Communication method and apparatus

By using a SIM card or ERoT within the client device to determine the trustworthiness of the target object, the reliance on network connectivity in remote authentication technology is eliminated, thus improving the accuracy and reliability of the verification.

WO2026012035A1PCT designated stage Publication Date: 2026-01-15HUAWEI TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2025/100184
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-07-10
Filing Date
2025-06-10
Publication Date
2026-01-15

AI Technical Summary

Technical Problem

Existing remote verification technologies require a network connection between the verifier and the verifier for trust verification, which leads to connection limitations and affects verification efficiency and credibility.

Method used

Deploy a verification module inside the client device, use a SIM card or ERoT to determine the trustworthiness of the target object, and perform internal verification through measurement files and proof files to reduce reliance on network connectivity.

Benefits of technology

It enables the verification of the trustworthiness of target objects without a network connection, improving the accuracy and trustworthiness of the verification and reducing connection restrictions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2025100184_15012026_PF_FP_ABST
    Figure CN2025100184_15012026_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the embodiments of the present application are a communication method and apparatus. The method comprises: a verification module acquiring a measurement file of a target object, wherein the verification module and the target object are installed inside the same device; the verification module acquiring an attestation file of the target object; and the verification module determining an authentication result on the basis of the attestation file and the measurement file, wherein the authentication result is used for indicating the credibility of the target object. In this way, a verification module and a target object are installed inside the same device, and the verification module can determine the credibility of the target object on the basis of a measurement file and an attestation file, thereby reducing connection restrictions in the remote attestation technology.
Need to check novelty before this filing date? Find Prior Art

Description

A communication method and apparatus

[0001] Cross-reference to related applications

[0002] This application claims priority to Chinese Patent Application No. 202410920959.0, filed on July 10, 2024, entitled "A Communication Method and Apparatus", the entire contents of which are incorporated herein by reference. Technical Field

[0003] This application relates to the field of communications, and more particularly to a communication method and apparatus. Background Technology

[0004] To verify the trustworthiness of remote entities, a secure remote proof technique has been proposed in the field of communications. The remote proof architecture primarily involves three roles: the relying party, the attester, and the verifier. Currently disclosed remote proof techniques include the following: the remote proof data flow proposed in the Internet Engineering Task Force (IETF) request for comments (RFC) 9334 standard; the passport data flow in remote proof; and the background-check data flow in remote proof.

[0005] In remote verification technologies, including any of the aforementioned data streams, the verifiable entity (or target program) needs to connect to the verifier (e.g., via network or Bluetooth) to verify the trustworthiness of the target program. Thus, remote verification technologies are limited by the connection between the verifier and the verifiable entity. Summary of the Invention

[0006] This application provides a communication method and apparatus to reduce connection limitations in remote verification technology.

[0007] Firstly, this application provides a communication method that can be applied to a verification module in a client device. The verification module can be a processor, chip, chip system, circuit, or software module, etc., and this application does not limit its application to these components. The method may include: the verification module acquiring a measurement file of a target object; the verification module and the target object being installed within the same device (such as the aforementioned client device); the measurement file indicating the range of parameter values ​​that at least one parameter must satisfy when the target object is trustworthy, and at least one parameter representing a characteristic of the target object during operation; the verification module acquiring a certification file of the target object, the certification file indicating the parameter values ​​corresponding to at least one parameter when the target object is running within the device; the verification module determining an authentication result based on the certification file and the measurement file; and the authentication result indicating the trustworthiness of the target object.

[0008] In this way, the verification module and the target object are installed inside the same device. The verification module can judge the credibility of the target object based on the measurement file and the proof file. Unlike the traditional scheme where the verification module and the target object are installed inside different devices, the device where the verification module is located in this application does not need to interact with the device where the remote target object is located to complete the credibility verification. Therefore, the connection restrictions in remote proof technology can be reduced.

[0009] In one possible design, the verification module can be housed within the subscriber identity module (SIM) card inside the device. This allows the verification module's functionality to be supported by the SIM card, which is endorsed by a trusted operator, increasing the credibility of the verification module and consequently the reliability of the authentication results it determines.

[0010] In one possible design, the verification module can be an embedded root of trust (ERoT). This allows the aforementioned function of determining authentication results based on metric and proof documents to be integrated into the ERoT, further increasing the credibility of the authentication results determined by the verification module.

[0011] In one possible design, the verification module may include an ERoT and a verification submodule. The aforementioned process of obtaining the proof document of the target object may include: the ERoT generating the proof document of the target object; the aforementioned process of determining the authentication result based on the proof document and the measurement document may include: the verification submodule determining the authentication result based on the proof document and the measurement document obtained by the ERoT. In this way, the ERoT can generate the proof document of the target object, and the verification submodule can implement the aforementioned function of determining the authentication result based on the measurement document and the proof document; only the definition and specifications of the verification submodule (including the acquisition of the measurement document and the determination of the authentication result) need to be designed, without changing the definition and specifications of the ERoT.

[0012] In one possible design, the verification submodule can also receive proof documents generated by ERoT forwarded by the target object. This allows the verification submodule to interact with the target object, adapting to passport data streams in remote proof and improving the applicability of the communication method.

[0013] In one possible design, the aforementioned process of obtaining the measurement file of the target object may include: the verification module obtaining the measurement file of the target object from the SIM card inside the device; the SIM card pre-stores measurement files corresponding to at least one object, and at least one object includes the target object. In this way, the verification module can obtain the measurement file of the target object from the SIM card, thereby determining the trustworthiness of the target object without interacting with external devices, reducing connection limitations in remote verification technologies.

[0014] In one possible design, the measurement file corresponding to at least one object is stored in the SIM card based on the initial configuration information of the SIM card; or, the measurement file corresponding to at least one object is stored in the SIM card based on the updated configuration information of the SIM card.

[0015] In one possible design, the verification module can also output or display the authentication result; alternatively, the verification module can also send the authentication result. In this way, the verification module can output or display the authentication result of the target object to the user, or send the authentication result of the target object to other devices for viewing, making the authentication result more intuitively accessible to the user.

[0016] In one possible design, the aforementioned process of sending the authentication result may include: the verification module signing the authentication result; and the verification module sending the signed authentication result. In this way, the verification module can sign the authentication result before sending it to other devices, making the authentication result less susceptible to tampering and improving its security.

[0017] Secondly, this application provides a communication method applied to a client device, or a component (such as a processor, chip, chip system, circuit, or others) or software module within the client device, wherein the client device includes an authentication module. Taking the application of this method to a client device as an example, the method may include: the client device receiving first configuration information from an operator device, the first configuration information indicating measurement files corresponding to at least one object; the at least one object including a target object; the measurement file of the target object indicating the range of parameter values ​​that at least one parameter must satisfy when the target object is trusted, the at least one parameter representing the characteristics of the target object during operation; the measurement file of the target object being used by the authentication module to determine the authentication result of the target object, the authentication result indicating the trustworthiness of the target object; the target object being any one of the at least one objects, the at least one object being installed within the client device; and the client device storing the measurement files corresponding to the at least one object according to the first configuration information.

[0018] In this way, the client device can receive and pre-store the measurement file of at least one object issued by the operator. The at least one object includes the target object, so that the verification module in the client device can determine the authentication result of the target object based on the measurement file of the target object inside the device. During the process of the verification module obtaining the measurement file, there is no need to interact with external devices, reducing the connection restrictions in remote authentication technology.

