IP Library Granted Patent US 12705369
Granted Patent B2
US 12705369 · App. 18/336,832 · Granted Aug 11, 2026

Data processing methods, apparatuses, and devices

Inventors: Chao Wu (Hangzhou, CN); Xiaofei Wan (Hangzhou, CN); Zhi Xin (Hangzhou, CN)
Assignee: Alipay (Hangzhou) Information Technology Co., Ltd.
G06F21/602G06F21/57G06F2221/033H04L9/14
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12705369
App. No.
18/336,832
Granted
Aug 11, 2026
Kind
B2
Abstract

Some embodiments of this specification provide data processing methods, apparatuses, and devices. One method includes: receiving encrypted debugging information and an encrypted first key from a client device, determining the device key corresponding to the client device, obtaining the debugging information based on the device key, the encrypted debugging information, and the encrypted first key, and performing abnormality detection on the trusted execution environment of the client device based on the debugging information to determine an abnormality detection result for the trusted execution environment.

Claims (73)

1 . A data processing method performed in a trusted execution environment of a server, the method comprising:

receiving encrypted debugging information and an encrypted first key from a client device, wherein the encrypted debugging information is obtained for a target application by encrypting debugging information generated in a trusted execution environment of the client device and a device identity certificate of the client device based on a first key, wherein the device identity certificate of the client device is generated based on an identifier of the client device, wherein encrypting the debugging information is performed in response to the client device determining that the target application runs abnormally in the trusted execution environment based on a running state of the target application, wherein the encrypted first key is obtained by encrypting the first key based on a device key generated by the server in the trusted execution environment for the client device;

determining the device key corresponding to the client device;

obtaining the debugging information based on the device key, the encrypted debugging information, and the encrypted first key; and

performing abnormality detection on the trusted execution environment of the client device based on the debugging information to determine an abnormality detection result for the trusted execution environment,

wherein before receiving the encrypted debugging information and the encrypted first key, the method further comprising:

establishing a secure channel with the client device based on a same channel establishment rule shared by the server and the client device;

obtaining the identifier of the client device through the secure channel;

generating the device key corresponding to the client device based on the identifier of the client device; and

sending the device key and the device identity certificate of the client device to the client device through the secure channel.

2 . The method according to claim 1 , wherein sending the device key and the device identity certificate of the client device to the client device comprises:

obtaining a channel key predetermined for the client device;

encrypting the device key and the device identity certificate of the client device based on the channel key to obtain target encryption information; and

sending the target encryption information to the client device through the secure channel to trigger the client device to decrypt the target encryption information in the trusted execution environment to obtain the device key and the device identity certificate of the client device.

3 . The method according to claim 2 , wherein obtaining the debugging information comprises:

decrypting the encrypted first key based on the device key to obtain the first key; and

decrypting the encrypted debugging information based on the first key to obtain the debugging information and the device identity certificate; and wherein

performing abnormality detection on the trusted execution environment of the client device comprises:

performing device identity authentication on the client device based on the device identity certificate; and

in response to the device identity authentication being successful, performing the abnormality detection on the trusted execution environment of the client device based on the debugging information.

4 . The method according to claim 3 , wherein the method further comprises:

generating an abnormality solution corresponding to the abnormality detection result based on a predetermined policy generation principle; and

sending the abnormality solution to the client device through the secure channel for triggering the client device to perform abnormality solution processing on the trusted execution environment.

5 . A server comprising:

at least one processor; and

one or more memories coupled to the at least one processor and storing programming instructions for execution by the at least one processor to perform, in a trusted execution environment, operations comprising:

receiving encrypted debugging information and an encrypted first key from a client device, wherein the encrypted debugging information is obtained for a target application by encrypting debugging information generated in a trusted execution environment of the client device and a device identity certificate of the client device based on a first key, wherein the device identity certificate of the client device is generated based on an identifier of the client device, wherein encrypting the debugging information is performed in response to the client device determining that the target application runs abnormally in the trusted execution environment based on a running state of the target application, wherein the encrypted first key is obtained by encrypting the first key based on a device key generated by the server in the trusted execution environment for the client device;

determining the device key corresponding to the client device;

obtaining the debugging information based on the device key, the encrypted debugging information, and the encrypted first key; and

performing abnormality detection on the trusted execution environment of the client device based on the debugging information to determine an abnormality detection result for the trusted execution environment,

wherein before receiving the encrypted debugging information and the encrypted first key, the operations further comprising:

establishing a secure channel with the client device based on a same channel establishment rule shared by the server and the client device;

obtaining the identifier of the client device through the secure channel;

generating the device key corresponding to the client device based on the identifier of the client device; and

sending the device key and the device identity certificate of the client device to the client device through the secure channel.

