Communication method and apparatus
By verifying the trustworthiness of the target object through the verification module inside the client device and the SIM card or ERoT, the dependence on network connection in remote authentication technology is resolved, and efficient and reliable trustworthiness judgment is achieved.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-06-10
- Publication Date
- 2026-03-26
AI Technical Summary
Existing remote verification technologies require data interaction between the verifier and the verifier via a network connection, which leads to connection limitations and affects the flexibility and efficiency of trust verification.
A verification module is deployed inside the client device, using a SIM card or ERoT to verify the trustworthiness of the target object. The reliance on network connectivity is reduced through internal data interaction within the device, and the verification module is endorsed by a trusted operator device to increase trustworthiness.
It enables the verification of the trustworthiness of target objects without relying on network connections, improving the accuracy and flexibility of verification, reducing connection restrictions, and enhancing the credibility of verification results.
Smart Images

Figure CN2025100184_26032026_PF_FP_ABST
Abstract
Description
Communication method and apparatus
[0001] Cross-reference to related applications
[0002] This application claims priority to the Chinese patent application No. 202410920959.0, filed on July 10, 2024, and entitled “A communication method and apparatus”, the entire contents of which are incorporated herein by reference. TECHNICAL FIELD
[0003] The present application relates to the field of communication, and in particular to a communication method and apparatus. BACKGROUND
[0004] In order to verify the trustworthiness of a remote entity, a security technology of remote attestation is proposed in the field of communication. In the remote attestation architecture, three roles are mainly involved: a relying party, an attester, and a verifier. The currently disclosed remote attestation technologies include the following one: the data flow of remote attestation proposed in the Internet Engineering Task Force (IETF) Request for Comments (RFC) 9334 standard, the passport data flow in remote attestation, and the background-check data flow in remote attestation.
[0005] In the remote attestation technology including any of the foregoing data flows, the attested party installed with a target program (or referred to as a target entity) needs to be connected (for example, network connection or Bluetooth connection) to the verifier to realize the verification of the trustworthiness of the target program. In this way, the remote attestation technology is limited by the connection between the verifier and the attested party. SUMMARY
[0006] Embodiments of the present application provide a communication method and apparatus for reducing the connection limitation in the remote attestation technology.
[0007] In a first aspect, the present application provides a communication method, which can be applied to a verification module in a client device. The verification module can be a processor, a chip, a chip system, a circuit or a software module, etc. The method can include: obtaining, by the verification module, a measurement file of a target object; the verification module and the target object are installed in the same device (e.g. the client device); the measurement file is used to indicate a parameter value range that at least one parameter needs to meet when the target object is trusted, and the at least one parameter is used to represent a feature of the target object in a running process; obtaining, by the verification module, a proof file of the target object, the proof file being used to indicate a parameter value corresponding to the at least one parameter when the target object runs in the device; determining, by the verification module, an authentication result according to the proof file and the measurement file; and the authentication result is used to indicate the trustworthiness of the target object.
[0008] In this way, the verification module and the target object are installed in the same device, and the verification module can determine the trustworthiness of the target object according to the measurement file and the proof file. Different from the scheme in which the verification module and the target object are installed in different devices, the device in which the verification module is located does not need to interact with the device in which the target object is located to complete the trustworthiness verification, so that the connection limitation in the remote proof technology can be reduced.
[0009] In a possible design, the verification module can be arranged in a subscriber identity module (SIM) card in the device. In this way, the function of the verification module can be supported by the SIM card, and the SIM card is backed by a trusted operator device, so that the trustworthiness of the verification module is increased, and the trustworthiness of the authentication result determined by the verification module is increased.
[0010] In a possible design, the verification module can be an embedded root of trust (ERoT). In this way, the function of determining the authentication result according to the measurement file and the proof file can be integrated on the ERoT, and the trustworthiness of the authentication result determined by the verification module is further increased.
[0011] In a possible design, the verification module can include an ERoT and a verification submodule; the process of obtaining the attestation file of the target object can include: the ERoT generating the attestation file of the target object; and the process of determining the authentication result according to the attestation file and the measurement file can include: the verification submodule determining the authentication result according to the attestation file and the measurement file obtained by the ERoT. In this way, the ERoT can generate the attestation file of the target object, and the verification submodule can implement the function of determining the authentication result according to the measurement file and the attestation file; only the definition and specification of the verification submodule (including the obtaining of the measurement file and the determination of the authentication result) need to be designed, and the definition and specification of the ERoT do not need to be changed.
[0012] In a possible design, the verification submodule can further receive the attestation file generated by the ERoT and forwarded by the target object. In this way, the verification submodule interacts with the target object, can adapt to the passport data flow in remote attestation, and improves the applicability of the communication method.
[0013] In a possible design, the process of obtaining the measurement file of the target object can include: the verification module obtaining the measurement file of the target object in a SIM card in the device; and the measurement file corresponding to at least one object is pre-stored in the SIM card, the at least one object including the target object. In this way, the verification module can obtain the measurement file of the target object from the SIM card, so as to determine the trustworthiness of the target object, without interacting with an external device, and reducing the connection restriction in remote attestation technology.
[0014] In a possible design, the measurement file corresponding to the at least one object is stored in the SIM card according to initial configuration information of the SIM card; or the measurement file corresponding to the at least one object is stored in the SIM card according to update configuration information of the SIM card.
[0015] In a possible design, the verification module can further output or display the authentication result; or the verification module can further send the authentication result. In this way, the verification module can output or display the authentication result of the target object to a user, or can send the authentication result of the target object to another device for viewing, so that the authentication result is more intuitive for the user to obtain.
[0016] In a possible design, the process of sending the authentication result can include: the verification module signing the authentication result; and the verification module sending the signed authentication result. In this way, the verification module can sign the authentication result before sending it to another device, so that the authentication result is not easy to be tampered with, and the security of the authentication result is improved.
[0017] In a second aspect, the present application provides a communication method, which is applied to a client device, or a component (such as a processor, a chip, a chip system, a circuit or other, etc.) or a software module in the client device, or a verification module. Taking the method applied to the client device as an example, the method can include: receiving, by the client device, first configuration information from an operator device, the first configuration information being used to indicate a measurement file corresponding to each of at least one object; the at least one object including a target object; the measurement file of the target object being used to indicate a parameter value range that at least one parameter needs to meet respectively, the at least one parameter being used to represent a feature of the target object in a running process; the measurement file of the target object being used for the verification module to determine an authentication result of the target object, the authentication result being used to indicate the trustworthiness of the target object; the target object being any one of the at least one object, the at least one object being installed in the client device respectively; and storing, by the client device, the measurement file corresponding to each of the at least one object according to the first configuration information.
[0018] In this way, the client device can receive and pre-store the measurement file of at least one object including a target object issued by the operator, so that the verification module in the client device can determine the authentication result of the target object based on the measurement file of the target object inside the device; in the process of obtaining the measurement file by the verification module, no interaction with external devices is needed, and the connection limitation in the remote attestation technology is reduced.
[0019] In a possible design, the client device can further receive second configuration information from the operator device; the second configuration information being used to indicate an update on the measurement file corresponding to each of the at least one object; the update including at least one of the following: deleting the measurement file corresponding to one or more objects in the at least one object; replacing the measurement file corresponding to one or more objects in the at least one object; and configuring a measurement file corresponding to one or more objects that are newly added on the basis of the at least one object. In this way, the client device can update the pre-stored measurement file corresponding to each of the at least one object through the second configuration information from the operator device.
[0020] In a possible design, the method shown in the second aspect is specifically applied to a SIM card installed in the client device, and the verification module is arranged in the SIM card. In this way, the measurement file required by the verification module is stored in the SIM card, and the SIM card is endorsed by a trusted operator device, so that the measurement file is not easy to be tampered with, and the trustworthiness of the authentication result determined by the verification module is increased.
