Trusted application startup method, device, equipment, medium and product based on trusted data space

By performing integrity verification and anonymous pipeline management on trusted applications, the integrity and security issues of trusted applications during installation or startup are solved, ensuring the identity authentication and secure startup of applications.

CN119740221BActive Publication Date: 2025-10-14LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411800329.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-09
Publication Date
2025-10-14
Estimated Expiration
2044-12-09

AI Technical Summary

Technical Problem

In a trusted data space, how to ensure the integrity of trusted applications and prevent malicious tampering or impersonation during installation or startup.

Method used

By verifying the integrity of the target trusted application, creating a target anonymous pipe and shielding other anonymous pipes, and using anonymous pipes to establish a secure channel for parent-child process communication, the application's identity authentication and secure startup are ensured.

Benefits of technology

It achieves secure startup of trusted applications, avoids impersonation and fraud during the connection process, and ensures the integrity, security and reliability of the startup process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119740221B_ABST
    Figure CN119740221B_ABST
Patent Text Reader

Abstract

The application discloses a trusted application program starting method and device based on a trusted data space, equipment, medium and product. The method comprises the following steps: in response to a program starting request of a target trusted application program, performing integrity verification on the target trusted application program to obtain an integrity verification result; if the integrity verification result is that the verification is passed, creating a target anonymous pipe between the target trusted application program, and shielding other anonymous pipes; the other anonymous pipes are the anonymous pipes except the target anonymous pipe; starting the target trusted application program according to program starting parameters of the target trusted application program, so that the target trusted application program connects the target anonymous pipe and runs the application program itself. The technical scheme of the embodiment of the application can ensure the integrity and security in the process of installing, starting and running the trusted application program.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of communication technology, and in particular to a trusted application startup method, device, equipment, medium and product based on a trusted data space. Background Art

[0002] Trusted applications are applications that have been verified and trusted for their security, privacy, and integrity. These applications typically adhere to strict development, security, and privacy standards, ensuring that user data and systems are protected from malicious activity or vulnerabilities. Trusted application integrity means that applications maintain their original state throughout their lifecycle, ensuring they are free from unauthorized tampering, modification, or destruction.

[0003] In trusted data space applications, trusted applications are incrementally installed by users through a manager based on data application requirements. However, the installation process itself compromises the integrity of the trusted data space virtual machine. Therefore, ensuring the integrity of trusted applications, and thus preventing malicious tampering or impersonation during installation or startup, has become a pressing issue. Summary of the Invention

[0004] The present invention provides a trusted application startup method, apparatus, device, medium and product based on a trusted data space, so as to ensure the integrity and security of the trusted application during installation, startup and operation.

[0005] According to one aspect of the present invention, a method for starting a trusted application based on a trusted data space is provided, the method comprising:

[0006] In response to a program start request of a target trusted application, performing integrity verification on the target trusted application to obtain an integrity verification result;

[0007] If the integrity verification result is passed, a target anonymous pipe is created between the target trusted application and other anonymous pipes are shielded; the other anonymous pipes are anonymous pipes other than the target anonymous pipe;

[0008] The target trusted application is started according to the program startup parameters of the target trusted application, so that the target trusted application is connected to the target anonymous pipe and runs its own application.

[0009] According to another aspect of the present invention, a trusted application startup device based on a trusted data space is provided, the device comprising:

[0010] a verification module, configured to, in response to a program start request of a target trusted application, perform integrity verification on the target trusted application and obtain an integrity verification result;

[0011] a pipeline establishment module, configured to, if the integrity verification result is a passed verification, create a target anonymous pipeline with the target trusted application and shield other anonymous pipelines at the same time; the other anonymous pipelines are anonymous pipelines other than the target anonymous pipeline;

[0012] The program startup module is used to start the target trusted application according to the program startup parameters of the target trusted application, so that the target trusted application can connect to the target anonymous pipe and run its own application.

[0013] According to another aspect of the present invention, an electronic device is provided, comprising:

[0014] at least one processor; and

[0015] a memory communicatively connected to the at least one processor; wherein,

[0016] The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor so that the at least one processor can execute the trusted application startup method based on the trusted data space described in any embodiment of the present invention.

[0017] According to another aspect of the present invention, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the trusted application startup method based on the trusted data space described in any embodiment of the present invention when executed.

