A secure and reliable startup method and system for power terminals

By using trusted chips on the power terminal to measure the U-Boot data and operating system cores, combined with the trusted computing platform and interface secure access, the problem of insufficient security protection of the power terminal is solved, and trustworthy verification and security guarantee of the terminal startup process are achieved.

CN115879087BActive Publication Date: 2025-08-22STATE GRID SHANGHAI ENERGY INTERCONNECTION RES INST CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202111139203.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-09-26
Publication Date
2025-08-22
Estimated Expiration
2041-09-26

AI Technical Summary

Technical Problem

Power terminals are vulnerable to attacks such as illegal eavesdropping, malicious tampering and identity fraud. The existing security protection measures are insufficient, especially at the hardware and operating system levels.

Method used

The U-Boot data, operating system kernel data and application programs of the power terminal are used to measure the U-Boot data, operating system kernel data and application programs. Through the collaboration between the trusted chip and the MCU and operating system core, a security and trusted protection mechanism for the hardware layer, system layer and application layer is established, including the security mechanism of the trusted computing platform module, the security mechanism of the trusted chip and the interface security access.

Benefits of technology

It realizes trustworthy verification of the power terminal startup process, prevents malicious code attacks and critical information from being stolen or tampered, and ensures the safe and trustworthy startup of the terminal.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115879087B_ABST
    Figure CN115879087B_ABST
Patent Text Reader

Abstract

The present invention discloses a secure and trusted startup method and system for power terminals, belonging to the technical field of network security protection for power terminals. The method includes: controlling the MCU to power on and start the power terminal; loading the operating system kernel through U-Boot; loading key components through the operating system kernel; loading the application program with the key component, and completing the startup of the power terminal. The present invention implements trusted verification of the terminal startup process, effectively preventing malicious code attacks and theft or tampering of key information during the terminal startup process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of power terminal network security protection, and more specifically, to a secure and trusted startup method and system for power terminals. Background Art

[0002] Power terminals such as distribution terminals, substation smart terminals, and concentrators (referred to as "terminals") generally have the characteristics of being numerous and widespread, operating outdoors, unmanned, and complex power application scenarios. They are easy targets for hacker attacks and are vulnerable to illegal eavesdropping, malicious tampering, identity fraud, and other attacks. However, the security protection level of power terminals, especially terminals with edge computing capabilities, plays a vital role in the normal operation of the entire system.

[0003] Currently, power terminals generally use security chips or software to authenticate their identities with the master station and protect the confidentiality, integrity, and availability of transmitted data at the application layer. However, terminal security still relies primarily on conventional protection measures such as shutting down redundant ports and services and implementing access control measures. However, the following risks still exist:

[0004] (1) Power terminal hardware risks: The USB ports, serial ports, network ports, etc. opened by the power terminal may be exploited by illegal access objects such as forged operation and maintenance tools to gain control of the terminal equipment; if the keys and certificates in the terminal are not protected by hardware, they may be illegally stolen by hackers; if the data encryption and decryption, random number verification and other measures provided by the chip do not have a security guarantee mechanism, there is a risk of being bypassed.

[0005] (2) Risks of power terminal operating systems: The operating system has no verification measures for its own status, and there is a risk that the operating system kernel or upper-layer important software will be tampered with; hackers can use vulnerability scanning and other measures to carry out vulnerability attacks, malicious code attacks, virus infections, etc.; when the system is repairing normal vulnerabilities, there is a risk of illegal patches being implanted.

[0006] (3) Power terminal application security risks: If the device does not have integrity verification measures for the received application software, there may be a risk of installing application software from illegal sources, which may lead to the implantation of viruses or Trojans. Summary of the Invention

[0007] To address the above issues, the present invention proposes a secure and trusted startup method for power terminals, comprising:

[0008] Power on the power terminal, start the trusted chip, read the U-Boot data of the power terminal through the trusted chip, calculate the U-Boot measurement value based on the U-Boot data, and measure the U-Boot measurement value based on the benchmark measurement value through the trusted chip. If the measurement is successful, control the MCU to power on and start the power terminal;

[0009] U-Boot is loaded through the MCU, and the kernel data of the power terminal operating system is read using U-Boot. The kernel measurement value of the operating system kernel is calculated based on the kernel data. The kernel measurement value of the operating system kernel is transmitted to the trusted chip through U-Boot. The trusted chip measures the kernel measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot.

