WO2017084553A1 - 一种在设备之间进行授权的方法和装置 - Google Patents

一种在设备之间进行授权的方法和装置 Download PDF

Info

Publication number
WO2017084553A1
WO2017084553A1 PCT/CN2016/105852 CN2016105852W WO2017084553A1 WO 2017084553 A1 WO2017084553 A1 WO 2017084553A1 CN 2016105852 W CN2016105852 W CN 2016105852W WO 2017084553 A1 WO2017084553 A1 WO 2017084553A1
Authority
WO
WIPO (PCT)
Prior art keywords
authorization information
authorization
encrypted
tee
ree
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2016/105852
Other languages
English (en)
French (fr)
Inventor
李定洲
周钰
郭伟
陈成钱
严翔翔
曾望年
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
China Unionpay Co Ltd
Original Assignee
China Unionpay Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by China Unionpay Co Ltd filed Critical China Unionpay Co Ltd
Publication of WO2017084553A1 publication Critical patent/WO2017084553A1/zh
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Images

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols

Definitions

  • Embodiments of the present invention relate to methods and apparatus for authorizing between devices.
  • the authorized device authorizes the authorized device, so that the authorized device can proxy the authorized device for the authorized operation, for example, performing the function specified by the authorized device, and acquiring the resource specified by the authorized device.
  • the authorized device authorizes the authorized device through the server. Since the authorization process involves the server, the authorized device needs to send an application to the server before authorizing, and then the server pushes the authorization information to the authorized device. This will reduce the efficiency of the authorization and result in higher costs. On the other hand, since the authorization process involves the server, the authorization information must be transmitted over the network, which will reduce the security of the authorization, and this also requires the authorized device to receive the push authorization information online. In addition, an unsecured operating system that authorizes the device can also result in authorization information being at risk.
  • a method for authorizing between devices comprising an authorization process, the authorization process comprising: generating and encrypting authorization information at a TEE end of the first device, and transmitting the encrypted authorization information to the REE end of the first device
  • the second device receives the encrypted authorization information at the REE end of the second device, decrypts and verifies the encrypted authorization information at the TEE end of the second device, and stores the authorization information at the second device.
  • An apparatus for authorizing between devices comprising an authorization process device, the authorization device comprising: means for generating and encrypting authorization information at a TEE end of the first device for being encrypted at a REE end of the first device Means for transmitting authorization information to the second device, means for receiving the encrypted authorization information at the REE end of the second device, means for decrypting and verifying the encrypted authorization information at the TEE end of the second device, for A device that stores the authorization information at the second device.
  • the advantages of the present invention include: the authorization between the devices is not limited to the authentication of the networked device and the server; the transmission of the device authorization information and the security of the localized storage are guaranteed by the TEE security technology solution; and the traditional server authentication mode is supported.
  • FIG. 1 is a schematic diagram of authorization between devices in accordance with an embodiment of the present invention.
  • FIG. 2 is a flow diagram of authorizing between devices in accordance with an embodiment of the present invention.
  • FIG. 3 is a flow diagram of authorizing between devices in accordance with an embodiment of the present invention.
  • FIG. 1 is a schematic diagram of authorization between devices in accordance with an embodiment of the present invention.
  • Figure 1 shows an authorized device, an authorized device, and a server.
  • the server is optional.
  • the authorization process and the execution of the authorization operation can be done only by the interaction between the authorized device and the authorized device.
  • the authorized device and the authorized device are each capable of running a Trusted Execution Environment (TEE) and a Rich Execution Environment (REE).
  • TEE technology can provide an operating system protected by hardware isolation for smart terminals such as mobile communication terminals.
  • TEE is independent of REE (for example, the Android operating system) and performs security-related applications. Security-related sensitive operations on the smart terminal will be performed in the TEE, while applications other than the secure application are executed in the REE.
  • Each of the rights device and the authorized device is provided with a trusted storage unit, an authorization information verification unit, an authorization information generation unit, and a TEE proxy unit in the REE.
  • the authorization information generating unit may generate authorization information according to the user's instruction.
  • the authorization information may include an authorized operation, time, location, or device ID.
  • the authorization information can include the time and location at which the authorization information was generated.
  • the authorization information may further define an authorized operation, such as when and where the authorized operation may be sent.
  • the authorization information verification unit is used to verify the authorization information.
  • the trusted storage unit is used to securely store authorization information under the TEE.
  • the TEE proxy unit, under the REE is used to assist in the transmission of information between the authorized device and the authorized device.
  • the TEE proxy unit can communicate with the TEE proxy unit under the REE of the authorized device, for example, using a mobile network, Bluetooth, infrared, near field communication. It will be appreciated that the authorized device may also include similar units in order to function as an authorizing device.
  • the optional server may include an authorization information verification unit for supplementing the verification authorization information when the authorized device and the authorized device cannot complete the point-to-point communication.
  • the authorizing device transmits the authorization information encrypted under the TEE to the authorized device through the TEE proxy unit under the REE.
  • the authorized device receives the encrypted authorization information through the TEE proxy unit under the REE, and decrypts and verifies the authorization information under the TEE.
