WO2014161458A1 - 用于安全性信息交互的设备及其系统管理装置的加载方法 - Google Patents

用于安全性信息交互的设备及其系统管理装置的加载方法 Download PDF

Info

Publication number
WO2014161458A1
WO2014161458A1 PCT/CN2014/074472 CN2014074472W WO2014161458A1 WO 2014161458 A1 WO2014161458 A1 WO 2014161458A1 CN 2014074472 W CN2014074472 W CN 2014074472W WO 2014161458 A1 WO2014161458 A1 WO 2014161458A1
Authority
WO
WIPO (PCT)
Prior art keywords
system management
management device
information interaction
security information
storage device
Prior art date
Application number
PCT/CN2014/074472
Other languages
English (en)
French (fr)
Inventor
柴洪峰
鲁志军
何朔
郭伟
周钰
于彬
Original Assignee
中国银联股份有限公司
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by 中国银联股份有限公司 filed Critical 中国银联股份有限公司
Publication of WO2014161458A1 publication Critical patent/WO2014161458A1/zh

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0853Network architectures or network communication protocols for network security for authentication of entities using an additional device, e.g. smartcard, SIM or a different communication terminal
    • GPHYSICS
    • G06COMPUTING; CALCULATING OR COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/70Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer
    • G06F21/71Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information
    • G06F21/74Protecting specific internal or peripheral components, in which the protection of a component leads to protection of the entire computer to assure secure computing or processing of information operating in dual or compartmented mode, i.e. at least one secure mode

