A computer system, an access control method, and a storage medium

The implementation of trusted measurement modules in computer systems to verify host trustworthiness through comparison with baseline values addresses the issue of unauthorized access and tampering, enhancing peripheral device data security.

CN115618362BActive Publication Date: 2025-07-15HYGON INFORMATION TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202211419573.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-14
Publication Date
2025-07-15
Estimated Expiration
2042-11-14

AI Technical Summary

Technical Problem

In the prior art, the peripheral device data of computer systems is relatively low, and illegal programs are prone to steal or tamper with important data, mainly because authorized information such as passwords are prone to steal or crack.

Method used

By introducing a trusted metric module into the computer system, the trusted metric value of the host is obtained and compared with the metric benchmark value, the peripheral devices are only allowed to be accessed when the host is trustworthy, and encrypted signatures and secure channels are used to ensure the security of data transmission.

Benefits of technology

Improves the security of data in peripheral devices, prevents illegal theft or tampering, and ensures that only trusted hosts can access peripheral devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115618362B_ABST
    Figure CN115618362B_ABST
Patent Text Reader

Abstract

An embodiment of the present invention discloses a computer system, an access control method, and a storage medium, which relate to the field of computer technologies and can improve the security of data in peripheral devices. The computer system includes: a host, a trusted measurement module, and a peripheral device; the trusted measurement module is respectively connected to the host and the peripheral device; wherein, the trusted measurement module is configured to obtain a trusted measurement value of the host; the peripheral device is configured to obtain the trusted measurement value of the host from the trusted measurement module, compare the trusted measurement value of the host with a measurement reference value, and determine whether to allow the host to access according to the comparison result. The present invention is applicable to computer security technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of computer technologies, and in particular, to a computer system, an access control method, and a storage medium. Background Art

[0002] In addition to a host, a modern computer system usually includes many peripheral devices connected to the host for inputting or outputting data. When the host is under a network attack, an illegal program in the host may illegally access these peripheral devices and steal or tamper with important data therefrom, thus greatly reducing the security of the data in the peripheral devices.

[0003] To solve this technical problem, the currently adopted technical solution is that when the host accesses a peripheral device, it needs to first input a password for authorization verification, and only when the host passes the verification can it access the peripheral device. However, the authorization information such as the password in this technical solution is easily stolen or cracked by an illegal program. After obtaining the authorization information, the illegal program can access the data in the peripheral device. Therefore, there is a technical problem of low data security in the peripheral device in the existing technical solution. Summary of the Invention

[0004] In view of this, embodiments of the present invention provide a computer system, an access control method, and a storage medium, which can improve the security of data in peripheral devices.

[0005] In a first aspect, an embodiment of the present invention provides a computer system, including: a host, a trusted measurement module, and a peripheral device; the trusted measurement module is respectively connected to the host and the peripheral device; wherein, the trusted measurement module is configured to obtain a trusted measurement value of the host; the peripheral device is configured to obtain the trusted measurement value of the host from the trusted measurement module, compare the trusted measurement value of the host with a measurement reference value, and determine whether to allow the host to access according to the comparison result.

[0006] Optionally, the trusted measurement module includes a first trusted measurement module and / or a second trusted measurement module; wherein, the first trusted measurement module is configured to record the trusted measurement value of the startup process of the operating system of the host; the second trusted measurement module is configured to record the trusted measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the startup of the operating system.

[0007] Optionally, the trusted measurement module is connected to the peripheral device through a physical line or through a logical link.

[0008] Optionally, the trusted measurement module is within the same module as the peripheral device; alternatively, the trusted measurement module is provided within the peripheral device; or the trusted measurement module is provided within the host.

[0009] Optionally, the peripheral device is specifically configured to: when receiving an access request from the host or periodically obtain the trusted measurement value of the host from the trusted measurement module, compare the trusted measurement value of the host with a measurement reference value, and determine whether to reject all or part of the access requests of the host according to the comparison result.

[0010] Optionally, the peripheral device has a first command interface for receiving the import of the trusted platform configuration information of the host, and the trusted platform configuration information includes the measurement reference value of the host.

[0011] Optionally, the peripheral device has a second command interface for receiving the import of the platform certificate of the host; the peripheral device is further configured to determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate; wherein, the first command interface and the second command interface are the same command interface or two different command interfaces.

[0012] Optionally, the platform certificate includes a first digital signature encrypted with a first private key, and a first public key corresponding to the first private key is provided in the peripheral device; when receiving the import of the platform certificate through the second command interface, the peripheral device is further configured to verify the first digital signature with the first public key, and if the verification is passed, determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate.

[0013] Optionally, the platform certificate contains a second public key, and the trusted platform configuration information includes a second digital signature encrypted with a second private key corresponding to the second public key; after receiving the import of the trusted platform configuration information through the first command interface, the peripheral device is further configured to verify the second digital signature with the second public key, and if the verification is passed, obtain the measurement reference value from the trusted platform configuration information.

[0014] In a second aspect, an access control method provided by an embodiment of the present invention is applied to a peripheral device of a computer system, and includes: obtaining a trusted measurement value of a host of the computer system; comparing the trusted measurement value of the host with a measurement reference value of the host obtained in advance; and determining whether to allow the host to access the peripheral device according to the comparison result.

[0015] Optionally, the trusted measurement value is the trusted measurement value of the startup process of the operating system of the host; and / or, the trusted measurement value is the trusted measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the operating system of the host is started.

[0016] Optionally, obtaining the trusted measurement value of the host of the computer system includes: obtaining the trusted measurement value of the host of the computer system through a trusted measurement module; wherein, the trusted measurement module is within the same module as the peripheral device; or, the trusted measurement module is provided in the peripheral device; or, the trusted measurement module is provided in the host.

[0017] Optionally, the trusted measurement module and the peripheral device are connected through a physical line or through a logical link.

[0018] Optionally, obtaining the trusted measurement value of the host of the computer system includes: when receiving an access request from the host, or periodically obtaining the trusted measurement value of the host.

[0019] Optionally, determining whether to allow the host to access the peripheral device according to the comparison result includes: determining whether to reject all or part of the access requests of the host to the peripheral device according to the comparison result.