  • the authorization information that is decrypted and verified is stored in the trusted storage unit of the authorized device. Thereafter, the authorized device will be able to authorize the device to perform authorized operations in accordance with the authorization information. Therefore, under the premise of ensuring security, the efficiency of authorization and proxy between devices can be improved.
  • FIG. 2 is a flow diagram of authorizing between devices in accordance with an embodiment of the present invention.
  • This embodiment shows an authorization process for a method of authorizing between devices.
  • the authorization process includes:
  • Step 201 Generate and encrypt authorization information on the TEE end of the first device.
  • Step 202 The encrypted authorization information is transmitted to the second device at the REE end of the first device.
  • Step 203 This step is optional, and in this step, it is determined whether the authorization information is backed up to the server;
  • step 203 When it is determined in step 203 that the authorization information is not backed up to the server, the process proceeds to step 204: in this step, the encrypted authorization information is received at the REE end of the second device;
  • Step 205 Decrypt and verify the encrypted authorization information at the TEE end of the second device.
  • Step 206 Store the authorization information in the second device, and the first device that is the authorized device has completed the authorization for the second device that is the authorized device.
  • step 203 When it is determined in step 203 that the authorization information is backed up to the server, proceed to step 207: in this step, the encrypted authorization information is transmitted from the first device and stored to the server;
  • Step 208 Decrypt and verify the encrypted authorization information at the server
  • Step 209 The verified authorization information is stored at the server, and the backup of the authorization information at the server is completed.
  • the authorization information is signed using the private key at the TEE end of the first device, and the encrypted authorization information is decrypted and verified using the public key at the TEE end of the second device.
  • the authorization information includes an authorization operation and also includes one or more of the following: the time, location, and device ID at which the authorization operation was performed.
  • Step 302 Receive the request at the REE end of the second device,
  • Step 303 Encrypt the authorization information on the TEE end of the second device, and send the encrypted authorization information to the first device through the REE terminal.
  • Step 304 Receive encrypted authorization information on the REE end of the first device
  • Step 305 Decrypt and verify the encrypted authorization information at the TEE end of the first device
  • Step 306 After the verification is successful, the first device responds to the authorization operation from the second device. For example, the first device can perform corresponding operations according to a request from the second device.
  • the request includes a device ID.
  • the authorization information is encrypted using the public key at the TEE end of the second device, and the encrypted authorization information is decrypted and verified using the private key at the TEE end of the first device.
  • the process of performing the authorization operation further includes: encrypting the authorization information on the TEE end of the second device, and sending the encrypted authorization information to the server through the REE end, decrypting and verifying the TEE end of the first device.
  • the encrypted authorization information after the verification succeeds, notifies the first device to respond to the authorization operation from the second device through the server.
  • the first device and the second device are mobile communication terminals.
  • one of the following methods is used to communicate between the REE terminal of the first device and the REE terminal of the second device: mobile network, Bluetooth, infrared, near field communication.
  • the following describes an apparatus for authorizing between devices, which includes an authorization process device, the authorization device comprising: means for generating and encrypting authorization information at a TEE end of the first device for use at the REE end of the first device The means for transmitting the encrypted authorization information to the second device, the means for receiving the encrypted authorization information at the REE end of the second device, the means for decrypting and verifying the encrypted authorization information at the TEE end of the second device, Means for storing the authorization information at the second device.
  • the authorizing device further comprises: means for transmitting and storing the encrypted authorization information from the first device to the server.
  • the authorization information includes an authorization operation, and further includes one or more of the following: a time, a place, and a device ID at which the authorization operation is performed.
  • the apparatus further includes means for performing an authorization operation, the means for performing an authorization operation comprising: means for transmitting a request from the first device to the second device, requesting the second device to proxy the first device for authorization operation Means for receiving the request at the REE end of the second device for use in the second device
  • the TEE end encrypts the authorization information, and sends the encrypted authorization information to the device of the first device through the REE terminal, and the device for receiving the encrypted authorization information at the REE end of the first device, for the first device
  • the TEE device decrypts and verifies the encrypted authorization information for responding to the authorized operation of the device from the second device at the first device after the verification is successful.
  • the request includes a device ID.
  • the apparatus further comprises: means for encrypting the authorization information using the public key at the TEE end of the second device for decrypting and verifying the encrypted authorization information using the private key at the TEE end of the first device Device.
  • the exemplary embodiments can be implemented in hardware, software, or a combination thereof. For example, some aspects of the invention may be implemented in hardware, while other aspects may be implemented in software. Although aspects of the exemplary embodiments of the present invention may be shown and described as a block diagram, a flowchart, it is well understood that the devices or methods described herein may be implemented in a system as a non-limiting example as functional module. Furthermore, the above-described apparatus should not be construed as requiring such separation in all embodiments, but it should be understood that the described program components and systems can generally be integrated into a single software product or packaged into multiple software products. .

