Information System Measurement Processing Method, Apparatus, Server, and Medium
By creating a trusted execution environment in a computer environment, the metric client application requests the metric configuration file to the metric trusted application and generates a metric verification request, the problem of reduced accuracy of metric results is solved and higher metric results are achieved.
Patent Information
- Application Number
- CN202510222704.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-06-03
- Estimated Expiration
- 2045-02-27
AI Technical Summary
In the prior art, the process of measuring configuration files and computing system data is easily attacked, resulting in a decrease in the accuracy of the measurement results.
By dividing the computer environment into a trusted execution environment and a non-trusted execution environment, the metric client application obtains the metric configuration file from the metric trusted application request, collects memory data based on the metric configuration file and generates a metric verification request. By metric trusted application verifies the metric value in the metric verification request in the trusted execution environment, compares it with the benchmark value, and generates the metric verification result.
In a trusted execution environment, the operation of calculating the metric value and comparing the benchmark value is performed through the metric trusted application, avoiding the process of calculating and comparing the benchmark value being attacked, and improving the accuracy of the metric results.
Smart Images

Figure CN119720178B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technologies, and in particular, to a method, apparatus, server, and medium for information system measurement processing. Background Art
[0002] With the development of the information industry, software running in information systems inevitably has vulnerabilities. Once software vulnerabilities are exploited by attackers, the business functions of the system will be affected. Dynamic measurement is a method for detecting attack behaviors. By dynamically monitoring the running state and system parameters of the system in real time, comparing the measurement values with the benchmark values to detect attack behaviors.
[0003] In the current related technologies, system data to be measured is obtained through a measurement configuration file, the system data to be measured is calculated, compared with the benchmark value to obtain a measurement result, and the measurement result is written into the trusted platform module. However, in the related technologies, the measurement configuration file and the process of calculating system data are vulnerable to attacks, resulting in a decrease in the accuracy rate of the measurement result. Summary of the Invention
[0004] The present application provides a method, apparatus, server, and medium for information system measurement processing to at least solve the problem of the decrease in the accuracy rate of the measurement result in the related technologies.
[0005] The present application provides a method for information system measurement processing, which is applied to measuring trusted applications and includes:
[0006] Receiving a request for obtaining a measurement configuration file sent by an operating system of a trusted execution environment;
[0007] Generating a retrieval instruction according to the request for obtaining the measurement configuration file;
[0008] Sending the retrieval instruction to the operating system of the trusted execution environment so that the operating system of the trusted execution environment obtains an encrypted measurement configuration file according to the retrieval instruction and decrypts the encrypted measurement configuration file to obtain the measurement configuration file;
[0009] Receiving the measurement configuration file sent by the operating system of the trusted execution environment;
[0010] Storing the measurement configuration file and generating a first shared storage address according to the measurement configuration file;
[0011] Send the first shared storage address to the trusted execution environment operating system, so that the trusted execution environment operating system sends the first shared storage address to the firmware layer. The first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to an untrusted execution environment, and send the first shared storage address to the trusted execution environment driver. The first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application. The first shared storage address is used to instruct the measurement client application to obtain a measurement configuration file according to the first shared storage address, and generate a measurement verification request according to the measurement configuration file;
[0012] Receive the measurement verification request sent by the measurement client application;
[0013] Generate a measurement result according to the measurement verification request;
[0014] Send the measurement result to the measurement client application, so that the measurement client application generates a measurement log according to the measurement result.
[0015] This application also provides an information system measurement processing device, which is applied to measure trusted applications and includes:
[0016] A first receiving module, configured to receive a request for obtaining a measurement configuration file sent by the trusted execution environment operating system;
[0017] A first generating module, configured to generate a retrieval instruction according to the request for obtaining the measurement configuration file;
[0018] A first sending module, configured to send the retrieval instruction to the trusted execution environment operating system, so that the trusted execution environment operating system obtains an encrypted measurement configuration file according to the retrieval instruction, and decrypts the encrypted measurement configuration file to obtain a measurement configuration file;
[0019] A second receiving module, configured to receive the measurement configuration file sent by the trusted execution environment operating system;
[0020] A storage module, configured to store the measurement configuration file, and generate a first shared storage address according to the measurement configuration file;
[0021] A second sending module, configured to send the first shared storage address to the trusted execution environment operating system, so that the trusted execution environment operating system sends the first shared storage address to the firmware layer. The first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to a non-trusted execution environment, and send the first shared storage address to the trusted execution environment driver. The first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application. The first shared storage address is used to instruct the measurement client application to obtain a measurement configuration file according to the first shared storage address, and generate a measurement verification request according to the measurement configuration file;
[0022] A third receiving module, configured to receive the measurement verification request sent by the measurement client application;
[0023] A second generating module, configured to generate a measurement result according to the measurement verification request;
[0024] A third sending module, configured to send the measurement result to the measurement client application, so that the measurement client application generates a measurement log according to the measurement result.
[0025] This application further provides a server, including: a memory, configured to store a computer program; a processor, configured to implement the steps of any one of the above information system measurement processing methods when executing the computer program.
[0026] This application further provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any one of the above information system measurement processing methods are implemented.
[0027] This application further provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any one of the above information system measurement processing methods are implemented.
[0028] Through this application, the execution environment of the software is divided into a trusted execution environment and a non-trusted execution environment. The measurement client application requests to obtain a measurement configuration file from the measurement trusted application, collects memory data according to the measurement configuration file, and generates a measurement verification request. The measurement trusted application verifies the measurement value in the measurement verification request in the trusted execution environment, compares it with the reference value, generates a measurement verification result, and sends the measurement verification result to the measurement client application. The measurement client application generates a measurement log. Compared with the prior art, a trusted execution environment is created, and in the trusted execution environment, the measurement trusted application executes operations to calculate the measurement value and compare the reference value, avoiding the process of calculating and comparing the reference value from being attacked, and improving the accuracy of the measurement result. Description of the Drawings
[0029] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required for use in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0030] Figure 1 Schematic diagram of the application scenario of the information system measurement processing method provided by the embodiments of the present application;
[0031] Figure 2 Flow chart of the information system measurement processing method provided by the embodiments of the present application Figure 1 ;
[0032] Figure 3 Flow chart of the information system measurement processing method provided by the embodiments of the present application Figure 2 ;
[0033] Figure 4 System structure diagram of dynamic measurement provided by the embodiments of the present application;
[0034] Figure 5 Flow chart of the information system measurement processing method provided by the embodiments of the present application Figure 3 ;
[0035] Figure 6 Schematic diagram of the interaction process of the information system measurement processing method provided by an embodiment of the present application;
[0036] Figure 7 Schematic diagram of the interaction process of the information system measurement processing method provided by another embodiment of the present application;
[0037] Figure 8 Schematic diagram of the structure of the information system measurement processing device provided by the embodiments of the present application;
[0038] Figure 9 Schematic diagram of the structure of the server provided by the present application. Detailed implementation manners
[0039] The following will clearly and completely describe the technical solutions in the embodiments of the present application in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present application.
[0040] It should be noted that in the description of this application, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0041] First, the nouns involved in this application are explained:
[0042] Measured trusted application: measureTA (measure Trusted Application), running in the trusted execution environment, calculating the measured value, and interacting with the operating system of the trusted execution environment.
[0043] Trusted execution environment operating system: TEEOS (Trusted execution environment Operating System), a security mechanism built in a computing system, creating a secure environment through hardware technology to ensure the security of the code and data running therein and prevent attackers from accessing or tampering with them.
