WO2024255732A1 - 安全评估、业务处理、安全信息传输方法及相关设备 - Google Patents
安全评估、业务处理、安全信息传输方法及相关设备 Download PDFInfo
- Publication number
- WO2024255732A1 WO2024255732A1 PCT/CN2024/098430 CN2024098430W WO2024255732A1 WO 2024255732 A1 WO2024255732 A1 WO 2024255732A1 CN 2024098430 W CN2024098430 W CN 2024098430W WO 2024255732 A1 WO2024255732 A1 WO 2024255732A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- electronic device
- security
- digital certificate
- management server
- target
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/14—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/57—Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
- G06F21/577—Assessing vulnerabilities and evaluating computer system security
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/04—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
- H04L63/0428—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
- H04L63/0442—Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/08—Network architectures or network communication protocols for network security for authentication of entities
- H04L63/0823—Network architectures or network communication protocols for network security for authentication of entities using certificates
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/123—Applying verification of the received information received data contents, e.g. message integrity
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1466—Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/002—Countermeasures against attacks on cryptographic mechanisms
- H04L9/003—Countermeasures against attacks on cryptographic mechanisms for power analysis, e.g. differential power analysis [DPA] or simple power analysis [SPA]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/002—Countermeasures against attacks on cryptographic mechanisms
- H04L9/004—Countermeasures against attacks on cryptographic mechanisms for fault attacks
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3247—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/40—Network security protocols
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F2221/00—Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F2221/03—Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
- G06F2221/034—Test or assess a computer or a system
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/12—Details relating to cryptographic hardware or logic circuitry
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L2209/00—Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
- H04L2209/72—Signcrypting, i.e. digital signing and encrypting simultaneously
Definitions
- the present application relates to the field of communication technology, and in particular to a security assessment, business processing, security information transmission method and related equipment.
- application service providers e.g., mobile payment, mobile banking, financial services, etc.
- the application server sends a security assessment request to the electronic device, and the electronic device obtains the security status information of the Rich Execution Environment (REE) based on the security assessment request and performs a security assessment to obtain the security assessment result of the REE, and returns the security assessment result to the application server, and then the application server can determine whether to allow the electronic device to access the requested service based on the security assessment result.
- REE Rich Execution Environment
- the embodiments of the present application provide a security assessment, business processing, security information transmission method and related equipment, which can improve the reliability of security assessment results of electronic equipment.
- an embodiment of the present application provides a security assessment method, the method comprising:
- the security coprocessor of the electronic device Upon receiving a security assessment request sent by an application server, the security coprocessor of the electronic device determines a target security assessment result according to first security information, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
- the security coprocessor of the electronic device decrypts the first ciphertext using the root key of the electronic device to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device;
- the security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
- the electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- an embodiment of the present application provides a security assessment device, which is applied to an electronic device, and the device includes:
- a first determination module is used to determine a target security assessment result according to first security information when receiving a security assessment request sent by an application server, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
- a signature module used to sign the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result
- the first sending module is used to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- an embodiment of the present application provides a service processing method, the method comprising:
- the application server sends a security assessment request to the electronic device, wherein the security assessment request is used to request an assessment of the security of the electronic device;
- the application server receives second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
- the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information
- the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device
- the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
- the application server determines, according to the second security information, whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service, wherein the target service is a service provided by the application server to the electronic device.
- an embodiment of the present application provides a service processing device, which is applied to an application server, and the device includes:
- a third sending module used to send a security assessment request to the electronic device, wherein the security assessment request is used to request an assessment of the security of the electronic device;
- a first receiving module is used to receive second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment REE of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
- a third determination module is used to determine whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
- an embodiment of the present application provides a method for transmitting security information, the method comprising:
- the management server generates a digital certificate, wherein the digital certificate includes the digital certificate of the electronic device and the digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
- the management server sends second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
- an embodiment of the present application provides a security information transmission device, which is applied to a management server, and the device includes:
- the fourth sending module is used to send second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or the identifier of the digital certificate of the electronic device.
- an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the security assessment method described in the first aspect are implemented.
- an embodiment of the present application provides an application server, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the business processing method described in the third aspect are implemented.
- an embodiment of the present application provides a management server, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the security information transmission method described in the fifth aspect are implemented.
- an embodiment of the present application provides a readable storage medium, wherein a program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the security assessment method described in the first aspect is implemented. Steps, or implement the steps in the business processing method as described in the third aspect, or implement the steps in the security information transmission method as described in the fifth aspect.
- an embodiment of the present application provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, or implement the steps in the business processing method described in the third aspect, or implement the steps in the security information transmission method described in the fifth aspect.
- an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method as described in the first aspect, or to implement the steps in the business processing method as described in the third aspect, or to implement the steps in the security information transmission method as described in the fifth aspect.
- the security coprocessor of the electronic device upon receiving a security assessment request sent by an application server, determines a target security assessment result based on first security information, wherein the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE; the security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor of the electronic device using the root key of the electronic device; the security coprocessor of the electronic device uses the private key of the electronic device to sign the target security assessment result to obtain a signature of the target security assessment result.
- the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE
- the security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, wherein the first
- the electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and the signature of the target security assessment result, that is, the embodiment of the present application determines the target security assessment result through the security coprocessor of the electronic device, and signs the target security assessment result through the private key of the electronic device, and encrypts the private key of the electronic device with the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device.
- the security coprocessor since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the above-mentioned security assessment process can be guaranteed.
- FIG1 is a flow chart of a security assessment method provided in an embodiment of the present application.
- FIG2 is a schematic diagram of a security assessment system provided in an embodiment of the present application.
- FIG3 is a flow chart of another security assessment method provided in an embodiment of the present application.
- FIG4 is a flow chart of another security assessment method provided in an embodiment of the present application.
- FIG5 is a flow chart of another security assessment method provided in an embodiment of the present application.
- FIG6 is a flow chart of another security assessment method provided in an embodiment of the present application.
- FIG7 is a schematic diagram of the structure of a security assessment device provided in an embodiment of the present application.
- FIG9 is a schematic diagram of the structure of another security assessment device provided in an embodiment of the present application.
- FIG10 is a schematic diagram of the structure of another security assessment device provided in an embodiment of the present application.
- FIG. 12 is a schematic diagram of the structure of another service processing device provided in an embodiment of the present application.
- FIG13 is a schematic diagram of the structure of a security information transmission device provided in an embodiment of the present application.
- FIG14 is a schematic diagram of the structure of another security information transmission device provided in an embodiment of the present application.
- FIG15 is a schematic diagram of a structure of an electronic device provided in an embodiment of the present application.
- FIG16 is a second schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
- first, second, etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first”, “second”, etc. are generally of one type, and the number of objects is not limited.
