WO2024255732A1 - 安全评估、业务处理、安全信息传输方法及相关设备 - Google Patents

安全评估、业务处理、安全信息传输方法及相关设备 Download PDF

Info

Publication number
WO2024255732A1
WO2024255732A1 PCT/CN2024/098430 CN2024098430W WO2024255732A1 WO 2024255732 A1 WO2024255732 A1 WO 2024255732A1 CN 2024098430 W CN2024098430 W CN 2024098430W WO 2024255732 A1 WO2024255732 A1 WO 2024255732A1
Authority
WO
WIPO (PCT)
Prior art keywords
electronic device
security
digital certificate
management server
target
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Ceased
Application number
PCT/CN2024/098430
Other languages
English (en)
French (fr)
Inventor
胡志远
何文登
Current Assignee (The listed assignees may be inaccurate. Google has not performed a legal analysis and makes no representation or warranty as to the accuracy of the list.)
Vivo Mobile Communication Co Ltd
Original Assignee
Vivo Mobile Communication Co Ltd
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by Vivo Mobile Communication Co Ltd filed Critical Vivo Mobile Communication Co Ltd
Priority to EP24822682.1A priority Critical patent/EP4730704A1/en
Publication of WO2024255732A1 publication Critical patent/WO2024255732A1/zh
Priority to US19/413,120 priority patent/US20260095321A1/en
Anticipated expiration legal-status Critical
Ceased legal-status Critical Current

Links

Classifications

    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/10Network architectures or network communication protocols for network security for controlling access to devices or network resources
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/14Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols using a plurality of keys or algorithms
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/57Certifying or maintaining trusted computer platforms, e.g. secure boots or power-downs, version controls, system software checks, secure updates or assessing vulnerabilities
    • G06F21/577Assessing vulnerabilities and evaluating computer system security
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/04Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks
    • H04L63/0428Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload
    • H04L63/0442Network architectures or network communication protocols for network security for providing a confidential data exchange among entities communicating through data packet networks wherein the data content is protected, e.g. by encrypting or encapsulating the payload wherein the sending and receiving network entities apply asymmetric encryption, i.e. different keys for encryption and decryption
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/08Network architectures or network communication protocols for network security for authentication of entities
    • H04L63/0823Network architectures or network communication protocols for network security for authentication of entities using certificates
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/12Applying verification of the received information
    • H04L63/123Applying verification of the received information received data contents, e.g. message integrity
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/1466Active attacks involving interception, injection, modification, spoofing of data unit addresses, e.g. hijacking, packet injection or TCP sequence number attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/002Countermeasures against attacks on cryptographic mechanisms
    • H04L9/003Countermeasures against attacks on cryptographic mechanisms for power analysis, e.g. differential power analysis [DPA] or simple power analysis [SPA]
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/002Countermeasures against attacks on cryptographic mechanisms
    • H04L9/004Countermeasures against attacks on cryptographic mechanisms for fault attacks
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3247Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving digital signatures
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/32Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
    • H04L9/3263Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L9/00Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
    • H04L9/40Network security protocols
    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F2221/00Indexing scheme relating to security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F2221/03Indexing scheme relating to G06F21/50, monitoring users, programs or devices to maintain the integrity of platforms
    • G06F2221/034Test or assess a computer or a system
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/12Details relating to cryptographic hardware or logic circuitry
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L2209/00Additional information or applications relating to cryptographic mechanisms or cryptographic arrangements for secret or secure communication H04L9/00
    • H04L2209/72Signcrypting, i.e. digital signing and encrypting simultaneously

