Security control method, device, and storage medium
By introducing secure smart cards into IoT devices and implementing biological identity authentication and secondary authorization based on operating system types, the problem of low security of IoT devices is solved, efficient and flexible security control is achieved, and the overall security and maintainability of the device are improved.
Patent Information
- Application Number
- CN202510273861.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-10
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-03-10
AI Technical Summary
The security of IoT devices is not high, the existing security technologies are costly and difficult to integrate, and the traditional SecureBoot mechanism is poorly flexible and cannot adapt to the needs of frequent updates.
Using secure smart cards as the core component, implementing different security control measures based on operating system types, integrating biological identity authentication technology, and building a double-layer defense line, including built-in biometric modules and secondary authorization mechanisms in secure smart cards to dynamically verify firmware integrity.
It improves the security of IoT devices, enhances the accuracy of identity authentication and the integrity and confidentiality of memory data, reduces hardware costs and update difficulty, and provides a flexible security upgrade mechanism.
Smart Images

Figure CN119783081B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information security technology, and particularly relates to a security control method, device, and storage medium. Background Art
[0002] In the wave of digitalization, Internet of Things (IoT) technology is widely applied in fields such as smart home, industrial production, and medical care. However, with the expansion of the application scope, the security challenges faced by the IoT are becoming increasingly severe.
[0003] Currently, the security of IoT devices is not high.
[0004] The above content is only used to assist in understanding the technical solution of this application, and does not represent an admission that the above content is prior art. Summary of the Invention
[0005] The main purpose of this application is to provide a security control method, device, and storage medium, aiming to solve the technical problem of the low security of current IoT devices.
[0006] To achieve the above purpose, this application proposes a security control method applied to an IoT device, where the IoT device includes a security smart card, and the method includes the following steps:
[0007] Receive a target access request;
[0008] Obtain the operating system type of the IoT device;
[0009] If the operating system type of the IoT device is the first operating system, perform biometric identification of the target user who issued the target access request through the security smart card;
[0010] If the operating system type of the IoT device is the second operating system, perform secondary authorization on the target access request based on the security smart card.
[0011] In one embodiment, before the step of receiving the target access request includes:
[0012] Perform security verification on the IoT device;
[0013] If the IoT device passes the security verification, execute the step: receive the target access request.
[0014] In one embodiment, the step of performing security verification on the IoT device includes:
[0015] Initialize the IoT device, and generate a public key, a private key, and a symmetric key through the security smart card;
[0016] Store the private key and the symmetric key in a secure storage area through the secure smart card.
[0017] Compile the firmware of the Internet of Things device;
[0018] Calculate the hash value of the firmware;
[0019] Sign the hash value of the firmware through the secure smart card based on a pre-generated private key to generate a signature value;
[0020] Store the signature value and the hash value of the firmware in the firmware storage area;
[0021] When the Internet of Things device starts up, load the firmware and extract the signature value from the firmware storage area;
[0022] Obtain the device identifier of the Internet of Things device;
[0023] Verify whether the device identifier matches an authorized device list pre-stored in the secure smart card through the secure smart card;
[0024] If the match is successful, verify the signature value based on the public key through the secure smart card;
[0025] If the verification passes, the Internet of Things device passes the security verification;
[0026] If the verification fails, the Internet of Things device fails the security verification, prevent the Internet of Things device from starting up, and record relevant security events in the security audit log of the secure smart card.
[0027] In one embodiment, the first operating system is a security-enhanced Linux system, and the step of performing biometric identification on the target user who issues the target access request through the secure smart card includes:
[0028] Receive a request from the target user to access a highly sensitive object;
[0029] Activate the biometric identification module through the secure smart card;
[0030] Collect biometric information of the target user through the biometric identification module;
[0031] Compare the biometric information with a pre-stored biometric template through the secure smart card;
[0032] If the comparison is successful, allow the target user to access the highly sensitive object according to a preset access control rule through the security-enhanced Linux system;
[0033] If the comparison fails, the security-enhanced Linux system rejects the access request of the target user and records the relevant security events in the security audit log of the security smart card.
[0034] In one embodiment, before the step of receiving the request of the target user to access a highly sensitive object, the following steps are included:
[0035] Receiving, by the biometric identification module, a biometric registration request of the target user to obtain the biometric template;
[0036] Storing the biometric template in the secure storage area of the security smart card.
[0037] In one embodiment, the second operating system is a real-time operating system, and the step of performing secondary authorization on the target access request based on the security smart card includes:
[0038] Performing a preliminary review on the target access request according to the preset memory access control rules through the memory protection unit of the real-time operating system;
[0039] If the preliminary review is passed, performing a secondary review on the target access request by the security smart card according to the preset memory access authorization policy;
[0040] If the secondary review is passed, accepting the target access request through the real-time operating system;
[0041] If the secondary review is not passed, rejecting the target access request through the real-time operating system and recording the relevant security events in the security audit log of the security smart card.