[0020] Optionally, the peripheral device has a first command interface; before comparing the trusted measurement value of the host with the previously obtained measurement reference value of the host, the access control method further includes: receiving the import of the trusted platform configuration information of the host through the first command interface, and the trusted platform configuration information contains the measurement reference value of the host.

[0021] Optionally, the peripheral device has a second command interface; the receiving the import of the trusted platform configuration information of the host through the first command interface includes: receiving the import of the platform certificate of the host through the second command interface; determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate; if so, receiving the import of the trusted platform configuration information of the host through the first command interface; wherein, the first command interface and the second command interface are the same command interface, or two different command interfaces.

[0022] Optionally, the platform certificate includes a first digital signature encrypted with a first private key, and a first public key corresponding to the first private key is set in the peripheral device; when receiving the import of the platform certificate of the host through the second command interface, the access control method further includes: verifying the first digital signature with the first public key; correspondingly, determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate includes: if the verification is passed, determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate.

[0023] Optionally, the platform certificate contains a second public key, and the trusted platform configuration information includes a second digital signature encrypted with a second private key corresponding to the second public key; after receiving the import of the trusted platform configuration information of the host through the first command interface, the access control method further includes: verifying the second digital signature with the second public key; if the verification is passed, obtaining the measurement reference value from the trusted platform configuration information.

[0024] In a third aspect, an embodiment of the present invention further provides a non-transitory computer-readable storage medium, and the non-transitory computer-readable storage medium stores one or more programs, and the one or more programs can be executed by one or more processors to implement any access control method provided by the embodiments of the present invention.

[0025] In the computer system, access control method, and storage medium provided by the embodiments of the present invention, the peripheral device can obtain the trusted measurement value of the host, and then compare the trusted measurement value of the host with the measurement reference value of the host. Furthermore, according to the comparison result, it can be determined whether the host is trusted, and the peripheral device only allows the host to access the peripheral device when it determines that the host is trusted. Therefore, it can be ensured that the host cannot illegally steal or tamper with the data in the peripheral device during access, thereby improving the security of the data in the peripheral device. Description of the Drawings

[0026] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for use in the description of the embodiments or the prior art. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings without creative efforts based on these drawings.

[0027] Figure 1 It is a schematic structural diagram of a computer system provided by an embodiment of the present invention;

[0028] Figure 2Schematic diagram of a static trusted measurement in the computer system according to an embodiment of the present invention;

[0029] Figure 3 Interaction schematic diagram of a host, a trusted measurement module, and peripheral devices in the computer system according to an embodiment of the present invention;

[0030] Figure 4 Schematic diagram of importing a platform certificate and trusted platform configuration information in the computer system according to an embodiment of the present invention;

[0031] Figure 5 Flow schematic diagram of an access control method provided by an embodiment of the present invention. Detailed implementation manners

[0032] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.

[0033] It should be clear that the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0034] A computer system includes a host and peripheral devices connected to the host; the peripheral devices can be directly plugged into an interface (such as a USB interface, etc.) on the host, or can be connected to the host through a data cable, or can be communicatively connected to the host wirelessly. Among them, the host includes a main board, a hard disk, a power supply, a graphics card, etc., and a central processing unit (denoted as CPU) and a memory, etc. are provided on the main board. The central processing unit can be a central processing unit with an x86 architecture, and the peripheral devices can be a cryptographic card, a password input module, a printer, a disk, a display, a keyboard, etc. The operating system running on the host can be a Windows operating system, or other operating systems such as Linux.

[0035] When the host accesses the peripheral device, it usually needs to input a password for authorization verification first. Only when the host passes the verification can it access the peripheral device. However, in practical applications, the applicant found that the authorization information such as the password in this technical solution is easily stolen or cracked by illegal programs. After obtaining the authorization information, the illegal programs can access the data in the peripheral device, resulting in low data security in the peripheral device.

[0036] The embodiments of the present invention provide a computer system, an access control method, and a storage medium. By performing trusted measurement on the host of the computer system to determine whether the host is trusted, only when the host is trusted is it allowed to access the peripheral device, thereby improving the data security in the peripheral device.

[0037] The following uses illustrative embodiments for description. Please refer toFigure 1 , which shows a schematic structural diagram of a computer system provided by an embodiment of the present invention. The computer system 1 provided by the embodiment of the present invention may include: a host 11, a trusted measurement module 12, and a peripheral device 13; the trusted measurement module 12 is respectively connected to the host 11 and the peripheral device 13; wherein, the trusted measurement module 12 is used to obtain the trusted measurement value of the host 11; the peripheral device 13 is used to obtain the trusted measurement value of the host 11 from the trusted measurement module 12, compare the trusted measurement value of the host 11 with a measurement reference value, and determine whether to allow the host 11 to access according to the comparison result.

[0038] In the embodiment of the present invention, the host 11 is the main part of the computer system 1, usually including a CPU, a memory, a motherboard, etc., and various system application software runs on it, which is the main target of various network attacks. The trusted state of the host 11 determines the security of the entire computer system 1. The peripheral device 13 is other devices in the computer system 1 except the host 11. The peripheral device 13 is a tool for the host 11 to communicate with the outside world, and can be of the input device type or the output device type, and can specifically be a password card, a password module, a printer, a disk, or a keyboard, etc.

[0039] When the peripheral device 13 is of the input device type, the host 11 can receive various data, which can be either numerical data or various non-numerical data, such as graphics, images, sounds, etc. When the peripheral device 13 is of the output device type, various data can be output in the forms of numbers, characters, images, sounds, etc.

[0040] The trusted measurement module 12 can perform integrity measurement on the host 11 to obtain the trusted measurement value of the host 11. In one example, the hash value of the host 11 can be calculated using a hash function as the trusted measurement value, and the trusted measurement value is stored in the trusted measurement module 12.

[0041] When the peripheral device 13 needs to verify the credibility of the host 11, it can obtain the credibility measurement value of the host 11 from the trusted measurement module 12, and compare this credibility measurement value with the measurement reference value of the host 11. If the two are equal, it indicates that the host 11 is trustworthy and will not steal or tamper with the data in the peripheral device 13. The peripheral device 13 can grant the host 11 access rights and allow the host 11 to access it. If the two are not equal, the host 11 is not allowed to access the peripheral device 13 to prevent the data in the peripheral device 13 from being stolen or tampered with. In this way, the peripheral device 13 only allows the host 11 to access it after confirming the credibility of the host 11 to implement the function of inputting or outputting data, thus ensuring that the host 11 will not illegally steal or tamper with the data in the peripheral device 13, thereby improving the security of the data in the peripheral device 13.

