information used to generate the signature key; or In a case where the image data integrity protection module digitally signs by using an image verification private key, the target information further includes image information and an image verification certificate, and the image verification certificate is generated by digitally signing an image verification public key based on a device private key.

6. The method of claim 2, wherein, The image information verification application module running in the REE calls the trusted camera driver module to obtain image information, and the obtaining includes: The image information verification application module running in the REE delivers a photographing request message to the image information verification trusted application module running in the TEE in a case where it is determined that the camera hardware module needs to be called in a trusted environment. The image information verification trusted application module running in the TEE sends the photographing request message to the trusted camera service module running in the TEE. The trusted camera service module calls the trusted camera driver module running in the TEE according to the photographing request message, and initiates a photographing request. The trusted camera driver module calls the camera hardware module. The image information verification trusted application module running in the TEE obtains image information. The image information includes image original data collected by the camera hardware module and image attribute information generated by the image information verification trusted application module, and the image attribute information includes at least one of a service name triggering photographing, a photographing position, a photographing time, and a photographing device model.

7. The method of claim 6, wherein, The image information verification application module running in the REE delivers a photographing request message to the image information verification trusted application module running in the TEE in a case where it is determined that the camera hardware module needs to be called in a trusted environment, and the delivering includes: The image information verification application module running in the REE sends the photographing request message through a client application module running in the camera framework layer of the REE in a case where it is determined that the camera hardware module needs to be called in a trusted environment. The photographing request message includes at least one of the following: precision information of the photographed image; indication information of photographing in a trusted environment; information that needs to be photographed; service information.

8. The method of claim 2, 6, or 7, wherein, In a case where an image information verification application module running in the REE invokes a trusted camera driver module to obtain image information, the target module digitally signs the image information to obtain image signature information, including: The image data signature application module receives a signature request message sent by the image information verification trusted application module running in the TEE, and the signature request message includes a hash value obtained based on the image information. The image data signature application module runs in the TEE and / or a secure element (SE); The image data signature application module digitally signs the hash value using a device private key to obtain image signature information; The image data signature application module sends the image signature information to the image information verification trusted application module.

9. The method of claim 1 or 8, wherein, The image information verification application module running in the REE sends the image signature information and the image information to the server, including: The image information verification application module running in the REE receives the image signature information and the image information sent by the image information verification trusted application module running in the TEE; The image information verification application module running in the REE sends the image signature information and the image information to the server.

10. The method of claim 9, wherein, The image information verification application module running in the REE receives the image signature information and the image information sent by the image information verification trusted application module running in the TEE, including: The image information verification application module running in the REE receives the image signature information and the image information sent by the image information verification trusted application module running in the TEE through a client application module of a camera framework layer running in the REE.

11. An image information secure transmission method, including: sending a camera use request message to an electronic device; receiving image signature information and image information fed back by an image information verification application module running in a REE of the electronic device; verifying the image signature information; processing the image information after verification.

12. The method of claim 11, wherein, The verification of the image signature information includes: verifying whether a server certificate is valid according to a root certificate of the server; verifying whether a device certificate is valid according to the server certificate in a case where the server certificate is valid; verifying whether the image signature information is valid according to the device certificate in a case where the device certificate is valid.

13. The method of claim 11, wherein, The receiving of the image signature information and the image information fed back by the image information verification application module running in the REE of the electronic device includes: receiving target information fed back by the image information verification application module running in the REE of the electronic device, and the target information includes image signature information; wherein the target information further includes image information and parameter information used to generate a signature key; or The target information further includes image information and an image verification certificate, and the image verification certificate is generated by digitally signing an image verification public key based on a device private key.

14. The method of claim 13, wherein, In a case where the target information further includes image information and parameter information used for generating a signature key, the verifying the image signature information includes: verifying, according to a root certificate of the server, whether a server certificate is valid; in a case where the server certificate is valid, verifying, according to the server certificate, whether a device certificate is valid; in a case where the device certificate is valid, generating a signature verification key according to a server private key, a device public key and the parameter information; verifying, according to the signature verification key, whether the image signature information is valid.