[0010] Use the trusted components of the operating system kernel to calculate the measurement values ​​of key components of the power terminal. The trusted chip measures the measurement values ​​of the key components according to the benchmark measurement values. If the measurement is successful, the key components are loaded through the operating system kernel.

[0011] The trusted component calculates the measurement values ​​of the application executable file and configuration file of the power terminal, and the trusted chip measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value. If the measurement is successful, the key component loads the application and completes the startup of the power terminal.

[0012] Optionally, the method further includes generating a measurement report, wherein the measurement report includes a determination or verification conclusion on whether the power terminal status is credible.

[0013] Optionally, the method also includes establishing a secure and reliable protection mechanism for the hardware layer, system layer and application layer of the target power terminal.

[0014] Optional hardware-layer security and trustworthy protection mechanisms, specifically including: security and trustworthy protection mechanisms for trusted computing platform modules, security and trustworthy protection mechanisms for trusted chips, and interface security access mechanisms;

[0015] The security and trustworthy protection mechanism of the trusted computing platform module is as follows: based on the trusted chip, a trusted third-party platform with anti-attack, anti-tampering and anti-detection is added to the power terminal; the trusted third-party platform measures the operating system software and application components in the power terminal to verify whether the power terminal is trustworthy;

[0016] The security and trustworthy protection mechanism of the trusted chip includes: a random number security mechanism, a cryptographic algorithm security mechanism, a cryptographic algorithm correctness mechanism, a COS algorithm security mechanism and a chip hardware security mechanism.

[0017] Optionally, a security and trustworthy protection mechanism is established at the system layer and the application layer, specifically: a trustworthy measurement mechanism at the system layer and the application layer.

[0018] The present invention also proposes a secure and reliable startup system for power terminals, comprising:

[0019] The power terminal startup unit powers on the power terminal, starts the trusted chip, reads the U-Boot data of the power terminal through the trusted chip, calculates the U-Boot measurement value based on the U-Boot data, and measures the U-Boot measurement value based on the benchmark measurement value through the trusted chip. If the measurement is successful, the MCU is controlled to power on and start the power terminal.

[0020] The operating system kernel loading unit loads U-Boot through the MCU, uses U-Boot to read the kernel data of the power terminal operating system, calculates the measurement value of the operating system kernel based on the kernel data, transmits the measurement value of the operating system kernel to the trusted chip through U-Boot, and uses the trusted chip to measure the measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot;

[0021] The key component loading unit uses the trusted components of the operating system kernel to calculate the measurement values ​​of the key components of the power terminal, measures the measurement values ​​of the key components according to the benchmark measurement values ​​through the trusted chip, and loads the key components through the operating system kernel if the measurement is successful;

[0022] The application loading unit calculates the measurement values ​​of the application executable file and configuration file of the power terminal through the trusted component, and measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value through the trusted chip. If the measurement is successful, the key component loads the application and completes the startup of the power terminal.

[0023] Optionally, the application loading unit is further configured to generate a measurement report, wherein the measurement report includes a determination or verification conclusion on whether the power terminal status is credible.

[0024] Optionally, a mechanism unit is established to establish a secure and trustworthy protection mechanism for the hardware layer, system layer and application layer of the target power terminal.

[0025] Optional hardware-layer security and trustworthy protection mechanisms, specifically including: security and trustworthy protection mechanisms for trusted computing platform modules, security and trustworthy protection mechanisms for trusted chips, and interface security access mechanisms;

[0026] The security and trustworthy protection mechanism of the trusted computing platform module is as follows: based on the trusted chip, a trusted third-party platform with anti-attack, anti-tampering and anti-detection is added to the power terminal; the trusted third-party platform measures the operating system software and application components in the power terminal to verify whether the power terminal is trustworthy;

[0027] The security and trustworthy protection mechanism of the trusted chip includes: a random number security mechanism, a cryptographic algorithm security mechanism, a cryptographic algorithm correctness mechanism, a COS algorithm security mechanism and a chip hardware security mechanism.

[0028] Optionally, a security and trustworthy protection mechanism is established at the system layer and the application layer, specifically: a trustworthy measurement mechanism at the system layer and the application layer.

