A trusted reporting and remote verification method for a mobile police end-to-end system
Through edge gateway generation and remote verification of trusted reports of extended smart terminals, the technical difficulties in generating and verifying trusted reports in the mobile police edge system are solved, and fast and secure trusted verification and management are achieved, meeting the security needs of mobile police systems.
Patent Information
- Application Number
- CN202310309657.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-28
- Publication Date
- 2025-08-19
- Estimated Expiration
- 2043-03-28
AI Technical Summary
The existing technology cannot effectively generate and remotely verify trusted reports of extended smart terminals in the mobile police end edge system, and the existing mechanisms and processes are redundant and cumbersome, which cannot meet the needs of fast trusted verification.
The edge gateway builds a trust chain based on the physical trusted root TPCM/TCM, generates trusted reports and remotely verify, including the edge gateway obtains PCR values and metric logs, generates signature data, and verifies signatures through the trusted management center to achieve fast trusted report distribution and verification.
It solves the problem of trusted reporting normative and identity verification of extended-class terminals in the end-edge system, prevents the forgery of trusted state, realizes the secure and trustworthy verification and management of extended-class terminals, and meets the security needs of mobile police systems.
Smart Images

Figure CN116321160B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of data security communication technology, and in particular to a trusted reporting and remote verification method for a mobile police terminal-edge system. Background Art
[0002] With the development of new information technologies such as 5G, artificial intelligence, and edge computing, and the widespread and large-scale application of mobile policing, wireless, intelligent, and collaborative police equipment is becoming increasingly popular. However, within the existing mobile policing "terminal-platform" architecture, a large number of new information technology devices, such as extended-type smart terminals (such as smart watches, smart bracelets, smart helmets, body cameras, and in-vehicle smart terminals), are not incorporated into the security requirements for mobile police terminals. Consequently, the practical and technical demands for wireless access to local area networks for more terminals and devices, as well as intelligent computing and processing at the edge gateway, are increasing. At the same time, the access authentication and trusted computing system construction of a large number of extended-type smart terminal equipment in the construction of mobile policing end-to-end systems have become one of the difficulties and challenges left unresolved in the current generation of mobile policing systems, yet must be addressed and resolved with the development of new technologies. Currently, in the actual construction of the equipment system, the mobile police edge gateway equipment complies with the technical requirements of GA / T1466-2018, GA / T2001-2022, etc., but its external extended smart terminals have not yet built an end-edge trusted computing protection system that continues the existing trusted computing system based on the physical hardware trusted root as the starting point of the trust chain.
[0003] In a trusted computing environment, scenarios often require remote proof of terminal identity and trusted platform trustworthiness. These scenarios are generally implemented through trusted reporting and trusted authentication mechanisms. The basis of the trusted reporting and trusted authentication mechanism is based on the EK endorsement key in the hardware physical trusted root, which is used for key verification and authentication key generation process and does not participate in other reporting and authentication work. After the terminal trusted computing platform generates the PIK corresponding to the user identity, the trusted computing platform uses the PIK to generate a trusted report for the PCR platform status register data in the TPCM / TCM. By issuing a trusted report to the remote terminal trusted computing platform, parsing the trusted report on the other end, and combining the trusted platform security mechanism, remote verification of the terminal identity and trustworthiness is achieved. Trusted reporting and verification is a three-party process, including the trusted management center, the local terminal trusted platform, and the remote terminal trusted platform. The local trusted computing platform and the remote trusted computing platform are the generation points of the trusted report and the execution points of the trusted authentication. The PIK certificate center of the trusted management center is the management center for the keys and certificates related to the trusted report, and the trusted policy center provides verification basis for the content of the trusted report. The reporting and verification mechanism framework of the local and remote trusted computing platforms is as follows: Figure 1As shown. Both the local and remote trusted computing platforms have the root CA signature public key or certificate of the trusted management center, which can verify the legitimacy of the PIK certificate in the interactive authentication. The terminal trust report and remote trust authentication process (one-way authentication) with a physical trusted root is as follows:
[0004] Step 1: The local and remote trusted platforms apply for PIK certificates and trusted policies from the trusted management center in advance;
[0005] Step 2: The local trusted platform A builds a trusted startup trust chain with the trusted platform control module TPCM as the initial trust point, completes the trust measurement and stores the measurement results in the PCR;
[0006] Step 3: The local trusted platform A generates standardized data fields based on the measurement values, measurement log records, and trusted computing platform identity information in the PCR according to the rules;
[0007] Step 4: Local trusted platform A uses the PIK private key to generate the signature information in step 3;
[0008] Step 5: Local trusted platform A generates a trusted report based on the information in steps 3 and 4;
[0009] Step 6: Local trusted platform A sends the trusted report and local PIK certificate (public key) to remote trusted platform B through a trusted connection;
[0010] Step 7: Remote trusted platform B uses the pre-set root CA public key to verify the legitimacy of A's PIK certificate;
[0011] Step 8: Remote trusted platform B parses the trust report and verifies the PCR value and key authenticity in the trust report from trusted platform A according to the trust policy.
