A dynamic measurement method, device and dynamic measurement system

By receiving and safely processing metric control instructions on the metric host, and managing metric control operations by the remote authentication server, the problem of dynamic metric host being easily attacked is solved, and the security of the system is improved.

CN114020329BActive Publication Date: 2025-05-23HYGON INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111294772.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-03
Publication Date
2025-05-23
Estimated Expiration
2041-11-03

AI Technical Summary

Technical Problem

In the prior art, dynamic measurement hosts are easily acquired by attackers, resulting in low system security.

Method used

By receiving the metric control instructions forwarded by the second processor on the first processor of the metric host, and after the remote authentication server performs the first security processing, it is sent to the second processor for security checks and operations. The method includes secure processing using encryption and signature keys and managing metric control operations through a remote authentication server.

Benefits of technology

Improves the security of dynamic metrics, prevents attackers from tampering with or leaking metric control instructions, and enhances the overall security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114020329B_ABST
    Figure CN114020329B_ABST
Patent Text Reader

Abstract

The embodiments of the present application disclose a dynamic measurement method, device and measurement system, which relate to the field of trusted computing technology and are invented to improve the security of the system. The method is based on the first processor of the measurement host, and includes: receiving the measurement control instruction forwarded by the second processor of the measurement host; wherein the measurement control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction, and sent to the second processor; performing a first security check corresponding to the first security processing on the measurement control instruction, wherein the second processor has no right to know the first decryption key and the first signature verification key; in response to the passing of the first security check, performing a corresponding measurement control operation according to the first control instruction to obtain a measurement control result. The present application is applicable to dynamic measurement.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of trusted computing technology, and in particular to a dynamic measurement method, device and measurement system. Background Art

[0002] Measurement is a key technology widely used in trusted computing. Measurement uses a certain method to extract the characteristic value of the target program or data. The characteristic value is unique and can be used to determine whether the target or data has been tampered with. Currently, there are two main forms of measurement: static measurement and dynamic measurement. Dynamic measurement means that continuous measurement can be performed while the target is running, and the status of the target can be monitored in real time.

[0003] In the prior art, when dynamic measurement is required on a measurement host, the measurement host controls dynamic measurement such as the creation and startup of measurement tasks, that is, the measurement host has control over dynamic measurement. However, when an attacker attacks the measurement host, the attacker can easily obtain control over the dynamic measurement, resulting in low system security. Summary of the invention

[0004] In view of this, embodiments of the present application provide a dynamic measurement method, device, and dynamic measurement system, which can improve the security of the system.

[0005] In a first aspect, an embodiment of the present application provides a dynamic measurement method, based on a first processor of a measurement host, comprising: receiving a measurement control instruction forwarded by a second processor of the measurement host; wherein the measurement control instruction is obtained by a remote authentication server performing a first security processing on the first control instruction, and sent to the second processor, the first security processing comprising: encrypting with a first encryption key and / or signing with a first signature key; performing a first security check corresponding to the first security processing on the measurement control instruction, the first security check comprising: decrypting the measurement control instruction with a first decryption key and / or verifying the signature of the measurement control instruction with a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; in response to passing the first security check, performing a corresponding measurement control operation according to the first control instruction to obtain a measurement control result.

[0006] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0007] According to a specific implementation manner of an embodiment of the present application, after performing a corresponding measurement control operation according to the first control instruction to obtain a measurement control result, the method further includes: performing a second security processing on the measurement control result to obtain a security control result, wherein the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key; sending the security control result to the second processor and forwarding it to the remote authentication server through the second processor.

[0008] According to a specific implementation method of an embodiment of the present application, the measurement control instruction carries first timeliness information; after obtaining the measurement control result and before performing the second security processing on the measurement control result, the method further includes: generating second timeliness information, and adding the second timeliness information and the first timeliness information to the measurement control result; after sending the security control result to the second processor and forwarding it to the remote authentication server through the second processor, the method further includes: receiving an update control instruction forwarded by the second processor and made by the remote authentication server for the measurement control result, the update control instruction carrying the second timeliness information and the third timeliness information; wherein the update control instruction is obtained by the remote authentication server performing the first security processing on the first control instruction and sending it to the second processor; and determining whether to execute the update control instruction based on the second timeliness information.

[0009] According to a specific implementation manner of an embodiment of the present application, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0010] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the method also includes: in response to the start measurement task instruction, starting a preset measurement task; in response to an abnormal measurement result corresponding to the preset measurement task, saving the measurement result and stopping measurement; or, the method also includes: in response to the start measurement task instruction, starting a preset measurement task; in response to an abnormal measurement result corresponding to the preset measurement task, saving the measurement result and stopping measurement; sending the measurement result as the measurement control result of the next measurement control instruction to the remote authentication server, wherein the next measurement control instruction includes a periodic remote authentication instruction.

[0011] In a second aspect, an embodiment of the present application provides a dynamic measurement method based on a remote authentication server, including: obtaining measurement basic information of a target measurement host; generating a first control instruction based on the measurement basic information; performing a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; sending the measurement control instruction to the target measurement host so that the second processor of the target measurement host forwards it to the first processor, and causing the first processor to perform corresponding measurement control operations according to the measurement control instruction to obtain a measurement control result.

[0012] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0013] According to a specific implementation manner of an embodiment of the present application, after sending the measurement control instruction, the method further includes: receiving a security control result forwarded by a second processor of the target measurement host, the security control result being sent to the second processor after the first processor of the target measurement host performs a second security processing on the measurement control result, the second security processing including: encrypting using a second encryption key and / or signing using a second signature key.

[0014] According to a specific implementation manner of an embodiment of the present application, before sending the measurement control instruction to the target measurement host, the method also includes: adding first timeliness information to the first control instruction; after receiving the security control result forwarded by the second processor of the target measurement host, the method also includes: performing a second security check on the security control result; the second security check includes: using a second decryption key to decrypt the security control result and / or using a second signature verification key to perform signature verification on the security control result, wherein the second processor has no right to know the second decryption key and the second signature verification key; if the second security check passes, obtaining the measurement control result according to the security control result; the measurement control result carries the first timeliness information and the second timeliness information; determining whether the measurement control result is credible according to the first timeliness information, and saving the second timeliness information.

[0015] According to a specific implementation method of an embodiment of the present application, it also includes: when it is determined that the measurement control result is credible, generating a first control instruction according to the measurement control result; performing the first security processing on the first control instruction to obtain an updated control instruction; and sending the updated control instruction to the second processor of the target measurement host.

[0016] According to a specific implementation manner of an embodiment of the present application, before sending the update control instruction to the second processor of the target metric host, the method also includes: generating third timeliness information and adding the third timeliness information and the second timeliness information to the first control instruction.

[0017] According to a specific implementation manner of an embodiment of the present application, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0018] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the method also includes: sending the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a periodic remote authentication instruction; in response to not receiving the measurement operation result of the periodic remote authentication instruction within a predetermined time, sending exception handling information to the second processor of the target measurement host; or, the method includes: sending the next measurement control instruction to the target measurement host, wherein the next measurement control instruction includes a remote authentication instruction; receiving the measurement operation result of the periodic remote authentication instruction forwarded by the second processor of the target measurement host, wherein the measurement operation result is an abnormal measurement result corresponding to a preset measurement task; sending exception handling information to the second processor of the target measurement host according to the received measurement operation result.

[0019] In a third aspect, an embodiment of the present application provides a dynamic measurement device, based on a first processor of a measurement host, including: a first receiving module, used to receive a measurement control instruction forwarded by a second processor of the measurement host; wherein the measurement control instruction is obtained by a remote authentication server performing a first security processing on the first control instruction and sent to the second processor, and the first security processing includes: encrypting with a first encryption key and / or signing with a first signature key; a first checking module, used to perform a first security check on the measurement control instruction corresponding to the first security processing, and the first security check includes: decrypting the measurement control instruction with a first decryption key and / or signing the measurement control instruction with a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; a first obtaining module, used to perform a corresponding measurement control operation according to the first control instruction in response to passing the first security check, and obtain a measurement control result.

[0020] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0021] According to a specific implementation method of an embodiment of the present application, the device also includes: a second obtaining module, which is used to perform a second security processing on the measurement control result to obtain a security control result after the first obtaining module performs a corresponding measurement control operation according to the first control instruction to obtain a measurement control result, and the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key; a first sending module, which is used to send the security control result to the second processor and forward it to the remote authentication server through the second processor.

[0022] According to a specific implementation method of an embodiment of the present application, the measurement control instruction carries first timeliness information; the device also includes: a first generating module, which is used to generate second timeliness information after the first obtaining module performs the corresponding measurement control operation according to the first control instruction to obtain the measurement control result, and before the second obtaining module performs the second security processing on the measurement control result, and add the second timeliness information and the first timeliness information to the measurement control result; the device also includes: a second receiving module, which is used to receive the update control instruction made by the remote authentication server for the measurement control result forwarded by the second processor after the sending module sends the security control result to the second processor and forwards it to the remote authentication server through the second processor, and the update control instruction carries the second timeliness information and the third timeliness information; wherein the update control instruction is obtained by the remote authentication server performing the first security processing on the first control instruction and sent to the second processor; a first determining module is used to determine whether to execute the update control instruction according to the second timeliness information.