[0029] The present invention realizes the trustworthy verification of the terminal startup process, and effectively prevents the occurrence of malicious code attacks and key information theft or tampering during the terminal startup process. BRIEF DESCRIPTION OF THE DRAWINGS

[0030] Figure 1 is a flow chart of the method of the present invention;

[0031] Figure 2 is a flow chart of an embodiment of the method of the present invention;

[0032] Figure 3 It is a structural diagram of the system of the present invention; DETAILED DESCRIPTION

[0033] Exemplary embodiments of the present invention will now be described with reference to the accompanying drawings. However, the present invention may be embodied in many different forms and is not limited to the embodiments described herein. These embodiments are provided to provide a thorough and complete disclosure of the present invention and to fully convey the scope of the present invention to those skilled in the art. The terminology used in the exemplary embodiments shown in the accompanying drawings is not intended to limit the present invention. In the accompanying drawings, identical elements are denoted by the same reference numerals.

[0034] Unless otherwise specified, the terms used herein (including technical terms) have the meanings commonly understood by those skilled in the art. In addition, it is understood that terms defined in commonly used dictionaries should be understood to have the same meanings as those in the context of the relevant fields, and should not be understood as idealized or overly formal meanings.

[0035] The present invention proposes a safe and reliable startup method for power terminals. Figure 1 Shown, including:

[0036] Power on the power terminal, start the trusted chip, read the U-Boot data of the power terminal through the trusted chip, calculate the U-Boot measurement value based on the U-Boot data, and measure the U-Boot measurement value based on the benchmark measurement value through the trusted chip. If the measurement is successful, control the MCU to power on and start the power terminal;

[0037] U-Boot is loaded through the MCU, and the kernel data of the power terminal operating system is read using U-Boot. The kernel measurement value of the operating system kernel is calculated based on the kernel data. The kernel measurement value of the operating system kernel is transmitted to the trusted chip through U-Boot. The trusted chip measures the kernel measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot.

[0038] Use the trusted components of the operating system kernel to calculate the measurement values ​​of key components of the power terminal. The trusted chip measures the measurement values ​​of the key components according to the benchmark measurement values. If the measurement is successful, the key components are loaded through the operating system kernel.

[0039] The trusted component calculates the measurement values ​​of the application executable file and configuration file of the power terminal, and the trusted chip measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value. If the measurement is successful, the key component loads the application and completes the startup of the power terminal.

[0040] The present invention will be further described below in conjunction with embodiments:

[0041] The operating system in the startup process takes Linux as an example, the process is as follows Figure 2 As shown:

[0042] (1) The terminal is powered on and the trusted chip is started.

[0043] (2) The trusted chip reads the U-boot data and calculates the U-boot metric value using the SM3 algorithm.

[0044] (3) The trusted chip performs measurement based on the benchmark measurement value. If the measurement is successful, the MCU is powered on. Otherwise, the terminal will not be able to start.

[0045] (4) MCU loads U-Boot, and U-Boot reads Linux kernel data.

[0046] (5) U-Boot uses the SM3 algorithm to calculate Linux kernel metrics through trusted components.

[0047] (6) U-Boot transmits the Linux kernel measurement value to the trusted chip.

[0048] (7) The trusted chip performs measurements based on the baseline measurement value and returns the results to U-Boot.

[0049] (8) If the measurement is successful, U-Boot loads the Linux kernel, and then the Linux kernel measures the application.

[0050] (9) The Linux kernel uses the SM3 algorithm to calculate the measurement values ​​of key components (such as key configuration files of the operating system) through trusted components.

[0051] (10) The Linux kernel transmits the key component measurement values ​​to the trusted chip.

[0052] (11) The trusted chip performs measurements based on the baseline measurement value and returns the results to the Linux kernel.

[0053] (12) If the measurement is successful, the Linux kernel loads the critical components.

[0054] (13) The key component calculates the measurement values ​​of the application executable file and configuration file using the SM3 algorithm or SM2 signature verification algorithm through the trusted component.

[0055] (14) The key component transmits the application installation package executable file and configuration file measurement value to the trusted chip.

[0056] (15) The trusted chip performs measurements based on the baseline measurement values ​​and returns the results to the key components.

[0057] (16) If the measurement is successful, the critical component loads the application.

[0058] (17) A measurement report is generated, which contains a judgment or verification conclusion on whether the terminal status is trustworthy and is sent to entities that need to interact with the terminal or provide services to the terminal.

[0059] Among them, in order to protect the SM3 summary value during the measurement process, it is recommended that the management agency sign the SM3 summary value generated in each step. When the new signature value needs to be written into the trusted chip, the signature value is used to identify the source.