[0012] Step 9: One-way trusted report generation and remote verification are completed.
[0013] Existing technologies have some inherent defects and deficiencies when applied to edge systems, which can be summarized as follows:
[0014] 1. The existing mobile police trusted computing system strictly adheres to the trusted trust chain, trusted security protection, and trusted report verification mechanism based on the physical root of trust module (TPCM / TCM). In the edge-to-end system scenario, it is unable to achieve trusted report generation and remote trusted verification for extended terminals.
[0015] 2. When existing technologies or mechanisms are used for bidirectional trusted report distribution and remote trusted verification between trusted platforms, the process is redundant and cumbersome, requiring multiple interactive verifications, which does not meet the actual needs of fast trusted verification in edge scenarios. Summary of the Invention
[0016] In view of the shortcomings of the existing technology, the present invention aims to provide a trusted reporting and remote verification method for a mobile police end-to-end system.
[0017] In order to achieve the above object, the present invention adopts the following technical solutions:
[0018] A method for trusted reporting and remote verification of a mobile police end-to-end system, comprising the following steps:
[0019] S1. The edge gateway gTSB is powered on and started, completing the initial construction of the trust chain based on TPCM or TCM, the trust measurement of itself and external expansion terminals, and the startup of system control component services;
[0020] S2. The edge gateway gTSB determines whether to report the trust report of the extended terminal based on the trust policy issued by the trust management center;
[0021] S3. If it is determined in step S2 that the extended terminal is reporting a trustworthy report, the edge gateway calls the TPCM to obtain the PCR register management entity;
[0022] S4. The edge gateway gTSB obtains the PCR values of itself and the extended terminal according to the identifier of the extended terminal;
[0023] S5. The edge gateway gTSB obtains the measurement event log record of the PCR value of itself and the extended terminal according to the identifier of the extended terminal;
[0024] S6. The edge gateway gTSB determines whether the basic data items of the trusted report of the extended terminal are complete;
[0025] S7. The edge gateway gTSB obtains its own trusted reporting root and PIK certificate;
[0026] S8. The edge gateway gTSB generates a trusted report and signature data for its own trusted computing platform;
[0027] S9. The edge gateway gTSB generates a trusted report and signature data of the trusted computing platform of the external extension terminal;
[0028] S10. The edge gateway gTSB calls the trusted connection and sends the trusted report and signature data generated in steps S8 and S9 to the trusted management center or the remote terminal trusted computing platform;
[0029] S11. The trusted management center or the remote terminal trusted computing platform parses the trusted report and measurement event log records, and calls the root CA or the carried PIK certificate to verify the signature;
[0030] S12. The trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the edge gateway PCR value;
[0031] S13. After the verification of step S12 is passed, the trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the extended terminal PCR value;
[0032] S14. The trusted management center or the remote terminal trusted computing platform generates a trusted verification result of the extended terminal according to the comparison strategy and stores it in the trusted management center.
[0033] Furthermore, the trusted management center or remote terminal trusted computing platform can support certificate authentication services and policy management services under the end-edge system.
