A trusted protection strategy and measurement method for mobile service end-edge systems
By building a trusted trust chain and TEE trusted execution environment at the edge gateway, the problem of extended terminals being unable to be included in the mobile business trusted computing system is solved, and standardized trusted measurement and secure access are achieved, thereby improving the security and flexibility of the mobile business end-edge system.
Patent Information
- Application Number
- CN202310312107.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-28
- Publication Date
- 2025-09-09
- Estimated Expiration
- 2043-03-28
AI Technical Summary
The existing mobile business trusted computing system strictly adheres to the construction of a trusted trust chain based on a physical trusted root module, resulting in the inability of extended terminals to be included in the mobile business trusted computing system, posing a security risk. In addition, the existing system does not have flexible expansion features and cannot support the access of extended smart terminals.
A trusted trust chain is built through the edge gateway, TPCM/TCM is used to generate trusted measurement results, and a TEE trusted execution environment is established in the extended terminal. Combined with domestic commercial encryption and identity authentication technology, trusted measurement of extended terminals is achieved, and a trusted computing protection architecture for the end-edge system is constructed.
It realizes the trust measurement of extended terminals, complies with the specifications of the public security mobile business field, makes up for the lack of trust protection in the mobile business end-edge system, improves the security and flexibility of the system, and adapts to the access needs of extended terminals.
Smart Images

Figure CN116614813B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a trusted protection strategy and measurement method for a mobile service end-edge system. Background Art
[0002] With the rapid development of wireless communication technology and public safety services, the practical and technical demands for wireless access to local area networks (LANs) for more terminals and devices, and intelligent computing and processing at edge gateways, are increasing. The mobile service end-edge system is booming. Building on the current mobile service architecture, a "end-edge" architecture is being constructed to serve people and objects, utilizing multiple wireless transmission links, and featuring edge management and services. This architecture supports end-edge collaborative applications to accommodate the needs of a wider range of devices connecting to the mobile service platform and conducting mobile services.
[0003] As mobile service edge systems are being developed, access authentication and trusted protection for a large number of future smart terminal devices will become a challenge left unfinished by the current next-generation mobile service system, yet must be addressed and resolved with the development of new technologies. Currently, in the actual development of this equipment system, mobile service edge gateway devices comply with technical requirements such as GA / T 1466-2018 and GA / T 2001-2022. However, their connected smart terminals (such as smart watches, smart bracelets, smart helmets, recorders, and in-vehicle smart terminals) have yet to establish an edge-to-edge trusted computing protection system that integrates with the existing trusted computing system based on a physical hardware root of trust as the starting point of the trust chain.
[0004] Trusted computing is a security technology that ensures the integrity of systems and applications, thereby ensuring that the system or software operates in the desired trusted state as designed. Trust and security complement each other, with trust being the foundation of security. Trust is primarily achieved through measurement and verification. Measurement involves capturing the state of the software or system being tested, while verification involves comparing the measurement results with reference values to determine consistency. A consistent result indicates verification has passed, while a mismatch indicates verification has failed. Trust measurement can be categorized as static or dynamic. Static measurement typically involves measuring the image of the runtime environment during initial installation or reboot. Measurement is performed on a step-by-step basis, with the first software launched measuring the next software launched. Successful verification of the measurement value signifies the successful transfer of the trust chain from the previous software level to the next. For example, during operating system bootup, a trusted operating system, based on a trusted boot chain established by a hardware root of trust, performs static measurements on objects in the boot chain, such as the motherboard firmware, bootloader, and operating system image. The static measurement results are verified by trusted management services to determine whether the system has been modified. Dynamic measurement and verification involves dynamically acquiring system and application operating characteristics during system runtime and determining whether the system is operating properly based on rule-based or model-based analysis.
[0005] The trusted measurement process based on physical root of trust is as follows:
[0006] Step 1: The host device is powered on and starts to build a trusted boot trust chain with the Trusted Platform Control Module (TPCM) as the initial trust point.
[0007] Step 2: TPCM works and initiates trust measurement of the motherboard, firmware, and bootloader;
[0008] Step 3: After the measurement in step 2 is completed, TPCM transfers control to the trusted software base TSB, which initiates the trusted measurement of objects such as the operating system boot program, kernel, system image, system files, system services, and application installation files;
[0009] Step 4: After the measurement in step 3 is completed, the TSB calls the TPCM / TCM interface to store the corresponding measurement results in the platform status register PCR;
[0010] Step 5: After the operating system completes booting, the TSB initiates trust measurement of kernel extensions, applications, segment data structures, memory data, and other objects.