[0060] Among them, the present invention establishes a security and trustworthy mechanism for the power terminal from three aspects: hardware layer, system layer, and application layer, which will be introduced in detail below.

[0061] Hardware layer;

[0062] The hardware layer of the terminal mainly establishes chip hardware security mechanisms and port security access mechanisms;

[0063] Hardware-layer trusted protection mechanism based on trusted chips;

[0064] Trusted Computing Platform Module Security Mechanism:

[0065] Trusted computing at the terminal's hardware layer is primarily implemented through a trusted chip. Compared to traditional security chips, the most significant feature of this trusted chip is its embedded Trusted Platform Module (TCM), a system-on-chip (SoC) integrated into the hardware architecture via a bus. The TCM encapsulates security functions required to build a trusted computing platform, including secure storage, cryptographic applications, certificate mechanisms, and security detection, providing the platform with basic security services. It strictly protects critical data signal lines and storage areas, making it difficult to intercept stored data using physical probes or standard optical detection techniques. In addition to protecting internal data, the chip also incorporates inherent protection against physical attacks. Signal detection is used during packaging to prevent removal. Removing the chip from the motherboard triggers a pre-wired signal line, causing the signal on that line to change, triggering a hard interrupt. The system then executes a self-destruct sequence, erasing all internal data and rendering the entire terminal's trusted chip inoperable.

[0066] The Trusted Platform integrates a traditional trusted chip with a trusted third party that is resistant to attack, tampering, and detection. This third party verifies the terminal's trustworthiness by measuring the operating system software and application components within the terminal. The Trusted Platform Module operates prior to the operating system and BIOS. From a technical perspective, it primarily includes five functions: integrity measurement, encrypted storage, identity authentication, internal resource access authorization, and encrypted transmission.

[0067] Trusted chip's own security mechanism;

[0068] 1) Random number security. When using trusted chips, random numbers are often used as an important factor in data authentication and key generation. Therefore, the randomness of random numbers must be fully guaranteed. Random number security technology is generally achieved through the use of a true random number generator.

[0069] 2) Cryptographic algorithm security. The trusted chip supports the national cryptographic algorithms SM1, SM2, SM3, SM4, and SM7. Security protection mechanisms are incorporated into the algorithm implementation process. All algorithms used must be verified with data provided by the National Cryptography Administration. The verification results are correct, ensuring the reliability of the security algorithm.

[0070] 3) Correctness of cryptographic algorithms. Check the correctness of the cryptographic algorithms built into the trusted chip by performing self-tests at power-on and during use. Preset the algorithm's related keys, plaintext data, ciphertext data, etc. in the power distribution trusted chip. When the chip is powered on or performs algorithm-related operations, the preset keys are used to encrypt, decrypt, sign, verify signatures, or perform hash calculations on the preset data. The calculation results are compared with the expected values. If they are the same, the self-test passes and other operations can continue. If they are different, the self-test fails, the corresponding error status word is set, and no other instructions can be executed subsequently.

[0071] 4) COS algorithm security. The security system of the trusted chip software system (COS) mainly consists of security status, file access rights, data exchange mode, and secure computing.

[0072] 5) Chip hardware security: To prevent attacks on the chip, the trusted chip is equipped with a voltage detector, a frequency detector, a temperature detector, and a watchdog reset circuit.

[0073] Interface security access mechanism;

[0074] Power terminals should implement necessary interface security access mechanisms to ensure that physical interfaces are controllable. This includes, but is not limited to: for USB ports, adopting an authentication mechanism based on peripheral interfaces to prohibit the installation of drivers for illegal USB flash drives; for network ports, retaining ports used for business data exchange between the terminal and the host station, and disabling other unused ports and services.

[0075] Trust measurement mechanism at the operating system layer;

[0076] The operating system is the core, foundational software loaded onto the hardware. Without security, the entire power terminal's security foundation is compromised. Currently, national standards for operating system security include "GB / T 34976-2017 Information Security Technology - Mobile Intelligent Terminal Operating System Security Technical Requirements and Test Evaluation Methods" and "GB / T 20272-2006 Information Security Technology - Operating System Security Technical Requirements." These standards utilize security features such as identity authentication, access control, and security audits to manage the software and hardware of mobile intelligent terminal devices, ensuring their secure operation.