[0042] In the computer system provided by the embodiment of the present invention, the peripheral device can obtain the credibility measurement value of the host from the trusted measurement module, and then compare the credibility measurement value of the host with the measurement reference value. Furthermore, according to the comparison result, it can be determined whether the host is trustworthy. The peripheral device only allows the host to access the peripheral device when it determines that the host is trustworthy. Thus, it can be ensured that the host cannot illegally steal or tamper with the data in the peripheral device, thereby improving the security of the data in the peripheral device.

[0043] Optionally, in an embodiment of the present invention, the trusted measurement module 12 may include a first trusted measurement module and / or a second trusted measurement module; wherein, the first trusted measurement module is used to record the credibility measurement value of the operating system startup process of the host; the second trusted measurement module is used to record the credibility measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the operating system starts.

[0044] In the embodiment of the present invention, the trusted measurement module 12 may be the first trusted measurement module (denoted as the static trusted measurement module), or the second trusted measurement module (denoted as the dynamic trusted measurement module), or may include both the first trusted measurement module and the second trusted measurement module, that is, may include both the static trusted measurement module and the dynamic trusted measurement module. The embodiment of the present invention does not make specific limitations on the measurement type. Generally speaking, the more measurement types are adopted, the more comprehensive the measurement is, and the more accurate the credibility measurement value of the host 11 obtained is.

[0045] The static trusted measurement module is a chip that implements the TPM (Trusted Platform Module) standard. Such chips can be physical entities, simulated by other chips, or implemented in firmware, as long as the TPM standard is implemented. Among them, the TPM standard is the underlying module standard for supporting trusted computing formulated by the TCG (Trusted Computing Group). The TPM is provided with a PCR (Platform Configuration Register) component to support the trusted measurement function in trusted computing.

[0046] The static trusted measurement module can perform a one-time measurement on the host 11, that is, at a certain moment, such as when the operating system of the host 11 starts, a measurement is performed on the host 11 (i.e., the startup measurement) to obtain the trusted measurement value of the host 11. During the running stage after the operating system starts, the trusted measurement value will not be measured again. Therefore, the trusted measurement value of the host 11 only reflects the integrity of the operating system of the host 11 at the startup moment and is static.

[0047] The startup measurement performed by the trusted measurement module 12 (i.e., the static trusted measurement module) at the moment when the operating system of the host 11 starts is a process of establishing a trust chain through layer-by-layer verification of "loading one level by one level and measuring one level by one level" starting from the trusted measurement root. The trusted measurement value is securely stored in the PCR of the trusted measurement module 12 (specifically, the static trusted measurement module). The following takes the CPU in the host as the X86 architecture and the operating system as the Linux system as an example for a more detailed description. As Figure 2 shown, after the Linux system starts, the static trusted measurement module uses the trusted measurement root 111 to perform a trusted measurement on the basic input / output system 112 (BIOS) of the operating system. After the basic input / output system 112 starts, it uses the basic input / output system 112 to perform a trusted measurement on the operating system loader 113 (GRand Unified Bootloader, Grub). After the operating system loader 113 starts, it uses the operating system loader 113 to perform a trusted measurement on the operating system kernel 114. After the operating system kernel 114 starts, it uses the operating system kernel 114 to perform a trusted measurement on the system application 115. Through such a process of step-by-step measurement, a startup trust chain can be established. The static trusted measurement values obtained by measuring the next level at each level during the startup process are centrally recorded in the trusted measurement module 12 (specifically, the static trusted measurement module).

[0048] In another example, the static trust measurement module can also perform a trust measurement on the host 11 when a certain program in the host 11 is loaded, so as to obtain the static trust measurement value of the host 11 at the moment when the program is loaded.

[0049] The dynamic trust measurement module can be used to dynamically determine the integrity of the measurement host 11. Specifically, during the running stage after the operating system of the host 11 is started, a dynamic measurement can be performed on a predetermined part of the operating system to obtain a dynamic trust measurement value. In one example, the dynamic measurement module can continuously scan and measure the key parts of the operating system during the running process of the operating system of the host 11 to obtain a dynamic trust measurement value and store it in the trust measurement module 12 (specifically, the dynamic trust measurement module). Generally speaking, compared with the static trust measurement value, the dynamic trust measurement value is more real-time and can more accurately reflect the credibility of the host 11.

[0050] Optionally, in an embodiment of the present invention, the trust measurement module 12 and the peripheral device 13 are connected through a physical line or through a logical link.

[0051] In the embodiment of the present invention, a secure channel can be set between the trust measurement module 12 and the peripheral device 13 to improve the security of the trust measurement value during the transmission process, prevent the trust measurement value from being tampered with during the transmission process, and thus ensure that the trust measurement value obtained by the peripheral device 13 from the trust measurement module 12 is true and reliable.

[0052] In an example of the embodiment of the present invention, the secure channel between the trust measurement module 12 and the peripheral device 13 can be implemented in a way of physical line connection. For example, the two can be connected through a dedicated bus without sharing the bus with other data transmission processes, thereby improving the security of the trust measurement value during the transmission process. In another example, the trust measurement module 12 and the peripheral device 13 can also be set inside the same module, which can also reduce the possibility of the trust measurement value being tampered with during the transmission process and improve the security of the trust measurement value during the transmission process. In yet another example, the trust measurement module 12 and the peripheral device 13 can also be connected by a logical link. Specifically, the trust measurement value can be encrypted in advance using an encryption algorithm, so that the trust measurement value is transmitted between the trust measurement module 12 and the peripheral device 13 in an encrypted form, thereby improving the security of the trust measurement value during the transmission process.

[0053] Optionally, in an embodiment of the present invention, the trust measurement module 12 and the peripheral device 13 are within the same module; or, the trust measurement module 12 is provided inside the peripheral device 13; or, the trust measurement module 12 is provided inside the host 11.