[0023] According to a specific implementation manner of an embodiment of the present application, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0024] According to a specific implementation method of an embodiment of the present application, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the device also includes: a first starting module, which is used to start a preset measurement task in response to the start measurement task instruction; a first saving module, which is used to save the measurement result and stop the measurement in response to an abnormal measurement result corresponding to the preset measurement task; or, the device also includes: a second starting module, which is used to start the preset measurement task in response to the start measurement task instruction; a second saving module, which is used to save the measurement result and stop the measurement in response to an abnormal measurement result corresponding to the preset measurement task; a second sending module, which is used to send the measurement result as the measurement control result of the next measurement control instruction to the remote authentication server, wherein the next measurement control instruction includes a periodic remote authentication instruction.

[0025] In a fourth aspect, an embodiment of the present application provides a dynamic measurement device, based on a remote authentication server, including: a first acquisition module, used to acquire measurement basic information of a target measurement host; a second generation module, used to generate a first control instruction based on the measurement basic information; a third acquisition module, used to perform a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; a third sending module, used to send the measurement control instruction to the target measurement host, so that the second processor of the target measurement host forwards it to the first processor, and the first processor performs a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result.

[0026] According to a specific implementation manner of an embodiment of the present application, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0027] According to a specific implementation method of an embodiment of the present application, the device also includes: a third receiving module, which is used to receive a security control result forwarded by a second processor of the target measurement host after the third sending module sends the measurement control instruction, and the security control result is sent to the second processor after the first processor of the target measurement host performs a second security processing on the measurement control result, and the second security processing includes: encrypting using a second encryption key and / or signing using a second signature key.

[0028] According to a specific implementation method of an embodiment of the present application, the device also includes: an adding module, which is used to add first timeliness information to the first control instruction before the third sending module sends the measurement control instruction to the target measurement host; the device also includes: a second checking module, which is used to perform a second security check on the security control result after the third receiving module receives the security control result forwarded by the second processor of the target measurement host; the second security check includes: using a second decryption key to decrypt the security control result and / or using a second signature verification key to sign the security control result, wherein the second processor has no right to know the second decryption key and the second signature verification key; a second acquisition module, which is used to obtain the measurement control result according to the security control result if the second security check passes; the measurement control result carries the first timeliness information and the second timeliness information; a third saving module, which is used to determine whether the measurement control result is credible according to the first timeliness information, and save the second timeliness information.

[0029] According to a specific implementation method of an embodiment of the present application, it also includes: a third generating module, which is used to generate a first control instruction according to the measurement control result when it is determined that the measurement control result is credible; a fourth obtaining module, which is used to perform the first security processing on the first control instruction to obtain an updated control instruction; and a fourth sending module, which is used to send the updated control instruction to the second processor of the target measurement host.

[0030] According to a specific implementation method of an embodiment of the present application, the device also includes: a fourth generation module, which is used to generate third timeliness information and add the third timeliness information and the second timeliness information to the first control instruction before the fourth sending module sends the update control instruction to the second processor of the target measurement host.

[0031] According to a specific implementation manner of an embodiment of the present application, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0032] According to a specific implementation method of an embodiment of the present application, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the device also includes: a fifth sending module, used to send the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a periodic remote authentication instruction; a sixth sending module, used to send exception handling information to the second processor of the target measurement host in response to not receiving the measurement operation result of the periodic remote authentication instruction within a predetermined time; or, the device includes: a seventh sending module, used to send the next measurement control instruction to the target measurement host, wherein the next measurement control instruction includes a remote authentication instruction; a fourth receiving module, used to receive the measurement operation result of the periodic remote authentication instruction forwarded by the second processor of the target measurement host, wherein the measurement operation result is a measurement result exception corresponding to a preset measurement task; an eighth sending module, used to send exception handling information to the second processor of the target measurement host according to the received measurement operation result.

[0033] In a fifth aspect, an embodiment of the present application provides a dynamic measurement system, comprising: a measurement host and a remote authentication server; wherein the measurement host comprises a first processor and a second processor; the first processor is used to execute any of the dynamic measurement methods described above based on the first processor of the measurement host, and the remote authentication server is used to execute any of the dynamic measurement methods described above of the remote authentication server.

[0034] In a sixth aspect, an embodiment of the present application provides an electronic device, comprising: a housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program code; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method described in any of the aforementioned implementation methods.

[0035] In a seventh aspect, an embodiment of the present application provides a computer-readable storage medium, which stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method described in any of the aforementioned implementation methods.

[0036] The dynamic measurement method, device and dynamic measurement system provided in this embodiment receive the measurement control instruction forwarded by the second processor of the measurement host, wherein the measurement control instruction is obtained by performing a first security processing on a first control instruction by a remote authentication server and sent to the second processor, and then a first security check corresponding to the first security processing is performed on the measurement control instruction. In response to the passing of the first security check, a corresponding measurement control operation is performed according to the first control instruction to obtain a measurement control result. Since the received measurement control instruction is forwarded by the remote authentication server through the second processor, the remote authentication server manages the measurement control operation, and the remote authentication server is relatively safe, thereby improving the security of dynamic measurement, and further improving the security of the system. Moreover, the measurement control instruction is obtained by performing a first security processing on the first control instruction, and then a first security check corresponding to the first security processing is used on the measurement control instruction, and the second processor has no right to know the first decryption key and the first signature verification key in the first security check. In this way, even if the measurement host is attacked, the communication content cannot be obtained, thereby avoiding the risk of tampering or leakage of the command during the transmission process, ensuring the security of the dynamic measurement command, and further improving the security of the system. BRIEF DESCRIPTION OF THE DRAWINGS

[0037] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.

[0038] Figure 1 A schematic diagram of a dynamic measurement method provided in an embodiment of the present application;

[0039] Figure 2 A schematic diagram of a flow chart of a dynamic measurement method provided in an embodiment of the present application;

[0040] Figure 3 A schematic diagram of a flow chart of a dynamic measurement method provided in yet another embodiment of the present application;

[0041] Figure 4 A schematic diagram of a dynamic measurement method provided in a specific embodiment of the present application;

[0042] Figure 5 A flowchart of abnormal measurement results provided for another specific implementation of the present application;

[0043] Figure 6 This is a schematic diagram of the structure of a dynamic measurement device according to an embodiment of the present application;

[0044] Figure 7 This is a structural schematic diagram of a dynamic measurement device according to another embodiment of the present application;

[0045] Figure 8 A schematic diagram of the structure of an electronic device provided in one embodiment of the present application. DETAILED DESCRIPTION

[0046] The embodiments of the present application are described in detail below in conjunction with the accompanying drawings. It should be clear that the described embodiments are only part of the embodiments of the present application, rather than all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without creative work are within the scope of protection of the present application.

[0047] To improve the security of the system, see Figure 1 , dynamic measurement tasks can be created at any time when needed. At the same time, when each dynamic measurement task is created, the dynamic measurement service will generate a random authorization code for it. The authorization code is stored in the memory space of the measurement host. When the measurement host needs to execute an operation command, the correct authorization code is required to perform the measurement task operation. This method adds an authorization code protection mechanism. Even if the system authority is obtained by an attacker, the attacker still cannot operate the measurement task without the authorization code, which plays a certain role in protecting the security of the system. However, the authorization code is in the memory of the measurement host, and the attacker can obtain the authorization code through memory analysis and other methods. The authorization code mechanism only increases the attack cost of the attacker, and the system risk still exists.

[0048] In view of this, the inventors discovered in their research that the security features of the remote authentication server can be used to transfer the control authority of dynamic measurement from the insecure measurement host to the secure remote authentication server, and when the remote authentication server interacts with the dynamic measurement module, the interactive information can be securely processed to improve the security of the system.

[0049] In order to enable those skilled in the art to better understand the technical concept, implementation plan and beneficial effects of the embodiments of the present application, specific embodiments are described in detail below.

[0050] In a first aspect, an embodiment of the present application provides a dynamic measurement method, based on a first processor of a measurement host, comprising: receiving a measurement control instruction forwarded by a second processor of the measurement host; wherein the measurement control instruction is obtained by a remote authentication server performing a first security processing on the first control instruction, and sent to the second processor, the first security processing comprising: encrypting with a first encryption key and / or signing with a first signature key; performing a first security check corresponding to the first security processing on the measurement control instruction, the first security check comprising: decrypting the measurement control instruction with a first decryption key and / or verifying the signature of the measurement control instruction with a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; in response to passing the first security check, performing a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result, thereby improving the security of the system.

[0051] Figure 2 A flow chart of a dynamic measurement method provided in an embodiment of the present application is shown in FIG. Figure 2 As shown, the dynamic measurement method of this embodiment, based on the first processor of the measurement host, may include:

[0052] S101, receiving a measurement control instruction forwarded by a second processor of a measurement host.

[0053] Dynamic measurement can continuously measure the measurement target while the program is running, and monitor in real time whether the program status has been tampered with.

[0054] The second processor may be a central processor on the measurement host, which may transfer the interactive information between the remote authentication server (RemoteAttestation Server or RA server) and the first processor. The first processor of this embodiment may be a security processor. In some examples, the first processor may be embedded in the second processor, and the dynamic measurement performed on the security processor may be called a trusted dynamic measurement. The security processor is responsible for periodically performing dynamic measurement and calculating hash values ​​on the registered protected memory segments during program execution, and comparing the hash values ​​with the reference values ​​to ensure that the information of the protected memory segments is not tampered with. Once tampering is detected, an abnormal signal may be issued to warn the user.

