Program Blocking Method and System in the Dual-System Trust Measurement Structure in the Cloud Environment
By uniformly storing whitelists in high-speed storage devices and mounting them to virtual machines in a cloud environment, the problem of program measurement lag and whitelist security in the dual-system trusted metric structure is solved, and the rapid blocking execution of virtual machine programs and the independence of dual-system trusted metrics is achieved.
Patent Information
- Application Number
- CN202411864041.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2044-12-18
AI Technical Summary
In the cloud environment, in the dual-system trusted metric structure, it is difficult for the existing technology to quickly measure the program in time, resulting in lagging program execution when the metric fails, and storing the whitelist in the virtual machine will cause security issues, which violates the trustworthiness requirements of the dual-system.
A new whitelist storage method is adopted to store all whitelists in high-speed storage devices, and divide them into multiple sub-devices, and mount them to different virtual machines respectively. The virtual machine accesses the whitelist through the /dev/mem device, ensures the read permission of the whitelist, and triggers the hook function to check the file hash value and attribute matching when the trusted management platform performs measurements.
It realizes that virtual machine program metrics can be quickly blocked when they fail in cloud environments, avoiding the security problem of whitelist tampering, and not affecting the trustworthy metrics of the dual systems.
Smart Images

Figure CN119337361B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of computer security, and particularly relates to a program blocking method and system in a dual-system trusted measurement structure in a cloud environment. Background Art
[0002] The statements in this part only provide background technical information related to the present invention and do not necessarily constitute prior art.
[0003] In a cloud environment, a trusted management platform is deployed on a host, and an agent is deployed on a virtual machine. The agent continuously sends trusted data to the trusted management platform, and the trusted management platform performs measurements based on the received information and the whitelist stored on the host. If the measurement fails, a log is written and the user is prompted. At the same time, the agent is also notified of subsequent processing, such as shutting down, disconnecting from the network, deleting illegal files, etc. This is a common operation under the dual-system trusted structure. In a common dual-system trusted measurement structure, the measurement process occurs at the trusted management platform end, i.e., the center end. When the measurement fails at the center end, the executable program located at the agent end has already been executed. If, at the agent end, the file is measured at the center end before being executed, it is not advisable in terms of time, especially when the trusted management platform is implemented in software form. Then, when the program measurement fails, the execution of the program needs to be stopped immediately. In real scenarios, there are many such requirements. Generally, in such scenarios, the whitelist needs to be placed in the agent system, but this brings security issues such as the whitelist being tampered with.
[0004] Since the whitelist is stored in the management platform, the subsequent processing (disconnecting from the network, deleting illegal files, etc.) in case of measurement failure has a lag. In real requirements, it is often required that illegal files are not allowed to be executed. That is, when the program in the virtual machine is executed, it needs to be checked whether it has been tampered with, and if it has been tampered with, it is not allowed to run. In such a scenario, the whitelist needs to be placed in the virtual machine for checking. However, storing the whitelist in the virtual machine has certain security issues and does not meet the requirements of the dual system. Summary of the Invention
[0005] To solve the above problems, the present invention proposes a program blocking method and system in a dual-system trusted measurement structure in a cloud environment. The present invention proposes a new storage method for the whitelist. Since the trusted management platform is placed on the host, all whitelists can be unified and stored in a high-speed storage device, and then the storage device is divided into multiple sub-devices and respectively mounted to different virtual machines; from the perspective of the virtual machine, there will be a storage device / dev / mem, which stores the whitelists of all its executable programs; this storage method is particularly suitable in a cloud environment. Through the new storage method of the whitelist and a series of operations based on this, it is possible to block the execution of programs in the virtual machine when the measurement fails, and at the same time, it does not affect the trusted measurement of the dual system.
