Terminal trusted access control method and apparatus

By introducing trust measurement and verification procedures into the terminal, trust measurement of boot process and operating system is performed, which solves the problem of low security in the interaction between the terminal and the IoT platform, improves the reliability and security of terminal access control, and reduces the computing pressure on the platform.

CN115834215BActive Publication Date: 2026-04-28BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD +3
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
BEIJING SMARTCHIP MICROELECTRONICS TECHNOLOGY CO LTD
Filing Date
2022-11-25
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

The interaction between the terminal and the IoT platform has low security and is vulnerable to malicious attacks by illegal programs.

Method used

By introducing a trust measurement program and a trust verification program into the terminal, the trustworthiness of the bootloader and operating system is measured, a trustworthiness value is generated, and compared with a benchmark trustworthiness value. If they do not match, the executable program is prohibited from running and an alarm message is issued to ensure the trustworthiness of the terminal's access to the IoT platform.

Benefits of technology

It improves the reliability and security of the interaction between the terminal and the IoT platform, reduces the computing pressure on the IoT platform, reduces resource waste, and enhances the reliability and flexibility of terminal access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115834215B_ABST
    Figure CN115834215B_ABST
Patent Text Reader

Abstract

The application discloses a terminal trusted access control method and device. A trusted verification program in the terminal can determine whether to prohibit an executable program based on a first trustworthiness value of a boot program after a processor is started, so that the trusted verification program in the terminal can also issue an alarm information in the case that the first trustworthiness value of the boot program is different from a first reference trustworthiness value, so as to facilitate maintenance personnel to maintain the terminal, and the reliability and flexibility of the terminal access control are improved. Moreover, the Internet of Things platform does not need to verify the identity of the terminal, so that the computing pressure of the Internet of Things platform is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, specifically to a terminal trusted access control method and apparatus. Background Technology

[0002] The Internet of Things (IoT) typically includes at least one IoT device, a terminal, and an IoT platform. The at least one IoT device is used to transmit collected data to the terminal. The terminal is used to manage the data sent by the at least one IoT device and transmit the data to the IoT platform, which is used to analyze the data sent by the terminal.

[0003] In related technologies, after startup, the terminal needs to establish a network connection with the IoT platform. After successfully establishing a network connection, the terminal can send data to the IoT platform. However, if the terminal is maliciously attacked by illegal programs, the security of the interaction between the terminal and the IoT platform will be low. Summary of the Invention

[0004] In view of the above problems, this application provides a terminal trusted access control method and apparatus, which can solve the problem of low security in the interaction between the terminal and the Internet of Things platform in the related technology.

[0005] On the one hand, a terminal trusted access control method is provided, applied to a terminal, wherein the terminal has a trusted measurement program, a trusted verification program, a boot program, a processor, and an executable program, and the method includes:

[0006] The trust measurement program responds to the boot command and starts the processor after performing a trust measurement on the boot loader;

[0007] The trust verification program obtains the first trust value for the trustworthiness measurement of the bootloader from the trust measurement program;

[0008] If the trust verification procedure determines that the first trust value is different from the first benchmark trust value, it will prohibit the execution of the executable program and issue an alarm message. The executable program includes a network connection program for establishing a network connection with the Internet of Things platform.

[0009] Optionally, the terminal also has an operating system; after the trust measurement program starts the processor, the method further includes:

[0010] The bootloader performs a trustworthiness check on the operating system and then boots it up.

[0011] The trust verification program obtains a second trust value from the bootloader to measure the trustworthiness of the operating system;

[0012] If the reliability verification procedure determines that the first reliability value differs from the first baseline reliability value, it will prevent the executable program from running and issue an alarm message, including:

[0013] If the reliability verification procedure determines that the first reliability value is different from the first benchmark reliability value, and / or the second reliability value is different from the second benchmark reliability value, it will prohibit the executable program from running and issue an alarm message.

[0014] Optionally, the method also includes:

[0015] If the credibility verification procedure determines that the first credibility value is the same as the first baseline credibility value, then the executable program is allowed to run.

[0016] Optionally, if the confidence verification procedure determines that the first confidence value is the same as the first baseline confidence value, then the executable program is allowed to run, including:

[0017] If the credibility verification procedure determines that the first credibility value is the same as the first baseline credibility value, and the second credibility value is the same as the second baseline credibility value, then the executable program is allowed to run.

[0018] Optionally, the trust verification procedure allows the executable program to run, including:

[0019] The trust verification procedure responds to the execution instructions for the executable program and performs integrity verification on the executable program;

[0020] If the trust verification procedure successfully verifies the executable program, then the executable program is allowed to run.

[0021] Optionally, the method also includes:

[0022] If the trust verification procedure fails to verify the executable program, it will prevent the executable program from running.

[0023] Optionally, after the trust verification procedure prevents the executable program from running, the method further includes:

[0024] The trust verification procedure issues an initial prompt message, which includes information about the executable program.

[0025] Optionally, after the trust verification procedure allows the executable program to run, the method further includes:

[0026] The trust verification program performs integrity verification on the target files that the executable program needs to call to run. The target files include at least one of the configuration files and library files.

[0027] If the trust verification program fails to verify the target file, it prohibits the executable program from calling the target file; if the verification of the target file is successful, it allows the executable program to call the target file.

[0028] Optionally, after the trust verification procedure prevents the executable program from calling the target file, the method further includes:

[0029] The trust verification procedure issues a second prompt message, which includes information about the target file.

[0030] Optionally, the terminal's operating system includes Linux, and the terminal also has a login authentication program; after the processor is started, the method further includes:

[0031] If the login verification program receives login requests for the target account within the target time period and fails to verify all login requests within the target number of times, the trusted verification program will be prohibited from starting. The target number of login requests is positively correlated with the target account's level.

[0032] If the login verification process receives fewer than or equal to the target number of login requests for the target account within the target time period, and the login requests are successfully verified, then the trusted verification process is allowed to start.

