A security defense method, device, equipment and storage medium
By verifying the source of the target option adjustment instructions in the security area of the central processor, ensuring that only instructions from the user area can perform corresponding adjustment operations, solving the system instability and security problems caused by voltage and frequency exceeding the range in the prior art, and achieving higher system security.
Patent Information
- Application Number
- CN202210259021.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-03-16
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2042-03-16
AI Technical Summary
In the prior art, when the voltage and frequency of the CPU and memory exceed the normal range, the system may be instable, increasing the risk of attacks, guard programs being bypassed or keys being stolen.
By receiving the encrypted target option adjustment instructions in the secure area of the central processor, decryption is used to use the pre-stored key and verify that the source of the instruction is the user area. Only when the instruction source is the user area, the locally stored random code is sent to the option control unit for verification, and the target option adjustment instruction is executed after the verification is successful.
It effectively reduces the insecurity caused by malicious programs, ensures that only legal instructions from the user area can perform corresponding adjustment operations, and enhances the security of the system.
Smart Images

Figure CN114817909B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the fields of computer hardware, software, and information security, and particularly to a security defense method, device, equipment, and storage medium. Background Art
[0002] Currently, chips such as the CPU (Central Processing Unit / Processor) and memory have their normal operating voltage and frequency ranges in physical design. Beyond the normal range, there may be situations such as excessive power consumption and burnout, or unstable timing / logical operations or system crashes. Instability may lead to problems such as being attacked, the protection program being bypassed, or the key being stolen.
[0003] The control of voltage / frequency is achieved through intelligent hardware circuits on the motherboard and memory modules. The voltage / frequency is adjusted by modifying the parameters in the corresponding CPU registers, the addresses or ports of the relevant motherboard circuits, and the corresponding parameter areas of the memory through software such as driver programs. For system security, such operations often require the highest system privileges, and even adjustments are made in the BIOS (Basic Input Output System) firmware. However, firmware, Trojans, or malicious programs that break into the OS (Operating System) to obtain system privileges can configure the voltage / frequency, resulting in system insecurity. Summary of the Invention
[0004] In view of this, the purpose of the present invention is to provide a security defense method, device, equipment, and storage medium that can verify the source of the received target option adjustment instruction to reduce the possibility of system insecurity caused by being attacked by malicious programs. The specific solutions are as follows:
[0005] In a first aspect, the present application discloses a security defense method applied to a security area in a central processing unit. The central processing unit further includes a user area. The method further includes:
[0006] Receiving an encrypted target option adjustment instruction, and decrypting the encrypted target option adjustment instruction using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area;
[0007] When the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification;
[0008] Receive the second random code sent by the option control unit and store the second random code for replacing the first random code in the local storage area.
[0009] Optionally, receiving the encrypted target option adjustment instruction, so as to perform a decryption operation on the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area, includes:
[0010] Receive the encrypted target option adjustment instruction and perform a decryption operation on the encrypted target option adjustment instruction by using the pre-stored public key to obtain a corresponding decryption result;
[0011] Based on the decryption result, determine whether the source of the target option adjustment instruction is the user area.
[0012] Optionally, the determining whether the source of the target option adjustment instruction is the user area based on the decryption result includes:
[0013] When the decryption result is successful decryption, it is determined that the source of the target option adjustment instruction is the user area, and then the step of sending the first random code stored in the local storage area to the option control unit is started;
[0014] When the decryption result is decryption failure, it is determined that the source of the target option adjustment instruction is not the user area, and the process ends.
[0015] Optionally, when the source of the encrypted target option adjustment instruction is the user area, sending the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification, includes:
[0016] When the source of the encrypted target option adjustment instruction is the user area, send the first random code stored in the local storage area to the option control unit, so that the option control unit compares the first random code with the third random code stored in the option control unit, and executes the target option adjustment instruction when the comparison result is the same.