[0006] According to some embodiments, the first solution of the present invention provides a program blocking method in a dual-system trusted measurement structure in a cloud environment, adopting the following technical solution:
[0007] The program blocking method in a dual-system trusted measurement structure in a cloud environment includes:
[0008] Each virtual machine registers information with the trusted management platform, generates a whitelist during the registration process, and sends it to the trusted management platform;
[0009] The trusted management platform stores the whitelist of each virtual machine on the high-speed storage device and generates virtual machine storage device mapping information and feeds it back to the corresponding virtual machine;
[0010] After the virtual machine starts, it reads the virtual machine storage device mapping information and loads it into the virtual machine memory. The virtual machine continuously sends trusted data to the trusted management platform, and the trusted management platform continuously measures the virtual machine;
[0011] When a file in the virtual machine requests to run from the trusted management platform, the trusted management platform determines whether to run it by comparing the file with the content in the whitelist;
[0012] When a file in the virtual machine requests an operation from the trusted management platform, the trusted management platform determines whether to control it by comparing the file with the content in the whitelist.
[0013] Further, the whitelist is a list of file names and hash values, where the hash value is the hash value of the file content and file attributes, or the hash value is the hash value of the file content.
[0014] Further, the virtual machine storage device mapping information includes the whitelist, the storage space location of the high-speed storage device, and other user permissions.
[0015] Further, when a file in a virtual machine requests to run from the trusted management platform, the trusted management platform determines whether to run it by comparing the file with the content in the whitelist. Specifically:
[0016] When a file in a virtual machine requests to run from the trusted management platform, a hook function is triggered;
[0017] The hook function accesses the whitelist. If it finds that the file is not in the whitelist, it rejects the run; otherwise, it calculates the hash value of the file and compares it with the hash value in the whitelist;
[0018] If the hash value of the file is inconsistent with the hash value in the whitelist, it rejects the run; otherwise, it matches the file with other attributes in the whitelist;
[0019] If the file does not match other attributes in the whitelist, it rejects the run.
[0020] Further, when a file in a virtual machine requests an operation from the trusted management platform, the trusted management platform determines whether to control it by comparing the file with the content in the whitelist. Specifically:
[0021] Before a file in a virtual machine requests an operation from the trusted management platform, a hook function is triggered;
[0022] The hook function accesses the whitelist. If it finds that the file is not in the whitelist, it does not perform any operation or control on it; otherwise, it determines whether the whitelist allows the corresponding operation;
[0023] If not allowed, it does not perform any operation or control on it. Otherwise, it determines whether the file matches other attributes in the whitelist. If not, it does not perform any operation or control on it.
[0024] Further, when a single virtual machine performs a software upgrade, a software package is installed in the virtual machine. During the continuous measurement of the virtual machine by the trusted management platform, the measurement fails and new files are found;
[0025] The trusted management platform obtains the corresponding whitelist according to the new files and stores it on the high-speed storage device, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine to complete the software upgrade.
[0026] Further, when multiple virtual machines perform a software upgrade, the software package is loaded on the trusted management platform, and the trusted management platform continuously measures the virtual machines;
[0027] The trusted management platform updates the whitelist according to the software package, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine;
[0028] The virtual machine installs software packages according to the new virtual machine storage device mapping information to complete software upgrade.
[0029] According to some embodiments, the second solution of the present invention provides a program blocking system in a dual-system trusted measurement structure in a cloud environment, adopting the following technical solution:
[0030] The program blocking system in the dual-system trusted measurement structure in a cloud environment includes a host and multiple virtual machines;
[0031] The host includes a trusted management platform and a high-speed storage device;
[0032] The virtual machine continuously sends trusted data to the trusted management platform through the agent for trusted measurement, and at the same time sends the whitelist to the host to be stored in the high-speed storage device;
[0033] The trusted management platform generates virtual machine storage device mapping information according to the storage space location of the whitelist in the high-speed storage device and feeds it back to the corresponding virtual machine, so that the virtual machine can be mounted to the host. When a certain virtual machine measurement fails, its execution can be blocked without affecting the trusted measurement of the dual system.
[0034] Further, the high-speed storage device is divided into multiple sub-devices, which are respectively mounted to different virtual machines.
[0035] Further, a mapped storage device is also provided on the virtual machine for storing the virtual machine storage device mapping information mapped by the trusted management platform according to the whitelist.
