An identity authentication method and device based on application software fingerprints

By adopting the identity authentication method based on application software fingerprint in automotive parts, the problem of high data leakage risk is solved, the balance between data security and system performance is achieved, and the system coupling and cost is reduced.

CN114372255BActive Publication Date: 2025-07-22国投云网数字科技有限公司
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202111553586.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-12-17
Publication Date
2025-07-22
Estimated Expiration
2041-12-17

AI Technical Summary

Technical Problem

In the prior art, application software for automotive parts lacks the ability to authenticate identity legality, resulting in high risk of data leakage. Traditional methods such as Agent implantation and data encryption have problems such as easy attacks, large resource utilization, and affecting system performance.

Method used

The identity authentication method based on application software fingerprint is adopted, and the micro-isolated abstract middleware communicates between the Rich OS and the TEE system, query or generate application fingerprints for identity authentication, ensure legitimacy, and the isolation and adaptation of underlying resources are achieved through the micro-isolated abstract middleware.

Benefits of technology

Improves the data security of automotive parts, prevents data leakage, reduces system coupling and resource usage, ensures that user experience and performance are not affected, and reduces costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114372255B_ABST
    Figure CN114372255B_ABST
Patent Text Reader

Abstract

The present invention discloses an identity authentication method and device based on application software fingerprints, which solves the problem that the application programs in the existing methods can randomly access the data of devices, such as in-vehicle component data, resulting in data leakage in the devices. An identity authentication method based on application software fingerprints includes the following steps: when an application program initiates an access to the underlying data resources in the Rich OS system, query whether there is an authentication record for the application fingerprint in the micro-isolation abstraction middleware. If there is, allow access to the underlying data; otherwise, perform fingerprint query or generate a new fingerprint for the application program in the TEE system and complete the identity authentication. This application also includes a device for implementing the method. The present invention can be applied to automotive components to improve the data security of automotive components and avoid data leakage of automotive components.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of automotive data security, and in particular, to an identity authentication method and device based on application software fingerprints. Background Art

[0002] With the popularization and in-depth development of ADAS and intelligent cockpits, a large amount of personal data and data related to national security are stored in automotive components, and the application software running in automotive components lacks the ability to authenticate identity legality.

[0003] The existing methods are application behavior detection methods, that is, Agents are implanted in the kernel layer or ring3 layer of the OS, and hook technology is used. When all application software accesses the underlying system resources, the hook program will pull the application into the Agent for inspection (based on rules or models), and after the inspection, the program will be released. Its disadvantage is that it is easy to be directly deleted by attackers and has a large coupling with the OS version; it also includes data encryption methods, where all personal sensitive information stored in components is encrypted before storage. In this way, even if there is a leakage, attackers cannot restore the real data without obtaining the key. Its disadvantage is that it occupies a large amount of system resources and affects the normal response speed of the system. Summary of the Invention

[0004] The present invention provides an identity authentication method and device based on application software fingerprints to solve the problem of data leakage existing in the existing methods and devices.

[0005] To solve the above problems, the present invention is implemented as follows:

[0006] An embodiment of the present invention provides an identity authentication method based on application software fingerprints, including the following steps: when an application program initiates an access to underlying data resources in the Rich OS system, query whether there is an authentication record of the application fingerprint in the micro-isolation abstraction middleware. If there is, allow access to the underlying data; otherwise, query or generate a new application fingerprint for the application program in the TEE system to complete the identity authentication.

[0007] Preferably, the step of querying or generating a new application fingerprint for the application program in the TEE system to complete the identity authentication further includes: querying whether there is an authentication record of the application fingerprint in the authentication center. If there is, send an instruction to allow access to the underlying data to the Rich OS system through the micro-isolation abstraction middleware; if not, query whether the application fingerprint exists and whether the application fingerprint is valid in the fingerprint database. If it exists and is valid, update the authentication record to the authentication center, and at the same time, send an instruction to allow access to the underlying data to the Rich OS system through the micro-isolation abstraction middleware;

[0008] Otherwise, a corresponding new application fingerprint is generated, and identity authentication is completed in the TEE system. An instruction to allow access to the underlying data is sent to the Rich OS system through the micro-isolation abstraction middleware.