[0077] Commonly used operating systems in power terminals include embedded operating systems such as Linux, UNIX, and VxWorks. Taking the Linux operating system as an example, its security mechanisms primarily include user authentication, autonomous access control, mandatory access control, and security auditing. Access control mechanisms are central to ensuring system security. Entity identity is determined through authentication, and security policies are enforced through authorization and access control. However, the security status of entities within the system may change during operation due to attacks. Relying solely on authentication-based access control cannot protect against operating system security threats.

[0078] From a structural perspective, the biggest difference between a secure operating system and a general operating system is that it has an internal Trusted Computing Base (TCB) and uses the functions provided by the TCB to protect the entire system. The TCB is the overall protection device within the operating system, including hardware, firmware, software, and a combination responsible for executing security policies. It is the core of the operating system to implement security functions. However, the integrity of the TCB itself cannot be guaranteed. Therefore, combining trusted computing technology with traditional secure operating systems has become a new solution for ensuring operating system security. By adding a trusted chip to the computing platform as a hardware root of trust, the trusted root is incorporated into the TCB as the core of the TCB. Then, through a trust chain transmission mechanism, the trust chain is gradually established and expanded, with each level measuring and authenticating the next level. Utilizing trusted computing technology, the security mechanism of the operating system is enhanced and a trusted operating environment is established within the operating system. Specifically, trusted computing technology provides the following important support and guarantees for operating system security:

[0079] (1) Provide a hardware root of trust to ensure the trustworthiness of the system's initial state. A trusted control module (TPCM) is added to the power terminal computing platform. TPCM starts before the CPU and actively measures the trustworthiness of the system's initial code. Using the trusted root of measurement (CRTM) in TPCM as the measurement starting point, trustworthiness is measured step by step for entities that obtain execution permissions in the platform. This builds a trust chain for the system, ensuring the trustworthiness of the initial state of any executing entity in the system. By extending the trust chain, the trustworthiness of the overall initial state of the system is ensured. The trustworthiness of the system's initial state effectively ensures the correct implementation of security policies and the normal operation of security mechanisms, laying the foundation for the safe operation of the operating system.

[0080] (2) Provide hardware-based cryptographic service assurance. Cryptographic technology is the core of information security. A large number of cryptographic mechanisms are used in the confidentiality and integrity security mechanisms of operating systems. Cryptographic mechanisms implemented in software are difficult to guarantee their own security. Trusted computing technology provides the system with cryptographic services supported by physical hardware, which has good isolation and computing efficiency. The TPCM module provides cryptographic algorithm engines such as symmetric cryptographic algorithms, asymmetric cryptographic algorithms, and hash functions, which can provide efficient cryptographic service assurance for the operating system.

[0081] (3) Provide secure storage for important core data. The core of the effectiveness of many important security mechanisms lies in the security of key security data. For example, the security of the key directly determines the security of the data encryption storage mechanism, and the security of the security policy file directly determines the security of the implementation of the system security function. In traditional operating systems, the storage environment of important information such as security policies and user keys is poorly isolated from the system operating environment, and the storage protection function is weak, which cannot provide effective storage protection support for the normal implementation of the security mechanism. Through the secure storage function of trusted computing, important key security-related data can be directly stored in TPCM, or rely on TPCM to protect the confidentiality and integrity of important security data, isolate it from the operating environment of the operating system, ensure the security of important security-related data, and provide effective secure storage support for the implementation of the system security mechanism.

[0082] (4) Trusted integrity measurement and reporting. The security mechanism of traditional operating systems can only ensure the safe and reliable operation of the system through security measures. However, due to the lack of a trusted party that is relatively independent of the system, it is difficult to prove the correct implementation of its internal security mechanism through the computing platform itself. The operating system does not have the ability to prove its own secure operation status. By adding a hardware root of trust to the system, the system has the ability to prove its own trustworthy status under the premise that users trust the unified and standardized hardware root of trust. Through the trusted measurement and trusted reporting functions of the root of trust, the trusted operation status of the operating system can be externally proved, providing important trust support for security applications in network environments.

[0083] To sum up, the use of trusted computing technology provides a hardware root of trust for the terminal operating system, which can effectively build a trust chain in the system, provide cryptographic service protection and secure storage capabilities for the security of the operating system, and provide strong cryptographic support and trusted protection for the security of the operating system.