Definitions

  • the present invention relates to a device for information interaction and a loading method thereof for the system management device, and more specifically The invention relates to a device for security information interaction and a loading method of the system management device thereof.
  • a device for security information interaction based on an existing trusted environment platform which usually includes System management device (such as a conventional multimedia operating system) and additional security system management device (example In addition to a secure operating system, such as TEE technology, additional security system management devices are usually Pre-built (for example, at the factory) in a non-volatile memory (such as EEPROM or FLASH) in.
  • System management device such as a conventional multimedia operating system
  • additional security system management device example In addition to a secure operating system, such as TEE technology, additional security system management devices are usually Pre-built (for example, at the factory) in a non-volatile memory (such as EEPROM or FLASH) in.
  • the existing technical solutions have the following problems: (1) the user cannot independently select the security system. Management device; (2) the user cannot upgrade the security system management device; (3) when the security system is managed When there is a problem with the device, the user cannot repair it by reinstalling it.
  • the present invention proposes to enable users to Security information for autonomously selecting a security system management device and upgrading and repairing it Interactive device and method of loading the system management device.
  • a device for security information interaction includes:
  • the first system management device providing an operating environment for a conventional application
  • the second system management device providing a security mode for the security application Operating environment to perform security information interaction processes
  • first storage device being the first system management device and the second system
  • the management device provides the environmental resources required for normal operation
  • the security information is used.
  • the interacting device uses the first system management device as the currently used system management device, but at the current Where the application to be run is a security application, the device for security information interaction will
  • the second system management device serves as a system management device currently in use.
  • the device for security information interaction is further include:
  • a second storage device configured to store a system management device to be operated
  • the guiding device stores the system tube to be operated stored in the second storage device Loading the device to the first storage device to operate as the second system management device, or Installing, by the communication interface, a system management device installation package stored in an external storage device to the Corresponding locations in the second storage device to form a system management device to be operated and then to be shipped a system management device of the row is loaded to the first storage device as the second system management device Running, or directly loading the system management device stored in the external storage device via the communication interface Loading to the first storage device to operate as the second system management device;
  • a user interface for receiving the selection instruction from a user.
  • the device for security information interaction is activated Afterwards, the user can enter a corresponding user interface of the user interface through a preset switch to input the Selecting an instruction indicating that loading to the first storage device is required as the second system a loading target that is managed by the management device, the loading target is one or more selected from the following items a system management device stored in the second storage device, stored in the external storage device One or more system management device installation packages, and one or both of the external storage devices Multiple system management devices.
  • the The user can set the loading order of the plurality of loading targets by the selection instruction.
  • the second storage device is a non-volatile memory.
  • the guiding device follows the selection before performing a loading operation
  • the loading order set by the instruction sequentially authenticates the one or more loading targets until the first is found a certified load target and then perform a load on the first certified mount target Operation, if the entire authentication process fails, clear relevant data generated during the authentication process and return to the The user interface prompts the user to reselect the load target.
  • the device for security information interaction is activated Thereafter, if the user does not input the selection instruction, the guiding device refers to the configuration file
  • the illustrated load target performs the load operation in the following manner: according to the load order set by the configuration file Performing a load operation on one or more load targets until one of the one or more load targets The load targets were loaded successfully.
  • the user is able to upgrade and/or through the guiding device Reload the second system management device currently in use.
  • Loading method of a security system management device for a device for security information interaction the party The method includes the following steps:
  • the system pipe to be operated stored in the second storage device The device is loaded to the first storage device to operate as a security system management device or will be stored externally a system management device installation package in the storage device is mounted to a corresponding location in the second storage device To form a system management device to be operated and then load the system management device to be operated to the office Said first storage device to operate as said security system management device, or directly stored externally a system management device in the storage device is loaded to the first storage device as the security system tube Run the device.
  • the method has the following advantages: enables the user to independently select the security system management device and can Upgrade and fix.
  • FIG. 1 is a schematic structure of an apparatus for security information interaction according to an embodiment of the present invention
  • FIG. 2 is a security system management of an apparatus for security information interaction in accordance with an embodiment of the present invention.
  • the device for security information interaction disclosed by the present invention includes a first system tube.
  • said A system management device 1 such as a conventional multimedia operating system, provides an operating environment for conventional applications.
  • the second system management device 2 is a security application (ie, an application requiring high security, such as gold) Payment applications in the field of integration) provide an operating environment in a secure mode to perform security information interactions Cheng.
  • the first storage device 3 (for example, a memory) is the first system management device 1 and the second system The management device 2 provides the environmental resources required for normal operation.
  • the communication interface 4 performs the said security Data communication between devices that interact with sexual information and external devices.
  • the application currently running is In the case of a conventional application, the device for security information interaction installs the first system management Set 1 as the currently used system management device, and the current application to be run is a security application.
  • the device for security information interaction will be the second system management device 2 (for example, security) Operating system) as a currently used system management device (exemplarily, said for security information exchange Inter-devices can be performed between the first system management device 1 and the second system management device 2 Switch).
  • the apparatus for security information interaction disclosed by the present invention further includes a guiding device 7.
  • the second storage device 5 is configured to store a system to be operated Management device.
  • the guiding device 7 manages the system to be operated stored in the second storage device 5 Loading the device into the first storage device 3 (eg, a memory) as the second system management device 2 And running, or via the communication interface 4, to be stored in an external storage device (eg, for security purposes)
  • a system management device installation package in a storage device in the connected remote server is installed to the second storage Corresponding positions in the storage device 5 to form a system management device to be operated and then to operate the system to be operated
  • the management device is loaded to the first storage device 3 (for example, a memory) to be managed as the second system
  • the device 2 is
  • the user can enter the device through a preset switch (such as a shortcut key).
