Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

106 results about "Trusted application" patented technology

A trusted application is an application developed by a third party that is given trusted status to run as part of Skype for Business Server but that is not a built-in part of the product.

Data security protection method and system for large model training

The invention discloses a data security protection method and system for large model training. The core of the method is that a data safe box trusted application (TA application) is deployed in a trusted execution environment (TEE) and cooperatively works with a user-defined virtual file system driver at a host machine side, so that an end-to-end secret state data access control link is constructed. Before encryption protection of sensitive data, a measurement value (including code hash, configuration parameters and a runtime state) of a current TEE instance is submitted to a remote verification service through a data safe box TA application, and the verification service only sends the measurement value (including code hash, configuration parameters and a runtime state) of the current TEE instance to the remote verification service after confirming that the TEE environment meets a preset security policy (such as a kernel version, a software version and configuration parameter compliance). And generating a secret key encrypted by a custom virtual file system on a host machine side through derivation. And malicious copying of a system memory and a storage medium is prevented, so that the traditional attack defense capability is effectively improved.
Owner:PANOVASIC TECHNOLOGY CO LTD

SoC chip pin layout intelligent optimization method based on matrix module

The invention provides an SoC chip pin layout intelligent optimization method based on a matrix module, and relates to the technical field of layout optimization, and the method comprises the steps: carrying out the application scene mining of an SoC chip, and carrying out the external module relation sorting of D trusted application scenes and the chip pin layout information of the SoC chip; matrix module layout compensation is carried out on the chip pin layout information according to the chip pin external relation graph network; performing D-dimensional scene search optimization on the first chip pin layout adjustment space according to the D trusted application scenes; guiding the first chip pin layout adjustment space to carry out D-round differential variation breeding expansion; and according to the layout risk analysis model and the layout improper calculation condition, carrying out progressive optimization on the second chip pin layout adjustment space to obtain a chip layout optimization result. According to the invention, the technical problem that the SoC chip pin layout stability is poor in the prior art can be solved, and the technical effect of improving the layout stability is achieved.
Owner:OPTEK MICROELECTRONICS CO LTD

System and method for remote attestation of vehicle features

Methods for attestation of a vehicle feature associated with a vehicle control unit are provided and include: detecting, using a trusted application, whether a configurable feature has been activated based on one or more detection models; periodically detecting during runtime, using each of the one or more detection models, whether the configurable feature is activated; generating a report of attestation results indicating that the configurable feature is one of: activated and unauthorized; activated and authorized; un-activated and authorized; and un-activated and unauthorized; determining whether an activated feature is unauthorized, wherein the activated feature is the configurable feature that has been detected as being activated; and activating a response mechanism and restoring the configurable feature of the vehicle to an inactive state in response to the activated feature being unauthorized.
Owner:DENSO CORP

End-side large model parameter protection method and system based on trusted execution environment

The invention provides an end-side large model parameter protection method and system based on a trusted execution environment, and the method comprises the steps: enabling a large model client application program to receive the input of a user, and transmitting the input of the user to a trusted application, namely, a large model security application; the REE OS kernel forwards the request of the user mode to the trusted application, proxy I / O and NPU of the trusted application and continuous memory allocation requests are achieved, and trusted application thread scheduling is achieved; the security monitor is used for forwarding a request of the REE OS kernel to the TEE OS kernel; the TEE OS kernel is responsible for carrying out security configuration related to the TrustZone with high privilege and realizing address space isolation between security applications; and the large model security application realizes pipeline recovery accelerated reasoning, dynamic memory capacity expansion and NPU device calling by an NPU driver to perform calculation acceleration. According to the method, the hardware acceleration capability of the reasoning task is guaranteed, meanwhile, the scale of a TEE trusted computing base (TCB) is controlled, and the overall safety and the performance expandability of the system are improved.
Owner:SHANGHAI JIAOTONG UNIV

Integrity verification and quality evaluation method before agricultural Internet of Things data uplink