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • Computing Systems (AREA)
  • General Engineering & Computer Science (AREA)
  • Telephonic Communication Services (AREA)
  • Mobile Radio Communication Systems (AREA)

Abstract

在设备之间进行授权的方法的装置。方法包括授权过程,该授权过程包括:在第一设备的TEE端生成并加密授权信息,在第一设备的REE端将经加密的授权信息传输到第二设备,在第二设备的REE端接收经加密的授权信息,在第二设备的TEE端解密并验证经加密的授权信息,在第二设备存储该授权信息。

Description

一种在设备之间进行授权的方法和装置 技术领域
本发明的实施例涉及在设备之间进行授权的方法和装置。
背景技术
授权设备向被授权设备进行授权,从而被授权设备可以代理授权设备进行授权的操作,例如执行授权设备指定的功能、获取授权设备指定的资源。
目前,授权设备通过服务器向被授权设备进行授权。由于授权过程涉及服务器,授权设备在进行授权前需要向服务器发送申请,然后由服务器向被授权设备推送授权信息。这会降低授权效率,导致较高成本。另一方面,由于授权过程涉及服务器,授权信息必须经过网络传输,这将降低授权的安全性,而且这还要求被授权设备在线才能接收推送的授权信息。另外,授权设备的不安全的操作系统也会导致授权信息处于风险。
发明内容
一种在设备之间进行授权的方法,该方法包括授权过程,该授权过程包括:在第一设备的TEE端生成并加密授权信息,在第一设备的REE端将经加密的授权信息传输到第二设备,在第二设备的REE端接收经加密的授权信息,在第二设备的TEE端解密并验证经加密的授权信息,在第二设备存储该授权信息。
在设备之间进行授权的装置,其包括授权过程装置,该授权装置包括:用于在第一设备的TEE端生成并加密授权信息的装置,用于在第一设备的REE端将经加密的授权信息传输到第二设备的装置,用于在第二设备的REE端接收经加密的授权信息的装置,用于在第二设备的TEE端解密并验证经加密的授权信息的装置,用于在第二设备存储该授权信息的装置。
本发明的优势包括:设备间的授权不限于联网设备与服务器端的认证;设备授权信息的传输、本地化存储的安全通过结合TEE安全技术方案得到保障;支持传统的服务器认证方式。
当结合附图阅读以下描述时也将理解本发明的实施例的其它特征和优势,其中附图借助于实例示出了本发明的实施例的原理。
附图说明
图1是根据本发明实施例的在设备之间进行授权的示意图。
图2是根据本发明实施例的在设备之间进行授权的流程图。
图3是根据本发明实施例的在设备之间进行授权的流程图。
具体实施方式
在下文中,将结合实施例描述本发明的原理。应当理解的是,给出的实施例只是为了本领域技术人员更好地理解并且实践本发明,而不是限制本发明的范围。例如,本说明书中包含许多具体的实施细节不应被解释为对发明的范围或可能被要求保护的范围的限制,而是应该被视为特定于实施例的描述。例如,在各实施例的上下文描述的特征可被组合在单一实施例中来实施。在单一实施例的上下文中描述的特可在多个实施例来实施。
