A method, system and device for realizing the acquisition and control of trusted static measurement elements

By optimizing the parser and registering it with the trusted software base agent module, the problems of insufficient flexibility and compatibility in the prior art are solved, and flexible collection and control of trusted static measurement elements are realized, and measurement efficiency and system security are improved.

CN119475361BActive Publication Date: 2025-05-30BEIJING XUANJI ANCHEN COMPUTING TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510054495.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-01-14
Publication Date
2025-05-30
Estimated Expiration
2045-01-14

AI Technical Summary

Technical Problem

When the prior art realizes the acquisition and control of trusted static metric elements, it is restricted by the endogenous security mechanism of the Linux kernel and the LSM framework, resulting in insufficient flexibility and compatibility issues.

Method used

By optimizing the parser, a third-party parser is obtained and registered in the trusted software base agent module to determine the monitored kernel functions and custom processing functions. Then, the trusted software base proxy module is loaded into the kernel of the operating system, the third-party parser is activated, the trusted static metric elements of the operating system process are collected, and the control is carried out through the metric engine.

Benefits of technology

It realizes the flexible collection and control of trusted static metric elements of the operating system without being restricted by the rigid LSM system, improves measurement efficiency and accuracy, reduces dependence on kernel versions, and enhances the security and compatibility of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119475361B_ABST
    Figure CN119475361B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of information security, and discloses a method, a system and a device for realizing the acquisition and control of trusted static measurement elements. The method includes: obtaining a third-party parser by optimizing a parser; registering the third-party parser into a trusted software base proxy module; loading the trusted software base proxy module into the kernel of an operating system; when the kernel of the operating system executes a monitored kernel function, calling a custom processing function proxied in the trusted software base proxy module to collect the trusted static measurement elements of an operating system process; sending the collected trusted static measurement elements to a measurement engine of the trusted software base, and controlling the process of the operating system according to the comparison result between the reference value calculated by the measurement engine and the reference value in a reference library, and in combination with a trusted software base proxy control mechanism. The reliability and reentry problems of a first-party parser are solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of information security, and particularly to a method, system and device for realizing the acquisition and control of trusted static measurement elements. Background Art

[0002] In order for the trusted platform control module to realize the trusted measurement of executable files in the operating system, the trusted agent needs to rely on the operating system LSM framework (Linux Security Modules) to realize the acquisition and control functions of measurement elements.

[0003] The security-enhanced Linux (an operating system) kernel often needs to control its critical execution paths, which requires the Linux kernel to have the ability to change the original execution flow of the kernel during the enhancement process. For this purpose, the kernel has established the LSM framework, which presets security checkpoints above all the critical execution paths of the kernel, and realizes the purpose of controlling the original process by registering to these checkpoints. Although LSM covers as many aspects related to daily affairs and security as possible, its fixed execution sites and quantity limit the flexibility of security functions. And with the iteration of technology and the response to existing security threats, the Linux kernel increasingly tends to restrict all security modules inside the kernel rather than dynamic loadable modules, and restricts the initialization timing of these codes, making them writable only in the relatively early stage of kernel initialization and then placed under read-only protection. For security vendors who often need to face the enhancement of the security of existing stock systems, it is undoubtedly neither flexible enough nor able to overcome the various endogenous security obstacles of the kernel.

[0004] Under this current situation, it is very necessary to create a flexible measurement element acquisition method that is not restricted by the rigid system of LSM and is compatible with the modern kernel's endogenous security mechanism.

[0005] The existing related technologies include:

[0006] I. Trusted Software Base Agent (TSB Agent), the principle based on the Linux Security Module (LSM) involves the extension of the Linux kernel security framework to enhance the security and integrity of the system. LSM allows developers of security policies to implement their own security policies without modifying the kernel code. These policies can control access to system resources and monitor the behavior of the system.

[0007] II. The first-party JProbe (parser), implemented based on KProbe (a lightweight kernel debugging tool), and can only be used for function entry addresses. KProbe is a general probe mechanism adopted by the Linux kernel. By inserting architecture-related breakpoint instructions at the instruction addresses to be probed, the original execution flow is interrupted and the system exception handling is entered, so that the CPU register status and memory content before and after the instruction execution can be probed. It is also possible to affect the subsequent system state by intervening in the CPU registers, including but not limited to modifying the instruction pointer register to change the execution path. These features can be used for kernel dynamic debugging, hot patching, and hooking of almost all kernel functions. JProbe was once part of the Kprobe system. Its feature is to use KProbe to instrument at specific instructions (function entry), save the CPU registers and stack content in the callback function of KProbe, and then call the user-defined JProbe probe function. These functions have the same prototype definition as the functions to be probed. The function parameters are either passed through the stack or through the registers. With the protection and backup of the current scene, JProbe can not only let the user function probe all the actual parameters corresponding to the prototype, but also restore the CPU registers and stack content that may have been changed after the probe function is executed. After that, the original execution flow (the function interrupted by the probe) is restored by calling a special return function.

[0008] The corresponding disadvantages of the above-mentioned existing related technologies:

[0009] I. 1. The TSB proxy has a small scope of application and needs to be adapted to each operating system kernel version, resulting in a large amount of adaptation work. 2. In high-version operating systems, for security reasons, the export of the kernel symbol table will be restricted, which will affect the adaptation based on LSM and the implementation of TSB. The kernel symbol table contains the addresses and information of all symbols (such as functions, variables, etc.) in the kernel, and is crucial for developing and debugging kernel modules (including LSM modules). Without this information, it will be difficult for developers to determine the exact location to hook, thus affecting the development and debugging of LSM modules.