[0018] According to another aspect of the present invention, a computer program product is provided. The computer program product includes a computer program. When the computer program is executed by a processor, the computer program implements the above-mentioned trusted application startup method based on the trusted data space.

[0019] The technical solution of the embodiment of the present invention verifies the integrity of the target trusted application, and when the integrity verification passes, creates a target anonymous pipe between the target trusted application and the target trusted application, while shielding other anonymous pipes, and starting the target trusted application according to the program startup parameters of the target trusted application, so that the target trusted application can connect to the target anonymous pipe and run its own application, thereby achieving secure startup of the trusted application. By using anonymous pipes to establish a secure channel for parent-child process communication, the identity of the trusted application process is identified, effectively avoiding impersonation and fraud by other communication methods during the connection process or after the connection is successful, and ensuring the integrity, security and reliability of the trusted application startup process.

[0020] It should be understood that the content described in this section is not intended to identify the key or important features of the embodiments of the present invention, nor is it intended to limit the scope of the present invention. Other features of the present invention will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0022] Figure 1 This is a flowchart of a method for starting a trusted application according to a first embodiment of the present invention;

[0023] Figure 2A This is a schematic diagram of an interaction process of starting a trusted application based on integrity verification according to a second embodiment of the present invention;

[0024] Figure 2B This is a schematic diagram of a remote certification report acquisition process interaction provided in accordance with the second embodiment of the present invention;

[0025] Figure 3 This is a schematic diagram of the structure of a trusted application startup device provided according to the third embodiment of the present invention;

[0026] Figure 4 It is a structural diagram of an electronic device that implements the trusted application startup method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0027] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.

[0028] It should be noted that the terms "first", "second", etc. in the description and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0029] Example 1

[0030] Figure 1 This is a flowchart of a trusted application startup method based on a trusted data space provided in the first embodiment of the present invention. This embodiment is applicable to the installation, startup and operation of trusted applications. The method can be executed by a trusted application startup device. The trusted application startup device can be implemented in the form of hardware and / or software. The trusted application startup device can be configured in an electronic device. Figure 1 As shown, the method includes:

[0031] S110 : In response to a program start request of a target trusted application, perform integrity verification on the target trusted application to obtain an integrity verification result.

[0032] S120: If the integrity verification result is passed, a target anonymous pipe is created between the target trusted application and the target trusted application, while shielding other anonymous pipes; other anonymous pipes are anonymous pipes other than the target anonymous pipe.

[0033] S130 : Starting the target trusted application according to the program starting parameters of the target trusted application, so that the target trusted application connects to the target anonymous pipe and runs its own application.

[0034] Among them, trusted applications refer to applications that have been verified and trusted in terms of security, privacy and integrity. The characteristics of trusted applications may include: security authentication, digital signatures, privacy protection and trusted sources. Among them, security authentication means that trusted applications have passed security testing and certification to ensure that their codes have no known vulnerabilities and their behaviors are predictable and controlled; digital signatures mean that trusted applications usually use digital signatures to verify the identity of developers and ensure that the software has not been tampered with; privacy protection means that trusted applications are transparent in the collection and use of user data and comply with privacy regulations to ensure that data will not be abused; trusted sources mean that trusted applications usually come from official, internal corporate development teams or verified developers, thereby effectively reducing the risk of obtaining malicious applications.

[0035] Trusted application integrity means that an application maintains its original state throughout its lifecycle, ensuring it is free from unauthorized tampering, modification, or destruction. This includes the integrity of all aspects of the application, including its code, configuration files, data, and runtime behavior. Ensuring application integrity ensures that the application runs as expected and is not compromised by malware or external attackers, thereby ensuring security and reliability.

[0036] The embodiment of the present invention is implemented by a trusted application manager, which can be used to install and launch trusted applications. The trusted application manager ensures that only applications that have passed integrity and security verification can be launched normally, thereby preventing impersonation and fraud during application installation or launch.

[0037] The target trusted application may be a trusted application that requires secure startup. Program startup parameters may be parameters required by the trusted application manager to start the target trusted application. These parameters may be pre-configured and stored in the trusted application manager. For example, the program startup parameters may include environment configuration parameters, input data parameters, network configuration parameters, security verification parameters, and logging and debugging parameters.

