Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

60 results about "Trusted application" patented technology

A trusted application is an application developed by a third party that is given trusted status to run as part of Skype for Business Server but that is not a built-in part of the product.

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

System and method for remote attestation of vehicle features

Methods for attestation of a vehicle feature associated with a vehicle control unit are provided and include: detecting, using a trusted application, whether a configurable feature has been activated based on one or more detection models; periodically detecting during runtime, using each of the one or more detection models, whether the configurable feature is activated; generating a report of attestation results indicating that the configurable feature is one of: activated and unauthorized; activated and authorized; un-activated and authorized; and un-activated and unauthorized; determining whether an activated feature is unauthorized, wherein the activated feature is the configurable feature that has been detected as being activated; and activating a response mechanism and restoring the configurable feature of the vehicle to an inactive state in response to the activated feature being unauthorized.
Owner:DENSO CORP

Integrity verification and quality evaluation method before agricultural Internet of Things data uplink

The invention relates to an integrity verification and quality evaluation method before agricultural Internet of Things data uploading, and belongs to the technical field of artificial intelligence and block chains. The method comprises the following steps: collecting agricultural Internet of Things data and constructing a data set; constructing a complete feature vector by adopting a double-branch filling network; generating a quality label for each sample; an integrity verification and quality evaluation model based on a deep neural network is constructed, and sample-level overall quality scoring, sensor-level abnormal confidence and data fingerprint generation are realized; performing verification and evaluation by setting thresholds of three prediction results; performing supervised training on the model through a composite loss function; and performing integrity verification and quality evaluation on to-be-evaluated agricultural Internet of Things data by adopting the trained model, and realizing reliable chaining, secure storage and trusted application of the agricultural Internet of Things data to a block chain for data samples which pass the integrity verification and have the overall quality score reaching the standard. The prediction precision can be improved.
Owner:QINGDAO AGRI UNIV

ARM heterogeneous edge device-oriented trusted deep learning reasoning method

The invention relates to a trusted deep learning reasoning method for an ARM heterogeneous edge device. The method comprises the following steps: a deployment stage: storing a structure file and a weight of a model in a core stack of a TEE through a static trusted application PTA; in the reasoning stage, REE loads a structure model and a weight from TEE secure storage, initializes a reasoning model and creates a thread pool; dynamic trusted applications TA0 and TA1 are adopted for asynchronous cooperative verification, TA0 executes non-convolutional layer reasoning and convolutional layer verification, TA1 executes convolutional layer verification, and TA0 and TA1 are executed in a staggered mode; verifying a convolution layer reasoning result by using an FTC algorithm; the GPU is used for accelerating parallel reasoning of a convolution layer, multi-TA cooperative verification is executed through the multi-core CPU, and asynchronous parallelism of model credible reasoning and convolution credible verification is achieved. The method is low in time delay and high in reliability, the privacy and integrity of the deep learning model can be protected, the time overhead of credible reasoning is reduced, and the real-time performance of credible deep learning reasoning on the ARM heterogeneous edge device is improved.
Owner:FUZHOU UNIV

Data processing method and device, electronic equipment and medium

The invention relates to a data processing method and device, electronic equipment and a medium. The data processing method comprises the following steps: acquiring calling data from a client application; setting the state of the core of the processor as an activated state in an operating system of the trusted execution environment; according to the calling data, a corresponding trusted application is called for data processing, processing result data is obtained, and the trusted application runs in an operating system of the trusted execution environment; wherein the number of the cores in the activated state is related to the number of the client applications calling the trusted application, and the cores in the activated state are used for running the trusted application. As the core in the activated state can be scheduled in the trusted execution environment, the corresponding trusted application does not need to be bound, so that the utilization rate of the processor is improved, and resources are fully utilized.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Matter certificate burning method and device, equipment and medium

The invention relates to the technical field of firmware burning, and discloses a Matter certificate burning method and device, equipment and a medium. The method comprises the steps of loading a client application and a trusted application in response to a received burning request; calling a client application to receive a certificate file and a file key sent by the external equipment, and encrypting and transmitting the certificate file and the file key to a trusted application in the trusted execution environment; and calling the trusted application to decrypt the certificate file based on the file key to obtain the Matter certificate, and writing the Matter certificate into the secure storage area of the trusted execution environment. According to the embodiment of the invention, the security of Matter certificate burning can be improved.
Owner:SHENZHEN SDMC TECH CO LTD