[0009] Preferably, the method further includes: communicating between the Rich OS system and the TEE system through the micro-isolation abstraction middleware.

[0010] Further, the method further includes: recording the application fingerprint authentication result through the micro-isolation abstraction middleware.

[0011] Further, the method further includes: when an application program initiates an access to the underlying data resources in the Rich OS system, after confirming the identity of the application program, it is further confirmed whether this access has the permission to access the data. If it has the access permission, the application program is allowed to access the underlying data; otherwise, the access to the corresponding underlying data is refused.

[0012] Preferably, the step of accessing the corresponding underlying data further includes: sending an instruction to call the underlying data interface to the underlying driver through the micro-isolation abstraction middleware.

[0013] Preferably, the step of generating the corresponding application fingerprint further includes: parameterizing the name, type, version number, process name, process ID, MD5, and / or application behavior of the application program, and generating a unique string corresponding to the application program through a specific function.

[0014] Preferably, the method further includes: periodically querying whether the application fingerprint is valid.

[0015] An embodiment of the present invention further provides an application software fingerprint identity authentication device, which uses the method according to any one of the embodiments of the present invention, and includes: a micro-isolation abstraction middleware, which is used to query whether there is an authentication record for the application fingerprint, and is also used to communicate between the Rich OS system and the TEE system, and is also used to implement micro-isolation and adaptation between the OS and the underlying layer in the Rich OS system; an authentication center, which is used to perform an application fingerprint identity authentication query according to the identity authentication query instruction sent by the micro-isolation abstraction middleware; a fingerprint database, which is used to store the application fingerprint corresponding to the application program; a fingerprint generation module, which is used to generate a corresponding application fingerprint according to the application program; a fingerprint status query module, which is used to query whether the status of the application fingerprint is valid.

[0016] Preferably, the micro-isolation abstraction middleware is further used for micro-isolation between the OS and the underlying layer.

[0017] The present application also proposes a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the method described in any one of the embodiments of the present application is implemented.

[0018] Furthermore, the present application also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the method described in any embodiment of the present application is implemented.

[0019] The above at least one technical solution adopted in the embodiments of the present application can achieve the following beneficial effects: The method of the present invention can strengthen the authentication and data control of application programs in automotive parts, ensure that data is not leaked by application programs, and improve the data security ability of automotive parts; The present invention combines the Rich OS and TEE systems to protect the fingerprint identity authentication function. Through the micro-isolation middleware technology, complete separation on the hardware is achieved, extremely low coupling is realized, security and services are separated independently, and on the basis of improving security, the user experience, performance, and cost are ensured not to be affected; The present invention performs fingerprint authentication based on application behavior through application programs, identifies the legitimacy of application software, and improves the control means for application software to access data. BRIEF DESCRIPTION OF THE DRAWINGS

[0020] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation to the present invention. In the drawings:

[0021] Figure 1 is a flowchart embodiment of the method of the present invention;

[0022] Figure 2 is a flowchart embodiment of the method of the present invention including instruction sending;

[0023] FIG. 3(a) is a connection schematic diagram of an embodiment of the device of the present invention;

[0024] FIG. 3(b) is an architecture schematic diagram of an embodiment of the device of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0025] To make the objectives, technical solutions, and advantages of the present invention clearer, the technical solutions of the present invention will be clearly and completely described below in conjunction with the specific embodiments of the present invention and the corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.

[0026] Automobile data security has become the most important issue for China's current regulatory agencies. In May 2021, the "Draft Provisions on the Administration of Automobile Data Security (for Comment)" issued by the Cyberspace Administration of China has been confirmed. With the popularization and in-depth development of ADAS (Advanced Driving Assistance System) and intelligent cockpits, a large amount of personal data and data related to national security will be stored in automobile components. Moreover, due to the networking of automobiles and the lack of the ability to authenticate the legality of the application software running in the components, attackers can arbitrarily implant application programs in the (Linux / Android system) of automobile components, such as DCU (Domain Control Unit) and IVI (In-Vehicle Infotainment) hosts, and directly access the sensitive data in the components. In addition, whether the legitimate applications in the components have the right to access personal sensitive data and transmit this data also needs to be concerned about.