[0034] Furthermore, the extended-type smart terminal has a TEE execution environment or an equally secure and trusted execution environment, and has pre-installed software cryptographic modules and trusted software base TSB, and has system function calls with the highest system permissions. At the same time, the trusted benchmark of the trusted software base TSB pre-installed in the extended-type smart terminal has been synchronously distributed to the trusted benchmark library of the northbound edge gateway through the mobile police system.
[0035] The beneficial effects of the present invention are: the present invention can be used to generate trusted reports for extended mobile terminals under the end-edge system in accordance with existing standard specifications and distribute them to a remote trusted computing platform for trusted verification. On the one hand, it solves the technical difficulties and problems of trusted report standardization and identity authentication of extended smart terminals in the mobile police end-edge system, prevents the falsification of trusted status of extended terminals, and incorporates the trusted report and verification mechanism of the system or software operation of extended terminals into the unified trusted computing system of public security. On the other hand, it realizes technical and application innovation based on the trusted report generation mechanism and security authentication strategy of the end-edge system, makes up for the lack of trusted report management and remote identity credibility verification in the current end-edge system under weak trusted root conditions, and meets the urgent needs for security trust, trusted verification and security management monitoring of extended mobile terminals. BRIEF DESCRIPTION OF THE DRAWINGS
[0036] Figure 1 A schematic diagram of the existing trusted reporting and one-way trusted verification mechanism framework;
[0037] Figure 2 This is a schematic diagram of the logical architecture of the device-edge system trust system in the method of Example 1 of the present invention;
[0038] Figure 3 This is a logical diagram of the device-edge trusted reporting and remote verification mechanism in the method of Example 1 of the present invention;
[0039] Figure 4 This is a schematic diagram of the data format of the end-edge trust report in the method of Example 1 of the present invention;
[0040] Figure 5 Schematic diagram of the implementation of the method of Example 2 of the present invention;
[0041] Figure 6 Schematic diagram of the implementation of the method of Example 3 of the present invention. DETAILED DESCRIPTION
[0042] The present invention will be further described below in conjunction with the accompanying drawings. It should be noted that this embodiment is based on the technical solution and provides a detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to this embodiment.
[0043] Example 1
[0044] This embodiment provides a trusted reporting and remote verification method for a mobile police terminal-edge system. Starting from the physical trusted root (TPCM / TCM) of the edge gateway (master node) of the mobile police terminal-edge system as the trusted trust chain, the trusted integrity measurement results of the extended class smart terminal are used to generate a trusted report. A trusted report remote distribution and trusted verification mechanism between trusted computing platforms (or trusted management centers) is designed, covering the trusted report generation, trusted connection establishment, trusted certificate and password interaction, and trusted verification process after the trusted measurement process of the extended class smart terminal. It should be noted that TCM refers to Trusted Cryptography Module, and TPCM refers to Trusted Platform Control Module.
[0045] Figure 2 The figure shows the logical architecture of the edge-to-edge trusted system. Because the measurement results of weakly trusted root-extended intelligent terminals are stored in the PCR registers of the standard TPCM / TCM, the trusted report content (PCR status values, trusted measurement values, and trusted measurement log records, etc.) is strongly dependent on the edge gateway trusted system. This conforms to the trusted trust transfer, trust association, and trust reporting requirements of the mobile policing edge-to-edge system. Furthermore, the remote distribution and verification mechanism of trusted reports significantly shortens the two-way verification process, meeting the security requirements of data confidentiality, non-repudiation, and uniqueness.
[0046] The effectiveness of the method of this embodiment depends on the following three conditions:
[0047] (1) The edge gateway device can build a complete trusted trust chain and generate a trusted measurement report based on the physical root of trust (TPCM / TCM) through the trusted software base TSB;
[0048] (2) The trusted management center can support certificate authentication services and policy management services in the edge-end system;
[0049] (3) Extended smart terminals have a TEE execution environment or an equally secure and trusted execution environment, and have pre-installed software cryptographic modules and trusted software bases TSB, and have the highest system authority to call system functions (such as system information acquisition, system interface calls and file operations, etc.). At the same time, the trusted benchmarks of the trusted software bases TSB pre-installed in the extended smart terminals have been synchronously distributed to the trusted benchmark library of the northbound edge gateway through the mobile police system.