[0044] Measured client application: measureCA (measure Client Application), running in the non-trusted execution environment, obtaining the data to be measured in the memory.
[0045] Firmware layer: Firmware / security monitor layer, performing the switching between the trusted execution environment and the non-trusted execution environment through SMC (Secure Monitor Call) instructions.
[0046] Trusted execution environment driver: TEEDriver (Trusted execution environment Driver), the TEE driver in the system, switching the running environment of the program through the firmware layer.
[0047] Firmware trusted platform module: fTPM (firmware Trusted Platform Module), a hardware-level encryption and security function module, used to protect the system startup process and prevent unauthorized access and tampering.
[0048] To solve the problem of the reduced accuracy of measurement results in the prior art, the embodiments of the present application propose the following technical concept: The inventor considered dividing the computer environment into two sides: the untrusted execution environment side and the trusted execution environment side. Deploy a measurement client application and a trusted execution environment driver on the untrusted execution environment side, and deploy a measurement trusted application, a trusted execution environment operating system, and a firmware trusted platform module on the trusted execution environment side. The switching between the trusted execution environment and the untrusted execution environment is realized through the firmware layer. Considering obtaining a measurement configuration file from the measurement trusted application through the measurement client application, the measurement configuration file is encrypted and stored in the trusted execution environment operating system, and the measurement configuration file is decrypted by the trusted execution environment operating system. Considering storing the measurement configuration file in a shared storage address by the measurement trusted application, the measurement client application obtains the data content to be collected by accessing the shared storage address, and collects the corresponding data to be measured according to the data content to be collected, generates a measurement verification request based on the data to be measured, the firmware layer converts the computing environment into a trusted execution environment, calculates a measurement value through the measurement trusted application, generates a measurement result, and returns the measurement result to the measurement client application to generate a measurement log. Compared with the prior art, the operations of calculating the measurement value and comparing the reference value are performed through the measurement trusted application in the trusted execution environment, avoiding the process of calculating and comparing the reference value from being attacked, and improving the accuracy of the measurement result.
[0049] To enable those skilled in the art of the present technology to better understand the solution of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0050] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the information system measurement processing method depends, the specific application environment architecture or specific hardware architecture will be described herein. Refer to Figure 1 , Figure 1 which is a schematic diagram of the application scenario of the information system measurement processing method provided by the embodiments of the present application.
[0051] As Figure 1 shown, this scenario includes: a measurement client application 101, a trusted execution environment driver 102, a firmware layer 103, a trusted execution environment operating system 104, and a measurement trusted application 105.
[0052] Among them, the measurement client application 101 and the trusted execution environment driver 102 are located in the untrusted execution environment, and the trusted execution environment operating system 104 and the measurement trusted application 105 are located in the trusted execution environment.
[0053] Specifically, the measurement client application 101 sends a request for obtaining a measurement configuration file to the trusted execution environment driver 102. The trusted execution environment driver 102 sends the request for obtaining the measurement configuration file to the firmware layer 103. The firmware layer 103 switches the non-trusted execution environment to the trusted execution environment and sends the request for obtaining the measurement configuration file to the trusted execution environment operating system 104. The trusted execution environment operating system 104 verifies the permissions of the measurement client application 101. If the verification passes, it sends the request for obtaining the measurement configuration file to the measurement trusted application 105. The measurement trusted application 105 generates a retrieval instruction and sends the retrieval instruction to the trusted execution environment operating system 104. The trusted execution environment operating system 104 obtains the encrypted measurement configuration file according to the retrieval instruction, decrypts it to obtain the measurement configuration file, and sends the measurement configuration file to the measurement trusted application 105. The measurement trusted application 105 stores the measurement configuration file and generates a first shared storage address, and sends the first shared storage address to the measurement client application 101 through the firmware layer 103 and the trusted execution environment driver 102 in sequence. The measurement client application 101 obtains the data to be measured according to the measurement configuration file, generates a measurement verification request, and sends the measurement verification request to the measurement trusted application 105. The measurement trusted application 105 generates a measurement result according to the measurement verification request and sends the measurement result to the measurement client application 101. The measurement client application 101 generates a measurement log according to the measurement result.
[0054] Figure 2 Schematic flow of the information system measurement processing method provided by the embodiments of the present application Figure 1 In this embodiment, the execution subject can be the measurement trusted application, and no special limitation is made here in this embodiment. As Figure 2 shown, the method includes:
[0055] S201: Receive a request for obtaining a measurement configuration file sent by the trusted execution environment operating system.
[0056] In this embodiment, the request for obtaining the measurement configuration file is generated by the measurement client application, and the measurement client application sends the request for obtaining the measurement configuration file to the trusted execution environment driver.
[0057] In this embodiment, the trusted execution environment driver generates an SMC request according to the request for obtaining the measurement configuration file and sends the SMC request recording the request for obtaining the measurement configuration file to the firmware layer.
[0058] In this embodiment, after receiving the SMC request, the firmware layer triggers an instruction, switches the non-trusted execution environment to the trusted execution environment, and at the same time sends the request for obtaining the measurement configuration file to the trusted execution environment operating system.
[0059] Specifically, the trusted execution environment operating system verifies the measurement client application according to the request for obtaining the measurement configuration file, and verifies whether the measurement client application has the permission to call the measurement trusted application in the trusted execution environment operating system.
[0060] Among them, if the verification passes, the trusted execution environment operating system sends the request for obtaining the measurement configuration file to the measurement trusted application.
[0061] Specifically, the request for obtaining the measurement configuration file sent by the trusted execution environment operating system is received through wireless communication.
[0062] S202: Generate a retrieval instruction according to the request for obtaining the measurement configuration file.
[0063] In this embodiment, the measurement trusted application includes a measurement module and a storage module.
[0064] Specifically, the storage module in the measurement trusted application generates a retrieval instruction and calls the secure storage function in the trusted execution environment operating system.
[0065] S203: Send the retrieval instruction to the trusted execution environment operating system, so that the trusted execution environment operating system obtains the encrypted measurement configuration file according to the retrieval instruction, and decrypts the encrypted measurement configuration file to obtain the measurement configuration file.
[0066] In this embodiment, the trusted execution environment operating system includes a secure storage module and an encryption / decryption module.
[0067] Specifically, the trusted execution environment operating system retrieves the encrypted measurement configuration file in the secure storage module according to the retrieval instruction, and decrypts the encrypted measurement configuration file through the encryption / decryption module to obtain the measurement configuration file.
[0068] Among them, the algorithms for encryption and decryption by the encryption / decryption module include, but are not limited to, symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms.
[0069] S204: Receive the measurement configuration file sent by the trusted execution environment operating system.
[0070] Specifically, the measurement configuration file sent by the trusted execution environment operating system is received through wireless communication.
[0071] S205: Store the measurement configuration file and generate a first shared storage address according to the measurement configuration file.
[0072] Specifically, the measurement configuration file is saved to the shared memory, and a first shared storage address is generated.
[0073] Among them, the first shared storage address includes the address information and data length of the shared memory.
[0074] S206: Send the first shared storage address to the trusted execution environment operating system, so that the trusted execution environment operating system sends the first shared storage address to the firmware layer. The first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to an untrusted execution environment, and send the first shared storage address to the trusted execution environment driver. The first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application. The first shared storage address is used to instruct the measurement client application to obtain a measurement configuration file according to the first shared storage address and generate a measurement verification request according to the measurement configuration file.