[0038] The program start request may be a request to start a target trusted application, which may be initiated proactively by a relevant technical staff, or initiated by the target trusted application, or automatically initiated by a trusted application manager based on set rules.

[0039] The trusted application manager performs integrity verification on the target trusted application. Specifically, the trusted application manager calculates the file hash value of each program file contained in the target trusted application, sorts and encodes each file hash value, and calculates the current hash value of the target trusted application in combination with the program version and program name of the target trusted application. The trusted application manager obtains the release hash value of the target trusted application at the time of program release and compares the current hash value with the release hash value. If the hash value comparison is successful, the integrity verification of the target trusted application is passed; if the hash value comparison fails, the integrity verification of the target trusted application is failed.

[0040] If the trusted application manager passes the integrity verification of the target trusted application, it creates a target anonymous pipe between the trusted application manager and the target trusted application. This target anonymous pipe can include two pairs of anonymous pipes for parent-child communication: one for transmitting data from the trusted application manager to the target trusted application, and another for transmitting data from the target trusted application to the trusted application manager. During creation, pipe descriptors corresponding to the target anonymous pipes are automatically generated, i.e., input and output file descriptors, which uniquely identify the target anonymous pipe for communication with the target trusted application.

[0041] Optionally, creating a target anonymous pipe with a target trusted application includes: creating a target anonymous pipe with the target trusted application and generating a pipe descriptor for the target anonymous pipe; binding the pipe descriptor to the target anonymous pipe and establishing a mapping relationship between the pipe descriptor and a preset fixed descriptor; and connecting the target trusted application to the target anonymous pipe based on the fixed descriptor.

[0042] The fixed descriptor is a pre-negotiated descriptor with the target trusted application. The target trusted application only has access to the fixed descriptor, not the pipe descriptor. The trusted application manager maps the pipe descriptor to the fixed descriptor, specifically by copying the pipe descriptor to fixed input and output file descriptors (fixed descriptors), thereby establishing a binding relationship with the target trusted application.

[0043] The target trusted application can be connected to the target anonymous pipe through a fixed descriptor; during the connection process, since the fixed descriptor and the pipe descriptor have a mapping relationship, the connection of the target trusted application can be mapped to the corresponding pipe descriptor to connect to the target anonymous pipe, and then communication can be established with the trusted application manager through the target anonymous pipe.

[0044] It's important to note that when the trusted application manager creates a target anonymous pipe between target trusted applications, it needs to shield other anonymous pipes. Other anonymous pipes are anonymous pipes other than the target anonymous pipe. This shielding prevents other trusted application processes from accessing pipes in the trusted application manager.

[0045] The trusted application manager starts the target trusted application according to the program startup parameters of the target trusted application, and monitors the program running status of the target trusted application, thereby determining whether the target trusted application is successfully started.

[0046] Optionally, the target trusted application runs in the following manner: connecting to the target anonymous pipe based on a fixed descriptor, and if the connection with the target anonymous pipe is successful, running the own application; if the connection with the target anonymous pipe fails, terminating the own application.

[0047] The technical solution of the embodiment of the present invention verifies the integrity of the target trusted application, and when the integrity verification passes, creates a target anonymous pipe between the target trusted application and the target trusted application, while shielding other anonymous pipes, and starting the target trusted application according to the program startup parameters of the target trusted application, so that the target trusted application can connect to the target anonymous pipe and run its own application, thereby achieving secure startup of the trusted application. By using anonymous pipes to establish a secure channel for parent-child process communication, the identity of the trusted application process is identified, effectively avoiding impersonation and fraud by other communication methods during the connection process or after the connection is successful, and ensuring the integrity, security and reliability of the trusted application startup process.

[0048] After a trusted application is successfully launched, it must undergo remote attestation before exchanging data with other requesters. Applications that haven't undergone remote attestation are untrustworthy and present a risk of data leakage. Therefore, this embodiment also provides a remote attestation method for trusted applications. This method ensures the reliability of the trusted application's operating environment while also proving the authenticity of the program's identity.

[0049] In an optional embodiment, after starting the target trusted application according to the program startup parameters of the target trusted application so that the target trusted application connects to the target anonymous pipe and runs its own application, the method further includes:

[0050] Step a1: Obtain a remote attestation report acquisition request of a target trusted application; the remote attestation report acquisition request is generated by the target trusted application after successfully running its own application and receiving a remote attestation request from a data exchange party.