[0033] On the other hand, a computer-readable storage medium is provided that stores a terminal trusted access control program thereon, which, when executed by a processor, implements the terminal trusted access control method described above.

[0034] In another aspect, a terminal is provided, including a memory, a trusted measurement program, a processor, and a terminal trusted access control program stored in the memory and capable of running on the trusted measurement program and the processor. When the trusted measurement program and the processor execute the terminal trusted access control program, they implement the terminal trusted access control method described above.

[0035] On the other hand, a terminal trusted access control device is provided, the device including: a trusted measurement module, a power-on guidance module and a trusted verification module;

[0036] The trust measurement module is used to start the processor in the terminal after performing a trust measurement on the boot module in response to the boot command;

[0037] The trust verification module is used to obtain a first trust value from the trust measurement module to measure the trustworthiness of the boot module; if it is determined that the first trust value is different from the first benchmark trust value, the executable program in the terminal is prohibited from running and an alarm message is issued. The executable program includes a network connection program for establishing a network connection with the Internet of Things platform.

[0038] Optionally, a boot module is used to perform a trustworthiness measurement on the operating system in the terminal after the trust measurement module starts the processor in the terminal, and then boot the operating system.

[0039] The reliability verification module is also used for:

[0040] Obtain a second credibility value from the boot module to measure the credibility of the operating system;

[0041] If it is determined that the first confidence value is different from the first baseline confidence value, and / or the second confidence value is different from the second baseline confidence value, then the executable program is prohibited from running and an alarm message is issued.

[0042] Optionally, the reliability verification module is also used for:

[0043] If the first confidence value is determined to be the same as the first baseline confidence value, then the executable program is allowed to run.

[0044] Optionally, the reliability verification module is also used for:

[0045] If it is determined that the first confidence value is the same as the first baseline confidence value, and the second confidence value is the same as the second baseline confidence value, then the executable program is allowed to run.

[0046] Optional, a trust verification module is used for:

[0047] In response to the execution instructions for the executable program, perform integrity verification on the executable program;

[0048] If the executable program is successfully verified, it is allowed to run.

[0049] Optionally, the reliability verification module is also used for:

[0050] If the executable program fails to be verified, the executable program will be prevented from running.

[0051] Optionally, the trust verification module allows the executable program to also be used after execution for:

[0052] Perform integrity verification on the target files that the executable program needs to call to run, including at least one of configuration files and library files;

[0053] If the verification of the target file fails, the executable program is prohibited from calling the target file; if the verification of the target file succeeds, the executable program is allowed to call the target file.

[0054] Optionally, the terminal's operating system includes Linux; the device also includes: a login verification module, used for:

[0055] After the trusted measurement module starts the processor in the terminal, if the number of login messages for the target account received within the target time period reaches the target number, and the verification of the target number of login messages fails, the trusted verification module is prohibited from starting. The target number is positively correlated with the level of the target account.

[0056] If the number of login requests for the target account received within the target time period is less than or equal to the target number, and the login information is successfully verified, then the trust verification module is allowed to start.

[0057] On the other hand, an Internet of Things (IoT) is provided, which includes: at least one IoT device, a terminal, and an IoT platform;

[0058] Each IoT device is used to send the collected data to the terminal;

[0059] The terminal includes the trusted access control device for terminals described above;

[0060] The Internet of Things (IoT) platform is used to receive data sent by terminals.

[0061] Additional aspects and advantages of this disclosure will be set forth in part in the description which follows, and in part will be obvious from the description, or may be learned by practice of this disclosure. Attached Figure Description

[0062] Figure 1 This is a schematic diagram of an Internet of Things (IoT) structure provided in an embodiment of this disclosure;

[0063] Figure 2 This is a flowchart of a terminal trusted access control method provided in an embodiment of this disclosure;

[0064] Figure 3 This is a flowchart of another terminal trusted access control method provided in this disclosure embodiment;

[0065] Figure 4 This is a schematic diagram of the structure of a terminal provided in an embodiment of this disclosure;

[0066] Figure 5 This is a block diagram of a terminal trusted access control device provided in an embodiment of this disclosure;

[0067] Figure 6 This is a block diagram of another terminal trusted access control device provided in the embodiments of this disclosure. Detailed Implementation

[0068] Embodiments of this disclosure are described in detail below, examples of which are illustrated in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and intended to explain this disclosure, and should not be construed as limiting this disclosure.

[0069] Driven by the growth in energy and electricity demand, the world's power grid has gradually evolved from traditional grids to modern grids, and from isolated urban grids to large-scale inter-regional and transnational internet networks, entering a new stage marked by robust smart grids. The power Internet of Things (IoT), constructed through advanced sensors, intelligent devices, and diverse networks, enables real-time monitoring of the power grid, users, distribution lines, smart substations, power plants, and related energy objects at all stages of power generation, transmission, transformation, distribution, and consumption. This achieves panoramic and holographic perception, information interconnection, and intelligent control at the energy internet level, playing a crucial driving role in the construction and operation of the energy internet. The energy internet and the power IoT are inseparable; the network and information security of the power IoT directly affects the production and operational security of the energy internet, and is an important aspect that the State Grid Corporation of China needs to consider regarding network and information security.

[0070] In related technologies, after power terminal startup, it can send a network connection request to an IoT platform. After successful authentication of the power terminal, the IoT platform can establish a network connection and exchange data. Specifically, the power terminal sends a network connection request to the IoT platform's access gateway. Upon receiving the request, the access gateway sends a network access decision request to the IoT platform's authentication server. If the authentication server is configured to operate in the order of user authentication, platform authentication, and integrity check, subsequent authentication will not occur if one authentication fails. User authentication occurs between the authentication server and the power terminal. Platform authentication and integrity checks occur between the IoT platform's access client and access server.

[0071] If user authentication between the power terminal and the authentication server is successful, the authentication server notifies the access server of a connection request. The access server and the access client then perform platform verification and integrity verification. If platform verification and integrity verification between the access server and the access client are successful, the authentication server sends a network access decision to the access gateway. The access gateway executes the authentication server's decision, and the network connection process ends.