图1是根据本发明实施例的在设备之间进行授权的示意图。图1示出了授权设备、被授权设备、服务器。在该实施例中,服务器是可选的。授权过程和执行授权操作可以仅通过授权设备和被授权设备之间的交互完成。授权设备和被授权设备各自能够运行可信执行环境TEE(Trusted Execution Environment)和多媒体执行环境REE(Rich Execution Environment)下。TEE技术能够为诸如移动通信终端等智能终端提供受到硬件隔离保护的操作系统。TEE独立于REE(例如,Android操作系统),并执行与安全相关的应用。智能终端上与安全相关的敏感操作将在TEE中执行,而除安全应用以外的其它应用在REE中执行。如图所示,授 权设备和被授权设备各自在TEE中设置有可信存储单元、授权信息验证单元、授权信息生成单元,以及在REE中设置有TEE代理单元。
在授权设备中,授权信息生成单元中可以根据用户的指令生成授权信息。授权信息可以包括授权的操作、时间、地点或者设备ID。在一个实例中,授权信息可以包括授权信息生成时的时间和地点。在另一个实例中,授权信息可以进一步限定授权的操作,例如授权的操作可以发送的时间和地点。授权信息验证单元用于验证授权信息。可信存储单元用于在TEE下安全存储授权信息。TEE代理单元,处于REE下,用于辅助与被授权设备之间的信息传输。TEE代理单元例如可以使用移动网络、蓝牙、红外线、近场通信与被授权设备的REE下的TEE代理单元通信。可以理解的是,被授权设备也可以包括类似的单元以便作为扮演授权设备的角色。
图1中,可选的服务器可以包括授权信息验证单元,在被授权设备与授权设备无法完成点对点通信时用于补充验证授权信息。
在一个实例中,授权设备通过REE下的TEE代理单元向被授权设备发送在TEE下加密的授权信息。被授权设备通过REE下的TEE代理单元接收该加密的授权信息,并且在TEE下解密并且验证该授权信息。被解密并验证通过的授权信息被存储在被授权设备的可信存储单元中。之后,被授权设备将可以根据该授权信息代理授权设备执行被授权的操作。由此,在保证安全的前提下,可以提高设备之间的授权与代理的效率。
图2是根据本发明实施例的在设备之间进行授权的流程图。该实施例示出在设备之间进行授权的方法的授权过程。该授权过程包括:
步骤201:在第一设备的TEE端生成并加密授权信息;
步骤202:在第一设备的REE端将经加密的授权信息传输到第二设备;
步骤203:该步骤是可选的,在该步骤中判断是否将授权信息备份到服务器;
当在步骤203中判断不将授权信息备份到服务器时,进入步骤204:在该步骤中在在第二设备的REE端接收经加密的授权信息;
步骤205:在第二设备的TEE端解密并验证经加密的授权信息;
步骤206:在第二设备存储该授权信息,至此作为授权的设备的第一设备完成了对于作为被授权设备的第二设备的授权;
当在步骤203中判断将授权信息备份到服务器时,进入步骤207:在该步骤中从第一设备将经加密的授权信息发送并存储到服务器;
步骤208:在服务器解密并且验证经加密的授权信息;
步骤209:在服务器存储经验证的授权信息,至此完成授权信息在服务器的备份。
在一个实例中,在第一设备的TEE端使用私钥对授权信息进行签名,在第二设备的TEE端使用公钥解密并验证经加密的授权信息。
在一个实例中,授权信息包括授权操作,并且还包括以下一个或多个:进行授权操作的时间、地点、设备ID。
图3是根据本发明实施例的在设备之间进行授权的流程图。该实施例示出在设备之间进行授权的方法的授权操作的过程。该进行授权操作的过程包括:
步骤301:从第一设备向第二设备发送请求,请求第二设备代理第一设备进行授权操作,
步骤302:在第二设备的REE端接收该请求,
步骤303:在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给第一设备,
步骤304:在第一设备的REE端接收经加密的授权信息,
步骤305:在第一设备的TEE端解密并验证经加密的授权信息,
步骤306:在验证成功后,在第一设备响应来自第二设备的授权操作。例如,第一设备可以根据来自第二设备的请求进行相应的操作。
在一个实例中,该请求包括设备ID。