[0051] The data exchanger can be any party that exchanges data with the target trusted application. The data exchanger initiates a remote attestation request to the target trusted application. Upon receiving the remote attestation request from the data exchanger, the target trusted application sends a remote attestation report acquisition request to the trusted application manager.

[0052] Step a2: Generate a target remote attestation report based on the remote attestation report acquisition request.

[0053] After receiving the remote attestation report acquisition request sent by the target trusted application, the trusted application manager parses the remote attestation report acquisition request and generates a target remote attestation report after authenticating the target trusted application.

[0054] Optionally, based on the remote attestation report acquisition request, a target remote attestation report is generated, including: based on the remote attestation report acquisition request, identifying the target trusted application, and generating an initial remote attestation report after the identification is passed; generating additional attestation information of the target trusted application, and appending the additional attestation information to the initial remote attestation report to obtain an intermediate remote attestation report; using the trusted execution environment private key to sign the intermediate remote attestation report to obtain the target remote attestation report.

[0055] Specifically, the trusted application manager parses the remote attestation request to obtain information such as the name, integrity hash value, program version, and program identifier of the trusted application, and based on the parsing results, identifies the target trusted application to ensure that the trusted application identity is reliable and authorized.

[0056] If the trusted application manager successfully identifies the target trusted application, it then obtains a chip-based virtual machine remote attestation report (the initial remote attestation report) based on the parsing results, such as the request source random number and program identifier. Simultaneously, it generates additional attestation information for the target trusted application. This additional attestation information may include the target trusted application's integrity verification hash value, application name, and application version. This additional attestation information is appended to the initial remote attestation report, resulting in an intermediate remote attestation report.

[0057] The trusted application manager uses the virtual machine private key, that is, the trusted execution environment private key, to sign the intermediate remote attestation report to obtain the target remote attestation report.

[0058] Step a3: Send the target remote attestation report to the target trusted application through the target anonymous channel, so that the target trusted application can feed back the target remote attestation report to the data exchange party.

[0059] The target remote attestation report is sent by the trusted application manager to the target trusted application through a target anonymous pipeline; the target trusted application feeds back the received target remote attestation report to the data exchange party, so that the data exchange party performs program identity verification based on the target remote attestation report.

[0060] Embodiment two

[0061] The embodiment is based on the above-mentioned embodiments and further provides a preferred example. The preferred example includes a trusted application startup process and a remote attestation report acquisition process.

[0062] Figure 2A is a trusted application based on integrity verification startup process interaction diagram provided by embodiment two of the application, and the method execution subject is a trusted application manager, and specifically includes the following steps:

[0063] Step b1, before starting the trusted application by the trusted application manager, the integrity of the trusted application is measured, wherein the measurement method is consistent with the measurement method when the application is published, first, the hash of each file is calculated, then all file hashes are sorted and encoded, combined with the name and version of the application, the hash of the trusted application is calculated.

[0064] Step b2, compare the hash value of the integrity measurement with the hash value in the application release list, and the signature of the release list should also be verified before comparison; if the hash values are the same, it means that the integrity verification is successful; otherwise, the integrity verification fails, and the trusted application startup process is terminated.

[0065] Step b3, after the integrity verification, two pairs of anonymous pipelines for parent-child communication are created, the access of the child process to the pipeline in the parent process is shielded, and the input and output file descriptors of the corresponding child process are copied to a fixed input and output file descriptor, so as to bind the trusted application process.

[0066] Step b4, according to the trusted application and the startup parameters, the trusted application is started, and the running state of the application is monitored.

[0067] Step b5, when the trusted application is started as a child process, the anonymous communication pipeline is connected, if the connection fails, it means that it is not started by the trusted application manager, and the trusted application startup process is terminated.

[0068] After successfully connecting the anonymous communication pipeline, the application logic is normally run.

[0069] Figure 2B is a remote attestation report acquisition process interaction diagram provided by embodiment two of the application, specifically including the following steps:

[0070] Step c1, when the trusted application receives the remote attestation request from the data exchange partner, sends a remote attestation report acquisition request to the trusted application manager.

[0071] Step c2, the trusted application manager receives the remote attestation report acquisition request from the trusted application, and identifies the trusted application process.