[0019] In one possible design, the client device can also receive second configuration information from the operator's equipment. This second configuration information instructs the updating of measurement files corresponding to at least one object. The update includes at least one of the following: deleting the measurement files corresponding to one or more of the at least one object; replacing the measurement files corresponding to one or more of the at least one object; or configuring corresponding measurement files for one or more newly added objects based on the at least one object. Thus, the client device can update the pre-stored measurement files corresponding to at least one object using the second configuration information from the operator's equipment.

[0020] In one possible design, the method shown in the second aspect is specifically applied to the SIM card installed in the client device, with the verification module located within the SIM card. In this way, the measurement file required by the verification module is stored in the SIM card, which is endorsed by a trusted operator device, making the measurement file less susceptible to tampering and increasing the credibility of the authentication results determined by the verification module.

[0021] In one possible design, the client device can also receive first instruction information from the carrier equipment, which instructs the client device to install an authentication module. The client device can also install the authentication module according to the first instruction information. This allows the installed authentication module to determine the authentication result of the target object based on the target object's measurement file, and the authentication result is used to indicate the trustworthiness of the target object. In this way, the functionality of the authentication module can be supported by the carrier equipment, increasing the trustworthiness of the authentication module and thus increasing the trustworthiness of the authentication result determined by the authentication module.

[0022] In one possible design, the client device can also receive identity verification information from the verification module of the operator's equipment, enabling the verification module to sign the authentication result of the target object based on the identity verification information. In this way, the client device can obtain the identity verification information from the verification module, allowing the verification module to sign the authentication result, thus improving the security of the authentication result during transmission.

[0023] Thirdly, this application provides a communication method applied to operator equipment, or components (such as processors, chips, chip systems, circuits, or others) within operator equipment, or software modules. Taking the application of this method to operator equipment as an example, the method may include: the operator equipment generating first configuration information, the first configuration information indicating measurement files corresponding to at least one object; the at least one object including a target object; the measurement file of the target object indicating the range of parameter values ​​that at least one parameter must satisfy when the target object is trusted, the at least one parameter representing the characteristics of the target object during operation; the target object being any one of the at least one objects, the at least one object being installed in a client device; and the operator equipment sending the first configuration information to the client device.

[0024] In one possible design, the operator equipment may also send second configuration information to the client equipment; the second configuration information is used to instruct the updating of the measurement files corresponding to at least one object respectively; the update includes at least one of the following: deleting the measurement files corresponding to one or more of the at least one object; replacing the measurement files corresponding to one or more of the at least one object; configuring the corresponding measurement files for one or more objects added based on the at least one object.

[0025] In one possible design, the operator equipment can also send a first instruction message to the client equipment, which instructs the client equipment to install a verification module; the verification module is used to determine the authentication result of the target object based on the target object's measurement file, and the authentication result is used to indicate the trustworthiness of the target object.

[0026] In one possible design, the operator equipment can also send the identity verification information of the authentication module installed in the client device to the client device, so that the authentication module can sign the authentication result of the target object based on the identity verification information.

[0027] Fourthly, this application also provides a communication device. This communication device can perform the methods or various possible designs described in the first aspect above. The communication device can be a chip or circuit capable of performing the functions corresponding to the above methods, or a device including such a chip or circuit.

[0028] In one possible design, the communication device includes a verification module; this verification module is used to perform the methods in any of the possible designs shown in the first aspect above. The aforementioned functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the aforementioned functions.

[0029] Fifthly, this application also provides a communication device. This communication device can perform the methods or various possible designs described in the second aspect above. The communication device can be a chip or circuit capable of performing the functions corresponding to the above methods, or a device including such a chip or circuit.

[0030] In one possible design, the communication device includes a communication module, a storage module, a processing module, and an authentication module; wherein the communication module is used to receive and / or send data; the storage module is used to store data; and the processing module is used to perform the operation of receiving information from the operator equipment as described in the second aspect above and any possible design thereof, based on the communication module, and to trigger the authentication module to perform the operation of determining the authentication result of the target object based on the metric file of the target object as described in the second aspect above and any possible design thereof, wherein the authentication result is used to indicate the trustworthiness of the target object.

[0031] Sixthly, this application also provides a communication device. This communication device can perform the methods or various possible designs described in the third aspect above. The communication device can be a chip or circuit capable of performing the functions corresponding to the above methods, or a device including such a chip or circuit.

[0032] In one possible design, the communication device includes: a communication module for receiving and / or transmitting data; and a processing module for implementing the method in any of the possible designs shown in the third aspect above, based on the communication module. The aforementioned functions can be implemented in hardware or by hardware executing corresponding software. The hardware or software includes one or more units corresponding to the aforementioned functions.

[0033] Seventhly, this application also provides a communication device. This communication device can execute the methods or various possible designs shown in the first, second, or third aspects above. The communication device includes a processor. When the processor executes instructions, it causes the communication device or a device equipped with the communication device to execute any of the possible designs shown in the first, second, or third aspects above.

[0034] Optionally, the communication device may further include a memory for storing computer-executable program code, which may include the aforementioned instructions. The memory may be located internally or externally to the communication device; this application does not limit this. The memory may be coupled to a processor.

[0035] The communication device may also include a communication interface. Optionally, if the communication device is a chip or circuit, the communication interface may be the chip's input / output interface, such as input / output pins.

[0036] Eighthly, this application provides a communication system comprising at least one of the following: a verification module executing the method of the first aspect, a client device executing the method of the second aspect, and an operator device executing the method of the third aspect, wherein the verification module is located within the operator device.

[0037] Ninthly, this application provides a computer-readable storage medium storing a computer program that, when run on a computer, causes the computer to perform any of the possible designs shown in the first, second, or third aspects above.

[0038] In a tenth aspect, this application provides a computer program product storing computer-executable instructions, which, when invoked by a computer, cause the computer to perform any of the possible designs shown in the first, second, or third aspects above.

[0039] Eleventhly, this application provides a chip including a processor for executing the methods in any of the possible designs shown in the first, second, or third aspects above. Optionally, the chip may further include a communication interface for inputting and / or outputting signaling or data. Optionally, the chip may further include a memory for storing the aforementioned computer program; the processor is coupled to the memory, and the processor can read the computer program stored in the memory to execute the methods in any of the possible designs shown in the first, second, or third aspects above.

[0040] Furthermore, the technical effects brought about by the third to eleventh aspects can be found in the descriptions of the various possible solutions in the first or second aspects above, and will not be repeated here. Attached Figure Description

[0041] Figure 1 is a schematic diagram of the architecture of a communication system provided in an embodiment of this application;

[0042] Figure 2a is a schematic diagram of the structure of a client device provided in an embodiment of this application;

[0043] Figure 2b is a schematic diagram of another client device provided in an embodiment of this application;

[0044] Figure 3a is an example architecture diagram of a communication system provided in an embodiment of this application;

[0045] Figure 3b is an example architecture diagram of another communication system provided in an embodiment of this application;

[0046] Figure 3c is an example architecture diagram of another communication system provided in an embodiment of this application;

[0047] Figure 4 is a flowchart illustrating a communication method provided in an embodiment of this application;

[0048] Figure 5a is an example diagram of a communication method provided in an embodiment of this application;

[0049] Figure 5b is an example diagram of another communication method provided in an embodiment of this application;

[0050] Figure 6 is an example architecture diagram of another communication system provided in an embodiment of this application;

[0051] Figure 7a is an example diagram of another communication method provided in an embodiment of this application;

[0052] Figure 7b is an example diagram of another communication method provided in an embodiment of this application;

[0053] Figure 8 is a schematic diagram of the structure of a communication device provided in an embodiment of this application;

[0054] Figure 9 is a schematic diagram of another communication device provided in an embodiment of this application. Detailed Implementation

[0055] To make the objectives, technical solutions, and beneficial effects of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0056] In the description of this application, unless otherwise stated, " / " signifies "or," for example, A / B can mean A or B. "And / or" in this application merely describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A alone, A and B simultaneously, or B alone. Furthermore, in the description of this application, "at least one" refers to one or more items, and "multiple" refers to two or more items. In the description of this application, terms such as "first" and "second" are used only for descriptive purposes and should not be construed as indicating or implying relative importance or order.