在一个实例中,在第二设备的TEE端使用公钥加密授权信息,在第一设备的TEE端使用私钥解密并验证经加密的授权信息。
在一个实例中,该进行授权操作的过程还包括:在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给服务器,在第一设备的TEE端解密并验证经加密的授权信息,在验证成功后,通过服务器通知第一设备响应来自第二设备的授权操作。
在本发明的上述实施例中,所述第一设备和所述第二设备是移动通信终端。
在本发明的上述实施例中,使用以下方式的一种在第一设备的REE端和第二设备的REE端之间通信:移动网络、蓝牙、红外线、近场通信。
图2和图3所示的各个框可被视为方法步骤、和/或被视为由于运行计算机程序代码而导致的操作、和/或被视为构建为实施相关功能的多个耦合的逻辑电路元件。尽管操作按特定的顺序在图中被描绘,但这不应被理解为要求按照所示的特定顺序或按依次顺序来执行这些操作,或要求所有例示的操作被执行,以达到理想的结果。在某些情况下,多任务并行处理可能是有利的。
以下描述在设备之间进行授权的装置,其包括授权过程装置,该授权装置包括:用于在第一设备的TEE端生成并加密授权信息的装置,用于在第一设备的REE端将经加密的授权信息传输到第二设备的装置,用于在第二设备的REE端接收经加密的授权信息的装置,用于在第二设备的TEE端解密并验证经加密的授权信息的装置,用于在第二设备存储该授权信息的装置。
在一个实施例中,该授权装置还包括:用于从第一设备将经加密的授权信息发送并存储到服务器的装置。用于在第一设备的TEE端使用私钥对授权信息进行签名的装置,用于在第二设备的TEE端使用公钥解密并验证经加密的授权信息的装置。
在一个实施例中,授权信息包括授权操作,并且还包括以下一个或多个:进行授权操作的时间、地点、设备ID。
在一个实施例中,该装置还包括进行授权操作的装置,该进行授权操作的装置包括:用于从第一设备向第二设备发送请求的装置,请求第二设备代理第一设备进行授权操作,用于在第二设备的REE端接收该请求的装置,用于在第二设备 的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给第一设备的装置,用于在第一设备的REE端接收经加密的授权信息的装置,用于在第一设备的TEE端解密并验证经加密的授权信息的装置,用于在验证成功后,在第一设备响应来自第二设备的授权操作的装置。
在一个实施例中,该请求包括设备ID。
在一个实施例中,该装置还包括:用于在第二设备的TEE端使用公钥加密授权信息的装置,用于在第一设备的TEE端使用私钥解密并验证经加密的授权信息的装置。
在一个实施例中,该进行授权操作的装置还包括:用于在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给服务器的装置,用于在第一设备的TEE端解密并验证经加密的授权信息的装置,用于在验证成功后,通过服务器通知第一设备响应来自第二设备的授权操作的装置。
示例性实施例可在硬件、软件或其组合中来实施。例如,本发明的某些方面可在硬件中实施,而其它方面则可在软件中实施。尽管本发明的示例性实施例的方面可被示出和描述为框图、流程图,但很好理解的是,这里描述的这些装置、或方法可在作为非限制性实例的系统中被实现为功能模块。此外,上述装置不应被理解为要求在所有的实施例中进行这种分离,而应该被理解为所描述的程序组件和系统通常可以被集成在单一的软件产品中或打包成多个软件产品。
相关领域的技术人员当结合附图阅读前述说明书时,对本发明的前述示例性实施例的各种修改和变形对于相关领域的技术人员会变得明显。因此,本发明的实施例不限于所公开的特定实施例,并且变形例和其它实施例意在涵盖在所附权利要求的范围内。

