Supercharge Your Innovation With Domain-Expert AI Agents!

Object memory credibility verification method and system in access control

An access control and verification method technology, applied in the field of information security, can solve problems such as insufficient security protection capability, inability to ensure the trusted operation of upper-layer applications, ignoring dynamic objects, etc., to achieve the effect of ensuring dynamic trustworthiness

Active Publication Date: 2020-05-08
BEIJING UNIV OF TECH
View PDF8 Cites 2 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, the shortcomings of the solution are: 1. TPM is used as the trusted anchor point, and there is no support for the national secret algorithm package; 2. The verification system is too cumbersome and superficial, that is, only the owner identity and creation time of the relevant static objects are passed. Create an image file of a static object for credible verification
However, the disadvantages of this scheme are: 1. The credible verification is still carried out by means of identifying the identity of the subject and the object and encrypting the dynamic object information by the TPM, which has considerable limitations; The specific information of the dynamic object is classified and processed, and the credibility is not high
[0006] In the patent document with the patent publication number CN 106295319, a security protection scheme for the operating system is disclosed by controlling the trust status of the subject and the object, but the classification of the object is mainly for the static file category, ignoring the important Dynamic objects, that is, processes, inter-process communication, etc., the security protection capability is not outstanding
[0007] Patent Publication No. CN 109992992A proposes a method of allocating sensitive data including statically allocated .data and .bss segments of trusted applications, and dynamically allocated stack and heap segments to internal random memory protected by trusted chips. The security domain of the access memory, and load the code and non-sensitive data into the security domain of the dynamic random access memory to realize the trusted protection of application data, but this solution only proposes to use the so-called "security domain" to protect sensitive data. However, there is a lack of credible dynamic verification of relevant sensitive data. Once the "security domain" is breached by an attacker, the application data is not credible.
[0008] To sum up, the existing trusted operation schemes do not classify the types of objects when dealing with trusted verification of objects, and the proposed requirements for trusted verification of objects are all aimed at those who can only act as subjects. "static objects" of the recipient, such as files, directories, devices, etc.
However, there is a lack of trusted verification of dynamic objects such as processes and inter-process communication
The credibility of the object cannot be effectively guaranteed, therefore, the trusted operation of the upper-layer application cannot be guaranteed

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Object memory credibility verification method and system in access control
  • Object memory credibility verification method and system in access control
  • Object memory credibility verification method and system in access control

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0033] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is a part of embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0034] Trusted computing technology can improve network security as follows:

[0035] 1. Operating system security upgrades, such as preventing rootkit insertion in UEFI, preventing rootkit insertion in OS, and preventing virus and attack driver injection, etc.

[0036] 2. Application integrity protection, such as preventing Trojan horses from be...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

The embodiment of the invention provides an object memory credibility verification method and system in access control, and the method comprises the steps: obtaining an object memory in an access control process, and dividing the object memory into an object process memory and an IPC object shared memory; and performing credibility verification on the object process memory and the IPC object shared memory respectively. Accoridng to the object memory credibility verification method and system in access control, object memory data is divided into an object process memory serving as a subject service object and an IPC object shared memory serving as inter-process communication; and credibility verification is carried out on the two object memories respectively, so that credibility verification of the uncertain object data neglected by the existing scheme is realized, and dynamic credibility of the application program in the running process is ensured.

Description

technical field [0001] The invention relates to the technical field of information security, in particular to a method and system for authenticating object memory in access control. Background technique [0002] With the rapid development of the Internet, the application of computer networks has gradually penetrated into all aspects of people's lives, resulting in an increasingly strong demand for building trusted network systems. Especially with the maturity of "cloud computing" technology, which is designed with the concept of dynamic resource allocation and on-demand services, the attack methods and tools it faces are becoming more and more diversified, and cloud security issues have also become constraints to the development of this emerging technology. bottleneck. With the rise of trusted computing technology, trusted operating systems have gradually become a research hotspot. The establishment of credibility not only requires the consistency measurement of the operati...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Applications(China)
IPC IPC(8): G06F21/78G06F21/60G06F9/54
CPCG06F21/78G06F21/602G06F9/544
Inventor 张建标黄浩翔冯星伟陶务升万永祺曹雪琛
Owner BEIJING UNIV OF TECH
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More