[0072] However, with the construction of the power Internet of Things (IoT), the power IoT platform faces the challenges of massive heterogeneous terminal access and the pressure of explosive growth in power data processing. Currently, in the context of massive terminals accessing the IoT platform, the power IoT platform has limited computing resources and it is difficult to effectively authenticate the terminals communicating with it. This allows attackers to impersonate legitimate terminals and interact with the power grid platform to carry out coordinated attacks on both the information and physical sides.

[0073] Figure 1This is a schematic diagram of the structure of an Internet of Things (IoT) provided in an embodiment of the present disclosure. The IoT may include at least one IoT device 10, a terminal 20, and an IoT platform 30. The IoT may be a power IoT, and the corresponding terminal 20 may be a power terminal. Figure 1 The following explanation uses an example of an Internet of Things (IoT) system comprising three IoT devices (10).

[0074] In this context, at least one IoT device 10 can establish a connection with the terminal 20, and the terminal 20 can establish a connection with the IoT platform 30, through a wired network or a wireless network.

[0075] Each IoT device 10 can be a data acquisition device, such as a temperature sensor or humidity sensor installed in a cable channel, and the IoT device 10 is used to transmit the real-time acquired data to the terminal 20.

[0076] The terminal 20 can be a terminal operated by administrators, such as a computer. The terminal 20 can centrally manage the data collected by the IoT device 10 and send the data collected by the IoT device 10 to the IoT platform 30 when the IoT platform 30 needs to perform data analysis.

[0077] The IoT platform 30 can be a device capable of analyzing data. For example, it can be a server, a server cluster consisting of several servers, or a cloud computing service center. The IoT platform 30 is used to analyze the received data.

[0078] The IoT platform 30 may include a power grid dispatch center platform, an information cloud platform, a supercomputing center platform, an information security platform, an artificial intelligence platform, and so on. The IoT platform 30 can include three main categories of data: power grid production control, enterprise management, and business marketing. It can upload various data to the application layer to achieve application functions such as customer service management, transmission and distribution management, production management, safety management, and business management, thereby achieving the goals of dispatching, trading, management, operation, and maintenance.

[0079] Figure 2 This is a flowchart of a terminal trusted access control method provided in an embodiment of this disclosure. This method can be applied to... Figure 1 In the terminal shown, such as Figure 2 As shown, the method includes:

[0080] Step 201: The trust measurement program responds to the boot command and starts the processor after performing a trust measurement on the boot loader.

[0081] In this embodiment, the terminal may have a trust measurement program, a bootloader, and a processor. The trust measurement program may be a trusted platform control module (TPCM), and the bootloader is a program hard-coded into the terminal's hardware, used to boot the operating system in the terminal. The processor may be a central processing unit (CPU).

[0082] Upon receiving a boot command, the trust measurement program can respond by performing a trust measurement on the bootloader, and then start the processor after performing the trust measurement. In other words, during the terminal boot process, the trust measurement program starts before the processor, and only starts the processor after performing a feasibility measurement on the bootloader.

[0083] Step 202: The trust verification procedure obtains the first trust value from the trust measurement procedure to measure the trustworthiness of the bootloader.

[0084] In this embodiment of the disclosure, after the processor in the terminal starts up, the processor can start the trust verification program, which can obtain a first trust value from the trust measurement program to measure the trustworthiness of the bootloader.

[0085] Step 203: If the credibility verification procedure determines that the first credibility value is different from the first benchmark credibility value, it will prohibit the executable program from running and issue an alarm message.

[0086] The terminal may also contain an executable program. After obtaining the first trust value of the bootloader, the trust verification program can check whether this first trust value is the same as the first baseline trust value. If the first trust value is different from the first baseline trust value, it can be determined that the bootloader has been maliciously tampered with, and the trust value of the bootloader is low. Therefore, the executable program on the terminal can be prevented from running, and an alarm message can be issued. The first baseline trust value is pre-stored in the trust verification program.

[0087] Optionally, the executable program may include a network connection program. After the trust verification program determines that the first trust value of the bootloader is different from the first benchmark trust value, it may prohibit the network connection program from running, thereby preventing the network connection program from establishing a network connection with the IoT platform, thereby preventing the terminal from accessing the IoT platform.

[0088] In summary, the embodiments of this disclosure provide a terminal trusted access control method. In this method, the trusted verification program in the terminal determines whether to run an executable program in the terminal based on a first trusted value obtained by a trusted measurement program from the trusted bootloader. If the first trusted value of the bootloader differs from a first baseline trusted value, the executable program is prohibited from running, thereby ensuring that all executable programs running in the terminal are trusted. This ensures the trustworthiness of the terminal establishing a network connection with the IoT platform, improves the reliability of terminal access control, and consequently enhances the reliability of the interaction between the terminal and the IoT platform.

[0089] Furthermore, since the decision to disable executable programs is based on the first trust value of the bootloader after processor startup, the trust verification program in the terminal can issue an alarm even if the first trust value of the bootloader differs from the first baseline trust value. This facilitates maintenance personnel in repairing the terminal, improving the reliability and flexibility of terminal access control. Moreover, because no authentication of the terminal is required by the IoT platform, the computational burden on the IoT platform is reduced, avoiding waste of IoT platform resources.

[0090] Figure 3 This is a flowchart of another terminal trusted access control method provided in this disclosure embodiment, which can be applied to... Figure 1 In the terminal shown, such as Figure 3 As shown, the method may include:

[0091] Step 301: The trust measurement program responds to the boot command and starts the processor after performing a trust measurement on the boot loader.

[0092] In this embodiment, the terminal may have a trust measurement program, a bootloader, and a CPU. The trust measurement program may be a TPCM (Trust Management Processor), and the trust measurement level may be integrated into a single chip. The bootloader is used to boot the operating system in the terminal, and it is a program hard-coded into the terminal's hardware. The processor may be a CPU.