[0075] Specifically, the measurement trusted application sends the first shared storage address to the trusted execution environment operating system. The trusted execution environment operating system combines the SMC instruction according to the driver program, writes the first shared storage address into the SMC instruction, and sends the SMC instruction to the firmware layer. After receiving the SMC instruction, the firmware layer switches the execution environment from the trusted execution environment to the untrusted execution environment, and sends the SMC request to the trusted execution environment driver. The trusted execution environment driver sends the first shared storage address in the SMC instruction to the measurement client application.
[0076] Specifically, the measurement client application reads the measurement configuration file according to the first shared storage address, obtains the data to be measured according to the measurement configuration file, collects the virtual address of the data to be measured and the corresponding address length information, converts the virtual address into a physical address, and generates a measurement verification request according to the physical address.
[0077] Among them, the content recorded in the measurement configuration file includes but is not limited to the process name of the user process, the memory segment to be measured, the memory block to be measured by the kernel module, the system network configuration, the system call information, the cycle of data acquisition, and the behavior response information.
[0078] S207: Receive the measurement verification request sent by the measurement client application.
[0079] In this embodiment, the measurement verification request is generated by the measurement client application, and the measurement client application sends the measurement verification request to the trusted execution environment driver.
[0080] In this embodiment, the trusted execution environment driver generates an SMC request according to the measurement verification request, and sends the SMC request recording the measurement verification request to the firmware layer.
[0081] In this embodiment, after receiving the SMC request, the firmware layer triggers an instruction to switch the untrusted execution environment to the trusted execution environment, and at the same time sends the measurement verification request to the trusted execution environment operating system.
[0082] In this embodiment, the trusted execution environment operating system sends a measurement verification request to the measurement trusted application.
[0083] S208: Generate a measurement result according to the measurement verification request.
[0084] Specifically, obtain the physical address in the measurement verification request, map the physical address to obtain a virtual address, calculate the virtual address according to the measurement algorithm to obtain a measurement value, and send a reference value retrieval instruction to the trusted execution environment operating system to retrieve the corresponding reference value and compare it with the measurement value to generate a measurement result.
[0085] S209: Send the measurement result to the measurement client application so that the measurement client application generates a measurement log according to the measurement result.
[0086] In this embodiment, the measurement result includes a measurement reference value and a measurement value.
[0087] Specifically, the measurement trusted application sends the measurement result to the trusted execution environment operating system. The trusted execution environment operating system generates an SMC instruction according to the measurement result, sends the SMC instruction to the firmware layer. The firmware layer switches the execution environment from the trusted execution environment to the untrusted execution environment according to the SMC instruction, and sends the SMC instruction to the trusted execution environment driver. The trusted execution environment driver sends the measurement result in the SMC instruction to the measurement client application, and the measurement client application generates a measurement log according to the measurement result.
[0088] As can be seen from the above embodiments, by dividing the execution environment of the software into a trusted execution environment and an untrusted execution environment, the measurement client application requests to obtain a measurement configuration file from the measurement trusted application, collects memory data according to the measurement configuration file and generates a measurement verification request. The measurement trusted application verifies the measurement value in the measurement verification request in the trusted execution environment, compares it with the reference value, generates a measurement verification result, sends the measurement verification result to the measurement client application, and the measurement client application generates a measurement log. Compared with the prior art, a trusted execution environment is created, and in the trusted execution environment, the measurement trusted application is used to perform operations such as calculating the measurement value and comparing the reference value, avoiding the process of calculating and comparing the reference value from being attacked, and improving the accuracy of the measurement result.
[0089] In an embodiment of the present application, step S208 includes:
[0090] S2081: Obtain the physical address in the measurement verification request.
[0091] In this embodiment, the physical address includes physical address information and an address length.
[0092] S2082: Map the physical address to obtain a virtual address.
[0093] In this embodiment, the virtual address includes virtual address information and an address length.
[0094] S2083: Measure the virtual address according to a measurement algorithm to obtain a measurement value.
[0095] In this embodiment, the measurement algorithm includes, but is not limited to, the national cryptographic algorithm, the SHA256 algorithm, and the SHA512 algorithm.
[0096] S2084: Send a reference value retrieval request to the trusted execution environment operating system, so that the trusted execution environment operating system obtains the encrypted reference value according to the reference value retrieval request and decrypts the encrypted reference value to obtain the reference value.
[0097] Specifically, the trusted execution environment operating system retrieves the encrypted reference value in the secure storage module according to the reference value retrieval request, and decrypts the encrypted reference value through the encryption and decryption module to obtain the reference value.
[0098] Among them, the algorithms for encryption and decryption by the encryption and decryption module include, but are not limited to, symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms.
[0099] S2085: Receive the reference value sent by the trusted execution environment operating system.
[0100] Specifically, receive the reference value sent by the trusted execution environment operating system through wireless communication.
[0101] S2086: Generate a measurement result according to the reference value and the measurement value.
[0102] Specifically, compare the reference value and the measurement value. If the measurement value is the same as the reference value, the measurement result is that the system is secure; if the measurement value is different from the reference value, generate system operation information according to the measurement result.
[0103] Among them, the system operation information includes, but is not limited to, terminating a process, alarm information, system error information, and terminating system operation.
[0104] As can be seen from the above embodiments, by measuring the physical address in the measurement verification request obtained by the trusted application in the trusted execution environment, mapping the physical address to a virtual address, calculating the measurement value through the measurement algorithm, and comparing it with the reference value in the trusted execution environment operating system, a measurement result is obtained, improving the security of the measurement process.
[0105] In an embodiment of the present application, after step S209, it further includes:
[0106] S210: Receive the measurement update request sent by the trusted execution environment operating system.
[0107] In this embodiment, the measurement client application receives the edited measurement configuration file, verifies the measurement configuration file, and determines whether the edited data exists, whether corresponding tasks are generated according to the edited data, and whether the corresponding execution operation is configured for non-passing the measurement. If the verification fails, the operation of updating the measurement configuration file ends; if the verification passes, the data address to be measured is obtained according to the edited measurement configuration file, the data address is converted into a physical address, saved in the shared memory, and a measurement update request is generated. The shared memory address and the edited measurement configuration file are recorded in the measurement update request.
[0108] In this embodiment, the measurement client application sends the measurement update request to the trusted execution environment driver. The trusted execution environment driver generates an SMC request according to the measurement update request, and sends the SMC request recording the measurement update request to the firmware layer. After receiving the SMC request, the firmware layer triggers an instruction to switch the non-trusted execution environment to the trusted execution environment, and at the same time sends the measurement update request to the trusted execution environment operating system. The trusted execution environment operating system sends the measurement update request to the measurement trusted application.
[0109] S211: Update the measurement configuration file according to the measurement update request to generate an update result.
[0110] Specifically, obtain the shared memory address in the measurement update request, obtain the physical address in the shared memory address, map the physical address to the trusted execution environment operating system to obtain a virtual address, calculate and generate the edited reference value according to the virtual address, and send the edited reference value and the edited measurement configuration file to the trusted execution environment operating system. The trusted execution environment operating system generates an update result according to the edited reference value and the edited measurement configuration file, and sends the update result to the measurement trusted application.
[0111] S212: Send the update result to the measurement client application so that the measurement client application generates an update log according to the update result.
[0112] In this embodiment, the update result includes update success and update failure.