[0021] In a possible design, the client device can further receive first indication information from the operator device, where the first indication information is used to instruct the client device to install the verification module; and the client device can further install the verification module according to the first indication information, so that the installed verification module can determine the authentication result of the target object according to the measurement file of the target object, where the authentication result is used to indicate the trustworthiness of the target object. In this way, the function of the verification module can be supported by the operator device, and the trustworthiness of the verification module is increased, thereby increasing the trustworthiness of the authentication result determined by the verification module.
[0022] In a possible design, the client device can further receive identity information of the verification module from the operator device, so that the verification module can sign the authentication result of the target object based on the identity information. In this way, the client device can obtain the identity information of the verification module, so that the verification module can sign the authentication result, thereby improving the security of the authentication result in the transmission process.
[0023] In a third aspect, this application provides a communication method, which is applied to an operator device, or a component (such as a processor, a chip, a chip system, a circuit or other components) in the operator device, or a software module. Taking the case that the method is applied to the operator device as an example, the method can include: the operator device generates first configuration information, where the first configuration information is used to instruct measurement files corresponding to at least one object respectively; the at least one object includes a target object; the measurement file of the target object is used to indicate a parameter value range that at least one parameter respectively needs to meet, where the at least one parameter is respectively used to represent a feature of the target object in a running process; the target object is any one of the at least one object, and the at least one object is respectively installed in a client device; and the operator device sends the first configuration information to the client device.
[0024] In a possible design, the operator device can further send second configuration information to the client device, where the second configuration information is used to instruct to update the measurement files corresponding to the at least one object respectively; and the update includes at least one of the following: deleting the measurement files corresponding to one or more objects in the at least one object; replacing the measurement files corresponding to one or more objects in the at least one object; and configuring the measurement files corresponding to one or more objects that are newly added on the basis of the at least one object.
[0025] In a possible design, the operator device can further send first indication information to the client device, where the first indication information is used to instruct the client device to install a verification module; and the verification module is used to determine an authentication result of the target object according to the measurement file of the target object, where the authentication result is used to indicate the trustworthiness of the target object.
[0026] In a possible design, the operator device can further send identity information of the verification module installed in the client device to the client device, so that the verification module signs the authentication result of the target object based on the identity information.
[0027] In a fourth aspect, the present application provides a communication apparatus. The communication apparatus can execute the method in the first aspect or any possible design of the first aspect. The communication apparatus can be a chip or circuit capable of performing the functions corresponding to the method, or a device including the chip or circuit.
[0028] In a possible design, the communication apparatus includes a verification module, which is configured to perform the method in any possible design of the first aspect. The foregoing functions can be implemented or executed through hardware, or implemented or executed through a combination of hardware and software.
[0029] In a fifth aspect, the present application provides a communication apparatus. The communication apparatus can execute the method in the second aspect or any possible design of the second aspect. The communication apparatus can be a chip or circuit capable of performing the functions corresponding to the method, or a device including the chip or circuit.
[0030] In a possible design, the communication apparatus includes a communication module, a storage module, a processing module and a verification module. The communication module is configured to receive and / or send data. The storage module is configured to store data. The processing module is configured to perform the operation of receiving the information of the operator device in the second aspect and any possible design of the second aspect based on the communication module, and trigger the verification module to perform the operation of determining the authentication result of the target object based on the measurement file of the target object in the second aspect and any possible design of the second aspect, where the authentication result is used to indicate the trustworthiness of the target object.
[0031] In a sixth aspect, the present application provides a communication apparatus. The communication apparatus can execute the method in the third aspect or any possible design of the third aspect. The communication apparatus can be a chip or circuit capable of performing the functions corresponding to the method, or a device including the chip or circuit.
[0032] In a possible design, the communication apparatus includes a communication module and a processing module. The communication module is configured to receive and / or send data. The processing module is configured to perform the method in any possible design of the third aspect based on the communication module. The foregoing functions can be implemented through hardware, or implemented through hardware executing corresponding software. The hardware or software includes one or more units corresponding to the foregoing functions.
[0033] In a seventh aspect, the present application provides a communication apparatus. The communication apparatus can implement the method in any of the possible designs of the first aspect, the second aspect or the third aspect. The communication apparatus comprises a processor. When the processor executes instructions, the communication apparatus or a device in which the communication apparatus is installed performs the method in any of the possible designs of the first aspect, the second aspect or the third aspect.
[0034] Optionally, the communication apparatus can further comprise a memory for storing computer executable program code, which can comprise the aforementioned instructions. The memory can be located inside the communication apparatus or outside the communication apparatus, which is not limited in the present application. The memory can be coupled with the processor.
[0035] Optionally, if the communication apparatus is a chip or a circuit, the communication interface can be an input / output interface of the chip, such as an input / output pin.
[0036] In an eighth aspect, the present application provides a communication system, which comprises at least one of the following: a verification module for implementing the method of the first aspect, a client device for implementing the method of the second aspect, an operator device for implementing the method of the third aspect, and the verification module is located inside the operator device.
[0037] In a ninth aspect, the present application provides a computer readable storage medium, which stores a computer program. When the computer program is run on a computer, the computer program makes the computer execute the method in any of the possible designs of the first aspect, the second aspect or the third aspect.
[0038] In a tenth aspect, the present application provides a computer program product, which stores computer executable instructions. When the computer executable instructions are invoked by a computer, the computer executable instructions make the computer execute the method in any of the possible designs of the first aspect, the second aspect or the third aspect.
[0039] In an eleventh aspect, the present application provides a chip, which comprises a processor for executing the method in any of the possible designs of the first aspect, the second aspect or the third aspect. Optionally, the chip can further comprise a communication interface for inputting and / or outputting signaling or data. Optionally, the chip can further comprise a memory for storing the aforementioned computer program; the processor is coupled with the memory, and the processor can read the computer program stored in the memory to execute the method in any of the possible designs of the first aspect, the second aspect or the third aspect.
[0040] In addition, the technical effects brought by the third aspect to the eleventh aspect can be referred to the description of each possible solution in the first aspect or the second aspect, which will not be repeated here. BRIEF DESCRIPTION OF DRAWINGS
[0041] FIG. 1 is a schematic diagram of an architecture of a communication system according to an embodiment of the present application;
[0042] FIG. 2a is a schematic diagram of a structure of a client device according to an embodiment of the present application;
[0043] FIG. 2b is a schematic diagram of another structure of a client device according to an embodiment of the present application;
[0044] FIG. 3a is a schematic diagram of an architecture of a communication system according to an embodiment of the present application;
[0045] FIG. 3b is a schematic diagram of another architecture of a communication system according to an embodiment of the present application;
[0046] FIG. 3c is a schematic diagram of another architecture of a communication system according to an embodiment of the present application;
[0047] FIG. 4 is a schematic diagram of a flow of a communication method according to an embodiment of the present application;
[0048] FIG. 5a is a schematic diagram of a communication method according to an embodiment of the present application;
[0049] FIG. 5b is a schematic diagram of another communication method according to an embodiment of the present application;
[0050] FIG. 6 is a schematic diagram of another architecture of a communication system according to an embodiment of the present application;
[0051] FIG. 7a is a schematic diagram of another communication method according to an embodiment of the present application;
[0052] FIG. 7b is a schematic diagram of another communication method according to an embodiment of the present application;
[0053] FIG. 8 is a schematic diagram of a structure of a communication apparatus according to an embodiment of the present application;
[0054] FIG. 9 is a schematic diagram of another structure of a communication apparatus according to an embodiment of the present application. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solutions and beneficial effects of the present application clearer, further detailed description will be made to the present application in combination with the drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application, and are not used to limit the present application.
[0056] In the description of the present application, unless otherwise specified, " / " means or, for example, A / B can mean A or B; "and / or" in the present application only describes the relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can mean: A exists alone, A and B exist together, and B exists alone. In addition, in the description of the present application, "at least one" means one or more, and "more" means two or more. In the description of the present application, "first", "second", etc. are used only for the purpose of distinguishing the description, and cannot be understood as indicating or implying relative importance, nor can it be understood as indicating or implying order.
