Resource management method, computing device, computing equipment, and readable storage medium
A resource management method suitable for a security architecture system including a secure element subsystem. The security architecture system is configured with N chip lifecycle states, N being an integer greater than 1, the secure element subsystem stores a plurality of resources, an access authority of the resources being associated with the N chip lifecycle states. The method includes performing access control on a resource based on a current chip lifecycle state of the security architecture system, the current chip lifecycle state of the security architecture system belonging to one of the N chip lifecycle states.
1 . A resource management method implemented by a security architecture system including a secure element subsystem storing at least an important resource, the security architecture system being configured with N chip lifecycle states including at least a chip manufacturing state, a chip manufacturing return state, a device manufacturing state, a device manufacturing return state, and a user management state, N being an integer greater than 1, an access authority of accessing the important resource being associated with each of the N chip lifecycle states respectively, the method comprising:
based on a current chip lifecycle state of the security architecture system, assigning an access authority for accessing the secure element subsystem to each of M debugging interfaces for testing and debugging a chip, M being an integer greater than 1;
obtaining a switching instruction for switching the current chip lifecycle state of the security architecture system; and
performing switching authority verification for the switching instruction, and determining whether to perform state switching based on a result of the switching authority verification;
wherein:
in response to the current chip lifecycle state being the chip manufacturing state or the chip manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem;
in response to the current chip lifecycle state being the device manufacturing state or the device manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem except for a chip manufacturer root key stored in the secure element subsystem; and
in response to the current chip lifecycle state being the user management state, the access authority assigned to each of M debug interface denies any of the M debugging interfaces to access the secure element subsystem.
2 . The method of claim 1 , further comprising:
obtaining an access instruction for the important resource, and determining whether to allow access to the important resource based on whether an access authority of the access instruction for the important resource matches the current chip lifecycle state of the security architecture system.
3 . The method of claim 2 , wherein:
the security architecture system includes the M debugging interfaces, each debugging interface being used to access resources stored in the secure element subsystem, M being an integer greater than or equal to 1; and
obtaining the access instruction for the important resource includes:
obtaining the access instruction for the important resource from a debugging interface belonging to one of the M hardware debugging interfaces, the debugging interface belonging to one of the M hardware debugging interfaces being a current debugging interface.
4 . The method of claim 1 , further comprising:
for each of the five chip lifecycle states, setting an address range of resources in the secure element subsystem allowed to be accessed, respectively;
in response to the address range of the resources in the secure element subsystem allowed to be accessed being accessed in the current chip lifecycle state, allowing the resources to be accessed; and
in response to the access range of the resources in the secure element subsystem not allowed to be accessed being accessed in the current chip lifecycle state, denying the resources to be accessed.
5 . The method of claim 1 , further comprising:
for each of the N chip lifecycle states, setting the important resource in the secure element subsystem allowed to be accessed, respectively;
in response to the important resource in the secure element subsystem allowed to be accessed being accessed in the current chip lifecycle state, allowing the important resource to be accessed; and
in response to the important resource in the secure element subsystem not allowed to be accessed being accessed in the current chip lifecycle state, denying the important resource to be accessed.
6 . The method of claim 1 , wherein the important resource includes a plurality of root keys, the method further comprising:
obtaining a key derivation request from a rich execution environment subsystem or a trusted execution environment subsystem in the security architecture system, the key derivation request including key identifier information for requesting the secure element subsystem to perform key derivation using a root key corresponding to the key identifier information in the plurality of root keys;
determining whether the key derivation request is allowed in the current chip lifecycle state;
in response to the key derivation request being allowed in the current chip lifecycle state, performing the key derivation using the root key corresponding to the key identifier information; and
in response to the key derivation request not being allowed in the current chip lifecycle state, not performing the key derivation using the root key corresponding to the key identifier information.
7 . The method of claim 1 , wherein:
the current chip lifecycle state of the security architecture system is recorded by programming a one-time memory for the current chip lifecycle state of the security architecture system to switch sequentially in the order of the chip manufacturing state, the device manufacturing state, the user management state, the chip manufacturing return state, and the device manufacturing return state.
8 . A computing device configured with a security architecture system including a secure element subsystem storing at least an important resource, the security architecture system being configured with N chip lifecycle states including at least a chip manufacturing state, a chip manufacturing return state, a device manufacturing state, a device manufacturing return state, and a user management state, N being an integer greater than 1, an access authority of accessing the important resource being associated with each of the N chip lifecycle states respectively, the computing device comprising:
a memory storing program instructions;
a receiver configured to obtain a switching instruction for switching a current chip lifecycle state of the security architecture system; and
a processor coupled to the memory, when being executed by the processor, the program instructions causing the processor to:
based on the current chip lifecycle state of the security architecture system, assign an access authority for accessing the secure element subsystem to each of M debugging interfaces for testing and debugging a chip, M being an integer greater than 1; and
perform switching authority verification for the switching instruction, and determine whether to perform state switching based on a result of the switching authority verification;
wherein:
in response to the current chip lifecycle state being the chip manufacturing state or the chip manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem;
in response to the current chip lifecycle state being the device manufacturing state or the device manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem except for a chip manufacturer root key stored in the secure element subsystem; and
in response to the current chip lifecycle state being the user management state, the access authority assigned to each of M debug interface denies any of the M debugging interfaces to access the secure element subsystem.