[0042] In addition, to achieve the above object, the present application further provides a security control device, which is disposed in an Internet of Things device, and the Internet of Things device includes a security smart card. The device includes:
[0043] A request receiving module, configured to receive a target access request and obtain the operating system type of the Internet of Things device;
[0044] A request control module, if the operating system type of the Internet of Things device is the first operating system, performing biometric identification on the target user who issues the target access request through the security smart card; if the operating system type of the Internet of Things device is the second operating system, performing secondary authorization on the target access request based on the security smart card.
[0045] In addition, to achieve the above object, the present application further provides a security control device, which includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the security control method as described above.
[0046] In addition, to achieve the above object, the present application further provides a storage medium, which is a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, it implements the steps of the security control method as described above.
[0047] One or more technical solutions provided by the present application have at least the following technical effects:
[0048] The present application takes the security smart card as the core hub, and performs security control on the target access request through the security smart card, and can be flexibly configured according to different Internet of Things application scenarios. Whether it is the industrial control and intelligent medical fields with extremely high security requirements, or the smart home and small sensor networks that are cost-sensitive and have relatively simple functions, it can accurately adapt to the needs and improve security by adjusting the strategies stored in the smart card and selecting different biometric modules.
[0049] In addition, based on the architecture design of the security smart card, it is more convenient to upgrade and replace various security technologies. For example, when the encryption algorithm needs to be updated to cope with new security threats, only the relevant modules need to be updated in the security smart card, without large-scale transformation of the entire Internet of Things device hardware; another example is that with the development of biometric technology, when introducing new and more accurate identification methods, they can be quickly integrated into the smart card and seamlessly connected to the existing system through software updates, providing strong support for the continuous development of the security protection of Internet of Things devices.
[0050] The present application implements different security control measures based on different operating system types, and integrates biometric authentication technology into Internet of Things devices. When the operating system type of the Internet of Things device is the first operating system, by installing a biometric identification module, such as a fingerprint recognition or iris recognition sensor, in the security smart card, user authentication is achieved, thereby enhancing the security of the Internet of Things device. And when the operating system type of the Internet of Things device is the second operating system, secondary authorization is performed on the target access request based on the security smart card, so that a double-layer defense line can be built, significantly enhancing the integrity and confidentiality of the memory data and enhancing the security of the Internet of Things device. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] The accompanying drawings here are incorporated into the specification and form a part of this specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0052] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0053] Figure 1 It is a schematic flowchart provided for the first embodiment of the security control method of the present application;
[0054] Figure 2 It is a schematic flowchart for performing startup verification in the security control method of the present application;
[0055] Figure 3 It is a schematic structural diagram of the Internet of Things device of the present application;
[0056] Figure 4 It is a schematic flowchart for performing biometric identification in the security control method of the present application;
[0057] Figure 5 It is a schematic module structure diagram of the security control device in the embodiment of the present application;
[0058] Figure 6 It is a schematic device structure diagram of the hardware operating environment involved in the security control method in the embodiment of the present application.
[0059] The realization of the purpose, functional features and advantages of the present application will be further described with reference to the embodiments and the drawings. Specific Embodiments
[0060] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the present application and are not used to limit the present application.
[0061] To better understand the technical solutions of the present application, the following will be described in detail in combination with the drawings of the specification and the specific embodiments.
[0062] The main solution of the embodiment of the present application is: receiving a target access request; obtaining the operating system type of the Internet of Things device; if the operating system type of the Internet of Things device is the first operating system, performing biometric identification on the target user who issues the target access request through the security smart card; if the operating system type of the Internet of Things device is the second operating system, performing secondary authorization on the target access request based on the security smart card.
[0063] In this embodiment, for the convenience of description, the Internet of Things device is used as the execution subject for elaboration below.
[0064] At present, the security of Internet of Things devices is not high.
[0065] This application provides a solution that implements different security control measures based on different operating system types and integrates biometric authentication technology into Internet of Things (IoT) devices. When the operating system type of the IoT device is the first operating system, biometric identification modules, such as fingerprint recognition or iris recognition sensors, are built into the secure smart card to implement user authentication, thereby enhancing the security of the IoT device. Moreover, when the operating system type of the IoT device is the second operating system, secondary authorization is performed on the target access request based on the secure smart card, thereby enabling the construction of a two-layer defense line, significantly enhancing the integrity and confidentiality of in-memory data, and enhancing the security of the IoT device.
[0066] Currently, the security of IoT devices is mainly achieved through the following technologies:
[0067] SecureBoot: SecureBoot is a security mechanism that acts in the initial stage of device startup. It verifies the loaded system software and firmware through digital signature verification and key management systems, and only allows code from reliable sources with intact integrity to start. This mechanism effectively prevents malware from being implanted into the system during the startup stage and provides guarantee for the secure operation of the device.