[0084] Business application software trustworthiness measurement;

[0085] Relying on trusted chips to dynamically measure terminal processes or applications will significantly impact the normal operation of the business. Therefore, for critical, long-running, and relatively basic business application software, trusted chips should still be used to implement trusted measurement from the chip to the operating system and then to the business application software to ensure the integrity of the business application software. For other business application software, it is recommended to use dynamic trusted measurement to monitor the status of the terminal application software. Dynamic trusted measurement is primarily based on the dynamic monitoring and analysis of important runtime status characteristic indicators and user behavior indicators. The characteristic indicators are then correlated using pattern recognition methods to ultimately identify the type of risk and determine the risk level based on the specific changes in the characteristic indicators. This function must be implemented based on a security monitoring system or platform.

[0086] The present invention also proposes a safe and reliable startup system for power terminals, such as Figure 3 Shown, including:

[0087] The power terminal startup unit 201 powers on the power terminal, starts the trusted chip, reads the U-Boot data of the power terminal through the trusted chip, calculates the U-Boot measurement value based on the U-Boot data, measures the U-Boot measurement value based on the benchmark measurement value through the trusted chip, and if the measurement is successful, controls the MCU to power on and start the power terminal;

[0088] The operating system kernel loading unit 202 loads U-Boot through the MCU, uses U-Boot to read kernel data of the power terminal operating system, calculates a measurement value of the operating system kernel based on the kernel data, transmits the measurement value of the operating system kernel to the trusted chip through U-Boot, and uses the trusted chip to measure the measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot;

[0089] The key component loading unit 203 calculates the measurement value of the key component of the power terminal using the trusted component of the operating system kernel, measures the measurement value of the key component according to the benchmark measurement value through the trusted chip, and loads the key component through the operating system kernel if the measurement is successful;

[0090] The application loading unit 204 calculates the measurement values ​​of the application executable file and configuration file of the power terminal through the trusted component, and measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value through the trusted chip. If the measurement is successful, the key component loads the application and completes the startup of the power terminal;

[0091] The mechanism establishment unit 205 establishes a secure and reliable protection mechanism for the hardware layer, system layer and application layer of the target power terminal.

[0092] The application loading unit 204 is further configured to generate a measurement report, wherein the measurement report includes a determination or verification conclusion on whether the power terminal status is credible.

[0093] Among them, the security and trustworthy protection mechanism of the hardware layer specifically includes: the security and trustworthy protection mechanism of the trusted computing platform module, the security and trustworthy protection mechanism of the trusted chip, and the interface security access mechanism;

[0094] The security and trustworthy protection mechanism of the trusted computing platform module is as follows: based on the trusted chip, a trusted third-party platform with anti-attack, anti-tampering and anti-detection is added to the power terminal; the trusted third-party platform measures the operating system software and application components in the power terminal to verify whether the power terminal is trustworthy;

[0095] The security and trustworthy protection mechanism of the trusted chip includes: a random number security mechanism, a cryptographic algorithm security mechanism, a cryptographic algorithm correctness mechanism, a COS algorithm security mechanism and a chip hardware security mechanism.

[0096] Among them, the system layer and the application layer establish a secure and trustworthy protection mechanism, specifically: a trustworthy measurement mechanism at the system layer and the application layer.

[0097] The present invention realizes the trustworthy verification of the terminal startup process, and effectively prevents the occurrence of malicious code attacks and key information theft or tampering during the terminal startup process.

[0098] It will be understood by those skilled in the art that the embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Furthermore, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The solutions in the embodiments of the present invention may be implemented in various computer languages, for example, the object-oriented programming language Java and the interpreted scripting language JavaScript.

[0099] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowcharts and / or block diagrams. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0100] These computer program instructions may also be stored in a computer readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 a process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0101] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing the instructions executed on the computer or other programmable device for implementing the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A step that specifies a function in one or more boxes.

[0102] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.

[0103] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.

Claims

1. A secure and trusted startup method for a power terminal, the method comprising: Power on the power terminal, start the trusted chip, read the U-Boot data of the power terminal through the trusted chip, calculate the U-Boot measurement value based on the U-Boot data, and measure the U-Boot measurement value based on the benchmark measurement value through the trusted chip. If the measurement is successful, control the MCU to power on and start the power terminal; U-Boot is loaded through the MCU, and the kernel data of the power terminal operating system is read using U-Boot. The kernel measurement value of the operating system kernel is calculated based on the kernel data. The kernel measurement value of the operating system kernel is transmitted to the trusted chip through U-Boot. The trusted chip measures the kernel measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot. Use the trusted components of the operating system kernel to calculate the measurement values ​​of key components of the power terminal. The trusted chip measures the measurement values ​​of the key components according to the benchmark measurement values. If the measurement is successful, the key components are loaded through the operating system kernel. The trusted component calculates the measurement values ​​of the application executable file and configuration file of the power terminal, and the trusted chip measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value. If the measurement is successful, the key component loads the application and completes the startup of the power terminal.