[0057] To better illustrate the solution of this application, the technical terms involved in this application are explained below:

[0058] 1. SIM card: A smart card primarily used to store user identification information, SMS data, and phone numbers.

[0059] 2. Trusted Execution Environment (TEE): This is a secure area within the central processing unit that ensures the confidentiality and integrity of programs and data within it.

[0060] 3. Trusted Platform Module (TPM): This is a microchip designed to provide basic security-related functions, primarily involving encryption keys.

[0061] The TPM includes SIM TPM, firmware-based trusted platform module (fTPM), and virtual trusted platform module (vTPM). SIM TPM is a mobile TPM implemented using a SIM card available in the mobile platform. fTPM is a firmware-based TPM running in a CPU trusted execution environment. vTPM is provided by and depends on a hypervisor in an isolated execution environment, which hides the software running within the virtual machine to protect its code from the influence of the software within the virtual machine.

[0062] 4. Read-only memory (ROM): This is a type of semiconductor memory. Its characteristic is that once data is stored in it, it cannot be rewritten or deleted, but the stored content will not be lost when the power is turned off.

[0063] 5. Electronically erasable programmable read-only memory (EEPROM): This is a type of ROM that can be rewritten multiple times electronically.

[0064] 6. Terminal equipment can be a device capable of receiving network equipment scheduling and instruction information, providing voice and / or data connectivity to users, or a handheld device with wireless connectivity, or other processing devices connected to a wireless modem, or a station (STA) device. Terminal equipment can communicate with one or more core networks or the Internet via a radio access network (RAN). For example, terminal equipment can be portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices. Terminal equipment can also be referred to as a subscriber unit (SS), subscriber station (MS), mobile station (MS), remote station (AP), access point (AP), remote terminal, access terminal, user agent, customer premises equipment (CPE), terminal, user equipment (UE), mobile terminal (MT), etc. Terminal equipment can also be wearable devices. Terminal equipment can also be equipment in next-generation communication systems. For example, terminal devices in 5G networks or terminal devices in future PLMN networks, and terminal devices in next-generation radio (NR) communication systems.Currently, terminal devices can include: mobile phones, tablets, laptops, PDAs, desktop computers, customer-premises equipment (CPE), mobile internet devices (MID), wearable devices (such as smartwatches, smart bracelets, pedometers, etc.), in-vehicle equipment (such as cars, bicycles, electric vehicles, airplanes, ships, trains, high-speed trains, etc.), virtual reality (VR) devices, augmented reality (AR) devices, wireless terminals in industrial control, smart home devices (such as refrigerators, televisions, air conditioners, electricity meters, etc.), intelligent robots, workshop equipment, wireless terminals in self-driving, wireless terminals in remote medical surgery, wireless terminals in smart grids, wireless terminals in transportation safety, wireless terminals in smart cities, or wireless terminals in smart homes, and flying equipment (such as intelligent robots, hot air balloons, drones, airplanes), etc. Terminal devices can also be other devices with terminal functions. For example, a terminal device can also be a device that performs terminal functions in D2D communication.

[0065] 7. Network equipment is an entity on the network side used to transmit or receive signals. Examples include transmission reception points (TRPs) and gNBs. Network equipment can be an access point (AP) in a wireless local area network (WLAN), a global system for mobile communication (GSM), or a base station (BS). A base station can be a base transceiver station (BTS) in code division multiple access (CDMA), a base station (nodeB, NB) in wideband code division multiple access (WCDMA), or an evolved node B (eNB or eNodeB) in long term evolution (LTE). Network equipment can also be a relay station or access point, or in-vehicle equipment, wearable devices, and network equipment in 5G networks, or network equipment in future evolved PLMNs, or gNodeB / gNB devices in NR systems. In some deployments, a gNB may include a centralized unit (CU) and a distributed unit (DU). The CU implements some of the gNB's functions, and the DU implements others. For example, the CU is responsible for handling non-real-time protocols and services. This includes implementing functions such as radio resource control (RRC), service data adaptation protocol (SDAP), and packet data convergence protocol (PDCP). The DU is responsible for handling physical layer protocols and real-time services. This includes implementing functions such as radio link control (RLC), medium access control (MAC), and physical (PHY) layers. The gNB may also include an active antenna unit (AAU). The AAU implements some physical layer processing functions, radio frequency processing, and related active antenna functions. Since information from the RRC layer ultimately becomes information from the PHY layer, or is derived from information from the PHY layer...Therefore, under this architecture, higher-layer signaling (e.g., RRC layer signaling) can also be considered to be sent by the DU, or by the DU and AAU. It is understood that the network device can be one or more of the following: CU node, DU node, and AAU node. Furthermore, the CU can be a network device in the radio access network (RAN), or a network device in the core network (CN); this application does not limit this. Additionally, in the embodiments of this application, the network device provides services to a cell, and the terminal device communicates with the network device through the transmission resources (e.g., frequency domain resources, or spectrum resources) used by the cell. The cell can be the cell corresponding to the network device (e.g., a base station). The cell can belong to a macro base station or to a base station corresponding to a small cell. For example, a small cell can include: a metro cell, a micro cell, a pico cell, a femto cell, etc. Because small cells have small coverage areas and low transmission power, they can provide high-speed data transmission services. Furthermore, in other possible cases, the network device can be any other device that provides wireless communication functionality to the terminal device. The embodiments of this application do not limit the specific technology or device form used in the network device. For example, in an open radio access network (ORAN) system, CU can also be called O-CU (open CU), DU can also be called O-DU, CU-CP can also be called O-CU-CP, CU-UP can also be called O-CU-UP, and RU can also be called O-RU. For ease of description, this application uses CU, CU-CP, CU-UP, DU, and RU as examples. Any of the units among CU (or CU-CP, CU-UP), DU, and RU in this application can be implemented through a software module, a hardware module, or a combination of software and hardware modules.

[0066] For example, network devices can be cellular base stations or routers. A router is a hardware device that connects two or more networks, acting as a gateway between them. It is a dedicated, intelligent network device that reads the address in each data packet and determines how to transmit it. In this embodiment, the router may be, for example, an Internet Protocol (IP) bearer network router or a campus network router.

[0067] 7. ERoT: Provides functions such as positive random number generation, packet classification rule (PCR) update, signing, and trusted key / file storage through an applet with TPM functionality within the SIM card.

[0068] In remote verification technologies, the verifier and the verifier need a network connection, such as a wireless connection, wired connection, or Bluetooth connection, to interact and verify the credibility of the verifier. Therefore, existing technologies rely heavily on network connectivity to determine the credibility of the verifier, which is quite limiting. To reduce the connection limitations in remote verification technologies, this application provides a communication system. Figure 1 is a schematic diagram of a communication system applicable to this application embodiment. This communication system includes a client device and an operator device (or cellular network operator device). The client device includes a verification module and a target object to be verified (e.g., software in a mobile phone, a bootloader in a network device). The client device can be the terminal device described above, or the network device described above. Optionally, the client device may also include other hardware / programs, which are not limited in this application.

[0069] In the embodiments of this application, the target object can be understood as hardware, entities, software, programs, configurations, environments, other objects to be authenticated, or a collection of objects to be authenticated within the client device.