[0093] Upon receiving a boot command, the trust measurement program can respond by performing a trust measurement on the bootloader, and then start the processor in the terminal. In other words, during the terminal boot process, the trust measurement program starts before the processor, and only after performing a trust measurement on the bootloader does the processor start.

[0094] The trust measurement program can use a verification algorithm to measure the trustworthiness of the bootloader and generate a first trustworthiness value. This verification algorithm can include algorithms such as digest algorithms and hash algorithms. During the trust measurement process, the program can prevent the processor from starting. After the trust measurement, the processor can be started. Optionally, the trust measurement program can control the processor startup via power supply and bus.

[0095] Step 302: The bootloader performs a trustworthiness measurement on the operating system and then boots the operating system.

[0096] In this embodiment of the disclosure, the terminal also has an operating system. After the processor in the terminal starts, the bootloader in the terminal starts first. The bootloader performs a trustworthiness measurement on the operating system in the terminal, and then boots the operating system. Optionally, the operating system may include Windows operating system and Linux operating system, etc.

[0097] Optionally, the bootloader can use a verification algorithm to measure the trustworthiness of the operating system and generate a second trustworthiness value.

[0098] Step 303: If the login verification program receives login information for the target account a target number of times within the target time period, and all login information fails to be verified for the target number of times, then the trusted verification program in the terminal is prohibited from starting.

[0099] In this embodiment, the terminal may also have a login verification program. The terminal's operating system may include a Linux operating system. After the operating system starts, the login verification program in the terminal can display a login interface. The login verification program can receive login information entered by the user on the login interface, which may include a login account and a login password. The login verification program may be a program within the operating system.

[0100] If the login verification program receives a target number of login requests for a target account within a target duration, and all of these login requests fail verification, the trusted verification process on the terminal can be disabled, thus preventing login from the terminal. The target number of attempts is positively correlated with the target account's level; the higher the target account's level, the more attempts are allowed, and the more times the target account can attempt to log in within the target duration. Conversely, the lower the target account's level, the fewer attempts are allowed, and the fewer times the target account can attempt to log in within the target duration. The target duration can be pre-stored in the login verification program; for example, the target duration could be 5 minutes.

[0101] Optionally, the login verification procedure can pre-store the correspondence between multiple login accounts and multiple login counts. The login count for each login account refers to the number of times that account logs in within a target duration. The login count in this correspondence is positively correlated with the login account's level. These multiple login accounts can include super accounts, regular accounts, and invalid accounts. The super account has a higher level than the regular account, and the regular account has a higher level than the invalid account. Consequently, the super account has more login counts than the regular account, and the regular account has more login counts than the invalid account.

[0102] After receiving the target account, the login verification procedure can determine the target number of times corresponding to that target account from the mapping relationship. For example, the target number of times corresponding to this target account can be 5.

[0103] In this embodiment, the login interface may include an account input box, a password input box, and a login button. The login verification program can obtain the user-entered login account from the account input box and the user-entered login password from the password input box. After receiving a selection operation on the login button, it can search for a reference account that matches the login account from a pre-stored database of multiple account-password mappings. If no reference account matching the login account is found, the login information verification is considered failed. If a reference account matching the login account is found, the login password and the reference password corresponding to the reference account are compared. If the login password matches the reference password, the login information verification is considered successful; if the login password does not match the reference password, the login information verification is considered failed.

[0104] By limiting the number of login attempts and the frequency of logins, the reliability and security of logins are improved by reducing the number of login attempts. Furthermore, setting different number of attempts for different account levels increases the flexibility of login.

[0105] Step 304: If the login verification procedure receives fewer than or equal to the target number of login requests for the target account within the target time period, and the login information is successfully verified, then the trusted verification procedure is allowed to start.

[0106] The terminal also has a trusted verification procedure. If the login verification procedure receives fewer than or equal to a target number of login requests for the target account within a target time period, and successfully verifies the login information, then the trusted verification procedure in the terminal can be allowed to start. In this embodiment of the disclosure, successful verification of the login information by the login verification procedure can refer to successful verification of the last received login information.

[0107] For example, assuming the target number of login attempts is 5, if the login verification program receives login information for the target account 3 times within the target duration, and successfully verifies the third login information received, then the trusted verification program can be allowed to start.

[0108] Step 305: The trust verification program obtains the first trust value for trust measurement of the bootloader from the trust measurement program, and obtains the second trust value for trust measurement of the operating system from the bootloader.

[0109] After successfully verifying the login information and allowing the trusted verification program to start, the trusted verification program can obtain a first trustworthiness value from the trusted measurement program to measure the trustworthiness of the bootloader, and obtain a second trustworthiness value from the bootloader to measure the trustworthiness of the operating system.

[0110] Step 306: The credibility verification procedure checks whether the first credibility value is the same as the first benchmark credibility value, and whether the second credibility value is the same as the second benchmark credibility value.

[0111] After obtaining the first confidence value and the second confidence value, the confidence verification procedure can detect whether the first confidence value is the same as the first benchmark confidence value, and whether the second confidence value is the same as the second benchmark confidence value.

[0112] If the first confidence value is the same as the first baseline confidence value, and the second confidence value is the same as the second baseline confidence value, then it can be determined that neither the bootloader nor the operating system has been maliciously tampered with, and therefore step 307 can be executed. If the first confidence value is different from the first baseline confidence value, then it can be determined that the bootloader has been maliciously tampered with, and therefore step 308 can be executed. If the second confidence value is different from the second baseline confidence value, then it can be determined that the operating system has been maliciously tampered with, and therefore step 308 can be executed.

[0113] The trust verification program pre-stores the first baseline trustworthiness value and the second baseline trustworthiness value. The first baseline trustworthiness value is obtained by a trust measurement program performing a trustworthiness measurement on the bootloader after it is installed on the terminal but before its first run, at which point the bootloader has not been tampered with. The second baseline trustworthiness value is obtained by a trust measurement of the operating system performed by the bootloader after it is installed on the terminal but before its first run, at which point the operating system has not been tampered with.