Definitions

  • the present application relates to the field of communication technology, and in particular to a security assessment, business processing, security information transmission method and related equipment.
  • application service providers e.g., mobile payment, mobile banking, financial services, etc.
  • the application server sends a security assessment request to the electronic device, and the electronic device obtains the security status information of the Rich Execution Environment (REE) based on the security assessment request and performs a security assessment to obtain the security assessment result of the REE, and returns the security assessment result to the application server, and then the application server can determine whether to allow the electronic device to access the requested service based on the security assessment result.
  • REE Rich Execution Environment
  • the embodiments of the present application provide a security assessment, business processing, security information transmission method and related equipment, which can improve the reliability of security assessment results of electronic equipment.
  • an embodiment of the present application provides a security assessment method, the method comprising:
  • the security coprocessor of the electronic device Upon receiving a security assessment request sent by an application server, the security coprocessor of the electronic device determines a target security assessment result according to first security information, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
  • the security coprocessor of the electronic device decrypts the first ciphertext using the root key of the electronic device to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device;
  • the security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
  • the electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • an embodiment of the present application provides a security assessment device, which is applied to an electronic device, and the device includes:
  • a first determination module is used to determine a target security assessment result according to first security information when receiving a security assessment request sent by an application server, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
  • a signature module used to sign the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result
  • the first sending module is used to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • an embodiment of the present application provides a service processing method, the method comprising:
  • the application server sends a security assessment request to the electronic device, wherein the security assessment request is used to request an assessment of the security of the electronic device;
  • the application server receives second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
  • the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information
  • the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device
  • the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
  • the application server determines, according to the second security information, whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service, wherein the target service is a service provided by the application server to the electronic device.
  • an embodiment of the present application provides a service processing device, which is applied to an application server, and the device includes:
  • a third sending module used to send a security assessment request to the electronic device, wherein the security assessment request is used to request an assessment of the security of the electronic device;
  • a first receiving module is used to receive second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment REE of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
  • a third determination module is used to determine whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
  • an embodiment of the present application provides a method for transmitting security information, the method comprising:
  • the management server generates a digital certificate, wherein the digital certificate includes the digital certificate of the electronic device and the digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
  • the management server sends second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
  • an embodiment of the present application provides a security information transmission device, which is applied to a management server, and the device includes:
  • the fourth sending module is used to send second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or the identifier of the digital certificate of the electronic device.
  • an embodiment of the present application provides an electronic device, comprising a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the security assessment method described in the first aspect are implemented.
  • an embodiment of the present application provides an application server, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the business processing method described in the third aspect are implemented.
  • an embodiment of the present application provides a management server, which includes a processor and a memory, wherein the memory stores programs or instructions that can be run on the processor, and when the programs or instructions are executed by the processor, the steps in the security information transmission method described in the fifth aspect are implemented.
  • an embodiment of the present application provides a readable storage medium, wherein a program or instruction is stored on the readable storage medium, and when the program or instruction is executed by a processor, the security assessment method described in the first aspect is implemented. Steps, or implement the steps in the business processing method as described in the third aspect, or implement the steps in the security information transmission method as described in the fifth aspect.
  • an embodiment of the present application provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the method described in the first aspect, or implement the steps in the business processing method described in the third aspect, or implement the steps in the security information transmission method described in the fifth aspect.
  • an embodiment of the present application provides a computer program product, which is stored in a storage medium and is executed by at least one processor to implement the method as described in the first aspect, or to implement the steps in the business processing method as described in the third aspect, or to implement the steps in the security information transmission method as described in the fifth aspect.
  • the security coprocessor of the electronic device upon receiving a security assessment request sent by an application server, determines a target security assessment result based on first security information, wherein the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE; the security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor of the electronic device using the root key of the electronic device; the security coprocessor of the electronic device uses the private key of the electronic device to sign the target security assessment result to obtain a signature of the target security assessment result.
  • the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE
  • the security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, wherein the first
  • the electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and the signature of the target security assessment result, that is, the embodiment of the present application determines the target security assessment result through the security coprocessor of the electronic device, and signs the target security assessment result through the private key of the electronic device, and encrypts the private key of the electronic device with the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device.
  • the security coprocessor since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the above-mentioned security assessment process can be guaranteed.
  • FIG1 is a flow chart of a security assessment method provided in an embodiment of the present application.
  • FIG2 is a schematic diagram of a security assessment system provided in an embodiment of the present application.
  • FIG3 is a flow chart of another security assessment method provided in an embodiment of the present application.
  • FIG4 is a flow chart of another security assessment method provided in an embodiment of the present application.
  • FIG5 is a flow chart of another security assessment method provided in an embodiment of the present application.
  • FIG6 is a flow chart of another security assessment method provided in an embodiment of the present application.
  • FIG7 is a schematic diagram of the structure of a security assessment device provided in an embodiment of the present application.
  • FIG9 is a schematic diagram of the structure of another security assessment device provided in an embodiment of the present application.
  • FIG10 is a schematic diagram of the structure of another security assessment device provided in an embodiment of the present application.
  • FIG. 12 is a schematic diagram of the structure of another service processing device provided in an embodiment of the present application.
  • FIG13 is a schematic diagram of the structure of a security information transmission device provided in an embodiment of the present application.
  • FIG14 is a schematic diagram of the structure of another security information transmission device provided in an embodiment of the present application.
  • FIG15 is a schematic diagram of a structure of an electronic device provided in an embodiment of the present application.
  • FIG16 is a second schematic diagram of the structure of an electronic device provided in an embodiment of the present application.
  • first, second, etc. in the specification and claims of the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the data used in this way can be interchangeable under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than those illustrated or described here, and the objects distinguished by "first”, “second”, etc. are generally of one type, and the number of objects is not limited.
  • the first object can be one or more.
  • “and/or” in the specification and claims represents at least one of the connected objects, and the character “/" generally indicates that the objects associated with each other are in an "or” relationship.
  • FIG. 1 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 1 , comprising the following steps:
  • Step 101 An application server sends a security assessment request to an electronic device, where the security assessment request is used to request an assessment of the security of the electronic device.
  • the application server may be any server that provides application services (e.g., mobile payment, mobile banking, financial services, etc.).
  • the electronic device may be a terminal, wherein the terminal may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer), a notebook computer, a personal digital assistant (Personal Digital Assistant, PDA), a handheld computer, a netbook, an ultra-mobile personal computer (Ultra-mobile Personal Computer, UMPC), an augmented reality (Augmented Reality, AR), a virtual reality (Virtual Reality, VR) device, a robot, a wearable device (Wearable Device), a vehicle-mounted device (Vehicle User Equipment, VUE), a ship-mounted device, a pedestrian terminal (Pedestrian User Equipment, PUE), game consoles, personal computers (Personal Computer, PC) and other terminal-side devices.
  • the terminal may be a mobile phone, a tablet computer (Tablet Personal Computer), a laptop computer (Laptop Computer),
  • the security assessment request may include an authorization token.
  • the authorization token may be an authorization token issued by a management server of the electronic device.
  • the application server may send a security assessment request to the REE side of the electronic device.
  • the application server may send a security assessment request to a security assessment client application (i.e., Client App) on the REE side of the electronic device through a security assessment module of the application server.
  • a security assessment client application i.e., Client App
  • the application server may transmit the security assessment request to the electronic device based on a transmission security mechanism.
  • the application server may transmit the security assessment request to the electronic device via the Transport Layer Security (TLS) protocol to improve transmission security.
  • TLS Transport Layer Security
  • Step 102 When the electronic device receives a security assessment request sent by the application server, the security coprocessor of the electronic device determines a target security assessment result based on first security information, wherein the first security information includes security status information of the REE of the electronic device or a security assessment result of the REE.
  • the electronic device includes a security coprocessor, for example, a secure processing unit (SPU).
  • the electronic device also includes a REE and a trusted execution environment (TEE), wherein a rich execution environment operating system (OS) runs in the REE, and a trusted execution environment operating system runs in the TEE, as shown in FIG2 .
  • the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, and has strong security.
  • the TEE has security risks such as software side channel attacks and reverse engineering attacks on TEE applications, and is less secure than the security coprocessor.
  • the security protocol processor of the electronic device can obtain the first security information and determine the target security assessment result based on the first security information. For example, the security protocol processor of the electronic device can receive the first security information from the TEE side of the electronic device, and the TEE side of the electronic device can receive the security status information of the REE from the REE side of the electronic device.
  • the REE side of the electronic device receives a security assessment request sent by the application server, collects security status information of the REE, and can send an authorization token, security status information of the REE, etc. to the TEE side of the electronic device. Then, the TEE side can verify the validity of the authorization token to detect whether the application server has the authority to obtain the security status of the electronic device.
  • the TEE side determines that the above authorization token is valid, it determines that the application server has the authority to obtain the security status of the electronic device, in which case subsequent security assessment-related operations can be continued; when the verification of the above authorization token fails or it is determined that the above authorization token is invalid, the security assessment-related operations can be terminated and a prompt message can be returned to prompt the application server to reapply for the authorization token.
  • the TEE side can send the security status information of the REE to the security coprocessor; or, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, and send the security status information of the TEE to the security coprocessor.
  • the security assessment results of REE are sent to the security coprocessor.
  • the first security information may also include security status information of the TEE of the electronic device or a security assessment result of the TEE.
  • the TEE side can collect the security status information of the TEE, and send the security status information of the TEE and the security status information of the REE to the security coprocessor; alternatively, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, and send the security status information of the TEE and the security assessment result of the REE to the security coprocessor; alternatively, the TEE side can perform a security assessment based on the security status information of the REE, obtain the security assessment result of the REE, perform a security assessment based on the security status information of the TEE, obtain the security assessment result of the TEE, and send the security assessment result of the TEE and the security assessment result of the REE to the security coprocessor.
  • the security assessment results of the above-mentioned comprehensive REE and the security assessment results of the above-mentioned TEE are used to obtain a target security assessment result.
  • the security assessment results of the above-mentioned REE and the security assessment results of the above-mentioned TEE can be weighted summed or comprehensively scored according to a preset model to obtain a target security assessment result.
  • the security status information of the above-mentioned REE may include, but is not limited to, indicator elements such as malicious/deceptive/counterfeit applications, virus infection, application signature verification, verification startup, application layer data encryption, software-based memory vulnerability defense, application layer trust measurement, and status information of each indicator element.
  • indicator elements such as malicious/deceptive/counterfeit applications, virus infection, application signature verification, verification startup, application layer data encryption, software-based memory vulnerability defense, application layer trust measurement, and status information of each indicator element.
  • the corresponding status information may be one of non-existent, unknown, and existing.
  • the corresponding status information may be one of non-existent, unknown, and existing.
  • the corresponding status information may be one of supported and unsupported.
  • the score corresponding to each indicator element can be determined based on the status information of each indicator element of the safety status information of the REE, and then the safety assessment result of the REE can be calculated based on the score and weight corresponding to each indicator element; or the safety status information of the REE can be input into a pre-constructed safety status assessment model to obtain the safety assessment result of the REE.
  • the security status information of the above TEE may include, but is not limited to, indicator elements such as malicious/deceptive/fake applications, virus infection, trusted verification startup, trusted user interaction, biometric identification, sensitive information storage, kernel real-time security protection, system integrity measurement, kernel control flow integrity measurement, and the status information of each indicator element.
  • indicator elements such as malicious/deceptive/fake applications, virus infection, trusted verification startup, trusted user interaction, biometric identification, sensitive information storage, kernel real-time security protection, system integrity measurement, kernel control flow integrity measurement, and the status information of each indicator element.
  • the indicator element is a malicious/deceptive/counterfeit application
  • the corresponding status information may be one of non-existent, unknown, and existing.
  • the indicator element is a virus infection
  • the corresponding status information may be one of non-existent, unknown, and existing.
  • the indicator element is trusted verification started, the corresponding status information may be one of supported and not supported.
  • the score corresponding to each indicator element can be determined based on the status information of each indicator element of the security status information of the above TEE, and then the security assessment result of the above TEE can be calculated based on the score and weight corresponding to each indicator element; or the security status information of the above TEE can be input into a pre-built security status assessment model to obtain the security assessment result of the above TEE.
  • the root key may be a random number generated by the electronic device, for example, the root key may be a random number generated by a hardware security module (HSM) or a security coprocessor of the electronic device.
  • the root key may be stored in a secure storage area, for example, a one-time programmable (OTP) memory.
  • OTP one-time programmable
  • the OTP memory may be located in a security protocol processor, or in other locations of the electronic device other than the security coprocessor.
  • the root key may be a newly generated root key for the security assessment of the electronic device, that is, the root key may be a root key dedicated to the security assessment of the electronic device; or, the root key may be a reused existing root key, in which case, in addition to being used for the security assessment of the electronic device, the root key is also used for other services or functions, for example, for the lock screen function of the electronic device.
  • the existing root key in the OTP memory of the electronic device may be reused to perform the security assessment of the electronic device.
  • the private key of the electronic device and the public key of the electronic device form a public-private key pair, wherein the public-private key pair of the electronic device can be generated by a hardware security module or a security coprocessor of the electronic device.
  • the private key of the electronic device can be encrypted by the security coprocessor using the root key of the electronic device and stored in a storage area of the electronic device, for example, in a flash memory (Flash) or an OTP memory of the electronic device, so that the risk of leakage of the private key of the electronic device can be reduced.
  • the security coprocessor can read the root key of the electronic device from the OTP memory of the security coprocessor and obtain the first ciphertext from the flash memory of the electronic device, and then decrypt the first ciphertext based on the root key of the electronic device to obtain the private key of the electronic device.
  • the root key pair of the electronic device is generated by the security coprocessor, which can improve the security of the public-private key pair of the electronic device.
  • the public-private key pair of the electronic device is generated by the security coprocessor; wherein the public-private key pair of the electronic device includes the private key of the electronic device and the private key pair of the electronic device.
  • the corresponding public key can improve the security of the public-private key pair of the electronic device.
  • the above-mentioned root key may also be referred to as a security assessment trust root
  • the private key of the above-mentioned electronic device may also be referred to as a device private key
  • the public key of the above-mentioned electronic device may also be referred to as a device public key.
  • Step 104 The security coprocessor signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
  • the security coprocessor may perform a hash calculation on the target security assessment result to obtain a hash value of the target security assessment result, and use a private key of the electronic device to sign the hash value of the target security assessment result to obtain a signature of the target security assessment result. This can improve the efficiency of signing the target security assessment result compared to directly using the private key of the electronic device to sign the target security assessment result.
  • Step 105 The electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • the security coprocessor can send the second security information to the TEE side, the TEE side can send the second security information to the REE side, and then the REE side can send the second security information to the application server.
  • the security coprocessor can send the second security information to the security assessment trusted application (Trusted App) on the TEE side, the security assessment trusted application on the TEE side can send the second security information to the security assessment client application on the REE side, and then the security assessment client application on the REE side sends the second security information to the security assessment module of the application server.
  • Truste App security assessment trusted application
  • Step 106 When the application server receives the second security information, it determines whether to allow the electronic device to access a target service or not according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
  • the target security assessment result is determined by the security coprocessor, and the target security assessment result is signed by the private key of the electronic device, and the private key of the electronic device is encrypted by the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device. It has the ability to resist attacks such as hardware side channels and fault injection, which can ensure the security of the above security assessment process.
  • the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
  • the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
  • the management server can be used to manage electronic devices.
  • the private key of the management server and the public key of the management server form a public-private key pair of the management server.
  • the public-private key pair of the management server can be generated by a key management service (KMS) or a hardware security module of the management server, and stored in the hardware security module of the management server.
  • KMS key management service
  • the private key of the management server can also be called a server private key
  • the public key of the management server can also be called a server public key.
  • the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
  • the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
  • the method may further include:
  • the electronic device stores the second digital certificate information when receiving the second digital certificate information from the management server.
  • the management server can sign the public key of the electronic device based on the private key of the management server to obtain the digital certificate of the electronic device, and can sign the public key of the management server based on the private key of the management server or the private key corresponding to the public key of the target digital certificate to obtain the digital certificate of the management server, and can
  • the digital certificate of the electronic device and the digital certificate of the management server are sent to the electronic device, and then the electronic device can store the digital certificate of the electronic device and the digital certificate of the management server in the flash memory of the electronic device.
  • the management server may receive a digital certificate generation request from the electronic device, and then the management server may generate the digital certificate based on the digital certificate generation request.
  • the digital certificate generation request may include the public key of the electronic device.
  • the above step 106 that is, the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the second security information, may include:
  • the application server verifies the digital certificate of the management server according to the public key in the digital certificate of the management server or the target digital certificate;
  • the application server verifies the digital certificate of the electronic device according to the digital certificate of the management server when the digital certificate of the management server passes the verification;
  • the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
  • the application server verifies the digital certificate of the management server based on the public key in the digital certificate of the management server; when the digital certificate of the management server is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, the application server verifies the digital certificate of the management server based on the target digital certificate.
  • the application server does not allow the electronic device to access the target service if any of the following conditions is met:
  • the digital certificate of the management server has not been verified or verification has failed
  • the digital certificate of the electronic device has not been verified or verification has failed
  • the signature of the target security assessment result did not pass verification or verification failed.
  • the embodiment of the present application performs a digital certificate chain (i.e., The digital certificate of the management server, the digital certificate of the electronic device and the signature of the target security assessment result are verified, and only when the verification of the above digital certificates passes, it is determined based on the target security assessment result whether the electronic device is allowed to access the target business or not.
  • a digital certificate chain i.e., The digital certificate of the management server, the digital certificate of the electronic device and the signature of the target security assessment result are verified, and only when the verification of the above digital certificates passes, it is determined based on the target security assessment result whether the electronic device is allowed to access the target business or not.
  • the application server can determine the identifier of the digital certificate of the management server based on the digital certificate of the electronic device, obtain the digital certificate of the management server based on the identifier of the digital certificate of the management server, and then verify the digital certificate of the management server based on the public key in the digital certificate of the management server or the target digital certificate according to the application server.
  • the method before the above step 102, that is, before the security coprocessor determines the target security assessment result according to the first security information, the method further includes:
  • the security coprocessor determines a target security assessment result according to the first security information.
  • FIG. 3 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 3 , comprising the following steps:
  • Step 301 The application server sends a security assessment request to the REE side of the electronic device, where the security assessment request is used to request an assessment of the security of the electronic device, and the security assessment request includes an authorization token.
  • Step 304 Upon receiving the authorization token and the security status information of the REE, the TEE side of the electronic device verifies whether the authorization token is valid.
  • step 305 is executed. Otherwise, the security assessment related operations can be terminated and a prompt message is returned to prompt the application server to reapply for the authorization token.
  • Step 305 The TEE side of the electronic device collects security status information of the TEE, performs a security assessment based on the security status information of the REE, and obtains a security assessment result of the REE.
  • Step 306 The TEE side of the electronic device sends first security information to the security coprocessor of the electronic device, where the first security information includes the security status information of the TEE and the security assessment result of the REE.
  • the security coprocessor when the security coprocessor receives the first security information, it inquires whether there is a verification result of the electronic device within the validity period in the electronic device; when there is a verification result of the electronic device within the validity period in the electronic device, the verification result of the electronic device within the validity period is determined as the target verification result; when there is no verification result of the electronic device within the validity period in the electronic device, the security coprocessor sends a verification request to the management server through the TEE and REE of the electronic device, which can not only improve the efficiency of security verification of the electronic device, but also save resource overhead.
  • the security coprocessor can store the verification result and set a corresponding validity period, during which it can determine whether the electronic device itself is a safe device based on the verification result.
  • the above validity period can be reasonably set according to actual needs.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the device fingerprint may be information that can uniquely identify the electronic device, such as a unique serial number of the device, a device identifier, etc.
  • Step 308 Upon receiving the verification request, the management server verifies the security of the electronic device according to security verification related parameters of the electronic device to obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device.
  • the management server can verify the security of the electronic device based on whether the system version of the electronic device is the latest version, whether the firmware version is the latest version, whether the system is rooted, whether the hardware configuration is tampered with, whether the firmware configuration is tampered with, etc., and obtain a verification result.
  • the security verification of the electronic device by the management server can also be called remote device certification, and the verification result can also be called remote device certification result.
  • the management server verifies the security of the electronic device according to the security verification related parameters of the electronic device, and after obtaining the verification result, the method further includes:
  • the management server may also send a verification result to the application server, and the application server may determine whether the electronic device itself is a safe device or an unsafe device based on the verification result, and further decide whether to allow the electronic device to access the target service.
  • the application server may determine whether to allow the electronic device to access the target service based on the above target security assessment result.
  • the application server may not allow the electronic device to access the target service.
  • the management server when the verification result indicates that the electronic device is an unsafe device, sends the verification result to the application server; accordingly, upon receiving the verification result, the application server does not allow the electronic device to access the target service.
  • Step 309 The management server sends the verification result to the electronic device.
  • Step 310 When the security coprocessor receives the verification result sent by the management server through the TEE and REE of the electronic device, if the verification result indicates that the electronic device is a safe device, the security coprocessor determines a target security assessment result according to the first security information.
  • the electronic device sends first indication information to the application server, where the first indication information is used to indicate that the electronic device is an unsafe device.