[0070] In the communication system shown in Figure 1, a verification module can be deployed inside the client device, and the target object to be verified (equivalent to the verifier) ​​is also installed inside the same client device. In this way, the verification module inside the client device can act as the verifier and verify the legitimacy or credibility of the target object through data interaction within the device without a network connection, thereby overcoming the limitation mentioned above that the verification process requires a network connection.

[0071] In some examples, the verification module can be deployed within the SIM card inside the client device. The client device can then interact with the carrier equipment via the SIM card to transmit data. With this design, the verification module's functionality is supported by the SIM card (carrier equipment), making it less susceptible to tampering and increasing its credibility. This overcomes the aforementioned network connectivity limitations and further enhances the trust between the verifier and the verified party, resulting in higher verification accuracy.

[0072] In other examples, the verification module can also be deployed in locations other than the SIM card within the client device. The client device can then interact with carrier equipment to transmit data. For instance, the client device can set data modification permissions at the location where the verification module is deployed, ensuring that data at that location can only be updated through a subset of trusted devices. This prevents users with lower privileges from modifying the data at that location, thus guaranteeing that the verification module is supported by trusted devices and enhancing its credibility.

[0073] The following description of the verification module in the SIM card is provided as an example, but this does not constitute a limitation on the deployment location of the verification module. The structure of the verification module deployed in other locations and the communication methods after the verification module is deployed in other locations can refer to the example of the verification module deployed in the SIM card.

[0074] Optionally, the aforementioned SIM card can be a Super SIM card. In the communication method shown in this application, the verification module may need to pre-store a large amount of data locally (e.g., measurement files of multiple objects), thus placing certain requirements on the storage space of the verification module. In this way, since the Super SIM card has a larger storage space, the problem of limited storage space for the verification module is avoided.

[0075] It is understood that the verification module can be deployed in the SIM card in various ways (e.g., as a mini-program), and this application does not specifically limit it. Below are two exemplary structural examples in the SIM card provided by this application.

[0076] Example Structure 1: The SIM card includes an authentication module, which is an ERoT (or SIM TPM). In other words, the functionality of the authentication module in this embodiment can be integrated into the ERoT.

[0077] Optionally, ERoT can be bound to a root of trust for measures (RTM) of the client device to ensure the integrity of measurement values ​​(e.g., declared values) from the client device. The binding methods include, but are not limited to, methods 1 and 2 described below:

[0078] 1. Use the TEE in the client device as a proxy for ERoT to bind ERoT and RTM;

[0079] 2. Bind ERoT and RTM using distance binding.

[0080] It should be understood that the binding method between ERoT and RTM can refer to traditional technologies, and this application does not limit it.

[0081] Figure 2a is a structural example diagram of a client device provided in an embodiment of this application. As shown in Figure 2a, the client device includes: a SIM card containing a verification module and a target object to be verified. In the following embodiments, the target object is described as a target program. The implementation process is similar for other cases such as target hardware or target environment. You can refer to the following implementation process of verifying the target program. In addition, the verification module is described as ERoT in the following embodiments.

[0082] Optionally, the verification module can be divided into two functional areas: a proof sub-application and a verification sub-application; or, the verification module can be divided into three functional areas: the main interface, the proof sub-application, and the verification sub-application.

[0083] Example Structure 2: The SIM card includes a verification module, which comprises an ERoT and a verification submodule. In other words, the verification submodule can interact with the ERoT to jointly implement the functions of the verification module in this embodiment.

[0084] Figure 2b is a structural example diagram of another client device provided in an embodiment of this application. As shown in Figure 2b, the client device includes: a SIM card containing a verification module and a target object to be verified (the target program is used as an example in the figure); wherein, the verification module includes ERoT and a verification submodule.

[0085] Optionally, in the structural examples of the client device shown in Figure 2a or Figure 2b above, the client device may also include a client device system and an authentication result manager.

[0086] Optionally, in the structural examples of the client device shown in Figure 2a or Figure 2b, the SIM card further includes a storage module. Optionally, this storage module can be an electrically erasable programmable read-only memory (EEPROM) or flash memory. Optionally, the storage module can be divided into two functional areas: a storage management applet and storage space. The storage management applet can write data, read data, and delete data in the storage space.

[0087] Based on the communication system shown in Figure 1, and taking the target program as the target object as an example, this application provides the following three communication system designs by way of example.

[0088] As shown in Figure 3a, this application embodiment provides a design for a communication system, which includes operator equipment (or a gold standard manager, endorser, or reference value provider), client equipment (including a verification module and a target program to be verified), and relying party equipment. The verification module can be located inside the SIM card of the client equipment; the structure of the client equipment can be referred to in Figure 2a or Figure 2b above.

[0089] As shown in Figure 3b, the communication system includes operator equipment, client equipment (including an authentication result manager, a SIM card containing an authentication module, and a target program to be authenticated), and dependent equipment. The authentication module is located within the SIM card inside the device, and the SIM card structure is as described in the aforementioned Structure Example 1. The structure of the client equipment can be referenced in Figure 2a.

[0090] As shown in Figure 3c, the communication system includes operator equipment, client equipment (including an authentication result manager, a SIM card containing an authentication module, and a target program to be authenticated), and dependent equipment. The authentication module is located in the SIM card inside the device, and the SIM card structure is as described in Example 2 above. The structure of the client equipment can be referred to in Figure 2b above.

[0091] To reduce connectivity limitations in remote authentication technologies, embodiments of this application provide a communication method. This communication method can be implemented in the communication systems shown in Figures 1, 3a, 3b, or 3c.

[0092] The communication method provided in the embodiments of this application will now be described with reference to the accompanying drawings. In the communication method described below, a target program is used as the target object for example, but this does not constitute a limitation of this application. Figure 4 illustrates a communication method provided in an embodiment of this application, which may include the following steps:

[0093] S401: The verification module obtains the measurement file of the target program. The verification module and the target program are installed in the same device (e.g., the client device shown in Figure 2a or Figure 2b); the measurement file is used to indicate the range of parameter values ​​(also called reference values) that at least one parameter must satisfy when the target program is trusted, and at least one parameter is used to represent the characteristics of the target program during operation (e.g., the hash value of the target program's code).

[0094] In the embodiments of this application, the measurement file is also called the golden measurement, the golden value, or the golden measurement file.

[0095] Optionally, the metrics document can also be used to indicate the criteria (or appraisal policy) for judging the trustworthiness of the target program. The criteria include at least one of the following: the priority or weight of each parameter, the algorithm for judging the trustworthiness of the target program, etc. In other words, the metrics document can indicate the importance of each parameter in judging the trustworthiness of the target program.

[0096] The aforementioned target program's metrics file is used to determine the authentication results of the target program's credibility.

[0097] In some examples, the authentication result of the target program's trustworthiness can be a binary result, namely, absolutely trustworthy or absolutely untrustworthy. The "target program is trustworthy" in the aforementioned S401 can be understood as absolutely trustworthy.

[0098] In other examples, the authentication result of the target program's trustworthiness can be a multivariate result, i.e., N levels of trustworthiness, where N is a positive integer; the "target program trustworthiness" in S401 above can be understood as N levels of trustworthiness. Optionally, the larger the value of N, the higher the trustworthiness of the target program; or, the larger the value of N, the lower the trustworthiness of the target program. For example, the measurement file may include the following data (the specific parameter value range is not defined in the table and should be determined according to the actual situation):

[0099] Table 1

[0100] In other examples, the authentication result of the target program's trustworthiness can be a numerical value used to characterize the degree of trustworthiness.