[0011] Step 6: After the measurement in step 5 is completed, the TSB calls the TPCM / TCM interface to store the corresponding measurement results in the platform status register PCR;
[0012] Step 7: The trusted trust chain and trusted measurement process of the host device from startup to operation is completed.
[0013] However, the existing mobile business trusted computing system strictly adheres to the trusted chain of trust built on the physical root of trust module (TPCM / TCM). This lacks the flexibility to expand security protection systems. Consequently, extended-type terminals connected to mobile business systems cannot be included in the unified supervision of the mobile business trusted computing system, posing a significant security risk. Extended-type smart terminals are designed for scenario-based services and, due to limitations in size, power consumption, performance, and usability, cannot be added with a hardware root of trust to support the existing mobile business trusted system. Summary of the Invention
[0014] In view of the shortcomings of the existing technology, the present invention aims to provide a trusted protection strategy and measurement method for a mobile service end-edge system.
[0015] In order to achieve the above object, the present invention adopts the following technical solutions:
[0016] A trusted protection strategy and measurement method for mobile service end-edge systems. The specific process is as follows:
[0017] S1. The edge gateway is powered on and started. After completing the application for the mobile business system digital certificate, building the trust chain based on TPCM / TCM, initiating the trusted measurement, and starting the system control component service, the initialization process of the edge gateway is completed.
[0018] S2. After the extended terminal is powered on and starts up, and the device certificate application, software password module initialization in the TEE trusted execution environment, and system control component service startup process are completed, the trusted software base eTSB calls the software password module and performs the first initial trust measurement according to the factory preset trust policy, and sets the initial measurement value value0 = [v1, v2..., v n ] Securely stored in the TEE software password module; the extended terminal completes the initialization process and accesses the edge gateway based on the wireless LAN;
[0019] S3: The extended terminal initiates the identity authentication process for accessing the edge gateway, carrying the extended terminal device certificate and authentication parameters;
[0020] S4. After completing the identity authentication of accessing the edge gateway in step S3, the trusted software base eTSB of the extended terminal calls the local software cryptographic module to generate the SM2 signature key pair used in the trusted process, reports the signature public key to the edge gateway gTSB for storage, and simultaneously applies for the SM2 encryption key pair from the TPCM or TCM of the edge gateway, which is securely stored in the TEE soft cryptographic module of the extended terminal;
[0021] S5. The trusted software base eTSB of the extended terminal carries the terminal system characteristic parameters to apply for a trusted policy from the trusted software base gTSB of the edge gateway, and uses the signature private key to generate signature information for the request data;
[0022] S6. The edge gateway obtains the registration data of the trusted software base eTSB of the extended terminal. After the signature is verified, it calls the TPCM to create the hardware trusted root container and platform trusted configuration register ePCR of the corresponding extended terminal, initializes the trusted key and storage area data of the corresponding TCM, and returns a registration response with the trusted measurement policy and trusted root identification information;
[0023] S7. The trusted software base gTSB of the edge gateway builds a trusted trust chain for the extended terminal with the trusted root of measurement eRTM of the extended terminal as the starting point, initiates trusted measurement to the trusted software base eTSB preset in the extended terminal, generates measurement results and compares them with the trusted reference value of the trusted software base eTSB of the corresponding type of extended terminal stored in the edge gateway;
[0024] S8. If the comparison result in step S7 is consistent, it means that the trusted software base eTSB has not been tampered with and is in a trustworthy state. The trusted software base eTSB parses the measurement instruction issued, and according to the trusted measurement policy returned in step S6, calls the system control component service of the extended terminal to initiate the trusted measurement of the boot program, system kernel, system image and system application files of the extended terminal, and generates a trusted measurement value value1 = [v1, v2..., v n ] and compare it with the initial measurement value value0 stored in TEE in step S2;
[0025] S9. If the comparison result in step S8 is consistent, it means that the system has not been attacked or tampered with during the process from step S1 to step S8, and the status is trustworthy; the trusted software base eTSB encrypts and signs value1 with the encryption private key and reports it to the trusted software base gTSB;
[0026] S10. After obtaining the ciphertext and signature information of value1 in step S9, the trusted software base gTSB first calls the signature public key of the extended class terminal stored in step S4 to verify the signature, and then calls the encryption private key of the extended class terminal to decrypt the ciphertext of value1 to obtain value1;
[0027] S11, the trusted software base gTSB calls TPCM or TCM, and generates the current measurement result hash1 = [h1, h2, ..., h n ] and stored in the ePCR platform configuration register.