15. The method of claim 13, wherein, In a case where the target information further includes image information and an image verification certificate, the verifying the image signature information includes: verifying, according to a root certificate of the server, whether a server certificate is valid; in a case where the server certificate is valid, verifying, according to the server certificate, whether a device certificate is valid; in a case where the device certificate is valid, verifying, according to the device certificate, whether the image verification certificate is valid; in a case where the image verification certificate is valid, verifying, according to the image verification certificate, whether the image signature information is valid. 16.An image information secure transmission apparatus applied to an electronic device, wherein the electronic device is deployed with a general-purpose execution environment (REE), and the apparatus comprises: an image information verification application module running in the REE, configured to invoke a camera hardware module according to a camera use request message sent by a server, and acquire image information; a target module configured to digitally sign the image information and acquire image signature information, wherein the target module comprises an image data integrity protection module running in a camera hardware abstraction layer module in the REE or an image data signature application module running in a trusted execution environment (TEE) ; the image information verification application module is further configured to send the image signature information and the image information to the server.

17. The apparatus of claim 16, wherein, The image information verification application module is configured to implement at least one of the following: in a case where the image information verification application module running in the REE is trusted by the electronic device, the image information verification application module running in the REE is configured to invoke the camera hardware module according to the camera use request message and acquire image information; in a case where the image information verification application module running in the REE invokes a trusted camera driver module and acquires image information, the image information verification application module is further configured to send the camera use request message to a client application module running in a camera framework layer in the REE; 18. The apparatus of claim 17, wherein, the client application module is configured to send a verification request to an image verification auxiliary trusted application module running in the TEE in a case where the client application module determines that the authenticity of image collected by the camera hardware module needs to be verified according to the camera use request message. ​ The image verification auxiliary trusted application module obtains a device security state evaluation result from a device security evaluation trusted application module running in the TEE, and the device security state evaluation result is used to indicate that the electronic device is trusted or untrusted.

19. The apparatus of claim 17 or 18, wherein, The image information verification application module is further configured to: In a case where the electronic device is trusted, the image information verification application module is further configured to: The camera hardware abstraction layer module running in the REE is configured to send a photographing request message to a camera driver module running in the REE. The camera driver module is configured to invoke the camera hardware module. The camera hardware abstraction layer module is further configured to obtain image information. The image information includes image raw data collected by the camera hardware module and image attribute information generated by the image information verification trusted application module, and the image attribute information includes at least one of the following: a service name triggering photographing, a photographing location, a photographing time, and a photographing device model.

20. The apparatus of any of claims 17-19, wherein, In a case where the image information verification application module running in the REE invokes the camera hardware module to obtain image information in a case where the electronic device is trusted according to the camera use request message, the image information verification application module is further configured to: receive target information sent by the camera hardware abstraction layer module running in the REE through a client application module of a camera framework layer running in the REE, the target information including image signature information; send the target information to a server; In a case where the image data integrity protection module digitally signs the image information by using a signature key, the target information further includes image information and parameter information used to generate the signature key; or In a case where the image data integrity protection module digitally signs by using an image verification private key, the target information further includes image information and an image verification certificate, and the image verification certificate is generated by digitally signing an image verification public key based on a device private key.

21. The apparatus of claim 17, wherein, The image information verification application module is further configured to, in a case where it is determined that the camera hardware module needs to be invoked in a trusted environment, deliver a photographing request message to an image information verification trusted application module running in the TEE. The image information verification trusted application module is configured to send a photographing request message to a trusted camera service module running in the TEE. The trusted camera service module is configured to invoke a trusted camera driver module running in the TEE according to the photographing request message, and initiate a photographing request. The trusted camera driver module is configured to invoke the camera hardware module. The image information verification trusted application module is further configured to obtain image information. The image information includes image raw data collected by the camera hardware module and image attribute information generated by the image information verification trusted application module, and the image attribute information includes at least one of the following: a service name triggering photographing, a photographing location, a photographing time, and a photographing device model.