[0057] In order to better illustrate the scheme of the present application, the technical terms related to the present application are explained as follows:
[0058] 1. SIM card: is mainly used for storing user identity recognition data, short message data and telephone number smart card.
[0059] 2. Trusted execution environment (TEE): is a secure area in the central processor, which can ensure that the programs and data therein are protected in terms of confidentiality and integrity.
[0060] 3. Trusted platform module (TPM): is a kind of microchip, which is designed to provide basic functions related to security, mainly involving encryption keys.
[0061] Among them, TPM includes SIM TPM, firmware-based trusted platform module (fTPM) and virtual trusted platform module (vTPM). SIM TPM is a TPM realized by replacing the mobile TPM based on the SIM card available in the mobile platform. fTPM is a TPM running in the CPU trusted execution environment based on firmware. vTPM is provided by the virtual machine monitor in the isolated execution environment and depends on the virtual machine monitor. The isolated execution environment hides the software running in the virtual machine to protect its code from the influence of the software in the virtual machine.
[0062] 4. Read only memory (ROM): is a kind of semiconductor memory, which is characterized by being unable to be rewritten or deleted once the data is stored in its body, but the stored content will not be lost due to power off.
[0063] 5、Electrically erasable programmable read only memory (EEPROM): A type of ROM that can be electronically rewritten many times.
[0064] 6、The terminal device can be a device capable of receiving network device scheduling and indication information, providing voice and / or data connectivity for users, or a handheld device with wireless connection function, or other processing devices connected to a wireless modem, or a station (STA) device. The terminal device can communicate with one or more core networks or the Internet through a radio access network (RAN). For example, the terminal device can be a portable, pocket, handheld, built-in, or vehicle-mounted mobile device. The terminal device can also be referred to as a subscriber unit, a subscriber station (SS), a mobile station (MS), a remote station, an access point (AP), a remote terminal, an access terminal, a user agent, a customer premises equipment (CPE), a terminal, a user equipment (UE), a mobile terminal (MT), etc. The terminal device can also be a wearable device. The terminal device can also be a device in a next-generation communication system. For example, a terminal device in a 5G network or a terminal device in a future evolved PLMN network, a terminal device in a new radio (NR) communication system, etc.At present, the terminal device can be: a mobile phone, a tablet computer, a notebook computer, a palm computer, a desktop computer, a customer-premises equipment (CPE), a mobile internet device (MID), a wearable device (for example, a smart watch, a smart bracelet, a pedometer, etc.), a vehicle-mounted device (for example, a car, a bicycle, an electric vehicle, an airplane, a ship, a train, a high-speed rail, etc.), a virtual reality (VR) device, an augmented reality (AR) device, a wireless terminal in industrial control, a smart home device (for example, a refrigerator, a television, an air conditioner, an electricity meter, etc.), a smart robot, a workshop device, a wireless terminal in self driving, a wireless terminal in remote medical surgery, a wireless terminal in a smart grid, a wireless terminal in transportation safety, a wireless terminal in a smart city, or a wireless terminal in a smart home, a flight device (for example, a smart robot, a hot air balloon, a drone, an airplane), etc. The terminal device can also be other devices with terminal functions, for example, the terminal device can also be a device that plays a terminal function in D2D communication.
[0065] 7、Network device is an entity in the network side for transmitting or receiving signals. For example, a transmission reception point (TRP), a gNB. The network device can be an AP in a wireless local area network (WLAN), a global system for mobile communication (GSM) or a base station (BS); wherein the base station can be a base transceiver station (BTS) in code division multiple access (CDMA), a base station (nodeB, NB) in wideband code division multiple access (WCDMA), or an evolutional node B (eNB or eNodeB) in long term evolution (LTE). The network device can also be a relay station or an access point, or a vehicle-mounted device, a wearable device, and a network device in a 5G network, or a network device in a future evolved PLMN, or a gNodeB / gNB and the like in an NR system. In some deployments, the gNB can include a centralized unit (CU) and a distributed unit (DU). The CU implements part of the functions of the gNB, and the DU implements part of the functions of the gNB. Illustratively, the CU is responsible for processing non-real-time protocols and services. For example, implementing radio resource control (RRC), service data adaptation protocol (SDAP) functions, functions of the packet data convergence protocol (PDCP) layer, etc. The DU is responsible for processing the physical layer protocol and real-time services. For example, implementing functions of the radio link control (RLC) layer, the medium access control (MAC) layer and the physical (PHY) layer, etc. The gNB can also include an active antenna unit (AAU). The AAU implements part of the physical layer processing functions, radio frequency processing and related functions of the active antenna. Since the information of the RRC layer will eventually become the information of the PHY layer, or be converted from the information of the PHY layer.Thus, in this architecture, high layer signaling (e.g., RRC layer signaling) can also be considered as being sent by the DU, or by the DU and the AAU. It can be understood that the network device can be a device including one or more of the CU node, the DU node, and the AAU node. In addition, the CU can be a network device in a radio access network (RAN), and the CU can be a network device in a core network (CN), which is not limited in the present application. In addition, in the embodiments of the present application, the network device serves a cell, and a terminal device communicates with the network device through a transmission resource (e.g., a frequency domain resource, or a spectrum resource) used by the cell. The cell can be a cell corresponding to the network device (e.g., a base station). The cell can belong to a macro base station or a base station corresponding to a small cell. Exemplarily, the small cell can include a metro cell, a micro cell, a pico cell, a femto cell, and the like. Since the small cell has the characteristics of small coverage and low transmit power, the small cell can provide high-rate data transmission services. In addition, in other possible cases, the network device can be another device providing wireless communication functions for the terminal device. The embodiments of the present application do not limit the specific technology and specific device form of the network device. For example, in an open radio access network (ORAN) system, the CU can also be referred to as an O-CU (open CU), the DU can also be referred to as an O-DU, the CU-CP can also be referred to as an O-CU-CP, the CU-UP can also be referred to as an O-CU-UP, and the RU can also be referred to as an O-RU. For the convenience of description, the CU, the CU-CP, the CU-UP, the DU, and the RU are taken as examples for description in the present application. Any one of the CU (or the CU-CP, the CU-UP), the DU, and the RU in the present application can be implemented by a software module, a hardware module, or a combination of a software module and a hardware module.
[0066] For example, the network device can be a cellular network base station or a router. The router is a hardware device that connects two or more networks and serves as a gateway between networks, is a special intelligent network device that reads the address in each data packet and then decides how to transmit. In the embodiments of the present application, the router is, for example, an internet protocol (IP) bearer network router, a campus network router, and the like.
[0067] 7. EROT: provides functions such as positive random number generation, packet classification rule (PCR) update, signature, key / file trusted storage, etc. through the applet with TPM function in the SIM card.
[0068] In the remote attestation technology, the verifier and the attachee need to be in the state of network connection, such as wireless connection, wired connection, Bluetooth connection, etc. to interact with each other, so as to realize the judgment and proof of the credibility of the attachee. It can be seen that the judgment of the credibility of the attachee in the prior art needs to rely on the network connection, which is relatively limited. In order to reduce the connection limitation in the remote attestation technology, the embodiment of the present application provides a communication system. FIG. 1 is a schematic diagram of a communication system suitable for the embodiment of the present application. The communication system includes a client device and an operator device (or a cellular network operator device). The client device includes a verification module and a target object to be verified (for example, software in a mobile phone, a bootloader in a network device). The client device can be the terminal device described above, or the network device described above. Optionally, the client device can also include other hardware / programs, etc., which are not limited in the present application.
[0069] In the embodiment of the present application, the target object can be understood as a hardware, entity, software, program, configuration, environment, other object to be authenticated or a collection of several objects to be authenticated in the client device.