[0028] Furthermore, the extended terminal has the system function call with the highest system authority, and the trusted benchmark of the TSB trusted software base preset in the extended terminal has been synchronously sent to the northbound edge gateway trusted benchmark library through the mobile service system.
[0029] The beneficial effects of the present invention are: by constructing a trusted computing protection architecture for wireless access of the mobile service end-edge system, the present invention focuses on the difficulties in trusted computing protection of the end-edge system and the current problems of heterogeneous security systems, and realizes the trust measurement of the extended terminals of the end-edge system based on trusted computing, domestic commercial encryption and identity authentication technologies. It complies with the requirements of relevant normative documents and technical standards in the field of public security mobile services, makes up for the lack and gaps in the current trusted protection architecture of the mobile service end-edge system, and meets the urgent needs of public security and government-related industries for the security construction of extended terminal equipment. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] Figure 1 This is a diagram of the trusted protection architecture of the mobile service end-edge system in Example 1 of the present invention;
[0031] Figure 2This is a logic block diagram of edge-to-edge trusted computing protection and trust measurement in Example 1 of the present invention;
[0032] Figure 3 This is a flowchart of the implementation of the method of Example 1 of the present invention;
[0033] Figure 4 This is a flowchart of the implementation of the method in Example 2 of the present invention. DETAILED DESCRIPTION
[0034] The present invention will be further described below in conjunction with the accompanying drawings. It should be noted that this embodiment is based on the technical solution and provides a detailed implementation method and specific operation process, but the protection scope of the present invention is not limited to this embodiment.
[0035] Example 1
[0036] This embodiment provides a trusted protection strategy and measurement method for a mobile service end-edge system, which establishes a trust chain connection between the various stages of the mobile service end-edge system's extended terminal access authentication and trusted measurement process (edge gateway initialization stage, extended terminal initialization stage, extended terminal access authentication stage, and trusted measurement stage initiated for extended terminals based on the edge gateway). The physical trusted root (TPCM / TCM) of the edge gateway (master node) is used as the starting point of the trusted trust chain, and the trusted trust chain construction and trusted measurement of the extended terminal (slave node) are constructed based on this, covering the trusted measurement of the extended terminal system initialization, startup, and operation stages.
[0037] Figure 1 The following illustrates the trusted protection architecture for the mobile service end-edge system in this embodiment. Because the trusted trust of weak root-of-trust extended terminals is based on the hardware root of trust of the edge gateway (master node), measurement and protection policies are dispatched and operated by the master node, and measurement results are stored in the PCR registers of the standard TPCM / TCM. Even if an external attack gains access to operating system privileges on the extended terminal, the trusted measurement results cannot be modified to forge the expected trusted state. This meets the trusted computing protection and security baseline requirements for mobile service end-edge systems.
[0038] The implementation of the method in this embodiment is based on the following three conditions:
[0039] (1) The edge gateway supports wireless LAN, allowing extended-type terminals that meet public safety regulations and equipment safety requirements to securely access the edge gateway via wireless LAN, providing trusted protection for the full-stack security link from the physical layer to the application layer;
[0040] (2) The initial startup process of the edge gateway has been implemented based on the physical root of trust (TPCM or TCM), and a complete trusted trust chain is built through the trusted software base TSB and a trusted measurement report is generated. It should be noted that TCM (Trusted Cryptography Module) refers to the trusted cryptographic module, and TPCM (Trusted Platform Control Module) refers to the trusted platform control module.
[0041] (3) Extended terminals have a TEE execution environment or an equivalent secure trusted execution environment, and have pre-installed software cryptographic modules and a trusted software base (TSB). They have the highest system privileges for system function calls (such as system information acquisition, system interface calls, and file operations). At the same time, the trusted baseline of the TSB trusted software base pre-installed on the extended terminal has been synchronously distributed to the trusted baseline library of the northbound edge gateway through the mobile business system. It should be noted that TEE (Trusted Execution Environment) refers to the trusted execution environment of the mobile operating system.