[0017] Optionally, before sending the first random code stored in the local storage area to the option control unit when the source of the encrypted target option adjustment instruction is the user area, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification, further includes:
[0018] After power-on is completed, communicate with the option control unit and obtain the target random code generated by the option control unit during power-on startup;
[0019] Store the target random code in the local storage area to obtain the first random code; and store the target random code in the option control unit to obtain the third random code.
[0020] Optionally, when the source of the encrypted target option adjustment instruction is the user area, send the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification, including:
[0021] When the source of the encrypted target option adjustment instruction is the user area, send the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code;
[0022] After successful verification, control the preset driver to modify the corresponding parameters in the option control unit so as to execute the target option adjustment instruction.
[0023] Optionally, the receiving the second random code sent by the option control unit and storing the second random code for replacing the first random code in the local storage area includes:
[0024] Receive the second random code sent by the option control unit; the second random code is the random code generated by the option control unit after executing the target option adjustment instruction;
[0025] Replace the first random code with the second random code so as to perform a verification operation using the second random code and the random code stored in the option control unit after receiving the encrypted target option adjustment instruction next time.
[0026] In a second aspect, the present application discloses a security defense device, which is applied to a security area in a central processing unit. The central processing unit further includes a user area, and further includes:
[0027] An instruction receiving module, configured to receive an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area;
[0028] A random code verification module, which is used to send the first random code stored in the local storage area to the option control unit when the source of the encrypted target option adjustment instruction is the user area, so that the option control unit verifies the first random code and executes the target option adjustment instruction after the verification is successful;
[0029] A random code update module, which is used to receive the second random code sent by the option control unit and store the second random code used to replace the first random code in the local storage area. In a third aspect, the present application discloses an electronic device, including:
[0030] A memory, which is used to save a computer program;
[0031] A processor, which is used to execute the computer program to implement the steps of the security defense method disclosed above.
[0032] In a fourth aspect, the present application discloses a computer-readable storage medium, which is used to store a computer program; wherein, when the computer program is executed by a processor, the security defense method disclosed above is implemented.
[0033] It can be seen that the present application provides a security defense method, including: receiving an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area; when the source of the encrypted target option adjustment instruction is the user area, sending the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after the verification is successful; receiving the second random code sent by the option control unit and storing the second random code used to replace the first random code in the local storage area. Thus, in the present application, the source of the received target option adjustment instruction is verified through the security area in the central processing unit, and it is judged whether the source of the target option adjustment instruction is the user area in the central processing unit according to the verification result. Only when the instruction source is the user area can the corresponding adjustment operation be performed, thereby reducing the possibility of system insecurity caused by being attacked by malicious programs. Description of the Drawings
[0034] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only the embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained according to the provided drawings without creative efforts.
[0035] Figure 1 Flowchart of a security defense method disclosed in this application;
[0036] Figure 2 Schematic diagram of a specific security defense method disclosed in this application;
[0037] Figure 3 Flowchart of a specific security defense method disclosed in this application;
[0038] Figure 4 Schematic diagram of the structure of the security defense device provided by this application;
[0039] Figure 5 Structural diagram of an electronic device provided by this application. Specific implementation manners
[0040] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.
[0041] Currently, when chips such as CPUs and memories are physically designed, they have a normal operating voltage and frequency range. Beyond the normal range, there may be situations such as excessive power consumption and burnout, or unstable timing / logical operations, or system crashes. Instability may lead to being attacked, the protection program being bypassed, or the key being stolen. For this reason, this application provides a security defense method that can avoid system security problems caused by being attacked by malicious programs.
[0042] An embodiment of the present invention discloses a security defense method. Refer to Figure 1 As shown, it is applied to the secure area in the central processing unit. The central processing unit also includes a user area. The method further includes:
[0043] Step S11: Receive an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area.