- the first object can be one or more.
- “and/or” in the specification and claims represents at least one of the connected objects, and the character “/" generally indicates that the objects associated with each other are in an "or” relationship.
- FIG. 1 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 1 , comprising the following steps:
- Step 101 An application server sends a security assessment request to an electronic device, where the security assessment request is used to request an assessment of the security of the electronic device.
- the application server may be any server that provides application services (e.g., mobile payment, mobile banking, financial services, etc.).
- the electronic device may be a terminal, wherein the terminal may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a handheld computer, a netbook, an ultra-mobile personal computer (Ultra-mobile Personal Computer, UMPC), an augmented reality (Augmented Reality, AR), a virtual reality (Virtual Reality, VR) device, a robot, a wearable device (Wearable Device), a vehicle-mounted device (Vehicle User Equipment, VUE), a ship-mounted device, a pedestrian terminal (Pedestrian User Equipment, PUE), game consoles, personal computers (Personal Computer, PC) and other terminal-side devices.
- the terminal may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer),
- the security assessment request may include an authorization token.
- the authorization token may be an authorization token issued by a management server of the electronic device.
- the application server may send a security assessment request to the REE side of the electronic device.
- the application server may send a security assessment request to a security assessment client application (i.e., Client App) on the REE side of the electronic device through a security assessment module of the application server.
- a security assessment client application i.e., Client App
- the application server may transmit the security assessment request to the electronic device based on a transmission security mechanism.
- the application server may transmit the security assessment request to the electronic device via the Transport Layer Security (TLS) protocol to improve transmission security.
- TLS Transport Layer Security
- Step 102 When the electronic device receives a security assessment request sent by the application server, the security coprocessor of the electronic device determines a target security assessment result based on first security information, wherein the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE.
- the electronic device includes a security coprocessor, for example, a secure processing unit (SPU).
- the electronic device also includes a REE and a trusted execution environment (TEE), wherein a rich execution environment operating system (OS) runs in the REE, and a trusted execution environment operating system runs in the TEE, as shown in FIG2 .
- the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, and has strong security.
- the TEE has security risks such as software side channel attacks and reverse engineering attacks on TEE applications, and is less secure than the security coprocessor.
- the security protocol processor of the electronic device can obtain the first security information and determine the target security assessment result based on the first security information. For example, the security protocol processor of the electronic device can receive the first security information from the TEE side of the electronic device, and the TEE side of the electronic device can receive the security status information of the REE from the REE side of the electronic device.
- the REE side of the electronic device receives a security assessment request sent by the application server, collects security status information of the REE, and can send an authorization token, security status information of the REE, etc. to the TEE side of the electronic device. Then, the TEE side can verify the validity of the authorization token to detect whether the application server has the authority to obtain the security status of the electronic device.
- the TEE side determines that the above authorization token is valid, it determines that the application server has the authority to obtain the security status of the electronic device, in which case subsequent security assessment-related operations can be continued; when the verification of the above authorization token fails or it is determined that the above authorization token is invalid, the security assessment-related operations can be terminated and a prompt message can be returned to prompt the application server to reapply for the authorization token.
- the TEE side can send the security status information of the REE to the security coprocessor; or, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, and send the security status information of the TEE to the security coprocessor.
- the security assessment results of REE are sent to the security coprocessor.
- the first security information may also include security status information of the TEE of the electronic device or a security assessment result of the TEE.
- the TEE side can collect the security status information of the TEE, and send the security status information of the TEE and the security status information of the REE to the security coprocessor; alternatively, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, and send the security status information of the TEE and the security assessment result of the REE to the security coprocessor; alternatively, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, perform a security assessment based on the security status information of the TEE, obtain the security assessment result of the TEE, and send the security assessment result of the TEE and the security assessment result of the REE to the security coprocessor.
- the security assessment results of the above-mentioned comprehensive REE and the security assessment results of the above-mentioned TEE are used to obtain a target security assessment result.
- the security assessment results of the above-mentioned REE and the security assessment results of the above-mentioned TEE can be weighted summed or comprehensively scored according to a preset model to obtain a target security assessment result.
- the security status information of the above-mentioned REE may include, but is not limited to, indicator elements such as malicious/deceptive/counterfeit applications, virus infection, application signature verification, verification startup, application layer data encryption, software-based memory vulnerability defense, application layer trust measurement, and status information of each indicator element.
- indicator elements such as malicious/deceptive/counterfeit applications, virus infection, application signature verification, verification startup, application layer data encryption, software-based memory vulnerability defense, application layer trust measurement, and status information of each indicator element.
- the corresponding status information may be one of non-existent, unknown, and existing.
- the corresponding status information may be one of non-existent, unknown, and existing.
- the corresponding status information may be one of supported and unsupported.
- the score corresponding to each indicator element can be determined based on the status information of each indicator element of the safety status information of the REE, and then the safety assessment result of the REE can be calculated based on the score and weight corresponding to each indicator element; or the safety status information of the REE can be input into a pre-constructed safety status assessment model to obtain the safety assessment result of the REE.
- the security status information of the above TEE may include, but is not limited to, indicator elements such as malicious/deceptive/fake applications, virus infection, trusted verification startup, trusted user interaction, biometric identification, sensitive information storage, kernel real-time security protection, system integrity measurement, kernel control flow integrity measurement, and the status information of each indicator element.
- indicator elements such as malicious/deceptive/fake applications, virus infection, trusted verification startup, trusted user interaction, biometric identification, sensitive information storage, kernel real-time security protection, system integrity measurement, kernel control flow integrity measurement, and the status information of each indicator element.
- the indicator element is a malicious/deceptive/counterfeit application
- the corresponding status information may be one of non-existent, unknown, and existing.
- the indicator element is a virus infection
- the corresponding status information may be one of non-existent, unknown, and existing.
- the indicator element is trusted verification started, the corresponding status information may be one of supported and not supported.
- the score corresponding to each indicator element can be determined based on the status information of each indicator element of the security status information of the above TEE, and then the security assessment result of the above TEE can be calculated based on the score and weight corresponding to each indicator element; or the security status information of the above TEE can be input into a pre-built security status assessment model to obtain the security assessment result of the above TEE.
- the root key may be a random number generated by the electronic device, for example, the root key may be a random number generated by a hardware security module (HSM) or a security coprocessor of the electronic device.
- the root key may be stored in a secure storage area, for example, a one-time programmable (OTP) memory.
- OTP one-time programmable
- the OTP memory may be located in a security protocol processor, or in other locations of the electronic device other than the security coprocessor.