[0042] The method of this embodiment starts by building a trusted trust chain for the extended terminal (slave node) through the physical trusted root (TPCM or TCM) of the edge gateway (master node) in the end-edge system, and then obtains the trusted measurement value of the extended terminal through step-by-step measurement of the trust chain, and generates the trusted status result value of the extended terminal through the built-in national secret algorithm SM3 of TPCM / TCM, and stores the above values in the physical trusted root PCR register of the edge gateway.
[0043] The logic block diagram of edge trusted computing protection and trust measurement in this embodiment is as follows: Figure 2 The main logical entities of the edge trusted computing system include the physical root of trust (TCM or TPCM), trusted software base gTSB, and trusted network connection of the edge gateway (master node), as well as the soft cryptographic module, trusted software base eTSB, and trusted network connection within the TEE trusted execution environment of the extended terminal (slave node).
[0044] like Figure 3 As shown, the specific process of the method in this embodiment is as follows:
[0045] S1: The edge gateway is powered on and started, completing the application for the mobile business system digital certificate, building the trust chain based on TPCM / TCM, initiating trusted measurement, and starting the system control component service, completing the initialization process of the edge gateway;
[0046] S2. After the extended terminal is powered on and starts up, and the device certificate application, software password module initialization in the TEE trusted execution environment, and system control component service startup process are completed, the trusted software base eTSB calls the software password module and performs the first initial trust measurement according to the factory preset trust policy, and sets the initial measurement value value0 = [v1, v2..., v n ] Securely stored in the TEE software password module; the extended terminal completes the initialization process and accesses the edge gateway based on the wireless LAN;
[0047] S3: The extended terminal initiates the identity authentication process for accessing the edge gateway, carrying the extended terminal device certificate and authentication parameters such as the terminal number, terminal type identifier, terminal hardware fingerprint, and owner information;
[0048] S4. After completing the identity authentication of accessing the edge gateway in step S3, the trusted software base eTSB of the extended terminal calls the local software cryptographic module to generate the SM2 signature key pair used in the trusted process, reports the signature public key to the edge gateway gTSB for storage, and simultaneously applies for the SM2 encryption key pair from the TPCM or TCM of the edge gateway, which is securely stored in the TEE soft cryptographic module of the extended terminal;
[0049] S5. The trusted software base eTSB of the extended terminal carries the terminal system characteristic parameters to apply for a trusted policy from the trusted software base gTSB of the edge gateway, and uses the signature private key to generate signature information for the request data;
[0050] S6. The edge gateway obtains the registration data of the trusted software base eTSB of the extended terminal. After the signature is verified, it calls TPCM to create the hardware trusted root container (eRTM, eRTS, and eRTR) and platform trusted configuration register ePCR of the corresponding extended terminal, initializes the trusted key and storage area data of the corresponding TCM, and returns a registration response with the trusted measurement policy and trusted root identification information;
[0051] S7. The trusted software base gTSB of the edge gateway builds a trusted trust chain for the extended terminal with the trusted root of measurement eRTM of the extended terminal as the starting point, initiates trusted measurement to the trusted software base eTSB preset in the extended terminal, generates measurement results and compares them with the trusted reference value of the trusted software base eTSB of the corresponding type of extended terminal stored in the edge gateway;
[0052] S8. If the comparison result in step S7 is consistent, it means that the trusted software base eTSB has not been tampered with and is in a trustworthy state. The trusted software base eTSB parses the measurement instruction issued, and according to the trusted measurement policy returned in step S6, calls the system control component service of the extended terminal to initiate the trusted measurement of the boot program, system kernel, system image and system application files of the extended terminal, and generates a trusted measurement value value1 = [v1, v2..., v n ] and compare it with the initial measurement value value0 stored in TEE in step S2;
[0053] S9. If the comparison result in step S8 is consistent, it means that the system has not been attacked or tampered with during the process from step S1 to step S8, and the status is trustworthy; the trusted software base eTSB encrypts and signs value1 with the encryption private key and reports it to the trusted software base gTSB;
[0054] S10. After obtaining the ciphertext and signature information of value1 in step S9, the trusted software base gTSB first calls the signature public key of the extended class terminal stored in step S4 to verify the signature, and then calls the encryption private key of the extended class terminal to decrypt the ciphertext of value1 to obtain value1;
[0055] S11, the trusted software base gTSB calls TPCM or TCM, and generates the current measurement result hash1 = [h1, h2, ..., h n ] and stored in the ePCR platform configuration register.