[0027] Automobile components are mainly divided into two categories according to the processor type: MCU (Micro Control Unit) and MPU (Micro Process Unit). Among them, MCU is mainly developed using C code or RTOS (Real-time operating system), such as the airbag ECU (Electronic Control Unit); MPU mainly uses the Linux / Android system, such as DCU or IVI. Among these two types of components, the MPU components store the most personal sensitive information. Therefore, this invention mainly aims at the application software in this type of components to implement the identity authentication technology of the application software.

[0028] Normally, for an application to access underlying data, it needs to go through the OS (operating system) kernel and BSP (Board Support Package) to access the data in ROM or RAM. The whole process has no protection and control mechanism at all. As long as the application installed in this component can, in theory, access all the data stored in this component, and the whole access process is not subject to any control.

[0029] The Trusted Execution Environment (TEE) can guarantee computations that are not interfered with by the regular operating system, so it is called "trusted". This is achieved by creating a small operating system that can run independently in the TrustZone (secure world), which directly provides a few services in the form of system calls (handled directly by the TrustZone kernel). Additionally, the TrustZone kernel can securely load and execute small programs called "Trustlets (special software modules)" to add "trusted" functions in the extended model. Trustlet programs can provide secure services for insecure (normal world) operating systems such as Android. Communication between the Rich OS and the TrustZone is through an IPC (Inter-Process Communication) channel, and applications can call applications in the TrustZone through the IPC channel. The specific system architecture diagram is as follows. Currently, TEE is mainly widely used in the ARM architecture, and for automotive components of MPU, the ARM architecture accounts for the vast majority at present. Therefore, most MPU automotive components on the market currently support TEE.

[0030] After applying TEE, the entire system startup process and architecture are as follows. A total of 7 steps are required. Therefore, from the perspective of the entire startup process, TEE can ensure the security of the entire startup, and attackers cannot crack TEE at the driver level. The process of applying TEE is as follows: First, the system is powered on, and the PC pointer points to the internal chip BOOT ROM address and executes; Second, the BOOT ROM is loaded from an external storage device, the preloader is verified and execution is jumped to; Third, the preloader loads (verifies) the ATF (ARM Trusted Firmware), TEE OS, and LK from external storage and jumps to the ATF to execute; Fourth, the ATF jumps to the TEE OS to execute initialization and then returns to the ATF; Fifth, the ATF jumps to the LK to execute; Sixth, the LK loads and runs the Android Linux kernel; Seventh, the system loads the Modem.

[0031] Compared with the original Linux / Android system, three parts, namely the microkernel, TEE OS, and ATF, are added, as shown in the figure below. Without the TEE system, the preloader directly loads the Linux Kernel / Android. Therefore, the TEE system architecture ensures the trustworthiness of the entire system from the startup perspective.

[0032] Identity authentication technology is an effective solution generated by the process of confirming the identity of an operator. It is a process of verifying whether the true identity of a subject matches the identity it claims. It can be divided into authentication between users and hosts and authentication between hosts. Traditional identity authentication technologies include static passwords, SMS passwords, dynamic passwords, digital signatures, biometric identification, X.509 certificates, etc. This invention will refer to, combine, and draw on these authentication technologies to form a set of identity authentication technologies for application software suitable for MPU automotive parts.

[0033] Existing identity authentication technologies include: implanting an Agent (application program) in the kernel layer or ring3 layer of the OS and using hook technology. When all application software accesses system underlying resources, the hook program will pull the application into the Agent for inspection (based on rules or models), and release the program after inspection. If an exception occurs, the Agent can directly terminate the process of the application.

[0034] The disadvantages are as follows: First, since the Agent is deployed in the OS kernel layer or ring3 layer and lacks a protection scheme, it is very easy to be directly deleted by attackers. Even if a protection program is placed at the BSP layer to increase the possibility of protecting the Agent, if the attacker understands this protection scheme, they can still delete the protection program at the BSP layer. Second, the Agent is affected by the OS version and has a very high coupling with the OS kernel. If the kernel is updated, the Agent also needs to be synchronized for adaptation and update. Since the OS kernel updates relatively quickly, it is very easy to forget to update the Agent, resulting in a situation where it does not match the new OS kernel, thus affecting the entire automotive parts.