[0036] Compared with the prior art, the beneficial effects of the present invention are as follows:
[0037] The present invention provides a compromise solution in a cloud computing environment. The trusted management platform as the center end is deployed on a physical host, and the agent is deployed in the virtual machine. The agent provides trusted data to the center for measurement. At the same time, the whitelist is mapped to the virtual machine in the form of a storage component for the virtual machine to read and use. The virtual machine only has read permission for the whitelist. In this scenario, the blocking of the program and the continuous measurement of the virtual machine are relatively independent. BRIEF DESCRIPTION OF THE DRAWINGS
[0038] The accompanying drawings forming a part of this specification are used to provide a further understanding of the present invention. The schematic embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation to the present invention.
[0039] Figure 1 It is an architecture diagram of a program blocking system in a dual-system trusted measurement structure in a cloud environment in the second embodiment of the present invention;
[0040] Figure 2 It is a diagram of the interaction processing procedure during the deployment of the trusted management platform and the virtual machine agent in the first embodiment of the present invention;
[0041] Figure 3 It is an example diagram of the format of the whitelist in the first embodiment of the present invention;
[0042] Figure 4 It is a schematic diagram of the storage space of the high-speed storage device in the first embodiment of the present invention;
[0043] Figure 5 It is a schematic diagram of the execution process of the executable file in the first embodiment of the present invention;
[0044] Figure 6 It is a flowchart of the file being operated in the first embodiment of the present invention;
[0045] Figure 7 It is a flowchart of the upgrade of a single virtual machine in the first embodiment of the present invention;
[0046] Figure 8 It is a flowchart of the batch upgrade of virtual machines in the first embodiment of the present invention. Detailed implementation manners
[0047] The present invention will be further described below in conjunction with the accompanying drawings and embodiments.
[0048] It should be noted that the following detailed descriptions are all illustrative and are intended to provide further descriptions of the present invention. Unless otherwise specified, all technical and scientific terms used herein have the same meaning as commonly understood by those of ordinary skill in the technical field to which the present invention belongs.
[0049] It should be noted that the terms used herein are only for describing specific implementation manners and are not intended to limit the exemplary embodiments according to the present invention. As used herein, unless otherwise clearly specified in the context, the singular form is also intended to include the plural form. In addition, it should also be understood that when the terms "comprise" and / or "include" are used in this specification, they indicate the presence of features, steps, operations, devices, components, and / or combinations thereof.
[0050] In the case of no conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.
[0051] Embodiment 1
[0052] As Figure 2 shown, this embodiment provides a program blocking method in a dual-system trusted measurement structure in a cloud environment. In this embodiment, the method includes the following steps:
[0053] Each virtual machine registers information with the trusted management platform, and generates a whitelist and sends it to the trusted management platform during the registration process;
[0054] The trusted management platform stores the whitelist of each virtual machine on a high-speed storage device and generates virtual machine storage device mapping information to feedback to the corresponding virtual machine;
[0055] After the virtual machine starts, it reads the virtual machine storage device mapping information and loads it into the virtual machine memory. The virtual machine continuously sends trusted data to the trusted management platform, and the trusted management platform continuously measures the virtual machine;
[0056] When a file in the virtual machine requests to run from the trusted management platform, the trusted management platform determines whether to run it by comparing the file with the content in the whitelist;
[0057] When a file in the virtual machine requests an operation from the trusted management platform, the trusted management platform determines whether to control it by comparing the file with the content in the whitelist.
[0058] The whitelist is a list of file names and hash values. Among them, the hash value is the hash value of the file content and file attributes, or the hash value is the hash value of the file content.
[0059] The virtual machine storage device mapping information includes the whitelist, the storage space location of the high-speed storage device, and other user permissions.
[0060] When a file in the virtual machine requests to run from the trusted management platform, the trusted management platform determines whether to run it by comparing the file with the content in the whitelist. Specifically:
[0061] When a file in the virtual machine requests to run from the trusted management platform, a hook function is triggered;
[0062] The hook function accesses the whitelist. If it is found that the file is not in the whitelist, the run is rejected; otherwise, the hash value of the file is calculated and compared with the hash value in the whitelist;
[0063] If the hash value of the file is inconsistent with the hash value in the whitelist, the run is rejected; otherwise, the file is matched with other attributes in the whitelist;
[0064] If the file does not match other attributes in the whitelist, the run is rejected.