[0056] Example 2
[0057] This embodiment uses an extended-type smartwatch terminal (HUAWEI WATCH 3, Harmony OS 2.0) connected to a mobile service edge intelligent wireless gateway (Open Harmony OS) as an example to describe the trusted computing protection policy linkage and trust measurement process of the mobile service end-edge system. Figure 4 As shown, the prerequisites include the startup and operation phase trust measurement of the edge gateway G, the initialization of the terminal TCM / TPCM / hardware cryptographic module (built-in security chip form), the operating system certificate application process and the startup of the system control components are all completed.
[0058] In this embodiment, the process of extending the edge trusted computing protection strategy and measurement for terminal A to access edge gateway G includes the following steps:
[0059] Step 1: The edge gateway G is powered on and started. After completing the mobile service device digital certificate application, the master node TPCM / TCM initial trust chain construction, the trust measurement and system control component service startup processes, the edge gateway initialization process is completed.
[0060] Step 2: After the extended terminal A is powered on and the device certificate (soft certificate) application is completed and the soft password module and the system control module are initialized, the trusted software base eTSB of terminal A calls the soft password module and performs the initial trust measurement according to the factory preset universal trust policy, and sets the initial measurement value value0 = [v1, v2, ..., v n ] is stored in TEE, and the extended terminal A completes the initialization process;
[0061] Step 3: Extended terminal A initiates the identity authentication process for accessing edge gateway G, accessing edge gateway G based on the wireless LAN, and carrying A terminal device certificate and authentication parameters;
[0062] Step 4: After completing the edge gateway identity authentication in step 3, the eTSB of the extended terminal A calls the local soft cryptographic module to generate the SM2 signature key pair used for the trusted protection service and applies for the SM2 encryption key pair from the trusted cryptographic module (TPCM / TCM) of the edge gateway G; the application request carries the trusted signature public key TC_Pubk_Sig of the extended terminal A;
[0063] Step 5: The trusted software base gTSB of edge gateway G parses the request, calls TPCM / TCM to generate the trusted encryption key pair Tc_Keys_Enc of extension terminal A, encrypts Tc_Keys_Enc using Tc_Pubk_Sig, and returns it to extension terminal A; gTSB stores the signature public keys Tc_Pubk_Sig and Tc_Keys_Enc corresponding to extension terminal A;
[0064] Step 6: The extended terminal eTSB parses the response message and decrypts it using the local signature private key Tc_Prik_Sig to obtain the encryption key pair Tc_Keys_Enc, which is securely stored in the TEE soft password module.
[0065] Step 7: eTSB carries the terminal system characteristic parameters of extended terminal A to apply for a trusted policy from the edge gateway gTSB, and uses the signature private key to generate signature information for the request data;
[0066] Step 8: The edge gateway G obtains the registration data of the extended terminal eTSB, and after verification by gTSB, calls the gateway's built-in TPCM to create the corresponding trusted root (eRTM, eRTS, and eRTR) container and platform trusted configuration register ePCR for A; initializes the corresponding TCM trusted key and storage area data, and returns a registration response carrying A's trusted policy and trusted root identification information Tc_ID;
[0067] Step 9: The edge gateway gTSB builds a trusted trust chain for the extended terminal A starting with the trusted root of measurement eRTM of the extended terminal A in the TPCM / TCM.
[0068] Step 10: The edge gateway gTSB initiates a trusted measurement to the eTSB trusted software base entity preset in the extended terminal A, generates a measurement value, and compares it with the trusted reference value of the eTSB trusted software base of the same type of extended terminal in the trusted reference library of the edge gateway G;
[0069] Step 11: If the comparison in step 9 is successful, it means that the eTSB software base has not been tampered with and the eTSB status is trustworthy;
[0070] Step 12: eTSB parses the measurement instruction issued by gTSB and, based on the trusted policy returned in step 6, calls the system control component service of extended terminal A to initiate trusted measurement of the A terminal boot program, system kernel, system image, and system application files. It generates a trusted measurement value value1 = [v1, v2…, vn] and compares it with the initial measurement value value0 stored in the TEE in step 2.