[0044] In this embodiment, when the security area in the central processing unit receives the encrypted target option adjustment instruction, the encrypted target option adjustment instruction is decrypted using the pre-stored public key to obtain the corresponding decryption result, and then based on the decryption result, it is determined whether the source of the target option adjustment instruction is the user area. It can be understood that there is a pre-stored public key in the security area of the central processing unit. When the security area of the central processing unit receives an encrypted target option adjustment instruction, the encrypted target option adjustment instruction is first decrypted using the pre-stored public key to obtain the corresponding decryption result. When the decryption result is successful decryption, it is determined that the source of the target option adjustment instruction is the user area. It should be noted that before the user area in the central processing unit sends the target option adjustment instruction to the security area, the target option adjustment instruction is first encrypted using the private key corresponding to the public key. Therefore, when the security area in the central processing unit successfully decrypts the encrypted target option adjustment instruction using the public key, it indicates that the source of the target option adjustment instruction is the user area in the central processing unit. Additionally, when the decryption result is decryption failure or the target option adjustment instruction is not encrypted, it indicates that the source of the target option adjustment instruction is not the user area, and then the target option adjustment instruction is not executed and the process ends.
[0045] Step S12: When the source of the encrypted target option adjustment instruction is the user area, send the first random code stored in the local storage area to the option control unit so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification.
[0046] In this embodiment, when the source of the encrypted target option adjustment instruction is the user area, the first random code stored in the local storage area is sent to the option control unit so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification. It can be understood that the first random code is stored in the local storage area in the security area. When the source of the encrypted target option adjustment instruction is the user area, the first random code is sent to the option control unit for verification, and the target option adjustment instruction is executed after successful verification to achieve the corresponding parameter adjustment. The first random code is a one-time random code, that is, the first random code has and only has one usage. After the security area in the central processing unit sends the first random code to the option control unit, the first random code becomes invalid regardless of whether the verification in the option control unit is successful. It should be noted that the first random code remains valid as long as it is not used and will not become invalid due to factors such as time.
[0047] Specifically, such asFigure 2 As shown, the central processing unit adopts a dual architecture, dividing the central processing unit into a user area and a security area. The security area is physically isolated and not vulnerable to attacks from the user area. When the target adjustment instruction is a voltage / frequency adjustment instruction, the arrow marked with a cross on the left side of the figure directly connects the user area and the voltage / frequency control unit, indicating that in the prior art, the user area directly communicates with the voltage / frequency control unit, and there may be a situation where the voltage / frequency control unit executes the target option adjustment instruction sourced from a malicious program. In this application, the security area of the central processing unit receives the voltage / frequency adjustment instruction and then decrypts the encrypted voltage / frequency adjustment instruction using a pre-stored key, that is, the signature verification operation in the figure. If the source of the voltage / frequency adjustment instruction is the user area of the central processing unit, the random code stored in the security area is sent to the voltage / frequency control unit for comparison. After successful comparison, the voltage / frequency adjustment instruction is executed. It can be understood that if the user area sends the voltage / frequency adjustment instruction to the security area, the target option adjustment instruction is signed using the private key before sending, so that the security area can perform signature verification. As shown, the control of voltage / frequency is achieved through the intelligent hardware circuits on the motherboard and the memory module.
[0048] Step S13: Receive the second random code sent by the option control unit and store the second random code for replacing the first random code in the local storage area.
[0049] In this embodiment, when the option control unit successfully verifies the first verification code and executes the target option adjustment instruction, it receives the second random code sent by the option control unit and stores the second random code for replacing the first random code in the local storage area. It can be understood that since the first random code has become invalid after the security area in the central processing unit sends the first random code to the option control unit, it is necessary to store the second random code sent by the option control unit received in the local storage area and use the second random code to overwrite the first random code, so that only one random code is still stored in the local storage area. It should be noted that the second random code has the same characteristics as the first random code.
[0050] It can be seen that the present application provides a security defense method, including: receiving an encrypted target option adjustment instruction, decrypting the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area; when the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification; receiving a second random code sent by the option control unit and storing the second random code for replacing the first random code in the local storage area. Thus, in the present application, the source of the received target option adjustment instruction is verified through the security area in the central processing unit, and it is judged whether the source of the target option adjustment instruction is the user area in the central processing unit according to the verification result. Only when the instruction source is the user area can the corresponding adjustment operation be performed, thereby reducing the possibility of system insecurity caused by being attacked by malicious programs.