[0113] Specifically, the measurement trusted application sends the update result to the trusted execution environment operating system. The trusted execution environment operating system generates an SMC instruction according to the update result, sends the SMC instruction to the firmware layer. The firmware layer switches the execution environment from the trusted execution environment to the non-trusted execution environment according to the SMC instruction, and sends the SMC instruction to the trusted execution environment driver. The trusted execution environment driver sends the update result in the SMC instruction to the measurement client application. The measurement client application generates an update log according to the update result.
[0114] As can be seen from the above embodiments, by measuring and updating the measurement configuration file in the trusted execution environment according to the measurement update request, and sending the update result to the measurement client application, the measurement client application generates an update log based on the update result, avoiding the process of updating the measurement configuration file from being attacked and improving the security of updating the measurement configuration file.
[0115] In an embodiment of the present application, step S211 includes:
[0116] S111: Obtain the second shared storage address in the measurement update request.
[0117] In this embodiment, the second shared storage address is the shared memory address in the measurement update request.
[0118] S112: Obtain the edited measurement configuration file and the edited physical address according to the second shared storage address.
[0119] In this embodiment, the physical address includes physical address information and address length.
[0120] Specifically, the measurement module of the measurement trusted application obtains the physical address according to the shared memory address.
[0121] S113: Calculate and generate the edited reference value according to the edited physical address.
[0122] Specifically, map the edited physical address to the operating system of the trusted execution environment to obtain a virtual address, and calculate and generate the edited reference value according to the virtual address.
[0123] S114: Send the edited measurement configuration file and the edited reference value to the operating system of the trusted execution environment, so that the operating system of the trusted execution environment generates an update result according to the edited measurement configuration file and the edited reference value.
[0124] Specifically, the measurement trusted application sends the edited measurement configuration file and the edited reference value to the operating system of the trusted execution environment. The operating system of the trusted execution environment backs up the corresponding unedited measurement configuration file and reference value, generates a backup file, records the edited measurement configuration file and the edited reference value as the new measurement configuration file and reference value, and deletes the corresponding unedited measurement configuration file and reference value to generate an update result.
[0125] S115: Receive the update result sent by the operating system of the trusted execution environment.
[0126] Specifically, receive the update result sent by the operating system of the trusted execution environment through wireless communication.
[0127] As can be seen from the above embodiments, by obtaining the edited physical address, calculating the edited reference value, writing the edited reference value and the edited measurement profile into the trusted execution environment operating system, and storing the measurement profile and the reference value in the trusted execution environment operating system of the trusted execution environment, the measurement profile and the reference value are prevented from being tampered with.
[0128] Figure 3 The flowchart of the information system measurement processing method provided by the embodiments of the present application Figure 2 , the execution subject of this embodiment can be a measurement client application, and no special limitation is made here in this embodiment. As Figure 3 shown, the method includes:
[0129] S301: Send a measurement profile acquisition request to the trusted execution environment driver, so that the trusted execution environment driver sends a measurement profile acquisition request to the firmware layer. The measurement profile acquisition request is used to instruct the firmware layer to switch the non-trusted execution environment to the trusted execution environment according to the measurement profile acquisition request, and send the measurement profile acquisition request to the trusted execution environment operating system. The measurement profile acquisition request is used to instruct the trusted execution environment operating system to verify the permission of the measurement client application according to the measurement profile acquisition request and generate a verification result. If the verification result is verification passed, the trusted execution environment operating system sends a measurement profile acquisition request to the measurement trusted application. The measurement profile acquisition request is used to instruct the measurement trusted application to generate a first shared storage address according to the measurement profile acquisition request and send the first shared storage address to the firmware layer. The first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to the non-trusted execution environment.
[0130] S302: Receive the first shared storage address sent by the firmware layer.
[0131] S303: Obtain the measurement profile according to the first shared storage address and generate a measurement verification request according to the measurement profile.
[0132] S304: Send the measurement verification request to the measurement trusted application, so that the measurement trusted application generates a measurement result according to the measurement verification request.
[0133] S305: Receive the measurement result sent by the measurement trusted application and generate a measurement log according to the measurement result.
[0134] Figure 4 The system structure diagram of dynamic measurement provided by the embodiments of the present application.
[0135] As Figure 4As shown, after the measurement client application in the non-trusted execution environment obtains the data to be measured according to the measurement configuration file, it transmits the data to be measured to the firmware layer through the firmware layer. The firmware layer converts the environment into a trusted execution environment, calculates the measurement value through the measurement trusted application, compares it with the reference value, generates a measurement result, and sends the measurement result to the measurement client. The measurement client generates a measurement log according to the measurement result and writes the measurement log into the firmware trusted platform module.
[0136] As can be seen from the above embodiments, by dividing the execution environment of the software into a trusted execution environment and a non-trusted execution environment, the measurement client application requests the measurement trusted application to obtain the measurement configuration file, collects memory data according to the measurement configuration file, and generates a measurement verification request. The measurement trusted application verifies the measurement value in the measurement verification request in the trusted execution environment, compares it with the reference value, generates a measurement verification result, and sends the measurement verification result to the measurement client application. The measurement client application generates a measurement log. Compared with the prior art, a trusted execution environment is created. In the trusted execution environment, the measurement trusted application is used to execute operations such as calculating the measurement value and comparing the reference value, avoiding attacks during the process of calculating and comparing the reference value, and improving the accuracy of the measurement result.
[0137] In an embodiment of the present application, step S303 includes:
[0138] S3031: Obtain the measurement configuration file in the first shared storage address.
[0139] Specifically, the measurement client application accesses the shared memory according to the first shared storage address and obtains the measurement configuration file stored in the shared memory.
[0140] S3032: Obtain the virtual address according to the measurement configuration file.
[0141] Specifically, obtain the virtual address of the data to be measured according to the measurement configuration file.
[0142] In this embodiment, the virtual address includes virtual address information and address length.
[0143] S3033: Convert the virtual address into a physical address.
[0144] In this embodiment, the physical address includes physical address information and address length.
[0145] S3034: Generate a measurement verification request according to the physical address.
[0146] Specifically, create a measurement verification request according to the physical address of the data to be measured.
[0147] As can be seen from the above embodiments, the measurement configuration file is obtained through the first shared storage address, the data to be measured is obtained according to the measurement configuration file, a measurement verification request is created according to the data to be measured, and the measurement value is calculated by the measurement trusted application according to the measurement verification request, improving the security of the measurement process.
[0148] In an embodiment of the present application, after step S305, it further includes:
[0149] S306: Send an interface call request to the firmware trusted platform module, so that the firmware trusted platform module establishes a communication link between the measurement client application and the firmware trusted platform module according to the interface call request.
[0150] Specifically, the interface call request is sent to the firmware trusted platform module by means of wireless communication.
[0151] In this embodiment, the firmware trusted platform module runs in a trusted execution environment.
[0152] S307: Send the measurement log to the firmware trusted platform module, so that the firmware trusted platform module obtains the program control register for storing the measurement log and writes the measurement log into the program control register.
[0153] Specifically, the measurement log is sent to the firmware trusted platform module by means of wireless communication.
[0154] As can be seen from the above embodiments, by establishing communication with the firmware trusted platform module, the measurement log is extended to the firmware trusted platform module in the trusted execution environment, and the security and extension speed of the measurement log extension are improved by the firmware trusted platform module.