[0054] Embodiments of the present invention can adopt various setting methods for the position of the trusted measurement module 12. Specifically, the trusted measurement module 12 and the peripheral device 13 can be set in the same module to improve the security of the trusted measurement value during transmission. Similarly, the trusted measurement module 12 can also be set inside the peripheral device 13 to facilitate the peripheral device 13 to obtain the trusted measurement value from the trusted measurement module 12; or, the trusted measurement module 12 can be set inside the host 11 to facilitate storing the trusted measurement value of the host 11 into the trusted measurement module 12. It should be noted that as long as the peripheral device 13 can obtain the trusted measurement value from the trusted measurement module 12, regardless of the position of the trusted measurement module 12, it belongs to the protection scope of the embodiments of the present invention.

[0055] Optionally, in an embodiment of the present invention, the peripheral device 13 is specifically configured to: when receiving an access request from the host 11 or periodically obtain the trusted measurement value of the host 11 from the trusted measurement module 12, compare the trusted measurement value of the host 11 with the measurement reference value, and determine whether to reject all or part of the access requests of the host 11 according to the comparison result.

[0056] In an example of the embodiments of the present invention, the peripheral device 13 can periodically obtain the trusted measurement value from the trusted measurement module 12 and compare the obtained trusted measurement value with the measurement reference value to determine the credibility of the host 11. There will be a time period between the moment when the trusted measurement value is obtained in this example and the moment when the host 11 initiates an access request to access the peripheral device 13 in the subsequent process. During this time period, if the host 11 is under a network attack, the trusted measurement value of the host 11 may change to a certain extent. Therefore, the trusted measurement value obtained by the above method can only roughly reflect the credibility of the host 11 at the moment when it initiates an access request to access the peripheral device 13.

[0057] In another example, such as Figure 3As shown, when the peripheral device 13 receives an access request from the host 11, it can obtain the trust measurement value of the host 11 from the trusted measurement module 12, and compare the trust measurement value of the host 11 with the measurement reference value. If the two are equal, it is confirmed that the host 11 is trusted, and thus the host 11 can be allowed to access the peripheral device 13. Then, the peripheral device 13 can process the data in response to the host's access request and return the processing result to the host 11. If the two are not equal, the peripheral device 13 confirms that the host 11 is untrusted. Then, according to the specific type of the host 11 and the specific comparison result, all access requests of the host 11 can be rejected, that is, the host 11 is not allowed to access the peripheral device 13 under any circumstances, so as to ensure the security of all data. Or when the two are not equal, the peripheral device 13 can, according to the specific type of the host 11 and the specific comparison result, reject some access requests of the host 11, and at the same time respond to another part of the access requests of the host 11. In this way, the host 11 can access the unimportant data in the peripheral device 13 but cannot access the important data in the peripheral device 13, thus ensuring the security of the important data. In this example, the acquisition time of the trust measurement value is almost exactly the same as the time when the host 11 initiates an access request to the peripheral device 13. Therefore, the real-time performance of the trust measurement value is good, and it can more accurately reflect the credibility of the host 11 at the moment when it initiates an access request to the peripheral device 13.

[0058] Optionally, in an embodiment of the present invention, the peripheral device 13 has a first command interface for receiving the import of the trusted platform configuration information 116 of the host 11, and the trusted platform configuration information 116 includes the measurement reference value 1162 of the host.

[0059] Generally speaking, the peripheral device 13 can form a computer system with a variety of different types of hosts. For example, when the peripheral device 13 is a disk, it can be installed on a host of model A or a host of model B. Different types of hosts have different measurement reference values due to different configurations. Therefore, in order to determine whether the host 11 is trusted, it is first necessary to obtain the measurement reference value corresponding to the host 11. In a specific implementation manner, regardless of the type of the host connected to the peripheral device 13, the peripheral device 13 can import the trusted platform configuration information of the host through the first command interface and obtain the measurement reference value of the host from the trusted platform configuration information. In this way, regardless of the type of host with which the peripheral device 13 is used, the peripheral device 13 can obtain the reference measurement value of the host to facilitate determining whether the host is trusted. In the case of subsequent replacement of the host, the trusted platform configuration information of the new host can be re-imported and the reference measurement value of the new host can be obtained from it to facilitate confirming whether the new host is trusted.

[0060] Optionally, in an embodiment of the present invention, the peripheral device 13 has a second command interface for receiving the import of the platform certificate 117 of the host 11. The peripheral device 13 is further configured to determine whether to receive the import of the trusted platform configuration information 116 according to the value of the first flag bit 1171 in the platform certificate 117. Wherein, the first command interface and the second command interface are the same command interface or two different command interfaces.

[0061] In an embodiment of the present invention, as Figure 4 shown, the value of the first flag bit 1171 in the platform certificate 117 is used to indicate whether to allow the import of the trusted platform configuration information 116. Before importing the platform certificate 117, the value of the first flag bit 1171 of the platform certificate 117 can be preset according to actual needs. For example, if the peripheral device 13 is allowed to import the trusted platform configuration information 116, the value of the first flag bit 1171 can be set to 1. If the peripheral device 13 is not allowed to import the trusted platform configuration information 116, the value of the first flag bit 1171 can be set to 0.

[0062] After that, when the peripheral device 13 imports the platform certificate 117 of the host 11 through the second command interface, the peripheral device 13 can determine whether to receive the import of the trusted platform configuration information 116 according to the value of the first flag bit 1171 in the platform certificate 117. Specifically, when the peripheral device 13 detects that the value of the first flag bit 1171 is 1, it receives the import of the trusted platform configuration information 116. When the peripheral device 13 detects that the value of the first flag bit 1171 is 0, it rejects the import of the trusted platform configuration information 116. In this way, for any peripheral device, by presetting the value of the first flag bit 1171 in the platform certificate 117, the import of the trusted platform configuration information 116 by the peripheral device can be flexibly controlled.

[0063] Optionally, in an embodiment of the present invention, the platform certificate 117 includes a first digital signature 1172 encrypted with a first private key, and a first public key 131 corresponding to the first private key is set in the peripheral device 13. When receiving the import of the platform certificate 117 through the second command interface, the peripheral device 13 is further configured to verify the first digital signature 1172 with the first public key 131. If the verification is passed, it determines whether to receive the import of the trusted platform configuration information according to the value of the first flag bit 1171 in the platform certificate 117.