  • a preset switch such as a shortcut key.
  • the selection instruction indicating a need Loading to the first storage device 3 (eg, a memory) to operate as the second system management device 2 a load target, the load target being one or more selected from the following: the second storage a system management device stored in 5, one or more systems stored in the external storage device a management device installation package (such as a secure operating system installation package) and the external storage device One or more system management devices stored.
  • the device for security information interaction disclosed in the present invention, if the user selects a plurality of loading targets, wherein the user can set the loading of the plurality of loading targets by the selection instruction Load order.
  • the second storage The device is a non-volatile memory such as EEPROM or FLASH.
  • the guiding device 7 is performing a loading operation (that is, mounting the loading target to the second storage device) Corresponding position in 5 and possibly subsequent loading of the loading target to the first storage device 3) And authenticating the one or more loading targets in sequence according to a loading order set by the selection instruction (This authentication is used to identify whether the loading target is issued by a certified or authorized party) until Find the first certified load target and then target the first certified load target Perform a load operation, if the entire authentication process fails, clear the relevant data generated during the authentication process and Return to the user interface to prompt the user to reselect the load target.
  • a loading operation that is, mounting the loading target to the second storage device
  • the guiding device 7 is performing a loading operation (that is, mounting the loading target to the second storage device) Corresponding position in 5 and possibly subsequent loading of the loading target to the first storage device 3)
  • authenticating the one or more loading targets in sequence according to a loading order set by the selection instruction (This authentication is used to identify whether the loading target is issued by a certified or
  • the guiding device 7 saves the relevant public key and signs the system with the associated private key Management device installation package, whereby if the guiding device 7 is able to verify the signature, the system management The device installation package is certified.
  • the boot device After the device with full information interaction is started, if the user does not input the selection instruction, the boot device Performing a load operation for the load target indicated by the configuration file in the following manner: according to the match Setting the loading order of the file to sequentially load one or more loading targets until the one One of the load targets is loaded successfully (ie, the default highest priority is loaded first) Load target, and load additional load targets in order when the load target fails to load).
  • the user can pass The guiding device 7 upgrades and/or reloads the second system management device 2 currently in use.
  • the device for security information interaction disclosed by the present invention has the following advantages: It is enough for the user to choose the security system management device autonomously and to upgrade and repair it.
  • the loading method of the security system management device of the device comprises the following steps: (A1) in the security letter After the device that interacts with the interaction starts, receives a selection instruction from the user; (A2) based on the selection instruction, Loading the system management device to be operated stored in the second storage device to the first storage device (eg Memory) to operate as a security system management device or to be stored on an external storage device (eg with The SD card connected to the device for security information interaction or through the network and the security information
  • the system management device installation package in the storage device in the remote server connected to the interactive device is installed to a corresponding location in the second storage device to form a system management device to be operated and then to a system management device to be operated loaded to the first storage device (eg, a memory) as the security System management device to run, or directly stored in
  • the security system management device for the device for security information interaction disclosed by the present invention
  • the loading method further includes: after the device for security information interaction is started, the user passes a preset switch (such as a shortcut key) enters a corresponding user interface to input the selection instruction, the selection
  • the instruction instruction indicates that it needs to be loaded into the first storage device (for example, a memory) as the security system tube a load target that is run by the device, the load target is one or more selected from the following: a system management device stored in the second storage device, one stored in the external storage device Or multiple system management device installation packages (such as a secure operating system installation package), and the external storage One or more system management devices stored in the device.
  • the security system management device for the device for security information interaction disclosed by the present invention The loading method further includes: if the user selects a plurality of loading targets, the user passes the selection The instruction sequence sets the loading order of the plurality of loading targets.
  • the security system management device for the device for security information interaction disclosed in the present invention is a non-volatile memory (such as EEPROM or FLASH).
  • the security system management device for the device for security information interaction disclosed by the present invention further includes: when the loading target is one stored in the external storage device Or multiple system management device installation packages (eg, a secure operating system installation package) and/or the external storage When one or more system management devices are stored in the device, the loading operation is performed (immediately loading the target) Mounting to a corresponding location in the second storage device and possibly subsequently loading the loading target to the location Said first storage device) in front of the one or more of the loading order set according to said selection instruction
  • the load target is authenticated (this authentication is used to identify whether the load target is authenticated or authorized Issued by the relevant party until the first certified load target is found, and then for the first Performs a load operation through a certified load target, and clears the entire authentication process if it fails
  • the relevant data generated during the process is returned to the user interface to prompt the user to reselect the loading target.
  • an authentication method may be used: the device for security information interaction saves correlation Public key, and the associated system management device installation package is signed using the associated private key, thereby The device for security information interaction can verify the signature, and the system management device installs the package authentication pass. Over.
  • the security system management device for the device for security information interaction disclosed by the present invention
  • the loading method further includes: after the device for security information interaction is started, if the user If the selection instruction is not input, the loading target indicated by the configuration file is executed as follows. Loading operation: loading one or more loading targets in sequence according to the loading order set by the configuration file Loading operations until one of the one or more load targets is successfully loaded (ie, first Load the default highest priority load target and load them in order when the load target fails to load Additional loading target).
  • the security system management device for the device for security information interaction disclosed by the present invention The loading method further includes: the user can upgrade and/or reload the second system tube currently in use Device.
  • the security system management device for the device for security information interaction disclosed by the present invention
  • the loading method has the following advantages: enables the user to independently select the security system management device It can be upgraded and fixed.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Hardware Design (AREA)
  • Computer Security & Cryptography (AREA)
  • Theoretical Computer Science (AREA)
  • General Engineering & Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • Signal Processing (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Mathematical Physics (AREA)
  • Software Systems (AREA)
  • General Physics & Mathematics (AREA)
  • Computing Systems (AREA)
  • Stored Programmes (AREA)
  • Management, Administration, Business Operations System, And Electronic Commerce (AREA)