[0035] Existing identity authentication technologies also include: data encryption. In theory, data encryption technology can encrypt all personal sensitive information stored in parts before storage. In this way, even if there is a leakage, attackers cannot restore the real data without obtaining the key. Data encryption has the following disadvantages: First, it occupies a very large amount of system resources and increases costs. With the diversification of data volume and data types, simple data encryption is suitable for a small amount of text-type data. However, for data such as pictures and videos, huge operations will occupy the resources of the CPU and memory. Parts manufacturers must replace CPUs with higher performance and larger memory to cope with this, thus greatly increasing the costs of parts. Second, it affects the normal response speed of the system and reduces the user experience. When the system uses encrypted data, it needs to decrypt it first, and decryption takes a certain amount of time. Accumulatively, it will affect the response time of normal application software, resulting in a reduction in the user experience.

[0036] The innovation points of the present invention are as follows: First, the present invention is an identity authentication based on the application behavior fingerprints of automotive parts. All applications in automotive parts are implemented through code, and the behaviors are fixed and unique. The present invention uses the application behavior as the "fingerprint" and further as an application identity authentication factor. Through the "fingerprint", applications can be easily distinguished. On the one hand, it is used for identity authentication, and at the same time, it can also facilitate data access control. Second, the present invention uses a micro-isolation abstract middleware for communication and function interaction between the Rich OS system and the TEE system, which increases the adaptation to the underlying layer and the OS, and also requires an increase in the corresponding information security capabilities.

[0037] The following will, in conjunction with the accompanying drawings, detail the technical solutions provided by each embodiment of the present invention.

[0038] Figure 1 This is an embodiment of the method flow of the present invention, which can be used for the identity authentication of automotive part application software. As an embodiment of the present invention, a fingerprint identity authentication method for application software specifically includes the following steps 101 to 102:

[0039] Step 101: When an application program initiates an access to the underlying data resource in the Rich OS system, query whether there is an authentication record of the application fingerprint in the micro-isolation abstract middleware.

[0040] In step 101, preferably, when an application program initiates an access to the underlying data resource in the Rich OS system, after confirming the identity of the application program, then confirm whether this access has the permission to access the data. If it has the access permission and there is an authentication record of the application fingerprint in the micro-isolation abstract middleware, allow the application program to access the underlying data; otherwise, reject the access to the corresponding underlying data.

[0041] Step 102: If there is an authentication record of the application fingerprint in the micro-isolation abstract middleware, allow access to the corresponding underlying data; otherwise, query or generate a new application fingerprint for the application program in the TEE system to complete the identity authentication.

[0042] In step 102, further, when querying or generating a new application fingerprint for the application program in the TEE system to complete the identity authentication, if the identity authentication condition is met, send a request to the Rich OS system through the micro-isolation abstract middleware to allow access to the corresponding underlying data; if the identity authentication condition is not met, send an identity authentication request to the application program in the Rich OS system.

[0043] In steps 101 and 102, communication is carried out between the Rich OS system and the TEE system through the micro-isolation abstraction middleware. The micro-isolation abstraction middleware can be used to implement communication and functional interaction between the two systems, isolation and adaptation of underlying resources (drivers, hardware resources), and isolation and adaptation at the operating system level, so as to effectively isolate applications and data and perform effective access control.

[0044] The embodiments of the present invention can bring the following effects. First, it realizes the identity authentication of application software in MPU automotive components and sets permissions for the application software to ensure that not all application software can access sensitive data in the components. These sensitive data include personal data and may also include sensitive data related to national security, solving the problem of data leakage in the device caused by random access to automotive component data.

[0045] Second, the application fingerprint authentication technology adopted by the present invention realizes the identity authentication of application software. Traditional authentication technologies usually use X.509 certificates, but this certificate needs to rely on the PKI system and requires online CA authentication. Such a technical solution is also not applicable to devices in the automotive internal network. Therefore, the embodiments of the present invention form an application fingerprint by locking application behaviors, processes, MD5, etc., which is suitable for the automotive field.