[0010] Second, although the first-party Jprobe can be used for the redirection of kernel functions, it has several obvious defects and limitations for security purposes: 1. Since Linux kernel version 4, the support for JProbe has been stopped and gradually removed. 2. Although it can be used to insert a user-defined function before a kernel function, after the execution of the user function, the execution of the original function cannot be skipped. Therefore, the control function of a trusted proxy cannot be implemented. 3. In the implementation of the first-party Jprobe, a global variable design is adopted, and relevant information is stored in the global variable kprobe_ctlblk. Because there is only one global variable, new probe instances will have a competition problem, which is the fundamental reason why the first-party Jprobe cannot be reentrant. When nested calls occur, the later calls will be ignored, and the security mechanism will also be bypassed. Therefore, the first-party Jprobe cannot be used for security purposes and cannot implement the security check function of a trusted proxy.

[0011] Therefore, how to provide a method, system, and device for implementing the acquisition control of trusted static measurement elements is an urgent problem to be solved at present. Summary of the Invention

[0012] Embodiments of the present invention provide a method, system, and device for implementing the acquisition control of trusted static measurement elements to solve the problems that the prior art is not flexible enough and to overcome the obstacles caused by various endogenous security of the kernel.

[0013] To have a basic understanding of some aspects of the disclosed embodiments, a simple summary is given below. This summary part is not a general review, nor is it to identify key / important constituent elements or to delineate the protection scope of these embodiments. Its sole purpose is to present some concepts in a simple form as a prelude to the detailed description that follows.

[0014] According to the first aspect of the embodiments of the present invention, a method for implementing the acquisition control of trusted static measurement elements is provided.

[0015] In one embodiment, a method for implementing the acquisition control of trusted static measurement elements includes:

[0016] Obtaining a third-party parser by optimizing a parser; registering the third-party parser in a trusted software base proxy module and determining the monitored kernel function and the custom processing function; loading the trusted software base proxy module into the kernel of the operating system and activating the third-party parser;

[0017] When the kernel of the operating system executes the monitored kernel function, triggering the third-party parser and calling the custom processing function proxied in the trusted software base proxy module; collecting the trusted static measurement elements of the operating system process by using the called custom processing function;

[0018] Send the collected trusted static measurement elements to the measurement engine of the trusted software base. Control the processes of the operating system according to the comparison result between the reference value calculated by the measurement engine and the reference value in the reference library, and in combination with the trusted software base proxy control mechanism.

[0019] In one embodiment, by optimizing the parser, the obtained third-party parser includes:

[0020] Utilize the mechanism of stack passing context information to optimize the parser regarding the reentry problem;

[0021] Optimize the parser for the problem of not being able to control whether to continue to return to the original execution thread.

[0022] In one embodiment, utilizing the mechanism of stack passing context information to optimize the parser regarding the reentry problem includes:

[0023] At the beginning stage of the parser process, allocate new stack space and place the context information at the bottom of the new stack space;

[0024] When an exception interrupt occurs, dynamically switch the original stack to the new stack space by modifying the content of the original stack pointer register;

[0025] After the parser process ends, release the new stack space.

[0026] In one embodiment, when an exception interrupt occurs, dynamically switching the original stack to the new stack space by modifying the content of the original stack pointer register includes:

[0027] Set the original stack pointer to the top of the new stack space and clear the top of the new stack space; return to the handler and continue execution.

[0028] In one embodiment, optimizing the parser for the problem of not being able to control whether to continue to return to the original execution thread includes:

[0029] According to the user function, determine whether the parser needs to return to the original execution thread;

[0030] When it is necessary to return to the original execution thread, call the return handler function to return to the original execution thread;

[0031] When it is not necessary to return to the original execution thread, call the end handler function to end the current parser process.

[0032] In one embodiment, when it is necessary to return to the original execution thread, calling the return handler function to return to the original execution thread includes:

[0033] Utilize the return processing function and obtain the value of the register through inline assembly code; according to the value of the register, obtain the current stack bottom address, and extract the parser context information from the current stack bottom address;

[0034] Call the breakpoint interrupt through inline assembly to enter the exception handling process; in the exception handling process, according to the parser context information, switch the current stack back to the original stack space, set the interrupted instruction with a single-step flag, and execute the original instruction step by step;

[0035] After the original instruction is executed step by step, the current central processing unit automatically enters the single-step debug exception interrupt stage;

[0036] In the single-step debug exception interrupt stage, search the global parser table through the address of the interrupt priority register of the central processing unit to determine the current parser;

[0037] Obtain the corresponding underlying kernel debugging tool structure through the current parser registration information, and obtain the instrumentation address of the kernel debugging tool through the kernel debugging tool structure;

[0038] According to the instrumentation address of the kernel debugging tool, obtain the new IP register address, and make the IP register point to the new IP register address, so that the single-step exception interrupt handling ends and returns to the original execution thread.

[0039] In one embodiment, calling the end processing function to end the current parser process includes:

[0040] After the parser's processing function is executed, call the end processing function and send the information that the parser's processing function has been executed to the operating system kernel; after completing the preset work, end the current parser process.

[0041] In one embodiment, the preset work includes:

[0042] Obtain the value of the current stack pointer through inline assembly;

[0043] According to the parser context information, restore the registers and stack of the central processing unit, and make the parser monitoring function return correctly to the caller after execution;

[0044] Set the return value for the base register; release the temporary stack.

[0045] According to the second aspect of the embodiments of the present invention, a system for implementing the acquisition control of trusted static measurement elements is provided.