Key management method, mobile device for digital currency transaction, apparatus, system, and storage medium

Embodiments of the present disclosure provide a key management method, a mobile device for a digital currency transaction, an apparatus, a system, and a storage medium. The mobile device serves as an acceptance terminal, and comprises a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, and the second execution environment is securely isolated from the first execution environment. The digital currency acquirer application is configured to send a key application request to a digital currency background system, receive core key data by means of a secure channel between the digital currency background system and the mobile device, and when it is detected that the mobile device has the second execution environment and the executable digital currency trusted application is installed in the second execution environment, send the core key data to the digital currency trusted application. The digital currency trusted application is configured to receive the core key data sent by the digital currency acquirer application and store the core key data in the second execution environment.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Zero trust architecture with browser-supported security posture data collection

A zero trust application enables access to a protected resource from a client device associated with a user. The client device has a browser, and an agent running locally and accessible via a local loopback interface. During an authentication flow, a browser-based script executes in the browser to deliver a challenge to the agent, and to collect a response to that challenge from the agent using a graphics file-based encoding scheme, and to deliver that information to the application for verifying the client device and its security posture. Depending on that security posture, the authentication flow may be permitted to complete. If a failure of the security posture is identified, the user may be permitted during the on-going authentication flow to address that failure and request a re-check of the posture.
Owner:AGILEBITS INC DBA 1PASSWORD

Data transmission method and related apparatus

The embodiment of the application provides a kind of data transmission method and related device, it is related to terminal technical field.The method comprises: client application CA indicates first information to first trusted application TA, first information indicates the target data of transmission first trusted application TA.First trusted application TA responds to first information, and write target data to first memory area, and indicate second information to client application CA, second information is used to indicate target storage address of target data in first memory area, and first memory area is the memory area in trusted execution environment TEE.Client application CA indicates third information to sensor control center, and third information includes second information or address information determined based on second information.Sensor control center determines target storage address based on third information, and obtains target data from first memory area based on target storage address.In this way, the security of data from TEE transmission to sensorhub can be improved.
Owner:HONOR DEVICE CO LTD

Shared memory management method and device, electronic equipment and storage medium

The invention provides a shared memory management method and device, electronic equipment and a storage medium, and the shared memory management method comprises the following steps executed by a common operating system: receiving a data sending request sent by a common application program; in response to the data sending request, allocating a shared memory block in a shared memory pool to the common application, so that the common application transmits data to the trusted application through the shared memory block; wherein a virtual address of a shared memory block in the shared memory pool is a kernel virtual address, and the kernel virtual address and a physical address, distributed to a physical memory of a common operating system, in the physical memory connected with the processor have a mapping relationship; therefore, not only can the time overhead of sharing data from a common application program to a trusted application program be reduced, but also the method is more suitable for operating systems with lower complexity, such as a real-time operating system without a virtual address and physical address mapping function and the like.
Owner:PHYTIUM TECH CO LTD

Physiological information application platform

PendingUS20260188481A1Data transportEngineering
A physiological information application platform includes a physiological information application device. The physiological information application device provides data exchange and utilization between a client application and a server application. Before exchanging data between the client application and the server application, it is required to confirm that the applications are authenticated as trusted applications, and an authentication is performed by obtaining an authorized encryption file through an authorization mechanism. Therefore, the physiological information application device provides a data topology application and an alarm management mechanism within an alarm system. Furthermore, the physiological information application device can operate without transferring the data to an external system, thereby reducing a risk of data loss and theft and improving data security.
Owner:BROADSIMS INC

Encryption, decryption method, system, and electronic device and storage medium

PendingCN122339668ACiphertextEngineering
This invention provides an encryption method and system applied to a trusted application. The method includes: obtaining key encryption storage request information from a client application, the key encryption storage request information containing an original key to be encrypted; reading the hash value of the root key from the electronic fuse area; generating key encryption information based on the hash value; encrypting the original key using the key encryption information to obtain key ciphertext; and storing the key ciphertext in a storage device. The encryption scheme provided by this invention achieves efficient protection of the key by combining hardware and key transfer (TA) protection, effectively overcoming security vulnerabilities in traditional storage methods and enhancing the security, integrity, and availability of key management.
Owner:BEIJING CO WHEELS TECH CO LTD