[0155] In an embodiment of the present application, after step S305, it further includes:
[0156] S308: Obtain the edited measurement configuration file.
[0157] In this embodiment, the edited measurement configuration file can be that the measurement client application actively receives the measurement configuration file sent by the developer, or can obtain the edited measurement configuration file regularly.
[0158] S309: Verify the edited measurement configuration file and generate a verification result.
[0159] In this embodiment, the measurement client application receives the edited measurement configuration file, verifies the measurement configuration file, judges whether the edited data exists, whether corresponding tasks are generated according to the edited data, and whether the execution operation corresponding to the failure after measurement is configured.
[0160] S310: If the verification result is that the verification passes, obtain the metric data address in the edited metric configuration file.
[0161] In this embodiment, if the verification fails, end the operation of updating the metric configuration file.
[0162] S311: Save the metric data address and generate a second shared storage address according to the metric data address.
[0163] Specifically, if the verification passes, obtain the data address to be measured according to the edited metric configuration file, convert the data address to a physical address, and save it in the shared memory.
[0164] S312: Send the second shared storage address to the trusted execution environment driver, so that the trusted execution environment driver generates a metric update request according to the second shared storage address, and sends the metric update request to the firmware layer. The metric update request is used to instruct the firmware layer to switch the non-trusted execution environment to the trusted execution environment, and send the metric update request to the trusted execution environment operating system. The metric update request is used to instruct the trusted execution environment operating system to send the metric update request to the metric trusted application. The metric update request is used to instruct the metric trusted application to update the metric configuration file according to the metric update request and generate an update result.
[0165] S313: Receive the update result sent by the metric trusted application.
[0166] As can be seen from the above embodiments, by obtaining the edited metric configuration file through the metric client application, verifying the edited metric configuration file, generating a second shared storage address according to the edited metric configuration file, sending the second shared storage address to the metric trusted application, and updating the metric configuration file in the trusted execution environment by the metric trusted application according to the metric update request and sending the update result to the metric client application, it avoids the process of updating the metric configuration file from being attacked and improves the security of updating the metric configuration file.
[0167] In an embodiment of the present application, after step S313, it further includes:
[0168] S314: Generate a log update request according to the update result.
[0169] In this embodiment, generate a log update request according to the updated metric log.
[0170] S315: Send the log update request to the firmware trusted platform module, so that the firmware trusted platform module queries the program control register storing the log according to the log update request and updates the program control register storing the log according to the log update request.
[0171] Specifically, the firmware trusted platform module receives the updated measurement log sent by the measurement client application, formats the original measurement log, controls the formatter register, and writes the updated measurement log into the program control register.
[0172] As can be seen from the above embodiments, by establishing communication with the firmware trusted platform module, the updated measurement log is extended to the firmware trusted platform module in the trusted execution environment. The original extended value is cleared by the firmware trusted platform module, and the updated measurement log is written into the program control register, improving the security and extension speed of measurement log extension.
[0173] Figure 5 Flow schematic of the information system measurement processing method provided by the embodiments of this application Figure 3 , the execution subject of this embodiment may be the trusted execution environment operating system, and no special limitation is made here in this embodiment. As Figure 5 shown, the method includes:
[0174] S501: Receive a request for obtaining a measurement configuration file sent by the firmware layer.
[0175] S502: Verify the permissions of the measurement client application according to the request for obtaining the measurement configuration file, and generate a verification result.
[0176] S503: If the verification result is verification passed, send the request for obtaining the measurement configuration file to the measurement trusted application, so that the measurement trusted application generates a retrieval instruction according to the request for obtaining the measurement configuration file.
[0177] S504: Receive the retrieval instruction sent by the measurement trusted application.
[0178] S505: Obtain the encrypted measurement configuration file according to the retrieval instruction.
[0179] S506: Decrypt the encrypted measurement configuration file to obtain the measurement configuration file.
[0180] S507: Send the measurement configuration file to the measurement trusted application, so that the measurement trusted application stores the measurement configuration file and generates a first shared storage address according to the measurement configuration file.
[0181] S508: Receive the first shared storage address sent by the measurement trusted application.
[0182] S509: Send the first shared storage address to the firmware layer so that the firmware layer switches the trusted execution environment to an untrusted execution environment according to the first shared storage address, and send the first shared storage address to the trusted execution environment driver. The first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application. The first shared storage address is used to instruct the measurement client application to generate a measurement verification request according to the first shared storage address and send the measurement verification request to the measurement trusted application. The measurement verification request is used to instruct the measurement trusted application to generate a measurement result according to the measurement verification request and send the measurement result to the measurement client application. The measurement result is used to instruct the measurement client application to generate a measurement log.
[0183] As can be seen from the above embodiments, by dividing the execution environment of the software into a trusted execution environment and an untrusted execution environment, the measurement client application requests the measurement trusted application to obtain the measurement configuration file, collects memory data according to the measurement configuration file and generates a measurement verification request. The measurement trusted application verifies the measurement value in the measurement verification request in the trusted execution environment, compares it with the reference value, generates a measurement verification result, and sends the measurement verification result to the measurement client application. The measurement client application generates a measurement log. Compared with the prior art, a trusted execution environment is created. In the trusted execution environment, the measurement trusted application performs operations of calculating the measurement value and comparing the reference value, avoiding being attacked in the process of calculating and comparing the reference value, and improving the accuracy rate of the measurement result.
[0184] In an embodiment of the present application, after step S509, it further includes:
[0185] S510: Receive the measurement update request sent by the firmware layer.
[0186] In this embodiment, the measurement update request is generated after the measurement client application obtains the edited measurement configuration file, verifies the edited measurement configuration file, and passes the verification.
[0187] S511: Send the measurement update request to the measurement trusted application so that the measurement trusted application obtains the second shared storage address in the measurement update request, obtains the edited measurement configuration file and the edited physical address according to the second shared storage address, and calculates and generates an edited reference value according to the edited physical address.
[0188] S512: Receive the edited measurement configuration file and the edited reference value sent by the measurement trusted application.
[0189] S513: Generate an update result according to the edited measurement configuration file and the edited reference value.
[0190] Specifically, obtain the measurement configuration file and the reference value before editing, generate a backup file, delete the measurement configuration file and the reference value before editing, and encrypt the edited measurement configuration file and the reference value through an encryption algorithm to generate an update result.
[0191] S514: Send the update result to the firmware layer, so that the firmware layer switches the trusted execution environment to an untrusted execution environment according to the update result, and send the update result to the trusted execution environment driver. The update result is used to instruct the trusted execution environment driver to send the update result to the measurement client application.
[0192] As can be seen from the above embodiments, by receiving a measurement update request, sending the measurement update request to a measurement trusted application, calculating a reference value through the measurement trusted application, backing up the original measurement configuration file and the corresponding reference value, deleting the original measurement configuration file and the corresponding reference value, writing the edited measurement configuration file and the reference value into the trusted execution environment operating system, and storing the measurement configuration file and the reference value through the trusted execution environment operating system deployed in the trusted execution environment, the measurement configuration file and the reference value are prevented from being tampered with, improving data security.
[0193] In an embodiment of the present application, step S513 includes:
[0194] S131: Query the measurement configuration file and the reference value before editing according to the edited measurement configuration file and the edited reference value.
[0195] Specifically, according to the edited measurement configuration file and the edited reference value, query the storage address in the secure storage module of the trusted execution environment operating system that records the measurement configuration file and the reference value before editing, so as to obtain the measurement configuration file and the reference value before editing.