2. The method according to claim 1 further comprises generating a measurement report, wherein the measurement report comprises a determination or verification conclusion on whether the state of the power terminal is credible.

3. The method according to claim 1 further comprises establishing a secure and trustworthy protection mechanism for the hardware layer, system layer and application layer of the target power terminal.

4. The method according to claim 3, wherein the hardware layer security and trustworthy protection mechanism specifically comprises: The security and trustworthy protection mechanism of the trusted computing platform module, the security and trustworthy protection mechanism of the trusted chip, and the interface security access mechanism; The security and trustworthy protection mechanism of the trusted computing platform module is as follows: based on the trusted chip, a trusted third-party platform with anti-attack, anti-tampering and anti-detection functions is added to the power terminal; Verify the trustworthiness of power terminals by measuring the operating system software and application components within the power terminals through a trusted third-party platform; The security and trustworthy protection mechanism of the trusted chip includes: a random number security mechanism, a cryptographic algorithm security mechanism, a cryptographic algorithm correctness mechanism, a COS algorithm security mechanism and a chip hardware security mechanism.

5. The method according to claim 3, wherein the system layer and the application layer establish a security and trustworthy protection mechanism, specifically: a trustworthy measurement mechanism at the system layer and the application layer.

6. A secure and trusted startup system for a power terminal, the system comprising: The power terminal startup unit powers on the power terminal, starts the trusted chip, reads the U-Boot data of the power terminal through the trusted chip, calculates the U-Boot measurement value based on the U-Boot data, and measures the U-Boot measurement value based on the benchmark measurement value through the trusted chip. If the measurement is successful, the MCU is controlled to power on and start the power terminal. The operating system kernel loading unit loads U-Boot through the MCU, uses U-Boot to read the kernel data of the power terminal operating system, calculates the measurement value of the operating system kernel based on the kernel data, transmits the measurement value of the operating system kernel to the trusted chip through U-Boot, and uses the trusted chip to measure the measurement value of the operating system kernel based on the baseline measurement value. If the measurement is successful, the operating system kernel is loaded through U-Boot; The key component loading unit uses the trusted components of the operating system kernel to calculate the measurement values ​​of the key components of the power terminal, measures the measurement values ​​of the key components according to the benchmark measurement values ​​through the trusted chip, and loads the key components through the operating system kernel if the measurement is successful; The application loading unit calculates the measurement values ​​of the application executable file and configuration file of the power terminal through the trusted component, and measures the measurement values ​​of the application executable file and configuration file according to the benchmark measurement value through the trusted chip. If the measurement is successful, the key component loads the application and completes the startup of the power terminal.

7. The system according to claim 6, wherein the application loading unit is further configured to generate a measurement report, wherein the measurement report includes a determination or verification conclusion on whether the power terminal status is credible.

8. The system according to claim 6, further comprising a mechanism unit for establishing a secure and reliable protection mechanism for the hardware layer, system layer and application layer of the target power terminal.

9. The system according to claim 8, wherein the hardware layer security and trustworthy protection mechanism specifically comprises: The security and trustworthy protection mechanism of the trusted computing platform module, the security and trustworthy protection mechanism of the trusted chip, and the interface security access mechanism; The security and trustworthy protection mechanism of the trusted computing platform module is as follows: based on the trusted chip, a trusted third-party platform with anti-attack, anti-tampering and anti-detection functions is added to the power terminal; Verify the trustworthiness of power terminals by measuring the operating system software and application components within the power terminals through a trusted third-party platform; The security and trustworthy protection mechanism of the trusted chip includes: a random number security mechanism, a cryptographic algorithm security mechanism, a cryptographic algorithm correctness mechanism, a COS algorithm security mechanism and a chip hardware security mechanism.

10. The system according to claim 8, wherein the system layer and the application layer establish a security and trustworthy protection mechanism, specifically: a trustworthy measurement mechanism of the system layer and the application layer.