Claims (18)

  1. 一种在设备之间进行授权的方法,其特征在于,该方法包括授权过程,该授权过程包括:
    在第一设备的TEE端生成并加密授权信息,
    在第一设备的REE端将经加密的授权信息传输到第二设备,
    在第二设备的REE端接收经加密的授权信息,
    在第二设备的TEE端解密并验证经加密的授权信息,
    在第二设备存储该授权信息。
  2. 如权利要求1所述的方法,其特征在于,该授权过程还包括:
    从第一设备将经加密的授权信息发送并存储到服务器。
  3. 如权利要求1所述的方法,其特征在于,
    在第一设备的TEE端使用私钥对授权信息进行签名,
    在第二设备的TEE端使用公钥解密并验证经加密的授权信息。
  4. 如权利要求1所述的方法,其特征在于,
    授权信息包括授权操作,并且还包括以下一个或多个:进行授权操作的时间、地点、设备ID。
  5. 如权利要求1所述的方法,其特征在于,该方法还包括进行授权操作的过程,该进行授权操作的过程包括:
    从第一设备向第二设备发送请求,请求第二设备代理第一设备进行授权操作,
    在第二设备的REE端接收该请求,
    在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给第一设备,
    在第一设备的REE端接收经加密的授权信息,
    在第一设备的TEE端解密并验证经加密的授权信息,
    在验证成功后,在第一设备响应来自第二设备的授权操作。
  6. 如权利要求5所述的方法,其特征在于,
    该请求包括设备ID。
  7. 如权利要求5所述的方法,其特征在于,
    在第二设备的TEE端使用公钥加密授权信息,
    在第一设备的TEE端使用私钥解密并验证经加密的授权信息。
  8. 如权利要求5所述的方法,其特征在于,该进行授权操作的过程还包括:
    在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给服务器,
    在第一设备的TEE端解密并验证经加密的授权信息,
    在验证成功后,通过服务器通知第一设备响应来自第二设备的授权操作。
  9. 如权利要求1至8中任意一项所述的方法,其特征在于,所述第一设备和所述第二设备是移动通信终端。
  10. 如权利要求1至8中任意一项所述的方法,其特征在于,使用以下方式的一种在第一设备的REE端和第二设备的REE端之间通信:移动网络、蓝牙、红外线、近场通信。
  11. 一种在设备之间进行授权的装置,其特征在于,授权过程装置,该授权装置包括:
    用于在第一设备的TEE端生成并加密授权信息的装置,
    用于在第一设备的REE端将经加密的授权信息传输到第二设备的装置,
    用于在第二设备的REE端接收经加密的授权信息的装置,
    用于在第二设备的TEE端解密并验证经加密的授权信息的装置,
    用于在第二设备存储该授权信息的装置。
  12. 如权利要求11所述的装置,其特征在于,该授权装置还包括:
    用于从第一设备将经加密的授权信息发送并存储到服务器的装置。
  13. 如权利要求11所述的装置,其特征在于,
    用于在第一设备的TEE端使用私钥对授权信息进行签名的装置,
    用于在第二设备的TEE端使用公钥解密并验证经加密的授权信息的装置。
  14. 如权利要求11所述的装置,其特征在于,
    授权信息包括授权操作,并且还包括以下一个或多个:进行授权操作的时间、地点、设备ID。
  15. 如权利要求11所述的装置,其特征在于,该装置还包括进行授权操作的装置,该进行授权操作的装置包括:
    用于从第一设备向第二设备发送请求的装置,请求第二设备代理第一设备进行授权操作,
    用于在第二设备的REE端接收该请求的装置,
    用于在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给第一设备的装置,
    用于在第一设备的REE端接收经加密的授权信息的装置,
    用于在第一设备的TEE端解密并验证经加密的授权信息的装置,
    用于在验证成功后,在第一设备响应来自第二设备的授权操作的装置。
  16. 如权利要求15所述的装置,其特征在于,
    该请求包括设备ID。
  17. 如权利要求15所述的装置,其特征在于,还包括:
    用于在第二设备的TEE端使用公钥加密授权信息的装置,
    用于在第一设备的TEE端使用私钥解密并验证经加密的授权信息的装置。
  18. 如权利要求15所述的方法,其特征在于,该进行授权操作的装置还包括:
    用于在第二设备的TEE端加密授权信息,并通过REE端将经加密的授权信息发送给服务器的装置,
    用于在第一设备的TEE端解密并验证经加密的授权信息的装置,
    用于在验证成功后,通过服务器通知第一设备响应来自第二设备的授权操作的装置。
PCT/CN2016/105852 2015-11-16 2016-11-15 一种在设备之间进行授权的方法和装置 Ceased WO2017084553A1 (zh)