Electronic device

An electronic device and a trusted application calling method are provided. After a client application initiates call information, a trusted application development platform receives the call information, determines a native trusted application corresponding to first identification information of the electronic device carried by the calling information from native trusted applications corresponding to at least two (or more) TEE OSs connected to the trusted application development platform, and sends the calling information to the native trusted applications corresponding to the first identification information. The native trusted application corresponding to the first identification information receives the calling information, determines a bytecode trusted application corresponding to the second identification information from at least one bytecode trusted application installed in the native trusted application according to the second identification information carried by the calling information, and calls the bytecode trusted application corresponding to the second identification information.
Owner:CHINA UNIONPAY

Authority management method and system for equipment flash, chip and intelligent terminal

The invention discloses an authority management method and system for equipment flashing, a chip and an intelligent terminal.The method comprises the steps that when an authorization mode for equipment flashing is a quick start authorization mode, a boot loader is started; the client application initiates a first authorization authentication request via the first trusted execution environment client interface; the trusted execution environment core driver receives the first authorization authentication request and switches the operating environment of the processor from a common world to a secure world; the trusted operating system receives and analyzes the first authorization authentication request, and schedules an early trusted application to obtain equipment fingerprint information from the first storage partition; when the equipment fingerprint information passes verification, modifying the first authorization mark, and correspondingly modifying the second authorization mark stored in the second storage partition; and the intelligent terminal is switched into the factory mode. According to the method and the device, the original flashing port can be controllably opened, so that the risk of illegal flashing is avoided, and meanwhile, legal flashing operation is guaranteed.
Owner:SHANGHAI SUMI TECH CO LTD +1

Equipment disconnection overtime locking control method and system and electronic equipment

PendingCN121864474ASolve security blind spotsReduce operation and maintenance complexitySecuring communicationNetwork connectionEmbedded system
The invention discloses a device disconnection overtime locking control method and system and electronic device.The method comprises the steps that after a device is started, an encrypted channel between a client application and a trusted application is established through the client application, and locking basic configuration and state data are read from a secure storage partition; wherein the client application runs in a common execution environment of the system, and the trusted application runs in a trusted execution environment of the system; the client application detects the network connection condition of the equipment in real time to obtain accumulated network disconnection time, and triggers the trusted application every a first time threshold value, so that the accumulated network disconnection time is encrypted and written into the secure storage partition through the trusted application; and when the accumulated network disconnection time exceeds a preset second time threshold value, the trusted application sets a machine locking position state of the equipment in the secure storage partition, and triggers the equipment to lock the machine.
Owner:SHANGHAI SUMI TECH CO LTD +1

Decentralization log processing method and system based on TEE and trusted measurement

The invention discloses a decentralized log processing method and system based on TEE and trusted measurement, and the system deploys an independent log service in each TEE, and establishes a trusted secure session channel with a trusted application in the same environment through bidirectional remote certification. A log service derives a dynamic key based on a real-time metric value (including an application identifier, a version number, code hash and a historical trust chain) of a trusted application to perform log encryption, calculates a ciphertext hash uplink evidence, and constructs a local hash chain in a TEE secure memory. When the application version is upgraded, the new version obtains the Hash chain tail value from the old version, the new log chain and the old log chain are connected through cascade Hash operation, and continuity is ensured. And cross-node credible verification is realized among different TEEs through remote certification, and distributed auditing is supported. According to the method, confidentiality, integrity, cross-version continuity and strong binding with the application state of the log are realized, and the security auditing capability of a distributed system is remarkably improved.
Owner:LINGSHU TECH CO LTD

Communication methods and devices between trusted applications in a multi-trusted execution environment

This application provides a communication method and device for trusted applications in a multi-trusted execution environment, applied to an electronic device including a first trusted execution environment and a second trusted execution environment. The first trusted execution environment includes a first trusted application and a second trusted application, and the second trusted execution environment includes a third trusted application, a fourth trusted application, and a second proxy module. In response to an operation to enable a first service, the third trusted application of the electronic device calls the second proxy module, and through a first link created by the second proxy module, calls the first trusted application to execute the first service. In response to an operation to enable a second service, the fourth trusted application of the electronic device calls the second proxy module, and through the first link, calls the second trusted application to execute the second service. Since the first link can be reused by each trusted application in the first trusted execution environment, the system load can be reduced, and the communication quality between trusted applications in a multi-trusted execution environment can be improved.
Owner:HONOR DEVICE CO LTD