[0196] S132: Generate a backup file according to the measurement configuration file and the reference value before editing.
[0197] Specifically, generate a backup file from the measurement configuration file and the reference value before editing, and store it in the backup storage area of the secure storage module.
[0198] S133: Encrypt the edited measurement configuration file and the edited reference value to obtain the encrypted measurement configuration file and reference value.
[0199] Specifically, encrypt the edited measurement configuration file and the edited reference value through an encryption module according to an encryption algorithm to obtain the encrypted measurement configuration file and reference value.
[0200] Among them, the encryption algorithm includes but is not limited to symmetric encryption algorithms, asymmetric encryption algorithms, and hash algorithms.
[0201] S134: Store the encrypted measurement configuration file and the reference value to generate an update result.
[0202] Specifically, store the encrypted measurement configuration file and the reference value in the secure storage module of the trusted execution environment operating system, and generate an update result.
[0203] As can be seen from the above embodiments, the measurement configuration file and the reference value before editing are backed up by the trusted execution environment operating system, the edited measurement configuration file and the reference value are encrypted by the encryption module, and stored in the secure storage module of the trusted execution environment operating system, avoiding the measurement configuration file and the reference value from being tampered with, and improving the security of the measurement configuration file and the reference value.
[0204] Reference Figure 6 , which is an embodiment of the interaction process of the measurement trusted application, the trusted execution environment operating system, the firmware layer, the trusted execution environment driver, and the measurement client application.
[0205] Figure 6 FIG. is a schematic diagram of the interaction process of the information system measurement processing method provided by an embodiment of the present application. In this embodiment, the interaction process of the measurement trusted application, the trusted execution environment operating system, the firmware layer, the trusted execution environment driver, and the measurement client application is taken as an example to illustrate the process of dynamic measurement. As Figure 6 shown, the details are as follows:
[0206] S601: The measurement client application sends a request to obtain the measurement configuration file to the trusted execution environment driver.
[0207] S602: The trusted execution environment driver sends a request to obtain the measurement configuration file to the firmware layer.
[0208] S603: The firmware layer switches the non-trusted execution environment to the trusted execution environment according to the request to obtain the measurement configuration file, and sends a request to obtain the measurement configuration file to the trusted execution environment operating system.
[0209] S604: The trusted execution environment operating system verifies the permissions of the measurement client application according to the request to obtain the measurement configuration file, and generates a verification result.
[0210] S605: If the verification result is verification passed, the trusted execution environment operating system sends a request to obtain the measurement configuration file to the measurement trusted application.
[0211] S606: The measurement trusted application generates a retrieval instruction according to the request to obtain the measurement configuration file, and sends the retrieval instruction to the trusted execution environment operating system.
[0212] S607: The trusted execution environment operating system obtains the encrypted measurement configuration file according to the retrieval instruction, decrypts the encrypted measurement configuration file to obtain the measurement configuration file, and sends the measurement configuration file to the measurement trusted application.
[0213] S608: The measurement trusted application stores the measurement configuration file, generates a first shared storage address according to the measurement configuration file, and sends the first shared storage address to the trusted execution environment operating system.
[0214] S609: The trusted execution environment operating system sends the first shared storage address to the firmware layer.
[0215] S610: The firmware layer switches the trusted execution environment to an untrusted execution environment according to the first shared storage address, and sends the first shared storage address to the trusted execution environment driver.
[0216] S611: The trusted execution environment driver sends the first shared storage address to the measurement client application.
[0217] S612: The measurement client application obtains the measurement configuration file according to the first shared storage address, generates a measurement verification request according to the measurement configuration file, and sends the measurement verification request to the measurement trusted application.
[0218] S613: The measurement trusted application generates a measurement result according to the measurement verification request, and sends the measurement result to the measurement client application.
[0219] S614: The measurement client application generates a measurement log according to the measurement result.
[0220] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation.
[0221] Figure 7 It is a schematic diagram of the interaction process of the information system measurement processing method provided by another embodiment of the present application. In this embodiment, the interaction process of the measurement trusted application, the trusted execution environment operating system, the firmware layer, the trusted execution environment driver, the measurement client application, and the firmware trusted platform module is taken as an example to illustrate the process of updating the measurement configuration file. As Figure 7 shown, the details are as follows:
[0222] S701: The measurement client application obtains the edited measurement configuration file.
[0223] S702: The measurement client application verifies the edited measurement configuration file and generates a verification result.
[0224] S703: If the verification result is verification passed, generate a second shared storage address according to the edited measurement configuration file, and send the second shared storage address to the trusted execution environment driver.
[0225] S704: The trusted execution environment driver generates a measurement update request according to the second shared storage address, and sends the measurement update request to the firmware layer.
[0226] S705: The firmware layer switches the non-trusted execution environment to the trusted execution environment, and sends the measurement update request to the trusted execution environment operating system.
[0227] S706: The trusted execution environment operating system sends the measurement update request to the measurement trusted application.
[0228] S707: The measurement trusted application calculates and generates a reference value according to the measurement update request, and sends the reference value to the trusted execution environment operating system.
[0229] S708: The trusted execution environment operating system generates an update result according to the reference value and the edited measurement configuration file in the measurement update request, and sends the update result to the firmware layer.
[0230] S709: The firmware layer switches the trusted execution environment to the non-trusted execution environment, and sends the update result to the trusted execution environment driver.
[0231] S710: The trusted execution environment driver sends the update result to the measurement client application.
[0232] S711: The measurement client application generates an update log according to the update result, and sends the update log to the firmware trusted platform module.
[0233] Figure 8 It is a schematic structural diagram of the information system measurement processing device provided by the embodiment of the present application. As Figure 8 shown, the information system measurement processing device 80 provided in this embodiment includes: a first receiving module 801, a first generating module 802, a first sending module 803, a second receiving module 804, a storage module 805, a second sending module 806, a third receiving module 807, a second generating module 808, and a third sending module 809.
[0234] The first receiving module 801 is configured to receive a request for obtaining a measurement configuration file sent by the trusted execution environment operating system.
[0235] The first generating module 802 is configured to generate a retrieval instruction according to the request for obtaining a measurement configuration file.
[0236] The first sending module 803 is configured to send a retrieval instruction to the trusted execution environment operating system, so that the trusted execution environment operating system obtains an encrypted measurement configuration file according to the retrieval instruction and decrypts the encrypted measurement configuration file to obtain the measurement configuration file.
[0237] The second receiving module 804 is configured to receive the measurement configuration file sent by the trusted execution environment operating system.
[0238] The storage module 805 is configured to store the measurement configuration file and generate a first shared storage address according to the measurement configuration file.
[0239] The second sending module 806 is configured to send the first shared storage address to the trusted execution environment operating system, so that the trusted execution environment operating system sends the first shared storage address to the firmware layer. The first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to an untrusted execution environment, and send the first shared storage address to the trusted execution environment driver. The first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application. The first shared storage address is used to instruct the measurement client application to obtain the measurement configuration file according to the first shared storage address and generate a measurement verification request according to the measurement configuration file.
[0240] The third receiving module 807 is configured to receive the measurement verification request sent by the measurement client application.
[0241] The second generation module 808 is configured to generate a measurement result according to the measurement verification request.
[0242] The third sending module 809 is configured to send the measurement result to the measurement client application, so that the measurement client application generates a measurement log according to the measurement result.
