IP Library Granted Patent US 12,052,356
Granted Patent B2
US 12,052,356 · App. 17/481,131 · Granted Jul 30, 2024

Method and apparatus for data storage and verification

Inventor: Caidi Wu (Shanghai, CN)
Assignee: Alibaba Group Holding Limited
H04L9/088G06F21/53
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,052,356
App. No.
17/481,131
Granted
Jul 30, 2024
Kind
B2
Abstract

Disclosed are data storage and verification methods and a device executable in a trusted execution environment. The data storage method comprises: encrypting, using a first key, user data and version information of the user data to generate first ciphertext, and storing the first ciphertext into a general storage space (S 310 ); generating verification information of the user data (S 320 ); and storing the version information and the verification information into a secure storage space (S 330 ). The present disclosure effectively prevents version rollback of user data.

Claims (39)

1. A method comprising:

encrypting, using a first key, user data and version information of the user data to generate a first ciphertext;

storing the first ciphertext into a general storage space;

generating verification information of the user data; and

storing the version information and the verification information into a secure storage space, the storing the version information and the verification information into the secure storage space comprising storing, by using a memory driver in a rich execution environment, the version information and the verification information into the secure storage space, the storing, by using the memory driver in the rich execution environment, the version information and the verification information into the secure storage space comprising:

combining the version information and the verification information into a data frame compliant with a write verification format of the secure storage space, the data frame comprising the version information, the verification information, a write count value, and a signature value, and the signature value being ciphertext obtained by encrypting, using a second key, the version information, the verification information, and the write count value; and

after the memory driver determines, according to the write count value and the signature value, that a current write operation is legitimate, storing the version information and the verification information into the secure storage space.

2. The method of claim 1 , further comprising using a preset mapping algorithm to map the user data to obtain a mapping value.

3. The method of claim 2 , wherein the verification information is the mapping value.

4. The method of claim 1 , further comprising dynamically generating the first key in a trusted execution environment.

5. The method of claim 1 , wherein the general storage space comprises a user data partition of an embedded memory card.

6. The method of claim 5 , wherein the secure storage space comprises a secure partition of the embedded memory card.

7. The method of claim 1 , further comprising recording the second key in a trusted execution environment.

8. A computing device comprising:

one or more processors; and

one or more memories storing thereon computer-readable instructions that, when executed by the one or more processors, cause the one or more processors to perform acts comprising:

acquiring a first ciphertext from a general storage space;

decrypting the first ciphertext to obtain user data and first version information;

computing first verification information of the user data;

acquiring, from a secure storage space, second version information and second verification information, wherein the secure storage spaces stores the second version information and the second verification information by using a memory driver in a rich execution environment, the second version information and the second verification information are combined into a data frame compliant with a write verification format of the secure storage space, the data frame comprising the second version information, the second verification information, a write count value, and a signature value, and the signature value is a ciphertext obtained by encrypting, using a key, the second version information, the second verification information, and the write count value; and

in response to determining that the first version information obtained by decrypting the first ciphertext is the same as the second version information acquired from the secure storage space, and the computed first verification information is the same as the second verification information acquired from the secure storage space, determining the user data and the first version information as secure.

9. The computing device of claim 8 , wherein the computing the first verification information of the user data comprises:

mapping, using a preset mapping algorithm, the user data to obtain the first verification information.

10. The computing device of claim 8 , wherein the general storage space comprises a user data partition of an embedded memory card.

11. The computing device of claim 10 , wherein the secure storage space comprises a secure partition of the embedded memory card.

12. One or more memories storing thereon computer-readable instructions that, when executed by one or more processors, cause the one or more processors to perform acts comprising:

encrypting, using a first key, user data and version information of the user data to generate a first ciphertext;

storing the first ciphertext into a general storage space;

generating verification information of the user data; and

storing the version information and the verification information into a secure storage space, the storing the version information and the verification information into the secure storage space comprising storing, by using a memory driver in a rich execution environment, the version information and the verification information into the secure storage space, the storing, by using the memory driver in the rich execution environment, the version information and the verification information into the secure storage space comprising:

combining the version information and the verification information into a data frame compliant with a write verification format of the secure storage space, the data frame comprising the version information, the verification information, a write count value, and a signature value, and the signature value being ciphertext obtained by encrypting, using a second key, the version information, the verification information, and the write count value; and

after the memory driver determines, according to the write count value and the signature value, that a current write operation is legitimate, storing the version information and the verification information into the secure storage space.

13. The one or more memories of claim 12 , wherein the acts further comprise using a preset mapping algorithm to map the user data to obtain a mapping value as the verification information.

14. The one or more memories of claim 12 , wherein the acts further comprise dynamically generating the first key in a trusted execution environment.

15. The one or more memories of claim 12 , wherein:

the general storage space comprises a user data partition of an embedded memory card; and

the secure storage space comprises a secure partition of the embedded memory card.

16. The one or more memories of claim 12 , wherein the acts further comprise recording the second key in a trusted execution environment.

17. The one or more memories of claim 13 , wherein the verification information is the mapping value.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 29, 2026
From: ALIBABA GROUP HOLDING LIMITED
To: CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PRIVATE LIMITED
Reel/Frame 075499/0384 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: WU, CAIDI
To: ALIBABA GROUP HOLDING LIMITED
Reel/Frame 059139/0370 →
Priority Claims (1)
CN 201910221335.9 · Mar 22, 2019 · national
Continuity (2)
Continuation PCTCN2020078528 · Mar 10, 2020
Related Publication 20220006617A1 · Jan 6, 2022