[0055] In this embodiment, the measurement control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction, and sent to the second processor.

[0056] The measurement control operation can be directly performed according to the first control instruction.

[0057] In this embodiment, the first security processing includes: encrypting using a first encryption key and / or signing using a first signature key.

[0058] The first control instruction can be encrypted using the first encryption key to obtain a measurement control instruction; the first control instruction can also be signed using the first signature key to obtain a measurement control instruction; the first control instruction can also be encrypted using the first encryption key to obtain an encrypted first control instruction, and then the encrypted first control instruction can be signed using the first signature key to obtain a measurement control instruction.

[0059] In some examples, the first encryption key may be a public key of a dynamic measurement module that executes the method of this embodiment, the first signature key may be a private key of a remote authentication server, and the dynamic measurement module in this embodiment may run on a first processor.

[0060] The public key of the dynamic measurement module can be obtained in the following way: the dynamic measurement module generates a key pair, sends the public key to the Certificate Authority (CA) server, and requests a certificate from the CA server. The CA server issues a certificate to the dynamic measurement module after confirming the identity of the requester and other information, and saves the certificate to the RA server. It can be understood that the certificate includes the public key of the dynamic measurement module.

[0061] The private key of the remote authentication server can be obtained in the following way: the remote authentication server generates a key pair, in which the private key is the private key of the remote authentication server, sends the public key to the CA server, and requests a certificate from the CA server. The CA server issues a certificate to the RA server after confirming the identity of the requester RA server and other information. It can be understood that the certificate includes the public key of the RA server.

[0062] S102: Perform a first security check corresponding to the first security processing on the measurement control instruction.

[0063] The first security check includes: using a first decryption key to decrypt the measurement control instruction and / or using a first signature verification key to perform signature verification on the measurement control instruction.

[0064] When the first encryption key is used for encryption in S101, correspondingly, the first decryption key is used to decrypt the measurement control instruction in this step; when the first signature key is used to sign in S101, correspondingly, the first signature verification key is used to verify the signature of the measurement control instruction in this step; when the first encryption key is used to encrypt and the first signature key is used to sign in S101, correspondingly, the first signature verification key is used to verify the signature and the first decryption key is used to decrypt in this step.

[0065] In some examples, the first decryption key pair may be a private key of a dynamic measurement module that executes the method of this embodiment, and the first signature verification key may be a public key of a remote authentication server.

[0066] The private key of the dynamic measurement module may be a private key in a key pair generated by the dynamic measurement module.

[0067] The public key of the remote authentication server can be obtained by the dynamic measurement module that executes the method of this embodiment. In a trusted environment, the certificate of the RA server is imported into the dynamic measurement module. The dynamic measurement module uses the public key of the certificate authority (CA) to verify the legitimacy of the certificate of the RA server and then saves the certificate of the RA server in the context of the dynamic measurement module. Specifically, it can be saved in the memory corresponding to the security processor, and the program running on the CPU cannot access the memory.

[0068] To improve the security of the measurement and further improve the security of the system, the second processor in this embodiment has no right to obtain the first decryption key and the first signature verification key.

[0069] S103: In response to the first security check being passed, performing a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result.

[0070] The measurement control instruction may be a control instruction related to measurement. In some examples, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0071] Among them, the measurement task creation instruction is used for common measurement tasks; the measurement task management instruction is used to manage measurement tasks, such as starting measurement tasks, updating measurement tasks, stopping measurement tasks, etc.; the periodic remote authentication instruction is used to periodically obtain the measurement status, which can be normal or abnormal measurement results.

[0072] Correspondingly, the result corresponding to the measurement task creation instruction is the measurement task creation result, the result corresponding to the measurement task management instruction is the measurement management execution result, and the result corresponding to the periodic remote authentication instruction is the measurement operation result. Among them, the measurement management execution result may include normal startup, measurement task updated, measurement task stopped and other information.

[0073] In this embodiment, by receiving the measurement control instruction forwarded by the second processor of the measurement host, wherein the measurement control instruction is obtained by performing a first security processing on the first control instruction by the remote authentication server, and is sent to the second processor, and then the measurement control instruction is subjected to a first security check corresponding to the first security processing, in response to the passing of the first security check, a corresponding measurement control operation is performed according to the first control instruction to obtain a measurement control result, because the received measurement control instruction is forwarded by the remote authentication server through the second processor, in this way, the remote authentication server manages the measurement control operation, and the remote authentication server is relatively safe, thereby improving the security of dynamic measurement, and further improving the security of the system, and the measurement control instruction is obtained by performing a first security processing on the first control instruction, and then the measurement control instruction is subjected to a first security check corresponding to the first security processing, and the second processor has no right to know the first decryption key and the first signature verification key in the first security check, so that even if the measurement host is attacked, the communication content cannot be obtained, thereby avoiding the risk of tampering or leakage of the command during the transmission process, and ensuring the security of the dynamic measurement command, thereby further improving the security of the system.

[0074] In order to improve the security of the measurement control result, another embodiment of the present application is basically the same as the above embodiment, except that, in this embodiment, after performing the corresponding measurement control operation according to the first control instruction to obtain the measurement control result (S103), the method further includes:

[0075] S104. Perform a second safety process on the measurement control result to obtain a safety control result.

[0076] The second security processing includes: encrypting using a second encryption key and / or signing using a second signature key.

[0077] The second encryption key may be different from the first decryption key and the first signature verification key, or the second encryption key may be the same as the first decryption key or the first signature verification key; the second signature key may be different from the first decryption key and the first signature verification key, or the second signature key may be the same as the first decryption key or the first signature verification key.

[0078] In some examples, the first verification key may be the public key of the remote authentication server, and the second encryption key may also be the public key of the remote authentication server; the first decryption key may be the private key of the dynamic measurement module, and the second signature key may also be the private key of the dynamic measurement module.

[0079] The measurement control result is encrypted and / or signed to obtain the security control result.

[0080] S105: Send the security control result to the second processor and forward it to the remote authentication server through the second processor.

[0081] The encrypted and / or signed security control result is forwarded to the remote authentication server through the second processor.

[0082] In this embodiment, a security control result is obtained by performing a second security processing on the measurement control result, and the security control result is then sent to a second processor and forwarded to a remote authentication server through the second processor. Since the second measurement control result is encrypted using a second encryption key and / or signed using a second signature key, the obtained security control result is forwarded to the remote authentication server through the second processor, thereby improving the security of the measurement control result.

[0083] In order to prevent replay attacks, another embodiment of the present application is basically the same as the above embodiment, except that the metric control instruction in this embodiment carries the first timeliness information.

[0084] The first time validity information may be a random number generated by the remote authentication server, or may be a confirmation number and a sequence number generated by the Transmission Control Protocol (TCP) during communication between the dynamic measurement module and the remote authentication server.

[0085] After obtaining the measurement control result and before performing a second security processing on the measurement control result, the method further includes:

[0086] S106: Generate second timeliness information, and add the second timeliness information and the first timeliness information to the measurement control result.

[0087] In some examples, the first time validity information may be a random number generated by a remote authentication server, and the second time validity information may be a random number generated by a first processor of the measurement host; if the first time validity information is the confirmation number A and sequence number B during TCP protocol transmission, then the second time validity information may be A as the sequence number, B plus the size of the data in the measurement control instruction to obtain C, and C may be used as the confirmation number. At this time, A and C may be used as the second time validity information.

[0088] Based on the above embodiment, after sending the security control result to the second processor and forwarding it to the remote authentication server through the second processor (S105), the method further includes:

[0089] S107: Receive an update control instruction forwarded by the second processor and made by the remote authentication server for the measurement control result, where the update control instruction carries the second timeliness information and the third timeliness information.

[0090] In this embodiment, the update control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction, and sent to the second processor.

[0091] When the remote authentication server's measurement control instruction is a measurement task creation instruction, the corresponding measurement control result is the measurement task creation result. After the remote authentication server receives the measurement task creation result, it can issue an update control instruction. At this time, the update control instruction can be a measurement task management instruction; similarly, when the measurement control instruction is a measurement task management instruction, the update control instruction can be a periodic remote authentication instruction.

[0092] The third aging information is generated in the same manner as the first aging information and the second aging information.

[0093] S108. Determine whether to execute the update control instruction according to the second timeliness information.

[0094] Taking the second timeliness information as a random number as an example, the second timeliness information carried in the update control instruction is compared with the second timeliness information generated in S106. If they are the same, it is determined that the update control instruction can be executed.

[0095] In this embodiment, by generating second timeliness information and adding the second timeliness information and the first timeliness information carried in the measurement control instruction to the measurement control result, an update control instruction made by the remote authentication server for the measurement control result is received, wherein the update control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction. Since the received update control instruction includes the second timeliness information and the third timeliness information, the second timeliness information in the update control instruction can be compared with the generated second timeliness information, and whether to execute the update control instruction can be determined based on the comparison result. The third timeliness information can be used as a basis for determining whether to execute the corresponding operation when interacting with the remote authentication server next time, thereby maintaining the freshness of the command and effectively preventing replay attacks.