[0071] Step 13: The comparison of step 11 is passed, indicating that the status of the extended terminal A in the time sequence process from step 1 to step 11 is credible; eTSB encrypts value1 with the Tc_Keys_Enc public key, signs it with Tc_Prik_Sig, and reports it to gTSB, carrying the master node trusted root identifier Tc_ID;
[0072] Step 14: After gTSB obtains the ciphertext and signature information of value1 in step 12, it calls the signature public key Tc_Pubk_Sig corresponding to A of TPCM / TCM in step 4 to verify the signature and calls the private key Tc_Keys_Enc to decrypt the ciphertext of value1 to obtain value1;
[0073] Step 15: gTSB calls TPCM / TCM to measure value1 according to the PCR register measurement result algorithm
[0074] hash i =ePCR i +1=SM3.Hash[ePCR i ||value1]
[0075] Generate the hash of this measurement result i Write to the ePCR platform configuration register. If it is determined that this result is the first write operation of the ePCR register, gTSB will hash this i The trusted reference of the extended terminal A is stored in the trusted reference library in the gTSB.
[0076] Step 16: The process ends.
[0077] Those skilled in the art can make various corresponding changes and modifications based on the above technical solutions and concepts, and all of these changes and modifications should be included in the scope of protection of the claims of the present invention.
Claims
1. A trusted protection strategy and measurement method for a mobile service end-edge system, characterized by: The specific process is: S1. The edge gateway is powered on and started. After completing the application for the mobile business system digital certificate, building the trust chain based on TPCM / TCM, initiating the trusted measurement, and starting the system control component service, the initialization process of the edge gateway is completed. S2. After the extended terminal is powered on and starts up, and the device certificate application, software password module initialization in the TEE trusted execution environment, and system control component service startup process are completed, the trusted software base eTSB calls the software password module and performs the first initial trust measurement according to the factory preset trust policy, and sets the initial measurement value value0 = [v1, v2..., v n ] is securely stored in the TEE soft password module; the extended terminal completes the initialization process and accesses the edge gateway based on the wireless LAN; S3: The extended terminal initiates the identity authentication process for accessing the edge gateway, carrying the extended terminal device certificate and authentication parameters; S4. After completing the identity authentication of accessing the edge gateway in step S3, the trusted software base eTSB of the extended terminal calls the local software cryptographic module to generate the SM2 signature key pair used in the trusted process, reports the signature public key to the edge gateway gTSB for storage, and simultaneously applies for the SM2 encryption key pair from the TPCM or TCM of the edge gateway, which is securely stored in the TEE soft cryptographic module of the extended terminal; S5. The trusted software base eTSB of the extended terminal carries the terminal system characteristic parameters to apply for a trusted policy from the trusted software base gTSB of the edge gateway, and uses the signature private key to generate signature information for the request data; S6. The edge gateway obtains the registration data of the trusted software base eTSB of the extended terminal. After the signature is verified, it calls the TPCM to create the hardware trusted root container and platform trusted configuration register ePCR of the corresponding extended terminal, initializes the trusted key and storage area data of the corresponding TCM, and returns a registration response with the trusted measurement policy and trusted root identification information; S7. The trusted software base gTSB of the edge gateway builds a trusted trust chain for the extended terminal with the trusted root of measurement eRTM of the extended terminal as the starting point, initiates trusted measurement to the trusted software base eTSB preset in the extended terminal, generates measurement results and compares them with the trusted reference value of the trusted software base eTSB of the corresponding type of extended terminal stored in the edge gateway; S8. If the comparison result in step S7 is consistent, it means that the trusted software base eTSB has not been tampered with and is in a trustworthy state. The trusted software base eTSB parses the measurement instruction issued, and according to the trusted measurement policy returned in step S6, calls the system control component service of the extended terminal to initiate the trusted measurement of the boot program, system kernel, system image and system application files of the extended terminal, and generates a trusted measurement value value1 = [v1, v2..., v n ] and compare it with the initial measurement value value0 stored in TEE in step S2; S9. If the comparison result in step S8 is consistent, it means that the system has not been attacked or tampered with during the process from step S1 to step S8, and the status is trustworthy; the trusted software base eTSB encrypts and signs value1 with the encryption private key and reports it to the trusted software base gTSB; S10. After obtaining the ciphertext and signature information of value1 in step S9, the trusted software base gTSB first calls the signature public key of the extended class terminal stored in step S4 to verify the signature, and then calls the encryption private key of the extended class terminal to decrypt the ciphertext of value1 to obtain value1; S11, the trusted software base gTSB calls TPCM or TCM, and generates the current measurement result hash1 = [h1, h2, ..., h n ] and stored in the ePCR platform configuration register.
2. The method according to claim 1, characterized in that The extended terminal has the system function call with the highest system authority, and the trusted benchmark of the TSB trusted software base preset in the extended terminal has been synchronously sent to the northbound edge gateway trusted benchmark library through the mobile business system.