[0064] In the embodiment of the present invention, the peripheral device 13 needs to be activated before it is used, and the peripheral device 13 can be used normally only after the activation is successful. Specifically, the process of activating the peripheral device 13 is to first import the platform certificate 117 and verify the authenticity of the platform certificate 117. Only when the verification is passed, it indicates that the platform certificate 117 is authentic and reliable, and then the successful activation of the peripheral device 13 can be achieved.

[0065] like Figure 4 As shown, in order to verify the authenticity of the platform certificate 117, the manufacturer of the peripheral device 13 can use the first key to digitally sign the platform certificate 117 in advance to form a first digital signature 1172, and set a first public key 131 corresponding to the aforementioned first private key in the peripheral device 13. The first private key and the first public key 131 are a pair of key pairs. In one example, when performing digital signature, an asymmetric cryptographic algorithm can be used, such as the national secret SM2 algorithm.

[0066] When the platform certificate 117 is imported into the peripheral device 13 through the second command interface, the first public key 131 in the peripheral device 13 can be used to verify the first digital signature 1172 in the platform certificate 117. If the verification is successful, it indicates that the platform certificate 117 has not been tampered with and is authentic and reliable. If the verification is not successful, it indicates that the platform certificate 117 is not authentic and reliable, so it can be not adopted. When it is determined that the platform certificate 117 is authentic and reliable, the peripheral device 13 will determine whether to import the trusted platform configuration information based on the value of the first flag bit 1171 in the platform certificate 117. In this way, since the authenticity of the platform certificate 117 is verified by a digital signature, the authenticity of the platform certificate 117 can be ensured, thereby improving the security of the data in the peripheral device 13.

[0067] Optionally, in one embodiment of the present invention, the platform certificate 117 includes a second public key 1173, and the trusted platform configuration information 116 includes a second digital signature 1161 encrypted by a second private key corresponding to the second public key 1173; after receiving the import of the trusted platform configuration information 116 through the first command interface, the peripheral device is also used to verify the second digital signature 1161 according to the second public key 1173, and if the verification passes, obtain the measurement reference value 1162 from the trusted platform configuration information 116.

[0068] like Figure 4As shown in the figure, in order to verify the authenticity of the trusted platform configuration information 116, before importing the trusted platform configuration information 116, a second public key 1173 can be set in the aforementioned platform certificate 117 in advance, and the trusted platform configuration information 116 can be digitally signed using the second private key corresponding to the second public key (the second public key 1173 and the second private key are a pair of key pairs) to form a second digital signature 1161. After importing the trusted platform configuration information 116 through the first command interface, the second public key 1173 can be obtained from the platform certificate 117, and the second digital signature 1161 can be verified using the second public key 1173. If the verification is passed, it indicates that the trusted platform configuration information 116 is true and reliable. Therefore, the measurement reference value 1162 can be further obtained from the trusted platform configuration information 116. If the verification fails, it indicates that the trusted platform configuration information 116 is not true and reliable. Therefore, it can be not adopted, so as to ensure the authenticity of the obtained measurement reference value 1162, and further improve the security of the data in the peripheral device 13.

[0069] In addition to including the aforementioned first flag bit 1171, the first digital signature 1172, and the second public key 1173, the platform certificate 117 may further include information such as the identification number of the peripheral device 13 and the platform certificate generation time.

[0070] In a second aspect, an embodiment of the present invention provides an access control method, which is applied to a peripheral device of a computer system and can improve the security of data in the peripheral device.

[0071] As Figure 5 shown, the access control method provided by the embodiment of the present invention is applied to a peripheral device of a computer system. The method may include:

[0072] S11, obtaining the trusted measurement value of the host of the computer system;

[0073] S12, comparing the trusted measurement value of the host with the previously obtained measurement reference value of the host;

[0074] S13, determining whether to allow the host to access the peripheral device according to the comparison result.

[0075] In an embodiment of the present invention, when a peripheral device needs to verify the credibility of the host of a computer system, it can first obtain the trusted measurement value of the host, and compare the trusted measurement value with the measurement reference value of the host. If the two are equal, it indicates that the host is trusted and will not steal or tamper with the data in the peripheral device, and the peripheral device can grant the host access permission to allow the host to access it. If the two are not equal, the host is not allowed to access the peripheral device to prevent the data in the peripheral device from being stolen or tampered with. In this way, the peripheral device only allows the host to access it after confirming the credibility of the host to implement the function of inputting or outputting data, thus ensuring that the host will not illegally steal or tamper with the data in the peripheral device, thereby improving the security of the data in the peripheral device.

[0076] For the access control method provided by the embodiment of the present invention, the peripheral device can first obtain the trusted measurement value of the host, and then compare the trusted measurement value of the host with the measurement reference value. Furthermore, according to the comparison result, it can be determined whether the host is trusted. The peripheral device only allows the host to access the peripheral device when it determines that the host is trusted. Therefore, it can be ensured that the host cannot illegally steal or tamper with the data in the peripheral device, thereby improving the security of the data in the peripheral device.

[0077] Optionally, in an embodiment of the present invention, the trusted measurement value is the trusted measurement value of the startup process of the host's operating system; and / or, the trusted measurement value is the trusted measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the startup of the host's operating system.

[0078] In the embodiment of the present invention, the trusted measurement value can be either a static trusted measurement value or a dynamic trusted measurement value, or can include both at the same time. The embodiment of the present invention does not make specific limitations on the measurement type. Generally speaking, the more measurement types are adopted, the more comprehensive the measurement is, and the more accurate the obtained trusted measurement value of the host is.

[0079] Specifically, the static trusted measurement module can perform a one-time measurement on the host, that is, at a certain moment, such as the moment when the host's operating system starts, perform a measurement on the host (i.e., startup measurement) to obtain the static trusted measurement value of the host. During the operation stage after the startup of the operating system, the trusted measurement value will not be measured again. Therefore, the trusted measurement value of the host only reflects the integrity of the host's operating system at the startup moment and is static.