[0243] In a possible implementation manner, the second generation module 808 includes:
[0244] The first obtaining unit is configured to obtain the physical address in the measurement verification request.
[0245] The mapping unit is configured to map the physical address to obtain a virtual address.
[0246] The measurement unit is configured to measure the virtual address according to the measurement algorithm to obtain a measurement value.
[0247] The first sending unit is configured to send a reference value retrieval request to the trusted execution environment operating system, so that the trusted execution environment operating system obtains an encrypted reference value according to the reference value retrieval request and decrypts the encrypted reference value to obtain the reference value.
[0248] The first receiving unit is configured to receive the reference value sent by the trusted execution environment operating system.
[0249] A generating unit, configured to generate a measurement result according to a reference value and a measured value.
[0250] In a possible implementation manner, the information system measurement processing device 80 further includes:
[0251] A fourth receiving module, configured to receive a measurement update request sent by a trusted execution environment operating system.
[0252] An update module, configured to update a measurement configuration file according to the measurement update request and generate an update result.
[0253] A fourth sending module, configured to send the update result to a measurement client application, so that the measurement client application generates an update log according to the update result.
[0254] In a possible implementation manner, the update module includes:
[0255] A second obtaining unit, configured to obtain a second shared storage address in the measurement update request.
[0256] A third obtaining unit, configured to obtain an edited measurement configuration file and an edited physical address according to the second shared storage address.
[0257] A calculation unit, configured to calculate and generate an edited reference value according to the edited physical address.
[0258] A second sending unit, configured to send the edited measurement configuration file and the edited reference value to the trusted execution environment operating system, so that the trusted execution environment operating system generates an update result according to the edited measurement configuration file and the edited reference value.
[0259] A second receiving unit, configured to receive the update result sent by the trusted execution environment operating system.
[0260] For the description of the features in the corresponding embodiment of the information system measurement processing device, reference may be made to the relevant description in the corresponding embodiment of the information system measurement processing method, which will not be elaborated herein one by one.
[0261] Figure 9 This is a schematic structural diagram of the server provided by the present application. As Figure 9 shown, the server 90 provided in this embodiment includes at least one processor 901 and a memory 902. Optionally, the server 90 further includes a communication component 903. Wherein, the processor 901, the memory 902, and the communication component 903 are connected through a bus.
[0262] In a specific implementation process, at least one processor 901 executes computer execution instructions stored in the memory 902, so that at least one processor 901 executes the above-mentioned information system measurement processing method embodiment.
[0263] For the specific implementation process of the processor 901, reference may be made to the foregoing method embodiments. Their implementation principles and technical effects are similar, and thus will not be elaborated herein.
[0264] In the foregoing embodiments, it should be understood that the processor may be a central processing unit (Central Processing Unit, abbreviated as CPU), or may also be other general-purpose processors, digital signal processors (Digital Signal Processor, abbreviated as DSP), application specific integrated circuits (Application Specific Integrated Circuit, abbreviated as ASIC), etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. The steps of the method disclosed in combination with the application can be directly implemented by a hardware processor, or implemented by a combination of hardware and software modules in the processor.
[0265] The memory may include a high-speed memory (Random Access Memory, RAM), and may also include a non-volatile memory (Non-volatile Memory, NVM), such as at least one disk memory.
[0266] The bus may be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, the buses in the drawings of this application are not limited to only one bus or one type of bus.
[0267] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. The computer program is configured to execute the steps in any of the foregoing embodiments of the information system metric processing method when running.
[0268] In an exemplary embodiment, the foregoing computer-readable storage medium may include, but is not limited to: USB flash drives, read-only memories (abbreviated as ROM), random access memories (abbreviated as RAM), mobile hard disks, magnetic disks, or optical discs and other media that can store computer programs.
[0269] An embodiment of the present application also provides a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps in any of the above-described embodiments of the information system metric processing method are implemented.
[0270] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-described embodiments of the information system metric processing method are implemented.
[0271] Those skilled in the art can further realize that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Skilled professionals can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present application.
[0272] The above has introduced in detail a method, apparatus, server, and medium for generating a prediction model of a gene regulatory network provided by the present application. Specific examples are used herein to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art in the technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A method for processing information system metrics, characterized in that: Applied to measure trusted applications, including: receiving a request for obtaining a measurement configuration file sent by a trusted execution environment operating system; generating a retrieval instruction according to the request to obtain the metric configuration file; Sending the retrieval instruction to the trusted execution environment operating system, so that the trusted execution environment operating system obtains the encrypted measurement configuration file according to the retrieval instruction, and decrypts the encrypted measurement configuration file to obtain the measurement configuration file; Receiving the measurement configuration file sent by the trusted execution environment operating system; storing the metric configuration file, and generating a first shared storage address according to the metric configuration file; Sending the first shared storage address to the trusted execution environment operating system, so that the trusted execution environment operating system sends the first shared storage address to the firmware layer, the first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to the non-trusted execution environment, and send the first shared storage address to the trusted execution environment driver, the first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application, the first shared storage address is used to instruct the measurement client application to obtain a measurement configuration file according to the first shared storage address, and generate a measurement verification request according to the measurement configuration file; receiving the metric verification request sent by the metric client application; generating a measurement result according to the measurement verification request; The measurement result is sent to the measurement client application, so that the measurement client application generates a measurement log according to the measurement result.
2. The information system metric processing method according to claim 1, characterized in that: Generating a measurement result according to the measurement verification request includes: Obtaining a physical address in the measurement verification request; Mapping the physical address to obtain a virtual address; Measuring the virtual address according to a measurement algorithm to obtain a measurement value; Sending a reference value retrieval request to the trusted execution environment operating system, so that the trusted execution environment operating system obtains the encrypted reference value according to the reference value retrieval request, and decrypts the encrypted reference value to obtain the reference value; Receiving a reference value sent by the trusted execution environment operating system; A measurement result is generated according to the reference value and the measurement value.
3. The information system metric processing method according to claim 1, characterized in that: After sending the measurement result to the measurement client application so that the measurement client application generates a measurement log according to the measurement result, the method further includes: Receiving a metric update request sent by the trusted execution environment operating system; Update the metric configuration file according to the metric update request and generate an update result; The update result is sent to the metric client application, so that the metric client application generates an update log according to the update result.
4. The information system metric processing method according to claim 3, characterized in that: The updating of the metric configuration file according to the metric update request and generating an update result includes: Obtaining a second shared storage address in the metric update request; Acquire the edited metric configuration file and the edited physical address according to the second shared storage address; Calculate and generate an edited reference value according to the edited physical address; Sending the edited metric configuration file and the edited reference value to the trusted execution environment operating system so that the trusted execution environment operating system generates an update result according to the edited metric configuration file and the edited reference value; Receive an update result sent by the trusted execution environment operating system.