Abstract

本发明提出了用于安全性信息交互的设备及其系统管理装置的加载方法,所述方法包括:在用于安全性信息交互的设备启动后,接收来自用户的选择指令;基于所述选择指令,将存储在外部存储装置中的系统管理装置安装包安装到所述第二存储装置中的相应位置以构成待运行的系统管理装置并随后将所述待运行的系统管理装置装载到所述第一存储装置以作为所述安全系统管理装置而运行。本发明所公开的设备及方法能够使得用户可以自主地选择安全系统管理装置并可对其进行升级和修复。

Description

用于安全性信息交互的设备及其系统管理装置的加载方法 技术领域
本发明涉及用于信息交互的设备及其系统管理装置的加载方法,更具体 地,涉及用于安全性信息交互的设备及其系统管理装置的加载方法。
背景技术
目前,随着计算机和网络应用的日益广泛以及不同领域的业务种类的日益 丰富,用于安全性信息交互(即对安全性要求较高的信息交互,例如金融领域 中的交易处理过程)的设备(尤其是基于移动终端的安全性信息交互设备)变 得越来越重要。
在现有的基于可信环境平台的用于安全性信息交互的设备(其通常包括常 规的系统管理装置(如常规的多媒体操作系统)和附加的安全系统管理装置(例 如附加的安全操作系统),诸如TEE技术)中,附加的安全系统管理装置通常 被预先(例如出厂时)内置在非易失性存储器(例如EEPROM或FLASH) 中。
然而,现有的技术方案存在如下问题:(1)用户无法自主地选择安全系统 管理装置;(2)用户无法对安全系统管理装置进行升级;(3)当安全系统管理 装置出现问题时,用户无法通过重新安装方式进行修复。
因此,存在如下需求:提供能够使得用户可以自主地选择安全系统管理装 置并可对其进行升级和修复的用于安全性信息交互的设备及其系统管理装置 的加载方法。
发明内容
为了解决上述现有技术方案所存在的问题,本发明提出了能够使得用户可 以自主地选择安全系统管理装置并可对其进行升级和修复的用于安全性信息 交互的设备及其系统管理装置的加载方法。
本发明的目的是通过以下技术方案实现的:
一种用于安全性信息交互的设备,所述用于安全性信息交互的设备包括:
第一系统管理装置,所述第一系统管理装置为常规的应用提供运行环境;
第二系统管理装置,所述第二系统管理装置为安全性应用提供安全模式下 的运行环境,以执行安全性信息交互过程;
第一存储装置,所述第一存储装置为所述第一系统管理装置和所述第二系 统管理装置提供正常运行所需的环境资源;
通信接口,所述通信接口执行所述用于安全性信息交互的设备与外部设备 之间的数据通信;
其中,在当前待运行的应用是常规的应用的情况下,所述用于安全性信息 交互的设备将所述第一系统管理装置作为当前使用的系统管理装置,而在当前 待运行的应用是安全性应用的情况下,所述用于安全性信息交互的设备将所述 第二系统管理装置作为当前使用的系统管理装置。
在上面所公开的方案中,优选地,所述用于安全性信息交互的设备进一步 包括:
第二存储装置,所述第二存储装置用于存储待运行的系统管理装置;
引导装置,在所述用于安全性信息交互的设备启动后,基于配置文件或用 户的选择指令,所述引导装置将存储在所述第二存储装置中的待运行的系统管 理装置装载到所述第一存储装置以作为所述第二系统管理装置而运行,或者经 由所述通信接口将存储在外部存储装置中的系统管理装置安装包安装到所述 第二存储装置中的相应位置以构成待运行的系统管理装置并随后将所述待运 行的系统管理装置装载到所述第一存储装置以作为所述第二系统管理装置而 运行,或者经由所述通信接口直接将存储在外部存储装置中的系统管理装置装 载到所述第一存储装置以作为所述第二系统管理装置而运行;
用户接口,所述用户接口用于接收来自用户的所述选择指令。
在上面所公开的方案中,优选地,在所述用于安全性信息交互的设备启动 后,用户能够通过预设的开关进入所述用户接口的对应的用户界面以输入所述 选择指令,所述选择指令指示需要装载到所述第一存储装置以作为所述第二系 统管理装置而运行的装载目标,所述装载目标是从下列项中选择的一个或多 个:所述第二存储装置中所存储的系统管理装置,所述外部存储装置中所存储 的一个或多个系统管理装置安装包、以及所述外部存储装置中所存储的一个或 多个系统管理装置。
在上面所公开的方案中,优选地,如果用户选择多个装载目标,则所述用 户能够通过所述选择指令设定所述多个装载目标的装载顺序。
在上面所公开的方案中,优选地,所述第二存储装置是非易失性存储器。
在上面所公开的方案中,优选地,当所述装载目标是所述外部存储装置中 所存储的一个或多个系统管理装置安装包和/或所述外部存储装置中所存储的 一个或多个系统管理装置时,所述引导装置在执行装载操作之前按照所述选择 指令设定的装载顺序依次对所述一个或多个装载目标进行认证,直至找出第一 个通过认证的装载目标,并随后针对所述第一个通过认证的装载目标执行装载 操作,如果整个认证过程失败,则清除认证过程中产生的相关数据并返回所述 用户界面以提示用户重新选择装载目标。
在上面所公开的方案中,优选地,在所述用于安全性信息交互的设备启动 后,如果用户没有输入所述选择指令,则所述引导装置针对所述配置文件所指 示的装载目标以如下方式执行装载操作:按照所述配置文件设定的装载顺序依 次对一个或多个装载目标进行装载操作,直至所述一个或多个装载目标中的一 个装载目标被装载成功。