[0051] See Figure 3 As shown, an embodiment of the present invention discloses a security defense method. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution.
[0052] Step S21: Receive an encrypted target option adjustment instruction, decrypt the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area.
[0053] Step S22: Communicate with the option control unit after power-on is completed and obtain a target random code generated by the option control unit during power-on startup.
[0054] In this embodiment, after the power-on of the security area in the central processing unit is completed, communicate with the option control unit to obtain a one-time target random code generated by the option control unit according to a preset random code generation algorithm while powering on. It can be understood that it is safe at the moment when it is determined that the power-on of the security area in the central processing unit is completed, and the obtained target random code is an accurate random code at this time. It should be noted that the target random code is equivalent to a Token authentication number, similar to a short message verification code.
[0055] Step S23: Store the target random code in the local storage area to obtain the first random code; and store the target random code in the option control unit to obtain the third random code.
[0056] In this embodiment, after the security area in the central processing unit obtains the target random code, the target random code is stored in the local storage area to obtain the first random code. It can be understood that after the option control unit generates the target random code, the target random code is simultaneously stored in the preset storage area of the option control unit to obtain the third random code.
[0057] Step S24: When the source of the encrypted target option adjustment instruction is the user area, the first random code stored in the local storage area is sent to the option control unit, so that the option control unit compares the first random code with the third random code stored in the option control unit, and when the comparison result is the same, the target option adjustment instruction is executed.
[0058] In this embodiment, when the source of the encrypted target option adjustment instruction is the user area, the first random code stored in the local storage area is sent to the option control unit, so that the option control unit compares the first random code with the third random code stored in the option control unit. It can be understood that the option control unit compares the first random code with the third random code. If the two random codes are the same, the comparison is successful, indicating that the target option adjustment instruction is secure, and thus the target adjustment instruction is executed. It should be noted that after the option control unit executes the target adjustment instruction, a new random code, that is, the second random code, is generated and sent to the security area. After the verification is successful, the preset driver is controlled to modify the corresponding parameters in the option control unit to execute the target option adjustment instruction.
[0059] It can be understood that when the third random code in the option control unit is the same as the first random code, the preset driver is controlled to modify the corresponding parameters in the option control unit to execute the target option adjustment instruction. It should be noted that the adjustment of the target option is achieved by modifying the parameters in the corresponding CPU registers, the addresses or ports of the motherboard-related circuits, and the parameter areas of the corresponding memory through software such as the driver.
[0060] Step S25: Receive the second random code sent by the option control unit and store the second random code for replacing the first random code in the local storage area.
[0061] In this embodiment, the second random code sent by the option control unit is received and stored in the local storage area to replace the first random code. It can be understood that after receiving the encrypted target option adjustment instruction next time, the second random code is sent to the option control unit so that the option control unit can perform a verification operation using the second random code and the random code stored in the preset storage area.
[0062] For the specific content of the above step S21, reference can be made to the corresponding content disclosed in the foregoing embodiment, and details will not be elaborated herein.
[0063] It can be seen that in the embodiment of the present application, by determining whether the source of the encrypted target option adjustment instruction is the user area, it is judged whether the instruction source is correct. Then, after the power-on is completed, the target random code generated by the option control unit during power-on startup is obtained. When the instruction source is the user area, the first random code stored in the local storage area is sent to the option control unit for comparison with the third random code. When the comparison is successful, the target option adjustment instruction is executed, thereby reducing the possibility of system insecurity caused by being attacked by malicious programs.