Trust management system and method

Provided are a trust management system and method, including a settlor module, a trustee module, a beneficiary module and a trust digital management module and effective in introducing automated and intelligent processing processes. The trust digital management module includes a trust-related question bank. The settlor control interface presents a plurality of questions of the trust-related question bank. The settlor module provides the trust digital management module with answers given by the client to the questions to allow the trust digital management module to create a digital trust agreement according to the answers. The settlor tracking module sends a message notification to the client according to application progress to reduce the need for human interventions, enhance trust application efficiency, and enable information to be real-time.
Owner:JOINVEST CO LTD

Equipment information identification method based on deep packet inspection

The invention provides an equipment information identification method based on deep packet inspection, and the method comprises the steps: S1, carrying out the deep packet inspection, identification and filtering of an input network data packet based on a preset trusted application rule base through a network intrusion detection engine, and obtaining trusted application traffic; s2, filtering user agent information based on a primary filtering rule in the trusted application traffic, and outputting candidate traffic; s3, for the candidate traffic, performing accurate extraction of equipment information from the whole HTTP protocol message to obtain structured equipment information; and S4, associating the structured equipment information with the corresponding network quintuple information, and outputting a value log file. According to the scheme, double screening is performed through combination of trusted application filtering and UA primary filtering, interference of forged UA and non-standard applications is eliminated from the source, and the accuracy of equipment detection is improved.
Owner:XIAN XINLU NETWORK TECH CO LTD

Face image input method and device, equipment and storage medium

The invention provides a face image input method and device, equipment and a storage medium, and the method comprises the steps: inputting a pre-generated face input instruction into a face recognition service process, so as to enable the face recognition service process to collect a face image, and initiating a memory application request to a kernel driver of a kernel layer; through a kernel driver, according to the memory application request and a preset allocation function, allocating a continuous memory from the continuous memory region; acquiring memory information of the continuous memory; sending the memory information to a face recognition service process, so that the face recognition service process sends the memory information to a client application, and the client application sends the memory information to a trusted application; after the trusted application receives the memory information, inputting the face image into a continuous memory according to the memory information; and after the face image is input, the continuous memory is released, so that the storage pressure of the electronic equipment is reduced.
Owner:SPREADTRUM COMM (TIANJIN) INC

Data transmission method and related apparatus

Embodiments of the present application provide a data transmission method and related apparatus, and relate to the technical field of terminals. The method is applied to an electronic device, the electronic device comprising a first secure environment TEE, a smart sensor hub, a non-secure environment REE, a client application CA running in the non-secure environment REE, and a first trusted application TA running in the first secure environment TEE. The method comprises: the client application CA indicating first information to the first trusted application TA, the first information being used to indicate target data of the first trusted application TA; and the first trusted application TA transmitting the target data of the first trusted application TA to the smart sensor hub in response to the first information. In this way, the communication mode of the trusted application TA can be enriched.
Owner:HONOR DEVICE CO LTD

Virtual secure element application system and method based on trusted execution environment

A virtual secure element application system and method based on a trusted execution environment are disclosed. The system comprises: a virtual secure element interface component deployed in a rich execution environment and at least one application; a virtual secure element trusted application deployed in a trusted execution environment, the virtual secure element trusted application being configured to create and run a virtual card operating system and at least one virtual applet running on the virtual card operating system; wherein the virtual secure element interface component provides a standard access interface consistent with a physical secure element, receives instructions from the application, and forwards the instructions to the virtual secure element trusted application; the virtual card operating system in the virtual secure element trusted application interprets and executes the instructions, calls a corresponding virtual applet in the at least one virtual applet for processing, and returns the processing result to the application via the virtual secure element interface component. The system can combine the respective functions of the secure element and the trusted execution environment.
Owner:WUXI RONGKA TECH CO LTD

Digital currency transaction method and system, device, apparatus, and storage medium

A mobile device for a digital currency transaction, a digital currency transaction method and system, an electronic apparatus, and a storage medium. The mobile device, as an acceptance terminal, comprises: a digital currency acquiring application executable in a first execution environment and a digital currency trusted application executable in a second execution environment. The digital currency acquiring application is configured to initiate a digital currency acquiring transaction to a payment terminal to obtain digital currency payment information or code information of an offline payment code returned by the payment terminal. The digital currency trusted application is configured to execute encryption and integrity processing of digital currency transaction information by using core key data stored in the second execution environment, and to send the processed digital currency transaction information to a digital currency backend system, such that the digital currency backend system executes the digital currency acquiring transaction.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Virtualization-based platform protection technology