在上面所公开的方案中,优选地,用户能够通过所述引导装置升级和/或 重新装载当前使用的第二系统管理装置。
本发明的目的也可以通过以下技术方案实现:
一种用于安全性信息交互的设备的安全系统管理装置的加载方法,所述方 法包括下列步骤:
(A1)在用于安全性信息交互的设备启动后,接收来自用户的选择指令;
(A2)基于所述选择指令,将存储在第二存储装置中的待运行的系统管 理装置装载到第一存储装置以作为安全系统管理装置而运行,或者将存储在外 部存储装置中的系统管理装置安装包安装到所述第二存储装置中的相应位置 以构成待运行的系统管理装置并随后将所述待运行的系统管理装置装载到所 述第一存储装置以作为所述安全系统管理装置而运行,或者直接将存储在外部 存储装置中的系统管理装置装载到所述第一存储装置以作为所述安全系统管 理装置而运行。
本发明所公开的用于安全性信息交互的设备及其系统管理装置的加载方 法具有下列优点:能够使得用户可以自主地选择安全系统管理装置并可以对其 进行升级和修复。
附图说明
结合附图,本发明的技术特征以及优点将会被本领域技术人员更好地理 解,其中:
图1是根据本发明的实施例的用于安全性信息交互的设备的示意性结构 图;
图2是根据本发明的实施例的用于安全性信息交互的设备的安全系统管理 装置的加载方法的流程图。
具体实施方式
图1是根据本发明的实施例的用于安全性信息交互的设备的示意性结构 图。如图1所示,本发明所公开的用于安全性信息交互的设备包括第一系统管 理装置1、第二系统管理装置2、第一存储装置3、通信接口4。其中,所述第 一系统管理装置1(例如常规的多媒体操作系统)为常规的应用提供运行环境。 所述第二系统管理装置2为安全性应用(即对安全性要求较高的应用,例如金 融领域中的支付应用)提供安全模式下的运行环境,以执行安全性信息交互过 程。所述第一存储装置3(例如内存)为所述第一系统管理装置1和所述第二系 统管理装置2提供正常运行所需的环境资源。所述通信接口4执行所述用于安全 性信息交互的设备与外部设备之间的数据通信。其中,在当前待运行的应用是 常规的应用的情况下,所述用于安全性信息交互的设备将所述第一系统管理装 置1作为当前使用的系统管理装置,而在当前待运行的应用是安全性应用的情 况下,所述用于安全性信息交互的设备将所述第二系统管理装置2(例如安全 操作系统)作为当前使用的系统管理装置(示例性地,所述用于安全性信息交 互的设备能够在所述第一系统管理装置1和所述第二系统管理装置2之间进行 切换)。
优选地,本发明所公开的用于安全性信息交互的设备进一步包括引导装置 7、第二存储装置5和用户接口6。所述第二存储装置5用于存储待运行的系统 管理装置。在所述用于安全性信息交互的设备启动后,基于配置文件或用户的 选择指令,所述引导装置7将存储在所述第二存储装置5中的待运行的系统管理 装置装载到所述第一存储装置3(例如内存)以作为所述第二系统管理装置2 而运行,或者经由所述通信接口4将存储在外部存储装置(例如与该用于安全 性信息交互的设备相连的SD卡或通过网络与该用于安全性信息交互的设备 相连的远程服务器中的存储设备)中的系统管理装置安装包安装到所述第二存 储装置5中的相应位置以构成待运行的系统管理装置并随后将所述待运行的系 统管理装置装载到所述第一存储装置3(例如内存)以作为所述第二系统管理 装置2而运行,或者经由所述通信接口4直接将存储在外部存储装置(例如与该 用于安全性信息交互的设备相连的SD卡或通过网络与该用于安全性信息交 互的设备相连的远程服务器中的存储设备)中的系统管理装置装载到所述第一 存储装置3(例如内存)以作为所述第二系统管理装置2而运行。所述用户接口 6用于接收来自用户的所述选择指令。
优选地,在本发明所公开的用于安全性信息交互的设备中,在所述用于安 全性信息交互的设备启动后,用户能够通过预设的开关(例如快捷键)进入所 述用户接口6的对应的用户界面以输入所述选择指令,所述选择指令指示需要 装载到所述第一存储装置3(例如内存)以作为所述第二系统管理装置2而运行 的装载目标,所述装载目标是从下列项中选择的一个或多个:所述第二存储装 置5中所存储的系统管理装置,所述外部存储装置中所存储的一个或多个系统 管理装置安装包(例如安全操作系统安装包)、以及所述外部存储装置中所存 储的一个或多个系统管理装置。
优选地,在本发明所公开的用于安全性信息交互的设备中,如果用户选择 多个装载目标,则所述用户能够通过所述选择指令设定所述多个装载目标的装 载顺序。
优选地,在本发明所公开的用于安全性信息交互的设备中,所述第二存储 装置是非易失性存储器(诸如EEPROM或FLASH)。
优选地,在本发明所公开的用于安全性信息交互的设备中,当所述装载目 标是所述外部存储装置中所存储的一个或多个系统管理装置安装包(例如安全 操作系统安装包)和/或所述外部存储装置中所存储的一个或多个系统管理装 置时,所述引导装置7在执行装载操作(即将装载目标安装到所述第二存储装 置5中的相应位置以及可能的随后将装载目标装载到所述第一存储装置3)之前 按照所述选择指令设定的装载顺序依次对所述一个或多个装载目标进行认证 (该认证用于鉴别所述装载目标是否是经过认证或授权的相关方发布的),直至 找出第一个通过认证的装载目标,并随后针对所述第一个通过认证的装载目标 执行装载操作,如果整个认证过程失败,则清除认证过程中产生的相关数据并 返回所述用户界面以提示用户重新选择装载目标。示例性地,可以使用如下认 证方式:所述引导装置7保存相关的公钥,而使用相关联的私钥签名所述系统 管理装置安装包,由此,如果所述引导装置7能够验证该签名,则该系统管理 装置安装包认证通过。