[0101] Before executing S401, the verification module (or the client device on which the verification module is installed) may pre-store a measurement file corresponding to at least one object locally, the at least one object including the aforementioned target object; the above-mentioned stored procedure is described below with the program as the object through two designs, but this does not constitute a limitation of this application, and the stored procedures of other objects can refer to the description of the stored procedures of the program.

[0102] In one possible design, the operator equipment can generate first configuration information. This first configuration information indicates the measurement files corresponding to at least one program. The operator equipment can also send the first configuration information to a client device; correspondingly, the client device can receive the first configuration information from the operator equipment; and the client device can also store the measurement files corresponding to the at least one program based on the first configuration information.

[0103] Optionally, before the operator equipment generates the first configuration information, the client device may send a first message to the operator equipment, the first message indicating the identifier of the at least one program. In this way, the operator equipment can send the first configuration information to the client device according to the client device's requirements for the measurement file, avoiding the waste of storage space on the client device due to redundant measurement files.

[0104] In other words, the operator equipment can proactively send the first configuration information to the client equipment, or it can send the first configuration information to the client equipment based on the client equipment's needs (such as the first message). This application does not impose any limitations on this.

[0105] Furthermore, the operator equipment can also generate second configuration information. The operator equipment can also send the second configuration information to the client equipment; correspondingly, the client equipment can also receive the second configuration information from the operator equipment; wherein, the second configuration information is used to instruct the updating of the measurement files corresponding to the at least one program; the update includes at least one of the following: deleting the measurement files corresponding to one or more of the at least one program; replacing the measurement files corresponding to one or more of the at least one program; configuring the corresponding measurement files for one or more programs added based on the at least one program.

[0106] Optionally, before the operator equipment generates the second configuration information, the client device can send a second message to the operator equipment. This second message indicates the identifier of the at least one program. In this way, the operator equipment can send a second measurement file to the client device according to the client device's requirements for the measurement file, avoiding the waste of storage space on the client device due to redundant measurement files.

[0107] In other words, the operator equipment can proactively send the second configuration information to the client equipment, or it can send the second configuration information to the client equipment based on the client equipment's needs (such as a second message). This application does not impose any limitations on this.

[0108] The aforementioned design can also be applied to SIM cards (including authentication modules) installed in client devices.

[0109] In another possible design, the verification module is deployed in the SIM card of the client device. The SIM card can pre-store measurement files of at least one program locally, and the at least one program includes the target program. In this way, the verification module can obtain the measurement files of the target program locally.

[0110] Optionally, the SIM card can be a Super SIM card. In this way, given the larger storage space of the Super SIM card, the verification module can store a large amount of data locally (such as measurement files from multiple programs), avoiding the problem of limited storage space for the verification module.

[0111] Optionally, the measurement file corresponding to at least one program may be stored in the SIM card based on the initial configuration information of the SIM card; or, the measurement file corresponding to at least one program may be stored in the SIM card based on the updated configuration information of the SIM card.

[0112] In some examples, before the SIM card is used for the first time, the operator's equipment can write a measurement file and an authentication module to the SIM card. When a measurement file needs to be updated later, the operator's equipment can write a new measurement file to the SIM card via OTA (Over-The-Air). During the aforementioned data writing process to the SIM card, the operator's equipment can ensure the integrity and reliability of the measurement file through signing. The measurement file initially written to the SIM card may include at least one of the following: a device endorsement obtained from an endorser (which may be the same as or different from the operator's equipment), a reference value range for at least one parameter obtained from a reference value provider (which may be the same as or different from the operator's equipment), and an evaluation strategy for the authentication results.

[0113] In some examples, at least one program includes a first program, and the SIM card can store the measurement file of the first program via SA1 to SA2.

[0114] SA1: The operator equipment can send initial configuration information to the SIM card. Correspondingly, the SIM card receives the initial configuration information from the operator equipment. This initial configuration information is used to indicate the measurement file for the first procedure.

[0115] For example, operator equipment can send initial configuration information to the SIM card via a card reader.

[0116] SA2: The SIM card stores the measurement file of the first program in the SIM card according to the initial configuration information.

[0117] In other examples, at least one program includes a second program, and the SIM card can store the measurement file of the second program via SB1 to SB2.

[0118] SB1: The operator equipment can send updated configuration information to the SIM card. Correspondingly, the SIM card receives the updated configuration information from the operator equipment. This updated configuration information is used to indicate the measurement file for the second procedure (e.g., the first measurement file).

[0119] For example, operator equipment can send updated configuration information to the SIM card via over-the-air (OTA) download.

[0120] SB2: The SIM card stores the measurement file of the second program (e.g., the first measurement file) in the SIM card according to the updated configuration information.

[0121] Optionally, when the SIM card already stores the measurement file of the second program (e.g., the second measurement file), the SIM card can overwrite and update the measurement file of the second program, that is, overwrite the second measurement file with the first measurement file.

[0122] It should be understood that the methods of storing at least one measurement file corresponding to each program locally in the two designs mentioned above can be cross-referenced, and this application does not limit them.

[0123] S402: The verification module obtains the evidence file of the target program, which indicates the parameter values ​​corresponding to at least one parameter when the target program is running inside the device.

[0124] In some examples, the verification module can collect a series of claims in the target program (or target environment) and generate a proof document based on these claims. Each claim corresponds to at least one parameter, and each claim can consist of a parameter name and a parameter value (name / value pair). The verification module generates the proof document by signing the aforementioned series of claims and adding a timestamp, thereby generating the proof document (or evidence). Optionally, the private key required for the verification module to sign (contained in the verification module's identity verification information) can be pre-written into the verification module by the operator's equipment. Optionally, to achieve the aforementioned signing of the series of claims, the operator's equipment can also pre-write the identity verification information corresponding to the verification module (which can be used as the private key for signing) into the SIM card.

[0125] Assuming the verification module is located in the SIM card inside the device, the process of obtaining the aforementioned proof document will be described below based on two different structural examples of the verification module.

[0126] In one possible design, when the SIM card has the structure of the aforementioned structure example one, in order to accommodate the passport data stream in remote authentication, the verification module can send authentication documents to the target program; and / or, the verification module can also receive authentication documents from the target program.

[0127] In another possible design, when the SIM card has the structure of the aforementioned structure example two, the aforementioned S402 can be executed by ERoT; that is, ERoT can generate proof files for the target program.

[0128] In some examples, ERoT can also send the aforementioned proof file to the verification submodule. For instance, ERoT can send the proof file to the verification submodule via thread interaction. Alternatively, ERoT can send the proof file to the target program, which can then forward it to the verification submodule. In other words, the verification submodule can also receive proof files generated by ERoT forwarded by the target program.

[0129] S403: The verification module determines the attestation result based on the supporting documentation and metrics. The attestation result indicates the credibility of the target program.

[0130] Optionally, the authentication result can carry a timestamp.

[0131] In some examples, the authentication result can be a binary result, a multivariate result, or a numerical value used to characterize the degree of trustworthiness.

[0132] In one possible design, when the verification module is located in the SIM card inside the device and the SIM card has the structure of the aforementioned structure example two, the aforementioned S403 can be executed by the verification submodule; that is, the verification submodule can determine the authentication result based on the proof document and measurement document obtained by ERoT.

[0133] The following is a brief explanation of the process for evaluating the credibility of a target program based on parameter information of at least one predefined parameter:

[0134] At least one parameter includes parameter a, parameter b, and parameter c, with the following meanings:

[0135] Parameter a: indicates whether the target program contains endorsement. When the value of parameter 1 is 1, it means that the target program contains endorsement. When the value of parameter 1 is 0, it means that the target program does not contain endorsement.

[0136] Parameter b: Used to indicate the version number of the target program.