9 . The computing device of claim 8 further comprising:
a receiver, the receiving unit being configured to obtain an access instruction for the important resource, wherein the processor is configured to:
determine whether to allow access to the important resource based on whether an access authority of the access instruction for the important resource matches the current chip lifecycle state of the security architecture system.
10 . The computing device of claim 9 , wherein:
the security architecture system includes M debugging interfaces, each debugging interface being used to access resources stored in the secure element subsystem, M being an integer greater than or equal to 1; and
the receiver is further configured to:
obtain the access instruction for the important resource from a debugging interface belonging to one of the M debugging interfaces, the debugging interface belonging to one of the M debugging interfaces being a current debugging interface.
11 . The computing device of claim 8 , wherein the processor is further configured to:
for each of the five chip lifecycle states, set an address range of resources in the secure element subsystem allowed to be accessed, respectively;
in response to the address range of the resources in the secure element subsystem allowed to be accessed being accessed in the current chip lifecycle state, allow the resources to be accessed; and
in response to the access range of the resources in the secure element subsystem not allowed to be accessed being accessed in the current chip lifecycle state, deny the resources to be accessed.
12 . The computing device of claim 8 , wherein the processor is further configured to:
for each of the N chip lifecycle states, set the important resource in the secure element subsystem allowed to be accessed, respectively;
in response to the important resource in the secure element subsystem allowed to be accessed being accessed in the current chip lifecycle state, allow the important resource to be accessed; and
in response to the important resource in the secure element subsystem not allowed to be accessed being accessed in the current chip lifecycle state, deny the important resource to be accessed.
13 . The computing device of claim 12 , wherein the important resource includes a plurality of root keys, and the processor is further configured to:
obtain a key derivation request from a rich execution environment subsystem or a trusted execution environment subsystem in the security architecture system, the key derivation request including key identifier information for requesting the secure element subsystem to perform key derivation using a root key corresponding to the key identifier information in the plurality of root keys;
determine whether the key derivation request is allowed in the current chip lifecycle state;
in response to the key derivation request being allowed in the current chip lifecycle state, perform the key derivation using the root key corresponding to the key identifier information; and
in response to the key derivation request not being allowed in the current chip lifecycle state, not perform the key derivation using the root key corresponding to the key identifier information.
14 . The computing device of claim 8 , wherein:
the current chip lifecycle state of the security architecture system is recorded by programming a one-time memory for the current chip lifecycle state of the security architecture system to switch sequentially in the order of the chip manufacturing state, the device manufacturing state, the user management state, the chip manufacturing return state, and the device manufacturing return state.
15 . A computing equipment, including a security architecture system including a secure element subsystem storing at least an important resource, the security architecture system being configured with N chip lifecycle states including at least a chip manufacturing state, a chip manufacturing return state, a device manufacturing state, a device manufacturing return state, and a user management state, N being an integer greater than 1, an access authority of accessing the important resource being associated with each of the N chip lifecycle states respectively, the computing equipment comprising:
a processor; and
a memory storing computer-readable program instructions that, when being executed by the processor, cause the processor to:
based on a current chip lifecycle state of the security architecture system, assign an access authority for accessing the secure element subsystem to each of M debugging interfaces for testing and debugging a chip, M being an integer greater than 1;
obtain a switching instruction for switching the current chip lifecycle state of the security architecture system; and
perform switching authority verification for the switching instruction, and determine whether to perform state switching based on a result of the switching authority verification;
wherein:
in response to the current chip lifecycle state being the chip manufacturing state or the chip manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem;
in response to the current chip lifecycle state being the device manufacturing state or the device manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem except for a chip manufacturer root key stored in the secure element subsystem; and
in response to the current chip lifecycle state being the user management state, the access authority assigned to each of M debug interface denies any of the M debugging interfaces to access the secure element subsystem.
16 . A non-transitory computer-readable storage medium comprising:
instructions stored in the non-transitory computer-readable storage medium that, when being executed by a processor, cause the processor to perform a resource management method suitable for a security architecture system, the security architecture system including a rich execution environment subsystem, a trusted execution environment subsystem, and a secure element subsystem, wherein the processor is configured to:
based on a current chip lifecycle state of the security architecture system, assign an access authority for accessing the secure element subsystem to each of M debugging interfaces for testing and debugging a chip, M being an integer greater than 1;
obtain a switching instruction for switching the current chip lifecycle state of the security architecture system; and
perform switching authority verification for the switching instruction, and determine whether to perform state switching based on a result of the switching authority verification;
wherein:
in response to the current chip lifecycle state being the chip manufacturing state or the chip manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem;
in response to the current chip lifecycle state being the device manufacturing state or the device manufacturing return state, the access authority assigned to each of the M debug interface allows each of M debugging interfaces to access the secure element subsystem except for a chip manufacturer root key stored in the secure element subsystem; and
in response to the current chip lifecycle state being the user management state, the access authority assigned to each of M debug interface denies any of the M debugging interfaces to access the secure element subsystem.