[0096] In some examples, the measurement control instruction is a measurement task management instruction, the measurement task management instruction includes a start measurement task instruction, and the method further includes:

[0097] S109. In response to the start measurement task instruction, start the preset measurement task.

[0098] After receiving the measurement task instruction, the preset measurement task is started. It is understandable that the preset measurement task may be a measurement task created before this step according to the measurement task creation instruction sent by the remote authentication server, and the measurement task includes the measurement target when it is created.

[0099] S110 . In response to a measurement result corresponding to a preset measurement task being abnormal, saving the measurement result and stopping the measurement.

[0100] When a measurement task is measuring, if the corresponding measurement result is abnormal or called a failure, the measurement result is saved and the measurement is stopped.

[0101] The process of measuring the measurement target can be as follows: (1) obtaining the measurement target and calculating the measurement target baseline value; (2) creating a measurement task; (3) measuring the measurement target; (4) comparing the real-time measurement value with the baseline value during measurement. If the comparison results are the same, it means that the measurement is normal, otherwise it means that the measurement is abnormal.

[0102] The abnormal measurement result in the above embodiment may be caused by the measurement target in the measurement host being attacked, and the command forwarding function of the measurement host is also attacked, so the remote authentication server cannot directly obtain the measurement result.

[0103] When the measurement target in the measurement host is attacked, resulting in abnormal measurement results, and the command forwarding function of the measurement host can be used normally, in some other examples, the method further includes:

[0104] S111. In response to the start measurement task instruction, start a preset measurement task.

[0105] S112. In response to a measurement result corresponding to a preset measurement task being abnormal, save the measurement result and stop the measurement.

[0106] S113. Send the measurement result as the measurement control result of the next measurement control instruction to the remote authentication server, wherein the next measurement control instruction includes a periodic remote authentication instruction.

[0107] The periodic remote authentication instruction may be a remote authentication instruction sent at a predetermined time interval, with the purpose of obtaining measurement operation results.

[0108] In the case of abnormal measurement results, the measurement results can be saved. When a periodic remote authentication instruction is received from the remote authentication server after a certain period of time, the measurement results can be sent to the remote authentication server as the measurement operation result of the periodic remote authentication instruction, so that the remote authentication server can further process the measurement failure result.

[0109] In the second aspect, an embodiment of the present application provides a dynamic measurement method, which obtains measurement basic information of a target measurement host based on a remote authentication server; generates a first control instruction based on the measurement basic information; performs a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; sending the measurement control instruction to the target measurement host so that the second processor of the target measurement host forwards it to the first processor, and causes the first processor to perform corresponding measurement control operations according to the measurement control instruction to obtain a measurement control result, thereby improving the security of the system.

[0110] Figure 3 A flow chart of a dynamic measurement method provided in another embodiment of the present application is as follows: Figure 3 As shown, the dynamic measurement method of this embodiment, based on the remote authentication server, may include:

[0111] S201. Obtain basic measurement information of a target measurement host.

[0112] The basic measurement information may include measurement target, measurement address, identification information of measurement task, measurement task creation result information, measurement management execution result and / or measurement operation result.

[0113] S202: Generate a first control instruction according to the measurement basic information.

[0114] The first control instruction may be a measurement task creation instruction before performing security processing, a measurement task management instruction and / or a periodic remote authentication instruction.

[0115] If the measurement target and measurement address of the measurement host are obtained, the measurement task creation instruction before security processing can be generated based on the information.

[0116] S203: Perform a first security processing on the first control instruction to obtain a measurement control instruction.

[0117] In this embodiment, the first security processing includes: instructions for encrypting using a first encryption key and / or signing using a first signature key.

[0118] The first control instruction can be encrypted using the first encryption key to obtain a measurement control instruction; the first control instruction can also be signed using the first signature key to obtain a measurement control instruction; the first control instruction can also be encrypted using the first encryption key to obtain an encrypted first control instruction, and then the encrypted first control instruction can be signed using the first signature key to obtain a measurement control instruction.

[0119] In some examples, the first encryption key may be a public key of a module executing the dynamic metric, and the first signing key may be a private key of a remote authentication server.

[0120] The public key of the dynamic measurement module can be obtained in the following way: the dynamic measurement module generates a key pair, sends the public key to the Certificate Authority (CA) server, and requests a certificate from the CA server. The CA server issues a certificate to the dynamic measurement module after confirming the identity of the requester and other information, and saves the certificate to the RA server. It can be understood that the certificate includes the public key of the dynamic measurement module.

[0121] The private key of the remote authentication server can be obtained in the following way: the remote authentication server generates a key pair, in which the private key is the private key of the remote authentication server, sends the public key to the CA server, and requests a certificate from the CA server. The CA server issues a certificate to the RA server after confirming the identity of the requester RA server and other information. It can be understood that the certificate includes the public key of the RA server.

[0122] S204: Send a metric control instruction to the target metric host, so that the second processor of the target metric host forwards the instruction to the first processor, and the first processor performs a corresponding metric control operation according to the metric control instruction to obtain a metric control result.

[0123] The second processor may be a central processor on the measurement host, which may transfer the interactive information between the remote authentication server (RemoteAttestation Server or RA server) and the first processor. The first processor of this embodiment may be a security processor. In some examples, the first processor may be embedded in the second processor, and the dynamic measurement performed on the security processor may be called a trusted dynamic measurement. The security processor is responsible for periodically performing dynamic measurement and calculating hash values ​​on the registered protected memory segments during program execution, and comparing the hash values ​​with the reference values ​​to ensure that the information of the protected memory segments is not tampered with. Once tampering is detected, an abnormal signal may be issued to warn the user.

[0124] The measurement control instruction may be a control instruction related to measurement. In some examples, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0125] Among them, the measurement task creation instruction is used for common measurement tasks; the measurement task management instruction is used to manage measurement tasks, such as starting measurement tasks, updating measurement tasks, stopping measurement tasks, etc.; the periodic remote authentication instruction is used to periodically obtain the measurement status, which can be normal or abnormal measurement results.

[0126] Correspondingly, the result corresponding to the measurement task creation instruction is the measurement task creation result, the result corresponding to the measurement task management instruction is the measurement management execution result, and the result corresponding to the periodic remote authentication instruction is the measurement operation result. Among them, the measurement management execution result may include normal startup, measurement task updated, measurement task stopped and other information.

[0127] In this embodiment, a first control instruction is generated according to the obtained measurement basic information of the target measurement host, and the first control instruction is subjected to a first security processing to obtain the measurement control instruction, and then the measurement control instruction is sent to the target measurement host. The first processor performs a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result. Since the measurement control instruction is obtained by generating the first control instruction by a remote authentication server and performing a first security processing on the first control instruction, the first processor performs a measurement control operation according to the measurement control instruction. In this way, the remote authentication server manages the measurement control operation, and the remote authentication server is relatively safe, thereby improving the security of dynamic measurement, and further improving the security of the system. Moreover, the measurement control instruction is obtained by performing a first security processing on the first control instruction, and thus the security of the system can be further improved. In addition, due to the architectural advantages of the remote authentication server, a remote authentication server can be used to simultaneously create and dynamically manage dynamic measurement tasks for multiple managed measurement hosts, expanding the original single-host dynamic measurement to star-shaped multi-machine dynamic measurement.

[0128] In order to improve the security of the measurement control result, another embodiment of the present application is basically the same as the above embodiment, except that, in this embodiment, after sending the measurement control instruction, the method further includes:

[0129] S205: Receive the security control result forwarded by the second processor of the target metric host.

[0130] The security control result is sent to the second processor after the first processor of the target measurement host performs second security processing on the measurement control result. The second security processing includes: encrypting with a second encryption key and / or signing with a second signature key.

[0131] The second encryption key may be different from the first decryption key and the first signature verification key, or the second encryption key may be the same as the first decryption key or the first signature verification key; the second signature key may be different from the first decryption key and the first signature verification key, or the second signature key may be the same as the first decryption key or the first signature verification key.

[0132] In some examples, the first signature key may be a public key of a remote authentication server, and the second encryption key may also be a public key of a remote authentication server; the first decryption key may be a private key of a dynamic measurement module, and the second signature key may also be a private key of a dynamic measurement module.

[0133] The measurement control result is encrypted and / or signed to obtain the security control result.

[0134] In order to prevent replay attacks, another embodiment of the present application is basically the same as the above embodiment, except that before sending the metric control instruction to the target metric host, the method further includes:

[0135] S206: Add first timeliness information to the first control instruction.

[0136] The first time validity information may be a random number generated by the remote authentication server, or may be a confirmation number and a sequence number generated by the Transmission Control Protocol (TCP) during communication between the dynamic measurement module and the remote authentication server.

[0137] After receiving the security control result forwarded by the second processor of the target metric host, the method further includes:

[0138] S207: Perform a second security check on the security control results.

[0139] The second security check includes: decrypting the security control result using the second decryption key and / or performing signature verification on the security control result using the second signature verification key, wherein the second processor has no right to know the second decryption key and the second signature verification key.