- the root key may be a newly generated root key for the security assessment of the electronic device, that is, the root key may be a root key dedicated to the security assessment of the electronic device; or, the root key may be a reused existing root key, in which case, in addition to being used for the security assessment of the electronic device, the root key is also used for other services or functions, for example, for the lock screen function of the electronic device.
- the existing root key in the OTP memory of the electronic device may be reused to perform the security assessment of the electronic device.
- the private key of the electronic device and the public key of the electronic device form a public-private key pair, wherein the public-private key pair of the electronic device can be generated by a hardware security module or a security coprocessor of the electronic device.
- the private key of the electronic device can be encrypted by the security coprocessor using the root key of the electronic device and stored in a storage area of the electronic device, for example, in a flash memory (Flash) or an OTP memory of the electronic device, so that the risk of leakage of the private key of the electronic device can be reduced.
- the security coprocessor can read the root key of the electronic device from the OTP memory of the security coprocessor and obtain the first ciphertext from the flash memory of the electronic device, and then decrypt the first ciphertext based on the root key of the electronic device to obtain the private key of the electronic device.
- the root key pair of the electronic device is generated by the security coprocessor, which can improve the security of the public-private key pair of the electronic device.
- the public-private key pair of the electronic device is generated by the security coprocessor; wherein the public-private key pair of the electronic device includes the private key of the electronic device and the private key pair of the electronic device.
- the corresponding public key can improve the security of the public-private key pair of the electronic device.
- the above-mentioned root key may also be referred to as a security assessment trust root
- the private key of the above-mentioned electronic device may also be referred to as a device private key
- the public key of the above-mentioned electronic device may also be referred to as a device public key.
- Step 104 The security coprocessor signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
- the security coprocessor may perform a hash calculation on the target security assessment result to obtain a hash value of the target security assessment result, and use a private key of the electronic device to sign the hash value of the target security assessment result to obtain a signature of the target security assessment result. This can improve the efficiency of signing the target security assessment result compared to directly using the private key of the electronic device to sign the target security assessment result.
- Step 105 The electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- the security coprocessor can send the second security information to the TEE side, the TEE side can send the second security information to the REE side, and then the REE side can send the second security information to the application server.
- the security coprocessor can send the second security information to the security assessment trusted application (Trusted App) on the TEE side, the security assessment trusted application on the TEE side can send the second security information to the security assessment client application on the REE side, and then the security assessment client application on the REE side sends the second security information to the security assessment module of the application server.
- Truste App security assessment trusted application
- Step 106 When the application server receives the second security information, it determines whether to allow the electronic device to access a target service or not according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
- the target security assessment result is determined by the security coprocessor, and the target security assessment result is signed by the private key of the electronic device, and the private key of the electronic device is encrypted by the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device. It has the ability to resist attacks such as hardware side channels and fault injection, which can ensure the security of the above security assessment process.
- the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
- the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
- the management server can be used to manage electronic devices.
- the private key of the management server and the public key of the management server form a public-private key pair of the management server.
- the public-private key pair of the management server can be generated by a key management service (KMS) or a hardware security module of the management server, and stored in the hardware security module of the management server.
- KMS key management service
- the private key of the management server can also be called a server private key
- the public key of the management server can also be called a server public key.
- the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
- the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
- the method may further include:
- the electronic device stores the second digital certificate information when receiving the second digital certificate information from the management server.
- the management server can sign the public key of the electronic device based on the private key of the management server to obtain the digital certificate of the electronic device, and can sign the public key of the management server based on the private key of the management server or the private key corresponding to the public key of the target digital certificate to obtain the digital certificate of the management server, and can
- the digital certificate of the electronic device and the digital certificate of the management server are sent to the electronic device, and then the electronic device can store the digital certificate of the electronic device and the digital certificate of the management server in the flash memory of the electronic device.
- the management server may receive a digital certificate generation request from the electronic device, and then the management server may generate the digital certificate based on the digital certificate generation request.
- the digital certificate generation request may include the public key of the electronic device.
- the above step 106 that is, the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the second security information, may include:
- the application server verifies the digital certificate of the management server according to the public key in the digital certificate of the management server or the target digital certificate;
- the application server verifies the digital certificate of the electronic device according to the digital certificate of the management server when the digital certificate of the management server passes the verification;
- the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
- the application server verifies the digital certificate of the management server based on the public key in the digital certificate of the management server; when the digital certificate of the management server is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, the application server verifies the digital certificate of the management server based on the target digital certificate.
- the application server does not allow the electronic device to access the target service if any of the following conditions is met:
- the digital certificate of the management server has not been verified or verification has failed
- the digital certificate of the electronic device has not been verified or verification has failed
- the signature of the target security assessment result did not pass verification or verification failed.
- the embodiment of the present application performs a digital certificate chain (i.e., The digital certificate of the management server, the digital certificate of the electronic device and the signature of the target security assessment result are verified, and only when the verification of the above digital certificates passes, it is determined based on the target security assessment result whether the electronic device is allowed to access the target business or not.
- a digital certificate chain i.e., The digital certificate of the management server, the digital certificate of the electronic device and the signature of the target security assessment result are verified, and only when the verification of the above digital certificates passes, it is determined based on the target security assessment result whether the electronic device is allowed to access the target business or not.
- the application server can determine the identifier of the digital certificate of the management server based on the digital certificate of the electronic device, obtain the digital certificate of the management server based on the identifier of the digital certificate of the management server, and then verify the digital certificate of the management server based on the public key in the digital certificate of the management server or the target digital certificate according to the application server.
- the method before the above step 102, that is, before the security coprocessor determines the target security assessment result according to the first security information, the method further includes:
- the security coprocessor determines a target security assessment result according to the first security information.
- FIG. 3 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 3 , comprising the following steps:
- Step 301 The application server sends a security assessment request to the REE side of the electronic device, where the security assessment request is used to request an assessment of the security of the electronic device, and the security assessment request includes an authorization token.
- Step 304 Upon receiving the authorization token and the security status information of the REE, the TEE side of the electronic device verifies whether the authorization token is valid.
- step 305 is executed. Otherwise, the security assessment related operations can be terminated and a prompt message is returned to prompt the application server to reapply for the authorization token.
- Step 305 The TEE side of the electronic device collects security status information of the TEE, performs a security assessment based on the security status information of the REE, and obtains a security assessment result of the REE.
- Step 306 The TEE side of the electronic device sends first security information to the security coprocessor of the electronic device, where the first security information includes the security status information of the TEE and the security assessment result of the REE.