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN201510785827.2A CN105592071A (zh) 2015-11-16 2015-11-16 一种在设备之间进行授权的方法和装置
CN201510785827.2 2015-11-16

Publications (1)

Publication Number Publication Date
WO2017084553A1 true WO2017084553A1 (zh) 2017-05-26

Family

ID=55931286

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2016/105852 Ceased WO2017084553A1 (zh) 2015-11-16 2016-11-15 一种在设备之间进行授权的方法和装置

Country Status (3)

Country Link
CN (1) CN105592071A (zh)
TW (1) TWI636373B (zh)
WO (1) WO2017084553A1 (zh)

Families Citing this family (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN105592071A (zh) * 2015-11-16 2016-05-18 中国银联股份有限公司 一种在设备之间进行授权的方法和装置
US11258871B2 (en) 2016-11-14 2022-02-22 Huawei Technologies Co., Ltd. Message push method and terminal
CN108419224B (zh) * 2018-03-16 2020-12-18 上海百联集团股份有限公司 信标设备、待授权设备、服务器以及加密授权方法
CN110858245B (zh) * 2018-08-24 2021-09-21 珠海格力电器股份有限公司 一种授权方法及数据处理设备
CN109547451B (zh) * 2018-11-30 2021-05-25 四川长虹电器股份有限公司 基于tee的可信认证服务认证的方法
CN110011956B (zh) * 2018-12-12 2020-07-31 阿里巴巴集团控股有限公司 一种数据处理方法和装置
CN111444528B (zh) * 2020-03-31 2022-03-29 海信视像科技股份有限公司 数据安全保护方法、装置及存储介质
CN111510918B (zh) * 2020-04-28 2022-08-02 拉扎斯网络科技(上海)有限公司 通信方法、系统、装置、电子设备和可读存储介质
CN116049913B (zh) * 2022-05-24 2023-11-03 荣耀终端有限公司 数据保存方法、装置、电子设备及计算机可读存储介质

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103856621A (zh) * 2012-12-06 2014-06-11 北京三星通信技术研究有限公司 用户设备之间授权的方法及装置
CN104754552A (zh) * 2013-12-25 2015-07-01 中国移动通信集团公司 一种可信执行环境tee初始化方法及设备
WO2015142403A1 (en) * 2014-03-20 2015-09-24 Oracle International Corporation System and method for deriving secrets from a master key bound to an application on a device
CN105592071A (zh) * 2015-11-16 2016-05-18 中国银联股份有限公司 一种在设备之间进行授权的方法和装置