[0070] In the communication system shown in FIG. 1, the verification module can be deployed in the client device, and the target object to be verified (equivalent to the attachee) is also installed in the same client device. In this way, the verification module in the client device can act as the role of the verifier, and the target object does not need to pass through the network connection, but can realize the verification of the legality or credibility of the target object through the data interaction in the device, thereby overcoming the limitation that the verification process needs to rely on the network connection mentioned above.
[0071] In some examples, the verification module can be deployed in the SIM card in the client device, and the client device can interact with the operator device through the SIM card to transmit data. With the foregoing design, the function of the verification module is supported by the SIM card (the operator device), so that the verification module is not easy to be tampered with, and the credibility of the verification module is increased. On the basis of overcoming the network connection limitation, the trust degree between the verifier and the attachee can be further improved, so that the verification accuracy is higher.
[0072] In some examples, the verification module can also be deployed in other locations inside the client device other than the SIM card. The client device can interact with the operator device to transmit data. For example, the client device can set data modification permissions at the location where the verification module is deployed, so that the data at this location can only be updated by partially trusted devices, i.e., a user with lower permissions cannot change the data at this location, thereby ensuring that the verification module is supported by a trusted device and providing the trustworthiness of the verification module.
[0073] The verification module is described in the following description as an example of being deployed in a SIM card, but this does not constitute a limitation on the location where the verification module is deployed. The structure of the verification module deployed in other locations and the communication method after the verification module is deployed in other locations can be referred to the example of the verification module being deployed in a SIM card.
[0074] Optionally, the SIM card can be a super SIM card. In the communication method shown in the present application, the verification module can need to pre-store a large amount of data (such as the measurement file of multiple objects) locally, so there is a certain requirement for the storage space of the verification module. In this way, since the super SIM card has a larger storage space, the problem of limited storage space of the verification module is avoided.
[0075] It can be understood that the verification module can be deployed in the SIM card in various forms (such as in the form of a small program), and the present application does not specifically limit it. The following are two structural examples of the SIM card provided by the present application as an example.
[0076] Structural example one: the SIM card includes a verification module, and the verification module is an ERoT (or SIM TPM). In other words, the function of the verification module in the embodiment of the present application can be integrated in the ERoT.
[0077] Optionally, the ERoT can be bound with a measurement root of trust (RTM) of the client device, thereby ensuring the integrity of the measurement value (such as the declaration value) from the client device. The binding manner includes but is not limited to the following 1 and 2:
[0078] 1. Using the TEE in the client device as a proxy of the ERoT to bind the ERoT and the RTM;
[0079] 2. Binding the ERoT and the RTM by distance binding.
[0080] It should be understood that the binding manner of the ERoT and the RTM can be referred to the conventional technology, and the present application does not limit it.
[0081] Figure 2a is a structural diagram of a client device according to an embodiment of the present application. As shown in Figure 2a, the client device comprises a SIM card comprising a verification module and a target object to be verified. In the following embodiments, the target object is taken as an example of a target program. The target object can be a target hardware, a target environment or other objects. The implementation process is similar to the following implementation process of verifying a target program. In addition, the verification module is taken as an example of an ERoT in the following embodiments.
[0082] Optionally, the verification module can be divided into two functional areas: a proof sub-application and a verification sub-application. Alternatively, the verification module can be divided into three functional areas: a main interface, a proof sub-application and a verification sub-application.
[0083] Structure Example Two: The SIM card comprises a verification module, and the verification module comprises an ERoT and a verification sub-module. In other words, the verification sub-module can interact with the ERoT to jointly implement the functions of the verification module in the embodiments of the present application.
[0084] Figure 2b is a structural diagram of another client device according to an embodiment of the present application. As shown in Figure 2b, the client device comprises a SIM card comprising a verification module and a target object to be verified (the target program is taken as an example in the figure); wherein the verification module comprises an ERoT and a verification sub-module.
[0085] Optionally, in the structural diagram of the client device shown in Figure 2a or Figure 2b, the client device can further comprise a client device system and an authentication result manager.
[0086] Optionally, in the structural diagram of the client device shown in Figure 2a or Figure 2b, the SIM card further comprises a storage module. Optionally, the storage module can be an electrically erasable programmable read only memory (EEPROM) or a flash memory. Optionally, the storage module can be divided into two functional areas: a storage management applet and a storage space. The storage management applet can write, read and delete data in the storage space.
[0087] Based on the communication system shown in Figure 1, and taking a target program as an example of a target object, the present application exemplarily provides the following three designs of communication systems.
[0088] As shown in FIG. 3a, the embodiment of the present application provides a design of a communication system, which includes an operator device (or a golden measurement manager, an endorser, a reference value provider), a client device (including a verification module and a target program to be verified) and a relying party device. The verification module can be placed in a SIM card inside the client device. The structure of the client device can refer to the aforementioned FIG. 2a or FIG. 2b.
[0089] As shown in FIG. 3b, the communication system includes an operator device, a client device (including an authentication result manager, a SIM card including a verification module and a target program to be verified) and a relying party device. The verification module is placed in a SIM card inside the device and the structure of the SIM card is the aforementioned structure example one. The structure of the client device can refer to the aforementioned FIG. 2a.
[0090] As shown in FIG. 3c, the communication system includes an operator device, a client device (including an authentication result manager, a SIM card including a verification module and a target program to be verified) and a relying party device. The verification module is placed in a SIM card inside the device and the structure of the SIM card is the aforementioned structure example two. The structure of the client device can refer to the aforementioned FIG. 2b.
[0091] In order to reduce the connection limitation in the remote attestation technology, the embodiment of the present application provides a communication method. The communication method can be implemented in the communication system shown in the aforementioned FIG. 1, FIG. 3a, FIG. 3b or FIG. 3c.
[0092] The communication method provided by the embodiment of the present application will be introduced below in combination with the accompanying drawings. In the following communication method, the target program is taken as an example of the target object, but it does not constitute a limitation on the present application. FIG. 4 is a communication method provided by the embodiment of the present application, which can include the following steps:
[0093] S401: The verification module obtains a measurement file of the target program. The verification module and the target program are installed inside the same device (for example, the client device shown in FIG. 2a or FIG. 2b). The measurement file is used to indicate the parameter value range (also referred to as the reference value) that at least one parameter needs to meet when the target program is trusted, and the at least one parameter is used to represent the characteristics of the target program in the running process (for example, the hash value of the code of the target program).
[0094] In the embodiment of the present application, the measurement file is also referred to as the golden measurement, the golden measurement value or the golden measurement file.
[0095] Optionally, the metric file can also be used to indicate a judgment basis (or appraisal policy) for judging the trustworthiness of the target program. The judgment basis includes at least one of the following: a priority or weight of each of the at least one parameter, an algorithm for judging the trustworthiness of the target program, and the like. That is, the metric file can indicate the importance of each parameter in judging the trustworthiness of the target program.
[0096] The aforementioned metric file of the target program is used to determine the authentication result of the trustworthiness of the target program.
[0097] In some examples, the authentication result of the trustworthiness of the target program can be a binary result, i.e., absolutely trustworthy or absolutely untrustworthy. The aforementioned "the target program is trustworthy" in S401 can be understood as absolutely trustworthy.
[0098] In other examples, the authentication result of the trustworthiness of the target program can be a multi-element result, i.e., N levels of trustworthiness, N being a positive integer; the aforementioned "the target program is trustworthy" in S401 can be understood as N levels of trustworthiness. Optionally, the greater the value of N, the higher the trustworthiness of the target program; or, the greater the value of N, the lower the trustworthiness of the target program. For example, the metric file can include the following data (the specific parameter value range is not defined in the table and should be determined according to actual conditions):
[0099] Table 1
[0100] In other examples, the authentication result of the trustworthiness of the target program can be a numerical value for representing the degree of trustworthiness.
[0101] Before performing S401, the verification module (or the client device in which the verification module is installed) can pre-store, locally, a metric file corresponding to at least one object, the at least one object including the aforementioned target object; the following describes the storage process by taking a program as the object and by two designs, but does not constitute a limitation on the present application, and the storage process of other objects can refer to the description of the storage process of the program.