[0068] SELinux: SELinux (Security-Enhanced Linux) is a security module embedded in the Linux kernel. It performs access control on resources such as files, processes, and network ports through fine-grained policy rules and enforces restrictions based on the permissions of the subject. Even if a malicious program enters the system, it will not be able to obtain critical resources arbitrarily due to strict access control, thereby reducing security risks caused by abuse of permissions.
[0069] MPU: The MPU (Memory Protection Unit) divides the memory into multiple independent regions according to task requirements, allocates independent memory spaces for each application or task module, and sets strict read, write, and execution permissions. This method prevents out-of-bounds memory access and illegal read and write between tasks, ensures the integrity and security of in-memory data, and avoids system crashes or data leaks caused by memory problems.
[0070] SE: SE (Secure Element) is a hardware security module that integrates functions such as encryption, decryption, digital signature, and key management. During the network data transmission process, it protects data security through encryption algorithms to prevent information theft. In the key generation and storage process, it uses hardware-level protection mechanisms to prevent external illegal access to keys, providing reliable guarantee for the data security of IoT devices.
[0071] Currently, the security problems of IoT devices include the following three points:
[0072] Shortcoming 1: Cost issue. If one chooses to purchase equipment equipped with the above-mentioned independent security technology components, or adapts and transforms existing equipment one by one, introducing complex independent modules, it will cost a huge amount.
[0073] Shortcoming 2: Different security technologies originate from diverse R & D backgrounds and technical systems. Integrating them not only requires proficiency in various technical principles, but also close collaboration among multiple professionals to complete complex integration and debugging work, which is extremely difficult.
[0074] Shortcoming 3: The SecureBoot mechanism usually relies on efuse (one-time programmable fuse) hardware to ensure the integrity and credibility of the firmware. However, efuse hardware has disadvantages such as high cost and poor flexibility. Once burned, it cannot be modified, and it is not suitable for Internet of Things application scenarios that require frequent firmware updates or are cost-sensitive.
[0075] It should be noted that the execution subject of this embodiment can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device, a security control device, an Internet of Things device, etc. that can implement the above functions. Hereinafter, taking the Internet of Things device as an example, this embodiment and the following embodiments will be described.
[0076] Based on this, the embodiment of the present application provides a security control method, referring to Figure 1 , Figure 1 which is the schematic flowchart provided for the first embodiment of the security control method of the present application.
[0077] In this embodiment, it is applied to an Internet of Things device, and the Internet of Things device includes a security smart card.
[0078] It should be noted that the security smart card can be inserted into the Internet of Things device.
[0079] It should be noted that the security smart card can be built with a biometric identification module, such as a fingerprint recognition or iris recognition sensor, to perform biometric identification of the target user through the security smart card.
[0080] The security control method includes steps S1~S2, steps S411~S412:
[0081] Step S1, receiving a target access request;
[0082] Step S2, obtaining the operating system type of the Internet of Things device.
[0083] It should be noted that currently, there are various types of operating systems for Internet of Things devices. Different operating systems have different security levels and adopt different security measures. Therefore, corresponding security measures need to be taken based on the type of operating system of the Internet of Things device.
[0084] Step S411, if the operating system type of the Internet of Things device is the first operating system, then the security smart card is used to perform biometric identification on the target user who issues the target access request;
[0085] Optionally, the first operating system can be an operating system that requires high-precision authentication of user identities.
[0086] Step S412, if the operating system type of the Internet of Things device is the second operating system, then secondary authorization is performed on the target access request based on the security smart card.
[0087] Optionally, the second operating system can be an operating system that is difficult to prevent complex illegal memory access behaviors.
[0088] Optionally, if the operating system type of the Internet of Things device is the second operating system, then when the Internet of Things device is running, the access requests for sensitive memory can be audited through the second operating system.
[0089] Optionally, if the operating system type of the Internet of Things device is the second operating system, then when the Internet of Things device is running, the access requests for sensitive memory can be audited through the security smart card.
[0090] Optionally, if the operating system type of the Internet of Things device is the second operating system, then when the Internet of Things device is running, the access requests for sensitive memory can be audited through the second operating system and the security smart card.
[0091] By implementing different security control measures based on different operating system types and integrating biometric authentication technology into Internet of Things devices, when the operating system type of the Internet of Things device is the first operating system, user authentication is achieved by integrating a biometric identification module, such as a fingerprint recognition or iris recognition sensor, into the security smart card, thereby enhancing the security of the Internet of Things device. And when the operating system type of the Internet of Things device is the second operating system, by auditing the access requests for sensitive memory through the second operating system and / or the security smart card, a solid double-layer defense line can be constructed, upgrading from simply preventing out-of-bounds memory access to comprehensively preventing various complex illegal memory operations, including malicious programs using memory vulnerabilities for code execution, data theft, etc., significantly enhancing the integrity and confidentiality of memory data, and thus enhancing the security of the Internet of Things device.