The invention relates to an integrity verification and quality evaluation method before agricultural Internet of Things data uploading, and belongs to the technical field of artificial intelligence and block chains. The method comprises the following steps: collecting agricultural Internet of Things data and constructing a data set; constructing a complete feature vector by adopting a double-branch filling network; generating a quality label for each sample; an integrity verification and quality evaluation model based on a deep neural network is constructed, and sample-level overall quality scoring, sensor-level abnormal confidence and data fingerprint generation are realized; performing verification and evaluation by setting thresholds of three prediction results; performing supervised training on the model through a composite loss function; and performing integrity verification and quality evaluation on to-be-evaluated agricultural Internet of Things data by adopting the trained model, and realizing reliable chaining, secure storage and trusted application of the agricultural Internet of Things data to a block chain for data samples which pass the integrity verification and have the overall quality score reaching the standard. The prediction precision can be improved.
Owner:QINGDAO AGRI UNIV

Android SoftPOS trusted application method and application system

The invention discloses an Android SoftPOS (Point Of Sale) trusted application method and an Android SoftPOS trusted application system. The method comprises the following steps: an application end initiates an authentication request to an application proof server, and obtains verification data and a plurality of random numbers; carrying out equipment and application integrity verification, generating an integrity proof and a hardware authentication certificate, and submitting the integrity proof and the hardware authentication certificate to a server; after the server passes the verification, signing and issuing a specific safety communication certificate of the equipment to the application end; and the application end establishes a secure communication channel with the server according to the certificate. Through multi-stage verification and a random number mechanism, it is ensured that only trusted equipment and applications can complete authentication, end-to-end secure communication is achieved by combining dynamic certificate signing and issuing, the confidentiality and integrity of payment data are remarkably improved, and the security risk is reduced.
Owner:SHENZHEN TOPWISE COMM CO LTD

Security virtual machine sensitive data full life cycle protection method and system and medium

The invention provides a safe virtual machine sensitive data full life cycle protection method and system and a medium, and the method comprises the steps that a collaborative architecture of a safe virtual machine module and a trusted execution environment module is constructed, the safe virtual machine module runs in a common world Android system and comprises a protected virtual machine, and the trusted execution environment module runs in the protected virtual machine; an encryption and decryption demand is triggered through a callback function in the load; and the trusted execution environment module runs in the secure world, and key management and encryption and decryption operations are executed by a trusted application. The two modules are connected through a data interaction module. When the protected virtual machine is closed or dormant, the sensitive data is transmitted to the trusted execution environment module through the client application to be encrypted and then stored in the nonvolatile storage; and when the protected virtual machine is started or awakened, the encrypted data is read, decrypted by the trusted execution environment module and then returned to the protected virtual machine, so that full-flow hardware-level protection of the data from operation to storage is realized. The invention aims to realize the hardware-level security protection of the sensitive data in the full life cycle of the virtual machine.
Owner:KYLIN CORP

Virtualization-based platform protection technology

A data processing system (DPS) uses platform protection technology (PPT) to protect some or all of the code and data belonging to certain software modules. The PPT may include a virtual machine monitor (VMM) to enable an untrusted application and a trusted application to run on top of a single operating system (OS), while preventing the untrusted application from accessing memory used by the trusted application. The VMM may use a first extended page table (EPT) to translate a guest physical address (GPA) into a first host physical address (HPA) for the untrusted application. The VMM may use a second EPT to translate the GPA into a second HPA for the trusted application. The first and second EPTs may map the same GPA to different HPAs. Other embodiments are described and claimed.
Owner:INTEL CORP

Data interaction method, system and device based on trusted execution environment, medium and program

The embodiment of the invention discloses a data interaction method, system and device based on a trusted execution environment, a medium and a program. The method comprises the steps that a trusted application generates an original request instruction according to request data and sends the original request instruction to a target TEE SE API; the target TEE SE API converts the original request instruction to obtain a conversion request instruction and sends the conversion request instruction to an SE protocol stack entry API; the SE protocol stack entry API carries out SE protocol stack data unification processing on the conversion request instruction to obtain a unified request instruction and sends the unified request instruction to an SE protocol stack; the SE protocol stack sends the unified request instruction to an SE hardware unit; and the SE hardware unit processes the unified request instruction to generate an original response instruction. According to the technical scheme, the adaptation cost, the maintenance cost and the memory computing space in the data interaction process based on the trusted execution environment can be reduced, and the efficiency and maintainability of data interaction based on the trusted execution environment are improved.
Owner:SHANGHAI TRUSTKERNEL INFORMATION TECH CO LTD