[0046] In one embodiment, the system for implementing the acquisition control of trusted static measurement elements includes:

[0047] Third-party tool construction module, which is used to obtain a third-party parser by optimizing a parser; register the third-party parser into a trusted software base agent module, and determine monitored kernel functions and custom processing functions; load the trusted software base agent module into the kernel of an operating system, and activate the third-party parser;

[0048] Metric element collection module, which is used to trigger the third-party parser and call a custom processing function proxied in the trusted software base agent module when the kernel of the operating system executes a monitored kernel function; collect trusted static metric elements of an operating system process by using the called custom processing function;

[0049] Process control module, which is used to send the collected trusted static metric elements to a metric engine of the trusted software base, and control the processes of the operating system according to a comparison result between a reference value calculated by the metric engine and a reference value in a reference library, and in combination with a trusted software base agent control mechanism.

[0050] According to a third aspect of an embodiment of the present invention, a computer device is provided.

[0051] In some embodiments, the computer device includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the steps of the above method are implemented.

[0052] According to a fourth aspect of an embodiment of the present invention, a computer-readable storage medium is provided.

[0053] In one embodiment, a computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the above method are implemented.

[0054] The technical solutions provided by the embodiments of the present invention may include the following beneficial effects:

[0055] (1) By solving the reliability and re-entry problems of the first-party JProbe, the present invention enables it to be applicable to a TSB (Trusted Software Base) agent module, improving the metric efficiency and accuracy.

[0056] (2) By using a third-party Jprobe, the present invention can break out of the constraints of the LSM, hook (a hook is a technique or mechanism used to intercept or insert additional processing code during program execution) any function of the kernel, including inline functions and even functions running in the interrupt context, greatly reducing the dependence on the adapted kernel. The entire core function only depends on a few specific kernel exported functions, which are supported by default and in the exported state in most kernels. Therefore, the dependence on the kernel version is reduced, the compatibility problem of the trusted computing agent in multiple operating systems is solved, and the technical application scope is improved.

[0057] It should be understood that the above general description and the following detailed description are merely exemplary and explanatory, and do not limit the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0058] The drawings herein are incorporated into the specification and constitute a part of this specification, showing embodiments consistent with the present invention, and are used together with the specification to explain the principles of the present invention.

[0059] Figure 1 is a flowchart of a method for implementing the acquisition control of trusted static measurement elements shown according to an exemplary embodiment;

[0060] Figure 2 is a schematic block diagram of a system for implementing the acquisition control of trusted static measurement elements shown according to an exemplary embodiment;

[0061] Figure 3 is a schematic structural diagram of a computer device shown according to an exemplary embodiment;

[0062] Figure 4 is a flowchart of the first-party Jprobe shown according to an exemplary embodiment;

[0063] Figure 5 is one of the flowcharts of the third-party Jprobe shown according to an exemplary embodiment;

[0064] Figure 6 is another flowchart of the third-party Jprobe shown according to an exemplary embodiment;

[0065] Figure 7 is the third flowchart of the third-party Jprobe shown according to an exemplary embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0066] The following description and the accompanying drawings fully disclose specific embodiments herein, enabling those skilled in the art to practice them. Parts and features of some embodiments may be included in or replace parts and features of other embodiments. The scope of the embodiments herein includes the entire scope of the claims and all available equivalents of the claims. In this document, the terms "first", "second", etc. are only used to distinguish one element from another, without requiring or implying any actual relationship or order between these elements. In fact, the first element can also be called the second element, and vice versa. Moreover, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a structure, device or equipment comprising a series of elements not only includes those elements but also other elements not expressly listed, or elements inherent to such structure, device or equipment. Without further limitation, an element defined by the statement "comprising one..." does not exclude the presence of additional identical elements in the structure, device or equipment comprising the element. The embodiments herein are described in a progressive manner, with each embodiment highlighting the differences from other embodiments. For the same or similar parts among the embodiments, reference may be made to each other.

[0067] In this document, the orientation or positional relationships indicated by the terms "longitudinal", "transverse", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc. are based on the orientation or positional relationships shown in the drawings, and are only for the convenience of describing this document and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation on the present invention. In the description herein, unless otherwise specified and defined, the terms "mounted", "connected", "coupled" shall be understood in a broad sense. For example, it may be a mechanical connection or an electrical connection, or may be the communication inside two elements. It may be directly connected or indirectly connected through an intermediate medium. For those of ordinary skill in the art, the specific meanings of the above terms can be understood according to specific circumstances.

[0068] In this document, unless otherwise stated, the term "plurality" means two or more.

[0069] In this document, the character " / " indicates that the objects before and after are in an "or" relationship. For example, A / B means: A or B.

[0070] In this document, the term "and / or" is an associative relationship describing an object, indicating that three relationships can exist. For example, A and / or B means: A or B, or, A and B these three relationships.

[0071] It should be understood that although the steps in the flowchart are shown sequentially in the direction of the arrows, these steps are not necessarily executed sequentially in the order indicated by the arrows. Unless otherwise clearly stated in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, at least a part of the steps in the figure may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or sub-steps or stages of other steps.

[0072] Each module in the device or system of the present application can be implemented in whole or in part by software, hardware, and their combination. The above-mentioned modules can be embedded in the processor of the computer device in hardware form or independent of it, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each of the above modules.

[0073] Without conflict, the embodiments in the present invention and the features in the embodiments can be combined with each other.

[0074] Figure 1 An embodiment of a method for implementing the acquisition control of trusted static measurement elements of the present invention is shown.

[0075] In this alternative embodiment, the method for implementing the acquisition control of trusted static measurement elements includes:

[0076] S101. Obtain a third-party parser by optimizing the parser; register the third-party parser into the trusted software base proxy module, and determine the monitored kernel function and the custom processing function; load the trusted software base proxy module into the kernel of the operating system, and activate the third-party parser;

[0077] S103. When the kernel of the operating system executes the monitored kernel function, trigger the third-party parser, and call the custom processing function proxied in the trusted software base proxy module; use the called custom processing function to collect the trusted static measurement elements of the operating system process;

[0078] S105. Send the collected trusted static measurement elements to the measurement engine of the trusted software base, and control the process of the operating system according to the comparison result between the reference value calculated by the measurement engine and the reference value in the reference library, and in combination with the trusted software base proxy control mechanism.