  • the security assessment of the electronic device fails.
  • Step 311 The security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, where the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device.
  • Step 312 The security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
  • Step 313 The security coprocessor of the electronic device sends second security information to the TEE side, wherein the second security information includes the target security assessment result, the signature of the target security assessment result and the first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or the identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
  • the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
  • Step 314 The TEE side sends the second security information to the REE side.
  • Step 315 The REE side sends the second security information to the application server.
  • Step 316 When the application server receives the second security information, it determines whether to allow the electronic device to access a target service or not according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
  • the target security assessment result is determined by the security coprocessor of the electronic device, and the target security assessment result is signed by the private key of the electronic device, and the private key of the electronic device is encrypted by the root key of the electronic device, so that the security assessment result can be bound to the electronic device, reducing the occurrence of tampering of the security assessment result, thereby improving the reliability of the security assessment result of the electronic device.
  • the security of the electronic device itself is verified by the management server, so that it can be ensured that the security coprocessor determines the target security assessment result according to the first security information when the electronic device itself is a secure device, so that the reliability of the security assessment of the electronic device can be further improved.
  • FIG. 4 is a flow chart of a security assessment method provided in an embodiment of the present application, as shown in FIG. 4 , comprising the following steps:
  • Step 401 Upon receiving a security assessment request sent by an application server, the security coprocessor of the electronic device determines a target security assessment result based on first security information, wherein the first security information includes security status information of a rich execution environment (REE) of the electronic device or a security assessment result of the REE.
  • first security information includes security status information of a rich execution environment (REE) of the electronic device or a security assessment result of the REE.
  • REE rich execution environment
  • the security protocol processor of the electronic device can obtain the first security information and determine the target security assessment result based on the first security information.
  • the security protocol processor of the electronic device may receive the first security information from the TEE side of the electronic device, and the TEE side of the electronic device may receive the security status information of the REE from the REE side of the electronic device.
  • Step 402 The security coprocessor of the electronic device uses the root key of the electronic device to decrypt the first ciphertext to obtain the private key of the electronic device, where the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor using the root key of the electronic device.
  • Step 403 The security coprocessor of the electronic device signs the target security assessment result using the private key of the electronic device to obtain a signature of the target security assessment result.
  • Step 404 The electronic device sends second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • the root key is stored in an OTP memory of the electronic device.
  • the root key is stored in the OTP memory, which can prevent the root key from being tampered with.
  • OTP memory may be located in the security coprocessor, or may be located in a position different from the security coprocessor in the electronic device.
  • the root key of the electronic device is generated by the security coprocessor.
  • the root key of the electronic device is generated by the security coprocessor. Since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the root key of the electronic device is improved.
  • the public-private key pair of the electronic device is generated by the security coprocessor
  • the public-private key pair of the electronic device is generated by the security coprocessor. Since the security coprocessor has the ability to resist attacks such as hardware side channels and fault injection, the security of the public-private key pair of the electronic device is improved.
  • the root key of the electronic device is generated by the security coprocessor, and the root key is stored in the OTP memory of the security coprocessor, so that the root key of the electronic device can only be accessed by the security coprocessor and will not be exposed to any software.
  • the root key of the electronic device is different from other device identifiers of the electronic device, that is, other device identifiers of the electronic device are not reused as root keys. This can prevent different services from being associated through the same device identifier, thereby reducing security risks such as device tracking and information leakage.
  • the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
  • the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
  • the first digital certificate information further includes the digital certificate of the management server or an identifier of the digital certificate of the management server;
  • the method further includes:
  • the security coprocessor of the electronic device determines a target security assessment result according to the first security information, including:
  • the security coprocessor of the electronic device determines a target security assessment result according to the first security information.
  • the method further includes:
  • the electronic device sends first indication information to the application server, where the first indication information is used to indicate that the electronic device is an unsafe device or that a security assessment of the electronic device has failed.
  • the electronic device obtains a target verification result of the electronic device, including:
  • the electronic device receives a verification result sent by the management server, wherein the target verification result is the verification result sent by the management server.
  • the method further includes:
  • the electronic device queries whether there is a verification result of the electronic device within the validity period in the electronic device;
  • the electronic device determines the verification result of the electronic device within the validity period as a target verification result
  • the electronic device sends a verification request to the management server, including:
  • the electronic device When the electronic device does not have a verification result of the electronic device within the validity period, the electronic device sends a verification request to the management server.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
  • the first security information includes a security assessment result of the REE and security status information of the TEE;
  • the security coprocessor of the electronic device determines a target security assessment result according to the first security information, including:
  • the security coprocessor of the electronic device performs a security assessment on the TEE according to the security status information of the TEE to obtain a security assessment result of the TEE;
  • the security coprocessor of the electronic device determines a target security assessment result according to the security assessment result of the TEE and the security assessment result of the REE.
  • the security coprocessor is used to perform security assessment on the TEE, which can improve the reliability of the security assessment result of the TEE compared to the security assessment of the TEE by the TEE itself.
  • the security assessment result of the REE is a security assessment result obtained by the TEE performing a security assessment based on the security status information of the REE.
  • the security assessment result of the REE is obtained by performing a security assessment based on the security status information of the REE by the TEE. Compared with the security assessment result of the REE obtained by performing a security assessment based on the security status information of the REE by the REE, the reliability of the security assessment result of the REE can be improved.
  • FIG. 5 is a flow chart of a service processing method provided in an embodiment of the present application. As shown in FIG. 5 , the method includes the following steps:
  • Step 501 The application server sends a security assessment request to the electronic device, where the security assessment request is used to request an assessment of the security of the electronic device;
  • Step 502 The application server receives second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, wherein the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, wherein the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
  • the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information
  • the target security assessment result is used to indicate the security of the rich execution environment (REE) of the electronic device
  • the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, wherein the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server;
  • Step 503 The application server determines whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
  • the application server determines, according to the second security information, whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service, including:
  • the application server verifies the digital certificate of the electronic device according to the digital certificate of the management server;
  • the application server verifies the signature of the target security assessment result according to the digital certificate of the electronic device
  • the application server determines whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
  • the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
  • the method further includes:
  • the application server obtains the digital certificate of the management server according to the identifier of the digital certificate of the management server.
  • FIG. 6 is a flow chart of a security information transmission method provided in an embodiment of the present application. As shown in FIG. 6 , the method includes the following steps:
  • Step 601 The management server generates a digital certificate, wherein the digital certificate includes the digital certificate of the electronic device and the digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
  • Step 602 The management server sends second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
  • the management server may receive a digital certificate generation request sent by the electronic device, and generate a digital certificate in response to the digital certificate generation reason.
  • the private key of the management server is stored in a hardware security module HSM of the management server.
  • the method further comprises:
  • the management server receives a verification request sent by the electronic device, wherein the verification request is used to request Requesting to verify the security of the electronic device, the verification request including security verification related parameters of the electronic device;
  • the management server verifies the security of the electronic device according to the security verification related parameters of the electronic device to obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device;
  • the management server sends the verification result to the electronic device.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the security information transmission method provided in the embodiment of the present application can be executed by a security information transmission device.
  • the security information transmission device provided in the embodiment of the present application is described by taking the security information transmission method executed by the security information transmission device as an example.
  • FIG. 7 is a schematic diagram of the structure of a security assessment device provided in an embodiment of the present application.
  • the security assessment device is applied to an electronic device.
  • the security assessment device 700 includes:
  • a first determination module 701 is configured to determine a target security assessment result according to first security information when a security assessment request sent by an application server is received, wherein the first security information includes security status information of a rich execution environment REE of the electronic device or a security assessment result of the REE;
  • a decryption module 702 configured to decrypt a first ciphertext using a root key of the electronic device to obtain a private key of the electronic device, wherein the first ciphertext is a ciphertext obtained by encrypting the private key of the electronic device using the root key of the electronic device by the security coprocessor of the electronic device;
  • the signature module 703 is used to sign the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
  • the first sending module 704 is configured to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • the root key is stored in a one-time programmable (OTP) memory of the electronic device.
  • OTP one-time programmable
  • the root key of the electronic device is generated by the security coprocessor.
  • the public-private key pair of the electronic device is generated by the security coprocessor
  • the public-private key pair of the electronic device includes a private key of the electronic device and a public key corresponding to the private key of the electronic device.
  • the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
  • the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
  • the first digital certificate information also includes the digital certificate of the management server or the management server.
  • the server's digital certificate identifier ;
  • the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
  • the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
  • the device further includes:
  • a first acquisition module 705 is configured to acquire a target verification result of the electronic device before determining a target security assessment result according to the first security information, wherein the target verification result is a verification result obtained by a management server verifying the security of the electronic device;
  • the first determining module 701 is specifically used for:
  • a target security assessment result is determined according to the first security information.
  • the device further includes:
  • the second sending module 706 is used to send first indication information to the application server when the target verification result indicates that the electronic device is an unsafe device, and the first indication information is used to indicate that the electronic device is an unsafe device or that the security assessment of the electronic device has failed.
  • the first acquisition module 705 is specifically used to:
  • a verification result sent by the management server is received, wherein the target verification result is the verification result sent by the management server.
  • the device further includes:
  • a query module 707 configured to query whether there is a verification result of the electronic device within the validity period in the electronic device before sending the verification request to the management server;
  • a second determining module 708 is configured to determine the verification result of the electronic device within the validity period as a target verification result if there is a verification result of the electronic device within the validity period in the electronic device;
  • the first acquisition module 705 is specifically used for:
  • a verification request is sent to a management server.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
  • the first security information includes a security assessment result of the REE and a security status of the TEE. information
  • the first determining module 701 is specifically used for:
  • a target security assessment result is determined according to the security assessment result of the TEE and the security assessment result of the REE.
  • the security assessment result of the REE is a security assessment result obtained by the TEE performing a security assessment based on the security status information of the REE.
  • the security assessment device in the embodiment of the present application can be an electronic device or a component in the electronic device, such as an integrated circuit or a chip.
  • the electronic device can be a terminal or other devices other than a terminal.
  • the electronic device can be a mobile phone, a tablet computer, a laptop computer, a PDA, a vehicle-mounted electronic device, a mobile Internet device (Mobile Internet Device, MID), an augmented reality (augmented reality, AR)/virtual reality (virtual reality, VR) device, a robot, a wearable device, an ultra-mobile personal computer (ultra-mobile personal computer, UMPC), a netbook or a personal digital assistant (personal digital assistant, PDA), etc.
  • It can also be a server, a network attached storage (Network Attached Storage, NAS), a personal computer (personal computer, PC), a television (television, TV), a teller machine or a self-service machine, etc., and the embodiment of the present application is not specifically limited.
  • Network Attached Storage NAS
  • PC personal computer
  • TV television
  • teller machine a self-service machine
  • the security assessment device in the embodiment of the present application may be a device having an operating system.
  • the operating system may be an Android operating system, an iOS operating system, or other possible operating systems, which are not specifically limited in the embodiment of the present application.
  • the security assessment device provided in the embodiment of the present application can implement each process implemented in the above method embodiment, and will not be described again here to avoid repetition.
  • FIG. 11 is a schematic diagram of the structure of a service processing device provided in an embodiment of the present application.
  • the service processing device is applied to an application server.
  • the service processing device 1100 includes:
  • a third sending module 1101 is used to send a security assessment request to an electronic device, where the security assessment request is used to request an assessment of the security of the electronic device;
  • the first receiving module 1102 is used to receive second security information from the electronic device, wherein the second security information includes a target security assessment result, a signature of the target security assessment result, and first digital certificate information, the target security assessment result is used to indicate the security of the rich execution environment REE of the electronic device, and the first digital certificate information includes a digital certificate of the electronic device or an identifier of the digital certificate of the electronic device, and the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server;
  • the third determination module 1103 is used to determine whether to allow the electronic device to access a target service or not to allow the electronic device to access a target service according to the second security information, wherein the target service is a service provided by the application server to the electronic device.
  • the third determining module is specifically configured to:
  • the digital certificate of the management server is verified according to the public key in the digital certificate of the management server or the target digital certificate, wherein the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
  • the digital certificate of the management server passes the verification, verifying the digital certificate of the electronic device according to the digital certificate of the management server;
  • the signature of the target security assessment result passes the verification, it is determined whether to allow the electronic device to access the target service or not to allow the electronic device to access the target service according to the target security assessment result.
  • the first digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
  • the device further includes:
  • a fourth determining module 1104 is configured to determine an identifier of the digital certificate of the management server according to the digital certificate of the electronic device before verifying the digital certificate of the management server according to the first digital certificate;
  • the second acquisition module 1105 is configured to acquire the digital certificate of the management server according to the identifier of the digital certificate of the management server.
  • the service processing device in the embodiment of the present application may be a server, or a component in the server, such as an integrated circuit or a chip.
  • the business processing device provided in the embodiment of the present application can implement each process implemented in the above method embodiment, and will not be described again here to avoid repetition.
  • FIG. 13 is a schematic diagram of the structure of a security information transmission device provided in an embodiment of the present application.
  • the security information transmission device is applied to a management server.
  • the security information transmission device 1300 includes:
  • a generation module 1301 is used to generate a digital certificate, wherein the digital certificate includes a digital certificate of the electronic device and a digital certificate of the management server, the digital certificate of the electronic device is obtained by signing the public key of the electronic device with the private key of the management server, the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or is obtained by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate, and the target digital certificate is a digital certificate located one level above the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs;
  • the fourth sending module 1302 is configured to send second digital certificate information to the electronic device, wherein the second digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device.
  • the second digital certificate information also includes the digital certificate of the management server or an identifier of the digital certificate of the management server.
  • the private key of the management server is stored in a hardware security module HSM of the management server.
  • the device further includes:
  • the second receiving module 1303 is used to receive a verification request sent by the electronic device, wherein the verification request is used to request verification of the security of the electronic device, and the verification request includes security verification related parameters of the electronic device;
  • a verification module 1304 configured to verify the security of the electronic device according to security verification related parameters of the electronic device, and obtain a verification result, wherein the verification result is used to indicate whether the electronic device is a safe device or an unsafe device;
  • the fifth sending module 1305 is used to send the verification result to the electronic device.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the secure information transmission device in the embodiment of the present application may be a server, or a component in the server, such as an integrated circuit or a chip.
  • the secure information transmission device provided in the embodiment of the present application can implement each process implemented in the above method embodiment. To avoid repetition, it will not be repeated here.
  • an embodiment of the present application also provides an electronic device 1500, including a processor 1501 and a memory 1502, and the memory 1502 stores a program or instruction that can be executed on the processor 1501.
  • the program or instruction is executed by the processor 1501
  • the various steps of the above-mentioned security assessment method embodiment are implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
  • the electronic devices in the embodiments of the present application include mobile electronic devices and non-mobile electronic devices.
  • FIG. 16 is a schematic diagram of the hardware structure of an electronic device implementing an embodiment of the present application.
  • the electronic device 1600 includes but is not limited to: a radio frequency unit 1601, a network module 1602, an audio output unit 1603, an input unit 1604, a sensor 1605, a display unit 1606, a user input unit 1607, an interface unit 1608, a memory 1609, and a processor 1610.
  • the processor 1610 may be a security coprocessor.
  • the electronic device 1600 may also include a power source (such as a battery) for supplying power to each component, and the power source may be logically connected to the processor 1610 through a power management system, so that the power management system can manage charging, discharging, and power consumption management.
  • a power source such as a battery
  • the electronic device structure shown in FIG16 does not constitute a limitation on the electronic device, and the electronic device may include more or fewer components than shown, or combine certain components, or arrange components differently, which will not be described in detail here.
  • the processor 1610 is used to determine the target security assessment result according to the first security information when receiving the security assessment request sent by the application server, wherein the first security information includes the electronic device The security status information of the rich execution environment REE or the security assessment result of the REE; decrypting the first ciphertext using the root key of the electronic device to obtain the private key of the electronic device, wherein the first ciphertext is the ciphertext obtained by encrypting the private key of the electronic device by the security coprocessor of the electronic device using the root key of the electronic device; signing the target security assessment result using the private key of the electronic device to obtain the signature of the target security assessment result;
  • the radio frequency unit 1601 is configured to send second security information to the application server, wherein the second security information includes the target security assessment result and a signature of the target security assessment result.
  • the root key is stored in a one-time programmable (OTP) memory of the electronic device.
  • OTP one-time programmable
  • the root key of the electronic device is generated by the security coprocessor.
  • the public-private key pair of the electronic device is generated by the security coprocessor
  • the public-private key pair of the electronic device includes a private key of the electronic device and a public key corresponding to the private key of the electronic device.
  • the second security information further includes first digital certificate information, and the first digital certificate information includes the digital certificate of the electronic device or an identifier of the digital certificate of the electronic device;
  • the digital certificate of the electronic device is obtained by signing the public key of the electronic device using the private key of the management server.
  • the first digital certificate information further includes the digital certificate of the management server or an identifier of the digital certificate of the management server;
  • the digital certificate of the management server is obtained by signing the public key of the management server with the private key of the management server, or by signing the public key of the management server with the private key corresponding to the public key of the target digital certificate.
  • the target digital certificate is a digital certificate located at the upper level of the digital certificate of the management server in the digital certificate chain to which the digital certificate of the management server belongs.
  • the processor 1610 is further configured to obtain a target verification result of the electronic device before determining the target security assessment result according to the first security information, wherein the target verification result is a verification result obtained by a management server verifying the security of the electronic device;
  • the processor 1610 is specifically configured to:
  • a target security assessment result is determined by the security coprocessor according to the first security information.
  • the radio frequency unit 1601 is also used to send first indication information to the application server when the target verification result indicates that the electronic device is an unsafe device, and the first indication information is used to indicate that the electronic device is an unsafe device or that the security assessment of the electronic device has failed.
  • the processor 1610 is specifically configured to:
  • a verification result sent by the management server is received, wherein the target verification result is the verification result sent by the management server.
  • processor 1610 is further configured to:
  • a verification request is sent to a management server.
  • the security verification related parameters of the electronic device include at least one of the following: device fingerprint, hardware configuration parameters, firmware configuration parameters, firmware version, system configuration parameters, system version.
  • the first security information also includes security status information of the trusted execution environment TEE of the electronic device or a security assessment result of the TEE.
  • the processor 1610 is specifically configured to:
  • a target security assessment result is determined according to the security assessment result of the TEE and the security assessment result of the REE.
  • the memory 1609 can be used to store software programs and various data.
  • the memory 1609 can mainly include a first storage area for storing programs or instructions and a second storage area for storing data, wherein the first storage area can store an operating system, an application program or instruction required for at least one function (such as a sound playback function, an image playback function, etc.).
  • the memory 1609 can include a volatile memory or a non-volatile memory, or the memory 1609 can include both volatile and non-volatile memories.
  • the non-volatile memory can be a read-only memory (Read-Only
  • the volatile memory may be a random access memory (RAM), a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDRSDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchronous link dynamic random access memory (SLDRAM) and a direct memory bus random access memory (DRRAM).
  • the memory 1609 in the embodiment of the present application includes but is not limited to these and any other suitable types of memories.
  • the processor 1610 may include one or more processing units; optionally, the processor 1610 integrates an application processor and a modem processor, wherein the application processor mainly processes operations related to an operating system, a user interface, and application programs, and the modem processor mainly processes wireless communication signals, such as a baseband processor. It is understandable that the modem processor may not be integrated into the processor 1610.
  • An embodiment of the present application also provides a readable storage medium, on which a program or instruction is stored.
  • a program or instruction is stored.
  • each process of the above-mentioned security assessment method embodiment is implemented, and the same technical effect can be achieved. To avoid repetition, it will not be repeated here.
  • the processor is the processor in the electronic device described in the above embodiment.
  • the readable storage medium includes a computer readable storage medium, such as a computer read-only memory ROM, a random access memory RAM, a magnetic disk or an optical disk.
  • an embodiment of the present application also provides a server 1700, including a processor 1701 and a memory 1702, and the memory 1702 stores a program or instruction that can be executed on the processor 1701.
  • the program or instruction When the program or instruction is executed by the processor 1701, it implements the various steps of the above-mentioned application server-side business processing method embodiment, or implements the various steps of the above-mentioned management server-side security information transmission method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • An embodiment of the present application further provides a chip, which includes a processor and a communication interface, wherein the communication interface is coupled to the processor, and the processor is used to run programs or instructions to implement the various processes of the above-mentioned security assessment method embodiment, or to implement the various processes of the above-mentioned business processing method embodiment, or to implement the various processes of the above-mentioned security information transmission method embodiment, and can achieve the same technical effect. To avoid repetition, it will not be repeated here.
  • the chip mentioned in the embodiments of the present application can also be called a system-level chip, a system chip, a chip system or a system-on-chip chip, etc.
  • the embodiment of the present application provides a computer program product, which is stored in a storage medium and executed by at least one processor to implement each process of the above-mentioned security assessment method embodiment, or, To implement each process of the above-mentioned business processing method embodiment, or to implement each process of the above-mentioned security information transmission method embodiment, and to achieve the same technical effect, it will not be repeated here to avoid repetition.
  • the technical solution of the present application can be embodied in the form of a computer software product, which is stored in a storage medium (such as ROM/RAM, a disk, or an optical disk), and includes a number of instructions for a terminal (which can be a mobile phone, a computer, a server, or a network device, etc.) to execute the methods described in each embodiment of the present application.
  • a storage medium such as ROM/RAM, a disk, or an optical disk
  • a terminal which can be a mobile phone, a computer, a server, or a network device, etc.