Network detection method and related device, electronic device and storage medium

The present application discloses a network detection method and related devices, electronic devices and storage media, wherein the network detection method includes: selecting an application that currently triggers a network service request as a target application; predicting the current network status based on the historical network information determined after the target application and the applications in the trusted application set each recently triggered a network service request; wherein the historical network information includes the historical network status and the historical moment when the historical network status was determined; based on the current network status, determining the timeout request duration of the target application; wherein the timeout request duration is positively correlated with the network quality represented by the current network status; and determining whether it is prompted that the network service request of the target application cannot be responded to based on whether the request feedback result of the target application is obtained within the timeout request duration. The above scheme can improve the judgment accuracy of the network status and the feedback speed of the application.
Owner:IFLYTEK CO LTD

Trusted application startup method, device, equipment, medium and product based on trusted data space

The application discloses a trusted application program starting method and device based on a trusted data space, equipment, medium and product. The method comprises the following steps: in response to a program starting request of a target trusted application program, performing integrity verification on the target trusted application program to obtain an integrity verification result; if the integrity verification result is that the verification is passed, creating a target anonymous pipe between the target trusted application program, and shielding other anonymous pipes; the other anonymous pipes are the anonymous pipes except the target anonymous pipe; starting the target trusted application program according to program starting parameters of the target trusted application program, so that the target trusted application program connects the target anonymous pipe and runs the application program itself. The technical scheme of the embodiment of the application can ensure the integrity and security in the process of installing, starting and running the trusted application program.
Owner:LINGSHU TECH CO LTD

ARM heterogeneous edge device-oriented trusted deep learning reasoning method

The invention relates to a trusted deep learning reasoning method for an ARM heterogeneous edge device. The method comprises the following steps: a deployment stage: storing a structure file and a weight of a model in a core stack of a TEE through a static trusted application PTA; in the reasoning stage, REE loads a structure model and a weight from TEE secure storage, initializes a reasoning model and creates a thread pool; dynamic trusted applications TA0 and TA1 are adopted for asynchronous cooperative verification, TA0 executes non-convolutional layer reasoning and convolutional layer verification, TA1 executes convolutional layer verification, and TA0 and TA1 are executed in a staggered mode; verifying a convolution layer reasoning result by using an FTC algorithm; the GPU is used for accelerating parallel reasoning of a convolution layer, multi-TA cooperative verification is executed through the multi-core CPU, and asynchronous parallelism of model credible reasoning and convolution credible verification is achieved. The method is low in time delay and high in reliability, the privacy and integrity of the deep learning model can be protected, the time overhead of credible reasoning is reduced, and the real-time performance of credible deep learning reasoning on the ARM heterogeneous edge device is improved.
Owner:FUZHOU UNIV

Communication method and communication device

The embodiment of the invention provides a communication method and a communication device. The method comprises the steps that a network data analysis function network element determines and discovers a trusted application function network element and an untrusted application function network element; the network data analysis function network element sends a first request and a second request to a network storage function network element, the first request is used for requesting information of a trusted application function network element, and the second request is used for requesting information of an untrusted application function network element; the network data analysis function network element receives a first response and a second response from the network storage function network element, the first response comprises the information of the trusted application function network element, and the second response comprises the information of the untrusted application function network element. Therefore, the network data analysis function network element can simultaneously obtain the information of the trusted application function network element and the information of the untrusted application function network element from the network storage function network element, and AI cooperation between the network data analysis function network element and the trusted application function network element and between the network data analysis function network element and the untrusted application function network element is satisfied.
Owner:HUAWEI TECH CO LTD

Data processing method and device, electronic equipment and medium

The invention relates to a data processing method and device, electronic equipment and a medium. The data processing method comprises the following steps: acquiring calling data from a client application; setting the state of the core of the processor as an activated state in an operating system of the trusted execution environment; according to the calling data, a corresponding trusted application is called for data processing, processing result data is obtained, and the trusted application runs in an operating system of the trusted execution environment; wherein the number of the cores in the activated state is related to the number of the client applications calling the trusted application, and the cores in the activated state are used for running the trusted application. As the core in the activated state can be scheduled in the trusted execution environment, the corresponding trusted application does not need to be bound, so that the utilization rate of the processor is improved, and resources are fully utilized.
Owner:BEIJING XIAOMI MOBILE SOFTWARE CO LTD