5. A method for processing information system metrics, characterized in that: Applicable to measure client applications, including: Sending a request to obtain a measurement configuration file to a trusted execution environment driver, so that the trusted execution environment driver sends the request to obtain a measurement configuration file to a firmware layer, wherein the request to obtain a measurement configuration file is used to instruct the firmware layer to switch a non-trusted execution environment to a trusted execution environment according to the request to obtain a measurement configuration file, and sending the request to obtain a measurement configuration file to a trusted execution environment operating system, wherein the request to obtain a measurement configuration file is used to instruct the trusted execution environment operating system to verify the permission of the measurement client application according to the request to obtain a measurement configuration file and generate a verification result. If the verification result is that the verification is passed, the trusted execution environment operating system sends the request to obtain a measurement configuration file to a measurement trusted application, wherein the request to obtain a measurement configuration file is used to instruct the measurement trusted application to generate a first shared storage address according to the request to obtain a measurement configuration file, and sends the first shared storage address to the firmware layer, wherein the first shared storage address is used to instruct the firmware layer to switch the trusted execution environment to a non-trusted execution environment; Receiving a first shared storage address sent by the firmware layer; Acquire a metric configuration file according to the first shared storage address, and generate a metric verification request according to the metric configuration file; Sending the measurement verification request to the measurement trusted application, so that the measurement trusted application generates a measurement result according to the measurement verification request; The measurement result sent by the measurement trusted application is received, and a measurement log is generated according to the measurement result.
6. The information system metric processing method according to claim 5, characterized in that: The obtaining a metric configuration file according to the first shared storage address, and generating a metric verification request according to the metric configuration file, includes: Obtaining a measurement configuration file in the first shared storage address; Obtaining a virtual address according to the metric configuration file; Converting the virtual address to a physical address; A metric verification request is generated based on the physical address.
7. The information system metric processing method according to claim 5, characterized in that: After receiving the measurement result sent by the measurement trusted application and generating a measurement log according to the measurement result, the method further includes: Sending an interface call request to a firmware trusted platform module, so that the firmware trusted platform module establishes a communication link between the measurement client application and the firmware trusted platform module according to the interface call request; The measurement log is sent to the firmware trusted platform module, so that the firmware trusted platform module obtains a program control register storing the measurement log, and writes the measurement log into the program control register.
8. The information system metric processing method according to claim 5, characterized in that: After receiving the measurement result sent by the measurement trusted application and generating a measurement log according to the measurement result, the method further includes: Get the edited metrics configuration file; Verifying the edited metric configuration file and generating a verification result; If the verification result is that the verification passes, obtaining the address of the measurement data in the edited measurement configuration file; Saving the measurement data address, and generating a second shared storage address according to the measurement data address; Sending the second shared storage address to a trusted execution environment driver, so that the trusted execution environment driver generates a metric update request according to the second shared storage address, and sending the metric update request to a firmware layer, wherein the metric update request is used to instruct the firmware layer to switch a non-trusted execution environment to a trusted execution environment, and sending the metric update request to a trusted execution environment operating system, wherein the metric update request is used to instruct the trusted execution environment operating system to send the metric update request to a metric trusted application, wherein the metric update request is used to instruct the metric trusted application to update a metric configuration file according to the metric update request and generate an update result; An update result sent by the measurement trusted application is received.
9. An information system measurement processing method, characterized in that: Applicable to trusted execution environment operating systems, including: Receive a request for obtaining a measurement configuration file sent by the firmware layer; Requesting verification of the permission of the measurement client application according to the obtained measurement configuration file, and generating a verification result; If the verification result is that the verification is passed, sending the request to obtain the metric configuration file to the metric trusted application, so that the metric trusted application generates a retrieval instruction according to the request to obtain the metric configuration file; receiving a retrieval instruction sent by the metric trusted application; Obtaining an encrypted measurement configuration file according to the retrieval instruction; decrypting the encrypted measurement configuration file to obtain the measurement configuration file; Sending the metric configuration file to the metric trusted application so that the metric trusted application stores the metric configuration file and generates a first shared storage address according to the metric configuration file; Receiving a first shared storage address sent by the measurement trusted application; The first shared storage address is sent to the firmware layer so that the firmware layer switches the trusted execution environment to the non-trusted execution environment according to the first shared storage address, and sends the first shared storage address to the trusted execution environment driver, wherein the first shared storage address is used to instruct the trusted execution environment driver to send the first shared storage address to the measurement client application, wherein the first shared storage address is used to instruct the measurement client application to generate a measurement verification request according to the first shared storage address and send the measurement verification request to the measurement trusted application, wherein the measurement verification request is used to instruct the measurement trusted application to generate a measurement result according to the measurement verification request and send the measurement result to the measurement client application, wherein the measurement result is used to instruct the measurement client application to generate a measurement log according to the measurement result.
10. The information system metric processing method according to claim 9, characterized in that: After sending the first shared storage address to the firmware layer, the method further includes: Receiving a metric update request sent by the firmware layer; Sending the metric update request to the metric trusted application, so that the metric trusted application obtains the second shared storage address in the metric update request, obtains the edited metric configuration file and the edited physical address according to the second shared storage address, and calculates and generates the edited reference value according to the edited physical address; receiving an edited metric configuration file and an edited reference value sent by the metric trusted application; generating an update result according to the edited metric configuration file and the edited benchmark value; The update result is sent to the firmware layer so that the firmware layer switches the trusted execution environment to a non-trusted execution environment according to the update result, and the update result is sent to the trusted execution environment driver, wherein the update result is used to instruct the trusted execution environment driver to send the update result to the measurement client application.
11. The information system metric processing method according to claim 10, characterized in that: Generating an update result according to the edited metric configuration file and the edited reference value comprises: According to the edited metric configuration file and the edited reference value, query and obtain the metric configuration file before editing and the reference value before editing; generating a backup file according to the metric configuration file before editing and the benchmark value before editing; Encrypting the edited metric configuration file and the edited reference value to obtain an encrypted metric configuration file and reference value; The encrypted metric configuration file and the benchmark value are stored to generate an update result.
12. A method for processing information system metrics, characterized in that: include: The measurement client application sends a request to obtain the measurement configuration file to the trusted execution environment driver; The trusted execution environment driver sends the request to obtain the measurement configuration file to the firmware layer; The firmware layer switches the non-trusted execution environment to the trusted execution environment according to the request to obtain the measurement configuration file, and sends the request to obtain the measurement configuration file to the trusted execution environment operating system; The trusted execution environment operating system verifies the permission of the measurement client application according to the measurement configuration file acquisition request, and generates a verification result; If the verification result is that the verification is passed, the trusted execution environment operating system sends the request to obtain the measurement configuration file to the measurement trusted application; The metric trusted application generates a retrieval instruction according to the request to obtain the metric configuration file, and sends the retrieval instruction to the trusted execution environment operating system; The trusted execution environment operating system obtains the encrypted measurement configuration file according to the search instruction, decrypts the encrypted measurement configuration file to obtain the measurement configuration file, and sends the measurement configuration file to the measurement trusted application; The metric trusted application stores the metric configuration file, generates a first shared storage address according to the metric configuration file, and sends the first shared storage address to the trusted execution environment operating system; The trusted execution environment operating system sends the first shared storage address to the firmware layer; The firmware layer switches the trusted execution environment to a non-trusted execution environment according to the first shared storage address, and sends the first shared storage address to the trusted execution environment driver; The trusted execution environment driver sends the first shared storage address to the measurement client application; The metric client application obtains the metric configuration file according to the first shared storage address, generates a metric verification request according to the metric configuration file, and sends the metric verification request to the metric trusted application; The metric trusted application generates a metric result according to the metric verification request, and sends the metric result to the metric client application; The measurement client application generates a measurement log according to the measurement result.
13. A server, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the information system metric processing method as claimed in any one of claims 1 to 12 when executing the computer program.
14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the information system metric processing method according to any one of claims 1 to 12.
15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the information system metric processing method according to any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Method for providing trusted services using trusted execution environment system
CN111382445A
TEE-based process dynamic integrity measurement method and system
CN117272286A