[0064] See Figure 4 As shown, the embodiment of the present application also correspondingly discloses a security defense device, which is applied to the security area in the central processing unit. The central processing unit further includes a user area, and further includes:
[0065] An instruction receiving module 11, configured to receive an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area;
[0066] A random code verification module 12, configured to send the first random code stored in the local storage area to the option control unit when the source of the encrypted target option adjustment instruction is the user area, so that the option control unit verifies the first random code and executes the target option adjustment instruction after the verification is successful;
[0067] A random code update module 13, configured to receive the second random code sent by the option control unit and store the second random code used to replace the first random code in the local storage area.
[0068] It can be seen that the present application includes: receiving an encrypted target option adjustment instruction, decrypting the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area; when the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification; receiving a second random code sent by the option control unit and storing the second random code for replacing the first random code in the local storage area. Thus, in the present application, the source of the received target option adjustment instruction is verified through the security area in the central processing unit, and it is judged whether the source of the target option adjustment instruction is the user area in the central processing unit according to the verification result. Only when the instruction source is the user area can corresponding adjustment operations be performed, thereby reducing the possibility of system insecurity caused by being attacked by malicious programs.
[0069] In some specific embodiments, the instruction receiving module 11 specifically includes:
[0070] An instruction receiving unit for receiving an encrypted target option adjustment instruction;
[0071] A decryption unit for decrypting the encrypted target option adjustment instruction by using a pre-stored key;
[0072] A source judgment unit for judging whether the source of the target option adjustment instruction is the user area based on the decryption result.
[0073] In some specific embodiments, the random code verification module 12 specifically includes:
[0074] A target random code acquisition unit for communicating with the option control unit after power-on completion and acquiring a target random code generated by the option control unit during power-on startup;
[0075] A first random code determination unit for storing the target random code in the local storage area to obtain the first random code;
[0076] A third random code determination unit for storing the target random code in the option control unit to obtain the third random code;
[0077] A random code verification unit for sending the first random code stored in the local storage area to the option control unit when the source of the encrypted target option adjustment instruction is the user area, so that the option control unit verifies the first random code.
[0078] In some specific embodiments, the random code update module 13 specifically includes:
[0079] A second random code acquisition unit, configured to receive the second random code sent by the option control unit; the second random code is a random code generated by the option control unit after executing the target option adjustment instruction;
[0080] A random code update unit, configured to replace the first random code with the second random code, so as to perform a verification operation using the second random code and the random code stored in the option control unit after receiving the encrypted target option adjustment instruction next time.
[0081] Furthermore, an embodiment of the present application also provides an electronic device. Figure 5 It is a structural diagram of an electronic device 20 shown according to an exemplary embodiment, and the content in the figure should not be considered as any limitation to the scope of use of the present application.
[0082] Figure 5 This is a schematic structural diagram of an electronic device 20 provided by an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the security defense method disclosed in any of the foregoing embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0083] In this embodiment, the power supply 23 is used to provide a working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and specific limitations are not imposed here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitations are imposed here.
[0084] In addition, as a carrier for resource storage, the memory 22 may be a read-only memory, a random access memory, a magnetic disk, or an optical disc, etc., and the resources stored thereon may include an operating system 221, a computer program 222, etc., and the storage method may be temporary storage or permanent storage.
[0085] Among them, the operating system 221 is used to manage and control each hardware device and computer program 222 on the electronic device 20, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the security defense method executed by the electronic device 20 disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.
[0086] Furthermore, an embodiment of the present application also discloses a storage medium in which a computer program is stored. When the computer program is loaded and executed by a processor, the steps of the security defense method disclosed in any of the foregoing embodiments are implemented.
[0087] In this specification, the various embodiments are described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0088] Finally, it should also be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, the element defined by the statement "including one..." does not exclude the existence of additional identical elements in the process, method, article or device including the said element.
[0089] The above has introduced in detail a security defense method, device, equipment and storage medium provided by the present invention. Specific examples are used in this article to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.