[0079] In this alternative embodiment, obtaining a third-party parser by optimizing the parser includes:

[0080] Optimize the parser for re - entry issues by using the mechanism of passing context information through the stack.

[0081] Optimize the parser for the issue of whether it is necessary to return to the original execution thread uncontrollably.

[0082] In this alternative embodiment, optimizing the parser for re - entry issues by using the mechanism of passing context information through the stack includes:

[0083] At the beginning stage of the parser process, allocate new stack space and place the context information at the bottom of the new stack space.

[0084] When an exception interrupts, dynamically switch the original stack to the new stack space by modifying the content of the original stack pointer register.

[0085] After the parser process ends, release the new stack space.

[0086] In this alternative embodiment, when an exception interrupts, dynamically switching the original stack to the new stack space by modifying the content of the original stack pointer register includes:

[0087] Set the original stack pointer to the top of the new stack space and clear the top of the new stack space; return to the handler and continue execution.

[0088] In this alternative embodiment, optimizing the parser for the issue of whether it is necessary to return to the original execution thread uncontrollably includes:

[0089] Judge whether the parser needs to return to the original execution thread according to the user function.

[0090] When it is necessary to return to the original execution thread, call the return handler function to return to the original execution thread.

[0091] When it is not necessary to return to the original execution thread, call the end handler function to end the current parser process.

[0092] In this alternative embodiment, when it is necessary to return to the original execution thread, calling the return handler function to return to the original execution thread includes:

[0093] Use the return handler function and obtain the register values through inline assembly code; according to the register values, obtain the current stack bottom address and extract the parser context information from the current stack bottom address.

[0094] Call a breakpoint interrupt through inline assembly to enter the exception handling process; in the exception handling process, according to the parser context information, switch the current stack back to the original stack space, set the interrupted instruction as a single - step flag, and execute the original instruction step - by - step.

[0095] After the original instruction is executed step by step, the current central processing unit automatically enters the single-step debugging exception interrupt phase.

[0096] In the single-step debugging exception interrupt phase, the global resolver table is searched through the address of the interrupt priority register of the central processing unit to determine the current resolver.

[0097] Through the current resolver registration information, the corresponding underlying kernel debugging tool structure is obtained, and through the kernel debugging tool structure, the instrumentation address of the kernel debugging tool is obtained.

[0098] According to the instrumentation address of the kernel debugging tool, a new IP register address is obtained, and the IP register is made to point to the new IP register address, so that the single-step exception interrupt handling ends and the original execution thread is returned.

[0099] In this alternative embodiment, calling the end processing function to end the current resolver process includes:

[0100] After the processing function of the resolver is executed, the end processing function is called, and the information that the processing function of the resolver has been executed is sent to the operating system kernel; after completing the preset work, the current resolver process ends.

[0101] In this alternative embodiment, the preset work includes:

[0102] The value of the current stack pointer is obtained through inline assembly.

[0103] According to the resolver context information, the registers and stack of the central processing unit are restored, and after the resolver monitoring function is executed, the correct return to the caller is made.

[0104] A return value is set for the base register; the temporary stack is released.

[0105] Figure 2 An embodiment of a system for implementing trusted static measurement element acquisition control according to the present invention is shown.

[0106] In this alternative embodiment, the system for implementing trusted static measurement element acquisition control includes:

[0107] A third-party tool construction module 201, configured to obtain a third-party resolver by optimizing the resolver; register the third-party resolver into the trusted software base proxy module, and determine the monitored kernel function and the custom processing function; load the trusted software base proxy module into the kernel of the operating system, and activate the third-party resolver;

[0108] The measurement element collection module 203 is used to trigger a third-party parser and call the custom processing function of the agent in the trusted software base agent module when the kernel of the operating system executes the monitored kernel function; collect the trusted static measurement elements of the operating system process by using the called custom processing function;

[0109] The process control module 205 is used to send the collected trusted static measurement elements to the measurement engine of the trusted software base, and control the processes of the operating system according to the comparison result between the reference value calculated by the measurement engine and the reference value in the reference library, and in combination with the trusted software base agent control mechanism.

[0110] To facilitate the understanding of the above technical solution of the present invention, the above technical solution of the present invention will be further described from the perspectives of architecture and principle as follows:

[0111] LSM (Linux Security Modules) is a loadable framework of the Linux kernel. It provides a general interface that allows security policies to be modularly integrated into the kernel. LSM enables administrators and developers to flexibly enhance the security of the Linux system without making a large number of modifications to the kernel code. LSM defines a series of security-related hooks that are called at key security decision points, such as file access, process creation, network communication, etc. The TSB agent can register its own processing functions to these hooks to implement security checks and controls at these key points.

[0112] First-party JProbe: The version natively supported in the operating system. It is a tool for dynamic tracking and analysis of the Linux kernel. It allows users to dynamically insert or remove trace points (probes) to monitor the behavior of the kernel without modifying the kernel source code. Jprobe is implemented based on the kernel's kprobes framework. Kprobes is a kernel debugging tool provided by Linux. It allows breakpoints to be set while the kernel is running to capture the execution flow at a specific code location. The kernel has had a built-in probe system called KProbe since a long time ago. Since the work of debugging the kernel is complex and difficult, the original intention of establishing this probe system is to provide a general detection mechanism before / after the execution of any kernel function (almost any, with only a few restrictions) to view the CPU register status and stack content. Obviously, this mechanism is not only used for kernel debugging, but also can be used for hotpatching of kernel functions. Due to its powerful enough capabilities and flexibility, the earlier version of the kernel implemented another more user-friendly probe environment that is close to human attention, called JProbe. Jprobe can be used to parse the actual parameters of kernel function operation, which is more realistic for observing the operation of kernel functions. This type of Jprobe that is natively supported by an earlier version of the kernel is called a first-party Jprobe. First-party Jprobe is built on the basis of Kprobe, and implements the function redirection function by modifying the CPU's IP register during Kprobe. JProbe was once part of the Kprobe system. The Linux kernel stopped supporting JProbe from version 4 and gradually removed it. KProbe has been retained to this day. KProbe is designed not to hide the core members of its underlying data structure from the outside, which makes third-party support for JProbe possible.