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Storage Device Security (AREA)

Abstract

本申请提供一种安全评估、业务处理、安全信息传输方法及相关设备,涉及通信技术领域,方法包括:在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,所述第一安全信息包括电子设备的REE的安全状态信息或者所述REE的安全评估结果;采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;将第二安全信息发送给所述应用服务器,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。

Description

安全评估、业务处理、安全信息传输方法及相关设备
相关申请的交叉引用
本申请主张2023年06月15日在中国提交的中国专利申请号202310715581.6的优先权,其全部内容通过引用包含于此。
技术领域
本申请涉及通信技术领域,尤其涉及一种安全评估、业务处理、安全信息传输方法及相关设备。
背景技术
应用服务(例如,手机支付、手机银行、金融服务等)提供方在向用户提供服务之前,往往需要对电子设备进行安全评估,在基于安全评估结果确定该电子设备为安全可信的设备的情况下才允许其接入服务。具体的,应用服务器向电子设备发送安全评估请求,电子设备基于安全评估请求,获取富执行环境(Rich Execution Environment,REE)的安全状态信息并进行安全评估,得到REE的安全评估结果,并向应用服务器返回该安全评估结果,进而应用服务器可以基于该安全评估结果确定是否允许该电子设备接入所申请访问的业务。然而,这种安全评估方式的可靠性较差。
发明内容
本申请实施例提供一种安全评估、业务处理、安全信息传输方法及相关设备,能够提高电子设备的安全评估结果的可靠性。
第一方面,本申请实施例提供了一种安全评估方法,所述方法包括:
在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;
所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;
所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
第二方面,本申请实施例提供了一种安全评估装置,应用于电子设备,所述装置包括:
第一确定模块,用于在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;
解密模块,用于采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;
签名模块,用于采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
第一发送模块,用于将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
第三方面,本申请实施例提供了一种业务处理方法,所述方法包括:
应用服务器向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
所述应用服务器从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
第四方面,本申请实施例提供了一种业务处理装置,应用于应用服务器,所述装置包括:
第三发送模块,用于向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
第一接收模块,用于从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
第三确定模块,用于根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
第五方面,本申请实施例提供了一种安全信息传输方法,所述方法包括:
管理服务器生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
所述管理服务器向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
第六方面,本申请实施例提供了一种安全信息传输装置,应用于管理服务器,所述装置包括:
生成模块,用于生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
第四发送模块,用于向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
第七方面,本申请实施例提供了一种电子设备,该电子设备包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第一方面所述的安全评估方法中的步骤。
第八方面,本申请实施例提供了一种应用服务器,该应用服务器包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第三方面所述的业务处理方法中的步骤。
第九方面,本申请实施例提供了一种管理服务器,该管理服务器包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如第五方面所述的安全信息传输方法中的步骤。
第十方面,本申请实施例提供了一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如第一方面所述的安全评估方法中的 步骤,或者实现如第三方面所述的业务处理方法中的步骤,或者实现如第五方面所述的安全信息传输方法中的步骤。
第十一方面,本申请实施例提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如第一方面所述的方法,或者实现如第三方面所述的业务处理方法中的步骤,或者实现如第五方面所述的安全信息传输方法中的步骤。
第十二方面,本申请实施例提供一种计算机程序产品,该程序产品被存储在存储介质中,该程序产品被至少一个处理器执行以实现如第一方面所述的方法,或者实现如第三方面所述的业务处理方法中的步骤,或者实现如第五方面所述的安全信息传输方法中的步骤。
本申请实施例中,在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的REE的安全状态信息或者所述REE的安全评估结果;所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名,也即本申请实施例通过电子设备的安全协处理器确定目标安全评估结果,并通过电子设备的私钥对所述目标安全评估结果进行签名,且采用电子设备的根密钥对电子设备的私钥进行加密,这样可以实现安全评估结果与电子设备的绑定,减少安全评估结果被篡改的情况发生,进而可以提高电子设备的安全评估结果的可靠性,此外,由于安全协处理器具备抗硬件侧信道、故障注入等攻击的能力,这样可以保证上述安全评估过程的安全性。
附图说明
图1是本申请实施例提供的一种安全评估方法的流程图;
图2是本申请实施例提供的安全评估系统的示意图;
图3是本申请实施例提供的另一种安全评估方法的流程图;
图4是本申请实施例提供的又一种安全评估方法的流程图;
图5是本申请实施例提供的又一种安全评估方法的流程图;
图6是本申请实施例提供的又一种安全评估方法的流程图;
图7是本申请实施例提供的一种安全评估装置的结构示意图;
图8是本申请实施例提供的另一种安全评估装置的结构示意图;
图9是本申请实施例提供的又一种安全评估装置的结构示意图;
图10是本申请实施例提供的又一种安全评估装置的结构示意图;
图11是本申请实施例提供的一种业务处理装置的结构示意图;
图12是本申请实施例提供的另一种业务处理装置的结构示意图;
图13是本申请实施例提供的一种安全信息传输装置的结构示意图;
图14是本申请实施例提供的另一种安全信息传输装置的结构示意图;
图15是本申请实施例提供的一种电子设备的结构示意图之一;
图16是本申请实施例提供的一种电子设备的结构示意图之二;
图17是本申请实施例提供的一种服务器的结构示意图。
具体实施方式
下面将结合本申请实施例中的附图,对本申请实施例中的技术方案进行清楚地描述,显然,所描述的实施例是本申请一部分实施例,而不是全部的实施例。基于本申请中的实施例,本领域普通技术人员获得的所有其他实施例,都属于本申请保护的范围。
本申请的说明书和权利要求书中的术语“第一”、“第二”等是用于区别类似的对象,而不用于描述特定的顺序或先后次序。应该理解这样使用的数据在适当情况下可以互换,以便本申请的实施例能够以除了在这里图示或描述的那些以外的顺序实施,且“第一”、“第二”等所区分的对象通常为一类,并不限定对象的个数,例如第一对象可以是一个,也可以是多个。此外,说明书以及权利要求中“和/或”表示所连接对象的至少其中之一,字符“/”,一般表示前后关联对象是一种“或”的关系。
下面结合附图,通过具体的实施例及其应用场景对本申请实施例提供的安全评估方法、装置、电子设备、管理服务器及应用服务器进行详细地说明。
参见图1,图1是本申请实施例提供的一种安全评估方法的流程图,如图1所示,包括以下步骤:
步骤101、应用服务器向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性。
本实施例中,上述应用服务器可以是任意提供应用服务(例如,手机支付、手机银行、金融服务等)的服务器。上述电子设备可以为终端,其中,终端可以是手机、平板电脑(Tablet Personal Computer)、膝上型电脑(Laptop Computer)、笔记本电脑、个人数字助理(Personal Digital Assistant,PDA)、掌上电脑、上网本、超级移动个人计算机(Ultra-mobile Personal Computer,UMPC)、增强现实(Augmented Reality,AR)、虚拟现实(Virtual Reality,VR)设备、机器人、可穿戴式设备(Wearable Device)、车载设备(Vehicle User Equipment,VUE)、船载设备、行人终端 (Pedestrian User Equipment,PUE)、游戏机、个人计算机(Personal Computer,PC)等终端侧设备。
上述安全评估请求可以包括授权令牌,示例性地,上述授权令牌可以是由电子设备的管理服务器发放的授权令牌。
示例性地,应用服务器可以向电子设备的REE侧发送安全评估请求。例如,如图2所示,应用服务器可以通过应用服务器的安全评估模块向电子设备的REE侧的安全评估客户端应用(即Client App)发送安全评估请求。
在一些可选的实施例中,应用服务器可以基于传输安全机制传输上述安全评估请求给电子设备。例如,应用服务器可以通过传输层安全(Transport Layer Security,TLS)协议传输上述安全评估请求给电子设备,以提高传输安全性。
步骤102、所述电子设备在接收到应用服务器发送的安全评估请求的情况下,所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的REE的安全状态信息或者所述REE的安全评估结果。
上述电子设备包括安全协处理器,例如,安全处理单元(Secure Processor Unit,SPU)。此外,上述电子设备还包括REE和可信执行环境(Trusted Execution Environment,TEE),其中,上述REE中运行有富执行环境操作系统(Operation System,OS),上述TEE中运行有可信执行环境操作系统,如图2所示。需要说明的是,上述安全协处理器具备抗硬件侧信道、故障注入等攻击的能力,其安全性强。而上述TEE存在软件侧信道攻击、TEE的应用遭受逆向工程攻击等安全风险,相较于安全协处理器,安全性较低。
具体的,电子设备在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协议处理器可以获取第一安全信息,并基于第一安全信息确定目标安全评估结果,例如,电子设备的安全协议处理器可以从电子设备的TEE侧接收第一安全信息,电子设备的TEE侧可以从电子设备的REE侧接收REE的安全状态信息。
示例性地,电子设备的REE侧接收应用服务器发送的安全评估请求,收集REE的安全状态信息,并可以向电子设备的TEE侧发送授权令牌、REE的安全状态信息等,进而TEE侧可以验证授权令牌的有效性,以检测应用服务器是否有权限获得电子设备的安全性状态,例如,TEE侧在确定上述授权令牌有效的情况下,确定应用服务器有权限获得电子设备的安全性状态,在该情况下可以继续后续的安全评估相关操作;在验证上述授权令牌失败或者确定上述授权令牌无效的情况下,可以结束安全评估相关操作,并返回提示信息,以提示应用服务器重新申请授权令牌。
进一步的,在确定应用服务器有权限获得电子设备的安全性状态的情况下,TEE侧可以将REE的安全状态信息发送给安全协处理器;或者,TEE侧可以基于REE的安全状态信息进行安全评估,得到REE的安全评估结果,并将TEE的安全状态信息和 REE的安全评估结果发送给安全协处理器。
在一些可选的实施例中,所述第一安全信息还可以包括所述电子设备的TEE的安全状态信息或者所述TEE的安全评估结果。
相应地,TEE侧可以收集TEE的安全状态信息,将TEE的安全状态信息和REE的安全状态信息发送给安全协处理器;或者,TEE侧可以基于REE的安全状态信息进行安全评估,得到REE的安全评估结果,并将TEE的安全状态信息和REE的安全评估结果发送给安全协处理器;或者,TEE侧可以基于REE的安全状态信息进行安全评估,得到REE的安全评估结果,基于TEE的安全状态信息进行安全评估,得到TEE的安全评估结果,并将TEE的安全评估结果和REE的安全评估结果发送给安全协处理器。
示例性地,在第一安全信息包括REE的安全状态信息的情况下,安全协处理器可以基于REE的安全状态信息进行安全评估,得到REE的安全评估结果,并可以将上述REE的安全评估结果作为目标安全评估结果;在第一安全信息包括REE的安全评估结果和TEE的安全状态信息的情况下,安全协处理器可以基于TEE的安全状态信息进行安全评估,得到TEE的安全评估结果,并可以综合上述REE的安全评估结果和上述TEE的安全评估结果,得到目标安全评估结果;在第一安全信息包括REE的安全评估结果和TEE的安全评估结果的情况下,安全协处理器可以直接综合上述REE的安全评估结果和上述TEE的安全评估结果,得到目标安全评估结果。
上述综合REE的安全评估结果和上述TEE的安全评估结果,得到目标安全评估结果,例如,可以将上述REE的安全评估结果和上述TEE的安全评估结果进行加权求和或根据预设模型进行综合评分,得到目标安全评估结果。
上述REE的安全状态信息可以包括但不限于恶意/欺骗/伪冒应用、病毒感染、应用签名验证、验证启动、应用层数据加密、软件方式的内存漏洞防御、应用层可信度量等指标要素,以及每一个指标要素的状态信息,例如,对于指标要素为恶意/欺骗/伪冒应用,对应的状态信息可以为不存在、未知、存在中的一者,又如,对于指标要素为病毒感染,对应的状态信息可以为不存在、未知、存在中的一者,再如,对于指标要素为验证启动,对应的状态信息可以为支持、不支持中的一者。
示例性的,对于基于REE的安全状态信息进行安全评估,可以基于上述REE的安全状态信息的各个指标要素的状态信息确定各个指标要素对应的评分,进而可以基于各个指标要素对应的评分和权重,计算得到上述REE的安全评估结果;或者可以将上述REE的安全状态信息输入预先构建的安全状态评估模型,得到上述REE的安全评估结果。
上述TEE的安全状态信息可以包括但不限于恶意/欺骗/伪冒应用、病毒感染、可信验证启动、可信用户交互、生物特征识别、敏感信息存储、内核实时安全保护、系统完整性度量、内核控制流完整性度量等指标要素,以及每一个指标要素的状态信息, 例如,对于指标要素为恶意/欺骗/伪冒应用,对应的状态信息可以为不存在、未知、存在中的一者,又如,对于指标要素为病毒感染,对应的状态信息可以为不存在、未知、存在中的一者,再如,对于指标要素为可信验证启动,对应的状态信息可以为支持、不支持中的一者。
示例性的,对于基于TEE的安全状态信息进行安全评估,可以基于上述TEE的安全状态信息的各个指标要素的状态信息确定各个指标要素对应的评分,进而可以基于各个指标要素对应的评分和权重,计算得到上述TEE的安全评估结果;或者可以将上述TEE的安全状态信息输入预先构建的安全状态评估模型,得到上述TEE的安全评估结果。
步骤103、所述安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文。
上述根密钥可以是由电子设备生成的随机数,例如,上述根密钥可以是由电子设备的硬件安全模块(Hardware Security Module,HSM)或者安全协处理器等生成的随机数。其中,上述根密钥可以存储于安全存储区域,例如,一次性可编程(One Time Programable,OTP)存储器。其中,上述OTP存储器可以位于安全协议处理器,或者位于电子设备的除安全协处理器之外的其他位置。
需要说明的是,上述根密钥可以是针对电子设备的安全性评估新生成的根密钥,也即上述根密钥可以是专用于电子设备的安全性评估的根密钥;或者,上述根密钥也可以是复用已有的根密钥,在该情况下,该根密钥除了用于电子设备的安全性评估,还用于其他业务或功能,例如,用于电子设备的锁屏功能。在一些可选的实施例中,可以复用电子设备的OTP存储器内已有的根密钥进行上述电子设备的安全性评估。
上述电子设备的私钥和电子设备的公钥形成公私密钥对,其中,上述电子设备的公私密钥对可以是由电子设备的硬件安全模块或者安全协处理器等生成。此外,上述电子设备的私钥可以由安全协处理器采用电子设备的根密钥进行加密后存储于电子设备的存储区域,例如,存储于电子设备的闪存(Flash)内或OTP存储器等,这样可以降低电子设备的私钥泄露的风险。
示例性地,安全协处理器可以从安全协处理器的OTP存储器读取电子设备的根密钥,并从电子设备的闪存获取第一密文,进而可以基于电子设备的根密钥对第一密文进行解密,得到电子设备的私钥。
在一些可选的实施例中,所述电子设备的根密钥对由所述安全协处理器生成,这样可以提高所述电子设备的公私密钥对的安全性。
在一些可选的实施例中,所述电子设备的公私密钥对由所述安全协处理器生成;其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对 应的公钥,这样可以提高所述电子设备的公私密钥对的安全性。
需要说明的是,上述根密钥也可以称为安全评估信任根,上述电子设备的私钥也可以称为设备私钥,上述电子设备的公钥也可以称为设备公钥。
步骤104、所述安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名。
在一些可选的实施例中,安全协处理器可以对目标安全评估结果进行哈希计算,得到目标安全评估结果的哈希值,并采用电子设备的私钥对所述目标安全评估结果的哈希值进行签名,得到目标安全评估结果的签名,这样相比于直接采用电子设备的私钥对目标安全评估结果进行签名,可以提高对目标安全评估结果进行签名的效率。
步骤105、所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
示例性地,安全协处理器可以将第二安全信息发送给TEE侧,TEE侧可以将上述第二安全信息发送给REE侧,进而REE侧可以将上述第二安全信息发送给应用服务器。例如,安全协处理器可以将第二安全信息发送给TEE侧的安全评估可信应用(Trusted App),TEE侧的安全评估可信应用可以将第二安全信息发送给REE侧的安全评估客户端应用,进而REE侧的安全评估客户端应用将第二安全信息发送给应用服务器的安全评估模块。
在一些可选的实施例中,电子设备的REE侧可以采用传输安全机制发送上述第二安全信息给应用服务器,例如,电子设备的REE侧可以基于TLS协议传输上述第二安全信息给应用服务器,以提高传输的安全性。
步骤106、所述应用服务器在接收到所述第二安全信息的情况下,根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
示例性地,可以基于电子设备的公钥对目标安全评估结果的签名进行验证,在验证通过的情况下,可以根据上述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,例如,在上述目标安全评估结果指示电子设备为安全的设备的情况下,允许所述电子设备接入目标业务,在上述目标安全评估结果指示电子设备为不安全的设备的情况下,不允许所述电子设备接入目标业务。可以理解的是,在上述目标安全评估结果的签名未验证通过的情况下,不允许所述电子设备接入目标业务。
本申请实施例通过安全协处理器确定目标安全评估结果,并通过电子设备的私钥对所述目标安全评估结果进行签名,且采用电子设备的根密钥对电子设备的私钥进行加密,这样可以实现安全评估结果与电子设备的绑定,减少安全评估结果被篡改的情况发生,进而可以提高电子设备的安全评估结果的可靠性。此外,由于安全协处理器 具备抗硬件侧信道、故障注入等攻击的能力,这样可以保证上述安全评估过程的安全性。
在一些可选的实施例中,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