[0080] The startup measurement performed by the trusted measurement module (herein referring to the static trusted measurement module) at the startup moment of the host operating system is a process of establishing a trust chain through layer-by-layer verification of "loading one level by one level and measuring one level by one level" starting from the root of trusted measurement. The trusted measurement value is securely stored in the PCR of the trusted measurement module (herein referring to the static trusted measurement module). The following takes the CPU in the host with an X86 architecture and the operating system as Linux as an example for more detailed description. As Figure 2 shown, after the Linux system starts, the static trusted measurement module uses the root of trusted measurement to perform trusted measurement on the basic input / output system of the operating system. After the basic input / output system starts, it uses the basic input / output system to perform trusted measurement on the operating system loader. After the operating system loader starts, it uses the operating system loader to perform trusted measurement on the operating system kernel. After the operating system kernel starts, it uses the operating system kernel to perform trusted measurement on system applications. Through such a process of step-by-step measurement, a startup trust chain can be established. The static trusted measurement values obtained by measuring the next level at each level during the startup process are centrally recorded in the trusted measurement module (herein referring to the static trusted measurement module).

[0081] In another example, the static trusted measurement module can also perform trusted measurement on the host when a certain program in the host is loaded to obtain the static trusted measurement value of the host at the moment when the program is loaded.

[0082] The dynamic trusted measurement module can be used to dynamically determine the integrity of the measured host. Specifically, during the running stage after the host operating system starts, it can perform dynamic measurement on a predetermined part of the operating system to obtain the dynamic trusted measurement value. In one example, the dynamic measurement module can continuously scan and measure the key parts of the operating system during the running process of the host operating system to obtain the dynamic trusted measurement value and store it in the trusted measurement module (herein referring to the dynamic trusted measurement module). Generally speaking, compared with the static trusted measurement value, the dynamic trusted measurement value is more real-time and can more accurately reflect the credibility of the host.

[0083] Optionally, in an embodiment of the present invention, obtaining the trusted measurement value of the host of the computer system (step S11) may include: obtaining the trusted measurement value of the host of the computer system through the trusted measurement module; wherein, the trusted measurement module and the peripheral device are within the same module; or, the trusted measurement module is provided in the peripheral device; or, the trusted measurement module is provided in the host.

[0084] In an embodiment of the present invention, the trusted measurement module can obtain and store the trusted measurement value of the host. The trusted measurement value can be either a static trusted measurement value, a dynamic trusted measurement value, or both. Then, the peripheral device can obtain the trusted measurement value of the host of the computer system from the trusted measurement module. The position of the trusted measurement module can be set in a variety of ways. Specifically, the trusted measurement module and the peripheral device can be set in the same module to improve the security of the trusted measurement value during transmission. Similarly, the trusted measurement module can also be set inside the peripheral device to facilitate the peripheral device to obtain the trusted measurement value from the trusted measurement module; or, the trusted measurement module can be set inside the host to facilitate storing the trusted measurement value of the host into the trusted measurement module. It should be noted that as long as the peripheral device can obtain the trusted measurement value from the trusted measurement module, regardless of the position of the trusted measurement module, it falls within the protection scope of the embodiment of the present invention.

[0085] Optionally, in an embodiment of the present invention, the trusted measurement module and the peripheral device are connected through a physical line or through a logical link.

[0086] In an example of the embodiment of the present invention, the secure channel between the trusted measurement module and the peripheral device can be implemented in a way of physical line connection. For example, the two can be connected through a dedicated bus without sharing the bus with other data transmission processes, thereby improving the security of the trusted measurement value during transmission. In another example, the trusted measurement module and the peripheral device can also be set inside the same module, which can also reduce the possibility of the trusted measurement value being tampered with during transmission and improve the security of the trusted measurement value during transmission. In yet another example, the trusted measurement module and the peripheral device can also be connected through a logical link. Specifically, the trusted measurement value can be encrypted in advance using an encryption algorithm so that the trusted measurement value is transmitted between the trusted measurement module and the peripheral device in an encrypted form, thereby improving the security of the trusted measurement value during transmission.

[0087] Optionally, in an embodiment of the present invention, obtaining the trusted measurement value of the host of the computer system (step S11) includes: when receiving an access request from the host, or periodically obtaining the trusted measurement value of the host.

[0088] In an embodiment of the present invention, in one example, the peripheral device may periodically obtain the trusted measurement value from the trusted measurement module, and compare the obtained trusted measurement value with the measurement reference value, so as to determine the credibility of the host. There will be a time period between the acquisition time of the trusted measurement value in this example and the time when the host sends an access request to access the peripheral device in the subsequent process. During this time period, if the host is under a network attack, the trusted measurement value of the host may change to some extent. Therefore, the trusted measurement value obtained by the above method can only roughly reflect the credibility of the host at the moment when the host sends an access request to access the peripheral device.

[0089] In another example, when the peripheral device receives an access request from the host, it may obtain the trusted measurement value of the host from the trusted measurement module, and compare the trusted measurement value of the host with the measurement reference value. If the two are equal, it is confirmed that the host is trusted, and thus the host can be allowed to access the peripheral device. Then the peripheral device can process the data in response to the host's access request and return the processing result to the host. In this example, the acquisition time of the trusted measurement value is almost exactly the same as the time when the host sends an access request to the peripheral device. Therefore, the real-time performance of this trusted measurement value is better, and it can more accurately reflect the credibility of the host at the moment when the host sends an access request to access the peripheral device.

[0090] Optionally, in an embodiment of the present invention, determining whether to allow the host to access the peripheral device according to the comparison result (step S13) may include: determining whether to reject all or part of the access requests of the host to the peripheral device according to the comparison result.

[0091] In an embodiment of the present invention, if the trusted measurement value is not equal to the measurement reference value, the peripheral device confirms that the host is not trusted, and then may reject all access requests of the host according to the specific type of the host and the specific comparison result, that is, the host is not allowed to access the peripheral device under any circumstances, so as to ensure the security of all data; or when the two are not equal, the peripheral device may reject part of the access requests of the host according to the specific type of the host and the specific comparison result, and at the same time respond to another part of the access requests of the host, so that the host can access the unimportant data in the peripheral device but cannot access the important data in the peripheral device, thus ensuring the security of the important data.