[0140] The second decryption key may be different from the first encryption key and the first signature key, and the second signature verification key may be the same as the first encryption key or the first signature key; the second signature key may be different from the first encryption key and the first signature key, and the second signature key may be the same as the first encryption key or the first signature key.

[0141] In some examples, the first signing key may be a private key of a remote authentication server, and the second decryption key may also be a private key of a remote authentication server; the first encryption key may be a private key of a dynamic measurement module, and the second verification key may also be a public key of the dynamic measurement module.

[0142] S208: When the second security check passes, obtain a measurement control result according to the security control result.

[0143] In this embodiment, the measurement control result carries the first timeliness information and the second timeliness information.

[0144] In some examples, the first time validity information may be a random number generated by a remote authentication server, and the second time validity information may also be a random number generated by a remote authentication server; the first time validity information is the confirmation number A and the sequence number B during TCP protocol transmission, then the second time validity information may be A as the sequence number, B plus the size of the data in the measurement control instruction to obtain C, and C may be used as the confirmation number. At this time, A and C may be used as the second time validity information.

[0145] S209: Determine whether the measurement control result is credible according to the first timeliness information, and save the second timeliness information.

[0146] Taking the first time validity information as a random number as an example, the first time validity information carried in the measurement control result is compared with the first time validity information added in the first control instruction in S206. If they are the same, the measurement control result is credible, and the second time validity information is saved so that the first processor can verify the measurement control instruction sent by the remote authentication server, thereby avoiding replay attacks.

[0147] In this embodiment, by adding the first timeliness information to the first control instruction, a second security check is performed on the security control result. When the second security check passes, the measurement control result is obtained according to the security control result, wherein the measurement control result carries the first timeliness information and the second timeliness information. Whether the measurement control result is credible is determined according to the first timeliness information, and the second timeliness information is saved. Since the measurement control result carries the first timeliness information and the second timeliness information, the first timeliness information in the measurement control result can be compared with the first timeliness information added in the first control instruction, and whether the measurement control result is credible is determined according to the comparison result, thereby maintaining the freshness of the command and effectively preventing replay attacks.

[0148] Another embodiment of the present application is basically the same as the above method, except that the method of this embodiment further includes:

[0149] S210. When it is determined that the measurement control result is credible, generate a first control instruction according to the measurement control result.

[0150] When the measurement control instruction of the remote authentication server is a measurement task creation instruction, the corresponding measurement control result is the measurement task creation result. After the remote authentication server receives the measurement task creation result, it can generate a first regulation instruction. At this time, the first regulation instruction can be a measurement task management instruction; similarly, when the measurement control instruction is a measurement task management instruction, the first regulation instruction can be a periodic remote authentication instruction.

[0151] S211. Perform a first security processing on the first control instruction to obtain an updated control instruction.

[0152] The first control instruction can be encrypted using the first encryption key to obtain an updated control instruction; the first control instruction can also be encrypted using the first signature key to obtain an updated control instruction; the first control instruction can also be encrypted using the first encryption key to obtain the encrypted first control instruction, and then the encrypted first control instruction can be signed using the first signature key to obtain an updated control instruction.

[0153] S212. Send an update control instruction to the second processor of the target metric host.

[0154] In some examples, before sending the update control instruction to the second processor of the target metric host (S212), the method further includes:

[0155] The third timeliness information is generated and the third timeliness information and the second timeliness information are added to the first control instruction.

[0156] The third aging information is generated in the same manner as the first aging information and the second aging information.

[0157] In this embodiment, the third timeliness information and the second timeliness information are added to the first control instruction, and the first security processing is performed to obtain the measurement control instruction. In this way, after receiving the instruction, the first processor can determine whether to execute the measurement control instruction based on the second timeliness information, thereby facilitating the prevention of replay attacks and improving the security of the system.

[0158] In some examples, the measurement control instruction is a measurement task management instruction, the measurement task management instruction includes a start measurement task instruction, and the method further includes:

[0159] S213. Send the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a periodic remote authentication instruction.

[0160] The purpose of sending periodic remote authentication commands is to obtain measurement operation results.

[0161] S214: In response to not receiving the measurement operation result of the remote authentication instruction within a predetermined time, sending exception handling information to the second processor of the target measurement host.

[0162] When the measurement operation result is not received within the predetermined time, the measurement target in the measurement host and the command forwarding function of the measurement host may be attacked, so the exception processing information is sent to the second processor of the target measurement host so as to timely handle the attack accordingly.

[0163] When the measurement target in the measurement host is attacked, resulting in abnormal measurement results, and the command forwarding function of the measurement host can be used normally, in some other examples, the method further includes:

[0164] S215. Send a next measurement control instruction to the target measurement host, wherein the next measurement control instruction includes a periodic remote authentication instruction.

[0165] The purpose of sending periodic remote authentication commands is to obtain measurement operation results.

[0166] S216: Receive the measurement operation result of the periodic remote authentication instruction forwarded by the second processor of the target measurement host.

[0167] In this embodiment, the measurement operation result is that the measurement result corresponding to the preset measurement task is abnormal.

[0168] S217. Send exception handling information to the second processor of the target measurement host according to the received measurement operation result.

[0169] The exception handling information is sent to the second processor of the target metric host so as to handle the attack accordingly in a timely manner.

[0170] The following is a detailed description of the solution of the present application with a specific embodiment, see Figure 4 .

[0171] Step 1: The RA server generates a key pair RA_KEY and requests the CA server to generate a certificate. After confirming the identity of the requester RA server and other information, the CA server issues a certificate RA_CET to the RA server. The CA server's certificate can be obtained from the official certification authority to verify the credibility of the CA.

[0172] Step 2: When a dynamic measurement module needs to be deployed, first import the RA server certificate into the dynamic measurement module in a trusted environment. The dynamic measurement module verifies the legitimacy of the RA certificate using the CA public key and saves the RA certificate in its own context.

[0173] Step 3: The dynamic measurement (DM) module generates a key pair and requests a certificate from the CA. After confirming the identity of the requester, the CA server issues a certificate DM_CET to the DM and saves the certificate to the RA server.

[0174] The above three steps are the initialization stage of dynamic measurement, which is operated in a trusted state. The trusted state means that the measurement module is not vulnerable to attacks. In addition, two new roles, CA and RA, are introduced to manage secret keys, and cryptographic technology is used for communication encryption and decryption and integrity assurance.

[0175] Step 4: When a host managed by RA needs to be dynamically measured, RA obtains the information that needs to be measured of the host, and generates a corresponding create measurement command according to the corresponding host.

[0176] Step 5: The RA server generates a random ra_nonce value, encrypts the ra_nonce value and the measurement command information using the DM's public key DM_Pub, signs it using the RA's private key RA_Pri, and sends it to the measurement host.

[0177] Step 6: The measurement host sends the encrypted and signed command to the dynamic measurement module DM.

[0178] Step 7. After receiving the command, the dynamic measurement module uses its own private key to decrypt it and uses RA's public key RA_Pub to verify the signature. After the signature verification is passed, the measurement task is created according to the creation command information, and the random number dm_nonce is generated and saved. dm_nonce is used to prevent replay attacks on DM. After successful creation, the task identifier (ID) and other information corresponding to the task are returned.

[0179] Step 8: The dynamic measurement module DM packages the ra_nonce, dm_nonce value, and task ID information, encrypts them using the RA's public key RA_Pub, signs them using its own private key DM_Pri, and returns them to the requested measurement host.

[0180] Step 9: The measurement host obtains the encrypted information and sends the information to the RA server.

[0181] Step 10: The RA server decrypts and verifies the signature, verifies the ra_nonce value, saves the dm_nonce for the next operation command, saves the measurement task ID and other information, and the measurement task creation is completed.

[0182] The above steps 4 to 10 are the measurement task creation phase for secure processing using the secret key generated in the initialization phase.

[0183] Step 11: When RA needs to manage the measurement task of a certain measurement host, such as starting, updating and other measurement operations, RA generates a measurement management command for the corresponding task of the corresponding machine.

[0184] Step 12: The RA server generates a random ra_nonce value, encrypts and signs the ra_nonce value, the saved dm_nonce value, and the management operation command information, and sends them to the measurement host.

[0185] Step 13: The measurement host sends the command with the encrypted signature to the dynamic measurement module.

[0186] Step 14: After receiving the command, the dynamic measurement module decrypts and verifies the signature, and verifies the relevant information (such as whether dm_nonce verifies whether it is a replay attack). After the verification is passed, the measurement task is operated according to the operation command, and the operation return information is obtained.

[0187] Step 15: The dynamic measurement module regenerates and saves the dm_nonce value, packages the ra_nonce value, dm_nonce value, operation return value and other information, encrypts and signs them and returns them to the requested measurement host.

[0188] Step 16: The measurement host sends the encrypted and signed operation return information to the RA server.

[0189] Step 17: The RA server performs decryption and signature verification, verifies the ra_nonce value, processes and saves the dm_nonce value and the operation return information, and the operation command ends.

[0190] The above steps 11 to 17 are the measurement task management stage.

[0191] Step 18: When the measurement task is started, RA periodically generates a remote authentication command for the target host, and after the nonce value is processed in the same way as above, the information to be sent is encrypted and signed and sent to the DM module via the measurement host.