Matter certificate burning method and device, equipment and medium

The invention relates to the technical field of firmware burning, and discloses a Matter certificate burning method and device, equipment and a medium. The method comprises the steps of loading a client application and a trusted application in response to a received burning request; calling a client application to receive a certificate file and a file key sent by the external equipment, and encrypting and transmitting the certificate file and the file key to a trusted application in the trusted execution environment; and calling the trusted application to decrypt the certificate file based on the file key to obtain the Matter certificate, and writing the Matter certificate into the secure storage area of the trusted execution environment. According to the embodiment of the invention, the security of Matter certificate burning can be improved.
Owner:SHENZHEN SDMC TECH CO LTD

A tenant sovereignty zone

The present disclosure relates to a system for secure processing and storing of sensitive data and non-sensitive data for a tenant in an execution environment of a cloud service. In the system according to the present disclosure, the sensitive data includes a plaintext sensitive data element. In contrast, the non-sensitive data does not include a plaintext sensitive data element. The execution environment of the system comprises a general execution area, wherein the general execution area allows full access by the cloud service provider, and a general application service running in the general execution area, wherein the general application service does not have access to the sensitive data, and wherein the general application service only processes the non-sensitive data. Furthermore, the execution environment of the system comprises a trusted execution area, and a trusted application service running in the trusted execution area.
Owner:COMFORTE AG

Key management method, mobile device for digital currency transaction, apparatus, system, and storage medium

Embodiments of the present disclosure provide a key management method, a mobile device for a digital currency transaction, an apparatus, a system, and a storage medium. The mobile device serves as an acceptance terminal, and comprises a digital currency acquirer application executable in a first execution environment and a digital currency trusted application executable in a second execution environment, and the second execution environment is securely isolated from the first execution environment. The digital currency acquirer application is configured to send a key application request to a digital currency background system, receive core key data by means of a secure channel between the digital currency background system and the mobile device, and when it is detected that the mobile device has the second execution environment and the executable digital currency trusted application is installed in the second execution environment, send the core key data to the digital currency trusted application. The digital currency trusted application is configured to receive the core key data sent by the digital currency acquirer application and store the core key data in the second execution environment.
Owner:THE PEOPLES BANK OF CHINA DIGITAL CURRENCY INST

Zero trust architecture with browser-supported security posture data collection

A zero trust application enables access to a protected resource from a client device associated with a user. The client device has a browser, and an agent running locally and accessible via a local loopback interface. During an authentication flow, a browser-based script executes in the browser to deliver a challenge to the agent, and to collect a response to that challenge from the agent using a graphics file-based encoding scheme, and to deliver that information to the application for verifying the client device and its security posture. Depending on that security posture, the authentication flow may be permitted to complete. If a failure of the security posture is identified, the user may be permitted during the on-going authentication flow to address that failure and request a re-check of the posture.
Owner:AGILEBITS INC DBA 1PASSWORD

Data transmission method and related apparatus

The embodiment of the application provides a kind of data transmission method and related device, it is related to terminal technical field.The method comprises: client application CA indicates first information to first trusted application TA, first information indicates the target data of transmission first trusted application TA.First trusted application TA responds to first information, and write target data to first memory area, and indicate second information to client application CA, second information is used to indicate target storage address of target data in first memory area, and first memory area is the memory area in trusted execution environment TEE.Client application CA indicates third information to sensor control center, and third information includes second information or address information determined based on second information.Sensor control center determines target storage address based on third information, and obtains target data from first memory area based on target storage address.In this way, the security of data from TEE transmission to sensorhub can be improved.
Owner:HONOR DEVICE CO LTD

Shared memory management method and device, electronic equipment and storage medium

The invention provides a shared memory management method and device, electronic equipment and a storage medium, and the shared memory management method comprises the following steps executed by a common operating system: receiving a data sending request sent by a common application program; in response to the data sending request, allocating a shared memory block in a shared memory pool to the common application, so that the common application transmits data to the trusted application through the shared memory block; wherein a virtual address of a shared memory block in the shared memory pool is a kernel virtual address, and the kernel virtual address and a physical address, distributed to a physical memory of a common operating system, in the physical memory connected with the processor have a mapping relationship; therefore, not only can the time overhead of sharing data from a common application program to a trusted application program be reduced, but also the method is more suitable for operating systems with lower complexity, such as a real-time operating system without a virtual address and physical address mapping function and the like.
Owner:PHYTIUM TECH CO LTD