[0046] Third, the embodiments of the present invention can also prevent the protection program from being deleted and tampered with. Since the authentication protection program is placed in the TEE OS, attackers cannot tamper with any application in the TEE OS whether it is running or stored. Because if the TEE OS is tampered with during storage, ATF cannot pass the verification and cannot be started when starting.

[0047] Fourth, through the micro-isolation middleware, the embodiments of the present invention can decouple the coupling between the Linux / Android OS and the underlying hardware, solving the problem that in the Rich OS system, due to updates, relevant security functions need to be re-adapted to the entire OS and the underlying hardware.

[0048] Fifth, the embodiments of the present invention do not affect the performance of the existing system and the response time of application programs, and avoid increasing the component cost. Because the TEE OS and the Rich OS are independent in terms of hardware, security applications do not consume the hardware resources of the Rich OS.

[0049] Figure 2 For the method flow embodiment of the present invention including instruction sending, a fingerprint identity authentication process for application software of automotive components based on micro-isolation is provided. As an embodiment of the present invention, a fingerprint identity authentication method for application software specifically includes the following steps 201 to 215:

[0050] Step 201: The application sends a request to the operating system to access the underlying data.

[0051] Step 202: The operating system requests to access the micro-isolation abstraction middleware.

[0052] Step 203: Query whether there is an authentication record for the application fingerprint through the micro-isolation abstraction middleware.

[0053] Step 204: If there is an authentication record for the application fingerprint in the micro-isolation abstraction middleware, call the underlying data interface through the BSP.

[0054] Step 205: Access the underlying data resources according to the instruction to call the underlying data interface.

[0055] In steps 201 - 205, when the application wants to access the underlying data resources, it needs to send a data access request to the operating system (Linux / Android). After receiving the request, the operating system directly sends an access request to the micro-isolation abstraction middleware. After receiving the request, the micro-isolation abstraction middleware confirms whether the application has been authenticated and passed, and at the same time confirms whether the application has the permission to access data this time. If it passes, it directly allows the application to call the underlying data interface of the BSP. At this time, the application can directly access the data stored in the ROM or RAM. If the micro-isolation abstraction middleware finds that the application does not have an authentication record, it sends a request to call the authentication center to the TEE trusted execution environment to authenticate the application.

[0056] It should be noted that a part of the application fingerprint authentication records are stored in the micro-isolation abstraction middleware, such as the application fingerprints corresponding to the applications that frequently access the underlying data recently, which avoids the process of the application having to perform identity authentication in the TEE system every time it accesses, facilitating the application to quickly access the underlying data. It should also be noted that the number of application fingerprint authentication records stored in the micro-isolation abstraction middleware is not limited.

[0057] Step 206: If there is no authentication record for the application fingerprint in the micro-isolation abstraction middleware, call the authentication center interface of the TEE OS through the micro-isolation abstraction middleware.

[0058] In step 206, the micro-isolation abstraction middleware plays a role in communicating between the Rich OS system and the TEE OS system.

[0059] Step 207: Query whether there is an authentication record for the application fingerprint in the authentication center.

[0060] In step 207, a part of the authentication records of the application fingerprints is stored in the authentication center, which facilitates a quick judgment on the existence of the application fingerprints, avoids traversing the fingerprint database to query the authentication records of the application fingerprints every time, and speeds up the speed at which the application program accesses the underlying data.

[0061] Step 208: If the authentication record of the application fingerprint in the authentication center exists, then authenticate this time through the micro-segmentation abstraction intermediate record.

[0062] In step 208, the micro-segmentation abstraction middleware can record the latest authentication result of the authentication center.

[0063] In step 208, after authenticating this time through the micro-segmentation abstraction intermediate record, transfer to steps 204 and 205.

[0064] Step 209: If the authentication record of the application fingerprint in the authentication center does not exist, then query whether the application fingerprint exists through the fingerprint database.

[0065] In step 209, all authenticated application fingerprints are stored in the fingerprint database, and traversing the fingerprint database can obtain the authentication result of the application fingerprint of the current application program.