[0092] In addition, traditional technologies usually rely on efuse hardware to ensure the integrity and credibility of firmware when IoT devices are starting up. Once the efuse is burned, it cannot be changed, which makes firmware updates extremely inconvenient and costly, especially for application scenarios that require frequent firmware iteration, and the limitations become more obvious. The embodiments of the present application abandon the dependence on efuse hardware and adopt a secure smart card as the core component to construct a SecureBoot mechanism. With its encryption function and storage characteristics, the secure smart card can not only generate and securely store the public and private key pairs during the device initialization phase, but also dynamically perform verification operations based on the firmware hash value and signature sent by the device during the subsequent startup process, greatly improving the flexibility and maintainability of the startup process, while significantly reducing the hardware cost.
[0093] The security issues of current IoT devices also include the following point:
[0094] Although SELinux provides access control policies for the operating system, there are still deficiencies in the protection of highly sensitive objects, and it is difficult to meet higher security requirements simply relying on conventional user authentication methods. At the same time, in low-cost RTOS (Real-Time Operating System) systems, the memory protection mechanism is relatively weak, and there is a lack of effective means to prevent illegal access to sensitive areas of memory.
[0095] Based on the above security issues, the embodiments of the present application are proposed.
[0096] Based on any of the above embodiments, in the second embodiment of the present application, for the same or similar content as any of the above embodiments, reference can be made to the above introduction and will not be elaborated hereinafter. On this basis, before step S3 of receiving a target access request, the security control method further includes step S1:
[0097] Step S1, perform a security verification on the IoT device;
[0098] If the IoT device passes the security verification, then execute step 3: receive the target access request.
[0099] The step S1 of performing a security verification on the IoT device includes steps S11 to S112:
[0100] Step S11, initialize the IoT device, and generate a public key, a private key, and a symmetric key through the secure smart card;
[0101] Step S12, store the private key and the symmetric key in a secure storage area through the secure smart card.
[0102] It should be noted that the secure smart card is built with an encryption module. During the initialization phase of the Internet of Things (IoT) device, a pair of public and private keys (denoted as and ) are generated using the true random number generator within the card. The private key is permanently stored in the secure storage area of the smart card, which employs hardware encryption technology to prevent external unauthorized access.
[0103] The public key can then be securely exported to the trusted storage area of the device (such as a specific secure partition in the read-only memory of the IoT device) when needed.
[0104] Meanwhile, the secure smart card also generates a device-specific symmetric key for subsequent secure communication between the IoT device and the secure smart card. This symmetric key is also stored in the secure area of the smart card and undergoes key negotiation with the IoT device during the first startup of the IoT device to ensure that both parties share the same key.
[0105] Step S13: Compile the firmware of the IoT device;
[0106] Step S14: Calculate the hash value of the firmware;
[0107] Among them, after the firmware of the IoT device is compiled, the hash value of the firmware (denoted as ) is calculated by the hash function built into the compilation toolchain of the IoT device.
[0108] Optionally, the hash function can select secure hash algorithms such as SHA-256 / SM3 to ensure the uniqueness and collision resistance of the hash value.
[0109] Step S15: Sign the hash value of the firmware by the secure smart card based on the pre-generated private key to generate a signature value;
[0110] Next, the IoT device sends to the secure smart card, and the secure smart card uses the pre-generated private key to sign to generate a signature value , and returns it to the IoT device.
[0111] Step S16: Store the signature value and the hash value of the firmware in the firmware storage area;
[0112] Among them, there is a firmware storage area in the IoT device, and the IoT device stores and together in the firmware storage area of the IoT device, associated with the firmware itself.
[0113] Step S17, when the Internet of Things device is started, load the firmware and extract the signature value from the firmware storage area;
[0114] Reference can be made to Figure 2 , Figure 2 , which is a schematic flow diagram for startup verification in the security control method of this application.
[0115] Among them, when the device is powered on and started, the bootloader first loads the firmware and extracts the signature value and the hash value of the firmware .
[0116] Among them, reference can be made to Figure 3 , Figure 3 , which is a schematic structural diagram of the Internet of Things device in this application. In Figure 3 , the Internet of Things device includes a security smart card, a main chip, and a biometric module. Among them, the main chip includes a Bootloader and a main operating system. Among them, the Bootloader and the security smart card interact to achieve the secure startup of the Internet of Things device.
[0117] Step S18, obtain the device identifier of the Internet of Things device;
[0118] Among them, the device identifier of the Internet of Things device can be set to .
[0119] Then, the Bootloader sends a startup verification request to the security smart card, and the request contains the hash value of the firmware and the device identifier .
[0120] Step S19, verify whether the device identifier matches the authorized device list pre-stored in the security smart card through the security smart card;
[0121] Among them, after receiving the request, the security smart card first verifies the device identifier to determine whether it matches the authorized device list pre-stored in the card to ensure the legitimacy of the device.