Physiological information application platform

PendingUS20260188481A1Data transportEngineering
A physiological information application platform includes a physiological information application device. The physiological information application device provides data exchange and utilization between a client application and a server application. Before exchanging data between the client application and the server application, it is required to confirm that the applications are authenticated as trusted applications, and an authentication is performed by obtaining an authorized encryption file through an authorization mechanism. Therefore, the physiological information application device provides a data topology application and an alarm management mechanism within an alarm system. Furthermore, the physiological information application device can operate without transferring the data to an external system, thereby reducing a risk of data loss and theft and improving data security.
Owner:BROADSIMS INC

Trusted application management graphical user interface for electronic device

1. The name of the design product: trusted application management graphical user interface of electronic equipment. 2. The use of the design product: an electronic device. 3. The design points of the design product: in the graphical user interface of the electronic equipment. 4. The picture or photo that best indicates the design points: interface change state diagram 2. 5. The electronic equipment is a conventional design, and other views are omitted. 6. The use of the graphical user interface: the product interface is an interactive interface for trusted application management; for details viewing of trusted application management in an edge container service platform; the main view interface is an edge container service overview interface; in the main view interface, after clicking "trusted application management" in the left menu bar "application market", interface change state diagram 1 is displayed; in interface change state diagram 1, after clicking the application name in any list, interface change state diagram 2 is displayed; in interface change state diagram 2, after sliding up to the bottom of the interface, interface change state diagram 3 is displayed.
Owner:新奥新智科技有限公司

Encryption, decryption method, system, and electronic device and storage medium

PendingCN122339668ACiphertextEngineering
This invention provides an encryption method and system applied to a trusted application. The method includes: obtaining key encryption storage request information from a client application, the key encryption storage request information containing an original key to be encrypted; reading the hash value of the root key from the electronic fuse area; generating key encryption information based on the hash value; encrypting the original key using the key encryption information to obtain key ciphertext; and storing the key ciphertext in a storage device. The encryption scheme provided by this invention achieves efficient protection of the key by combining hardware and key transfer (TA) protection, effectively overcoming security vulnerabilities in traditional storage methods and enhancing the security, integrity, and availability of key management.
Owner:BEIJING CO WHEELS TECH CO LTD

Communication method and communication apparatus

Embodiments of the present application provide a communication method and a communication apparatus. The method comprises: a network data analytics function network element determines that a trusted application function network element and an untrusted application function network element are discovered; the network data analytics function network element sends a first request and a second request to a network storage function network element, the first request being used for requesting information about the trusted application function network element, and the second request being used for requesting information about the untrusted application function network element; and the network data analytics function network element receives a first response and a second response from the network storage function network element, the first response comprising the information about the trusted application function network element, and the second response comprising the information about the untrusted application function network element. Thus, the network data analytics function network element can obtain both the information about the trusted application function network element and the information about the untrusted application function network element from the network storage function network element, thereby meeting the requirement for AI collaboration of the network data analytics function network element with both the trusted application function network element and the untrusted application function network element.
Owner:HUAWEI TECH CO LTD

New graphical user interface for trusted application management of electronic devices

1. The name of the design product: new graphical user interface for trusted application management of electronic equipment. 2. The use of the design product: an electronic device. 3. The design points of the design product: the graphical user interface in the electronic equipment. 4. The picture or photo that best indicates the design points: interface change state diagram 1. 5. The electronic equipment is a conventional design, and other views are omitted. 6. The use of the graphical user interface: the product interface is a new interactive interface for trusted application management; it is used for new operation of trusted application management in the edge container service platform; the main view interface is an edge container service overview interface; in the main view interface, after clicking "trusted application management" in the left menu bar "application market", interface change state diagram 1 is displayed; in interface change state diagram 1, after clicking the "new" button in the upper right corner, interface change state diagram 2 is displayed; in interface change state diagram 2, after sliding to the bottom of the interface, interface change state diagram 3 is displayed.
Owner:新奥新智科技有限公司