[0065] When a file in the virtual machine requests an operation from the trusted management platform, the trusted management platform determines whether to control it by comparing the file with the content in the whitelist. Specifically:
[0066] Before a file in the virtual machine requests an operation from the trusted management platform, a hook function is triggered;
[0067] The hook function accesses the whitelist. If a file is not found in the whitelist, no operation or control is performed on it; otherwise, it is determined whether the whitelist permits the corresponding operation.
[0068] If not permitted, no operation or control is performed on it; otherwise, it is determined whether the file matches other attributes in the whitelist. If not, no operation or control is performed on it.
[0069] When a single virtual machine performs a software upgrade, a software package is installed in the virtual machine. During the continuous measurement of the virtual machine by the trusted management platform, the measurement fails and new files are found.
[0070] The trusted management platform obtains the corresponding whitelist according to the new files and stores it on the high-speed storage device, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine to complete the software upgrade.
[0071] When multiple virtual machines perform a software upgrade, the software package is loaded on the trusted management platform, and the trusted management platform continuously measures the virtual machines.
[0072] The trusted management platform updates the whitelist according to the software package, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine.
[0073] The virtual machine installs the software package according to the new virtual machine storage device mapping information to complete the software upgrade.
[0074] As Figure 2 shown, the interaction processing between the trusted management platform and the virtual machine agent during deployment is as follows:
[0075] The trusted management platform is deployed on the host, and by default, the security of the host is higher; the agent is deployed on the virtual machine.
[0076] The agent registers with the trusted management platform; during registration, it is necessary to ensure that the virtual machine is in a secure state. During the registration process, a whitelist is generated in the virtual machine and submitted to the trusted management platform.
[0077] The format of the whitelist is as Figure 3 shown, that is, the whitelist is a list of file names and hash values. The hash value can be either the hash value of the file content or the hash value of the file content plus the file attributes.
[0078] After the trusted management platform receives the whitelist, it configures the hardware management device and allocates a storage space on the high-speed storage device (hereinafter referred to as whitelist-space) to store the whitelist. This space is then mapped to the corresponding virtual machine as a read-only device for the virtual machine. From the perspective of the virtual machine, a / dev / mem device is added.
[0079] The mapping information of the whitelist-space - virtual machine storage device can be read and written in the trusted management platform. However, the virtual machine can only read it and cannot overwrite it.
[0080] The trusted management platform sets other attributes of the whitelist-space according to the user interface, that is, the operation permissions of the files in the virtual machine that the user can set. For example, whether the file can be deleted. Many other attributes can be set according to requirements, as Figure 4 shown. The modification of the whitelist is operated by the user in the trusted management platform.
[0081] That is to say, the virtual machine storage device mapping information includes the whitelist, the storage space location of the high-speed storage device, and other user permissions.
[0082] After that, the trusted management platform will continuously measure the virtual machine through the agent module.
[0083] Virtual machine executes files, scenario analysis.
[0084] When the virtual machine starts, it reads the content of the whitelist in the virtual machine storage device - / dev / mem and loads it into the memory. The virtual machine continuously sends trusted data to the trusted management platform, and the trusted management platform continuously measures the virtual machine. When a certain file in the virtual machine (including drivers, dynamic libraries, executable files, configuration files, etc., taking executable file A as an example here) is tampered with and then run, the virtual machine will query the data in / dev / mem in the memory and perform corresponding processing according to the configuration of the whitelist inside.
[0085] As Figure 5 shown, it is the execution process of an executable file.
[0086] Before the executable file is executed, it will enter a hook function, and the hook function will access the whitelist. If it is found that the file is not in the whitelist, the execution will be refused; if it is found that the calculated hash value is inconsistent with the hash value in the whitelist, the execution will be refused; if it is found that it does not match other attributes, the execution will be refused. For example, a certain user is not allowed to execute a certain program, while other users are allowed. This can be achieved through attribute configuration.
[0087] It should be noted that when other files in the virtual machine are tampered with and then run, the above process is followed, that is, the hook function is triggered first and then subsequent processing is carried out.
[0088] As Figure 6 shown, it is the execution process when a file is read, modified, or deleted, that is, the specific process when a file is requested to be operated on.