6 . The server according to claim 5 , wherein sending the device key and the device identity certificate of the client device to the client device comprises:

obtaining a channel key predetermined for the client device;

encrypting the device key and the device identity certificate of the client device based on the channel key to obtain target encryption information; and

sending the target encryption information to the client device through the secure channel to trigger the client device to decrypt the target encryption information in the trusted execution environment to obtain the device key and the device identity certificate of the client device.

7 . The server according to claim 6 , wherein

obtaining the debugging information comprises:

decrypting the encrypted first key based on the device key to obtain the first key; and

decrypting the encrypted debugging information based on the first key to obtain the debugging information and the device identity certificate; and wherein

performing abnormality detection on the trusted execution environment of the client device comprises:

performing device identity authentication on the client device based on the device identity certificate; and

in response to the device identity authentication being successful, performing the abnormality detection on the trusted execution environment of the client device based on the debugging information.

8 . The server according to claim 7 , wherein the operations further comprising:

generating an abnormality solution corresponding to the abnormality detection result based on a predetermined policy generation principle; and

sending the abnormality solution to the client device through the secure channel for triggering the client device to perform abnormality solution processing on the trusted execution environment.

9 . A non-transitory, computer-readable medium storing one or more instructions executable by at least one processor in a trusted execution environment of a server, to perform operations comprising:

receiving encrypted debugging information and an encrypted first key from a client device, wherein the encrypted debugging information is obtained for a target application by encrypting debugging information generated in a trusted execution environment of the client device and a device identity certificate of the client device based on a first key, wherein the device identity certificate of the client device is generated based on an identifier of the client device, wherein encrypting the debugging information is performed in response to the client device determining that the target application runs abnormally in the trusted execution environment based on a running state of the target application, wherein the encrypted first key is obtained by encrypting the first key based on a device key generated by the server in the trusted execution environment for the client device;

determining the device key corresponding to the client device;

obtaining the debugging information based on the device key, the encrypted debugging information, and the encrypted first key; and

performing abnormality detection on the trusted execution environment of the client device based on the debugging information to determine an abnormality detection result for the trusted execution environment,

wherein before receiving the encrypted debugging information and the encrypted first key, the operations further comprising:

establishing a secure channel with the client device based on a same channel establishment rule shared by the server and the client device;

obtaining the identifier of the client device through the secure channel;

generating the device key corresponding to the client device based on the identifier of the client device; and

sending the device key and the device identity certificate of the client device to the client device through the secure channel.

10 . The non-transitory, computer-readable medium according to claim 9 , wherein sending the device key and the device identity certificate of the client device to the client device comprises:

obtaining a channel key predetermined for the client device;

encrypting the device key and the device identity certificate of the client device based on the channel key to obtain target encryption information; and

sending the target encryption information to the client device through the secure channel to trigger the client device to decrypt the target encryption information in the trusted execution environment to obtain the device key and the device identity certificate of the client device.

11 . The non-transitory, computer-readable medium according to claim 10 , wherein

obtaining the debugging information comprises:

decrypting the encrypted first key based on the device key to obtain the first key; and

decrypting the encrypted debugging information based on the first key to obtain the debugging information and the device identity certificate; and wherein

performing abnormality detection on the trusted execution environment of the client device comprises:

performing device identity authentication on the client device based on the device identity certificate; and

in response to the device identity authentication being successful, performing the abnormality detection on the trusted execution environment of the client device based on the debugging information.

12 . The non-transitory, computer-readable medium according to claim 11 , wherein the operations further comprising:

generating an abnormality solution corresponding to the abnormality detection result based on a predetermined policy generation principle; and

sending the abnormality solution to the client device through the secure channel for triggering the client device to perform abnormality solution processing on the trusted execution environment.