[0113] TPCM: Trusted Platform Control Module; TSB: Trusted Software Base; TCM: Trusted Cryptographic Module; LSM: Linux Security Module; Hook: Hook function, a function pointer pre-buried on a specific execution path, in order to be triggered at a specific time in a specific scenario; JProbe: A special probe system that can obtain the parameters of the probed function and modify the kernel execution path; KProbe: A general probe mechanism used by the Linux kernel; SP register: Stack pointer register; EX register: A general 16-bit data register.

[0114] Autonomous Trusted Computing: Autonomous trusted computing refers to a completely autonomous trusted computing technology, which is a secure and trusted foundation for network security. Specifically, autonomous trusted computing is a technology that ensures the predictability of information systems. It involves performing security protection during computing to ensure that the calculation results are always the same as the expected values, and that the entire computing process is measurable, controllable, and not interfered with.

[0115] TSB: It consists of multiple functional modules, including the basic trust base, control mechanism, measurement mechanism, decision-making mechanism, trusted reference library, and support mechanism, etc. As part of the dual-system architecture, together with TPCM, TSB forms a parallel structure of computing components and protection components, realizing the trusted monitoring of the working processes of general computing system hardware, operating systems, and application programs.

[0116] TSB Agent: The trusted software base agent, deployed in the operating system, is responsible as a third party for obtaining the code and data related to the preset protection objects from the operating system of the computing component. These data include but are not limited to system startup files, operating system kernels, initial file systems (initramfs), executable files, etc., and send the collected elements to TSB to ensure trusted measurement during the system startup and running phases.

[0117] Third-party Jprobe: The upgraded Jprobe.

[0118] Reentry: When the entire process of Jprobe has not ended, the Jprobe process is nested and executed due to hitting a breakpoint again.

[0119] In the present invention, the TSB agent adopts the third-party Jprobe mechanism to implement the collection of trusted measurement elements. The third-party Jprobe mechanism provides a method for dynamically inserting trace points without relying on the kernel symbol table, which is a means to solve the LSM adaptation problem. The third-party Jprobe allows dynamically inserting or removing trace points without recompiling the kernel to monitor and analyze kernel behavior. The following is a detailed description of its principle and process.

[0120] Principle:

[0121] 1. Dynamic tracing: The third-party Jprobe allows dynamically inserting and removing monitoring points without restarting the system. These monitoring points can be placed at the entry or exit points of kernel functions. First, determine the monitoring points, define the kernel functions to be monitored and the processing functions to be executed when these functions are called. Compile the Jpobe kernel module using the kernel build system. When the system starts, the Jprobe kernel module is automatically loaded. After the module is loaded, it automatically starts monitoring the specified kernel functions. If it is necessary to stop monitoring, the Jprobe module can be unloaded to remove the monitoring points.

[0122] 2. Function Interception: By setting third-party Jprobes at the entry and exit of critical kernel functions, that is, adding the logic for collecting elements required by the TSB agent and logging in the entry function, and adding the logic for logging the execution results of the elements in the exit function. Therefore, the TSB agent can intercept the execution of these functions and perform custom security checks.

[0123] 3. Event Handling: When the kernel executes to the third-party Jprobe monitoring point, the handling functions registered by the TSB agent will be called, and these handling functions can perform operations such as security checks and logging.

[0124] 4. No Symbol Table Required: The third-party Jprobe does not depend on the kernel symbol table, so it can be used in systems where the kernel symbol table is not exported, which helps to solve the problem that the symbol table is not exported in high-version operating systems.

[0125] 5. Flexibility and Scalability: The TSB agent can flexibly add or remove third-party Jprobes to adapt to different security requirements and monitoring strategies.

[0126] Process:

[0127] 1. Determine Monitoring Points: Determine the kernel functions to be monitored, and these functions may be security-sensitive operations such as file access and network communication.

[0128] 2. Write Handling Functions: Write custom handling functions that will be executed when the third-party Jprobe is triggered. These handling functions will contain security check logic.

[0129] 3. Register the Third-Party Jprobe: Register the Jprobe in the TSB agent module, specifying the address of the kernel function to be monitored and the custom handling function.

[0130] 4. Load the TSB Agent Module: Load the TSB agent module into the kernel, and the third-party Jprobe will be activated.

[0131] 5. The Kernel Executes the Monitoring Function: When the kernel executes to the monitored function, the third-party Jprobe is triggered.

[0132] 6. Execute the TSB Agent Handling Function: The handling function of the TSB agent is called to perform operations such as security checks and logging.

[0133] 7. Decision and Response: Based on the check results of the handling function, the TSB agent can decide whether to allow the operation to continue or take other security response measures.

[0134] 8. Logging and Auditing: The TSB agent can record security-related events for post-event auditing and analysis.

[0135] By leveraging a third - party Jprobe TSB proxy, dynamic monitoring and security control of the operating system can be achieved without relying on the kernel symbol table. The present invention provides a flexible and effective way to enhance system security, especially in operating system environments where the kernel symbol table is not exported for security reasons.