[0122] Among them, verifying the device identifier each time the Internet of Things device is started is equivalent to setting a dynamic device authentication function. Only devices pre-registered and authorized in the security smart card can be unlocked and started, eliminating the possibility of illegal devices accessing the Internet of Things network, reducing security risks such as data leakage and network attacks caused by illegal access, and ensuring the boundary security of the entire Internet of Things system.
[0123] Step S110, if the match is successful, the security smart card verifies the signature value based on the public key;
[0124] If the match is successful, the security smart card uses the public key to verify the signature value , that is, to verify whether the signature value is generated using the corresponding private key and matches the hash value of the firmware .
[0125] Step S111, if the verification passes, the Internet of Things device passes the security verification;
[0126] If the signature value verification passes, it indicates that the firmware is complete and not tampered with. The security smart card returns a verification passed signal to the Bootloader, allowing the Internet of Things device to continue starting up.
[0127] Step S112, if the verification fails, the Internet of Things device fails the security verification, prevents the Internet of Things device from starting up, and records the relevant security events in the security audit log of the security smart card.
[0128] If the signature value verification fails, the security smart card sends an alarm signal to the Bootloader to prevent the Internet of Things device from starting up, and can choose to record the relevant security events in the security audit log of the security smart card for subsequent analysis.
[0129] In the embodiment of the present application, by abandoning the traditional efuse hardware dependence and adopting a security smart card to construct a SecureBoot mechanism, during the startup of the Internet of Things device, based on the dynamic verification process of the public-private key pair and the firmware hash value, it is ensured that the loaded firmware is not tampered with.
[0130] By abandoning the traditional efuse hardware dependence, the embodiment of the present application adopts a security smart card to construct a SecureBoot mechanism. During the startup of the Internet of Things device, based on the dynamic verification process of the public-private key pair and the firmware hash value, it is ensured that the loaded firmware is not tampered with. Whether facing malicious software attempting to implant code during the startup phase or firmware damage caused by accidental factors, it can be accurately identified and effectively prevent the device from being attacked from the startup source.
[0131] Compared with the traditional static SecureBoot verification method, the embodiments of the present application introduce a dynamic Internet of Things device authentication and security auditing function. When an Internet of Things device starts up each time, the security smart card not only verifies the integrity of the firmware, but also verifies the device identifier to ensure that only legally authorized devices can start, effectively preventing the access of illegal devices. Moreover, once a verification failure is detected, the security smart card can immediately record relevant security events in the audit log, providing a strong basis for subsequent troubleshooting and security analysis. This is the active defense and post-event traceability capabilities lacking in traditional technologies.
[0132] In addition, the feature of immediately recording security events in the audit log in the embodiments of the present application provides clear clues for accident backtracking for operation and maintenance personnel. Once a device startup anomaly occurs, the root cause of the problem can be quickly located through the audit log, whether the firmware has been tampered with, the device identity has been stolen, or other reasons are clear at a glance. At the same time, long-term analysis of the audit data can also discover potential security trends and early warning of possible large-scale security events.
[0133] Based on any of the above embodiments, in the third embodiment of the present application, the same or similar content as any of the above embodiments can be referred to the above introduction and will not be repeated hereinafter. On this basis, the first operating system is a security-enhanced Linux system, and the biometric identification of the target user who issues the target access request through the security smart card includes steps S4113 to S4118:
[0134] Step S4113, receiving a request from the target user to access a highly sensitive object;
[0135] It should be noted that for the security-enhanced Linux system, the embodiments of the present application formulate corresponding security policies for the security-enhanced Linux system.
[0136] Among them, for highly sensitive protected objects in Internet of Things devices, such as sensitive data files, key system processes, etc., rules related to biometric authentication are added to the SELinux policy file. These rules stipulate that only when the user passes the biometric identification of the security smart card and the verification result matches the pre-stored biometric template, can the corresponding highly sensitive object be accessed.
[0137] For example, for a medical Internet of Things device, the file storing patient privacy data is defined as a highly sensitive object, and the SELinux policy stipulates that only medical staff who have passed the biometric authentication of the security smart card can access the file in a read-only manner to prevent data leakage.
[0138] Refer to Figure 4 , Figure 4It is a schematic flowchart of biometric identification for the security control method of this application. In Figure 4 when a user attempts to access a highly sensitive object, SELinux first detects and receives the access request, and sends a biometric authentication request to the security smart card. The request contains relevant information of the access request (such as access object identifier, access type, etc.).
[0139] Step S4114, activate the biometric identification module through the security smart card;
[0140] Step S4115, collect biometric information of the target user through the biometric identification module;
[0141] Step S4116, compare the biometric information with the pre-stored biometric template through the security smart card;
[0142] Among them, the security smart card activates the biometric identification module, collects the current biometric information of the user, and compares it with the pre-stored biometric template.