[0050] like Figure 3 As shown, the main logical entities of the edge trusted computing system include the physical root of trust (TCM or TPCM) of the edge gateway (master node), the trusted software base gTSB and the trusted network connection, and also include the soft cryptographic module, the trusted software base eTSB and the trusted network connection in the TEE trusted execution environment of the extended intelligent terminal (slave node).
[0051] The data format of the end-edge trust report is as follows: Figure 4 shown.
[0052] The method of this embodiment specifically includes the following steps:
[0053] S1. The edge gateway gTSB is powered on and started, completing the process of establishing a trust chain based on TPCM or TCM, measuring the trustworthiness of itself and external expansion terminals, and starting the system control component services.
[0054] S2. The edge gateway gTSB determines whether to report the trust report of the extended terminal based on the trust policy issued by the trust management center;
[0055] S3. If it is determined in step S2 that the extended terminal is reporting a trustworthy report, the edge gateway calls the TPCM to obtain the PCR register management entity;
[0056] S4. The edge gateway gTSB obtains the PCR values of itself and the extended terminal according to the identifier of the extended terminal;
[0057] S5. The edge gateway gTSB obtains the measurement event log record of the PCR value of itself and the extended terminal according to the identifier of the extended terminal;
[0058] S6. The edge gateway gTSB determines whether the basic data items of the trusted report of the extended terminal are complete;
[0059] It should be noted that according to the definition in the trusted report specification of Appendix A of the GA / T 2001-2022 standard, the basic data items of the trusted report in this embodiment include uid (a unique identifier used to describe the trusted computing platform), static_m (the current trusted computing static measurement value), dynamic_m (the current trusted computing dynamic measurement value), tc_strategy (a hash value of trusted policy information such as trusted computing security mechanism and assurance policy), sign_pik (the PIK certificate signature value of static_m, dynamic_m and tc_strategy), tc_status (the overall trusted measurement result status of the current computing node), and time (the generation time of the trusted report).
[0060] S7. The edge gateway gTSB obtains its own trusted reporting root and PIK certificate;
[0061] S8, the edge gateway gTSB generates a trusted report and signature data of its own trusted computing platform; the signature data is the signature result generated by SM2 on the hash value of the trusted report data item;
[0062] S9. The edge gateway gTSB generates a trusted report and signature data of the trusted computing platform of the external extension terminal;
[0063] S10. The edge gateway gTSB calls the trusted connection and sends the trusted report and signature data generated in steps S8 and S9 to the trusted management center or the remote terminal trusted computing platform;
[0064] S11. The trusted management center or the remote terminal trusted computing platform parses the trusted report and measurement event log records, and calls the root CA or the carried PIK certificate to verify the signature;
[0065] S12. The trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the edge gateway PCR value;
[0066] S13. After the verification of step S12 is passed, the trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the extended terminal PCR value;
[0067] S14. The trusted management center or the remote terminal trusted computing platform generates a trusted verification result of the extended terminal according to the comparison strategy and stores it in the trusted management center.
[0068] Example 2
[0069] This embodiment takes an extended smart watch terminal (HUAWEI WATCH 3, operating system Harmony OS2.0) connected to a mobile police wireless intelligent gateway (operating system Harmony OS 2.0) as an example to further illustrate the trusted report generation and remote trusted verification process under the edge-end trusted computing system. The scenario in this embodiment is that the extended terminal sends a trusted report to the trusted management center via the edge gateway.
[0070] In this embodiment, the extended terminal A generates a trust report through the edge gateway G and sends it to the remote trust management center to implement the trust verification process, such as Figure 5 As shown, the following steps are included:
[0071] Step 1: The edge gateway G is powered on and starts up, completing the process of establishing a trust chain based on TPCM / TCM, measuring the trustworthiness of itself and the external expansion terminal A, and starting the system control component services.