[0102] In one possible design, the operator device can generate first configuration information. The first configuration information is used to indicate a metric file corresponding to each of at least one program. The operator device can also send the first configuration information to the client device; correspondingly, the client device can receive the first configuration information from the operator device; and the client device can store the metric file corresponding to each of the at least one program according to the first configuration information.
[0103] Optionally, before the operator device generates the first configuration information, the client device can send a first message to the operator device, the first message being used to indicate the identity of the at least one program. In this way, the operator device can send the first configuration information to the client device according to the demand of the client device for the metric file, so as to avoid the waste of storage space of the client device caused by the redundancy of the metric file.
[0104] That is, the operator device can actively send the first configuration information to the client device, or send the first configuration information to the client device based on the demand (e.g., the first message) of the client device, which is not limited in the present application.
[0105] Further, the operator device can also generate second configuration information. The operator device can also send the second configuration information to the client device, and correspondingly, the client device can also receive the second configuration information from the operator device, wherein the second configuration information is used to indicate the update of the metric file corresponding to the at least one program respectively; the update includes at least one of the following: deleting the metric file corresponding to one or more programs in the at least one program; replacing the metric file corresponding to one or more programs in the at least one program; configuring the metric file corresponding to one or more programs newly added on the basis of the at least one program.
[0106] Optionally, before the operator device generates the second configuration information, the client device can send a second message to the operator device, the second message being used to indicate the identity of the at least one program. In this way, the operator device can send the second metric file to the client device according to the demand of the client device for the metric file, so as to avoid the waste of storage space of the client device caused by the redundancy of the metric file.
[0107] That is, the operator device can actively send the second configuration information to the client device, or send the second configuration information to the client device based on the demand (e.g., the second message) of the client device, which is not limited in the present application.
[0108] The foregoing design can also be applied to the SIM card (including the verification module) installed in the client device.
[0109] In another possible design, the verification module is deployed in the SIM card in the client device, and the SIM card can pre-store the metric file of the at least one program including the target program locally. In this way, the verification module can obtain the metric file of the target program locally.
[0110] Optionally, the SIM card can be a super SIM card. In this way, given the larger storage space of the super SIM card, the verification module can store a large amount of data (e.g., measurement files of multiple programs) locally, avoiding the problem of limited storage space of the verification module.
[0111] Optionally, the measurement file corresponding to each of the at least one program can be stored in the SIM card according to initial configuration information of the SIM card; or the measurement file corresponding to each of the at least one program can be stored in the SIM card according to update configuration information of the SIM card.
[0112] In some examples, before the SIM card is used for the first time, the carrier device can write the measurement file and the verification module into the SIM card; when there is a measurement file to be updated subsequently, the carrier device can write a new measurement file into the SIM card through OTA. In the foregoing process of writing data into the SIM card, the carrier device can ensure the integrity and trustworthiness of the measurement file through signature. The measurement file written into the SIM card for the first time can include at least one of the following: device endorsement (which can be the same as or different from the carrier device) obtained from an endorser, a parameter value range of at least one parameter obtained from a reference value provider (which can be the same as or different from the carrier device), an evaluation strategy of an authentication result.
[0113] In some examples, the at least one program includes a first program, and the SIM card can implement storage of the measurement file of the first program through SA1 to SA2.
[0114] SA1: The carrier device can send initial configuration information to the SIM card. Correspondingly, the SIM card receives the initial configuration information from the carrier device. The initial configuration information is used to indicate the measurement file of the first program.
[0115] For example, the carrier device can send the initial configuration information to the SIM card through a card reader.
[0116] SA2: The SIM card stores the measurement file of the first program in the SIM card according to the initial configuration information.
[0117] In other examples, the at least one program includes a second program, and the SIM card can implement storage of the measurement file of the second program through SB1 to SB2.
[0118] SB1: The carrier device can send update configuration information to the SIM card. Correspondingly, the SIM card receives the update configuration information from the carrier device. The update configuration information is used to indicate the measurement file (e.g., the first measurement file) of the second program.
[0119] For example, the operator device can send the update configuration information to the SIM card through over the air (OTA).
[0120] SB2: The SIM card stores the measurement file (e.g., the first measurement file) of the second program in the SIM card according to the update configuration information.
[0121] Optionally, when the measurement file (e.g., the second measurement file) of the second program has been stored in the SIM card, the SIM card can perform an overwriting update on the measurement file of the second program, i.e., overwriting the second measurement file with the first measurement file.
[0122] It should be understood that the two aforementioned designs of locally storing the measurement file corresponding to at least one program can be cross-referenced, and the present application does not make any limitation.
[0123] S402: The verification module obtains an evidence file of the target program, and the evidence file is used to indicate the parameter value corresponding to at least one parameter when the target program runs in the device.
[0124] In some examples, the verification module can collect a series of claims in the target program (or target environment), and generate the evidence file according to the series of claims. Each claim corresponds to at least one parameter, and each claim can be composed of a name / value pair. The verification module generates the evidence file by signing the aforementioned series of claims and adding timestamp information, thereby generating the evidence file (or evidence). Optionally, the private key required by the verification module for signing (included in the identity information of the verification module) can be pre-written into the verification module by the operator device. Optionally, in order to realize the aforementioned signing of the series of claims, the operator device can also pre-write the identity information (which can be used as a private key for signing) corresponding to the verification module into the SIM card.
[0125] Assuming that the verification module is set in the SIM card inside the device, based on the two different structural examples of the verification module, the following describes the aforementioned process of obtaining the evidence file through two designs.
[0126] In one possible design, when the structure of the SIM card is the aforementioned structural example one, in order to adapt to the passport data flow in remote attestation, the verification module can send the evidence file to the target program; and / or, the verification module can also receive the evidence file from the target program.
[0127] In another possible design, when the structure of the SIM card is the aforementioned structural example two, the aforementioned S402 can be performed by the ERoT; that is, the ERoT can generate the evidence file of the target program.
[0128] In some examples, the ERoT can also send the aforementioned attestation file to the verification submodule. For example, the ERoT sends the aforementioned attestation file to the verification submodule through thread interaction. For another example, the ERoT can send the attestation file to the target program; and the target program forwards the aforementioned attestation file to the verification submodule. In other words, the verification submodule can also receive the attestation file generated by the ERoT forwarded by the target program.
[0129] S403: The verification submodule determines an attestation result according to the attestation file and the measurement file. The attestation result is used to indicate the trustworthiness of the target program.
[0130] Optionally, the attestation result can carry a timestamp.
[0131] In some examples, the attestation result can be a binary result, a multi-element result, or a numerical value used to represent the degree of trustworthiness.
[0132] In a possible design, when the verification submodule is arranged in a SIM card inside a device and the structure of the SIM card is the aforementioned structure example two, the aforementioned S403 can be performed by the verification submodule; that is, the verification submodule can determine the attestation result according to the attestation file and the measurement file obtained by the ERoT.
[0133] The following briefly describes the evaluation process of the trustworthiness of the target program based on parameter information of at least one predefined parameter:
[0134] The at least one parameter includes a parameter a, a parameter b, and a parameter c, and has the following meanings:
[0135] The parameter a is used to indicate whether the target program contains endorsement. When the parameter value of the parameter 1 is 1, it indicates that the target program contains endorsement. When the parameter value of the parameter 1 is 0, it indicates that the target program does not contain endorsement.
[0136] The parameter b is used to indicate the version number of the target program.
[0137] The parameter c is used to indicate the parameter value corresponding to the code integrity of the target program.
[0138] It can be learned from S401 that the measurement file of the target program (wherein N=4) includes the following data:
[0139] Table 2
[0140] It can be learned from S402 that the attestation file of the target program includes the following data: the parameter value of the parameter a is 1, the parameter value of the parameter b is 3.2.7, and the parameter value of the parameter c is 11.