Family Cites Families (9)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
DE602004026787C5 (de) * 2004-03-22 2021-10-21 Nokia Technologies Oy Sicherer datentransfer
US20060020553A1 (en) * 2004-07-26 2006-01-26 Septon Daven W License proxy process to facilitate license sharing between a plurality of applications
US7882356B2 (en) * 2006-10-13 2011-02-01 Microsoft Corporation UPnP authentication and authorization
KR20080048764A (ko) * 2006-11-29 2008-06-03 삼성전자주식회사 권리객체에 대리 서명하는 방법 및 장치와 대리인증서 발급방법 및 장치
US20110154501A1 (en) * 2009-12-23 2011-06-23 Banginwar Rajesh P Hardware attestation techniques
US8788810B2 (en) * 2009-12-29 2014-07-22 Motorola Mobility Llc Temporary registration of devices
CN103186720B (zh) * 2011-12-28 2016-03-09 北大方正集团有限公司 一种数字版权管理方法、设备及系统
KR20130143263A (ko) * 2012-06-21 2013-12-31 에스케이플래닛 주식회사 트러스티드 플랫폼 기반의 개방형 아이디 인증 방법, 이를 위한 장치 및 시스템
US9348997B2 (en) * 2014-03-13 2016-05-24 Intel Corporation Symmetric keying and chain of trust

Patent Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN103856621A (zh) * 2012-12-06 2014-06-11 北京三星通信技术研究有限公司 用户设备之间授权的方法及装置
CN104754552A (zh) * 2013-12-25 2015-07-01 中国移动通信集团公司 一种可信执行环境tee初始化方法及设备
WO2015142403A1 (en) * 2014-03-20 2015-09-24 Oracle International Corporation System and method for deriving secrets from a master key bound to an application on a device
CN105592071A (zh) * 2015-11-16 2016-05-18 中国银联股份有限公司 一种在设备之间进行授权的方法和装置

Non-Patent Citations (1)

* Cited by examiner, † Cited by third party
Title
ZHANG, DAWEI ET AL.: "Security and Trusted Intelligent Mobile Terminal", ZTE TECHNOLOGY JOURNAL, vol. 21, no. 5, 31 October 2015 (2015-10-31), ISSN: 1009-6868 *

Also Published As

Publication number Publication date
CN105592071A (zh) 2016-05-18
TW201719476A (zh) 2017-06-01
TWI636373B (zh) 2018-09-21

Similar Documents

Publication Publication Date Title
TWI636373B (zh) Method and device for authorizing between devices
CN109347835B (zh) 信息传输方法、客户端、服务器以及计算机可读存储介质
US11501294B2 (en) Method and device for providing and obtaining graphic code information, and terminal
CN113114668B (zh) 一种信息传输方法、移动终端、存储介质及电子设备
CN107743067B (zh) 数字证书的颁发方法、系统、终端以及存储介质
CN111028397A (zh) 认证方法及装置、车辆控制方法及装置
CN110621014B (zh) 一种车载设备及其程序升级方法、服务器
CN102045333B (zh) 一种安全报文过程密钥的生成方法
CN105915338B (zh) 生成密钥的方法和系统
CN104704500B (zh) 用于片上系统装置中的内容保护的集成电路、无线显示系统、方法、装置、设备和介质
JP2008533882A (ja) 暗号化キーをバックアップ及び復元する方法
CN106411902B (zh) 一种数据安全传输方法及系统
CN110519215B (zh) 一种数据通信方法和装置
WO2018040642A1 (zh) 控制车辆与移动终端连接的方法、装置及车辆
US11153344B2 (en) Establishing a protected communication channel
CN116032556B (zh) 小程序应用的密钥协商方法及装置
CN114070614A (zh) 身份认证方法、装置、设备、存储介质和计算机程序产品
CN110838919B (zh) 通信方法、存储方法、运算方法及装置
CN113783879A (zh) 载具控制方法、系统、载具、设备及介质
JP2014235753A (ja) データを入力する方法と装置
CN115801232A (zh) 一种私钥保护方法、装置、设备及存储介质
CN109391581A (zh) 一种电子设备控制系统
CN107155184B (zh) 一种带有安全加密芯片的wifi模块及其通信方法
CN107682380B (zh) 一种交叉认证的方法及装置
WO2013189457A2 (zh) 终端和云系统服务器以及其交互方法和系统

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 16865730

Country of ref document: EP

Kind code of ref document: A1

NENP Non-entry into the national phase

Ref country code: DE

122 Ep: pct application non-entry in european phase

Ref document number: 16865730

Country of ref document: EP

Kind code of ref document: A1