[0072] Step c3, if the identification is passed, the trusted application manager acquires the remote attestation report based on the chip virtual machine according to the request information.

[0073] Step c4, the trusted application manager attaches the integrity information of the trusted application, including the integrity hash value, the trusted application name and the trusted application version, to the remote attestation report according to the trusted application process.

[0074] Step c5, the trusted application manager signs the remote attestation report after attaching the integrity information of the trusted application using the virtual machine private key.

[0075] Step c6, the trusted application manager returns the signed remote attestation report to the corresponding trusted application through the bound anonymous pipe.

[0076] Step c7, the trusted application receives the remote attestation report and responds to the trusted application of the data exchange partner for remote attestation verification.

[0077] Embodiment three

[0078] Figure 3 A structure schematic diagram of a trusted application starting device based on a trusted data space is provided for the third embodiment of the present application. The trusted application starting device based on a trusted data space provided by the embodiment of the present application can be suitable for the installation, starting and running of the trusted application, and the trusted application starting device based on a trusted data space can be realized in the form of hardware and / or software, such as Figure 3 As shown in the figure, the device specifically includes: a verification module 301, a pipe establishment module 302 and a program starting module 303. Among them,

[0079] The verification module 301 is used for responding to the program starting request of the target trusted application, and performing integrity verification on the target trusted application to obtain an integrity verification result.

[0080] The pipe establishment module 302 is used for creating a target anonymous pipe with the target trusted application if the integrity verification result is verified, and shielding other anonymous pipes; the other anonymous pipes are the anonymous pipes except the target anonymous pipe.

[0081] The program starting module 303 is configured to start the target trusted application according to the program starting parameter of the target trusted application, so that the target trusted application connects the target anonymous pipe and runs the application of the target trusted application.

[0082] The technical scheme of the embodiment of the application verifies the integrity of the target trusted application, and when the integrity verification is passed, creates the target anonymous pipe between the target trusted application, shields other anonymous pipes, starts the target trusted application according to the program starting parameter of the target trusted application, so that the target trusted application connects the target anonymous pipe and runs the application of the target trusted application, and realizes the safe starting of the trusted application. The identity of the trusted application process is identified by using the anonymous pipe to establish a secure channel for parent-child process communication, effectively avoiding the impersonation and fraud behavior in the connection process or after the connection is successful by using other communication methods, and ensuring the integrity, security and reliability in the starting process of the trusted application.

[0083] Optionally, the pipe establishing module 302 is specifically configured to:

[0084] create the target anonymous pipe between the target trusted application, generate the pipe descriptor of the target anonymous pipe, bind the pipe descriptor and the target anonymous pipe, and establish the mapping relationship between the pipe descriptor and the preset fixed descriptor; and the target trusted application connects the target anonymous pipe based on the fixed descriptor.

[0085] Optionally, the target trusted application is run in the following manner:

[0086] connects the target anonymous pipe based on the fixed descriptor, if the connection with the target anonymous pipe is successful, runs the application of the target trusted application, and if the connection with the target anonymous pipe fails, terminates the application of the target trusted application.

[0087] Optionally, the device further comprises:

[0088] The request obtaining module is configured to obtain a remote attestation report obtaining request of the target trusted application after the target trusted application is started according to the program starting parameter of the target trusted application, so that the target trusted application connects the target anonymous pipe and runs the application of the target trusted application; the remote attestation report obtaining request is generated by the target trusted application after successfully running the application of the target trusted application and receiving the remote attestation request of the data exchange party.

[0089] The report generating module is configured to generate a target remote attestation report according to the remote attestation report obtaining request.

[0090] report feedback module, configured to send the target remote attestation report to the target trusted application through the target anonymous channel, so that the target trusted application feeds back the target remote attestation report to the data exchange party.

[0091] Optionally, a report generation module, specifically configured to:

[0092] According to the remote attestation report acquisition request, identity identification is performed on the target trusted application, and after the identification passes, an initial remote attestation report is generated;

[0093] Additional attestation information of the target trusted application is generated, and the additional attestation information is attached to the initial remote attestation report to obtain an intermediate remote attestation report;

[0094] The intermediate remote attestation report is signed by using a trusted execution environment private key to obtain a target remote attestation report.

[0095] Optionally, the additional attestation information includes an integrity verification hash value, an application program name and an application program version of the target trusted application.