[0066] Step 210: If the authentication record of the application fingerprint exists in the fingerprint database query, then query the application fingerprint status through the fingerprint status query module.

[0067] In step 210, the fingerprint status query module queries whether the status of the fingerprint is active (valid) or cancelled (invalid). The management center can regularly check whether the fingerprint status of each application program is in an active state. If it is not in an active state, the management center needs to prevent the application from accessing data subsequently.

[0068] Step 211: If the application fingerprint status is valid, then update the application fingerprint through the authentication center.

[0069] In step 211, after completing the update of the application fingerprint, transfer to step 208.

[0070] Step 212: If at least one of the following conditions is met: the application fingerprint status is invalid, the authentication record of the application fingerprint does not exist in the fingerprint database query, then request to generate an application fingerprint through the fingerprint generation module.

[0071] In step 212, the step of generating the corresponding application fingerprint further includes: parameterizing the name, type, version number, process name, process ID, MD5, and / or application behaviors of the application, such as calling interfaces, accessed file paths, file operations, network access, etc., and generating a unique string corresponding to the application through a specific function, such as SHA256 or entropy. This string is the application fingerprint of the application.

[0072] Step 213: Initiate an application fingerprint generation request through the micro-isolation abstraction middleware.

[0073] Step 214: Invoke the application fingerprint generation interface through the operating system.

[0074] Step 215: Collect the data required for generating the application fingerprint through the application.

[0075] In steps 206 to 215, further consider whether the application has the permission to access the underlying data: when the trusted execution environment receives the authentication center call request from the micro-isolation abstraction middleware, and after the authentication center receives the request, it queries whether the application has an application fingerprint in the authentication center. If the authentication center finds the application fingerprint, it returns the application fingerprint to the micro-isolation abstraction middleware. The micro-isolation abstraction middleware records this authentication and at the same time confirms that the application has the permission to access the data, and then allows the application to call the underlying data. If the authentication center cannot find the application fingerprint, it sends a request to the fingerprint database. The fingerprint database queries. If it can find the application fingerprint, it first goes to the fingerprint status query module to query whether the status of the application fingerprint is valid. If it is valid, it updates the application fingerprint to the authentication center. At the same time, the authentication center sends the application fingerprint information to the micro-isolation abstraction middleware, records this authentication, and at the same time allows the application to access the underlying data. If the application fingerprint is not in the fingerprint database either, or the application fingerprint in the fingerprint database has an invalid status, then the fingerprint generation module will be called to let the application regenerate a new application fingerprint. The fingerprint generation module sends it to the micro-isolation abstraction middleware, and the micro-isolation abstraction middleware directly sends it to the application through the OS, allowing the application to initiate the fingerprint generation operation and perform identity authentication.

[0076] Traditional identity authentication is achieved through methods such as X.509 certificates, human biometrics, usernames, and passwords. There has never been identity authentication through the "behavior" of users. At most, violations are judged through behavior. For example, the relatively popular UEBA judges whether a behavior is an attack through abnormal behaviors during use. The applications in automotive parts are all implemented through code, and the behaviors are fixed and specific. For example, a navigation application will only access map data and will never suddenly access data in a music application. Therefore, using application behavior as a "fingerprint" as an application identity authentication factor has strong characteristics. Applications can be easily distinguished through the "fingerprint", which can be used for identity authentication on the one hand and also facilitate data access control on the other hand.

[0077] Figure 3(a) is a connection schematic diagram of an embodiment of the device of the present invention, and Figure 3(b) is an architecture schematic diagram of an embodiment of the device of the present invention. A software application fingerprint identity authentication system that can use the method of any embodiment of the present invention includes: a micro-isolation abstraction middleware 1, an authentication center 2, a fingerprint database 3, a fingerprint generation module 4, and a fingerprint status query module 5.

[0078] Figure 3(a) provides a schematic diagram of the connection relationships of the various modules of the device of the present invention. Figure 3(b) provides the architecture of the various modules of the device of the present invention in the Rich OS system and the TEE system. Among them, the authentication center, the fingerprint database, the fingerprint generation module, and the fingerprint status query module are placed in the TEE OS. At the same time, a micro-isolation abstraction layer middleware is inserted between the two systems (the Rich system and the trusted execution system) to protect and isolate the underlying resources, realize communication between the two systems, and also realize the adaptation of the operating systems between the two systems.