- the security coprocessor when the security coprocessor receives the first security information, it inquires whether there is a verification result of the electronic device within the validity period in the electronic device; when there is a verification result of the electronic device within the validity period in the electronic device, the verification result of the electronic device within the validity period is determined as the target verification result; when there is no verification result of the electronic device within the validity period in the electronic device, the security coprocessor sends a verification request to the management server through the TEE and REE of the electronic device, which can not only improve the efficiency of security verification of the electronic device, but also save resource overhead.
- the security coprocessor can store the verification result and set a corresponding validity period, during which it can determine whether the electronic device itself is a safe device based on the verification result.
- the above validity period can be reasonably set according to actual needs.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the device fingerprint may be information that can uniquely identify the electronic device, such as a unique serial number of the device, a device identifier, etc.
- Step 308 Upon receiving the verification request, the management server verifies the security of the electronic device according to security verification related parameters of the electronic device to obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device.
- the management server can verify the security of the electronic device based on whether the system version of the electronic device is the latest version, whether the firmware version is the latest version, whether the system is rooted, whether the hardware configuration is tampered with, whether the firmware configuration is tampered with, etc., and obtain a verification result.
- the security verification of the electronic device by the management server can also be called remote device certification, and the verification result can also be called remote device certification result.
- the management server verifies the security of the electronic device according to the security verification related parameters of the electronic device, and after obtaining the verification result, the method further includes:
- the management server may also send a verification result to the application server, and the application server may determine whether the electronic device itself is a safe device or an unsafe device based on the verification result, and further decide whether to allow the electronic device to access the target service.
- the application server may determine whether to allow the electronic device to access the target service based on the above target security assessment result.
- the application server may not allow the electronic device to access the target service.
- the management server when the verification result indicates that the electronic device is an unsafe device, sends the verification result to the application server; accordingly, upon receiving the verification result, the application server does not allow the electronic device to access the target service.
- Step 309 The management server sends the verification result to the electronic device.
- Step 310 When the security coprocessor receives the verification result sent by the management server through the TEE and REE of the electronic device, if the verification result indicates that the electronic device is a safe device, the security coprocessor determines a target security assessment result according to the first security information.
- the electronic device sends first indication information to the application server, where the first indication information is used to indicate that the electronic device is an unsafe device.
- the security assessment of the electronic device fails.
- Step 311 The security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, where the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device.
- Step 312 The security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
- Step 313 The security coprocessor of the electronic device sends second security information to the TEE side, wherein the second security information includes the target security assessment result, the signature of the target security assessment result and the first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or the identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
- the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
- Step 314 The TEE side sends the second security information to the REE side.
- Step 315 The REE side sends the second security information to the application server.
- Step 316 When the application server receives the second security information, it determines whether to allow the electronic device to access a target service or not according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
- the target security assessment result is determined by the security coprocessor of the electronic device, and the target security assessment result is signed by the private key of the electronic device, and the private key of the electronic device is encrypted by the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device.
- the security of the electronic device itself is verified by the management server, so that it can be ensured that the security coprocessor determines the target security assessment result according to the first security information when the electronic device itself is a secure device, so that the reliability of the security assessment of the electronic device can be further improved.
- FIG. 4 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 4 , comprising the following steps:
- Step 401 Upon receiving a security assessment request sent by an application server, the security coprocessor of the electronic device determines a target security assessment result based on first security information, wherein the first security information includes security status information of a rich execution environment (REE) of the electronic device or a security assessment result of the REE.
- first security information includes security status information of a rich execution environment (REE) of the electronic device or a security assessment result of the REE.
- REE rich execution environment
- the security protocol processor of the electronic device can obtain the first security information and determine the target security assessment result based on the first security information.
- the security protocol processor of the electronic device may receive the first security information from the TEE side of the electronic device, and the TEE side of the electronic device may receive the security status information of the REE from the REE side of the electronic device.
- Step 402 The security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, where the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device.
- Step 403 The security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
- Step 404 The electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- the root key is stored in an OTP memory of the electronic device.
- the root key is stored in the OTP memory, which can prevent the root key from being tampered with.
- OTP memory may be located in the security coprocessor, or may be located in a position different from the security coprocessor in the electronic device.
- the root key of the electronic device is generated by the security coprocessor.
- the root key of the electronic device is generated by the security coprocessor. Since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the root key of the electronic device is improved.
- the public-private key pair of the electronic device is generated by the security coprocessor
- the public-private key pair of the electronic device is generated by the security coprocessor. Since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the public-private key pair of the electronic device is improved.
- the root key of the electronic device is generated by the security coprocessor, and the root key is stored in the OTP memory of the security coprocessor, so that the root key of the electronic device can only be accessed by the security coprocessor and will not be exposed to any software.
- the root key of the electronic device is different from other device identifiers of the electronic device, that is, other device identifiers of the electronic device are not reused as root keys. This can prevent different services from being associated through the same device identifier, thereby reducing security risks such as device tracking and information leakage.
- the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
- the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
- the first digital certificate information further includes the digital certificate of the management server or an identifier of the digital certificate of the management server;
- the method further includes:
- the security coprocessor of the electronic device determines a target security assessment result according to the first security information, including:
- the security coprocessor of the electronic device determines a target security assessment result according to the first security information.
- the method further includes:
- the electronic device sends first indication information to the application server, where the first indication information is used to indicate that the electronic device is an unsafe device or that a security assessment of the electronic device has failed.
- the electronic device obtains a target verification result of the electronic device, including:
- the electronic device receives a verification result sent by the management server, wherein the target verification result is the verification result sent by the management server.
- the method further includes:
- the electronic device queries whether there is a verification result of the electronic device within the validity period in the electronic device;
- the electronic device determines the verification result of the electronic device within the validity period as a target verification result
- the electronic device sends a verification request to the management server, including:
- the electronic device When the electronic device does not have a verification result of the electronic device within the validity period, the electronic device sends a verification request to the management server.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
- the first security information includes a security assessment result of the REE and security status information of the TEE;
- the security coprocessor of the electronic device determines a target security assessment result according to the first security information, including:
- the security coprocessor of the electronic device performs a security assessment on the TEE according to the security status information of the TEE to obtain a security assessment result of the TEE;
- the security coprocessor of the electronic device determines a target security assessment result according to the security assessment result of the TEE and the security assessment result of the REE.
- the security coprocessor is used to perform security assessment on the TEE, which can improve the reliability of the security assessment result of the TEE compared to the security assessment of the TEE by the TEE itself.
- the security assessment result of the REE is a security assessment result obtained by the TEE performing a security assessment based on the security status information of the REE.
- the security assessment result of the REE is obtained by performing a security assessment based on the security status information of the REE by the TEE. Compared with the security assessment result of the REE obtained by performing a security assessment based on the security status information of the REE by the REE, the reliability of the security assessment result of the REE can be improved.