[0072] Step 2: Edge gateway G determines whether to report the trust report of extended terminal A based on the trust policy issued by the trust management center;
[0073] Step 3: When step 2 determines that the extended terminal A trust report is reported, the edge gateway G calls TPCM to obtain the PCR register management entity;
[0074] Step 4: The edge gateway G obtains its own and extended terminal PCR values according to the identifier of the extended terminal A;
[0075] Step 5: The edge gateway gTSB obtains the measurement event log record of the PCR value of itself and the extended terminal A according to the extended terminal A identifier;
[0076] Step 6: The edge gateway gTSB determines whether the basic data items of the trusted report of the extended terminal A are complete;
[0077] Step 7: The edge gateway gTSB obtains the trusted reporting root and PIK certificates of gateway G;
[0078] Step 8: The edge gateway gTSB generates a trusted report and signature data for its own trusted computing platform;
[0079] Step 9: The edge gateway gTSB generates a trusted report and signature data for the trusted computing platform of the external extension terminal A;
[0080] Step 10: The edge gateway gTSB calls the trusted connection and sends the trusted report and related data in steps 8 and 9 to the trusted management center;
[0081] Step 11: The Trust Management Center parses the trusted report and measurement event log records and calls the root CA (or the PIK certificate carried in the request) to verify the signature;
[0082] Step 12: The trusted management center uses the PIK certificate to verify the signature of the PCR value of the edge gateway G;
[0083] Step 13: After the verification in step 12 is passed, the trusted management center uses the PIK to verify the signature of the PCR value of the extended terminal A;
[0084] Step 14: The trusted management center generates a trusted verification result for the extended terminal A based on the comparison strategy and stores it securely.
[0085] Step 15: The process ends.
[0086] Example 3
[0087] This embodiment is an example process in which a police extended-type smart watch terminal (HUAWEI WATCH 3, Harmony OS2.0) accesses a mobile police edge intelligent wireless gateway (Open Harmony OS), generates an edge-to-edge trusted report and sends it to a remote mobile police terminal (HUAWEI Mate50, equipped with Harmony OS operating system), and the remote mobile police terminal performs trusted verification on the trusted report.
[0088] In this embodiment, the extension terminal A generates a trustworthy report through the edge gateway G and sends it to the remote mobile police terminal B to implement the trustworthy verification process. Figure 6 As shown, the following steps are included:
[0089] Step 1: Remote mobile police terminal B initiates a trusted verification challenge to the extended terminal A. Terminal B generates a trusted report locally and sends it to the trusted management center with identification information and request information.
[0090] Step 2: The trusted management center accepts the request, verifies B's trustworthiness, generates B's trusted status value B_Status, and obtains the PIK certificate of the edge gateway G;
[0091] Step 3: The trusted management center obtains the encryption public key Enc_PubKey of the edge gateway G, encrypts the data information in step 2, and generates {B_Status}|Enc_PubKey;
[0092] Step 4: The trusted management center generates a hash of {B_Status}|Enc_PubKey, etc., and signs it, encapsulating the message response and returning it to terminal B;
[0093] Step 5: Terminal B sends a trusted verification challenge for extended terminal A to edge gateway G, carrying the encapsulated response message in step 4;
[0094] Step 6: Edge gateway G parses the request message from terminal B and calls the root CA to verify the validity of the encapsulated message in step 4 carried in the message;
[0095] Step 7: Edge gateway G uses the encrypted private key Enc_PriKey to decrypt the encapsulated message and obtain the trusted status result of terminal B;
[0096] Step 8: In step 7, the trusted status of terminal B is normal, and the edge gateway G initiates the trusted report generation process for the external expansion terminal A;
[0097] Step 9: Edge gateway G calls TPCM to obtain the PCR register management entity according to the trust policy issued by the trust management center;
[0098] Step 10: The edge gateway G obtains its own and extended terminal PCR values according to the extended terminal A identifier;
[0099] Step 11: The edge gateway G obtains the measurement event log record of the PCR values of itself and the extended terminal A according to the identifier of the extended terminal A;
[0100] Step 12: The edge gateway G determines whether the basic data items of the trusted report of the extended terminal A are complete;
[0101] Step 13: Edge gateway G obtains the trusted reporting root and PIK certificates of gateway G;