22. The apparatus of claim 21, wherein, The image information verification application module is further configured to: in a case where it is determined that the camera hardware module needs to be invoked in a trusted environment, send a photographing request message by a client application module of a camera framework layer running in the REE. The photographing request message includes at least one of the following: precision information of a photographed image; indication information of photographing in a trusted environment; information that needs to be photographed; service information.

23. The apparatus of claim 17, 21 or 22, wherein, In a case where the image information verification application module running in the REE invokes the trusted camera driver module to obtain image information, the image data signature application module is configured to: receive a signature request message sent by the image information verification trusted application module running in the TEE, the signature request message including a hash value obtained based on the image information, and the image data signature application module running in the TEE and / or a secure element (SE); perform digital signature on the hash value by using a device private key to obtain image signature information; send the image signature information to the image information verification trusted application module.

24. The apparatus of claim 16 or 23, wherein, The image information verification application module is configured to: receive the image signature information and the image information sent by the image information verification trusted application module running in the TEE; and send the image signature information and the image information to the server.

25. The apparatus of claim 24, wherein, The image information verification application module is configured to: receive the image signature information and the image information sent by the image information verification trusted application module running in the TEE by a client application module of a camera framework layer running in the REE. 26.An electronic device deployed with a general execution environment (REE), comprising a processor, a memory, and a program or instructions stored in the memory and executable on the processor, and the program or instructions are executed by the processor to implement the steps of the image information secure transmission method according to any one of claims 1-10. 27.An image information secure transmission apparatus, comprising: a sending module configured to send a camera use request message to an electronic device; a receiving module configured to receive image signature information and image information fed back by an image information verification application module running in a REE of the electronic device; a verification module configured to verify the image signature information; a processing module configured to process the image information after verification.

28. The apparatus of claim 27, wherein, The verification module is configured to: verify whether a server certificate is valid according to a root certificate of the server; verify whether a device certificate is valid according to the server certificate in a case where the server certificate is valid; and verify whether the image signature information is valid according to the device certificate in a case where the device certificate is valid.

29. The apparatus of claim 27, wherein, The receiving module is configured to: receive target information fed back by the image information verification application module running in the REE of the electronic device, the target information including image signature information; the target information further including: image information and parameter information used to generate a signature key; or the target information further including: image information and an image verification certificate generated by performing digital signature on an image verification public key based on a device private key.

30. The apparatus of claim 29, wherein, In the case that the target information further comprises image information and parameter information used for generating a signature key, the verification module is configured to: verify whether the server certificate is valid according to the root certificate of the server; in the case that the server certificate is valid, verify whether the device certificate is valid according to the server certificate; in the case that the device certificate is valid, generate a signature verification key according to the server private key, the device public key and the parameter information; verify whether the image signature information is valid according to the signature verification key.

31. The apparatus of claim 29, wherein, In the case that the target information further comprises image information and image verification certificate, the verification module is configured to: verify whether the server certificate is valid according to the root certificate of the server; in the case that the server certificate is valid, verify whether the device certificate is valid according to the server certificate; in the case that the device certificate is valid, verify whether the image verification certificate is valid according to the device certificate; in the case that the image verification certificate is valid, verify whether the image signature information is valid according to the image verification certificate.

32. A server comprising a processor, a memory, and a program or instructions stored on the memory and executable on the processor, the program or instructions being executed by the processor to implement the steps of the image information secure transmission method according to any one of claims 11-15.

Citation Information

Patent Citations

  • Method and device for preventing information tampering

    CN109600392A

  • Data security processing terminal, system and method

    CN110474874A

  • Image processing method, device and equipment

    CN115357929A

  • Security evaluation method, service processing method, security information transmission method and related equipment

    CN116633661A

  • Image information secure transmission method and device, electronic equipment and server

    CN118694867A