Claims
1. A security defense method, characterized in that, it is applied to a security area in a central processing unit, and the central processing unit further includes a user area. The method further includes: Receiving an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction by using a pre-stored key, and to determine whether the source of the encrypted target option adjustment instruction is the user area; When the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in a local storage area to an option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification; Receiving a second random code sent by the option control unit and storing the second random code for replacing the first random code in the local storage area; Wherein, the step of when the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in a local storage area to an option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification includes: When the source of the encrypted target option adjustment instruction is the user area, sending the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code; After successful verification, controlling a preset driver to modify corresponding parameters in the option control unit so as to execute the target option adjustment instruction.
2. The security defense method according to claim 1, characterized in that, the step of receiving an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction by using a pre-stored key, and to determine whether the source of the encrypted target option adjustment instruction is the user area includes: Receiving an encrypted target option adjustment instruction and decrypting the encrypted target option adjustment instruction by using the pre-stored public key to obtain a corresponding decryption result; Judging whether the source of the target option adjustment instruction is the user area based on the decryption result.
3. The security defense method according to claim 2, characterized in that, the step of judging whether the source of the target option adjustment instruction is the user area based on the decryption result includes: When the decryption result is successful decryption, it is determined that the source of the target option adjustment instruction is the user area, and then the step of sending the first random code stored in the local storage area to the option control unit is started; When the decryption result is failed decryption, it is determined that the source of the target option adjustment instruction is not the user area, and the process ends.
4. The security defense method according to claim 1, characterized in that, the step of when the source of the encrypted target option adjustment instruction is the user area, sending a first random code stored in a local storage area to an option control unit, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification includes: When the source of the encrypted target option adjustment instruction is the user area, send the first random code stored in the local storage area to the option control unit, so that the option control unit compares the first random code with the third random code stored in the option control unit, and executes the target option adjustment instruction when the comparison result is the same.
5. The security defense method according to claim 4, wherein, when the source of the encrypted target option adjustment instruction is the user area, sending the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code, and before executing the target option adjustment instruction after successful verification, further includes: After the power-on is completed, communicate with the option control unit and obtain the target random code generated by the option control unit during power-on startup; Store the target random code in the local storage area to obtain the first random code; and store the target random code in the option control unit to obtain the third random code.
6. The security defense method according to any one of claims 1 to 5, wherein, receiving the second random code sent by the option control unit and storing the second random code for replacing the first random code in the local storage area includes: Receiving the second random code sent by the option control unit; the second random code is a random code generated by the option control unit after executing the target option adjustment instruction; Replace the first random code with the second random code, so as to use the second random code to perform a verification operation with the random code stored in the option control unit after receiving the encrypted target option adjustment instruction next time.
7. A security defense device, wherein, applied to the security area in the central processing unit, the central processing unit further includes a user area, and further includes: An instruction receiving module, configured to receive an encrypted target option adjustment instruction, so as to decrypt the encrypted target option adjustment instruction by using a pre-stored key to determine whether the source of the encrypted target option adjustment instruction is the user area; A random code verification module, configured to send the first random code stored in the local storage area to the option control unit when the source of the encrypted target option adjustment instruction is the user area, so that the option control unit verifies the first random code and executes the target option adjustment instruction after successful verification; A random code update module, configured to receive the second random code sent by the option control unit and store the second random code for replacing the first random code in the local storage area; wherein, the random code verification module includes: A random code verification unit, when the source of the encrypted target option adjustment instruction is the user area, sends the first random code stored in the local storage area to the option control unit, so that the option control unit verifies the first random code, and after successful verification, controls a preset driver to modify corresponding parameters in the option control unit, so as to execute the target option adjustment instruction.
8. An electronic device, characterized in that it includes: a memory for storing a computer program; a processor for executing the computer program to implement the steps of the security defense method according to any one of claims 1 to 6.
9. A computer-readable storage medium, characterized in that it is used for storing a computer program; wherein, when the computer program is executed by a processor, the security defense method according to any one of claims 1 to 6 is implemented.
Citation Information
Patent Citations
Identity authentication method, terminal and server
WO2017177435A1