[0192] Step 19: After the DM module decrypts and verifies the signature, it also processes the nonce value and returns the corresponding measurement information and the nonce value to RA after encryption and signature. RA processes the returned information. If the measurement status is normal, it continues to wait for the next periodic authentication; if it is abnormal, it performs exception processing on the measurement host.

[0193] The above steps 18 and 19 are a periodic remote authentication process. Even if the attacker manipulates the measurement host to refuse to forward the command, the RA can still conclude that the measurement host is abnormal during the periodic authentication.

[0194] In the above process, RA will obtain the DM's dm_nonce value when the measurement task is created. Therefore, when RA sends a new command, it will send dm_nonce to DM. DM compares the value with the value it has saved to confirm whether it is the latest command, thus ensuring the freshness of the command.

[0195] When DM returns to RA, it regenerates a new dm_nonce and returns it to RA. RA adds the new dm_nonce to the new control command and sends it to DM, so that a different nonce value is used for each communication. Therefore, even if the measurement host sends the old transfer command to DM, DM will refuse service due to nonce anomalies. This method effectively resists repeated attacks on the DM module. Similarly, repeated attacks on RA are also resisted using ra_nonce.

[0196] See also Figure 5 When the dynamic measurement module is started and performs dynamic measurement, after the protected content in the measurement host is attacked, the processing steps of an embodiment of the present application are as follows:

[0197] Step 1: If the measurement result of the dynamic measurement module DM is abnormal, the measurement failure information is saved and the measurement is stopped.

[0198] Step 2: When receiving the periodic remote authentication command from RA, DM returns the abnormal measurement information to RA via the measurement host. RA determines that the measurement host is abnormal and performs abnormal processing.

[0199] It is understandable that the information exchanged between the dynamic measurement module and the RA server may also be added with a nonce value and securely processed to improve the security of the interactive information.

[0200] See also Figure 5 When the dynamic measurement module is started and dynamic measurement is performed, the protected content in the measurement host is attacked, and the transfer function of the measurement host is also destroyed. The processing steps of an embodiment of the present application are as follows:

[0201] Step 1: The protected content of the measurement host is attacked, and the function of the measurement host to transfer communication content is destroyed.

[0202] Step 2: When the measurement result of the dynamic measurement module is abnormal, the measurement information is saved and the measurement is stopped.

[0203] Step 3: When the periodic remote authentication command of RA is sent to the measurement host, the command cannot be forwarded because the measurement host is attacked.

[0204] Step 4: After the RA server waits for a predetermined time, it detects that the periodic remote authentication command is not responded to, and determines that a problem occurs in the measurement host.

[0205] The measurement information encrypted and signed by the DM may also be obtained from the DM module in other ways to be decrypted and verified to further determine the anomaly.

[0206] In a third aspect, a dynamic measurement device provided by an embodiment of the present application is based on a remote authentication server and includes: a first receiving module, used to receive a measurement control instruction forwarded by a second processor of a measurement host; wherein the measurement control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction and sent to the second processor, and the first security processing includes: encrypting with a first encryption key and / or signing with a first signature key; a first checking module, used to perform a first security check on the measurement control instruction corresponding to the first security processing, and the first security check includes: decrypting the measurement control instruction with a first decryption key and / or signing the measurement control instruction with a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; a first obtaining module, used to perform a corresponding measurement control operation according to the first control instruction in response to passing the first security check, to obtain a measurement control result, thereby improving the security of the system.

[0207] Figure 6 This is a schematic diagram of the structure of a dynamic measurement device according to an embodiment of the present application. Figure 6 As shown, the dynamic measurement device of this embodiment, based on the first processor of the measurement host, may include: a first receiving module 11, used to receive the measurement control instruction forwarded by the second processor of the measurement host; wherein the measurement control instruction is obtained by the remote authentication server performing a first security processing on the first control instruction, and sent to the second processor, the first security processing includes: encrypting with a first encryption key and / or signing with a first signature key; a first checking module 12, used to perform a first security check on the measurement control instruction corresponding to the first security processing, the first security check includes: decrypting the measurement control instruction with a first decryption key and / or signing the measurement control instruction with a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; a first obtaining module 13, used to respond to the passing of the first security check, perform a corresponding measurement control operation according to the first control instruction, and obtain a measurement control result.

[0208] The device of this embodiment can be used to perform Figure 2 The technical solution of the method embodiment shown has similar implementation principles and technical effects, which will not be repeated here.

[0209] The device of this embodiment receives the measurement control instruction forwarded by the second processor of the measurement host, wherein the measurement control instruction is obtained by performing a first security processing on the first control instruction by the remote authentication server and sent to the second processor, and then the measurement control instruction is subjected to a first security check corresponding to the first security processing. In response to passing the first security check, the corresponding measurement control operation is performed according to the first control instruction to obtain a measurement control result. Since the received measurement control instruction is forwarded by the remote authentication server through the second processor, the remote authentication server manages the measurement control operation, and the remote authentication server is relatively safe, thereby improving the security of dynamic measurement, and further improving the security of the system. Moreover, the measurement control instruction is obtained by performing a first security processing on the first control instruction, and then the measurement control instruction is subjected to a first security check corresponding to the first security processing, and the second processor has no right to obtain the first decryption key and the first signature verification key in the first security check. In this way, even if the measurement host is attacked, the communication content cannot be obtained, thereby avoiding the risk of tampering or leakage of the command during the transmission process, and ensuring the security of the dynamic measurement command, thereby further improving the security of the system.

[0210] As an optional implementation, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0211] As an optional implementation, the device also includes: a second obtaining module, used to perform a second security processing on the measurement control result to obtain a security control result after the first obtaining module performs a corresponding measurement control operation according to the first control instruction to obtain a measurement control result, wherein the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key; a first sending module, used to send the security control result to the second processor and forward it to the remote authentication server through the second processor.

[0212] As an optional implementation, the measurement control instruction carries first timeliness information; the device also includes: a first generating module, which is used to generate second timeliness information after the first obtaining module performs the corresponding measurement control operation according to the first control instruction to obtain the measurement control result, and before the second obtaining module performs the second security processing on the measurement control result, and add the second timeliness information and the first timeliness information to the measurement control result; the device also includes: a second receiving module, which is used to receive an update control instruction made by the remote authentication server for the measurement control result forwarded by the second processor after the sending module sends the security control result to the second processor and forwards it to the remote authentication server through the second processor, the update control instruction carrying the second timeliness information and the third timeliness information; wherein the update control instruction is obtained by the remote authentication server performing the first security processing on the first control instruction and sending it to the second processor; a first determining module, which is used to determine whether to execute the update control instruction according to the second timeliness information.

[0213] As an optional implementation manner, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0214] As an optional implementation, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the device also includes: a first starting module, used to start a preset measurement task in response to the start measurement task instruction; a first saving module, used to save the measurement result and stop measurement in response to an abnormal measurement result corresponding to the preset measurement task; or, the device also includes: a second starting module, used to start a preset measurement task in response to the start measurement task instruction; a second saving module, used to save the measurement result and stop measurement in response to an abnormal measurement result corresponding to the preset measurement task; a second sending module, used to send the measurement result to the remote authentication server as the measurement control result of the next measurement control instruction, wherein the next measurement control instruction includes a periodic remote authentication instruction.

[0215] The device of the above embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar and will not be repeated here.

[0216] In a fourth aspect, a dynamic measurement device provided by an embodiment of the present application is based on a remote authentication server and may include: a first acquisition module, used to acquire measurement basic information of a target measurement host; a second generation module, used to generate a first control instruction based on the measurement basic information; a third acquisition module, used to perform a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; a third sending module, used to send the measurement control instruction to the target measurement host, so that the second processor of the target measurement host forwards it to the first processor, and the first processor performs a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result, thereby improving the security of the system.

[0217] Figure 7 This is a structural diagram of a dynamic measurement device according to another embodiment of the present application. Figure 7 As shown, the dynamic measurement device of this embodiment, based on the remote authentication server, may include: a first acquisition module 21, used to acquire the measurement basic information of the target measurement host; a second generation module 22, used to generate a first control instruction according to the measurement basic information; a third acquisition module 23, used to perform a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; a third sending module 24, used to send the measurement control instruction to the target measurement host, so that the second processor of the target measurement host forwards it to the first processor, and the first processor performs a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result.

[0218] The device of this embodiment can be used to perform Figure 3 The technical solution of the method embodiment shown has similar implementation principles and technical effects, which will not be repeated here.

[0219] The device of this embodiment generates a first control instruction based on the obtained measurement basic information of the target measurement host, performs a first security processing on the first control instruction, obtains the measurement control instruction, and then sends the measurement control instruction to the target measurement host. The first processor performs a corresponding measurement control operation according to the measurement control instruction to obtain a measurement control result. Since the measurement control instruction is obtained by generating the first control instruction by a remote authentication server and performing a first security processing on the first control instruction, the first processor performs a measurement control operation according to the measurement control instruction. In this way, the remote authentication server manages the measurement control operation, and the remote authentication server is relatively safe, thereby improving the security of dynamic measurement, and further improving the security of the system. Moreover, the measurement control instruction is obtained by performing a first security processing on the first control instruction, so that the security of the system can be further improved. In addition, due to the architectural advantages of the remote authentication server, a remote authentication server can be used to simultaneously create and dynamically manage dynamic measurement tasks for multiple managed measurement hosts, expanding the original single-host dynamic measurement to star-shaped multi-machine dynamic measurement.