[0092] Optionally, in an embodiment of the present invention, the peripheral device has a first command interface; before comparing the trusted measurement value of the host with the previously obtained measurement reference value of the host (step S12), the access control method may further include: receiving the import of the trusted platform configuration information of the host through the first command interface, and the trusted platform configuration information includes the measurement reference value of the host.

[0093] Generally speaking, a peripheral device can form a computer system with multiple different types of hosts. For example, when the peripheral device is a disk, it can be installed on a host of model A or a host of model B. Different types of hosts have different measurement benchmark values due to different configurations. Therefore, in order to determine whether a host is trustworthy, it is first necessary to obtain the measurement benchmark value corresponding to the host. In a specific implementation, regardless of the type of host to which the peripheral device is connected, the peripheral device can import the trusted platform configuration information of the host through the first command interface and obtain the measurement benchmark value of the host from the trusted platform configuration information. In this way, regardless of the type of host used in combination with the peripheral device, the peripheral device can obtain the reference measurement value of the host to facilitate determining whether the host is trustworthy. In the case of replacing the host subsequently, the trusted platform configuration information of the new host can be imported again, and the reference measurement value of the new host can be obtained from it to facilitate confirming whether the new host is trustworthy.

[0094] Optionally, in an embodiment of the present invention, the peripheral device has a second command interface; receiving the import of the trusted platform configuration information of the host through the first command interface includes: receiving the import of the platform certificate of the host through the second command interface; determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate; if so, receiving the import of the trusted platform configuration information of the host through the first command interface; where the first command interface and the second command interface are the same command interface or two different command interfaces.

[0095] In the embodiment of the present invention, as Figure 4 shown, the value of the first flag bit in the platform certificate is used to indicate whether to allow the import of the trusted platform configuration information. Before importing the platform certificate, the value of the first flag bit of the platform certificate can be preset according to actual needs. For example, if the peripheral device is allowed to import the trusted platform configuration information, the value of the first flag bit can be set to, and if the peripheral device is not allowed to import the trusted platform configuration information, the value of the first flag bit can be set to 0.

[0096] After that, when the peripheral device imports the platform certificate of the host through the second command interface, the peripheral device can determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate. Specifically, when the peripheral device detects that the value of the first flag bit is, it receives the import of the trusted platform configuration information, and when the peripheral device detects that the value of the first flag bit is 0, it rejects the import of the trusted platform configuration information. In this way, for any peripheral device, by presetting the value of the first flag bit in the platform certificate, the import of the trusted platform configuration information by the peripheral device can be flexibly controlled.

[0097] Optionally, in an embodiment of the present invention, the platform certificate includes a first digital signature encrypted with a first private key, and a first public key corresponding to the first private key is set in the peripheral device; when receiving the import of the platform certificate of the host through the second command interface, the access control method may further include: verifying the first digital signature with the first public key;

[0098] Correspondingly, determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate may include: if the verification is passed, determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate.

[0099] In an embodiment of the present invention, before using the peripheral device, it needs to be activated, and the peripheral device can only be used normally after successful activation. Specifically, the process of activating the peripheral device is to first import the platform certificate and verify the authenticity of the platform certificate. Only when the verification is passed does it indicate that the platform certificate is true and reliable, that is, the successful activation of the peripheral device is achieved.

[0100] Such as Figure 4 shown, in order to verify the authenticity of the platform certificate, the manufacturer of the peripheral device can pre-sign the platform certificate with the first key to form a first digital signature, and set a first public key corresponding to the foregoing first private key in the peripheral device. The first private key and the first public key are a pair of key pairs. In one example, when performing digital signature, an asymmetric cryptographic algorithm can be used, such as the national cryptographic SM2 algorithm.

[0101] When the platform certificate is imported into the peripheral device through the second command interface, the first public key in the peripheral device can be used to verify the first digital signature in the platform certificate. If the verification is passed, it indicates that the platform certificate has not been tampered with and is true and reliable. If the verification fails, it indicates that the platform certificate is not true and reliable, so it can be not adopted. When it is determined that the platform certificate is true and reliable, the peripheral device will determine whether to import the trusted platform configuration information according to the value of the first flag bit in the platform certificate. In this way, since the authenticity of the platform certificate is verified by using the digital signature method, the authenticity of the platform certificate can be ensured, and thus the security of the data in the peripheral device can be improved.

[0102] Optionally, in an embodiment of the present invention, the platform certificate contains a second public key, and the trusted platform configuration information includes a second digital signature encrypted with a second private key corresponding to the second public key;

[0103] After receiving the import of the trusted platform configuration information of the host through the first command interface, the access control method may further include: verifying the second digital signature according to the second public key; if the verification is passed, obtaining the measurement reference value from the trusted platform configuration information.

[0104] As Figure 4 shown, in order to verify the authenticity of the trusted platform configuration information, before importing the trusted platform configuration information, the second public key may be set in the aforementioned platform certificate in advance, and the trusted platform configuration information may be digitally signed using the second private key corresponding to the second public key (the second public key and the second private key are a pair of key pairs) to form a second digital signature. After importing the trusted platform configuration information through the first command interface, the second public key may be obtained from the platform certificate, and the second digital signature may be verified using the second public key. If the verification is passed, it indicates that the trusted platform configuration information is true and reliable. Therefore, the measurement reference value may be further obtained from the trusted platform configuration information. If the verification fails, it indicates that the trusted platform configuration information is not true and reliable. Therefore, it may not be adopted, thereby ensuring the authenticity of the obtained measurement reference value and further improving the security of the data in the peripheral device.

[0105] In addition to including the aforementioned first flag bit, the first digital signature, and the second public key, the platform certificate may further include: information such as the identification number of the peripheral device and the generation time of the platform certificate.

[0106] In a third aspect, an embodiment of the present invention further provides a non-transitory computer-readable storage medium having one or more programs, and the one or more programs can be executed by one or more processors to implement any one of the access control methods provided in the foregoing embodiments. The specific execution process of the processor for the above steps and the steps further executed by the processor by running the executable program code may refer to the description of the foregoing embodiments and will not be elaborated herein.

[0107] It should be noted that in this article, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "including a..." does not exclude the existence of another identical element in the process, method, article or device including the element.

[0108] Each embodiment in this specification is described in a related manner. For the same or similar parts among the embodiments, reference can be made to each other. The key point of each embodiment is to illustrate the differences from other embodiments.