[0114] Step 307: The trust verification procedure allows the executable program to run.

[0115] The terminal also has an executable program. After the trust verification program determines that the first trust value of the bootloader is the same as the first baseline trust value, and the second trust value is the same as the second baseline trust value, the executable program in the terminal can be allowed to run.

[0116] In this embodiment of the disclosure, during the process of acquiring a first confidence value and a second confidence value, and detecting whether the first confidence value is the same as a first benchmark confidence value, and whether the second confidence value is the same as a second benchmark confidence value, the confidence verification program must prohibit the execution of the executable program on the terminal. After determining that the first confidence value is the same as the first benchmark confidence value, and the second confidence value is the same as the second benchmark confidence value, the executable program on the terminal can be allowed to run.

[0117] The terminal may include multiple executable programs, which can be any one of those executable programs. For example, the executable program could be an ELF program.

[0118] Upon detecting a run instruction for the executable program, the trust verification program can perform an integrity verification on the executable program in response to the run instruction. If the verification is successful, the executable program can be allowed to run. If the verification fails, the executable program can be prevented from running, and the trust verification program can issue a first prompt message, which may include information about the executable program, such as its name and storage path. This facilitates maintenance personnel in quickly locating and repairing abnormal executable files.

[0119] Optionally, the trust verification program may store a first baseline verification value for each executable program. This first baseline verification value is obtained by the trust verification program using a verification algorithm to verify the executable program before it is installed on the terminal and before it is run for the first time.

[0120] The trust verification procedure can respond to the execution instruction for the executable program by using the verification algorithm to verify the executable program and generate a first verification value. If the first verification value is the same as the first baseline verification value of the executable program, it can be determined that the verification of the executable program is successful. If the first verification value is different from the first baseline verification value of the executable program, it can be determined that the verification of the executable program has failed.

[0121] By performing integrity checks on the executable program before it runs, and allowing it to run only if the checks are successful, the trustworthiness of the running executable program is ensured. Furthermore, when the executable program interacts with an IoT platform, the trustworthiness of the executable program interacting with the IoT platform can be effectively ensured.

[0122] In this embodiment of the disclosure, after successfully verifying the executable program, the trust verification program can also perform integrity verification on the target files that the executable program needs to call during its execution. These target files may include at least one of a configuration file and a library file. For example, the configuration file may have the extension .cfg, and the library file may have the extension .0.

[0123] If the trust verification program fails to verify the target file, it can prevent the executable program from calling the target file; if the verification of the target file is successful, it can allow the executable program to call the target file.

[0124] Optionally, the trusted verification program may pre-store the second benchmark verification value of the target file corresponding to the different executable programs. Each second benchmark verification value is generated by the trusted verification program using a verification algorithm to verify the target file before installing the target file and calling the target file for the first time.

[0125] During the execution of the executable program, the trust verification program uses a verification algorithm to verify the target file that the executable program needs to call, generating a second verification value. If the second verification value differs from the second baseline verification value, it can be determined that the verification of the target file has failed, and a second prompt message can be issued. This second prompt message can include information about the target file, such as its name and storage path. This facilitates maintenance personnel in quickly locating and repairing the abnormal target file. If the second verification value is the same as the second baseline verification value, it can be determined that the verification of the target file has succeeded.

[0126] During the execution of each executable program, the integrity of the target files that the executable program needs to call is verified. If the target file is successfully verified, the executable program is allowed to call that target file, thereby ensuring the trustworthiness of the target files called by the executable program. Furthermore, when the executable program interacts with the IoT platform, the trustworthiness of the executable program interacting with the IoT platform can be effectively ensured.

[0127] In this embodiment, the executable program may include a network connection program for establishing a network connection with an IoT platform. After determining that the first trustworthiness value of the bootloader is the same as the first baseline trustworthiness value, and that the second trustworthiness value is the same as the second baseline trustworthiness value, the trust verification program may, in response to a run instruction for the network connection program, perform integrity verification on the network connection program. If the verification of the network connection program is successful, the network connection program can be allowed to establish a network connection with the IoT platform, thereby effectively ensuring that all terminals connected to the IoT platform are trustworthy, and thus ensuring the security of terminal-IoT platform interaction. If the verification of the network connection program fails, the network connection program can be prohibited from running, thereby preventing the terminal from establishing a network connection with the IoT platform.

[0128] Optionally, the executable program may also include data encryption programs, data encapsulation programs, data decryption programs, etc.

[0129] In this embodiment, after receiving data from an IoT device, the data encryption program encrypts the received data and sends it to a data encapsulation program. The data encapsulation program then encapsulates the encrypted data and transmits it to the IoT platform. The IoT platform can also send data to a terminal, and the data decryption program decrypts the data sent by the IoT platform.

[0130] Step 308: The trust verification procedure prevents the executable program from running and issues an alarm message.

[0131] After determining that the first trustworthiness value of the bootloader differs from the first baseline trustworthiness value, and / or that the second trustworthiness value differs from the second baseline trustworthiness value, the trustworthiness verification procedure can prevent the execution of executable programs on the terminal and can issue an alarm message to indicate that the terminal's bootloader and / or operating system are untrustworthy. Optionally, the trustworthiness verification procedure can prevent the execution of all executable programs on the terminal.

[0132] Optionally, after determining that the first confidence value of the bootloader is different from the first baseline confidence value, and / or the second confidence value is different from the second baseline confidence value, the trust verification procedure may prohibit the network connection program from running, thereby preventing the network connection program from establishing a network connection with the IoT platform.

[0133] The alarm information may include information about the bootloader and / or operating system, such as the storage paths of the bootloader and operating system. This can effectively ensure that maintenance personnel can quickly locate the abnormality in the bootloader and / or operating system and quickly repair the bootloader.

[0134] In this embodiment of the disclosure, the terminal may also have a basic input output system (BIOS). The trust measurement program can respond to a power-on command by performing a trust measurement on the bootloader and BIOS in the terminal before starting the processor in the terminal. Optionally, the trust measurement program can use a verification algorithm to perform a trust measurement on the BIOS and generate a third trust value.