[0079] In an embodiment of the present invention, the micro-isolation abstraction middleware is used to query whether there is an authentication record for the application fingerprint, and is also used to communicate between the Rich OS system and the TEE system, and is also used to perform access control on the data in automotive parts and perform micro-isolation and adaptation between the OS and the underlying layer in the Rich OS system.

[0080] The authentication center is used to perform an application fingerprint identity authentication query according to the identity authentication query instruction sent by the micro-isolation abstraction middleware.

[0081] The fingerprint database is used to store the application fingerprints corresponding to application programs.

[0082] The fingerprint generation module is used to generate the corresponding application fingerprint according to the application program.

[0083] The fingerprint status query module is used to query whether the status of the application fingerprint is valid.

[0084] Specifically, the certification center is responsible for authenticating the fingerprints of application programs, confirming the identities of the application programs, and notifying the control center of the authentication results, whether to allow or block.

[0085] The fingerprint database is used to store the fingerprints of trusted application programs. After the system restarts, all application programs need to be re-authenticated. The fingerprint generation module is used to generate the fingerprints of application programs.

[0086] The fingerprint generation module needs to parameterize in advance the names, process names, MD5s, application behaviors (such as calling interfaces, accessed file paths, file operations, network access, etc.) of the application programs for which fingerprints are to be generated, and generate a unique string corresponding to the application program through specific functions such as SHA256 or entropy. This string is the fingerprint of the application program.

[0087] The fingerprint status query module queries whether the status of the fingerprint is active or deactivated. The control center needs to regularly check whether the fingerprint status of each application program is active. If it is not active, the control center needs to prevent the application from accessing data subsequently.

[0088] The micro-segmentation abstraction middleware is used to implement communication and functional interaction between two systems, isolation and adaptation of underlying resources (driver programs, hardware resources), and isolation and adaptation at the operating system level. Thus, it effectively isolates applications and data and performs effective access control.

[0089] The micro-segmentation abstraction middleware is also used to implement any one of the following functions:

[0090] BSP underlying driver encapsulation: Encapsulate the current mainstream underlying driver programs in the automotive industry, such as the driver programs of mainstream chips such as NXP, Infineon, Renesas, and TI, to ensure the underlying adaptation of the micro-segmentation abstraction middleware.

[0091] OS encapsulation: Encapsulate the current relatively mainstream Linux / Android system kernels, and the micro-kernel abstraction middleware switches the API encapsulation interfaces according to different versions.

[0092] Data resource access permission control: Based on the behavior permissions of applications, perform access control on data resources and do not allow applications to access data resources outside their access permissions.

[0093] Auditing: Record the logs of application data access, identity authentication, etc., and at the same time implement log auditing and report anomalies.

[0094] Embodiments of the present invention mainly target the TEE system. In terms of implementation, the TEE needs to be transformed and developed. Four Trustlets, namely, a certification center, a fingerprint database, a fingerprint generation module, and a fingerprint status query module, need to be developed for the TEE OS. At the same time, the micro-isolation abstraction middleware needs to be developed to increase the adaptation to the underlying layer and the OS, and corresponding information security capabilities also need to be added. Since the entire startup process is based on the trusted computing system provided by ARM and has a complete trusted chain, it can ensure trust at each step during startup, thus ensuring the trust and security of the entire system to the greatest extent.

[0095] Therefore, the present application also proposes a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the method described in any embodiment of the present application.

[0096] Furthermore, the present application also proposes an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, it implements the method described in any embodiment of the present application.

[0097] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0098] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as the combination of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for implementing the specified functions in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0099] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including an instruction device, and the instruction device implements the process inFigure 1 one or more processes and / or blocks Figure 1 functions specified in one or more blocks.

[0100] These computer program instructions may also be loaded onto a computer or other programmable data processing apparatus, causing a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, so that the instructions executed on the computer or other programmable apparatus provide steps for implementing the functions specified in one Figure 1 one or more processes and / or blocks Figure 1 or more processes and / or blocks.