[0089] When a file is deleted / modified / read, the virtual machine first needs to determine whether the file is in the whitelist. Different from executable files, executable files are rejected if they are not in the whitelist. For file editing actions, if they are not in the whitelist, they are not controlled. That is to say, as long as the trusted management platform does not perform special attribute control on the file, by default, users are allowed to create, modify, read, and delete an ordinary file.
[0090] When it is found that the file is in the whitelist, control is carried out according to the attributes. For example, if the whitelist attribute does not allow the file to be deleted, the user cannot delete it.
[0091] Set the exclusion list. When a user is doing development work in a certain directory and needs to frequently modify and execute the files inside, the "exclusion control" attribute can be set. When it is 1, monitoring of this file can be rejected. That is, the addition, deletion, editing, and execution of this file are no longer concerned about and processed.
[0092] For software upgrades and updates in the virtual machine, when the software in the virtual machine needs to be upgraded, it can be upgraded in two ways.
[0093] As shown in Figure 7, install directly on the virtual machine. In the trusted management platform, new files will be found. In the trusted management platform, perform the operation of adding a new whitelist and add the corresponding files to the corresponding virtual machine. This upgrade method is suitable for upgrading a single virtual machine.
[0094] As Figure 8 shown, directly place the software package on the trusted management platform. The trusted management platform generates a whitelist, loads it into the corresponding virtual machine, and then installs it on the virtual machine. This upgrade method is suitable for batch upgrades. At the same time, the continuous measurement will not fail during the upgrade process.
[0095] That is to say, when the software in the virtual machine needs to be upgraded, place the software package to be upgraded on the trusted management platform. The trusted management platform generates a corresponding upgrade whitelist according to the software package, merges the upgrade whitelist into the corresponding whitelists of each virtual machine that needs to be batch-upgraded to update the whitelists of the virtual machines, and then sends the software package to the corresponding virtual machines according to the updated whitelists and installs and upgrades it in the virtual machines.
[0096] Embodiment 2
[0097] As Figure 1 shown, this embodiment provides a program blocking system in a dual-system trusted measurement structure in a cloud environment, including a host and multiple virtual machines;
[0098] The host includes a trusted management platform and a high-speed storage device;
[0099] The virtual machine continuously sends trusted data to the trusted management platform for trusted measurement by using an agent, and at the same time sends a whitelist to the host to be stored in the high-speed storage device;
[0100] The trusted management platform generates virtual machine storage device mapping information according to the storage space position of the whitelist in the high-speed storage device and feeds it back to the corresponding virtual machine, so that the virtual machine can be mounted to the host. When a certain virtual machine measurement fails, its execution can be blocked without affecting the trusted measurement of the dual system.
[0101] In this embodiment, all whitelists are uniformly placed in a high-speed storage device, and the high-speed storage device is divided into multiple sub-devices, which are respectively mounted to different virtual machines.
[0102] A mapped storage device, i.e., / dev / mem, is also set on the virtual machine to store the virtual machine storage device mapping information mapped by the trusted management platform according to the whitelist, that is, the whitelist of all executable programs of the virtual machine itself.
[0103] This storage method is especially suitable in a cloud environment. Through the new storage method of the whitelist and a series of operations based on this, it is possible to block the execution of programs in the virtual machine when the measurement fails; at the same time, it does not affect the trusted measurement of the dual system.
[0104] Although the specific implementation manners of the present invention are described above in conjunction with the accompanying drawings, it is not a limitation to the protection scope of the present invention. Those skilled in the art should understand that various modifications or deformations that can be made without creative labor on the basis of the technical solutions of the present invention are still within the protection scope of the present invention.
Claims
1. A program blocking method in a dual-system trusted measurement structure under a cloud environment, characterized in that: include: Each virtual machine registers information with the trusted management platform. During the registration process, a whitelist is generated and sent to the trusted management platform. The trusted management platform stores the whitelist of each virtual machine on a high-speed storage device, and generates virtual machine storage device mapping information and feeds it back to the corresponding virtual machine; After the virtual machine is started, the virtual machine storage device mapping information is read and loaded into the virtual machine memory, the virtual machine continuously sends trusted data to the trusted management platform, and the trusted management platform continuously measures the virtual machine; When a file in a virtual machine requests to run from the trusted management platform, the trusted management platform compares the file with the content in the whitelist to determine whether to run; When a file in a virtual machine requests an operation from the trusted management platform, the trusted management platform compares the file with the content in the whitelist to determine whether to control it.