优选地,在本发明所公开的用于安全性信息交互的设备中,在所述用于安 全性信息交互的设备启动后,如果用户没有输入所述选择指令,则所述引导装 置针对所述配置文件所指示的装载目标以如下方式执行装载操作:按照所述配 置文件设定的装载顺序依次对一个或多个装载目标进行装载操作,直至所述一 个或多个装载目标中的一个装载目标被装载成功(即首先装载默认最高优先级 的装载目标,并且当该装载目标装载失败时按照顺序装载另外的装载目标)。
优选地,在本发明所公开的用于安全性信息交互的设备中,用户能够通过 所述引导装置7升级和/或重新装载当前使用的第二系统管理装置2。
由上可见,本发明所公开的用于安全性信息交互的设备具有下列优点:能 够使得用户可以自主地选择安全系统管理装置并可以对其进行升级和修复。
图2是根据本发明的实施例的用于安全性信息交互的设备的安全系统管理 装置的加载方法的流程图。如图2所示,本发明所公开的用于安全性信息交互 的设备的安全系统管理装置的加载方法包括下列步骤:(A1)在用于安全性信 息交互的设备启动后,接收来自用户的选择指令;(A2)基于所述选择指令, 将存储在第二存储装置中的待运行的系统管理装置装载到第一存储装置(例如 内存)以作为安全系统管理装置而运行,或者将存储在外部存储装置(例如与 该用于安全性信息交互的设备相连的SD卡或通过网络与该用于安全性信息 交互的设备相连的远程服务器中的存储设备)中的系统管理装置安装包安装到 所述第二存储装置中的相应位置以构成待运行的系统管理装置并随后将所述 待运行的系统管理装置装载到所述第一存储装置(例如内存)以作为所述安全 系统管理装置而运行,或者直接将存储在外部存储装置(例如与该用于安全性 信息交互的设备相连的SD卡或通过网络与该用于安全性信息交互的设备相 连的远程服务器中的存储设备)中的系统管理装置装载到所述第一存储装置 (例如内存)以作为所述安全系统管理装置而运行。
优选地,本发明所公开的用于安全性信息交互的设备的安全系统管理装置 的加载方法进一步包括:在所述用于安全性信息交互的设备启动后,用户通过 预设的开关(例如快捷键)进入对应的用户界面以输入所述选择指令,所述选 择指令指示需要装载到所述第一存储装置(例如内存)以作为所述安全系统管 理装置而运行的装载目标,所述装载目标是从下列项中选择的一个或多个:所 述第二存储装置中所存储的系统管理装置,所述外部存储装置中所存储的一个 或多个系统管理装置安装包(例如安全操作系统安装包)、以及所述外部存储 装置中所存储的一个或多个系统管理装置。
优选地,本发明所公开的用于安全性信息交互的设备的安全系统管理装置 的加载方法进一步包括:如果用户选择多个装载目标,则所述用户通过所述选 择指令设定所述多个装载目标的装载顺序。
优选地,在本发明所公开的用于安全性信息交互的设备的安全系统管理装 置的加载方法中,所述第二存储装置是非易失性存储器(诸如EEPROM或 FLASH)。
优选地,本发明所公开的用于安全性信息交互的设备的安全系统管理装置 的加载方法进一步包括:当所述装载目标是所述外部存储装置中所存储的一个 或多个系统管理装置安装包(例如安全操作系统安装包)和/或所述外部存储 装置中所存储的一个或多个系统管理装置时,在执行装载操作(即将装载目标 安装到所述第二存储装置中的相应位置以及可能的随后将装载目标装载到所 述第一存储装置)之前按照所述选择指令设定的装载顺序依次对所述一个或多 个装载目标进行认证(该认证用于鉴别所述装载目标是否是经过认证或授权的 相关方发布的),直至找出第一个通过认证的装载目标,并随后针对所述第一 个通过认证的装载目标执行装载操作,并且如果整个认证过程失败,则清除认 证过程中产生的相关数据并返回所述用户界面以提示用户重新选择装载目标。 示例性地,可以使用如下认证方式:所述用于安全性信息交互的设备保存相关 的公钥,而使用相关联的私钥签名所述系统管理装置安装包,由此,如果所述 用于安全性信息交互的设备能够验证该签名,则该系统管理装置安装包认证通 过。
优选地,本发明所公开的用于安全性信息交互的设备的安全系统管理装置 的加载方法进一步包括:在所述用于安全性信息交互的设备启动后,如果用户 没有输入所述选择指令,则针对配置文件所指示的装载目标以如下方式执行装 载操作:按照所述配置文件设定的装载顺序依次对一个或多个装载目标进行装 载操作,直至所述一个或多个装载目标中的一个装载目标被装载成功(即首先 装载默认最高优先级的装载目标,并且当该装载目标装载失败时按照顺序装载 另外的装载目标)。
优选地,本发明所公开的用于安全性信息交互的设备的安全系统管理装置 的加载方法进一步包括:用户能够升级和/或重新装载当前使用的第二系统管 理装置。
由上可见,本发明所公开的用于安全性信息交互的设备的安全系统管理装 置的加载方法具有下列优点:能够使得用户可以自主地选择安全系统管理装置 并可以对其进行升级和修复。
尽管本发明是通过上述的优选实施方式进行描述的,但是其实现形式并不 局限于上述的实施方式。应该认识到:在不脱离本发明主旨和范围的情况下, 本领域技术人员可以对本发明做出不同的变化和修改。