[0136] To make Jprobe applicable to the TSB proxy module and implement its functions, it is necessary to transform and optimize on the basis of the first - party Jprobe, mainly including the following two aspects.

[0137] I. Solve the re - entry problem

[0138] Since the first - party Jprobe and Kprobe are tightly coupled, its state information is stored in the global Kprobe control block. And this control block is exactly the root cause of possible re - entry of Kprobe. The Kprobe control block provides context information for the currently processed Jprobe. Jprobe needs this information to guide back to the trajectory before the execution of the Jprobe user function and also needs this information to restore the stack and CPU registers. To solve the problems of high coupling and re - entry simultaneously, the present invention passes context information through the stack. Therefore, how to safely use the stack and restore stack data afterwards is the core problem of the present invention.

[0139] The new design of the present invention simultaneously meets the following conditions: 1. Pass context information through the stack. 2. Do not damage the original stack data. 3. Be able to calculate the address where the context information is located through a definite method.

[0140] To meet the above conditions simultaneously, the third - party Jprobe will re - allocate the entire stack space and align the new stack to the boundary of the 16K address. In this way, it is always possible to simply obtain the new stack bottom address by masking the value of the SP register. And the context information is fixedly stored here. After introducing this scheme, three additional steps will be caused:

[0141] 1. At the beginning stage of the Jprobe process, allocate a new stack space and place the context information at the bottom of the stack.

[0142] 2. In the int3 exception interrupt context, the content of the original stack pointer register SP needs to be modified to dynamically switch the stack to the newly allocated space. Save the current stack pointer; set the stack pointer to the top of the newly allocated stack; clear the top of the new stack to ensure there is no garbage data; return to the handler and continue execution.

[0143] 3. After the Jprobe process ends, the newly allocated space needs to be released, otherwise it will cause memory leakage.

[0144] II. Solve the problem of being unable to control whether to continue executing the original function

[0145] 1. Need to return to the original execution thread

[0146] jprobe_return is a macro that is called in the return processing function (post_handler) of Jprob. The role of this macro is to handle specific operations on the return path after the monitoring function of Jprobe has finished executing. If you want to return to the original execution thread and continue executing the interrupted function, you need to call the jprobe_return function, which is a special function implemented for this purpose. This function obtains the value of the SP register through inline assembly code, then calculates the current stack bottom address based on this value, retrieves the Jprobe context information from this address, and determines whether it is safe to continue based on whether the context information can be successfully parsed. If everything goes smoothly, it will directly call the int3 interrupt through inline assembly, thus entering the int3 exception handling process again.

[0147] During the int3 exception handling process, it is still necessary to obtain the Jprobe context information through the value of the SP register, and at this stage, restore the original stack content and CPU register content. Since the CPU register contains the SP register, the current stack is also switched back to the original stack space at the same time. After that, set the single-step flag for the interrupted instruction and prepare to execute the original instruction step by step.

[0148] After the single-step execution is completed, the current CPU automatically enters the single-step debug exception interrupt. In the interrupt handling function, the global Jprobe table is searched through the address of the CPU's interrupt priority register (IP) to determine which Jprobe's processing process the current is in. After confirming the current Jprobe, obtain its underlying Kprobe structure through the Jprobe registration information, obtain the original Kprobe instrumentation address through the Kprobe structure, calculate the new IP register address through the following formula, and then set the IP register to point to this address, and the single-step exception interrupt handling ends.

[0149] Kprobe->addr + IP + kprobe->copied_ip – 1

[0150] Among them, Kprobe->addr is the starting address of the kernel function monitored by kprobe; IP is the address of the currently executing instruction; kprobe->copied_ip - 1 is the exact address of the kprobe breakpoint.

[0151] 2. Do not need to return to the original execution thread

[0152] If the user function determines that there is no need to return to the original execution thread, it is completed by the newly added special function jprobe_done. jprobe_done is used to indicate the end of a Jprobe processing. The jprobe_done macro is called after the execution of the Jprobe's processing function (jprobe->entry or jprobe->exit). The role of this macro is to tell the kernel that the Jprobe processing function has been executed and it is possible to resume the execution of the interrupted instruction. It needs to complete the following 4 tasks to end the current Jprobe processing and return to the caller of the original interrupted function.

[0153] 1. Obtain the value of the current stack pointer (SP) through inline assembly.

[0154] 2. Calculate the Jprobe context information and use the content saved in this context information to restore the values of the original stack and CPU registers. Jprobe captures the current CPU registers and stack information at the entry (pre_handler) of the monitored function and saves them in a context structure. At the exit (post_handler) of the monitored function, Jprobe uses the saved context information to restore the CPU registers and stack, ensuring that the function can correctly return to the caller after execution. This process allows Jprobe to monitor the function execution without affecting the original behavior of the function and system stability.

[0155] 3. Set the return value for the base register (BX) to pass the data returned by the user function.

[0156] 4. Release the temporary stack.

[0157] This function uses assembly code to complete most of the work, especially modifying the stack frame and directly returning to the original caller. Regardless of the value returned by the user function, the original interrupted function will not be called, thus implementing the TSB proxy control function.

[0158] The technical problems solved by the present invention include:

[0159] 1. To be applicable to the TSB proxy and implement the functions of collecting and controlling trusted measurement elements, the present invention optimizes the first-party Jprobe: (1) Solves the problem that the first-party Jprobe cannot determine whether to continue executing the original function. (2) Solves the problem that the first-party Jprobe is not reentrant.

[0160] 2. Reduce the dependence on the kernel version, solve the compatibility problem of the TSB proxy in multiple operating systems, and improve the technical application scope.