本实施例中,上述管理服务器可以用于对电子设备进行管理。上述管理服务器的私钥和管理服务器的公钥形成管理服务器的公私密钥对。示例性地,上述管理服务器的公私密钥对可以由管理服务器的密钥管理服务(Key Management Service,KMS)或硬件安全模块等生成,并存储于管理服务器的硬件安全模块。需要说明的是,上述管理服务器的私钥也可以称为服务器私钥,上述管理服务器的公钥也可以称为服务器公钥。
在一些可选的实施例中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;
其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
相应地,上述步骤105之前,也即所述电子设备将第二安全信息发送给所述应用服务器之前,所述方法还可以包括:
所述管理服务器生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
所述管理服务器向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
所述电子设备在从所述管理服务器接收到所述第二数字证书信息的情况下,存储所述第二数字证书信息。
具体地,管理服务器可以基于管理服务器的私钥对所述电子设备的公钥进行签名得到电子设备的数字证书,可以基于管理服务器的私钥或者目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到管理服务器的数字证书,并可以将上述 电子设备的数字证书和管理服务器的数字证书发送给电子设备,进而电子设备可以将上述电子设备的数字证书和管理服务器的数字证书存储于电子设备的闪存。
在一些可选的实施例中,所述管理服务器生成数字证书之前,所述管理服务器可以从所述电子设备接收数字证书生成请求,进而所述管理服务器可以基于上述数字证书生成请生成数字证书。可选的,上述数字证书生成请求可以包括电子设备的公钥。
在一些可选的实施例中,所述第二数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
相应地,上述步骤106,也即所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务可以包括:
所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证;
所述应用服务器在所述管理服务器的数字证书通过验证的情况下,根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;
所述应用服务器在所述电子设备的数字证书通过验证的情况下,根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;
所述应用服务器在所述目标安全评估结果的签名通过验证的情况下,根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
可以理解的是,在管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到的情况下,所述应用服务器根据所述管理服务器的数字证书中的公钥对所述管理服务器的数字证书进行验证;在管理服务器的数字证书为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到的情况下,所述应用服务器根据目标数字证书对所述管理服务器的数字证书进行验证。
上述根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,例如,在上述目标安全评估结果确定电子设备为安全的设备的情况下,应用服务器允许所述电子设备接入目标业务,在上述目标安全评估结果确定电子设备为不安全的设备的情况下,应用服务器不允许所述电子设备接入目标业务。
在一些可选的实施例中,在满足如下任一项的情况下,应用服务器不允许所述电子设备接入目标业务:
管理服务器的数字证书未通过验证或者验证失败;
电子设备的数字证书未通过验证或者验证失败;
目标安全评估结果的签名未通过验证或者验证失败。
本申请实施例基于目标数字证书或者管理服务器的数字证书进行数字证书链(即 管理服务器的数字证书、电子设备的数字证书和目标安全评估结果的签名)的验签,并仅在上述各个数字证书验证通过的情况下基于目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,这样可以进一步减少上述目标安全评估结果被攻击者篡改的情况发生,进而可以进一步保证安全评估的可靠性。
在一些可选的实施中,在所述第二数字证书信息还包括所述管理服务器的数字证书的情况下,所述应用服务器可以直接根据所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证;在所述第二数字证书信息还包括所述管理服务器的数字证书的标识的情况下,所述应用服务器可以根据所述管理服务器的数字证书的标识从管理服务器获取所述管理服务器的数字证书,进而可以根据所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证。
在一些可选的实施中,在所述第二数字证书信息未包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识的情况下,所述应用服务器可以根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识,根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书,进而可以根据所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证。
在一些可选的实施例中,上述步骤102之前,也即所述安全协处理器根据所述第一安全信息确定目标安全评估结果之前,所述方法还包括:
所述安全协处理器获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
相应地,上述步骤102,也即所述安全协处理器根据所述第一安全信息确定目标安全评估结果,包括:
在所述目标验证结果指示所述电子设备为安全的设备的情况下,所述安全协处理器根据所述第一安全信息确定目标安全评估结果。
示例性地,安全协处理器可以在每次需要进行安全评估的情况下,均向管理服务器发送验证请求,并从管理服务器接收验证结果,以保证每次进行安全评估的情况下电子设备自身是安全的设备;或者,安全协处理器可以周期性地向管理服务器发送验证请求,从管理服务器接收验证结果并进行存储,在有每个周期内均可基于该验证结果确定电子设备本身的安全性,这样可以在保证电子设备自身是安全的设备的同时,节省开销。
相应地,安全协处理器在获取到目标验证结果之后,若目标验证结果指示电子设备为安全的设备,则安全协处理器可以根据所述第一安全信息确定目标安全评估结果;若目标验证结果指示电子设备为不安全的设备,则安全协处理器可以结束流程,也即 停止安全评估相关操作,并提示应用服务器安全评估失败或者电子设备为不安全的设备。
本申请实施例通过管理服务器对电子设备自身的安全性进行验证,这样可以保证在电子设备自身为安全的设备的情况下安全协处理器根据所述第一安全信息确定目标安全评估结果,这样可以进一步提高对电子设备的安全评估的可靠性。
参见图3,图3是本申请实施例提供的一种安全评估方法的流程图,如图3所示,包括以下步骤:
步骤301、应用服务器向电子设备的REE侧发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性,所述安全评估请求包括授权令牌。
步骤302、所述电子设备的REE侧在接收到应用服务器发送的安全评估请求的情况下,所述电子设备的REE侧获取REE的安全状态信息。
步骤303、所述电子设备的REE侧向所述电子设备的TEE侧发送所述授权令牌和所述REE的安全状态信息。
步骤304、所述电子设备的TEE侧在接收到所述授权令牌和所述REE的安全状态信息的情况下,验证所述授权令牌是否有效。
其中,TEE侧在确定上述授权令牌有效的情况下,确定应用服务器有权限获得电子设备的安全性状态,在该情况下,执行步骤305,否则,可以结束安全评估相关操作,并返回提示信息,以提示应用服务器重新申请授权令牌。
步骤305、所述电子设备的TEE侧收集所述TEE的安全状态信息,基于所述REE的安全状态信息进行安全评估,得到所述REE的安全评估结果。
步骤306、所述电子设备的TEE侧将第一安全信息发送给所述电子设备的安全协处理器,所述第一安全信息包括所述TEE的安全状态信息和所述REE的安全评估结果。
需要说明的是,上述步骤301至步骤306可以参见前述实施例的相关说明,在此不做赘述。
步骤307、所述安全协处理器在接收到所述第一安全信息的情况下,通过所述电子设备的TEE和REE向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数。
在一些可选的实施例中,所述安全协处理器在接收到所述第一安全信息的情况下,查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,将处于有效期内的所述电子设备的验证结果确定为目标验证结果;在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,所述安全协处理器通过所述电子设备的TEE和REE向管理服务器发送验证请求,这样不仅可以提高对电子设备的安全性验证的效率,还可以节约资源开销。
需要说明的是,在该实施例中,安全协处理器在每次通过所述电子设备的TEE和REE从管理服务器接收到验证结果之后,可以将该验证结果进行存储,并设置对应的有效期,在该有效期内均可以基于该验证结果确定电子设备自身是否为安全的设备。其中,上述有效期可以根据实际需求进行合理设置。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
示例性的,上述设备指纹可以是可唯一性标识该电子设备的信息,例如,设备的唯一序列号、设备标识等。
步骤308、所述管理服务器在接收到所述验证请求的情况下,根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备。
示例性地,管理服务器可以基于电子设备的系统版本是否为最新版本、固件版本是否为最新版本、系统是否被Root、硬件配置是否被篡改、固件配置是否被篡改等验证电子设备的安全性,得到验证结果。其中,上述管理服务器对电子设备进行安全性验证也可以称为设备远程证明,上述验证结果也可以称为设备远程证明结果。
在一些可选的实施例中,所述管理服务器根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果之后,所述方法还包括:
所述管理服务器向所述应用服务器发送所述验证结果。
本实施例中,管理服务器还可以向应用服务器发送验证结果,应用服务器可以基于上述验证结果确定电子设备自身为安全的设备或者不安全的设备,进而可以决定是否允许电子设备接入目标业务。
示例性的,在上述验证结果指示电子设备为安全的设备的情况下,应用服务器可以基于上述目标安全评估结果确定是否允许电子设备接入目标业务,在上述验证结果指示电子设备为不安全的设备的情况下,应用服务器可以不允许电子设备接入目标业务。
在一些可选的实施例中,在所述验证结果指示电子设备为不安全的设备的情况下,所述管理服务器向所述应用服务器发送所述验证结果;相应地,所述应用服务器在接收到所述验证结果的情况下,不允许电子设备接入目标业务。
步骤309、所述管理服务器向所述电子设备发送所述验证结果。
步骤310、所述安全协处理器在通过所述电子设备的TEE和REE接收到所述管理服务器发送的验证结果的情况下,若所述验证结果指示所述电子设备为安全的设备,则根据所述第一安全信息确定目标安全评估结果。
可选地,若所述验证结果指示所述电子设备为不安全的设备,则所述电子设备向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安 全的设备或者对所述电子设备的安全评估失败。
步骤311、所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文。
步骤312、所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名。
步骤313、所述电子设备的安全协处理器将第二安全信息发送给所述TEE侧,其中,所述第二安全信息包括所述目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
在一些可选的实施例中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
步骤314、所述TEE侧将所述第二安全信息发送给所述REE侧。
步骤315、所述REE侧将所述第二安全信息发送给所述应用服务器。
步骤316、所述应用服务器在接收到所述第二安全信息的情况下,根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
需要说明的是,上述步骤311至步骤316可以参见前述实施例的相关说明,在此不做赘述。
本申请实施例通过所述电子设备的安全协处理器确定目标安全评估结果,并通过电子设备的私钥对所述目标安全评估结果进行签名,且采用电子设备的根密钥对电子设备的私钥进行加密,这样可以实现安全评估结果与电子设备的绑定,减少安全评估结果被篡改的情况发生,进而可以提高电子设备的安全评估结果的可靠性。此外,通过管理服务器对电子设备自身的安全性进行验证,这样可以保证在电子设备自身为安全的设备的情况下安全协处理器根据所述第一安全信息确定目标安全评估结果,这样可以进一步提高对电子设备的安全评估的可靠性。
参见图4,图4是本申请实施例提供的一种安全评估方法的流程图,如图4所示,包括以下步骤:
步骤401、在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果。
具体的,电子设备在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协议处理器可以获取第一安全信息,并基于第一安全信息确定目标安全评估结 果,例如,电子设备的安全协议处理器可以从电子设备的TEE侧接收第一安全信息,电子设备的TEE侧可以从电子设备的REE侧接收REE的安全状态信息。
步骤402、所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文。
步骤403、所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名。
步骤404、所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
可选地,所述根密钥存储于所述电子设备的OTP存储器。
本实施例中,将根密钥存储于OTP存储器,可以避免根密钥被篡改。
需要说明的是,上述OTP存储器可以位于安全协处理器,或者可以位于电子设备中不同于安全协处理器的位置。
可选地,所述电子设备的根秘钥由所述安全协处理器生成。
本实施例中,由安全协处理器生成电子设备的根秘钥,由于安全协处理器具备抗硬件侧信道、故障注入等攻击的能力,这样提高电子设备的根秘钥的安全性。
可选地,所述电子设备的公私密钥对由所述安全协处理器生成;
其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
本实施例中,由安全协处理器生成电子设备的公私密钥对,由于安全协处理器具备抗硬件侧信道、故障注入等攻击的能力,这样提高电子设备的公私密钥对的安全性。
在一些可选的实施例中,所述电子设备的根密钥由所述安全协处理器生成,且所述根密钥存储于所述安全协处理器的OTP存储器,这样电子设备的根密钥只能由安全协处理器访问,不会暴露给任何软件。
在一些可选的实施例中,所述电子设备的根密钥与所述电子设备的其他设备标识均不相同,也即不重用电子设备的其他设备标识作为根密钥,这样可以防止不同业务之间能通过相同的设备标识进行关联,进而可以降低设备跟踪、信息泄漏等安全风险。
可选地,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
可选地,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;
其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务 器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
可选地,所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果之前,所述方法还包括:
所述电子设备获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果,包括:
在所述目标验证结果指示所述电子设备为安全的设备的情况下,所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果。
可选的,所述方法还包括:
在所述目标验证结果指示所述电子设备为不安全的设备的情况下,所述电子设备向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安全的设备或者对所述电子设备的安全评估失败。
可选地,所述电子设备获取所述电子设备的目标验证结果,包括:
所述电子设备向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
所述电子设备接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
可选地,所述电子设备向管理服务器发送验证请求之前,所述方法还包括:
所述电子设备查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;
在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备将处于有效期内的所述电子设备的验证结果确定为目标验证结果;
所述电子设备向管理服务器发送验证请求,包括:
在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备向管理服务器发送验证请求。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
可选地,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
可选地,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;
所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果,包括:
所述电子设备的安全协处理器根据所述TEE的安全状态信息对所述TEE进行安全评估,得到所述TEE的安全评估结果;
所述电子设备的安全协处理器根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
本实施例中,通过安全协处理器对TEE进行安全评估,相比于通过TEE自身对TEE进行安全评估,可以提高TEE的安全评估结果的可靠性。
可选地,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
本实施例中,通过TEE基于所述REE的安全状态信息进行安全评估得到REE的安全评估结果,相比于通过REE基于REE的安全状态信息进行安全评估得到REE的安全评估结果,可以提高REE的安全评估结果的可靠性。
需要说明的是,该实施方式的实现方式可以参见图1和图3所示的实施例的相关说明,此处不作赘述。
参见图5,图5是本申请实施例提供的一种业务处理方法的流程图,如图5所示,包括以下步骤:
步骤501、应用服务器向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
步骤502、所述应用服务器从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
步骤503、所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
可选地,所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,包括:
所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一 级的数字证书;
在所述管理服务器的数字证书通过验证的情况下,所述应用服务器根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;
在所述电子设备的数字证书通过验证的情况下,所述应用服务器根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;
在所述目标安全评估结果的签名通过验证的情况下,所述应用服务器根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
可选地,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
可选地,所述应用服务器根据第一数字证书对所述管理服务器的数字证书进行验证之前,所述方法还包括:
所述应用服务器根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;
所述应用服务器根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
需要说明的是,该实施方式的实现方式可以参见图1和图3所示的实施例的相关说明,此处不作赘述。
参见图6,图6是本申请实施例提供的一种安全信息传输方法的流程图,如图6所示,包括以下步骤:
步骤601、管理服务器生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
步骤602、所述管理服务器向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
在一些可选的实施例中,管理服务器可以接收电子设备发送的数字证书生成请求,并响应于所述数字证书生成理由,生成数字证书。
可选地,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
可选地,所述方法还包括:
所述管理服务器接收所述电子设备发送的验证请求,其中,所述验证请求用于请 求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
所述管理服务器根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;
所述管理服务器向所述电子设备发送所述验证结果。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
需要说明的是,该实施方式的实现方式可以参见图1和图3所示的实施例的相关说明,此处不作赘述。
本申请实施例提供的安全信息传输方法,执行主体可以为安全信息传输装置。本申请实施例中以安全信息传输装置执行安全信息传输方法为例,说明本申请实施例提供的安全信息传输装置。
参见图7,图7是本申请实施例提供的一种安全评估装置的结构示意图,该安全评估装置应用于电子设备,如图7所示,所述安全评估装置700包括:
第一确定模块701,用于在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;
解密模块702,用于采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;
签名模块703,用于采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
第一发送模块704,用于将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
可选地,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
可选地,所述电子设备的根秘钥由所述安全协处理器生成。
可选地,所述电子设备的公私密钥对由所述安全协处理器生成;
其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
可选地,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
可选地,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理 服务器的数字证书的标识;
其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
可选地,参见图8,所述装置还包括:
第一获取模块705,用于所述根据所述第一安全信息确定目标安全评估结果之前,获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
所述第一确定模块701具体用于:
在所述目标验证结果指示所述电子设备为安全的设备的情况下,根据所述第一安全信息确定目标安全评估结果。
可选地,参见图9,所述装置还包括:
第二发送模块706,用于在所述目标验证结果指示所述电子设备为不安全的设备的情况下,向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安全的设备或者对所述电子设备的安全评估失败。
可选地,所述第一获取模块705具体用于:
向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
可选地,参见图10,所述装置还包括:
查询模块707,用于在所述向管理服务器发送验证请求之前,查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;
第二确定模块708,用于在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,将处于有效期内的所述电子设备的验证结果确定为目标验证结果;
所述第一获取模块705具体用于:
在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,向管理服务器发送验证请求。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
可选地,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
可选地,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态 信息;
所述第一确定模块701具体用于:
根据所述TEE的安全状态信息对所述TEE进行安全评估,得到所述TEE的安全评估结果;
根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
可选地,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
本申请实施例中的安全评估装置可以是电子设备,也可以是电子设备中的部件,例如集成电路或芯片。该电子设备可以是终端,也可以为除终端之外的其他设备。示例性地,电子设备可以为手机、平板电脑、笔记本电脑、掌上电脑、车载电子设备、移动上网装置(Mobile Internet Device,MID)、增强现实(augmented reality,AR)/虚拟现实(virtual reality,VR)设备、机器人、可穿戴设备、超级移动个人计算机(ultra-mobile personal computer,UMPC)、上网本或者个人数字助理(personal digital assistant,PDA)等,还可以为服务器、网络附属存储器(Network Attached Storage,NAS)、个人计算机(personal computer,PC)、电视机(television,TV)、柜员机或者自助机等,本申请实施例不作具体限定。
本申请实施例中的安全评估装置可以为具有操作系统的装置。该操作系统可以为安卓(Android)操作系统,可以为ios操作系统,还可以为其他可能的操作系统,本申请实施例不作具体限定。
本申请实施例提供的安全评估装置能够实现上述方法实施例实现的各个过程,为避免重复,这里不再赘述。
参见图11,图11是本申请实施例提供的一种业务处理装置的结构示意图,该业务处理装置应用于应用服务器,如图11所示,所述业务处理装置1100包括:
第三发送模块1101,用于向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
第一接收模块1102,用于从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
第三确定模块1103,用于根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
可选地,所述第三确定模块具体用于:
根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
在所述管理服务器的数字证书通过验证的情况下,根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;
在所述电子设备的数字证书通过验证的情况下,根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;
在所述目标安全评估结果的签名通过验证的情况下,根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
可选地,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
可选地,参见图12,所述装置还包括:
第四确定模块1104,用于所述根据第一数字证书对所述管理服务器的数字证书进行验证之前,根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;
第二获取模块1105,用于根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
本申请实施例中的业务处理装置可以是服务器,也可以是服务器中的部件,例如集成电路或芯片。
本申请实施例提供的业务处理装置能够实现上述方法实施例实现的各个过程,为避免重复,这里不再赘述。
参见图13,图13是本申请实施例提供的一种安全信息传输装置的结构示意图,该安全信息传输装置应用于管理服务器,如图13所示,所述安全信息传输装置1300包括:
生成模块1301,用于生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
第四发送模块1302,用于向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
可选地,所述第二数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
可选地,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
可选地,参见图14,所述装置还包括:
第二接收模块1303,用于接收所述电子设备发送的验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
验证模块1304,用于根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;
第五发送模块1305,用于向所述电子设备发送所述验证结果。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
本申请实施例中的安全信息传输装置可以是服务器,也可以是服务器中的部件,例如集成电路或芯片。
本申请实施例提供的安全信息传输装置能够实现上述方法实施例实现的各个过程,为避免重复,这里不再赘述。
可选的,如图15所示,本申请实施例还提供一种电子设备1500,包括处理器1501和存储器1502,存储器1502上存储有可在所述处理器1501上运行的程序或指令,该程序或指令被处理器1501执行时实现上述安全评估方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
需要说明的是,本申请实施例中的电子设备包括移动电子设备和非移动电子设备。
图16为实现本申请实施例的一种电子设备的硬件结构示意图。
该电子设备1600包括但不限于:射频单元1601、网络模块1602、音频输出单元1603、输入单元1604、传感器1605、显示单元1606、用户输入单元1607、接口单元1608、存储器1609、以及处理器1610等部件。其中,上述处理器1610可以是安全协处理器。
本领域技术人员可以理解,电子设备1600还可以包括给各个部件供电的电源(比如电池),电源可以通过电源管理系统与处理器1610逻辑相连,从而通过电源管理系统实现管理充电、放电、以及功耗管理等功能。图16中示出的电子设备结构并不构成对电子设备的限定,电子设备可以包括比图示更多或更少的部件,或者组合某些部件,或者不同的部件布置,在此不再赘述。
其中,处理器1610,用于在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备 的富执行环境REE的安全状态信息或者所述REE的安全评估结果;采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
射频单元1601,用于将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
可选地,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
可选地,所述电子设备的根密钥由所述安全协处理器生成。
可选地,所述电子设备的公私密钥对由所述安全协处理器生成;
其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
可选地,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
可选地,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;
其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
可选地,所述处理器1610,还用于所述根据所述第一安全信息确定目标安全评估结果之前,获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
所述处理器1610具体用于:
在所述目标验证结果指示所述电子设备为安全的设备的情况下,通过所述安全协处理器根据所述第一安全信息确定目标安全评估结果。
可选地,所述射频单元1601,还用于在所述目标验证结果指示所述电子设备为不安全的设备的情况下,向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安全的设备或者对所述电子设备的安全评估失败。
可选地,所述处理器1610具体用于:
向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
可选地,所述处理器1610还用于:
所述向管理服务器发送验证请求之前,查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;
在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,将处于有效期内的所述电子设备的验证结果确定为目标验证结果;
在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,向管理服务器发送验证请求。
可选地,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
可选地,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
可选地,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;
所述处理器1610具体用于:
根据所述TEE的安全状态信息对所述TEE进行安全评估,得到所述TEE的安全评估结果;
根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
可选地,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
应理解的是,本申请实施例中,输入单元1604可以包括图形处理器(Graphics Processing Unit,GPU)16041和麦克风16042,图形处理器16041对在视频捕获模式或图像捕获模式中由图像捕获装置(如摄像头)获得的静态图片或视频的图像数据进行处理。显示单元1606可包括显示面板16061,可以采用液晶显示器、有机发光二极管等形式来配置显示面板16061。用户输入单元1607包括触控面板16071以及其他输入设备16072中的至少一种。触控面板16071,也称为触摸屏。触控面板16071可包括触摸检测装置和触摸控制器两个部分。其他输入设备16072可以包括但不限于物理键盘、功能键(比如音量控制按键、开关按键等)、轨迹球、鼠标、操作杆,在此不再赘述。
存储器1609可用于存储软件程序以及各种数据。存储器1609可主要包括存储程序或指令的第一存储区和存储数据的第二存储区,其中,第一存储区可存储操作系统、至少一个功能所需的应用程序或指令(比如声音播放功能、图像播放功能等)等。此外,存储器1609可以包括易失性存储器或非易失性存储器,或者,存储器1609可以包括易失性和非易失性存储器两者。其中,非易失性存储器可以是只读存储器(Read-Only  Memory,ROM)、可编程只读存储器(Programmable ROM,PROM)、可擦除可编程只读存储器(Erasable PROM,EPROM)、电可擦除可编程只读存储器(Electrically EPROM,EEPROM)或闪存。易失性存储器可以是随机存取存储器(Random Access Memory,RAM),静态随机存取存储器(Static RAM,SRAM)、动态随机存取存储器(Dynamic RAM,DRAM)、同步动态随机存取存储器(Synchronous DRAM,SDRAM)、双倍数据速率同步动态随机存取存储器(Double Data Rate SDRAM,DDRSDRAM)、增强型同步动态随机存取存储器(Enhanced SDRAM,ESDRAM)、同步连接动态随机存取存储器(Synch link DRAM,SLDRAM)和直接内存总线随机存取存储器(Direct Rambus RAM,DRRAM)。本申请实施例中的存储器1609包括但不限于这些和任意其它适合类型的存储器。
处理器1610可包括一个或多个处理单元;可选的,处理器1610集成应用处理器和调制解调处理器,其中,应用处理器主要处理涉及操作系统、用户界面和应用程序等的操作,调制解调处理器主要处理无线通信信号,如基带处理器。可以理解的是,上述调制解调处理器也可以不集成到处理器1610中。
本申请实施例还提供一种可读存储介质,所述可读存储介质上存储有程序或指令,该程序或指令被处理器执行时实现上述安全评估方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
其中,所述处理器为上述实施例中所述的电子设备中的处理器。所述可读存储介质,包括计算机可读存储介质,如计算机只读存储器ROM、随机存取存储器RAM、磁碟或者光盘等。
可选的,如图17所示,本申请实施例还提供一种服务器1700,包括处理器1701和存储器1702,存储器1702上存储有可在所述处理器1701上运行的程序或指令,该程序或指令被处理器1701执行时实现上述应用服务器侧业务处理方法实施例的各个步骤,或者实现上述管理服务器侧安全信息传输方法实施例的各个步骤,且能达到相同的技术效果,为避免重复,这里不再赘述。
本申请实施例另提供了一种芯片,所述芯片包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现上述安全评估方法实施例的各个过程,或者,实现上述业务处理方法实施例的各个过程,或者,实现上述安全信息传输方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
应理解,本申请实施例提到的芯片还可以称为系统级芯片、系统芯片、芯片系统或片上系统芯片等。
本申请实施例提供一种计算机程序产品,该程序产品被存储在存储介质中,该程序产品被至少一个处理器执行以实现如上述安全评估方法实施例的各个过程,或者, 实现上述业务处理方法实施例的各个过程,或者,实现上述安全信息传输方法实施例的各个过程,且能达到相同的技术效果,为避免重复,这里不再赘述。
需要说明的是,在本文中,术语“包括”、“包含”或者其任何其他变体意在涵盖非排他性的包含,从而使得包括一系列要素的过程、方法、物品或者装置不仅包括那些要素,而且还包括没有明确列出的其他要素,或者是还包括为这种过程、方法、物品或者装置所固有的要素。在没有更多限制的情况下,由语句“包括一个……”限定的要素,并不排除在包括该要素的过程、方法、物品或者装置中还存在另外的相同要素。此外,需要指出的是,本申请实施方式中的方法和装置的范围不限按示出或讨论的顺序来执行功能,还可包括根据所涉及的功能按基本同时的方式或按相反的顺序来执行功能,例如,可以按不同于所描述的次序来执行所描述的方法,并且还可以添加、省去、或组合各种步骤。另外,参照某些示例所描述的特征可在其他示例中被组合。
通过以上的实施方式的描述,本领域的技术人员可以清楚地了解到上述实施例方法可借助软件加必需的通用硬件平台的方式来实现,当然也可以通过硬件,但很多情况下前者是更佳的实施方式。基于这样的理解,本申请的技术方案本质上或者说对现有技术做出贡献的部分可以以计算机软件产品的形式体现出来,该计算机软件产品存储在一个存储介质(如ROM/RAM、磁碟、光盘)中,包括若干指令用以使得一台终端(可以是手机,计算机,服务器,或者网络设备等)执行本申请各个实施例所述的方法。
上面结合附图对本申请的实施例进行了描述,但是本申请并不局限于上述的具体实施方式,上述的具体实施方式仅仅是示意性的,而不是限制性的,本领域的普通技术人员在本申请的启示下,在不脱离本申请宗旨和权利要求所保护的范围情况下,还可做出很多形式,均属于本申请的保护之内。