- FIG. 5 is a flow chart of a service processing method provided in an embodiment of the present application. As shown in FIG. 5 , the method includes the following steps:
- Step 501 The application server sends a security assessment request to the electronic device, where the security assessment request is used to request an assessment of the security of the electronic device;
- Step 502 The application server receives second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, wherein the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, wherein the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
- the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information
- the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device
- the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, wherein the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
- Step 503 The application server determines whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
- the application server determines, according to the second security information, whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service, including:
- the application server verifies the digital certificate of the electronic device according to the digital certificate of the management server;
- the application server verifies the signature of the target security assessment result according to the digital certificate of the electronic device
- the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
- the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
- the method further includes:
- the application server obtains the digital certificate of the management server according to the identifier of the digital certificate of the management server.
- FIG. 6 is a flow chart of a security information transmission method provided in an embodiment of the present application. As shown in FIG. 6 , the method includes the following steps:
- Step 601 The management server generates a digital certificate, wherein the digital certificate includes the digital certificate of the electronic device and the digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
- Step 602 The management server sends second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
- the management server may receive a digital certificate generation request sent by the electronic device, and generate a digital certificate in response to the digital certificate generation reason.
- the private key of the management server is stored in a hardware security module HSM of the management server.
- the method further comprises:
- the management server receives a verification request sent by the electronic device, wherein the verification request is used to request Requesting to verify the security of the electronic device, the verification request including security verification related parameters of the electronic device;
- the management server verifies the security of the electronic device according to the security verification related parameters of the electronic device to obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device;
- the management server sends the verification result to the electronic device.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the security information transmission method provided in the embodiment of the present application can be executed by a security information transmission device.
- the security information transmission device provided in the embodiment of the present application is described by taking the security information transmission method executed by the security information transmission device as an example.
- FIG. 7 is a schematic diagram of the structure of a security assessment device provided in an embodiment of the present application.
- the security assessment device is applied to an electronic device.
- the security assessment device 700 includes:
- a first determination module 701 is configured to determine a target security assessment result according to first security information when a security assessment request sent by an application server is received, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
- a decryption module 702 configured to decrypt a first ciphertext using a root key of the electronic device to obtain a private key of the electronic device, wherein the first ciphertext is a ciphertext obtained by encrypting the private key of the electronic device using the root key of the electronic device by the security coprocessor of the electronic device;
- the signature module 703 is used to sign the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
- the first sending module 704 is configured to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- the root key is stored in a one-time programmable (OTP) memory of the electronic device.
- OTP one-time programmable
- the root key of the electronic device is generated by the security coprocessor.
- the public-private key pair of the electronic device is generated by the security coprocessor
- the public-private key pair of the electronic device includes a private key of the electronic device and a public key corresponding to the private key of the electronic device.
- the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
- the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
- the first digital certificate information also includes the digital certificate of the management server or the management server.
- the server's digital certificate identifier ;
- the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
- the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
- the device further includes:
- a first acquisition module 705 is configured to acquire a target verification result of the electronic device before determining a target security assessment result according to the first security information, wherein the target verification result is a verification result obtained by a management server verifying the security of the electronic device;
- the first determining module 701 is specifically used for:
- a target security assessment result is determined according to the first security information.
- the device further includes:
- the second sending module 706 is used to send first indication information to the application server when the target verification result indicates that the electronic device is an unsafe device, and the first indication information is used to indicate that the electronic device is an unsafe device or that the security assessment of the electronic device has failed.
- the first acquisition module 705 is specifically used to:
- a verification result sent by the management server is received, wherein the target verification result is the verification result sent by the management server.
- the device further includes:
- a query module 707 configured to query whether there is a verification result of the electronic device within the validity period in the electronic device before sending the verification request to the management server;
- a second determining module 708 is configured to determine the verification result of the electronic device within the validity period as a target verification result if there is a verification result of the electronic device within the validity period in the electronic device;
- the first acquisition module 705 is specifically used for:
- a verification request is sent to a management server.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
- the first security information includes a security assessment result of the REE and a security status of the TEE. information
- the first determining module 701 is specifically used for:
- a target security assessment result is determined according to the security assessment result of the TEE and the security assessment result of the REE.
- the security assessment result of the REE is a security assessment result obtained by the TEE performing a security assessment based on the security status information of the REE.
- the security assessment device in the embodiment of the present application can be an electronic device or a component in the electronic device, such as an integrated circuit or a chip.
- the electronic device can be a terminal or other devices other than a terminal.
- the electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR)/virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc.
- It can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., and the embodiment of the present application is not specifically limited.
- Network Attached Storage NAS
- PC personal computer
- TV television
- teller machine a self-service machine
- the security assessment device in the embodiment of the present application may be a device having an operating system.
- the operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.
- the security assessment device provided in the embodiment of the present application can implement each process implemented in the above method embodiment, and will not be described again here to avoid repetition.
- FIG. 11 is a schematic diagram of the structure of a service processing device provided in an embodiment of the present application.
- the service processing device is applied to an application server.
- the service processing device 1100 includes:
- a third sending module 1101 is used to send a security assessment request to an electronic device, where the security assessment request is used to request an assessment of the security of the electronic device;
- the first receiving module 1102 is used to receive second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment REE of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server;
- the third determination module 1103 is used to determine whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
- the third determining module is specifically configured to:
- the digital certificate of the management server is verified according to the public key in the digital certificate of the management server or the target digital certificate, wherein the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
- the digital certificate of the management server passes the verification, verifying the digital certificate of the electronic device according to the digital certificate of the management server;
- the signature of the target security assessment result passes the verification, it is determined whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
- the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
- the device further includes:
- a fourth determining module 1104 is configured to determine an identifier of the digital certificate of the management server according to the digital certificate of the electronic device before verifying the digital certificate of the management server according to the first digital certificate;
- the second acquisition module 1105 is configured to acquire the digital certificate of the management server according to the identifier of the digital certificate of the management server.
- the service processing device in the embodiment of the present application may be a server, or a component in the server, such as an integrated circuit or a chip.
- the business processing device provided in the embodiment of the present application can implement each process implemented in the above method embodiment, and will not be described again here to avoid repetition.
- FIG. 13 is a schematic diagram of the structure of a security information transmission device provided in an embodiment of the present application.
- the security information transmission device is applied to a management server.
- the security information transmission device 1300 includes:
- a generation module 1301 is used to generate a digital certificate, wherein the digital certificate includes a digital certificate of the electronic device and a digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
- the fourth sending module 1302 is configured to send second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
- the second digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
- the private key of the management server is stored in a hardware security module HSM of the management server.