[0135] The trust verification program can also obtain a third trust value from the trust measurement program to measure the trustworthiness of the BIOS, and check whether the first trust value is the same as the first baseline trust value, whether the second trust value is the same as the second baseline trust value, and whether the third trust value is the same as the third baseline trust value. If the first trust value is the same as the first baseline trust value, the second trust value is the same as the second baseline trust value, and the third trust value is the same as the third baseline trust value, then it can be determined that the bootloader, operating system, and BIOS have not been maliciously tampered with, and therefore step 307 can be executed.

[0136] If at least one of the first confidence value differs from the first baseline confidence value, the second confidence value differs from the second baseline confidence value, and the third confidence value differs from the third baseline confidence value, then step 308 can be executed. Optionally, if the third confidence value differs from the third baseline confidence value, the alarm information may further include BIOS information, such as the BIOS storage path.

[0137] The third benchmark confidence value is obtained by measuring the confidence of the BIOS after it is installed on the terminal and before it is run for the first time.

[0138] In summary, the embodiments of this disclosure provide a terminal trusted access control method. In this method, the trusted verification program in the terminal determines whether to run an executable program in the terminal based on a first trusted value obtained by a trusted measurement program from the trusted bootloader. If the first trusted value of the bootloader differs from a first baseline trusted value, the executable program is prohibited from running, thereby ensuring that all executable programs running in the terminal are trusted. This further ensures the trustworthiness of the terminal establishing a network connection with the IoT platform, improves the reliability of terminal access control, and enhances the reliability of interaction between the terminal and the IoT platform.

[0139] Furthermore, since the decision to disable executable programs is based on the first trust value of the bootloader after processor startup, the trust verification program in the terminal can issue an alarm even if the first trust value of the bootloader differs from the first baseline trust value. This facilitates maintenance personnel in repairing the terminal, improving the reliability and flexibility of terminal access control. Moreover, since no authentication of the terminal is required by the IoT platform, the computational burden on the IoT platform is reduced.

[0140] This disclosure provides a computer-readable storage medium storing a terminal trusted access control program. When executed by a processor, the terminal trusted access control program implements the terminal trusted access control method described in the above embodiments, for example... Figure 2 or Figure 3 The terminal trusted access control method shown is illustrated.

[0141] Figure 4 This is a schematic diagram of the structure of a terminal provided in an embodiment of this disclosure, such as... Figure 4 As shown, the system includes a memory 401, a trusted measurement program 402, a processor 403, and a terminal trusted access control program stored in the memory 401 and capable of running on the trusted measurement program 402 and the processor 403. When the trusted measurement program 402 and the processor 403 execute the terminal trusted access control program, they implement the terminal trusted access control method described in the above embodiments. For example, the trusted measurement program 402 executes the above... Figure 2 Step 201 shown and Figure 3 The processor 403 performs the above-described step 301. Figure 2 Steps 202 and 203 shown, and the above Figure 3 Steps 302 to 307 are shown.

[0142] Figure 5 This is a block diagram of a terminal trusted access control device provided in an embodiment of this disclosure, such as... Figure 5 As shown, the device may include: a trust measurement module 501, a trust verification module 502, and a power-on module 503.

[0143] The trust measurement module 501 is used to start the processor in the terminal after performing a trust measurement on the boot module 503 in the terminal in response to the power-on command.

[0144] The trust verification module 502 is used to obtain a first trust value from the trust measurement module 501 to measure the trustworthiness of the boot program; if it is determined that the first trust value is different from the first benchmark trust value, the executable program in the terminal is prohibited from running and an alarm message is issued. The executable program includes a network connection program for establishing a network connection with the Internet of Things platform.

[0145] In summary, the embodiments of this disclosure provide a terminal trusted access control device. In this device, the trusted verification module in the terminal determines whether to run an executable program in the terminal based on a first trusted value obtained by the trusted measurement module from the trusted bootloader. If the first trusted value of the bootloader differs from a first baseline trusted value, the executable program is prohibited from running, thereby ensuring that all executable programs running in the terminal are trusted. This, in turn, ensures the trustworthiness of the terminal establishing a network connection with the IoT platform, improving the reliability of the interaction between the terminal and the IoT platform.

[0146] Furthermore, since the decision to disable executable programs is based on the first trust value of the bootloader after processor startup, the trust verification module in the terminal can issue an alarm if the first trust value of the bootloader differs from the first baseline trust value. This facilitates maintenance personnel in repairing the terminal, improving the reliability and flexibility of terminal access control. Moreover, since no IoT platform is required to authenticate the terminal, the computational burden on the IoT platform is reduced.

[0147] Optionally, the boot module 503 is used to perform a trustworthiness measurement on the operating system in the terminal after the trust measurement module 501 starts the processor in the terminal, and then boot the operating system.

[0148] The trust verification module 502 is also used for:

[0149] Obtain a second credibility value from the boot module 503 to measure the credibility of the operating system;

[0150] If it is determined that the first confidence value is different from the first baseline confidence value, and / or the second confidence value is different from the second baseline confidence value, then the executable program is prohibited from running and an alarm message is issued.

[0151] Optionally, the trust verification module 502 is also used for:

[0152] If the first confidence value is determined to be the same as the first baseline confidence value, then the executable program is allowed to run.

[0153] Optionally, the trust verification module 502 is also used for:

[0154] If it is determined that the first confidence value is the same as the first baseline confidence value, and the second confidence value is the same as the second baseline confidence value, then the executable program is allowed to run.

[0155] Optional, the trust verification module 502 is used for:

[0156] In response to the execution instructions for the executable program, perform integrity verification on the executable program.

[0157] If the executable program is successfully verified, it is allowed to run.

[0158] Optionally, the trust verification module 502 is also used for:

[0159] If the executable program fails to be verified, the executable program will be prevented from running.