A data processing system (DPS) uses platform protection technology (PPT) to protect some or all of the code and data belonging to certain software modules. The PPT may include a virtual machine monitor (VMM) to enable an untrusted application and a trusted application to run on top of a single operating system (OS), while preventing the untrusted application from accessing memory used by the trusted application. The VMM may use a first extended page table (EPT) to translate a guest physical address (GPA) into a first host physical address (HPA) for the untrusted application. The VMM may use a second EPT to translate the GPA into a second HPA for the trusted application. The first and second EPTs may map the same GPA to different HPAs. Other embodiments are described and claimed.
Owner:INTEL CORP

Trusted execution environment running state integrity measurement method facing TrustZone block chain node

The invention discloses a TrustZone block chain node-oriented trusted execution environment running state integrity measurement method, which relates to the field of computer technology and information security, and is composed of a strategy management module, an integrity measurement module, an evaluation module and a security log construction module. According to the method, the kernel, the static component, the trusted application and the system call in the trusted execution environment of the block chain node equipment can be measured, evaluated and recorded, and a complete log of the component and the event which influence the integrity during operation in the trusted execution environment is formed. The method is used for solving the problem that the integrity of the existing ARM TrustZone block chain node equipment is difficult to ensure when the equipment runs in the trusted execution environment, so that the node is trusted in the whole life cycle, and the integrity measurement of the running state of the TrustZone block chain node in the trusted execution environment is safely and efficiently realized.
Owner:BEIJING JIAOTONG UNIV

A method, apparatus and device for processing an image

This specification discloses an image processing method, apparatus, and device. The method is applied to a terminal device equipped with a trusted execution environment. The method includes: acquiring user image data by calling a camera component through a trusted application and setting the user image data in the trusted execution environment; generating watermark information for the user image data based on the user image data and a preset seed key in the trusted execution environment to protect the privacy of the user image data; sending the user image data, watermark information, and seed key to a server; triggering the server to verify the watermark information using the user image data and seed key to obtain a corresponding verification result; receiving the verification result sent by the server; and if the verification result is successful, performing corresponding business processing based on the user image data.
Owner:SHANGHAI JIAOTONG UNIV +1

Offline interaction system and method using cryptography

A method includes a first device receiving, from a second device, an interaction request message comprising an amount and a second device certificate. The first device can verify the second device certificate using a server computer public key corresponding to a server computer private key. A trusted application in a secure element of the first device can determine whether or not the amount is less than an offline amount stored in the secure element. If the amount is less than the offline amount, the trusted application can determine an updated offline amount based on the amount. The trusted application can generate an interaction response message comprising the amount and a trusted application certificate. The first device can then provide the interaction response message to the second device.
Owner:VISA INTERNATIONAL SERVICE ASSOCIATION

Android softpos trusted application method and application system

The application discloses an Android SoftPOS trusted application method and system. The method comprises the following steps: an application end initiates an authentication request to an application proof server, obtains verification data and a plurality of random numbers; then, device and application integrity verification is performed, integrity proof and hardware authentication certificates are generated, and the generated integrity proof and hardware authentication certificates are submitted to the server; after the server verifies the integrity proof and the hardware authentication certificates, the server issues a device-specific secure communication certificate for the application end; and the application end establishes a secure communication channel with the server by using the certificate. Through multi-stage verification and a random number mechanism, only trusted devices and applications can complete authentication, dynamic certificate issuance is combined, end-to-end secure communication is realized, the confidentiality and integrity of payment data are significantly improved, and security risks are reduced.
Owner:SHENZHEN TOPWISE COMM CO LTD

A privacy protection based biometric identification method, device and equipment

The embodiment of the specification discloses a privacy protection-based biological identification method, device and equipment, the method is applied to a terminal device provided with a trusted execution environment, and includes the following steps: in the case that a biological identification request is acquired, biological identification data of a user used for biological identification processing is collected based on a biological identification component; the biological identification data of the user is transmitted from the biological identification component to the trusted execution environment by a biological identification trusted application used for executing the biological identification processing; wherein the trusted execution environment is provided with a privacy processing rule for performing privacy protection processing on the biological identification data of the user provided by the biological identification trusted application; in the trusted execution environment, the biological identification data of the user is subjected to privacy protection processing by the privacy processing rule, and processed biological identification data of the user is obtained; the processed biological identification data of the user is acquired from the trusted execution environment based on the biological identification trusted application, and is provided to a server.
Owner:ALIPAY (HANGZHOU) INFORMATION TECH CO LTD