[0143] Step S4117, if the comparison is successful, allow the target user to access the highly sensitive object through the security-enhanced Linux system according to the preset access control rules;
[0144] Among them, if the comparison is successful, the security smart card returns a signal of authentication passed to SELinux, and SELinux allows the user to access the highly sensitive object according to the normal access control rules.
[0145] Step S4118, if the comparison fails, reject the access request of the target user through the security-enhanced Linux system, and record the relevant security events in the security audit log of the security smart card.
[0146] If the comparison fails, the security smart card returns a signal of authentication failed to SELinux. SELinux rejects the user's access request and records the relevant security events in the audit log of the smart card for subsequent tracking and analysis.
[0147] Previously, SELinux mainly relied on conventional user authentication means, such as username-password combinations, to control access to system resources. However, this approach is vulnerable to security risks such as password cracking and impersonation when dealing with highly sensitive objects. In the embodiments of this application, biometric authentication technology is integrated into the SELinux policy system. By embedding a high-precision biometric identification module, such as a fingerprint recognition or iris recognition sensor, in a security smart card, user authentication is achieved. Only when the user passes the biometric identification of the smart card and the biometric features match the template pre-stored in the card is access to highly sensitive objects permitted, enhancing the security and accuracy of authentication.
[0148] In addition, traditional SELinux policies are relatively fixed during device operation and are difficult to flexibly adjust according to real-time security requirements. The embodiments of this application endow SELinux policies with the ability to dynamically adapt. By leveraging the storage and computing functions of the security smart card, diverse and customized access policy rules are pre-stored in the security smart card. During the operation of Internet of Things devices, according to different access scenarios and user behaviors, the security smart card can provide adaptive policies to SELinux in real time, ensuring effective response to complex and changing security threats, which is a dynamic protection advantage that traditional SELinux cannot match.
[0149] Among them, relying on the ability of the security smart card to store and distribute policies, SELinux policies can dynamically adapt according to the real-time operating state of the device and user behaviors. In the Internet of Things scenario with multiple users and multiple tasks, different users have different requirements for system resources. The policies provided by the smart card in real time can not only ensure that highly sensitive resources are not illegally accessed, but also flexibly allocate ordinary resources, improving the overall operating efficiency of the system and avoiding affecting device performance due to overly strict or loose access control.
[0150] Based on any of the above embodiments, in Embodiment 4 of this application, for content that is the same as or similar to any of the above embodiments, reference can be made to the above introduction and will not be elaborated hereinafter. On this basis, before step S4113 of receiving a request from the target user to access a highly sensitive object, the security control method further includes steps S4111~S4112:
[0151] Step S4111, receiving a biometric feature registration request from the target user through the biometric identification module to obtain the biometric feature template;
[0152] Step S4112, storing the biometric feature template in the secure storage area of the security smart card.
[0153] Among them, the secure smart card is built with a biometric identification module, such as a fingerprint recognition sensor or a high-precision iris recognition module (selected according to application scenarios and cost requirements). These modules have advanced biometric collection and preprocessing functions, and can quickly and accurately collect users' biometric information.
[0154] Before the device runs, the user needs to register their biometric characteristics on the biometric identification module of the secure smart card, and store their biometric templates (such as fingerprint templates or iris templates) in the secure storage area of the secure smart card. This area is similar to the key storage area and adopts multi-layer encryption protection to ensure the security of biometric templates.
[0155] Integrating biometric authentication technology into the SELinux policy system, with the help of the biometric identification module built in the secure smart card, the user identity verification is realized. Compared with the traditional username-password method, biometric characteristics such as fingerprints and irises are unique and non-replicable, reducing the risk of identity fraud, ensuring that only legitimate authorized users can access highly sensitive data, such as patient privacy information in the medical Internet of Things and transaction data in the financial Internet of Things, and enhancing the confidentiality of highly sensitive data.
[0156] Based on any of the above embodiments, in the fifth embodiment of the present application, the content that is the same as or similar to any of the above embodiments can be referred to the above introduction and will not be repeated hereinafter. On this basis, the second operating system is a real-time operating system. The secondary authorization of the target access request based on the secure smart card includes steps S4121 to S4124:
[0157] Step S4121, when receiving an access request to the memory in the sensitive area, perform a preliminary review through the memory protection unit of the real-time operating system according to the preset memory access control rules;
[0158] Among them, in the low-cost real-time operating system RTOS system, a dedicated driver is developed to achieve a tight connection between the secure smart card and the real-time operating system RTOS. This driver provides a series of APIs (application programming interfaces) for the RTOS to send memory access requests to the secure smart card and receive the authorization results of the secure smart card. Refer to Figure 3 , Figure 3 is a schematic structural diagram of the Internet of Things device of the present application. In Figure 3 , the real-time operating system is the main operating system, and the real-time operating system can receive the authorization results of the secure smart card through the driver.