[0137] Parameter c: The parameter value used to indicate the code integrity of the target program.

[0138] Based on S401, it can be determined that the target program's measurement file (where N=4) includes the following data:

[0139] Table 2

[0140] Based on S402, the proof file of the target program includes the following data: the parameter value of parameter a is 1, the parameter value of parameter b is 3.2.7, and the parameter value of parameter c is 11.

[0141] The verification module can determine the credibility of the target program as either absolutely trustworthy or Level 3 trustworthy based on the aforementioned measurement and verification documents.

[0142] Furthermore, the verification module can also execute the following S404.

[0143] S404: The verification module outputs or displays the authentication result; or, the verification module sends the authentication result.

[0144] In one possible design, the process of the verification module sending the authentication result may include: the verification module signing the authentication result; and the verification module sending the signed authentication result. For example, in the communication system shown in Figure 3a, the verification module may send the signed authentication result to the dependent device.

[0145] Optionally, the aforementioned signature can be determined based on the identity verification information of the verification module (including the private key of the verification module).

[0146] In some examples, the operator device may send a first instruction message to the operator device (or SIM card) to instruct the operator device (or SIM card) to install a verification module; the verification module is used to determine the authentication result of any program (e.g., a target program) installed in the operator device (or the device to which the SIM card belongs).

[0147] Optionally, the first indication information may include the identity verification information of the verification module.

[0148] In other examples, the operator equipment can send the authentication module's identity verification information to the client equipment (or SIM card); correspondingly, the client equipment (or SIM card) can receive the authentication module's identity verification information from the operator equipment.

[0149] In some examples, in conjunction with the communication systems shown in Figures 3b and 3c, the communication method shown in Figure 4 can be implemented through the following steps.

[0150] In the communication system shown in Figure 3b, the communication method may include the following S5a-1 to S5a-7 (as shown in Figure 5a):

[0151] S5a-1: The operator equipment stores the measurement file in the storage space through the storage management applet in the verification module via a card reader (for the first write) or OTA (for subsequent updates). The aforementioned S5a-1 can be found in the descriptions of SA1 to SA2, or SB1 to SB2, and will not be repeated here.

[0152] S5a-2: The verification module collects claims in the target program. Furthermore, the verification module can also generate supporting documentation based on these claims.

[0153] In some examples, S5a-2 can be implemented between multiple functional areas within the verification module in the following way: the main interface calls the proof sub-application and passes the declaration to the proof sub-application as a parameter; the proof sub-application generates a proof file based on the declaration and sends the proof file to the main interface.

[0154] S5a-3: The verification module can send the verification document to the target program.

[0155] S5a-4: The target program sends the supporting documentation to the verification module. Furthermore, the verification module can determine the target program's authentication result based on the measurement file and the supporting documentation.

[0156] In some examples, S5a-4 can be implemented between multiple functional areas within the verification module in the following way: the main interface calls the verification sub-application (which has obtained the proof file), so that the verification sub-application compares the proof file with the measurement file and generates an authentication result; the verification sub-application can return the authentication result to the main interface.

[0157] To accommodate passport data flow in remote verification, the communication method may include S5a-3 and S5a-4. It should be understood that both S5a-3 and S5a-4 are optional steps.

[0158] S5a-5: The authentication module can send the authentication result to the target program, the device system of the client device (the device on which the target program is located), or the authentication result manager of the client device (the device on which the target program is located).

[0159] Optionally, the target program may store the authentication result.

[0160] Optionally, the client device's system can select a processing method for the target program based on the authentication result; for example, the client device's processing method for the target program includes: continuing to use the target program, stopping the use of the target program, or uninstalling the target program.

[0161] S5a-6: The authentication module can forward the authentication result to the device system of the dependent party through the device system of the client device (the device where the target program is located).

[0162] Optionally, the dependent device system may select a processing method for the target program based on the certification result; for example, the processing method of the dependent device for the target program may include: approving the installation of the target program or not approving the installation of the target program.

[0163] Optionally, the dependent device system can feed back the processing method to the client device's device system.

[0164] It should be understood that S5a-5 and S5a-6 are optional steps.

[0165] In the communication system shown in Figure 3c, the communication method may include the following S5b-1 to S5b-7 (as shown in Figure 5b).

[0166] S5b-1: The operator equipment stores the measurement file in the storage space through the storage management applet in the verification module via a card reader (for the first write) or over-the-air download (for subsequent updates). The aforementioned S5b-1 can be found in the descriptions of SA1 to SA2, or SB1 to SB2, and will not be repeated here.

[0167] S5b-2: The ERoT in the verification module collects claims in the target program. Furthermore, ERoT can also generate proof documents based on these claims.

[0168] S5b-3: ERoT sends the generated proof file to the target program.

[0169] S5b-4: The target program sends the proof documents to the verification submodule.

[0170] S5b-5: The verification submodule compares the proof file with the measurement file and generates the authentication result for the target program.

[0171] S5b-6: The verification submodule sends the authentication result to the target program, the device system of the client device (the device where the target program resides), or the authentication result manager of the client device (the device where the target program resides). The description of S5b-6 is similar to that of S5a-5 and will not be repeated here.

[0172] S5b-7: The verification submodule can forward the authentication result to the device system of the dependent party through the device system of the client device (the device where the target program resides). The description of S5b-7 can be found in S5a-6, and will not be repeated here.

[0173] The communication systems shown in Figures 4 to 5b are examples using the target program as the target object. The implementation process of other target objects can be similarly referred to, and will not be elaborated on in this application.

[0174] In some other possible examples, as shown in Figure 6, the client device and the dependent device can be routers. Router A (the client device) is configured with a SIM card, and router A can interact with router B (the dependent device).

[0175] In the communication system shown in Figure 6, when the SIM card structure is as described in the aforementioned structure example one, the communication method may include the following S7a-1 to S7a-7 (as shown in Figure 7a). In this communication method, the target object to be verified may be the hardware and / or software in router A.

[0176] S7a-1 to S7a-4 can be parameters S5a-1 to S5a-4 in the aforementioned Figure 5a.

[0177] S7a-5: The authentication module can forward the authentication result to the device system of router B through the device system of router A.

[0178] S7a-6: Based on the authentication result, router B's device system can send processing feedback to router A's device system. For example, the processing feedback may include: accepting router A as a trusted neighbor or not accepting router A as a trusted neighbor.

[0179] In the communication system shown in Figure 6, when the SIM card has the structure of the aforementioned structure example two, the communication method may include the following S7b-1 to S7b-7 (as shown in Figure 7b).

[0180] S7b-1 to S7b-5 can be parameters S5b-1 to S5b-5 in the aforementioned Figure 5b.

[0181] S7b-6 and S7b-7 can be parameters S7b-5 and S7b-6 in the aforementioned Figure 7a.

[0182] In the various embodiments of this application, unless otherwise specified or in case of logical conflict, the terminology and / or descriptions of different embodiments are consistent and can be referenced by each other. The technical features of different embodiments can be combined to form new embodiments according to their inherent logical relationship.

[0183] The methods provided by the embodiments of this application have been described above with reference to the accompanying drawings. The communication devices provided by the embodiments of this application will be described below with reference to the accompanying drawings.

[0184] Based on the same technical concept, this application also provides a communication device for implementing the communication method provided in the above embodiments. Referring to FIG8, the communication device 800 includes a communication module 801 and a processing module 802. The communication module 801 is used to receive and / or send data; the processing module 802 is used to implement the steps in the communication method shown in FIG4.

[0185] Optionally, the communication device 800 also includes a verification module 803; the verification module 803 can call the aforementioned communication module 801 and processing module 802.

