Supercharge Your Innovation With Domain-Expert AI Agents!

Method and system for trusted verification of object memory in access control

An access control and verification method technology, applied in the field of information security, can solve the problems of insufficient security protection capability, cumbersome verification system, and inability to ensure the trusted operation of upper-layer applications, and achieve the effect of ensuring dynamic trustworthiness

Active Publication Date: 2022-03-11
BEIJING UNIV OF TECH
View PDF8 Cites 0 Cited by
  • Summary
  • Abstract
  • Description
  • Claims
  • Application Information

AI Technical Summary

Problems solved by technology

However, the shortcomings of the solution are: 1. TPM is used as the trusted anchor point, and there is no support for the national secret algorithm package; 2. The verification system is too cumbersome and superficial, that is, only the owner identity and creation time of the relevant static objects are passed. Create an image file of a static object for credible verification
However, the disadvantages of this scheme are: 1. The credible verification is still carried out by means of identifying the identity of the subject and the object and encrypting the dynamic object information by the TPM, which has considerable limitations; The specific information of the dynamic object is classified and processed, and the credibility is not high
[0006] In the patent document with the patent publication number CN 106295319, a security protection scheme for the operating system is disclosed by controlling the trust status of the subject and the object, but the classification of the object is mainly for the static file category, ignoring the important Dynamic objects, that is, processes, inter-process communication, etc., the security protection capability is not outstanding
[0007] Patent Publication No. CN 109992992A proposes a method of allocating sensitive data including statically allocated .data and .bss segments of trusted applications, and dynamically allocated stack and heap segments to internal random memory protected by trusted chips. The security domain of the access memory, and load the code and non-sensitive data into the security domain of the dynamic random access memory to realize the trusted protection of application data, but this solution only proposes to use the so-called "security domain" to protect sensitive data. However, there is a lack of credible dynamic verification of relevant sensitive data. Once the "security domain" is breached by an attacker, the application data is not credible.
[0008] To sum up, the existing trusted operation schemes do not classify the types of objects when dealing with trusted verification of objects, and the proposed requirements for trusted verification of objects are all aimed at those who can only act as subjects. "static objects" of the recipient, such as files, directories, devices, etc.
However, there is a lack of trusted verification of dynamic objects such as processes and inter-process communication
The credibility of the object cannot be effectively guaranteed, therefore, the trusted operation of the upper-layer application cannot be guaranteed

Method used

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
View more

Image

Smart Image Click on the blue labels to locate them in the text.
Viewing Examples
Smart Image
  • Method and system for trusted verification of object memory in access control
  • Method and system for trusted verification of object memory in access control
  • Method and system for trusted verification of object memory in access control

Examples

Experimental program
Comparison scheme
Effect test

Embodiment Construction

[0033] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments It is a part of embodiments of the present invention, but not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by persons of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0034] Trusted computing technology can improve network security as follows:

[0035] 1. Operating system security upgrades, such as preventing rootkit insertion in UEFI, preventing rootkit insertion in OS, and preventing virus and attack driver injection, etc.

[0036] 2. Application integrity protection, such as preventing Trojan horses from be...

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

PUM

No PUM Login to View More

Abstract

An embodiment of the present invention provides a method and system for authentically verifying object memory in access control, the method comprising: acquiring object memory in the access control process, and dividing the object memory into object process memory and IPC object shared memory; Trustworthiness verification is performed on the object process memory and the IPC object shared memory respectively. The object memory trusted verification method and system in the access control provided by the embodiment of the present invention divides the object memory data into the object process memory serving as the main service object and the IPC object shared memory serving as the inter-process communication, and respectively classifies the two types of objects Trustworthiness verification is performed on the memory separately, which realizes the trustworthiness verification of the indeterminate object data ignored by the existing schemes, and ensures the dynamic trustworthiness of the application program during operation.

Description

technical field [0001] The invention relates to the technical field of information security, in particular to a method and system for authenticating object memory in access control. Background technique [0002] With the rapid development of the Internet, the application of computer networks has gradually penetrated into all aspects of people's lives, resulting in an increasingly strong demand for building trusted network systems. Especially with the maturity of "cloud computing" technology, which is designed with the concept of dynamic resource allocation and on-demand services, the attack methods and tools it faces are becoming more and more diversified, and cloud security issues have also become constraints to the development of this emerging technology. bottleneck. With the rise of trusted computing technology, trusted operating systems have gradually become a research hotspot. The establishment of credibility not only requires the consistency measurement of the operati...

Claims

the structure of the environmentally friendly knitted fabric provided by the present invention; figure 2 Flow chart of the yarn wrapping machine for environmentally friendly knitted fabrics and storage devices; image 3 Is the parameter map of the yarn covering machine
Login to View More

Application Information

Patent Timeline
no application Login to View More
Patent Type & Authority Patents(China)
IPC IPC(8): G06F21/78G06F21/60G06F9/54
CPCG06F21/78G06F21/602G06F9/544
Inventor 张建标黄浩翔冯星伟陶务升万永祺曹雪琛
Owner BEIJING UNIV OF TECH
Features
  • R&D
  • Intellectual Property
  • Life Sciences
  • Materials
  • Tech Scout
Why Patsnap Eureka
  • Unparalleled Data Quality
  • Higher Quality Content
  • 60% Fewer Hallucinations
Social media
Patsnap Eureka Blog
Learn More