[0159] The driver defines the function SendMemoryAccessRequest(address, size,access_type), where address indicates the memory address requested for access, size indicates the size of the memory area requested for access, and access_type indicates the access type (such as read, write, execute, etc.). At the same time, the function ReceiveAuthorizationResult() is defined to receive the authorization result returned by the smart card.
[0160] It should be noted that when an application initiates an access request to sensitive memory in the RTOS system, the RTOS MPU will first conduct a preliminary review according to the conventional memory access control rules. If the preliminary review is passed, it means that the access request initially meets the memory protection requirements at the RTOS level.
[0161] Step S4122, if the preliminary review is passed, a secondary review is performed through the secure smart card according to a preset memory access authorization policy;
[0162] Next, the RTOS sends a memory access request to the secure smart card through the driver. After the secure smart card receives the request, it performs a secondary review based on the memory access authorization policy pre-stored in the card.
[0163] Among them, the memory access authorization policy can be customized according to the functions and security requirements of the device. For example, for some key system variable storage areas, only specific system processes can access them at specific running stages.
[0164] Step S4123: if the secondary review is passed, the access request to the sensitive area memory is allowed through the real-time operating system;
[0165] Step S4124: If the secondary audit fails, the access request to the sensitive area memory is rejected by the real-time operating system, and the relevant security event is recorded in the security audit log of the secure smart card.
[0166] After the smart card audit is completed, the driver returns the authorization result to the RTOS. If the authorization result is passed, the RTOS allows the application to perform the final memory access; otherwise, the RTOS denies the application's access request and can choose to record related security events in the smart card audit log for subsequent analysis.
[0167] In a low-cost RTOS system, the traditional memory protection mechanism relies solely on the MPU for single-level access control, which is somewhat insufficient for guarding against complex illegal memory access behaviors. The embodiment of this application introduces a secondary authorization mechanism for MPU access by a secure smart card. When an application initiates a memory access request to a sensitive area, the MPU first conducts a preliminary compliance review. After passing, the RTOS sends a detailed memory access request to the secure smart card through a specially developed driver. The smart card conducts a secondary in-depth review of the request based on a pre-customized memory access authorization policy, comprehensively considering multi-dimensional factors such as the access time, process, and memory area. Only after the secondary review passes is the final memory access permitted, thereby enhancing the reliability of memory protection.
[0168] In addition, different from the isolated memory protection mode of traditional technologies, the embodiment of this application emphasizes the close driver cooperation between the secure smart card and the RTOS. Through a specially designed driver, the smart card and the RTOS are interconnected, and a series of API functions such as sending memory access requests and receiving authorization results are defined to achieve efficient and secure interaction between the two. This driver cooperation mode ensures the smooth operation of the secondary authorization mechanism, enabling the secure smart card and the MPU to form an organic whole.
[0169] In addition, the secondary authorization mechanism for MPU access introduced by the secure smart card in the low-cost RTOS system improves the security of memory data. The preliminary compliance review of the MPU combined with the secondary in-depth review of the smart card comprehensively considers multi-dimensional factors, upgrading from simply preventing memory out-of-bounds access to comprehensively guarding against various complex illegal memory operations, including malicious programs using memory vulnerabilities for code execution, data theft, etc., significantly enhancing the integrity and confidentiality of memory data.
[0170] In addition, the driver realizes the close cooperation between the secure smart card and the RTOS, promoting interaction with concise API functions. This cooperation mode enables the secondary authorization mechanism to operate smoothly, reducing security vulnerabilities caused by problems such as poor communication and incompatible interfaces, and at the same time reducing the difficulty for developers to integrate the secure smart card and the RTOS.
[0171] It should be noted that the above examples are only for understanding this application and do not constitute a limitation on the security control method of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0172] This application also provides a security control device. Please refer to Figure 5 and is set in an Internet of Things device. The Internet of Things device includes a secure smart card. The security control device includes:
[0173] A request receiving module 10, configured to receive a target access request; and obtain the operating system type of the Internet of Things device.
[0174] A request control module 20, configured to perform biometric identification on a target user who issues the target access request through the security smart card if the operating system type of the Internet of Things device is a first operating system; and perform secondary authorization on the target access request based on the security smart card if the operating system type of the Internet of Things device is a second operating system.
[0175] The security control device provided in this application adopts the security control method in the above embodiment, and can solve the technical problem of low security of Internet of Things devices. Compared with the prior art, the beneficial effects of the security control device provided in this application are the same as those of the security control method provided in the above embodiment, and other technical features in the security control device are the same as those disclosed in the above embodiment method, which will not be elaborated here.
[0176] This application provides a security control device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the security control method in the first embodiment above.
[0177] Next, refer to Figure 6 , which shows a schematic structural diagram of a security control device suitable for implementing the embodiments of this application. The security control device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (tablet computers), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 6 The security control device shown is only an example, and should not impose any limitations on the functions and usage scope of the embodiments of this application.
[0178] As Figure 6As shown, the security control device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory 1002 or the program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the xxx device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems can be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the security control device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a security control device with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems can be alternatively implemented or had.