Claims (9)

  1. 一种用于安全性信息交互的设备,所述用于安全性信息交互的设备包 括:
    第一系统管理装置,所述第一系统管理装置为常规的应用提供运行环境;
    第二系统管理装置,所述第二系统管理装置为安全性应用提供安全模式下 的运行环境,以执行安全性信息交互过程;
    第一存储装置,所述第一存储装置为所述第一系统管理装置和所述第二系 统管理装置提供正常运行所需的环境资源;
    通信接口,所述通信接口执行所述用于安全性信息交互的设备与外部设备 之间的数据通信;
    其中,在当前待运行的应用是常规的应用的情况下,所述用于安全性信息 交互的设备将所述第一系统管理装置作为当前使用的系统管理装置,而在当前 待运行的应用是安全性应用的情况下,所述用于安全性信息交互的设备将所述 第二系统管理装置作为当前使用的系统管理装置。
  2. 根据权利要求1所述的用于安全性信息交互的设备,其特征在于,所述 用于安全性信息交互的设备进一步包括:
    第二存储装置,所述第二存储装置用于存储待运行的系统管理装置;
    引导装置,在所述用于安全性信息交互的设备启动后,基于配置文件或用 户的选择指令,所述引导装置将存储在所述第二存储装置中的待运行的系统管 理装置装载到所述第一存储装置以作为所述第二系统管理装置而运行,或者经 由所述通信接口将存储在外部存储装置中的系统管理装置安装包安装到所述 第二存储装置中的相应位置以构成待运行的系统管理装置并随后将所述待运 行的系统管理装置装载到所述第一存储装置以作为所述第二系统管理装置而 运行,或者经由所述通信接口直接将存储在外部存储装置中的系统管理装置装 载到所述第一存储装置以作为所述第二系统管理装置而运行;
    用户接口,所述用户接口用于接收来自用户的所述选择指令。
  3. 根据权利要求2所述的用于安全性信息交互的设备,其特征在于,在所 述用于安全性信息交互的设备启动后,用户能够通过预设的开关进入所述用户 接口的对应的用户界面以输入所述选择指令,所述选择指令指示需要装载到所 述第一存储装置以作为所述第二系统管理装置而运行的装载目标,所述装载目 标是从下列项中选择的一个或多个:所述第二存储装置中所存储的系统管理装 置,所述外部存储装置中所存储的一个或多个系统管理装置安装包、以及所述 外部存储装置中所存储的一个或多个系统管理装置。
  4. 根据权利要求3所述的用于安全性信息交互的设备,其特征在于,如果 用户选择多个装载目标,则所述用户能够通过所述选择指令设定所述多个装载 目标的装载顺序。
  5. 根据权利要求4所述的用于安全性信息交互的设备,其特征在于,所述 第二存储装置是非易失性存储器。
  6. 根据权利要求5所述的用于安全性信息交互的设备,其特征在于,当所 述装载目标是所述外部存储装置中所存储的一个或多个系统管理装置安装包 和/或所述外部存储装置中所存储的一个或多个系统管理装置时,所述引导装 置在执行装载操作之前按照所述选择指令设定的装载顺序依次对所述一个或 多个装载目标进行认证,直至找出第一个通过认证的装载目标,并随后针对所 述第一个通过认证的装载目标执行装载操作,如果整个认证过程失败,则清除 认证过程中产生的相关数据并返回所述用户界面以提示用户重新选择装载目 标。
  7. 根据权利要求6所述的用于安全性信息交互的设备,其特征在于,在所 述用于安全性信息交互的设备启动后,如果用户没有输入所述选择指令,则所 述引导装置针对所述配置文件所指示的装载目标以如下方式执行装载操作:按 照所述配置文件设定的装载顺序依次对一个或多个装载目标进行装载操作,直 至所述一个或多个装载目标中的一个装载目标被装载成功。
  8. 根据权利要求7所述的用于安全性信息交互的设备,其特征在于,用户 能够通过所述引导装置升级和/或重新装载当前使用的第二系统管理装置。
  9. 一种用于安全性信息交互的设备的安全系统管理装置的加载方法,所 述方法包括下列步骤:
    (A1)在用于安全性信息交互的设备启动后,接收来自用户的选择指令;
    (A2)基于所述选择指令,将存储在第二存储装置中的待运行的系统管 理装置装载到第一存储装置以作为安全系统管理装置而运行,或者将存储在外 部存储装置中的系统管理装置安装包安装到所述第二存储装置中的相应位置 以构成待运行的系统管理装置并随后将所述待运行的系统管理装置装载到所 述第一存储装置以作为所述安全系统管理装置而运行,或者直接将存储在外部 存储装置中的系统管理装置装载到所述第一存储装置以作为所述安全系统管 理装置而运行。
PCT/CN2014/074472 2013-04-02 2014-04-01 用于安全性信息交互的设备及其系统管理装置的加载方法 WO2014161458A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201310112102.8 2013-04-02
CN201310112102.8A CN104102497B (zh) 2013-04-02 2013-04-02 用于安全性信息交互的设备及其系统管理装置的加载方法