[0141] The verification module can determine the authentication result of the trustworthiness of the target program as absolutely trusted or 3-level trusted based on the aforementioned measurement file and attestation file of the target program.
[0142] Further, the verification module can further perform the following S404.
[0143] S404: The verification module outputs or displays the authentication result; or the verification module sends the authentication result.
[0144] In a possible design, the process in which the verification module sends the authentication result can include: the verification module can sign the authentication result; and the verification module can send the signed authentication result. For example, in the communication system shown in FIG. 3a, the verification module can send the signed authentication result to the relying party device.
[0145] Optionally, the aforementioned signature can be determined based on identity information of the verification module (including a private key of the verification module).
[0146] In some examples, the operator device can send first indication information to the operator device (or the SIM card), where the first indication information is used to instruct the operator device (or the SIM card) to install the verification module, and the verification module is used to determine the authentication result of any program (for example, the target program) installed in the operator device (or a device to which the SIM card belongs).
[0147] Optionally, the first indication information can include identity information of the verification module.
[0148] In some other examples, the operator device can send the identity information of the verification module to the client device (or the SIM card); and correspondingly, the client device (or the SIM card) can receive the identity information of the verification module from the operator device.
[0149] In some examples, in combination with the communication system shown in FIG. 3b and FIG. 3c, the aforementioned communication method shown in FIG. 4 can be implemented through the following steps.
[0150] [According to the correction of Rule 91 on 05.02.2026] In the communication system shown in FIG. 3b, the communication method can include the following S5a-1 to S5a-6 (as shown in FIG. 5a):
[0151] S5a-1: The operator device stores the measurement file into the storage space through the storage management applet in the verification module by means of the card reader (first-time writing) or OTA (subsequent update). The aforementioned S5a-1 can refer to the description of SA1 to SA2, or refer to the description of SB1 to SB2, which are not repeated here.
[0152] S5a-2: The verification module collects the declaration in the target program. Further, the verification module can also generate a proof file according to the declaration.
[0153] In some examples, S5a-2 can be implemented between multiple functional areas inside the verification module in the following way: the main interface calls the proof sub-application, and passes the declaration to the proof sub-application as a parameter; the proof sub-application generates a proof file according to the declaration, and sends the proof file to the main interface.
[0154] S5a-3: The verification module can send the proof file to the target program.
[0155] S5a-4: The target program sends the proof file to the verification module. Further, the verification module can also determine the authentication result of the target program according to the measurement file and the proof file.
[0156] In some examples, S5a-4 can be implemented between multiple functional areas inside the verification module in the following way: the main interface calls the verification sub-application (which has obtained the proof file), so that the verification sub-application compares the proof file with the measurement file to generate an authentication result; the verification sub-application can return the authentication result to the main interface.
[0157] To adapt to the passport data flow in remote attestation, the communication method can include S5a-3 and S5a-4. It should be understood that both S5a-3 and S5a-4 are optional steps.
[0158] S5a-5: The verification module can send the authentication result to the target program, the device system of the client device (the device where the target program is located), or the authentication result manager of the client device (the device where the target program is located).
[0159] Optionally, the target program can store the authentication result.
[0160] Optionally, the device system of the client device can select a processing method for the target program according to the authentication result; for example, the processing method of the client device for the target program includes: continuing to use the target program, stopping using the target program, or uninstalling the target program.
[0161] S5a-6: The verification module can forward the authentication result to the device system of the relying party through the device system of the client device (the device where the target program is located).
[0162] Optionally, the device system of the relying party can select a processing method for the target program according to the authentication result; for example, the processing method of the relying party device for the target program includes: approving the installation of the target program or not approving the installation of the target program.
[0163] Optionally, the device system of the relying party can feed back the processing method to the device system of the client device.
[0164] It should be understood that the foregoing S5a-5 and the foregoing S5a-6 are optional steps.
[0165] In the communication system shown in FIG. 3c, the communication method can include the following S5b-1 to S5b-7 (as shown in FIG. 5b).
[0166] S5b-1: The operator device stores the measurement file into the storage space through the storage management applet in the verification module by means of the card reader (first time writing) or over-the-air download (subsequent update). The foregoing S5b-1 can refer to the description of SA1 to SA2, or refer to the description of SB1 to SB2, which will not be repeated here.
[0167] S5b-2: The ERoT in the verification module collects the declaration in the target program. Further, the ERoT can also generate a proof file according to the declaration.
[0168] S5b-3: The ERoT sends the generated proof file to the target program.
[0169] S5b-4: The target program sends the proof file to the verification sub-module.
[0170] S5b-5: The verification sub-module compares the proof file with the measurement file and generates the authentication result of the target program.
[0171] S5b-6: The verification sub-module sends the authentication result to the target program, the device system of the client device (the device where the target program is located) or the authentication result manager of the client device (the device where the target program is located). The foregoing S5b-6 can refer to the description of S5a-5, which will not be repeated here.
[0172] S5b-7: The verification sub-module can forward the authentication result to the device system of the relying party through the device system of the client device (the device where the target program is located). The foregoing S5b-7 can refer to the description of S5a-6, which will not be repeated here.
[0173] The communication systems shown in FIGS. 4 to 5b are all examples introduced with the target program as the target object, and the implementation process of other target objects can be similarly referred to, which will not be expanded one by one.
[0174] In other possible examples, as shown in FIG. 6, the client device and the relying party device can be routers. The router A (client device) is configured with a SIM card, and the router A can interact with the router B (relying party device).
[0175] [Rule 91 correction 05.02.2026] In the communication system shown in FIG. 6, when the structure of the SIM card is the aforementioned structure example one, the communication method can include the following S7a-1 to S7a-6 (as shown in FIG. 7a). In the communication method, the target object to be verified can be hardware and / or software in the router A.
[0176] [Rule 91 correction 05.02.2026] S7a-1 to S7a-4 can refer to S5a-1 to S5a-4 in the aforementioned FIG. 5a.
[0177] S7a-5: The verification module can forward the authentication result to the device system of the router B through the device system of the router A.
[0178] S7a-6: The device system of the router B can send a processing feedback to the device system of the router A according to the authentication result. For example, the processing feedback includes: accepting the router A as a trusted neighbor or not accepting the router A as a trusted neighbor.
[0179] In the communication system shown in FIG. 6, when the structure of the SIM card is the aforementioned structure example two, the communication method can include the following S7b-1 to S7b-7 (as shown in FIG. 7b).
[0180] [Rule 91 correction 05.02.2026] S7b-1 to S7b-5 can refer to S5b-1 to S5b-5 in the aforementioned FIG. 5b.
[0181] [Rule 91 correction 05.02.2026] S7b-6 and S7b-7 can refer to S7a-5 and S7a-6 in the aforementioned FIG. 7a.
[0182] In various embodiments of the present application, the terms and / or descriptions of different embodiments are consistent and can be referred to each other if there is no special description and logical conflict, and the technical features in different embodiments can be combined to form new embodiments according to their inherent logical relationship.
[0183] The method provided by the embodiments of the present application is described above in combination with the drawings, and the communication device provided by the embodiments of the present application is described below in combination with the drawings.
[0184] Based on the same technical concept, the present application also provides a communication device for implementing the communication method provided by the above embodiments. Referring to FIG. 8, the communication device 800 includes a communication module 801 and a processing module 802. The communication module 801 is used for receiving and / or sending data; and the processing module 802 is used for implementing the steps in the communication method shown in FIG. 4.
[0185] Optionally, the communication apparatus 800 further includes a verification module 803; the verification module 803 can invoke the aforementioned communication module 801 and the processing module 802.
[0186] Optionally, the communication apparatus 800 further includes a storage module 804; the aforementioned processing module 802 can invoke the aforementioned storage module 804, so as to realize storage of data.