Claims (53)

  1. 一种安全评估方法,所述方法包括:
    在接收到应用服务器发送的安全评估请求的情况下,电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;
    所述电子设备的安全协处理器采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述安全协处理器采用所述电子设备的根密钥对所述电子设备的私钥加密所得到的密文;
    所述电子设备的安全协处理器采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
    所述电子设备将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
  2. 根据权利要求1所述的方法,其中,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
  3. 根据权利要求1所述的方法,其中,所述电子设备的根秘钥由所述安全协处理器生成。
  4. 根据权利要求1所述的方法,其中,所述电子设备的公私密钥对由所述安全协处理器生成;
    其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
  5. 根据权利要求1所述的方法,其中,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
    其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
  6. 根据权利要求5所述的方法,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;
    其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
  7. 根据权利要求1至6中任一项所述的方法,其中,所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果之前,所述方法还包括:
    所述电子设备获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
    所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果,包括:
    在所述目标验证结果指示所述电子设备为安全的设备的情况下,所述电子设备的安全协处理器根据第一安全信息确定目标安全评估结果。
  8. 根据权利要求7所述的方法,其中,所述方法还包括:
    在所述目标验证结果指示所述电子设备为不安全的设备的情况下,所述电子设备向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设备为不安全的设备或者对所述电子设备的安全评估失败。
  9. 根据权利要求7所述的方法,其中,所述电子设备获取所述电子设备的目标验证结果,包括:
    所述电子设备向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
    所述电子设备接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
  10. 根据权利要求9所述的方法,其中,所述电子设备向管理服务器发送验证请求之前,所述方法还包括:
    所述电子设备查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;
    在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备将处于有效期内的所述电子设备的验证结果确定为目标验证结果;
    所述向管理服务器发送验证请求,包括:
    在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,所述电子设备向管理服务器发送验证请求。
  11. 根据权利要求10所述的方法,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
  12. 根据权利要求1至6中任一项所述的方法,其中,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
  13. 根据权利要求12所述的方法,其中,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;
    所述电子设备的安全协处理器根据所述第一安全信息确定目标安全评估结果,包括:
    所述电子设备的安全协处理器根据所述TEE的安全状态信息对所述TEE进行安全 评估,得到所述TEE的安全评估结果;
    所述电子设备的安全协处理器根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
  14. 根据权利要求13所述的方法,其中,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
  15. 一种业务处理方法,所述方法包括:
    应用服务器向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
    所述应用服务器从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
    所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
  16. 根据权利要求15所述的方法,其中,所述应用服务器根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,包括:
    所述应用服务器根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
    在所述管理服务器的数字证书通过验证的情况下,所述应用服务器根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;
    在所述电子设备的数字证书通过验证的情况下,所述应用服务器根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;
    在所述目标安全评估结果的签名通过验证的情况下,所述应用服务器根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
  17. 根据权利要求16所述的方法,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
  18. 根据权利要求16所述的方法,其中,所述应用服务器根据第一数字证书对所述 管理服务器的数字证书进行验证之前,所述方法还包括:
    所述应用服务器根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;
    所述应用服务器根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
  19. 一种安全信息传输方法,所述方法包括:
    管理服务器生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
    所述管理服务器向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
  20. 根据权利要求19所述的方法,其中,所述第二数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
  21. 根据权利要求19或20所述的方法,其中,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
  22. 根据权利要求19或20所述的方法,其中,所述方法还包括:
    所述管理服务器接收所述电子设备发送的验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
    所述管理服务器根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;
    所述管理服务器向所述电子设备发送所述验证结果。
  23. 根据权利要求22所述的方法,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
  24. 一种安全评估装置,应用于电子设备,所述装置包括:
    第一确定模块,用于在接收到应用服务器发送的安全评估请求的情况下,根据第一安全信息确定目标安全评估结果,其中,所述第一安全信息包括所述电子设备的富执行环境REE的安全状态信息或者所述REE的安全评估结果;
    解密模块,用于采用所述电子设备的根密钥对第一密文进行解密,得到所述电子设备的私钥,所述第一密文为所述电子设备的安全协处理器采用所述电子设备的根密 钥对所述电子设备的私钥加密所得到的密文;
    签名模块,用于采用所述电子设备的私钥对所述目标安全评估结果进行签名,得到所述目标安全评估结果的签名;
    第一发送模块,用于将第二安全信息发送给所述应用服务器,其中,所述第二安全信息包括所述目标安全评估结果和所述目标安全评估结果的签名。
  25. 根据权利要求24所述的装置,其中,所述根密钥存储于所述电子设备的一次性可编程OTP存储器。
  26. 根据权利要求24所述的装置,其中,所述电子设备的根秘钥由所述安全协处理器生成。
  27. 根据权利要求24所述的装置,其中,所述电子设备的公私密钥对由所述安全协处理器生成;
    其中,所述电子设备的公私密钥对包括所述电子设备的私钥和所述电子设备的私钥对应的公钥。
  28. 根据权利要求24所述的装置,其中,所述第二安全信息还包括第一数字证书信息,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识;
    其中,所述电子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到。
  29. 根据权利要求28所述的装置,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识;
    其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书。
  30. 根据权利要求24至29中任一项所述的装置,其中,所述装置还包括:
    第一获取模块,用于所述根据所述第一安全信息确定目标安全评估结果之前,获取所述电子设备的目标验证结果,其中,所述目标验证结果为管理服务器对所述电子设备的安全性进行验证所得到的验证结果;
    所述第一确定模块具体用于:
    在所述目标验证结果指示所述电子设备为安全的设备的情况下,根据所述第一安全信息确定目标安全评估结果。
  31. 根据权利要求30所述的装置,其中,所述装置还包括:
    第二发送模块,用于在所述目标验证结果指示所述电子设备为不安全的设备的情况下,向所述应用服务器发送第一指示信息,所述第一指示信息用于指示所述电子设 备为不安全的设备或者对所述电子设备的安全评估失败。
  32. 根据权利要求30所述的装置,其中,所述第一获取模块具体用于:
    向管理服务器发送验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
    接收所述管理服务器发送的验证结果,其中,所述目标验证结果为所述管理服务器发送的验证结果。
  33. 根据权利要求32所述的装置,其中,所述装置还包括:
    查询模块,用于在所述向管理服务器发送验证请求之前,查询所述电子设备内是否存在处于有效期内的所述电子设备的验证结果;
    第二确定模块,用于在所述电子设备内存在处于有效期内的所述电子设备的验证结果的情况下,将处于有效期内的所述电子设备的验证结果确定为目标验证结果;
    所述第一获取模块具体用于:
    在所述电子设备内不存在处于有效期内的所述电子设备的验证结果的情况下,向管理服务器发送验证请求。
  34. 根据权利要求33所述的装置,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
  35. 根据权利要求24至29中任一项所述的装置,其中,所述第一安全信息还包括所述电子设备的可信执行环境TEE的安全状态信息或者所述TEE的安全评估结果。
  36. 根据权利要求35所述的装置,其中,所述第一安全信息包括所述REE的安全评估结果和所述TEE的安全状态信息;
    所述第一确定模块具体用于:
    根据所述TEE的安全状态信息对所述TEE进行安全评估,得到所述TEE的安全评估结果;
    根据所述TEE的安全评估结果和所述REE的安全评估结果确定目标安全评估结果。
  37. 根据权利要求36所述的装置,其中,所述REE的安全评估结果为所述TEE基于所述REE的安全状态信息进行安全评估所得到的安全评估结果。
  38. 一种业务处理装置,应用于应用服务器,所述装置包括:
    第三发送模块,用于向电子设备发送安全评估请求,所述安全评估请求用于请求评估所述电子设备的安全性;
    第一接收模块,用于从所述电子设备接收第二安全信息,其中,所述第二安全信息包括目标安全评估结果、所述目标安全评估结果的签名和第一数字证书信息,所述目标安全评估结果用于指示所述电子设备的富执行环境REE的安全性,所述第一数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识,所述电 子设备的数字证书为采用管理服务器的私钥对所述电子设备的公钥进行签名得到;
    第三确定模块,用于根据所述第二安全信息确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务,其中,所述目标业务为所述应用服务器向所述电子设备提供的业务。
  39. 根据权利要求38所述的装置,其中,所述第三确定模块具体用于:
    根据所述管理服务器的数字证书中的公钥或者目标数字证书对所述管理服务器的数字证书进行验证,其中,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用所述目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
    在所述管理服务器的数字证书通过验证的情况下,根据所述管理服务器的数字证书对所述电子设备的数字证书进行验证;
    在所述电子设备的数字证书通过验证的情况下,根据所述电子设备的数字证书对所述目标安全评估结果的签名进行验证;
    在所述目标安全评估结果的签名通过验证的情况下,根据所述目标安全评估结果确定允许所述电子设备接入目标业务或者不允许所述电子设备接入目标业务。
  40. 根据权利要求39所述的装置,其中,所述第一数字证书信息还包括所述管理服务器的数字证书或者所述管理服务器的数字证书的标识。
  41. 根据权利要求39所述的装置,其中,所述装置还包括:
    第四确定模块,用于所述根据第一数字证书对所述管理服务器的数字证书进行验证之前,根据所述电子设备的数字证书确定所述管理服务器的数字证书的标识;
    第二获取模块,用于根据所述管理服务器的数字证书的标识获取所述管理服务器的数字证书。
  42. 一种安全信息传输装置,应用于管理服务器,所述装置包括:
    生成模块,用于生成数字证书,其中,所述数字证书包括电子设备的数字证书和所述管理服务器的数字证书,所述电子设备的数字证书为采用所述管理服务器的私钥对所述电子设备的公钥进行签名得到,所述管理服务器的数字证书为采用所述管理服务器的私钥对所述管理服务器的公钥进行签名得到,或者为采用目标数字证书的公钥对应的私钥对所述管理服务器的公钥进行签名得到,所述目标数字证书为在所述管理服务器的数字证书所属的数字证书链中位于所述管理服务器的数字证书上一级的数字证书;
    第四发送模块,用于向所述电子设备发送第二数字证书信息,其中,所述第二数字证书信息包括所述电子设备的数字证书或者所述电子设备的数字证书的标识。
  43. 根据权利要求42所述的装置,其中,所述第二数字证书信息还包括所述管理服 务器的数字证书或者所述管理服务器的数字证书的标识。
  44. 根据权利要求42或43所述的装置,其中,所述管理服务器的私钥存储于所述管理服务器的硬件安全模块HSM。
  45. 根据权利要求42或43所述的装置,其中,所述装置还包括:
    第二接收模块,用于接收所述电子设备发送的验证请求,其中,所述验证请求用于请求验证所述电子设备的安全性,所述验证请求包括所述电子设备的安全验证相关参数;
    验证模块,用于根据所述电子设备的安全验证相关参数对所述电子设备的安全性进行验证,得到验证结果,其中,所述验证结果用于指示所述电子设备为安全的设备或者不安全的设备;
    第五发送模块,用于向所述电子设备发送所述验证结果。
  46. 根据权利要求45所述的装置,其中,所述电子设备的安全验证相关参数包括如下至少一项:设备指纹,硬件配置参数,固件配置参数,固件版本,系统配置参数,系统版本。
  47. 一种电子设备,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求1-14中任一项所述的安全评估方法的步骤。
  48. 一种管理服务器,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求15-18中任一项所述的安全评估方法的步骤。
  49. 一种应用服务器,包括处理器和存储器,所述存储器存储可在所述处理器上运行的程序或指令,所述程序或指令被所述处理器执行时实现如权利要求19-23中任一项所述的安全评估方法的步骤。
  50. 一种可读存储介质,所述可读存储介质上存储程序或指令,所述程序或指令被处理器执行时实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
  51. 一种电子设备,包括所述电子设备被配置用于执行如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
  52. 一种芯片,包括处理器和通信接口,所述通信接口和所述处理器耦合,所述处理器用于运行程序或指令,实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
  53. 一种计算机程序产品,所述计算机程序产品被存储在非瞬态存储介质中,所述计算机程序产品被至少一个处理器执行以实现如权利要求1-14中任一项所述的安全评估方法的步骤,或者实现如权利要求15-18中任一项所述的安全评估方法的步骤,或者实现如权利要求19-23中任一项所述的安全评估方法的步骤。
PCT/CN2024/098430 2023-06-15 2024-06-11 安全评估、业务处理、安全信息传输方法及相关设备 Ceased WO2024255732A1 (zh)