Application verification method and apparatus

Embodiments of the present description provide an application verification method and apparatus. The method is executable by an attestation server, and comprises: receiving a first acquisition request for an identity credential sent by any first application in a target group, the target group comprising a plurality of associated trusted applications, and the first acquisition request comprising an application identity certificate of the first application; verifying the application identity certificate by using an application verification rule for the first application in a pre-stored group verification rule for the target group; and, in response to the application identity certificate passing the verification, generating and returning a first identity credential, the first identity credential comprising a group identifier of the target group and at least part of information in the application identity certificate, and being used for identity authentication when the first application communicates with other applications in the target group.
Owner:ANT GROUP CO LTD

Electronic device

An electronic device and a trusted application calling method are provided. After a client application initiates call information, a trusted application development platform receives the call information, determines a native trusted application corresponding to first identification information of the electronic device carried by the calling information from native trusted applications corresponding to at least two (or more) TEE OSs connected to the trusted application development platform, and sends the calling information to the native trusted applications corresponding to the first identification information. The native trusted application corresponding to the first identification information receives the calling information, determines a bytecode trusted application corresponding to the second identification information from at least one bytecode trusted application installed in the native trusted application according to the second identification information carried by the calling information, and calls the bytecode trusted application corresponding to the second identification information.
Owner:CHINA UNIONPAY

Authority management method and system for equipment flash, chip and intelligent terminal

The invention discloses an authority management method and system for equipment flashing, a chip and an intelligent terminal.The method comprises the steps that when an authorization mode for equipment flashing is a quick start authorization mode, a boot loader is started; the client application initiates a first authorization authentication request via the first trusted execution environment client interface; the trusted execution environment core driver receives the first authorization authentication request and switches the operating environment of the processor from a common world to a secure world; the trusted operating system receives and analyzes the first authorization authentication request, and schedules an early trusted application to obtain equipment fingerprint information from the first storage partition; when the equipment fingerprint information passes verification, modifying the first authorization mark, and correspondingly modifying the second authorization mark stored in the second storage partition; and the intelligent terminal is switched into the factory mode. According to the method and the device, the original flashing port can be controllably opened, so that the risk of illegal flashing is avoided, and meanwhile, legal flashing operation is guaranteed.
Owner:SHANGHAI SUMI TECH CO LTD +1

Data migration method, device, equipment, medium and product based on trusted execution environment in trusted data space

The application discloses a data migration method and device based on a trusted execution environment in a trusted data space, equipment, storage and products. The method comprises the following steps: sending a remote proof request to a second trusted application in a second trusted execution environment, so that the second trusted application generates and feeds back a remote authentication report based on the remote proof request; performing a secure and trusted verification on the remote authentication report, and after the verification is passed, sending a data key acquisition request to the second trusted application, so that the second trusted application generates and feeds back data key communication ciphertext according to the data key acquisition request; sending an encrypted data acquisition request to the second trusted application, so that the second trusted application generates and feeds back encrypted data according to the encrypted data acquisition request; and storing the data key communication ciphertext and the encrypted data. The technical scheme of the application realizes data security migration of the trusted application data, and realizes seamless access and use of the data in the new and old environments.
Owner:LINGSHU TECH CO LTD

Equipment disconnection overtime locking control method and system and electronic equipment

PendingCN121864474ASolve security blind spotsReduce operation and maintenance complexitySecuring communicationNetwork connectionEmbedded system
The invention discloses a device disconnection overtime locking control method and system and electronic device.The method comprises the steps that after a device is started, an encrypted channel between a client application and a trusted application is established through the client application, and locking basic configuration and state data are read from a secure storage partition; wherein the client application runs in a common execution environment of the system, and the trusted application runs in a trusted execution environment of the system; the client application detects the network connection condition of the equipment in real time to obtain accumulated network disconnection time, and triggers the trusted application every a first time threshold value, so that the accumulated network disconnection time is encrypted and written into the secure storage partition through the trusted application; and when the accumulated network disconnection time exceeds a preset second time threshold value, the trusted application sets a machine locking position state of the equipment in the secure storage partition, and triggers the equipment to lock the machine.
Owner:SHANGHAI SUMI TECH CO LTD +1