- the device further includes:
- the second receiving module 1303 is used to receive a verification request sent by the electronic device, wherein the verification request is used to request verification of the security of the electronic device, and the verification request includes security verification related parameters of the electronic device;
- a verification module 1304 configured to verify the security of the electronic device according to security verification related parameters of the electronic device, and obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device;
- the fifth sending module 1305 is used to send the verification result to the electronic device.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the secure information transmission device in the embodiment of the present application may be a server, or a component in the server, such as an integrated circuit or a chip.
- the secure information transmission device provided in the embodiment of the present application can implement each process implemented in the above method embodiment. To avoid repetition, it will not be repeated here.
- an embodiment of the present application also provides an electronic device 1500, including a processor 1501 and a memory 1502, and the memory 1502 stores a program or instruction that can be executed on the processor 1501.
- the program or instruction is executed by the processor 1501
- the various steps of the above-mentioned security assessment method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the electronic devices in the embodiments of the present application include mobile electronic devices and non-mobile electronic devices.
- FIG. 16 is a schematic diagram of the hardware structure of an electronic device implementing an embodiment of the present application.
- the electronic device 1600 includes but is not limited to: a radio frequency unit 1601, a network module 1602, an audio output unit 1603, an input unit 1604, a sensor 1605, a display unit 1606, a user input unit 1607, an interface unit 1608, a memory 1609, and a processor 1610.
- the processor 1610 may be a security coprocessor.
- the electronic device 1600 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1610 through a power management system, so that the power management system can manage charging, discharging, and power consumption management.
- a power source such as a battery
- the electronic device structure shown in FIG16 does not constitute a limitation on the electronic device, and the electronic device may include more or fewer components than shown, or combine certain components, or arrange components differently, which will not be described in detail here.
- the processor 1610 is used to determine the target security assessment result according to the first security information when receiving the security assessment request sent by the application server, wherein the first security information includes the electronic device The security status information of the rich execution environment REE or the security assessment result of the REE; decrypting the first ciphertext using the root key of the electronic device to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor of the electronic device using the root key of the electronic device; signing the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
- the radio frequency unit 1601 is configured to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
- the root key is stored in a one-time programmable (OTP) memory of the electronic device.
- OTP one-time programmable
- the root key of the electronic device is generated by the security coprocessor.
- the public-private key pair of the electronic device is generated by the security coprocessor
- the public-private key pair of the electronic device includes a private key of the electronic device and a public key corresponding to the private key of the electronic device.
- the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
- the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
- the first digital certificate information further includes the digital certificate of the management server or an identifier of the digital certificate of the management server;
- the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
- the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
- the processor 1610 is further configured to obtain a target verification result of the electronic device before determining the target security assessment result according to the first security information, wherein the target verification result is a verification result obtained by a management server verifying the security of the electronic device;
- the processor 1610 is specifically configured to:
- a target security assessment result is determined by the security coprocessor according to the first security information.
- the radio frequency unit 1601 is also used to send first indication information to the application server when the target verification result indicates that the electronic device is an unsafe device, and the first indication information is used to indicate that the electronic device is an unsafe device or that the security assessment of the electronic device has failed.
- the processor 1610 is specifically configured to:
- a verification result sent by the management server is received, wherein the target verification result is the verification result sent by the management server.
- processor 1610 is further configured to:
- a verification request is sent to a management server.
- the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
- the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
- the processor 1610 is specifically configured to:
- a target security assessment result is determined according to the security assessment result of the TEE and the security assessment result of the REE.
- the memory 1609 can be used to store software programs and various data.
- the memory 1609 can mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area can store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.).
- the memory 1609 can include a volatile memory or a non-volatile memory, or the memory 1609 can include both volatile and non-volatile memories.
- the non-volatile memory can be a read-only memory (Read-Only
- the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
- the memory 1609 in the embodiment of the present application includes but is not limited to these and any other suitable types of memories.
- the processor 1610 may include one or more processing units; optionally, the processor 1610 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1610.
- An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
- a program or instruction is stored.
- each process of the above-mentioned security assessment method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
- the processor is the processor in the electronic device described in the above embodiment.
- the readable storage medium includes a computer readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
- an embodiment of the present application also provides a server 1700, including a processor 1701 and a memory 1702, and the memory 1702 stores a program or instruction that can be executed on the processor 1701.
- the program or instruction When the program or instruction is executed by the processor 1701, it implements the various steps of the above-mentioned application server-side business processing method embodiment, or implements the various steps of the above-mentioned management server-side security information transmission method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned security assessment method embodiment, or to implement the various processes of the above-mentioned business processing method embodiment, or to implement the various processes of the above-mentioned security information transmission method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
- the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
- the embodiment of the present application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement each process of the above-mentioned security assessment method embodiment, or, To implement each process of the above-mentioned business processing method embodiment, or to implement each process of the above-mentioned security information transmission method embodiment, and to achieve the same technical effect, it will not be repeated here to avoid repetition.
- the technical solution of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, a disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.