[0096] The trusted application starting device provided by the embodiment of the application can execute the trusted application starting method provided by any embodiment of the application, and has the corresponding function modules and beneficial effects of the execution method.

[0097] Embodiment four

[0098] Figure 4 A structural schematic diagram of an electronic device 40 that can be used to implement embodiments of the application is shown. The electronic device is intended to represent various forms of digital computers, such as laptops, desktops, tablets, personal digital assistants, servers, blade servers, mainframes, and other appropriate computers. The electronic device can also represent various forms of mobile devices, such as personal digital processors, cellular telephones, smart phones, wearable devices (e.g., headsets, glasses, watches, etc.), and other similar computing devices. The components shown here, their connections and relationships, and their functions, are meant to be examples only, and are not intended to limit the implementations of the applications described and / or claimed in this document.

[0099] As Figure 4As shown, the electronic device 40 includes at least one processor 41, and a memory, such as a read-only memory (ROM) 42, a random access memory (RAM) 43, etc., connected to the at least one processor 41 in communication. The memory stores computer programs executable by the at least one processor 41, and the processor 41 can perform various appropriate actions and processes according to the computer programs stored in the read-only memory (ROM) 42 or loaded into the random access memory (RAM) 43 from the storage unit 48. In the RAM 43, various programs and data required for the operation of the electronic device 40 can also be stored. The processor 41, the ROM 42, and the RAM 43 are connected to each other through a bus 44. An input / output (I / O) interface 45 is also connected to the bus 44.

[0100] Various components in the electronic device 40 are connected to the I / O interface 45, including an input unit 46, such as a keyboard, a mouse, etc., an output unit 47, such as various types of displays, a speaker, etc., a storage unit 48, such as a magnetic disk, an optical disk, etc., and a communication unit 49, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 49 allows the electronic device 40 to exchange information / data with other devices through a computer network, such as the Internet, and / or various telecommunication networks.

[0101] The processor 41 can be various general and / or special-purpose processing components having processing and computing capabilities. Some examples of the processor 41 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special-purpose artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 41 performs various methods and processes described above, such as the trusted application launching method.

[0102] In some embodiments, the trusted application launching method can be implemented as a computer program tangibly embodied in a computer readable storage medium, such as the storage unit 48. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 40 via the ROM 42 and / or the communication unit 49. When the computer program is loaded onto the RAM 43 and executed by the processor 41, one or more steps of the trusted application launching method described above can be performed. Alternatively, in other embodiments, the processor 41 can be configured to perform the trusted application launching method by any other appropriate means, such as by means of firmware.

[0103] The various embodiments of the systems and techniques described above can be implemented in digital electronic circuitry, integrated circuitry, a field programmable gate array (FPGA), an application specific integrated circuit (ASIC), a system on a chip (SOC), a load programmable logic device (CPLD), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include implementation in one or more computer programs that are executable and / or interpretable on a programmable system including at least one programmable processor, which can be special or general purpose, coupled to receive data and instructions from, and to transmit data and instructions to, a storage system, at least one input device, and at least one output device.

[0104] Computer programs used to implement the processes of the application can be written in any combination of one or more programming languages. These computer programs can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus, such that the computer program, when executed, can cause instructions defined in the flow charts and / or block diagrams to be implemented. The computer program can be executed entirely on a machine, partially on a machine, partially on a machine as a standalone software package and partially on a remote machine or entirely on a remote machine or server.

[0105] In the context of the present application, a computer-readable storage medium can be a tangible medium that can contain or store computer programs for use by or in connection with an instruction execution system, apparatus, or device. Computer-readable storage media can include, but are not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium can be a machine-readable signal medium. More specific examples of the machine-readable storage medium will include one or more lines of electrical connections, portable computer disks, hard disk drives, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or Flash memory), optical fibers, portable compact disc read-only memories (CD-ROMs), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.

[0106] To provide interaction with a user, the systems and techniques described herein can be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0107] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0108] A computing system may include clients and servers. The clients and servers are typically remote from each other and typically interact via a communication network. This client-server relationship arises through computer programs running on the respective computers, creating a client-server relationship. The server may be a cloud server, also known as a cloud computing server or cloud host. This server is a hosting product within the cloud computing service ecosystem that addresses the management difficulties and limited scalability of traditional physical hosting and VPS services.