[0179] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the methods of the embodiments disclosed in the present application are executed.
[0180] The security control device provided by the present application adopts the security control method in the above-mentioned embodiment, and can solve the technical problem of low security of Internet of Things devices. Compared with the prior art, the beneficial effects of the security control device provided by the present application are the same as those of the security control method provided by the above-mentioned embodiment, and other technical features in the security control device are the same as those disclosed in the method of the previous embodiment, and will not be elaborated here.
[0181] It should be understood that each part disclosed in the present application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0182] As described above, this is only the specific implementation manner of the present application. However, the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of changes or substitutions, which should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the protection scope of the claims.
[0183] The present application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the security control method in the above embodiments.
[0184] The computer-readable storage medium provided by the present application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems or devices, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.
[0185] The above computer-readable storage medium can be included in the security control device; or it can exist separately without being assembled into the security control device.
[0186] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by the security control device, the security control device is caused to: receive a target access request; obtain the operating system type of the Internet of Things device; if the operating system type of the Internet of Things device is the first operating system, perform biometric identification on the target user who issues the target access request through the security smart card; if the operating system type of the Internet of Things device is the second operating system, perform secondary authorization on the target access request based on the security smart card.
[0187] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by connecting through an Internet service provider using the Internet).
[0188] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutively represented blocks may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0189] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0190] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for performing the above-mentioned security control method, and can solve the technical problem of low security of Internet of Things devices. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the security control method provided by the above embodiments, and will not be elaborated here.
[0191] The above are only some embodiments of the present application, and thus do not limit the patent scope of the present application. Any equivalent structural transformation made under the technical concept of the present application by using the content of the specification and drawings of the present application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of the present application.
Claims
1. A security control method, characterized in that, Applied to an Internet of Things device, the Internet of Things device includes a security smart card, and the method includes the following steps: Receive a target access request; Obtain the operating system type of the Internet of Things device; If the operating system type of the Internet of Things device is the first operating system, perform biometric identification on the target user who issues the target access request through the security smart card; If the operating system type of the Internet of Things device is the second operating system, and the second operating system is a real-time operating system, perform secondary authorization on the target access request based on the security smart card, including: Perform a preliminary review of the target access request through the memory protection unit of the real-time operating system according to preset memory access control rules; If the preliminary review is passed, send a memory access request to the security smart card through the driver of the real-time operating system, so that after receiving the request, the security smart card performs a secondary review of the target access request according to the preset memory access authorization policy; If the secondary review is passed, accept the target access request through the real-time operating system; If the secondary review is not passed, reject the target access request through the real-time operating system, and record the relevant security event in the security audit log of the security smart card.
2. The method according to claim 1, characterized in that, Before the step of receiving the target access request includes: Perform a security verification on the Internet of Things device; If the Internet of Things device passes the security verification, execute the step: receive the target access request.
3. The method according to claim 2, wherein The step of performing a security verification on the Internet of Things device includes: Initialize the Internet of Things device, and generate a public key, a private key, and a symmetric key through the security smart card; Store the private key and the symmetric key in a secure storage area through the security smart card; Compile the firmware of the Internet of Things device; Calculate the hash value of the firmware; Sign the hash value of the firmware through the security smart card based on the pre-generated private key to generate a signature value; Store the signature value and the hash value of the firmware in the firmware storage area; When the Internet of Things device starts up, load the firmware, and extract the signature value from the firmware storage area; Obtain the device identifier of the Internet of Things device; Verify whether the device identifier matches the authorized device list pre-stored in the security smart card through the security smart card; If the match is successful, verify the signature value based on the public key through the security smart card; If the verification is passed, the Internet of Things device passes the security verification; If the verification fails, the Internet of Things device fails the security verification, prevents the Internet of Things device from starting up, and records the relevant security event in the security audit log of the security smart card.
4. The method according to claim 1, characterized in that, The first operating system is a security-enhanced Linux system, and the step of performing biometric identification on the target user who issues the target access request through the security smart card includes: Receive the request of the target user to access a highly sensitive object; Activate the biometric identification module through the security smart card; Collect the biometric information of the target user through the biometric identification module; Compare the biometric information with a pre-stored biometric template through the security smart card; If the comparison is successful, allow the target user to access the highly sensitive object through the security-enhanced Linux system according to preset access control rules; If the comparison fails, reject the access request of the target user through the security-enhanced Linux system and record the relevant security events in the security audit log of the security smart card.
5. The method according to claim 4, wherein Before the step of receiving the request from the target user to access the highly sensitive object, the following steps are included: Receive a biometric registration request from the target user through the biometric identification module to obtain the biometric template; Store the biometric template in the secure storage area of the security smart card.
6. A security control device, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the security control method according to any one of claims 1 to 5.
7. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the security control method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Multi-system login method and device, storage medium and program product
CN119583150A