Priority Applications (2)

Application Number Priority Date Filing Date Title
EP24822682.1A EP4730704A1 (en) 2023-06-15 2024-06-11 Security evaluation method, service processing method, security information transmission method and related device
US19/413,120 US20260095321A1 (en) 2023-06-15 2025-12-09 Security evaluation method, service processing method, security information transmission method, and related device

Applications Claiming Priority (2)

Application Number Priority Date Filing Date Title
CN202310715581.6A CN116633661B (zh) 2023-06-15 2023-06-15 安全评估、业务处理、安全信息传输方法及相关设备
CN202310715581.6 2023-06-15

Related Child Applications (1)

Application Number Title Priority Date Filing Date
US19/413,120 Continuation US20260095321A1 (en) 2023-06-15 2025-12-09 Security evaluation method, service processing method, security information transmission method, and related device

Publications (1)

Publication Number Publication Date
WO2024255732A1 true WO2024255732A1 (zh) 2024-12-19

Family

ID=87638212

Family Applications (1)

Application Number Title Priority Date Filing Date
PCT/CN2024/098430 Ceased WO2024255732A1 (zh) 2023-06-15 2024-06-11 安全评估、业务处理、安全信息传输方法及相关设备

Country Status (4)

Country Link
US (1) US20260095321A1 (zh)
EP (1) EP4730704A1 (zh)
CN (1) CN116633661B (zh)
WO (1) WO2024255732A1 (zh)

Families Citing this family (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN116633661B (zh) * 2023-06-15 2026-02-24 维沃移动通信有限公司 安全评估、业务处理、安全信息传输方法及相关设备
CN118488119A (zh) * 2024-05-09 2024-08-13 维沃移动通信有限公司 信息传输方法、装置、管理服务器、电子设备及应用服务器
CN118694867A (zh) * 2024-06-21 2024-09-24 维沃移动通信有限公司 图像信息安全传输方法、装置、电子设备及服务器

Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110213039A (zh) * 2018-02-28 2019-09-06 华为技术有限公司 一种管理方法、终端和服务器
CN110838919A (zh) * 2019-11-01 2020-02-25 广州小鹏汽车科技有限公司 通信方法、存储方法、运算方法及装置
WO2020177116A1 (zh) * 2019-03-07 2020-09-10 华为技术有限公司 仿冒app识别方法及装置
CN114245375A (zh) * 2020-09-09 2022-03-25 华为技术有限公司 一种密钥跨设备分发方法及电子设备
CN114598541A (zh) * 2022-03-18 2022-06-07 维沃移动通信有限公司 一种安全评估方法及装置、电子设备和可读存储介质
CN115706993A (zh) * 2021-08-03 2023-02-17 华为技术有限公司 认证方法、可读介质和电子设备
CN116633661A (zh) * 2023-06-15 2023-08-22 维沃移动通信有限公司 安全评估、业务处理、安全信息传输方法及相关设备

Family Cites Families (3)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN108768664B (zh) * 2018-06-06 2020-11-03 腾讯科技(深圳)有限公司 密钥管理方法、装置、系统、存储介质和计算机设备
US11223485B2 (en) * 2018-07-17 2022-01-11 Huawei Technologies Co., Ltd. Verifiable encryption based on trusted execution environment
US11706199B2 (en) * 2019-08-06 2023-07-18 Samsung Electronics Co., Ltd Electronic device and method for generating attestation certificate based on fused key

Patent Citations (7)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
CN110213039A (zh) * 2018-02-28 2019-09-06 华为技术有限公司 一种管理方法、终端和服务器
WO2020177116A1 (zh) * 2019-03-07 2020-09-10 华为技术有限公司 仿冒app识别方法及装置
CN110838919A (zh) * 2019-11-01 2020-02-25 广州小鹏汽车科技有限公司 通信方法、存储方法、运算方法及装置
CN114245375A (zh) * 2020-09-09 2022-03-25 华为技术有限公司 一种密钥跨设备分发方法及电子设备
CN115706993A (zh) * 2021-08-03 2023-02-17 华为技术有限公司 认证方法、可读介质和电子设备
CN114598541A (zh) * 2022-03-18 2022-06-07 维沃移动通信有限公司 一种安全评估方法及装置、电子设备和可读存储介质
CN116633661A (zh) * 2023-06-15 2023-08-22 维沃移动通信有限公司 安全评估、业务处理、安全信息传输方法及相关设备

Also Published As

Publication number Publication date
EP4730704A1 (en) 2026-04-22
CN116633661A (zh) 2023-08-22
US20260095321A1 (en) 2026-04-02
CN116633661B (zh) 2026-02-24

Similar Documents

Publication Publication Date Title
CN109361668B (zh) 一种数据可信传输方法
US10601795B2 (en) Service processing method and electronic device
US10530753B2 (en) System and method for secure cloud computing
US20240388453A1 (en) Key management and service processing
CN114598541B (zh) 一种安全评估方法及装置、电子设备和可读存储介质
US8127146B2 (en) Transparent trust validation of an unknown platform
US10270776B2 (en) Secure zone for secure transactions
WO2024255732A1 (zh) 安全评估、业务处理、安全信息传输方法及相关设备
US20050283826A1 (en) Systems and methods for performing secure communications between an authorized computing platform and a hardware component
WO2019218919A1 (zh) 区块链场景下的私钥管理方法、装置及系统
CN105718807B (zh) 基于软tcm和可信软件栈的安卓系统及其可信认证系统与方法
US20250168017A1 (en) Method, apparatus, device and storage medium for device authentication and checking
US20040010686A1 (en) Apparatus for remote working
CN108200078B (zh) 签名认证工具的下载安装方法及终端设备
CN108335105B (zh) 数据处理方法及相关设备
EP4018403A1 (en) Authenticator app for consent architecture
WO2025232741A1 (zh) 信息传输方法、装置、管理服务器、电子设备及应用服务器
WO2023284691A1 (zh) 一种账户的开立方法、系统及装置
TW201539239A (zh) 伺服器、用戶設備以及用戶設備與伺服器的交互方法
JP2018117185A (ja) 情報処理装置、情報処理方法
CN117792767A (zh) 通信方法、相关装置及存储介质
US20250286729A1 (en) Data processing method and apparatus based on trusted execution environment, device, and medium
WO2026007926A1 (zh) 数据共享方法及相关设备
WO2025227758A1 (zh) 数据共享方法、设备及系统
Kim et al. Secure user authentication based on the trusted platform for mobile devices

Legal Events

Date Code Title Description
121 Ep: the epo has been informed by wipo that ep was designated in this application

Ref document number: 24822682

Country of ref document: EP

Kind code of ref document: A1

WWE Wipo information: entry into national phase

Ref document number: 2024822682

Country of ref document: EP

NENP Non-entry into the national phase

Ref country code: DE

ENP Entry into the national phase

Ref document number: 2024822682

Country of ref document: EP

Effective date: 20260115

ENP Entry into the national phase

Ref document number: 2024822682

Country of ref document: EP

Effective date: 20260115

ENP Entry into the national phase

Ref document number: 2024822682

Country of ref document: EP

Effective date: 20260115

ENP Entry into the national phase

Ref document number: 2024822682

Country of ref document: EP

Effective date: 20260115

WWP Wipo information: published in national office

Ref document number: 2024822682

Country of ref document: EP