[0109] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in the present invention can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solution of the present invention can be achieved. This is not limited herein.

[0110] The above specific embodiments do not limit the scope of protection of the present invention. Those skilled in the art will appreciate that various modifications, combinations, sub-combinations, and substitutions may be made based on design requirements and other factors. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention are intended to be included within the scope of protection of the present invention.

Claims

1. A method for starting a trusted application based on a trusted data space, characterized in that: include: In response to a program start request of a target trusted application, performing integrity verification on the target trusted application to obtain an integrity verification result; If the integrity verification result is passed, a target anonymous pipe is created between the target trusted application and other anonymous pipes are shielded; the other anonymous pipes are anonymous pipes other than the target anonymous pipe; Starting the target trusted application according to a program startup parameter of the target trusted application, so that the target trusted application connects to the target anonymous pipe and runs its own application; The step of creating a target anonymous pipeline with the target trusted application comprises: A target anonymous pipe is created between the target trusted application and the target anonymous pipe, and a pipe descriptor of the target anonymous pipe is generated; the pipe descriptor is bound to the target anonymous pipe, and a mapping relationship between the pipe descriptor and a preset fixed descriptor is established; the target trusted application is connected to the target anonymous pipe based on the fixed descriptor.

2. The method according to claim 1, characterized in that The target trusted application runs as follows: The target anonymous pipe is connected based on the fixed descriptor. If the connection with the target anonymous pipe is successful, the own application is run; if the connection with the target anonymous pipe fails, the own application is terminated.

3. The method according to claim 1, characterized in that After starting the target trusted application according to the program startup parameters of the target trusted application so that the target trusted application connects to the target anonymous pipe and runs its own application, the method further includes: Obtaining a remote attestation report acquisition request of the target trusted application; the remote attestation report acquisition request is generated by the target trusted application after successfully running its own application and receiving a remote attestation request from the data exchange party; Generate a target remote attestation report according to the remote attestation report acquisition request; The target remote attestation report is sent to the target trusted application through the target anonymous channel, so that the target trusted application feeds back the target remote attestation report to the data exchange party.

4. The method according to claim 3, characterized in that Generating a target remote attestation report according to the remote attestation report acquisition request includes: Identify the target trusted application according to the remote attestation report acquisition request, and generate an initial remote attestation report after the identification is successful; generating additional attestation information of the target trusted application, and appending the additional attestation information to the initial remote attestation report to obtain an intermediate remote attestation report; The intermediate remote attestation report is signed using the trusted execution environment private key to obtain a target remote attestation report.

5. The method according to claim 4, characterized in that The additional certification information includes the integrity verification hash value, application name, and application version of the target trusted application.

6. A trusted application startup device based on a trusted data space, characterized in that: include: a verification module, configured to, in response to a program start request of a target trusted application, perform integrity verification on the target trusted application and obtain an integrity verification result; a pipeline establishment module, configured to, if the integrity verification result is a passed verification, create a target anonymous pipeline with the target trusted application and shield other anonymous pipelines at the same time; the other anonymous pipelines are anonymous pipelines other than the target anonymous pipeline; A program startup module, configured to start the target trusted application according to program startup parameters of the target trusted application, so that the target trusted application connects to the target anonymous pipe and runs its own application; Among them, the pipeline establishment module is specifically used to: Creating a target anonymous pipe with the target trusted application and generating a pipe descriptor for the target anonymous pipe; binding the pipe descriptor to the target anonymous pipe and establishing a mapping relationship between the pipe descriptor and a preset fixed descriptor; The target trusted application connects to the target anonymous pipe based on the fixed descriptor.

7. An electronic device, characterized in that: The electronic device comprises: at least one processor; and a memory communicatively connected to the at least one processor; wherein, The memory stores a computer program that can be executed by the at least one processor, and the computer program is executed by the at least one processor to enable the at least one processor to execute the trusted application startup method based on the trusted data space according to any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a processor to implement the trusted application startup method based on a trusted data space according to any one of claims 1 to 5 when executed.

9. A computer program product, characterized in that The computer program product comprises a computer program, which, when executed by a processor, implements the trusted application startup method based on a trusted data space according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • User authentication method, system, equipment and medium

    CN117978532A

  • Method and system for re-associating anonymised data with a data owner

    WO2024104901A1