[0161] In addition, in the drawings of the present invention, Figure 4The first-party Jprobe workflow in

[0162] Hit the Kprobe probe point - call the Jprobe framework function to prepare the environment for executing the replacement function - save the content of the original SP register to the context information block - back up the last 64 bytes of the original stack content to the context information block - modify the IP register to point to the user-defined Jprobe replacement function - return 1 to inform Kprobe that the content of the IP register has changed - Kprobe holds the point and ends the current exception handling - the user Jprobe replacement function starts to execute on the original stack - call the Jprobe_return function to return to the original execution thread - the Jprobe_return function calls the int3 interrupt - re-enter the breakpoint exception handling process - determine whether the exception is caused by Jprobe_return based on the memory range where the value of the IP register is located - restore all CPU registers, including the SP register, and restore the stack address to the state before the replacement function is executed - restore the last 64 bytes of the original stack from the Kprobe global variable - set the single-step execution flag for the first instruction of the original probe function and end the breakpoint exception handling - Kprobe executes the original probe function as normal - Kprobe resets the global variable, releases the occupied flag, and can handle the next Kprobe - the execution trace returns to the original probe function.

[0163] Figures 5 - 7 The third-party Jprobe workflow in

[0164] Hit the Kprobe probe point - call the Jprobe framework function to prepare the environment for executing the replacement function - calculate the stack size required for the current context environment - allocate stack space - align the stack space to the 32K boundary - install the context information block at the bottom of the new stack space - add a magic identifier to the context - copy the original stack information to the newly allocated stack space - save the content of the original SP register to the context information block - modify the SP register to point to the top of the new stack - modify the IP register to point to the user-defined Jprobe replacement function - return 1 to inform Kprobe that the content of the IP register has changed - Kprobe ends the exception handling process in advance and resets the current CPU's current_kprobe global variable - the user Jprobe replacement function starts to run on the new stack space - after the replacement function is executed, determine whether the original probe function needs to be executed.

[0165] If it is necessary to execute the original probe function, call the jprobe_return function to return to the original execution thread - the jprobe_return function calls the int3 interrupt - re-enters the breakpoint exception handling process - performs a bitwise AND operation on the value of SP in the CPU register snapshot and the result of taking the one's complement of (32K - 1) to obtain the stack address, and obtains the address of the context information based on this address - restores all CPU registers, including the SP register, switches back to the original stack space - releases the temporary stack space - sets the single-step execution flag for the first instruction of the original probe function and ends the breakpoint exception handling - Kprobe normally executes the original probe function - the execution trace returns to the original probe function.

[0166] If it is not necessary to execute the original probe function, call the Jprobe_done function to end the current Jprobe process - perform a bitwise AND operation on the value of SP in the CPU register snapshot and the result of taking the one's complement of (32K - 1) to obtain the stack address, and obtain the address of the context information based on this address - save the return value passed by the user replacement function in the AX register (x86 ABI) - if there is a backup in the context information block, restore the original stack content - restore the content of the SP register from the saved value in the context, and at this time the stack frame switches to the calling function of the function being probed - restore the other registers saved by the called function as specified by the ABI - release the temporary stack space - return as a normal function, and the original probe function will not be executed.

[0167] Figure 5 Segment ① of Figure 6 is connected to Figure 6 Segment ② and segment ③ in Figure 7 are respectively connected to segment ② and segment ③ in

[0168] The present invention provides a method for collecting and controlling trusted measurement elements based on the third-party Jprobe technology, including:

[0169] Using the third-party Jprobe technology to implement system calls of the trusted software base (TSB) agent to achieve the collection of measurement elements of processes; intercepting system call behaviors through the third-party Jprobe technology and sending the intercepted main / object information elements to the measurement engine of the TSB; the measurement engine calls specific measurement operations, calculates the reference value, and compares it with the reference value in the reference library; returns the measurement result to the TSB agent control mechanism to achieve the control of processes.

[0170] The present invention provides a method for solving the non-reentrant problem of Jprobe, including:

[0171] Calculate the stack size required for the current context environment, and dynamically allocate temporary stack space for each instance to solve the problem of non-reentrant Jprobe; install the context information block at the bottom of the new stack space; copy the original stack information to the newly allocated stack space; save the content of the original SP register to the context information block; modify the SP register to point to the top of the new stack to switch the stack.

[0172] The present invention provides a method for preventing an interrupted function from resuming execution, including:

[0173] Define a special function jprobe_done, which triggers a breakpoint exception by calling the int3 soft interrupt (to enhance compatibility with kernel versions, third-party Jprobes are also compatible with int3 and int1 breakpoint exceptions); obtain the address of the bottom of the stack based on the value of the stack pointer (SP) in the CPU register snapshot, and thus obtain the address of the context information; save the return value passed by the user replacement function in the AX register (in a 64-bit system, the AX register is used to store and pass the function return value); restore the stack content; restore the content of the stack pointer (SP) register from the saved value of the context, and at this time the stack frame is switched to the calling function of the probed function; restore all registers saved by the called function required by the Application Binary Interface (ABI); release the temporary stack space; after releasing the temporary stack space, call return to return to the parent function (the function that originally called the probed function and caused the Kprobe to hit), so as to directly return from the user replacement function to the parent function without executing the original probed function.

[0174] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 3 shown. The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store static information and dynamic information data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.

[0175] Those skilled in the art can understand that Figure 3The structure shown is only a block diagram of some structures related to the solution of the present invention, and does not constitute a limitation on the computer device to which the solution of the present invention is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.

[0176] In addition, the present invention also provides a computer device, including a memory and a processor. A computer program is stored in the memory, and when the processor executes the computer program, the steps in the above method embodiments are implemented.

[0177] Furthermore, the present invention also provides a computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above method embodiments are implemented.