[0187] In a possible example, when the communication apparatus 800 is used to realize the function of the aforementioned verification module shown in FIG. 4, the verification module 803 can execute the following steps based on the communication module 801: obtaining a measurement file of a target object; the communication apparatus 800 and the target object are installed in the same device; the measurement file is used to indicate a parameter value range that at least one parameter respectively needs to meet, the at least one parameter respectively represents a feature of the target object in a running process when the target object is trusted; the verification module 803 can also execute the following steps based on the communication module 801: obtaining an attestation file of the target object, the attestation file is used to indicate a parameter value corresponding to the at least one parameter when the target object runs in the device; the verification module 803 can execute the following steps based on the processing module 802: determining an authentication result according to the attestation file and the measurement file; the authentication result is used to indicate the trustworthiness of the target object.
[0188] In a possible design, the communication apparatus 800 is arranged in a SIM card in a device.
[0189] In a possible design, the communication apparatus 800 is an ERoT.
[0190] In a possible design, the communication apparatus 800 includes an ERoT and a verification submodule; the aforementioned process of obtaining the attestation file of the target object can include: the ERoT generates the attestation file of the target object; the aforementioned process of determining the authentication result according to the attestation file and the measurement file can include: the verification submodule determines the authentication result according to the attestation file and the measurement file obtained by the ERoT.
[0191] In a possible design, the verification submodule can also receive the attestation file generated by the ERoT and forwarded by the target object.
[0192] In a possible design, the communication module 801 is specifically used for: obtaining the measurement file of the target object in a subscriber identity module SIM card in the device; the SIM card pre-stores the measurement file corresponding to at least one object respectively, the at least one object includes the target object.
[0193] In a possible design, the at least one object respectively corresponding metric file is stored in the SIM card according to initial configuration information of the SIM card; or the at least one object respectively corresponding metric file is stored in the SIM card according to update configuration information of the SIM card.
[0194] In a possible design, the verification module 803 can further perform the following step based on the processing module 802: output or display the authentication result; or the verification module 803 can further perform the following step based on the communication module 801: send the authentication result.
[0195] In a possible design, the communication module 801 is specifically configured to: sign the authentication result; and send the signed authentication result.
[0196] In a possible example, when the communication apparatus 800 is used to implement the functions of the client device shown in FIG. 4, the processing module 802 is configured to perform the following steps based on the communication module 801: receive first configuration information from an operator device, the first configuration information being used to indicate metric files respectively corresponding to at least one object; the at least one object includes a target object; the metric file of the target object is used to indicate a parameter value range that at least one parameter respectively needs to satisfy, the at least one parameter respectively being used to represent a feature of the target object in a running process; the metric file of the target object is used for the verification module to determine an authentication result of the target object, the authentication result being used to indicate the trustworthiness of the target object; the target object is any one of the at least one object, and the at least one object is respectively installed in the communication apparatus 800; and the processing module 802 is configured to perform the following step based on the storage module 804: store, according to the first configuration information, the metric files respectively corresponding to the at least one object in the communication apparatus 800.
[0197] Optionally, the processing module 802 is further configured to trigger the verification module 803 to perform the following step: determine, based on the metric file of the target object, the authentication result of the target object, the authentication result being used to indicate the trustworthiness of the target object.
[0198] In a possible design, the communication module 801 is further configured to: receive second configuration information from the operator device; and the second configuration information is used to indicate that the metric files respectively corresponding to the at least one object are updated; the update includes at least one of the following: deleting the metric files respectively corresponding to one or more objects in the at least one object; replacing the metric files respectively corresponding to one or more objects in the at least one object; and configuring the metric files respectively corresponding to one or more objects that are newly added on the basis of the at least one object.
[0199] In a possible design, the method shown in the second aspect is specifically applied to a SIM card installed in the communication apparatus 800, and the verification module is arranged in the SIM card.
[0200] In a possible design, the communication module 801 is further configured to receive first indication information from the operator device, where the first indication information is used to instruct the communication apparatus 800 to install a verification module; and the processing module 802 is further configured to install the verification module according to the first indication information, where the verification module is configured to determine an authentication result of the target object according to the metric file of the target object, and the authentication result is used to indicate the trustworthiness of the target object.
[0201] In a possible design, the communication module 801 is further configured to receive identity information of the verification module from the operator device, so that the verification module signs the authentication result of the target object based on the identity information.
[0202] In a possible example, when the communication apparatus 800 is configured to implement the functions of the operator device shown in FIG. 4, the processing module is configured to generate first configuration information, where the first configuration information is used to indicate metric files corresponding to at least one object respectively, and the at least one object includes the target object; the metric file of the target object is used to indicate a parameter value range that at least one parameter respectively needs to satisfy, where the at least one parameter is respectively used to represent a feature of the target object in a running process; the target object is any one of the at least one object, and the at least one object is respectively installed in a client; and the communication module 801 is configured to send the first configuration information to the client device.
[0203] In a possible design, the communication module 801 is further configured to send second configuration information to the client device, where the second configuration information is used to instruct to update the metric files corresponding to the at least one object respectively; and the update includes at least one of the following: deleting the metric files corresponding to one or more objects in the at least one object; replacing the metric files corresponding to one or more objects in the at least one object; and configuring the metric files corresponding to one or more objects that are newly added on the basis of the at least one object.
[0204] In a possible design, the communication module 801 is further configured to send first indication information to the client device, where the first indication information is used to instruct the client device to install a verification module; and the verification module is configured to determine an authentication result of the target object according to the metric file of the target object, and the authentication result is used to indicate the trustworthiness of the target object.
[0205] In a possible design, the communication module 801 is further configured to send identity information of the verification module installed in the client device to the client device, so that the verification module signs the authentication result of the target object based on the identity information.
[0206] Based on the same technical concept, the embodiment of the present application further provides another communication device 900, which can implement the communication method provided by the above embodiment. Referring to FIG. 9, the communication device 900 comprises a processor 901. Optionally, the communication device 900 further comprises a memory 902 and / or a communication interface 903. The memory can be arranged in the interior of the communication device or arranged in the exterior of the communication device, which is not limited in the present application. Among them, the communication interface 903, the processor 901 and the memory 902 are connected with each other. Exemplarily, the communication device 900 can be the verification module shown in the embodiment of the present application.
[0207] Optionally, the communication interface 903, the processor 901 and the memory 902 are connected with each other through a bus 904. The bus 904 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the convenience of representation, only one thick line is used in FIG. 9, but it does not mean that there is only one bus or only one type of bus.
[0208] The communication interface 903 is configured to receive and / or send signals, and realize communication with other devices other than the communication device.
[0209] The processor 901 can be used for executing the communication method in the foregoing FIG. 4, which can refer to the description in the above embodiments and will not be repeated here. The processor 901 can be a central processing unit (CPU), a network processor (NP), or a combination of CPU and NP, etc. The processor 901 can further include a hardware chip. The hardware chip can be an application-specific integrated circuit (ASIC), a programmable logic device (PLD) or a combination thereof. The PLD can be a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof. The processor 901 can be implemented by hardware, and of course, can also execute corresponding software by hardware.
[0210] The memory 902 is configured to store program instructions and the like. Specifically, the program instructions can include program codes including computer operation instructions. The memory 902 can include a random access memory (RAM) and can also include a non-volatile memory such as at least one disk memory. The processor 901 executes the program instructions stored in the memory 902 to implement the above functions, thereby implementing the method provided by the above embodiments.
[0211] Based on the same technical concept, the embodiments of the present application further provide a computer program, which, when executed on a computer, causes the computer to perform the method provided by the above embodiments.
[0212] Based on the same technical concept, the embodiments of the present application further provide a computer readable storage medium, which stores a computer program, and when the computer program is executed on a computer, causes the computer to perform the method provided by the above embodiments.
[0213] The storage medium can be any available medium that can be accessed by a computer. By way of example, and not limitation, such computer-readable media can comprise RAM, ROM, EEPROM, CD-ROM or other optical disk storage, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to carry or store desired program code in the form of instructions or data structures and that can be accessed by a computer.