[0101] In a typical configuration, a computing device includes one or more processors (CPUs), an input / output interface, a network interface, and memory.

[0102] The memory may include non-permanent memory in a computer-readable medium, random access memory (RAM) and / or non-volatile memory such as read-only memory (ROM) or flash memory (flash RAM). The memory is an example of a computer-readable medium.

[0103] It should also be noted that the term "comprising", "including" or any other variation thereof is intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or apparatus. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or apparatus comprising the element.

[0104] The above are only embodiments of the present invention and are not intended to limit the present invention. For those skilled in the art, the present invention may have various modifications and changes. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included within the scope of the claims of the present invention.

Claims

1. An identity authentication method based on the fingerprint of application software, characterized in that, It includes the following steps: When an application initiates an access to underlying data resources in the Rich OS system, query in the micro-isolation abstraction middleware whether there is an authentication record for the application fingerprint. If there is, allow access to the underlying data; otherwise, query or generate a new application fingerprint for the application in the TEE system to complete the identity authentication; The step of accessing the underlying data further includes: sending an instruction to call the underlying data interface to the underlying driver through the micro-isolation abstraction middleware; The step of querying or generating a new application fingerprint for the application in the TEE system to complete the identity authentication further includes: Query whether there is an authentication record of the application fingerprint in the authentication center. If there is, send an instruction to allow access to the underlying data to the Rich OS system through the micro-isolation abstraction middleware; If not, query in the fingerprint database whether the application fingerprint exists and whether the application fingerprint is valid. If it exists and is valid, update the authentication record to the authentication center, and at the same time send an instruction to allow access to the underlying data to the Rich OS system through the micro-isolation abstraction middleware; Otherwise, let the application generate a corresponding new application fingerprint, complete the identity authentication in the TEE system, and send an instruction to allow access to the underlying data to the Rich OS system through the micro-isolation abstraction middleware.

2. The identity authentication method based on the fingerprint of the application software according to claim 1, wherein The method further includes: Communicating between the Rich OS system and the TEE system through the micro-isolation abstraction middleware.

3. The method for identity authentication based on the fingerprint of an application software according to claim 1, wherein The method further includes: Recording the application fingerprint authentication result through the micro-isolation abstraction middleware.

4. The identity authentication method based on the fingerprint of the application software according to claim 1, characterized in that, The method further includes: When an application initiates an access to underlying data resources in the Rich OS system, after confirming the identity of the application, then confirm whether this access has the permission to access the data. If it has the access permission, allow the application to access the underlying data; otherwise, reject the access to the corresponding underlying data.

5. The method for identity authentication based on the fingerprint of an application software according to claim 1, characterized in that, The step of generating the corresponding application fingerprint further includes: Parameterize the name, type, version number, process name, process number, MD5 and / or application behavior of the application, and generate a unique string corresponding to the application through a specific function.

6. The identity authentication method based on the fingerprint of the application software according to claim 1, wherein The method further includes: Regularly query whether the application fingerprint is valid.

7. An identity authentication device based on the fingerprint of application software, using the method according to any one of claims 1 to 6, characterized in that It includes: A micro-isolation abstraction middleware, which is used to query whether there is an authentication record for the application fingerprint, communicate between the Rich OS system and the TEE system, and is also used to implement micro-isolation and adaptation between the OS and the underlying layer in the Rich OS system; An authentication center, which is used to perform identity authentication of the application program fingerprint according to the identity authentication query instruction sent by the micro-isolation abstraction middleware; A fingerprint database, which is used to store the application fingerprint corresponding to the application program; A fingerprint generation module, which is used to generate a corresponding application fingerprint according to the application program; A fingerprint status query module, which is used to query whether the status of the application fingerprint is valid.

8. The identity authentication device based on the fingerprint of the application software according to claim 7, wherein, The micro-isolation abstraction middleware is also used for micro-isolation between the OS and the underlying layer.

Citation Information

Patent Citations

  • Method of accessing secure element (SE), terminals and computer-readable storage medium

    CN108171063A