[0178] Those of ordinary skill in the art can understand that all or part of the processes in the above method embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the above method embodiments. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided by the present invention can include at least one of non-volatile and volatile memories. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc.

[0179] The present invention is not limited to the structures already described and shown in the drawings, and various modifications and changes can be made without departing from its scope. The scope of the present invention is only limited by the appended claims.

Claims

1. A method for realizing the collection and control of trusted static measurement elements, characterized in that: The method includes: By optimizing the parser, a third-party parser is obtained; the third-party parser is registered in the trusted software base agent module, and the monitored kernel function and the custom processing function are determined; the trusted software base agent module is loaded into the kernel of the operating system, and the third-party parser is activated; The third-party parser obtained by optimizing the parser includes: Utilize the stack to pass context information to optimize the parser for reentrancy issues; Optimize the parser to prevent it from being able to control whether it needs to return to the original execution thread; The mechanism of using the stack to transfer context information to optimize the parser with respect to the reentrancy problem includes: At the beginning of the parser process, new stack space is allocated and the context information is placed at the bottom of the new stack space; When an exception occurs, the original stack is dynamically switched to the new stack space by modifying the content of the original stack pointer register; After the parser process ends, the new stack space is released; When the kernel of the operating system executes the monitored kernel function, the third-party parser is triggered, and the custom processing function of the agent in the trusted software base agent module is called; the trusted static measurement elements of the operating system process are collected by using the called custom processing function; The collected trusted static measurement elements are sent to the measurement engine of the trusted software base. According to the comparison results between the benchmark values ​​calculated by the measurement engine and the benchmark values ​​in the benchmark library, and combined with the trusted software base agent control mechanism, the operating system process is controlled.

2. A method for realizing collection and control of trusted static measurement elements according to claim 1, characterized in that: When an abnormal interrupt occurs, dynamically switching the original stack to a new stack space by modifying the content of the original stack pointer register comprises: Set the original stack pointer to the top of the new stack space and clean up the top of the new stack space; return to the handler and continue execution.

3. The method for realizing the collection and control of trusted static measurement elements according to claim 1, characterized in that: The optimization of the problem that the parser cannot control whether it needs to return to the original execution thread further includes: According to the user function, determine whether the parser needs to return to the original execution thread; When it is necessary to return to the original execution thread, the return processing function is called to return to the original execution thread; When there is no need to return to the original execution thread, the end processing function is called to end the current parser process.

4. A method for realizing collection and control of trusted static measurement elements according to claim 3, characterized in that: When it is necessary to return to the original execution thread, calling the return processing function to return to the original execution thread includes: Use the return processing function and inline assembly code to get the value of the register; according to the value of the register, get the current stack bottom address, and fetch the parser context information from the current stack bottom address; The inline assembly is used to call the breakpoint interrupt and enter the exception handling process. During the exception handling process, the current stack is switched back to the original stack space according to the parser context information, and the interrupted instruction is set as the single-step flag, and the original instruction is executed in a single-step manner. After the single-step execution of the original instruction is completed, the current CPU automatically enters the single-step debugging exception interrupt stage; In the single-step debugging abnormal interrupt stage, the global parser table is searched through the address of the interrupt priority register of the central processing unit to determine the current parser; The corresponding underlying kernel debugging tool structure is obtained through the current parser registration information, and the kernel debugging tool plug-in address is obtained through the kernel debugging tool structure; According to the stub address of the kernel debugging tool, a new IP register address is obtained, and the IP register is made to point to the new IP register address, so that the single-step exception interrupt processing ends and returns to the original execution thread.

5. The method for realizing the collection and control of trusted static measurement elements according to claim 3, characterized in that: The calling end processing function to end the current parser process includes: After the parser processing function is executed, the end processing function is called, and the parser processing function execution completion information is sent to the operating system kernel; after completing the preset work, the current parser process is ended.

6. A method for realizing collection and control of trusted static measurement elements according to claim 5, characterized in that: The pre-set tasks include: Get the current stack pointer value through inline assembly; According to the parser context information, the CPU registers and stack are restored, and the parser monitor function is executed and correctly returns to the caller; Set the return value to the base register; free the temporary stack.

7. A system for realizing the collection and control of trusted static measurement elements, characterized in that: The system includes: A third-party tool building module is used to obtain a third-party parser by optimizing the parser; register the third-party parser into the trusted software base agent module, and determine the monitored kernel function and the custom processing function; load the trusted software base agent module into the kernel of the operating system, and activate the third-party parser; The third-party parser obtained by optimizing the parser includes: Utilize the stack to pass context information to optimize the parser for reentrancy issues; Optimize the parser to prevent it from being able to control whether it needs to return to the original execution thread; The mechanism of using the stack to transfer context information to optimize the parser with respect to the reentrancy problem includes: At the beginning of the parser process, new stack space is allocated and the context information is placed at the bottom of the new stack space; When an exception occurs, the original stack is dynamically switched to the new stack space by modifying the content of the original stack pointer register; After the parser process ends, the new stack space is released; The measurement element collection module is used to trigger the third-party parser when the kernel of the operating system executes the monitored kernel function, and call the custom processing function of the agent in the trusted software base agent module; collect the trusted static measurement elements of the operating system process by using the called custom processing function; The process control module is used to send the collected trusted static measurement elements to the measurement engine of the trusted software base, and control the process of the operating system based on the comparison results of the benchmark values ​​calculated by the measurement engine and the benchmark values ​​in the benchmark library, combined with the trusted software base agent control mechanism.

8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.

Citation Information

Patent Citations

  • Dynamic measuring method based on dependable computing and management system

    CN103577748A

  • Dynamic trusted measurement implementation method, device and equipment, medium and trusted system

    CN118484813A