[0214] Based on the same technical concept, the embodiment of the present application further provides a chip for reading a computer program stored in a memory, and implementing the method provided in the above embodiment.
[0215] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, a system, or a computer program product. Therefore, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer-usable program code.
[0216] The present application is described with reference to the flowcharts and / or block diagrams of the method, device (system), and computer program product according to the present application. It should be understood that each flow and / or block in the flowcharts and / or block diagrams can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing apparatus to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing apparatus generate means for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0217] These computer program instructions can also be stored in a computer-readable memory that can direct the computer or other programmable data processing apparatus to work in a specific manner, so that the instructions stored in the computer-readable memory produce a manufactured product including instruction means, which implements the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0218] These computer program instructions can also be loaded onto a computer or other programmable data processing apparatus, so that a series of operation steps are performed on the computer or other programmable data processing apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable data processing apparatus provide steps for implementing the functions specified in one or more flows in the flowcharts and / or one or more blocks in the block diagrams.
[0219] Obviously, many modifications and variations of the present application are possible in light of the above teachings. It is, therefore, to be understood that within the scope of the appended claims and their equivalents, the application can be practiced otherwise than as specifically described.
Claims
1. A communication method characterized by comprising: The method is applied to a verification module, and the method comprises: obtaining a measurement file of a target object; the verification module and the target object are installed in the same device; the measurement file is used to indicate a parameter value range that at least one parameter needs to meet when the target object is trusted, the at least one parameter being used to represent a feature of the target object in a running process; obtaining a certificate file of the target object, the certificate file being used to indicate a parameter value corresponding to the at least one parameter when the target object runs in the device; determining an authentication result according to the certificate file and the measurement file; the authentication result is used to indicate the trustworthiness of the target object.
2. The method of claim 1, wherein, The verification module is arranged in a subscriber identity module (SIM) card in the device.
3. The method of claim 2, wherein, The verification module is an embedded root of trust (ERoT).
4. The method of claim 2, wherein, The verification module comprises the ERoT and a verification submodule. The obtaining of the certificate file of the target object comprises: the ERoT generates the certificate file of the target object. The determining of the authentication result according to the certificate file and the measurement file comprises: the verification submodule determines the authentication result according to the measurement file and the certificate file obtained by the ERoT.
5. The method of claim 4, wherein, Further comprising: The verification submodule receives the certificate file generated by the ERoT and forwarded by the target object.
6. The method of any one of claims 1-5, wherein, The obtaining of the measurement file of the target object comprises: obtaining the measurement file of the target object in a SIM card in the device; at least one object including the target object is pre-stored in the SIM card, and the at least one object corresponds to a measurement file respectively.
7. The method of claim 6, wherein, The measurement file corresponding to the at least one object is stored in the SIM card according to initial configuration information of the SIM card; or the measurement file corresponding to the at least one object is stored in the SIM card according to update configuration information of the SIM card.
8. The method of any one of claims 1-7, wherein, The method further comprises: outputting or displaying the authentication result; or sending the authentication result.
9. The method of claim 8, wherein, The sending of the authentication result comprises: signing the authentication result; sending the signed authentication result.
10. A communication method characterized by comprising: The method is applied to a client device comprising a verification module, and the method comprises: receiving first configuration information from an operator device, the first configuration information being used to indicate a measurement file corresponding to at least one object; the at least one object comprises a target object; the measurement file of the target object is used to indicate a parameter value range that at least one parameter needs to meet when the target object is trusted, the at least one parameter being used to represent a feature of the target object in a running process; the measurement file of the target object is used for the verification module to determine an authentication result of the target object, the authentication result being used to indicate the trustworthiness of the target object; the target object is any one of the at least one object, and the at least one object is installed in the client device respectively; storing the measurement file corresponding to the at least one object according to the first configuration information.
11. The method of claim 10, wherein, Further comprising: receiving second configuration information from the operator device; the second configuration information is used to indicate that the metric files corresponding to the at least one object are updated; the update includes at least one of the following: deleting the metric files corresponding to one or more objects in the at least one object; replacing the metric files corresponding to one or more objects in the at least one object; configuring the metric files corresponding to one or more objects added on the basis of the at least one object.
12. The method of claim 10 or 11, wherein, The method is specifically applied to a subscriber identity module (SIM) card installed in the client device, and the verification module is arranged in the SIM card.
13. The method of any one of claims 10-12, wherein, Further comprising: receiving first indication information from the operator device, the first indication information being used to instruct the client device to install the verification module; installing the verification module according to the first indication information.
14. The method of any one of claims 10-13, wherein, Further comprising: receiving identity information of the verification module from the operator device, so that the verification module signs the authentication result of the target object based on the identity information.
15. A method of communication, comprising: The method is applied to an operator device, and the method comprises: generating first configuration information, the first configuration information being used to indicate metric files corresponding to the at least one object; the at least one object includes a target object; the metric file of the target object is used to indicate parameter value ranges that at least one parameter respectively needs to meet when the target object is trusted, the at least one parameter being respectively used to represent features of the target object in a running process; the target object is any object in the at least one object, and the at least one object is respectively installed in a client device; sending the first configuration information to the client device.
16. The method of claim 15, wherein, Further comprising: sending second configuration information to the client device; the second configuration information is used to instruct that the metric files corresponding to the at least one object are updated; the update includes at least one of the following: deleting the metric files corresponding to one or more objects in the at least one object; replacing the metric files corresponding to one or more objects in the at least one object; configuring the metric files corresponding to one or more objects added on the basis of the at least one object.
17. The method of claim 15 or 16, wherein, The method further comprises: sending first indication information to the client device, the first indication information being used to instruct the client device to install a verification module; the verification module is used to determine an authentication result of the target object according to the metric file of the target object, and the authentication result is used to indicate the trustworthiness of the target object.
18. The method of claim 17, wherein, Further comprising: sending identity information of the verification module to the client device, so that the verification module signs the authentication result of the target object based on the identity information.
19. A communications device, characterized by The method comprises a module for executing the method according to any one of claims 1 to 9.
20. A communications device, characterized by The method comprises: a communication module, a storage module, a processing module, and a verification module; the communication module is used to receive and / or send data; the storage module is used to store data; and the processing module is used to process data. The processing module is configured to perform the operation of receiving the information of the operator device based on the communication module, and trigger the verification module to perform the operation of determining the authentication result of the target object based on the metric file of the target object, the authentication result being used to indicate the trustworthiness of the target object.
21. A communications device, characterized by Comprising: a communication module and a processing module; the communication module is configured to receive and / or send data; the processing module is configured to perform the method according to any one of claims 15-18 based on the communication module.
22. A communications device, characterized by Comprising: at least one processor; the at least one processor is configured to execute computer-executable program code or instructions to implement the method according to any one of claims 1-9, or implement the method according to any one of claims 10-14, or implement the method according to any one of claims 15-18.
23. The apparatus of claim 22, wherein, Further comprising a memory configured to store the computer-executable program code or instructions.
24. A communication system, characterized by Comprising: a verification module, a client device and an operator device, the verification module being inside the operator device; the verification module is configured to perform the method according to any one of claims 1-9; the client device is configured to perform the method according to any one of claims 10-14; the operator device is configured to perform the method according to any one of claims 15-18.
25. A computer readable storage medium, characterized in that, The computer-readable storage medium stores computer-executable instructions, which, when invoked by a computer, cause the computer to perform the method according to any one of claims 1-9, or perform the method according to any one of claims 10-14, or perform the method according to any one of claims 15-18.
26. A computer program product, characterised in that, The computer program product stores computer-executable instructions, which, when invoked by a computer, cause the computer to perform the method according to any one of claims 1-9, or perform the method according to any one of claims 10-14, or perform the method according to any one of claims 15-18.
27. A chip, characterized by The chip comprises a processor, the processor is configured to execute computer-executable program code or instructions to implement the method according to any one of claims 1-9, or implement the method according to any one of claims 10-14, or implement the method according to any one of claims 15-18.