- a storage medium such as ROM/RAM, a disk, or an optical disk
- a terminal which can be a mobile phone, a computer, a server, or a network device, etc.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Computing Systems (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Storage Device Security (AREA)
Abstract
Description
Claims (53)
- 一种安全评估方法,所述方法包括:在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
- 根据权利要求1所述的方法,其中,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
- 根据权利要求1所述的方法,其中,所述电子设备的根秘钥由所述安全协处理器生成。
- 根据权利要求1所述的方法,其中,所述电子设备的公私密钥对由所述安全协处理器生成;其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
- 根据权利要求1所述的方法,其中,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
- 根据权利要求5所述的方法,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
- 根据权利要求1至6中任一项所述的方法,其中,所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果之前,所述方法还包括:所述电子设备获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,包括:在所述目标验证结果指示所述电子设备为安全的设备的情况下,所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果。
- 根据权利要求7所述的方法,其中,所述方法还包括:在所述目标验证结果指示所述电子设备为不安全的设备的情况下,所述电子设备向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安全的设备或者对所述电子设备的安全评估失败。
- 根据权利要求7所述的方法,其中,所述电子设备获取所述电子设备的目标验证结果,包括:所述电子设备向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;所述电子设备接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
- 根据权利要求9所述的方法,其中,所述电子设备向管理服务器发送验证请求之前,所述方法还包括:所述电子设备查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备将处于有效期内的所述电子设备的验证结果确定为目标验证结果;所述向管理服务器发送验证请求,包括:在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备向管理服务器发送验证请求。
- 根据权利要求10所述的方法,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
- 根据权利要求1至6中任一项所述的方法,其中,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
- 根据权利要求12所述的方法,其中,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果,包括:所述电子设备的安全协处理器根据所述TEE的安全状态信息对所述TEE进行安全 评估,得到所述TEE的安全评估结果;所述电子设备的安全协处理器根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
- 根据权利要求13所述的方法,其中,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
- 一种业务处理方法,所述方法包括:应用服务器向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;所述应用服务器从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
- 根据权利要求15所述的方法,其中,所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,包括:所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;在所述管理服务器的数字证书通过验证的情况下,所述应用服务器根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;在所述电子设备的数字证书通过验证的情况下,所述应用服务器根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;在所述目标安全评估结果的签名通过验证的情况下,所述应用服务器根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
- 根据权利要求16所述的方法,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
- 根据权利要求16所述的方法,其中,所述应用服务器根据第一数字证书对所述 管理服务器的数字证书进行验证之前,所述方法还包括:所述应用服务器根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;所述应用服务器根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
- 一种安全信息传输方法,所述方法包括:管理服务器生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;所述管理服务器向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
- 根据权利要求19所述的方法,其中,所述第二数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
- 根据权利要求19或20所述的方法,其中,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
- 根据权利要求19或20所述的方法,其中,所述方法还包括:所述管理服务器接收所述电子设备发送的验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;所述管理服务器根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;所述管理服务器向所述电子设备发送所述验证结果。
- 根据权利要求22所述的方法,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
- 一种安全评估装置,应用于电子设备,所述装置包括:第一确定模块,用于在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;解密模块,用于采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密 钥对所述电子设备的私钥加密所得到的密文;签名模块,用于采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;第一发送模块,用于将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
- 根据权利要求24所述的装置,其中,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
- 根据权利要求24所述的装置,其中,所述电子设备的根秘钥由所述安全协处理器生成。
- 根据权利要求24所述的装置,其中,所述电子设备的公私密钥对由所述安全协处理器生成;其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
- 根据权利要求24所述的装置,其中,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
- 根据权利要求28所述的装置,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
- 根据权利要求24至29中任一项所述的装置,其中,所述装置还包括:第一获取模块,用于所述根据所述第一安全信息确定目标安全评估结果之前,获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;所述第一确定模块具体用于:在所述目标验证结果指示所述电子设备为安全的设备的情况下,根据所述第一安全信息确定目标安全评估结果。
- 根据权利要求30所述的装置,其中,所述装置还包括:第二发送模块,用于在所述目标验证结果指示所述电子设备为不安全的设备的情况下,向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设 备为不安全的设备或者对所述电子设备的安全评估失败。
- 根据权利要求30所述的装置,其中,所述第一获取模块具体用于:向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
- 根据权利要求32所述的装置,其中,所述装置还包括:查询模块,用于在所述向管理服务器发送验证请求之前,查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;第二确定模块,用于在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,将处于有效期内的所述电子设备的验证结果确定为目标验证结果;所述第一获取模块具体用于:在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,向管理服务器发送验证请求。
- 根据权利要求33所述的装置,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
- 根据权利要求24至29中任一项所述的装置,其中,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
- 根据权利要求35所述的装置,其中,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;所述第一确定模块具体用于:根据所述TEE的安全状态信息对所述TEE进行安全评估,得到所述TEE的安全评估结果;根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
- 根据权利要求36所述的装置,其中,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
- 一种业务处理装置,应用于应用服务器,所述装置包括:第三发送模块,用于向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;第一接收模块,用于从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电 子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;第三确定模块,用于根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
- 根据权利要求38所述的装置,其中,所述第三确定模块具体用于:根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;在所述管理服务器的数字证书通过验证的情况下,根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;在所述电子设备的数字证书通过验证的情况下,根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;在所述目标安全评估结果的签名通过验证的情况下,根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
- 根据权利要求39所述的装置,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
- 根据权利要求39所述的装置,其中,所述装置还包括:第四确定模块,用于所述根据第一数字证书对所述管理服务器的数字证书进行验证之前,根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;第二获取模块,用于根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
- 一种安全信息传输装置,应用于管理服务器,所述装置包括:生成模块,用于生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;第四发送模块,用于向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
- 根据权利要求42所述的装置,其中,所述第二数字证书信息还包括所述管理服 务器的数字证书或者所述管理服务器的数字证书的标识。
- 根据权利要求42或43所述的装置,其中,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
- 根据权利要求42或43所述的装置,其中,所述装置还包括:第二接收模块,用于接收所述电子设备发送的验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;验证模块,用于根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;第五发送模块,用于向所述电子设备发送所述验证结果。
- 根据权利要求45所述的装置,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
- 一种电子设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1-14中任一项所述的安全评估方法的步骤。
- 一种管理服务器,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求15-18中任一项所述的安全评估方法的步骤。
- 一种应用服务器,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求19-23中任一项所述的安全评估方法的步骤。
- 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