[0186] Optionally, the communication device 800 also includes a storage module 804; the aforementioned processing module 802 can call the aforementioned storage module 804 to realize data storage.

[0187] In one possible example, when the communication device 800 is used to implement the function of the verification module shown in FIG4 above, the verification module 803 can perform the following steps based on the communication module 801: obtaining the measurement file of the target object; the communication device 800 and the target object are installed inside the same device; the measurement file is used to indicate the parameter value range that at least one parameter must satisfy when the target object is trustworthy, and at least one parameter is used to represent the characteristics of the target object during operation; the verification module 803 can also perform the following steps based on the communication module 801: obtaining the certification file of the target object, the certification file is used to indicate the parameter values ​​corresponding to at least one parameter when the target object is running inside the device; the verification module 803 can perform the following steps based on the processing module 802: determining the authentication result according to the certification file and the measurement file; the authentication result is used to indicate the trustworthiness of the target object.

[0188] In one possible design, the communication device 800 is located in the SIM card inside the device.

[0189] In one possible design, the communication device 800 is an ERoT.

[0190] In one possible design, the communication device 800 includes an ERoT and a verification submodule; the aforementioned process of obtaining the proof document of the target object may include: the ERoT generating the proof document of the target object; the aforementioned process of determining the authentication result based on the proof document and the measurement document may include: the verification submodule determining the authentication result based on the proof document and the measurement document obtained by the ERoT.

[0191] In one possible design, the verification submodule can also receive proof files generated by ERoT forwarded by the target object.

[0192] In one possible design, the communication module 801 is specifically used to: obtain a measurement file of the target object from the user identification module SIM card inside the device; the SIM card pre-stores at least one measurement file corresponding to each object, and the at least one object includes the target object.

[0193] In one possible design, the measurement file corresponding to at least one object is stored in the SIM card based on the initial configuration information of the SIM card; or, the measurement file corresponding to at least one object is stored in the SIM card based on the updated configuration information of the SIM card.

[0194] In one possible design, the verification module 803 may also perform the following steps based on the processing module 802: output or display the authentication result; or, the verification module 803 may also perform the following steps based on the communication module 801: send the authentication result.

[0195] In one possible design, the communication module 801 is specifically used for: signing the authentication result; and sending the signed authentication result.

[0196] In one possible example, when the communication device 800 is used to implement the functions of the client device shown in FIG4 above, the processing module 802 is used to perform the following steps based on the communication module 801: receiving first configuration information from the operator equipment, the first configuration information being used to indicate at least one measurement file corresponding to each of the at least one object; the at least one object includes a target object; the measurement file of the target object is used to indicate the parameter value range that at least one parameter must satisfy when the target object is trusted, the at least one parameter being used to represent the characteristics of the target object during operation; the measurement file of the target object is used by the verification module to determine the authentication result of the target object, the authentication result being used to indicate the trustworthiness of the target object; the target object is any one of the at least one objects, and the at least one object is installed in the communication device 800; the processing module 802 is used to perform the following steps based on the storage module 804: storing the measurement files corresponding to at least one object in the communication device 800 according to the first configuration information.

[0197] Optionally, the processing module 802 is also used to trigger the verification module 803 to perform the following steps: determine the authentication result of the target object based on the target object's measurement file, and the authentication result is used to indicate the trustworthiness of the target object.

[0198] In one possible design, the aforementioned communication module 801 is further configured to: receive second configuration information from the operator equipment; the second configuration information is used to instruct the updating of the measurement files corresponding to at least one object respectively; the update includes at least one of the following: deleting the measurement files corresponding to one or more of the at least one object; replacing the measurement files corresponding to one or more of the at least one object; configuring the corresponding measurement files for one or more objects added based on at least one object.

[0199] In one possible design, the method shown in the second aspect is specifically applied to a SIM card installed in the communication device 800, and the verification module is located in the SIM card.

[0200] In one possible design, the aforementioned communication module 801 is further configured to: receive first instruction information from the operator equipment, the first instruction information being used to instruct the communication device 800 to install the verification module; the aforementioned processing module 802 is further configured to: install the verification module according to the first instruction information; the verification module is configured to determine the authentication result of the target object according to the target object's measurement file, the authentication result being used to indicate the trustworthiness of the target object.

[0201] In one possible design, the aforementioned communication module 801 is further configured to: receive identity verification information from the verification module of the operator equipment, so that the verification module can sign the authentication result of the target object based on the identity verification information.

[0202] In one possible example, when the communication device 800 is used to implement the functions of the operator equipment shown in FIG4 above, the processing module is used to: generate first configuration information, the first configuration information being used to indicate the measurement files corresponding to at least one object; at least one object includes a target object; the measurement file of the target object is used to indicate the parameter value range that at least one parameter must satisfy when the target object is trusted, and at least one parameter is used to represent the characteristics of the target object during operation; the target object is any one of the at least one objects, and the at least one object is installed in the client; the communication module 801 is used to: send the aforementioned first configuration information to the client device.

[0203] In one possible design, the communication module 801 is further configured to: send second configuration information to a client device; the second configuration information is used to instruct the updating of the measurement files corresponding to at least one object; the update includes at least one of the following: deleting the measurement files corresponding to one or more of the at least one object; replacing the measurement files corresponding to one or more of the at least one object; configuring the corresponding measurement files for one or more objects added based on at least one object.

[0204] In one possible design, the communication module 801 is further configured to: send a first indication message to a client device, the first indication message being used to instruct the client device to install a verification module; the verification module being used to determine the authentication result of the target object based on the target object's measurement file, the authentication result being used to indicate the trustworthiness of the target object.

[0205] In one possible design, the communication module 801 is also used to: send the identity verification information of the verification module installed in the client device to the client device, so that the verification module signs the authentication result of the target object based on the identity verification information.

[0206] Based on the same technical concept, this application also provides another communication device 900, which can implement the communication method provided in the above embodiments. Referring to FIG9, the communication device 900 includes a processor 901. Optionally, the communication device 900 further includes a memory 902 and / or a communication interface 903. The memory can be placed inside or outside the communication device, and this application does not limit this. The communication interface 903, the processor 901, and the memory 902 are interconnected. Exemplarily, the communication device 900 can be the verification module shown in the embodiments of this application.

[0207] Optionally, the communication interface 903, the processor 901, and the memory 902 are interconnected via a bus 904. The bus 904 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of illustration, only one thick line is used in Figure 9, but this does not indicate that there is only one bus or one type of bus.

[0208] The communication interface 903 is used to receive and / or send signals to enable communication with other devices besides the communication device.

[0209] The processor 901 can be used to execute the communication method shown in Figure 4 above. This communication method is described in the above embodiments and will not be elaborated here. The processor 901 can be a central processing unit (CPU), a network processor (NP), or a combination of a CPU and an NP, etc. The processor 901 may further include a hardware chip. The hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof. When implementing the above functions, the processor 901 can be implemented in hardware, or it can be implemented by executing corresponding software.

[0210] The memory 902 is used to store program instructions, etc. Specifically, the program instructions may include program code, which includes computer operation instructions. The memory 902 may include random access memory (RAM) and may also include non-volatile memory, such as at least one disk storage device. The processor 901 executes the program instructions stored in the memory 902 to implement the above functions, thereby implementing the method provided in the above embodiments.

[0211] Based on the same technical concept, this application also provides a computer program that, when run on a computer, causes the computer to execute the methods provided in the above embodiments.

[0212] Based on the same technical concept, embodiments of this application also provide a computer-readable storage medium storing a computer program that, when run on a computer, causes the computer to perform the methods provided in the above embodiments.