Publications (1)

Publication Number Publication Date
WO2014161458A1 true WO2014161458A1 (zh) 2014-10-09

Family

ID=51657592

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2014/074472 WO2014161458A1 (zh) 2013-04-02 2014-04-01 用于安全性信息交互的设备及其系统管理装置的加载方法

Country Status (2)

Country Link
CN (1) CN104102497B (zh)
WO (1) WO2014161458A1 (zh)

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105636027A (zh) * 2015-05-20 2016-06-01 宇龙计算机通信科技(深圳)有限公司 外部设备连接方法、外部设备连接装置和终端

Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1922623A (zh) * 2004-02-17 2007-02-28 富士通株式会社 无线钱包
CN101833817A (zh) * 2009-03-11 2010-09-15 中兴通讯股份有限公司 一种非接触电子支付中实现应用选择的方法及终端
CN102087687A (zh) * 2009-12-04 2011-06-08 株式会社Ntt都科摩 状态通知装置以及状态通知方法

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CA2650662A1 (en) * 2006-04-24 2007-11-08 Encryptakey, Inc. Portable device and methods for performing secure transactions
US8024790B2 (en) * 2007-04-11 2011-09-20 Trend Micro Incorporated Portable secured computing environment for performing online confidential transactions in untrusted computers
CN101256608B (zh) * 2008-03-25 2010-04-07 北京飞天诚信科技有限公司 安全操作方法和系统

Patent Citations (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN1922623A (zh) * 2004-02-17 2007-02-28 富士通株式会社 无线钱包
CN101833817A (zh) * 2009-03-11 2010-09-15 中兴通讯股份有限公司 一种非接触电子支付中实现应用选择的方法及终端
CN102087687A (zh) * 2009-12-04 2011-06-08 株式会社Ntt都科摩 状态通知装置以及状态通知方法

Cited By (1)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105636027A (zh) * 2015-05-20 2016-06-01 宇龙计算机通信科技(深圳)有限公司 外部设备连接方法、外部设备连接装置和终端

Also Published As

Publication number Publication date
CN104102497A (zh) 2014-10-15
CN104102497B (zh) 2017-08-25

Similar Documents

Publication Publication Date Title
US10417427B2 (en) Method for authenticating firmware volume and system therefor
US10395039B2 (en) Customer-owned trust of device firmware
US20150193620A1 (en) System and Method for Managing UEFI Secure Boot Certificates
US9916574B2 (en) Secure computing device and method
CN101231768B (zh) 一种多应用智能卡及实现智能卡多应用的方法
US10338933B2 (en) Method for generating custom BIOS setup interface and system therefor
US9569620B2 (en) Method for processing UEFI protocols and system therefor
US9413746B2 (en) Extension point application and configuration of a login module
US20100082955A1 (en) Verification of chipset firmware updates
CN110008690B (zh) 终端应用的权限管理方法、装置、设备和介质
CN104023032B (zh) 基于可信执行环境技术的应用受限卸载方法、服务器和终端
US20180217831A1 (en) Method and apparatus for secure multi-cycle vehicle software updates
US20140149730A1 (en) Systems and methods for enforcing secure boot credential isolation among multiple operating systems
US11698971B2 (en) Secure boot device
US9081965B2 (en) Systems and methods for command-based entry into basic input/output system setup from operating system
US10771462B2 (en) User terminal using cloud service, integrated security management server for user terminal, and integrated security management method for user terminal
CN101895883A (zh) 一种支持鉴权算法更新的智能卡及方法
US10262309B1 (en) Augmenting a BIOS with new programs
US12118092B2 (en) Secure firmware interface
WO2014161458A1 (zh) 用于安全性信息交互的设备及其系统管理装置的加载方法
CN102622254A (zh) 电视机宕机处理方法和系统
CN115344401A (zh) 基于鸿蒙系统的xfs实现方法、装置、设备与可读存储介质
KR20150105271A (ko) 악성 코드 차단 방법, 커널 레벨에서 악성 코드를 차단하는 휴대형 단말기 및 악성 코드 차단 방법의 프로그램을 저장하는 다운로드 서버
CN116400935B (zh) 一种应用安装系统及方法
US11989300B2 (en) Firmware secure boot customization extensions

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 14778886

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

32PN Ep: public notification in the ep bulletin as address of the adressee cannot be established

Free format text: NOTING OF LOSS OF RIGHTS PURSUANT TO RULE 112(1)EPC ( EPO FORM 1205A DATED 26/01/2016 )

122 Ep: pct application non-entry in european phase

Ref document number: 14778886

Country of ref document: EP

Kind code of ref document: A1