- 一种电子设备,包括所述电子设备被配置用于执行如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
- 一种芯片,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
- 一种计算机程序产品,所述计算机程序产品被存储在非瞬态存储介质中,所述计算机程序产品被至少一个处理器执行以实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
Priority Applications (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP24822682.1A EP4730704A1 (en) | 2023-06-15 | 2024-06-11 | Security evaluation method, service processing method, security information transmission method and related device |
| US19/413,120 US20260095321A1 (en) | 2023-06-15 | 2025-12-09 | Security evaluation method, service processing method, security information transmission method, and related device |
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| CN202310715581.6A CN116633661B (zh) | 2023-06-15 | 2023-06-15 | 安全评估、业务处理、安全信息传输方法及相关设备 |
| CN202310715581.6 | 2023-06-15 |
Related Child Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| US19/413,120 Continuation US20260095321A1 (en) | 2023-06-15 | 2025-12-09 | Security evaluation method, service processing method, security information transmission method, and related device |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| WO2024255732A1 true WO2024255732A1 (zh) | 2024-12-19 |
Family
ID=87638212
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| PCT/CN2024/098430 Ceased WO2024255732A1 (zh) | 2023-06-15 | 2024-06-11 | 安全评估、业务处理、安全信息传输方法及相关设备 |
Country Status (4)
| Country | Link |
|---|---|
| US (1) | US20260095321A1 (zh) |
| EP (1) | EP4730704A1 (zh) |
| CN (1) | CN116633661B (zh) |
| WO (1) | WO2024255732A1 (zh) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116633661B (zh) * | 2023-06-15 | 2026-02-24 | 维沃移动通信有限公司 | 安全评估、业务处理、安全信息传输方法及相关设备 |
| CN118488119A (zh) * | 2024-05-09 | 2024-08-13 | 维沃移动通信有限公司 | 信息传输方法、装置、管理服务器、电子设备及应用服务器 |
| CN118694867A (zh) * | 2024-06-21 | 2024-09-24 | 维沃移动通信有限公司 | 图像信息安全传输方法、装置、电子设备及服务器 |
Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110213039A (zh) * | 2018-02-28 | 2019-09-06 | 华为技术有限公司 | 一种管理方法、终端和服务器 |
| CN110838919A (zh) * | 2019-11-01 | 2020-02-25 | 广州小鹏汽车科技有限公司 | 通信方法、存储方法、运算方法及装置 |
| WO2020177116A1 (zh) * | 2019-03-07 | 2020-09-10 | 华为技术有限公司 | 仿冒app识别方法及装置 |
| CN114245375A (zh) * | 2020-09-09 | 2022-03-25 | 华为技术有限公司 | 一种密钥跨设备分发方法及电子设备 |
| CN114598541A (zh) * | 2022-03-18 | 2022-06-07 | 维沃移动通信有限公司 | 一种安全评估方法及装置、电子设备和可读存储介质 |
| CN115706993A (zh) * | 2021-08-03 | 2023-02-17 | 华为技术有限公司 | 认证方法、可读介质和电子设备 |
| CN116633661A (zh) * | 2023-06-15 | 2023-08-22 | 维沃移动通信有限公司 | 安全评估、业务处理、安全信息传输方法及相关设备 |
Family Cites Families (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN108768664B (zh) * | 2018-06-06 | 2020-11-03 | 腾讯科技(深圳)有限公司 | 密钥管理方法、装置、系统、存储介质和计算机设备 |
| US11223485B2 (en) * | 2018-07-17 | 2022-01-11 | Huawei Technologies Co., Ltd. | Verifiable encryption based on trusted execution environment |
| US11706199B2 (en) * | 2019-08-06 | 2023-07-18 | Samsung Electronics Co., Ltd | Electronic device and method for generating attestation certificate based on fused key |
-
2023
- 2023-06-15 CN CN202310715581.6A patent/CN116633661B/zh active Active
-
2024
- 2024-06-11 EP EP24822682.1A patent/EP4730704A1/en active Pending
- 2024-06-11 WO PCT/CN2024/098430 patent/WO2024255732A1/zh not_active Ceased
-
2025
- 2025-12-09 US US19/413,120 patent/US20260095321A1/en active Pending
Patent Citations (7)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN110213039A (zh) * | 2018-02-28 | 2019-09-06 | 华为技术有限公司 | 一种管理方法、终端和服务器 |
| WO2020177116A1 (zh) * | 2019-03-07 | 2020-09-10 | 华为技术有限公司 | 仿冒app识别方法及装置 |
| CN110838919A (zh) * | 2019-11-01 | 2020-02-25 | 广州小鹏汽车科技有限公司 | 通信方法、存储方法、运算方法及装置 |
| CN114245375A (zh) * | 2020-09-09 | 2022-03-25 | 华为技术有限公司 | 一种密钥跨设备分发方法及电子设备 |
| CN115706993A (zh) * | 2021-08-03 | 2023-02-17 | 华为技术有限公司 | 认证方法、可读介质和电子设备 |
| CN114598541A (zh) * | 2022-03-18 | 2022-06-07 | 维沃移动通信有限公司 | 一种安全评估方法及装置、电子设备和可读存储介质 |
| CN116633661A (zh) * | 2023-06-15 | 2023-08-22 | 维沃移动通信有限公司 | 安全评估、业务处理、安全信息传输方法及相关设备 |
Also Published As
| Publication number | Publication date |
|---|---|
| EP4730704A1 (en) | 2026-04-22 |
| CN116633661A (zh) | 2023-08-22 |
| US20260095321A1 (en) | 2026-04-02 |
| CN116633661B (zh) | 2026-02-24 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| CN109361668B (zh) | 一种数据可信传输方法 | |
| US10601795B2 (en) | Service processing method and electronic device | |
| US10530753B2 (en) | System and method for secure cloud computing | |
| US20240388453A1 (en) | Key management and service processing | |
| CN114598541B (zh) | 一种安全评估方法及装置、电子设备和可读存储介质 | |
| US8127146B2 (en) | Transparent trust validation of an unknown platform | |
| US10270776B2 (en) | Secure zone for secure transactions | |
| WO2024255732A1 (zh) | 安全评估、业务处理、安全信息传输方法及相关设备 | |
| US20050283826A1 (en) | Systems and methods for performing secure communications between an authorized computing platform and a hardware component | |
| WO2019218919A1 (zh) | 区块链场景下的私钥管理方法、装置及系统 | |
| CN105718807B (zh) | 基于软tcm和可信软件栈的安卓系统及其可信认证系统与方法 | |
| US20250168017A1 (en) | Method, apparatus, device and storage medium for device authentication and checking | |
| US20040010686A1 (en) | Apparatus for remote working | |
| CN108200078B (zh) | 签名认证工具的下载安装方法及终端设备 | |
| CN108335105B (zh) | 数据处理方法及相关设备 | |
| EP4018403A1 (en) | Authenticator app for consent architecture | |
| WO2025232741A1 (zh) | 信息传输方法、装置、管理服务器、电子设备及应用服务器 | |
| WO2023284691A1 (zh) | 一种账户的开立方法、系统及装置 | |
| TW201539239A (zh) | 伺服器、用戶設備以及用戶設備與伺服器的交互方法 | |
| JP2018117185A (ja) | 情報処理装置、情報処理方法 | |
| CN117792767A (zh) | 通信方法、相关装置及存储介质 | |
| US20250286729A1 (en) | Data processing method and apparatus based on trusted execution environment, device, and medium | |
| WO2026007926A1 (zh) | 数据共享方法及相关设备 | |
| WO2025227758A1 (zh) | 数据共享方法、设备及系统 | |
| Kim et al. | Secure user authentication based on the trusted platform for mobile devices |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| 121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 24822682 Country of ref document: EP Kind code of ref document: A1 |
|
| WWE | Wipo information: entry into national phase |
Ref document number: 2024822682 Country of ref document: EP |
|
| NENP | Non-entry into the national phase |
Ref country code: DE |
|
| ENP | Entry into the national phase |
Ref document number: 2024822682 Country of ref document: EP Effective date: 20260115 |
|
| ENP | Entry into the national phase |
Ref document number: 2024822682 Country of ref document: EP Effective date: 20260115 |
|
| ENP | Entry into the national phase |
Ref document number: 2024822682 Country of ref document: EP Effective date: 20260115 |
|
| ENP | Entry into the national phase |
Ref document number: 2024822682 Country of ref document: EP Effective date: 20260115 |
|
| WWP | Wipo information: published in national office |
Ref document number: 2024822682 Country of ref document: EP |