[0160] Optionally, after disabling the executable program, the trust verification module 502 is also used for:

[0161] Issue the first prompt message, which includes information about the executable program.

[0162] Optionally, after the executable program has run, the trust verification module 502 is also used for:

[0163] The integrity of the target files called by the executable program is verified. The target files include at least one of the configuration files and library files.

[0164] If the verification of the target file fails, the executable program is prohibited from calling the target file; if the verification of the target file succeeds, the executable program is allowed to call the target file.

[0165] Optionally, after the trust verification program prohibits the executable program from calling the target file, the trust verification module 502 is also used for:

[0166] A second prompt message is issued, which includes information about the target file.

[0167] Optionally, the terminal's operating system includes Linux; see reference. Figure 6 The device may also include: a login verification module 504, used for:

[0168] After the trusted measurement module starts the processor in the terminal, if the number of login messages for the target account received within the target duration reaches the target number, and the verification of the target number of login messages fails, the trusted verification module 502 in the terminal is prohibited from starting. The target number is positively correlated with the level of the target account.

[0169] If the number of login requests for the target account received within the target time period is less than or equal to the target number, and the login information is successfully verified, then the trusted verification module 502 is allowed to start.

[0170] In summary, the embodiments of this disclosure provide a terminal trusted access control device. In this device, the trusted verification module in the terminal determines whether to run an executable program in the terminal based on a first trusted value obtained by the trusted measurement module from the trusted bootloader. If the first trusted value of the bootloader differs from a first baseline trusted value, the executable program is prohibited from running. This ensures that all executable programs running in the terminal are trusted, thereby ensuring the trustworthiness of the terminal establishing a network connection with the IoT platform, improving the reliability of trusted access control for the terminal, and enhancing the reliability of interaction between the terminal and the IoT platform.

[0171] Furthermore, since the decision to disable executable programs is based on the first trust value of the bootloader after processor startup, the trust verification module in the terminal can issue an alarm if the first trust value of the bootloader differs from the first baseline trust value. This facilitates maintenance personnel in repairing the terminal, improving the reliability and flexibility of terminal access control. Moreover, since no IoT platform is required to authenticate the terminal, the computational burden on the IoT platform is reduced.

[0172] In this embodiment of the disclosure, the terminal may include the aforementioned trusted access control device.

[0173] It should be noted that the logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device. More specific examples (a non-exhaustive list) of computer-readable media include: an electrical connection having one or more wires (electronic device), a portable computer disk drive (magnetic device), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Alternatively, the computer-readable medium may be paper or other suitable media on which the program can be printed, since the program can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in a computer memory.

[0174] It should be understood that various parts of this disclosure can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any one or a combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc.

[0175] In the description of this specification, references to terms such as "optional," "some embodiments," "example," "specific example," or "some examples," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of this disclosure. In this specification, the illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0176] Furthermore, the terms "first," "second," etc., used in the embodiments of this disclosure are for descriptive purposes only and should not be construed as indicating or implying relative importance, or implicitly specifying the number of technical features indicated in this embodiment. Therefore, features defined with terms such as "first" and "second" in the embodiments of this disclosure can explicitly or implicitly indicate that the embodiment includes at least one of those features. In the description of this disclosure, the word "multiple" means at least two or more, such as two, three, four, etc., unless otherwise explicitly specified in the embodiments.

[0177] In this disclosure, unless otherwise explicitly specified or limited in the embodiments, the terms "installation," "connection," "joining," and "fixing," etc., appearing in the embodiments should be interpreted broadly. For example, a connection can be a fixed connection, a detachable connection, or an integral part; it can also be a mechanical connection, an electrical connection, etc. Of course, it can also be a direct connection, or an indirect connection through an intermediate medium, or it can be the internal communication between two components, or the interaction between two components. Those skilled in the art can understand the specific meaning of the above terms in this disclosure based on the specific implementation.

[0178] Although embodiments of the present disclosure have been shown and described above, it is understood that the above embodiments are exemplary and should not be construed as limiting the present disclosure. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments within the scope of the present disclosure.

Claims

1. A terminal trusted access control method, characterized in that, Applied to a terminal, the terminal having a trust measurement program, a trust verification program, a boot loader, a processor, an executable program, an operating system, and a basic input / output system (BIOS), the method includes: The trust measurement program responds to the power-on command and, after performing a trust measurement on the bootloader and BIOS, starts the processor; The bootloader performs a trustworthiness measurement on the operating system and then boots the operating system. The trust verification program obtains a first trust value from the trust measurement program to measure the trustworthiness of the bootloader, a second trust value from the bootloader to measure the trustworthiness of the operating system, and a third trust value from the trust measurement program to measure the trustworthiness of the BIOS. If the credibility verification program determines that the first credibility value is different from the first benchmark credibility value, it will prohibit the execution of the executable program and issue an alarm message. The executable program includes a network connection program for establishing a network connection with the Internet of Things platform. Wherein, if the credibility verification procedure determines that the first credibility value is different from the first benchmark credibility value, it prohibits the executable program from running, including: If the credibility verification program detects at least one of the following: the first credibility value differs from the first benchmark credibility value; the second credibility value differs from the second benchmark credibility value; and the third credibility value differs from the third benchmark credibility value, then the executable program is prohibited from running. After the trust verification procedure allows the executable program to run, the method further includes: The trust verification program performs integrity verification on the target files that the executable program needs to call to generate a second verification value. The target files include at least one of configuration files and library files. If the second verification value is different from the second baseline verification value, it is determined that the verification of the target file has failed, and the executable program is prohibited from calling the target file; if the verification of the target file is successful, the executable program is allowed to call the target file. Wherein, the first benchmark confidence value is generated by verifying the bootloader through a verification algorithm after the terminal installs the bootloader and before the bootloader runs for the first time; the second benchmark confidence value is generated by verifying the operating system through a verification algorithm after the terminal installs the operating system and before the operating system runs for the first time; the second benchmark verification value is generated by verifying the target file using a verification algorithm before the target file is installed and called for the first time.