[0102] Step 14: The edge gateway G generates a trusted report and signature data for its own trusted computing platform;
[0103] Step 15: The edge gateway G generates a trusted report and signature data for the trusted computing platform of the external extension terminal A;
[0104] Step 16: Edge gateway G invokes the trusted connection and sends the trusted report and related data generated in the above steps to terminal B;
[0105] Step 17: Terminal B parses the trusted report and measurement event log records of extended terminal A sent by edge gateway G, and calls the root CA to verify the signature;
[0106] Step 18: Terminal B uses the PIK certificate of edge gateway G (carried in step 16, encrypted transmission) to verify the signature of the PCR value of edge gateway G;
[0107] Step 19: After step 18 is verified, terminal B uses the PIK certificate of edge gateway G (carried in step 16, encrypted transmission) to verify the signature of the PCR value of extended terminal A;
[0108] Step 20: Terminal B generates a trusted verification result for the extended terminal A based on the trusted policy and returns the result to the upper-layer application service for the next business operation;
[0109] Step 21: The process ends.
[0110] Those skilled in the art can make various corresponding changes and modifications based on the above technical solutions and concepts, and all of these changes and modifications should be included in the scope of protection of the claims of the present invention.
Claims
1. A method for trusted reporting and remote verification of a mobile police end-to-end system, characterized in that: The specific steps include: S1. The edge gateway gTSB is powered on and started, completing the initial construction of the trust chain based on TPCM or TCM, the trust measurement of itself and external expansion terminals, and the startup of system management and control component services; S2. The edge gateway gTSB determines whether to report the trust report of the external expansion terminal based on the trust policy issued by the trust management center; S3. If it is determined in step S2 that a trustworthy report of an external extension terminal is being reported, the edge gateway calls the TPCM to obtain the PCR register management entity; S4. The edge gateway gTSB obtains the PCR values of itself and the external extension terminal according to the identifier of the external extension terminal; S5. The edge gateway gTSB obtains the measurement event log record of the PCR value of itself and the external extension terminal according to the identifier of the external extension terminal; S6. The edge gateway gTSB determines whether the basic data items of the trusted report of the external extension terminal are complete; S7, the edge gateway gTSB obtains its own trusted reporting root and PIK certificate; S8, the edge gateway gTSB generates trusted reports and signature data for its own trusted computing platform; S9, the edge gateway gTSB generates a trusted report and signature data for the trusted computing platform of the external extension terminal; S10. The edge gateway gTSB calls the trusted connection and sends the trusted report and signature data generated in steps S8 and S9 to the trusted management center or the remote terminal trusted computing platform; S11. The trusted management center or the remote terminal trusted computing platform parses the trusted report and measurement event log records, and calls the root CA or the carried PIK certificate to verify the signature; S12. The trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the edge gateway PCR value; S13. After the verification of step S12 is passed, the trusted management center or the remote terminal trusted computing platform uses the PIK certificate to verify the signature of the external extended terminal PCR value; S14. The trusted management center or the remote terminal trusted computing platform generates a trusted verification result of the external extension terminal according to the comparison strategy and stores it in the trusted management center.
2. The method according to claim 1, characterized in that The trusted management center or remote terminal trusted computing platform can support certificate authentication services and policy management services under the end-edge system.
3. The method according to claim 1, characterized in that The external expansion terminal has a TEE execution environment or an equally secure trusted execution environment, and has pre-installed software cryptographic modules and trusted software base TSB, and has system function calls with the highest system permissions. At the same time, the trusted benchmark of the trusted software base TSB pre-installed in the external expansion terminal has been synchronously sent to the northbound edge gateway trusted benchmark library through the mobile police system.
Citation Information
Patent Citations
Mobile service end-side system credible protection strategy and measurement method
CN116614813A