[0213] The storage medium can be any available medium that a computer can access. For example, but not limited to, a computer-readable medium can include RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage media or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.

[0214] Based on the same technical concept, this application also provides a chip for reading a computer program stored in a memory to implement the method provided in the above embodiments.

[0215] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0216] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more blocks of the flowchart illustrations and / or one or more blocks of the block diagrams.

[0217] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.

[0218] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.

[0219] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. A communication method, characterized in that, Applied to the verification module, the method includes: Obtain the measurement file of the target object; the verification module and the target object are installed inside the same device; the measurement file is used to indicate the parameter value range that at least one parameter must satisfy when the target object is trustworthy, and the at least one parameter is used to represent the characteristics of the target object during operation; Obtain a certification document for the target object, the certification document being used to indicate the parameter values ​​corresponding to at least one parameter when the target object is running inside the device; The authentication result is determined based on the supporting documentation and the measurement documentation; the authentication result is used to indicate the trustworthiness of the target object.

2. The method as described in claim 1, characterized in that, The verification module is located in the user identification module SIM card inside the device.

3. The method as described in claim 2, characterized in that, The verification module is an embedded root of trust (ERoT).

4. The method as described in claim 2, characterized in that, The verification module includes ERoT and a verification submodule; The step of obtaining the proof file of the target object includes: the ERoT generating the proof file of the target object; The step of determining the authentication result based on the proof document and the measurement document includes: the verification submodule determining the authentication result based on the measurement document and the proof document obtained by the ERoT.

5. The method as described in claim 4, characterized in that, Also includes: The verification submodule receives the proof document generated by the ERoT and forwarded by the target object.

6. The method according to any one of claims 1-5, characterized in that, Obtain the measurement file of the target object, including: The measurement file of the target object is obtained from the SIM card inside the device; the SIM card pre-stores measurement files corresponding to at least one object, and the at least one object includes the target object.

7. The method as described in claim 6, characterized in that, The measurement files corresponding to the at least one object are stored in the SIM card based on the initial configuration information of the SIM card; or, the measurement files corresponding to the at least one object are stored in the SIM card based on the updated configuration information of the SIM card.

8. The method according to any one of claims 1-7, characterized in that, The method further includes: Output or display the authentication result; or, Send the authentication result.

9. The method as described in claim 8, characterized in that, The sending of authentication results includes: Sign the authentication result; Send the authentication result after signing.

10. A communication method, characterized in that, Applied to a client device, the client device including a verification module, the method includes: The system receives first configuration information from an operator device. This first configuration information indicates a measurement file corresponding to at least one object. The at least one object includes a target object. The measurement file of the target object indicates the range of parameter values ​​that at least one parameter must satisfy when the target object is trusted. The at least one parameter represents a characteristic of the target object during operation. The measurement file of the target object is used by the verification module to determine the authentication result of the target object, and the authentication result indicates the trustworthiness of the target object. The target object is any one of the at least one objects, and the at least one object is installed in the client device. Based on the first configuration information, store the measurement files corresponding to each of the at least one object.

11. The method as described in claim 10, characterized in that, Also includes: Receive second configuration information from the operator equipment; the second configuration information is used to instruct the updating of the measurement files corresponding to the at least one object; the update includes at least one of the following: Delete the measurement file corresponding to one or more of the at least one object; Replace the metric file corresponding to one or more of the at least one object; Configure the corresponding metric file for one or more new objects added based on the at least one object.

12. The method as described in claim 10 or 11, characterized in that, The method is specifically applied to the user identification module SIM card installed in the client device, and the verification module is set in the SIM card.

13. The method according to any one of claims 10-12, characterized in that, Also includes: Receive a first instruction information from the operator equipment, the first instruction information being used to instruct the client device to install the verification module; Install the verification module according to the first instruction information.

14. The method according to any one of claims 10-13, characterized in that, Also includes: The authentication module receives identity verification information from the operator's equipment, so that the authentication module signs the authentication result of the target object based on the identity verification information.

15. A communication method, characterized in that, Applied to carrier equipment, the method includes: Generate first configuration information, which is used to indicate the measurement files corresponding to the at least one object; the at least one object includes a target object; the measurement file of the target object is used to indicate the parameter value range that at least one parameter must satisfy when the target object is trusted, and the at least one parameter is used to represent the characteristics of the target object during operation; the target object is any one of the at least one objects, and the at least one object is installed in the client device. The first configuration information is sent to the client device.

16. The method as described in claim 15, characterized in that, Also includes: Send second configuration information to the client device; the second configuration information is used to instruct the updating of the measurement files corresponding to the at least one object; the update includes at least one of the following: Delete the measurement file corresponding to one or more of the at least one object; Replace the metric file corresponding to one or more of the at least one object; Configure the corresponding metric file for one or more new objects added based on the at least one object.

17. The method as described in claim 15 or 16, characterized in that, The method further includes: A first instruction message is sent to the client device, the first instruction message being used to instruct the client device to install a verification module; the verification module is used to determine the authentication result of the target object based on the target object's measurement file, the authentication result being used to indicate the trustworthiness of the target object.

18. The method as described in claim 17, characterized in that, Also includes: The authentication module sends its identity verification information to the client device, so that the authentication module signs the authentication result of the target object based on the identity verification information.

19. A communication device, characterized in that, Includes a module for performing the method as described in any one of claims 1-9.

20. A communication device, characterized in that, include: Communication module, storage module, processing module, and verification module; The communication module is used to receive and / or send data; The storage module is used to store data; The processing module is configured to perform the operation of receiving information from the operator equipment in the method as described in any one of claims 10-14 based on the communication module, and to trigger the verification module to perform the operation of determining the authentication result of the target object based on the measurement file of the target object in the method as described in any one of claims 10-14, wherein the authentication result is used to indicate the trustworthiness of the target object.

21. A communication device, characterized in that, include: Communication module and processing module; The communication module is used to receive and / or send data; The processing module is configured to execute the method as described in any one of claims 15-18 based on the communication module.

22. A communication device, characterized in that, include: At least one processor; The at least one processor is configured to execute computer-executable program code or instructions to implement the method as described in any one of claims 1-9, or the method as described in any one of claims 10-14; or the method as described in any one of claims 15-18.

23. The apparatus as claimed in claim 22, characterized in that, It also includes a memory for storing the computer-executable program code or instructions.

24. A communication system, characterized in that, include: The system includes a verification module, a client device, and a carrier device, wherein the verification module is located inside the carrier device. The verification module is used to perform the method as described in any one of claims 1-9; The client device is used to perform the method as described in any one of claims 10-14; The operator equipment is used to perform the method as described in any one of claims 15-18.

25. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions that, when invoked by a computer, cause the computer to perform the method as described in any one of claims 1-9, or the method as described in any one of claims 10-14, or the method as described in any one of claims 15-18.

26. A computer program product, characterized in that, The computer program product stores computer-executable instructions, which, when invoked by a computer, cause the computer to perform the method as described in any one of claims 1-9, or the method as described in any one of claims 10-14, or the method as described in any one of claims 15-18.

27. A chip, characterized in that, The chip includes a processor. The processor is configured to execute computer-executable program code or instructions to implement the method as described in any one of claims 1-9, or the method as described in any one of claims 10-14; or the method as described in any one of claims 15-18.

Citation Information

Patent Citations

  • Data processing method, system and device, equipment and medium

    CN116401655A

  • Remote attestation method, device and system

    CN116502188A

  • Trusted verification method and device

    CN116842517A

  • Data processing method and device based on trusted execution environment, equipment and medium

    CN116980163A

  • Remote attestation method and device, electronic equipment and storage medium

    CN117834627A