2. The method according to claim 1, characterized in that, The method further includes: If the credibility verification procedure determines that the first credibility value is the same as the first benchmark credibility value, then the executable program is allowed to run.

3. The method according to claim 2, characterized in that, If the credibility verification procedure determines that the first credibility value is the same as the first benchmark credibility value, then it allows the executable program to run, including: If the credibility verification procedure determines that the first credibility value is the same as the first benchmark credibility value, the second credibility value is the same as the second benchmark credibility value, and the third credibility value is the same as the third benchmark credibility value, then the executable program is allowed to run.

4. The method according to claim 2, characterized in that, The trust verification procedure allows the executable program to run, including: The trust verification procedure performs integrity verification on the executable program in response to the execution instructions for the executable program. If the trust verification procedure successfully verifies the executable program, then the executable program is allowed to run.

5. The method according to claim 4, characterized in that, The method further includes: If the trust verification procedure fails to verify the executable program, then the executable program is prohibited from running.

6. The method according to claim 5, characterized in that, After the trust verification procedure prevents the executable program from running, the method further includes: The trust verification program issues a first prompt message, which includes information about the executable program.

7. The method according to claim 1, characterized in that, After the trust verification procedure prevents the executable program from calling the target file, the method further includes: The trust verification procedure issues a second prompt message, which includes information about the target file.

8. The method according to any one of claims 1 to 7, characterized in that, The terminal's operating system includes a Linux operating system, and the terminal also has a login verification program; after the processor is started, the method further includes: If the login verification procedure receives a target number of login requests for the target account within a target time period, and all login requests for the target number of times fail to be verified, then the trusted verification procedure is prohibited from starting. The target number of times is positively correlated with the level of the target account. If the login verification procedure receives fewer than or equal to the target number of login requests for the target account within the target duration, and successfully verifies the login information, then the trusted verification procedure is allowed to start.

9. A computer-readable storage medium, characterized in that, It stores a trusted terminal access control program, which, when executed by a processor, implements the trusted terminal access control method according to any one of claims 1 to 8.

10. A terminal, characterized in that, The device includes a memory, a trusted measurement program, a processor, and a terminal trusted access control program stored in the memory and capable of running on the trusted measurement program and the processor. When the trusted measurement program and the processor execute the terminal trusted access control program, they implement the terminal trusted access control method according to any one of claims 1 to 8.

11. A terminal trusted access control device, characterized in that, The device includes: a trust measurement module, a boot module, a trust verification module, an operating system, and a BIOS; The trust measurement module is used to start the processor in the terminal after performing a trust measurement on the boot boot module in response to the boot command; The boot-up module is used to perform a trustworthiness measurement on the operating system in the terminal after the trust measurement module starts the processor in the terminal, and then guide the operating system to start. The trust verification module is used to obtain a first trust value for trust measurement of the boot module from the trust measurement module, a second trust value for trust measurement of the operating system from the boot program, and a third trust value for trust measurement of the BIOS from the trust measurement program; if it is determined that the first trust value is different from the first baseline trust value, the executable program in the terminal is prohibited from running and an alarm message is issued, the executable program including a network connection program for establishing a network connection with the Internet of Things platform; The credibility verification module is configured to prevent the executable program from running if it detects that at least one of the following: the first credibility value is different from the first benchmark credibility value; the second credibility value is different from the second benchmark credibility value; and the third credibility value is different from the third benchmark credibility value. After the trust verification module allows the executable program to run, it is also used for: The integrity of the target files called by the executable program is verified to generate a second verification value, wherein the target files include at least one of configuration files and library files; If the second verification value is different from the second baseline verification value, it is determined that the verification of the target file has failed, and the executable program is prohibited from calling the target file; if the verification of the target file is successful, the executable program is allowed to call the target file. Wherein, the first benchmark confidence value is generated by verifying the bootloader through a verification algorithm after the terminal installs the bootloader and before the bootloader runs for the first time; the second benchmark confidence value is generated by verifying the operating system through a verification algorithm after the terminal installs the operating system and before the operating system runs for the first time; the second benchmark verification value is generated by verifying the target file using a verification algorithm before the target file is installed and called for the first time.

12. The apparatus according to claim 11, characterized in that, The reliability verification module is also used for: If it is determined that the first confidence value is the same as the first baseline confidence value, then the executable program is allowed to run.

13. The apparatus according to claim 12, characterized in that, The reliability verification module is also used for: If it is determined that the first confidence value is the same as the first baseline confidence value, the second confidence value is the same as the second baseline confidence value, and the third confidence value is the same as the third baseline confidence value, then the executable program is allowed to run.

14. The apparatus according to any one of claims 11 to 13, characterized in that, The reliability verification module is used for: In response to the execution instructions for the executable program, the integrity of the executable program is verified; If the executable program is successfully verified, then the executable program is allowed to run.

15. The apparatus according to claim 14, characterized in that, The reliability verification module is also used for: If the verification of the executable program fails, the executable program is prohibited from running.

16. The apparatus according to any one of claims 11 to 13, characterized in that, The terminal's operating system includes a Linux operating system; the device further includes a login verification module, used for: After the trusted measurement module starts the processor in the terminal, if the number of login messages for the target account received within the target time period reaches the target number, and the verification of the target number of login messages fails, then the trusted verification module is prohibited from starting. The target number is positively correlated with the level of the target account. If the number of login requests for the target account received within the target duration is less than or equal to the target number, and the login requests are successfully verified, then the trust verification module is allowed to start.

17. An Internet of Things (IoT) characterized in that, The Internet of Things (IoT) includes: at least one IoT device, terminal, and IoT platform; Each of the IoT devices is used to send the collected data to the terminal; The terminal includes the terminal trusted access control device according to any one of claims 11 to 16; The IoT platform is used to receive data sent by the terminal.

Citation Information

Patent Citations

  • Trusted starting method and device for operating system, mobile terminal and storage medium

    CN112445537A