[0220] As an optional implementation, the measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

[0221] As an optional implementation, the device also includes: a third receiving module, used to receive a security control result forwarded by the second processor of the target measurement host after the third sending module sends the measurement control instruction, and the security control result is sent to the second processor after the first processor of the target measurement host performs a second security processing on the measurement control result, and the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key.

[0222] As an optional implementation, the device also includes: an adding module, which is used to add first timeliness information to the first control instruction before the third sending module sends the measurement control instruction to the target measurement host; the device also includes: a second checking module, which is used to perform a second security check on the security control result after the third receiving module receives the security control result forwarded by the second processor of the target measurement host; the second security check includes: using a second decryption key to decrypt the security control result and / or using a second signature verification key to sign the security control result, wherein the second processor has no right to know the second decryption key and the second signature verification key; a second acquisition module, which is used to obtain the measurement control result according to the security control result if the second security check passes; the measurement control result carries the first timeliness information and the second timeliness information; a third saving module, which is used to determine whether the measurement control result is credible according to the first timeliness information, and save the second timeliness information.

[0223] As an optional implementation, it also includes: a third generating module, used to generate a first control instruction according to the measurement control result when it is determined that the measurement control result is credible; a fourth obtaining module, used to perform the first security processing on the first control instruction to obtain an updated control instruction; and a fourth sending module, used to send the updated control instruction to the second processor of the target measurement host.

[0224] As an optional implementation, the device also includes: a fourth generating module, used to generate third timeliness information and add the third timeliness information and the second timeliness information to the first control instruction before the fourth sending module sends the update control instruction to the second processor of the target measurement host.

[0225] As an optional implementation manner, the measurement control result includes at least one of the following: a measurement task creation result, a measurement management execution result, and a measurement operation result.

[0226] As an optional implementation, the measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a start measurement task instruction; the device also includes: a fifth sending module, used to send the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a periodic remote authentication instruction; a sixth sending module, used to send exception handling information to the second processor of the target measurement host in response to not receiving the measurement operation result of the periodic remote authentication instruction within a predetermined time; or, the device includes: a seventh sending module, used to send the next measurement control instruction to the target measurement host, wherein the next measurement control instruction includes a remote authentication instruction; a fourth receiving module, used to receive the measurement operation result of the periodic remote authentication instruction forwarded by the second processor of the target measurement host, wherein the measurement operation result is a measurement result exception corresponding to a preset measurement task; an eighth sending module, used to send exception handling information to the second processor of the target measurement host according to the received measurement operation result.

[0227] The device of the above embodiment can be used to execute the technical solution of the above method embodiment. Its implementation principle and technical effect are similar and will not be repeated here.

[0228] An embodiment of the present application provides a dynamic measurement system, which may include: a measurement host and a remote authentication server; wherein the measurement host includes a first processor and a second processor; the first processor is used to execute any dynamic measurement method based on the first processor of the measurement host, and the remote authentication server is used to execute any dynamic measurement method based on the remote authentication server.

[0229] Figure 8 The structural schematic diagram of the electronic device provided for an embodiment of the present application may include: a shell 61, a processor 62, a memory 63, a circuit board 64 and a power supply circuit 65, wherein the circuit board 64 is arranged inside the space enclosed by the shell 61, and the processor 62 and the memory 63 are arranged on the circuit board 64; the power supply circuit 65 is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory 63 is used to store executable program code; the processor 62 runs the program corresponding to the executable program code by reading the executable program code stored in the memory 63, so as to execute any one of the dynamic measurement methods provided in the aforementioned embodiments, and thus can also achieve corresponding beneficial technical effects, which have been described in detail in the previous text and will not be repeated here.

[0230] The above electronic devices exist in many forms, including but not limited to:

[0231] (1) Ultra-mobile personal computer devices: These devices fall into the category of personal computers, have computing and processing capabilities, and generally also have mobile Internet access features. These terminals include: PDA, MID and UMPC devices, such as iPad.

[0232] (2) Server: A device that provides computing services. The server consists of a processor, hard disk, memory, system bus, etc. The server is similar to a general computer architecture, but because it needs to provide highly reliable services, it has higher requirements in terms of processing power, stability, reliability, security, scalability, operability, etc.

[0233] (3) Other electronic devices with data interaction functions.

[0234] Correspondingly, an embodiment of the present application also provides a computer-readable storage medium, which stores one or more programs. The one or more programs can be executed by one or more processors to implement any dynamic measurement method provided by the aforementioned embodiments, thereby also being able to achieve the corresponding technical effects, which have been described in detail above and will not be repeated here.

[0235] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0236] Each embodiment in this specification is described in a related manner, and the same or similar parts between the embodiments can be referenced to each other, and each embodiment focuses on the differences from other embodiments.

[0237] In particular, for the device embodiment, since it is basically similar to the method embodiment, the description is relatively simple, and the relevant parts can be referred to the partial description of the method embodiment.

[0238] For the convenience of description, the above device is described by dividing the functions into various units / modules. Of course, when implementing the present application, the functions of each unit / module can be implemented in the same or multiple software and / or hardware.

[0239] A person skilled in the art can understand that all or part of the processes in the above-mentioned embodiments can be implemented by instructing the relevant hardware through a computer program, and the program can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes of the embodiments of the above-mentioned methods. The storage medium can be a disk, an optical disk, a read-only memory (ROM) or a random access memory (RAM), etc.

[0240] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any changes or substitutions that can be easily thought of by a person skilled in the art within the technical scope disclosed in the present application should be included in the protection scope of the present application. Therefore, the protection scope of the present application shall be based on the protection scope of the claims.

Claims

1. A dynamic measurement method, It is characterized in that Based on the first processor of the metric host, the first A processor is a security processor, and the method includes: Receive a measurement control instruction forwarded by a second processor of a measurement host; wherein the measurement control instruction is obtained by a remote authentication server performing a first security processing on a first control instruction and sent to the second processor, wherein the first security processing includes: encrypting with a first encryption key and / or signing with a first signature key; the second processor is a central processing unit; performing a first security check corresponding to the first security processing on the measurement control instruction, the first security check comprising: decrypting the measurement control instruction using a first decryption key and / or performing signature verification on the measurement control instruction using a first signature verification key, wherein the second processor has no right to know the first decryption key and the first signature verification key; In response to the first security check being passed, a corresponding measurement control operation is performed according to the first control instruction to obtain a measurement control result.

2. The method according to claim 1, It is characterized in that The measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

3. The method according to claim 1, It is characterized in that After performing a corresponding metric control operation according to the first control instruction and obtaining a metric control result, the method further includes: Performing a second security processing on the measurement control result to obtain a security control result, wherein the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key; The security control result is sent to the second processor and forwarded to the remote authentication server through the second processor.

4. The method according to claim 3, It is characterized in that The measurement control instruction carries first timeliness information; After obtaining the measurement control result and before performing a second security processing on the measurement control result, the method further includes: generating second aging information, and adding the second aging information and the first aging information to the measurement control result; After sending the security control result to the second processor and forwarding it to the remote authentication server through the second processor, the method further includes: receiving an update control instruction forwarded by the second processor and made by the remote authentication server for the measurement control result, wherein the update control instruction carries the second timeliness information and the third timeliness information; wherein the update control instruction is obtained by the remote authentication server performing the first security processing on the first control instruction, and sent to the second processor; Determine whether to execute the update control instruction according to the second timeliness information.

5. The method according to claim 2, It is characterized in that The measurement control result includes at least one of the following: measurement task creation result, measurement management execution result, and measurement operation result.

6. The method according to claim 5, It is characterized in that The measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a measurement task start instruction; The method further comprises: In response to the start measurement task instruction, start a preset measurement task; In response to a measurement result corresponding to the preset measurement task being abnormal, saving the measurement result and stopping the measurement; or, The method further comprises: In response to the start measurement task instruction, start a preset measurement task; In response to a measurement result corresponding to the preset measurement task being abnormal, saving the measurement result and stopping the measurement; The measurement result is sent to the remote authentication server as the measurement control result of the next measurement control instruction, wherein the next measurement control instruction includes the periodic remote authentication instruction.

7. A dynamic measurement method, It is characterized in that Based on remote authentication server, including: Get the basic measurement information of the target measurement host; Generate a first control instruction according to the measurement basic information; Performing a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: using a first encryption key to encrypt and / or using a first signature key to sign the instruction; Send the measurement control instruction to the target measurement host, so that the second processor of the target measurement host forwards it to the first processor, and the first processor performs the corresponding measurement control operation according to the measurement control instruction to obtain the measurement control result; the first processor is a security processor The second processor is a central processing unit.

8. The method according to claim 7, It is characterized in that The measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

9. The method according to claim 7, It is characterized in that After sending the measurement control instruction, the method further includes: Receive a security control result forwarded by the second processor of the target measurement host, the security control result is sent to the second processor after the first processor of the target measurement host performs a second security processing on the measurement control result, the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key.