[0109] In particular, for the device embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference can be made to the partial description of the method embodiments.

[0110] For the convenience of description, the above device is described by dividing its functions into various units / modules. Of course, when implementing the present invention, the functions of each unit / module can be realized in the same or multiple software and / or hardware.

[0111] Those of ordinary skill in the art can understand that all or part of the processes of implementing the methods in the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), or the like.

[0112] As mentioned above, the above are only the specific implementation manners of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered by the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.

Claims

1. A computer system, characterized in that, Comprising: A host, a trusted measurement module, and a peripheral device; the trusted measurement module is respectively connected to the host and the peripheral device; the host includes a CPU, a memory, and a motherboard; wherein, The trusted measurement module is used to obtain the trusted measurement value of the host; The peripheral device is used to obtain the trusted measurement value of the host from the trusted measurement module, compare the trusted measurement value of the host with a measurement reference value, and determine whether to allow the host to access according to the comparison result; Wherein, the peripheral device has a first command interface, and the first command interface is used to receive the import of the trusted platform configuration information of the host, and the trusted platform configuration information contains the measurement reference value of the host.

2. The computer system according to claim 1, wherein The trusted measurement module includes a first trusted measurement module and / or a second trusted measurement module; wherein, The first trusted measurement module is used to record the trusted measurement value of the operating system startup process of the host; The second trusted measurement module is used to record the trusted measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the operating system is started.

3. The computer system according to claim 1, wherein The trusted measurement module and the peripheral device are connected through a physical line or through a logical link.

4. The computer system according to claim 1, wherein The trusted measurement module and the peripheral device are within the same module; or, The trusted measurement module is provided in the peripheral device; or, The trusted measurement module is provided in the host.

5. The computer system according to claim 1, wherein The peripheral device is specifically used for: when receiving an access request from the host, or periodically obtaining the trusted measurement value of the host from the trusted measurement module, comparing the trusted measurement value of the host with the measurement reference value, and determining whether to reject all or part of the access requests of the host according to the comparison result.

6. The computer system according to claim 1, characterized in that, The peripheral device has a second command interface, and the second command interface is used to receive the import of the platform certificate of the host; The peripheral device is further used to determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate; wherein, the first command interface and the second command interface are the same command interface or two different command interfaces.

7. The computer system according to claim 6, wherein The platform certificate includes a first digital signature encrypted with a first private key, and a first public key corresponding to the first private key is set in the peripheral device; When receiving the import of the platform certificate through the second command interface, the peripheral device is further used to verify the first digital signature with the first public key, and if the verification is passed, determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate.

8. The computer system according to claim 6 or 7, wherein The platform certificate contains a second public key, and the trusted platform configuration information includes a second digital signature encrypted with a second private key corresponding to the second public key; After receiving the import of the trusted platform configuration information through the first command interface, the peripheral device is further configured to verify the second digital signature using the second public key, and if the verification is passed, obtain the measurement reference value from the trusted platform configuration information.

9. An access control method, applied to a peripheral device of a computer system, characterized in that, The access control method includes: Obtaining a trusted measurement value of a host of a computer system; the host includes a CPU, a memory, and a motherboard; Comparing the trusted measurement value of the host with a previously obtained measurement reference value of the host; Determining whether to allow the host to access the peripheral device according to the comparison result; Wherein, the peripheral device has a first command interface; Before comparing the trusted measurement value of the host with a previously obtained measurement reference value of the host, the access control method further includes: Receiving the import of the trusted platform configuration information of the host through the first command interface, and the trusted platform configuration information includes the measurement reference value of the host.

10. The access control method according to claim 9, wherein The trusted measurement value is the trusted measurement value of the startup process of the operating system of the host; And / or, The trusted measurement value is the trusted measurement value obtained by dynamically measuring a predetermined part of the operating system during the operation after the operating system of the host is started.

11. The access control method according to claim 9, wherein The obtaining of the trusted measurement value of the host of the computer system includes: Obtaining the trusted measurement value of the host of the computer system through a trusted measurement module; wherein, The trusted measurement module is within the same module as the peripheral device; or, The trusted measurement module is provided in the peripheral device; or, The trusted measurement module is provided in the host.

12. The access control method according to claim 11, wherein The trusted measurement module and the peripheral device are connected by a physical line or by a logical link.

13. The access control method according to claim 9, wherein The obtaining of the trusted measurement value of the host of the computer system includes: when receiving an access request of the host, or periodically obtaining the trusted measurement value of the host.

14. The access control method according to claim 9, wherein The determining whether to allow the host to access the peripheral device according to the comparison result includes: Determining whether to reject all or part of the access requests of the host to the peripheral device according to the comparison result.

15. The access control method according to claim 9, wherein, The peripheral device has a second command interface; The receiving the import of the trusted platform configuration information of the host through the first command interface includes: Receiving the import of the platform certificate of the host through the second command interface; Determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate; If so, receiving the import of the trusted platform configuration information of the host through the first command interface; wherein, the first command interface and the second command interface are the same command interface or two different command interfaces.

16. The access control method according to claim 15, wherein The platform certificate includes a first digital signature encrypted using a first private key, and a first public key corresponding to the first private key is provided in the peripheral device; When receiving the import of the platform certificate of the host through the second command interface, the access control method further includes: verifying the first digital signature using the first public key; Correspondingly, determining whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate includes: If the verification is passed, determine whether to receive the import of the trusted platform configuration information according to the value of the first flag bit in the platform certificate.

17. The access control method according to claim 15 or 16, wherein The platform certificate contains a second public key, and the trusted platform configuration information includes a second digital signature encrypted using the second private key corresponding to the second public key; After receiving the import of the trusted platform configuration information of the host through the first command interface, the access control method further includes: Verifying the second digital signature according to the second public key; If the verification is passed, obtain the measurement reference value from the trusted platform configuration information.

18. A non-transitory computer-readable storage medium, characterized in that, The non-transitory computer-readable storage medium stores computer instructions for causing the computer to execute the access control method according to any one of claims 9 to 17.

Citation Information

Patent Citations

  • Trusted processor chip realized in multi-redundancy mode and in-chip trusted measurement method

    CN115081034A