2. The program blocking method in the dual-system trust measurement structure under the cloud environment as claimed in claim 1 is characterized in that: The whitelist is a list of file names and hash values, wherein the hash value is a hash value of the file content and the file attribute, or the hash value is a hash value of the file content.
3. The program blocking method in the dual-system trust measurement structure under the cloud environment as claimed in claim 1 is characterized in that: The virtual machine storage device mapping information includes a white list, a storage space location of a high-speed storage device, and other user permissions.
4. The program blocking method in the dual-system trust measurement structure under the cloud environment as claimed in claim 1, characterized in that: When a file in the virtual machine requests to run from the trusted management platform, the trusted management platform determines whether to run the file based on the comparison between the file and the content in the whitelist, specifically: When the file in the virtual machine requests to run from the trusted management platform, the hook function is triggered; The hook function accesses the whitelist, and if it finds that the file is not in the whitelist, it refuses to run; otherwise, it calculates the hash value of the file and compares it with the hash value in the whitelist; If the hash value of the file does not match the hash value in the whitelist, it will be rejected; otherwise, the file will be matched with other attributes in the whitelist; If the file does not match other attributes in the whitelist, it is refused to run.
5. The method for blocking programs in a dual-system trusted measurement structure in a cloud environment as claimed in claim 1, characterized in that: When a file in the virtual machine requests an operation from the trusted management platform, the trusted management platform compares the file with the content in the whitelist to determine whether to control it, specifically: Before the file in the virtual machine requests an operation from the trusted management platform, the hook function is triggered; The hook function accesses the whitelist. If it is found that the file is not in the whitelist, it will not be operated or controlled; otherwise, it will determine whether the whitelist allows the corresponding operation; If not allowed, no operation or control will be performed on it. Otherwise, it will be determined whether the file matches other attributes in the whitelist. If not, no operation or control will be performed on it.
6. The method for blocking programs in a dual-system trusted measurement structure in a cloud environment as claimed in claim 1, characterized in that: When a single virtual machine is performing a software upgrade, a software package is installed in the virtual machine, and the trusted management platform continuously measures the virtual machine, and the measurement fails and a new file is found; The trusted management platform obtains the corresponding white list according to the new file and stores it on a high-speed storage device, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine to complete the software upgrade.
7. The method for blocking programs in a dual-system trust measurement structure under a cloud environment as claimed in claim 1, characterized in that: When a batch of virtual machines are undergoing software upgrades, the software package is loaded on the trusted management platform, and the trusted management platform continuously measures the virtual machines; The trusted management platform updates the whitelist according to the software package, and generates new virtual machine storage device mapping information and feeds it back to the corresponding virtual machine; The virtual machine installs the software package according to the new virtual machine storage device mapping information to complete the software upgrade.
8. The program blocking system in the dual-system trusted measurement structure under the cloud environment is characterized by: Includes the host and multiple virtual machines; The host includes a trusted management platform and a high-speed storage device; The virtual machine uses the agent to continuously send trusted data to the trusted management platform for trust measurement, and sends the whitelist to the host to be stored in a high-speed storage device; The trusted management platform generates virtual machine storage device mapping information based on the storage space location of the whitelist in the high-speed storage device and feeds it back to the corresponding virtual machine, so that the virtual machine and the host are mounted. When a virtual machine fails to measure, its execution can be blocked without affecting the trusted measurement of the dual system.
9. The program blocking system in the dual-system trust measurement structure under the cloud environment as claimed in claim 8, characterized in that: The high-speed storage device is divided into a plurality of sub-devices, which are mounted to different virtual machines respectively.
10. The program blocking system in the dual-system trust measurement structure in the cloud environment as claimed in claim 8, characterized in that: The virtual machine is also provided with a mapping storage device for storing virtual machine storage device mapping information mapped by the trusted management platform according to the white list.
Citation Information
Patent Citations
Virtual machine measurement method and apparatus
CN105159744A
Mobile office method of mobile software white list mechanism based on trusted measurement
CN110502888A