10. The method according to claim 9, It is characterized in that Before sending the metric control instruction to the target metric host, the method further includes: Adding first timeliness information to the first control instruction; After receiving the security control result forwarded by the second processor of the target metric host, the method further includes: Performing a second security check on the security control result; the second security check includes: decrypting the security control result using a second decryption key and / or performing signature verification on the security control result using a second signature verification key, wherein the second processor has no right to know the second decryption key and the second signature verification key; When the second security check passes, obtain the metric control result according to the security control result; the metric control result carries the first aging information and the second aging information; Determine whether the metric control result is credible according to the first aging information, and save the second aging information.

11. The method according to claim 10, wherein, further comprising: When it is determined that the metric control result is credible, generate a first regulation instruction according to the metric control result; Perform the first security processing on the first regulation instruction to obtain an updated regulation instruction; Send the updated regulation instruction to the second processor of the target metric host.

12. The method according to claim 11, wherein, Before sending the updated regulation instruction to the second processor of the target metric host, the method further comprises: Generate third aging information and add the third aging information and the second aging information to the first regulation instruction.

13. The method according to claim 8, wherein, The metric control result includes at least one of the following: metric task creation result, metric management execution result, metric operation result.

14. The method according to claim 13, wherein, The metric control instruction is the metric task management instruction, and the metric task management instruction includes a start metric task instruction; The method further comprises: Send the next metric control instruction to the target metric host, wherein the next metric control instruction includes a periodic remote authentication instruction; In response to the metric operation result that the periodic remote authentication instruction is not received within a predetermined time, send exception handling information to the second processor of the target metric host; or, The method further comprises: Send the next metric control instruction to the target metric host, wherein the next metric control instruction includes a remote authentication instruction; Receive the metric operation result of the second processor of the target metric host forwarding the periodic remote authentication instruction, wherein the metric operation result is an exception of the metric result corresponding to a preset metric task; Send exception handling information to the second processor of the target metric host according to the received metric operation result.

15. A dynamic metric device, wherein, Based on the first processor of the metric host, the first The processor is a security processor, and the device includes: A first receiving module, configured to receive a metric control instruction forwarded by the second processor of the metric host; wherein, the metric control instruction is obtained by the remote authentication server performing first security processing on the first control instruction and sent to the second processor, and the first security processing includes: encrypting using a first encryption key and / or signing using a first signature key; the second processor is a central processing unit; a first checking module, configured to perform a first security check on the measurement control instruction corresponding to the first security processing, wherein the first security check comprises: decrypting the measurement control instruction using a first decryption key and / or performing signature verification on the measurement control instruction using a first signature verification key, wherein the second processor has no right to obtain the first decryption key and the first signature verification key; The first obtaining module is used to perform a corresponding measurement control operation according to the first control instruction in response to the first security check being passed, so as to obtain a measurement control result.

16. The device according to claim 15, It is characterized in that The measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

17. The device according to claim 15, It is characterized in that The device also includes: a second obtaining module, configured to, after the first obtaining module performs a corresponding measurement control operation according to the first control instruction to obtain a measurement control result, perform a second security processing on the measurement control result to obtain a security control result, wherein the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key; The first sending module is configured to send the security control result to the second processor and forward the result to the remote authentication server through the second processor.

18. The device according to claim 17, It is characterized in that The measurement control instruction carries first timeliness information; the device also includes: A first generating module, configured to generate second aging information after the first obtaining module performs a corresponding metric control operation according to the first control instruction to obtain a metric control result and before the second obtaining module performs a second security processing on the metric control result, and add the second aging information and the first aging information to the metric control result; The device also includes: a second receiving module, configured to receive, after the sending module sends the security control result to the second processor and forwards it to the remote authentication server through the second processor, an update control instruction made by the remote authentication server for the measurement control result, which is forwarded by the second processor, and the update control instruction carries the second timeliness information and the third timeliness information; wherein the update control instruction is obtained by the remote authentication server performing the first security processing on the first control instruction, and sent to the second processor; The first determination module is used to determine whether to execute the update control instruction according to the second timeliness information.

19. The device according to claim 16, It is characterized in that The measurement control result includes at least one of the following: measurement task creation result, measurement management execution result, and measurement operation result.

20. The device according to claim 19, It is characterized in that The measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a measurement task start instruction; The device also includes: A first starting module, configured to start a preset measurement task in response to the start measurement task instruction; A first saving module is configured to save the measurement result and stop the measurement in response to an abnormal measurement result corresponding to the preset measurement task; or The device also includes: A second starting module, configured to start a preset measurement task in response to the start measurement task instruction; A second saving module, configured to save the measurement result and stop the measurement in response to an abnormal measurement result corresponding to the preset measurement task; The second sending module is used to send the measurement result as the measurement control result of the next measurement control instruction to the remote authentication server, wherein the measurement control instruction includes a periodic remote authentication instruction.

21. A dynamic measurement device, It is characterized in that Based on remote authentication server, including: The first acquisition module is used to acquire basic measurement information of the target measurement host; A second generating module, configured to generate a first control instruction according to the measurement basic information; A third obtaining module is used to perform a first security processing on the first control instruction to obtain a measurement control instruction; wherein the first security processing includes: an instruction encrypted using a first encryption key and / or signed using a first signature key; The third sending module is used to send the measurement control instruction to the target measurement host, so that the second processor of the target measurement host forwards it to the first processor, and the first processor performs corresponding measurement control operations according to the measurement control instruction to obtain a measurement control result; the first processor is a security processor; the second processor is a central processor.

22. The device according to claim 21, It is characterized in that The measurement control instruction includes at least one of the following: a measurement task creation instruction, a measurement task management instruction, and a periodic remote authentication instruction.

23. The device according to claim 21, It is characterized in that The device also includes: A third receiving module is used to receive a security control result forwarded by the second processor of the target measurement host after the third sending module sends the measurement control instruction, and the security control result is sent to the second processor after the first processor of the target measurement host performs a second security processing on the measurement control result, and the second security processing includes: encrypting with a second encryption key and / or signing with a second signature key.

24. The device according to claim 23, It is characterized in that The device also includes: an adding module, configured to add first timeliness information to the first control instruction before the third sending module sends the measurement control instruction to the target measurement host; The device also includes: a second checking module, configured to perform a second security check on the security control result after the third receiving module receives the security control result forwarded by the second processor of the target metric host; the second security check includes: decrypting the security control result using a second decryption key and / or performing signature verification on the security control result using a second signature verification key, wherein the second processor has no right to know the second decryption key and the second signature verification key; A second acquisition module is used to acquire the measurement control result according to the security control result when the second security check passes; the measurement control result carries the first timeliness information and the second timeliness information; The third saving module is used to determine whether the measurement control result is credible according to the first timeliness information, and save the second timeliness information.

25. The device according to claim 24, It is characterized in that Also includes: A third generating module is used to generate a first control instruction according to the measurement control result when it is determined that the measurement control result is credible; a fourth obtaining module, configured to perform the first security processing on the first control instruction to obtain an updated control instruction; The fourth sending module is used to send the update control instruction to the second processor of the target metric host.

26. The device according to claim 25, It is characterized in that The device also includes: The fourth generating module is used to generate third timeliness information and add the third timeliness information and the second timeliness information to the first control instruction before the fourth sending module sends the update control instruction to the second processor of the target metric host.

27. The device according to claim 22, It is characterized in that The measurement control result includes at least one of the following: measurement task creation result, measurement management execution result, and measurement operation result.

28. The device according to claim 27, It is characterized in that The measurement control instruction is the measurement task management instruction, and the measurement task management instruction includes a measurement task start instruction; The device also includes: A fifth sending module, configured to send the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a periodic remote authentication instruction; a sixth sending module, configured to send exception handling information to the second processor of the target measurement host in response to not receiving the measurement operation result of the periodic remote authentication instruction within a predetermined time; or, The device comprises: a seventh sending module, configured to send the next measurement control instruction to the target measurement host, wherein the measurement control instruction includes a remote authentication instruction; A fourth receiving module is used to receive a measurement operation result of the periodic remote authentication instruction forwarded by the second processor of the target measurement host, wherein the measurement operation result is an abnormal measurement result corresponding to a preset measurement task; An eighth sending module is used to send exception handling information to the second processor of the target measurement host according to the received measurement operation result.

29. A dynamic measurement system, It is characterized in that include: A measurement host and a remote authentication server; wherein the measurement host includes a first processor and a second processor; The first processor is used to execute the dynamic measurement method described in claims 1-6, and the remote authentication server is used to execute the dynamic measurement method described in claims 7-14.

30. An electronic device, It is characterized in that include: A housing, a processor, a memory, a circuit board and a power supply circuit, wherein the circuit board is placed inside the space enclosed by the housing, and the processor and the memory are arranged on the circuit board; the power supply circuit is used to supply power to various circuits or devices of the above-mentioned electronic device; the memory is used to store executable program codes; the processor runs a program corresponding to the executable program code by reading the executable program code stored in the memory, so as to execute the method described in any one of claims 1 to 6 or 7 to 14.

31. A computer-readable storage medium, It is characterized in that The computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement the method of any one of the preceding claims 1-6 or 7-14.

Citation Information

Patent Citations

  • Safety starting method, management method, device and equipment for operating system

    CN111045743A

  • Method and device for preventing malicious rollback of virtual machine and electronic equipment

    CN113407299A