Data access method, device, medium and device executed by edge device

By establishing a secure communication connection between edge devices and the cloud and performing trusted verification, the problem of network attacks during edge device data access is solved, achieving higher security and trusted data access.

CN119808061BActive Publication Date: 2025-09-16BEIJING BAIDU NETCOM SCI & TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411855717.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-16
Publication Date
2025-09-16
Estimated Expiration
2044-12-16

AI Technical Summary

Technical Problem

Edge devices face the risk of attacks from cyber criminals during data access, and existing technologies are difficult to effectively improve the security of data access.

Method used

A secure communication connection is established between the edge device and the cloud, the first application is used for trusted verification, the feature information of the second application is obtained and authenticated with the cloud to ensure the security of data access.

Benefits of technology

It improves the security of data access on edge devices, prevents illegal intrusion and tampering, and ensures the credibility of data access rights.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119808061B_ABST
    Figure CN119808061B_ABST
Patent Text Reader

Abstract

The present disclosure provides a data access method, apparatus, medium, and device executed by an edge device, relating to the fields of computer technology, particularly edge computing, remote access, data security, and other technical fields. The implementation scheme comprises: establishing a secure communication connection with the cloud via a first application; in response to receiving a data access request from a second application, performing trustworthy verification on the current first application; in response to the first application passing the trustworthy verification, obtaining a first current value of first feature information of the second application based on the first application; sending a first authentication request to the cloud via the first application; and in response to the first application receiving the verification result sent by the cloud, authorizing the second application to access the data.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of computer technology, in particular to technical fields such as edge computing, remote access, and data security, and specifically to a data access method, apparatus, electronic device, computer-readable storage medium, and computer program product executed by an edge device. Background Art

[0002] With the rise of edge computing, more and more data and applications are generated and processed at the edge. Edge devices are used in a wide range of applications, including smart homes, smart cities, industrial internet, healthcare, agriculture, retail, transportation and logistics, energy management, environmental monitoring, and public safety.

[0003] The ease of deploying edge devices, on the one hand, brings enormous computing and storage capabilities to edge networks, enabling the creation of higher-bandwidth and lower-latency applications; on the other hand, it also increases the attack surface for cybercriminals, who can exploit more entry points to infiltrate the network, making it a very viable target for attack.

[0004] The approaches described in this section are not necessarily approaches that have been previously conceived or employed. Unless otherwise indicated, it should not be assumed that any approach described in this section is prior art simply by virtue of its inclusion in this section. Similarly, unless otherwise indicated, the issues raised in this section should not be considered as having been recognized in any prior art. Summary of the Invention

[0005] The present disclosure provides a data access method, apparatus, electronic device, computer-readable storage medium, and computer program product executed by an edge device.

[0006] According to one aspect of the present disclosure, a data access method performed by an edge device is provided, including: establishing a secure communication connection with the cloud through a first application; in response to receiving a data access request from a second application, performing trusted verification on the current first application; in response to the first application passing the trusted verification, obtaining a first current value of the first characteristic information of the second application based on the first application, the first characteristic information including at least one of the running directory of the second application, the directory to be accessed, and the device information of the edge device; sending a first authentication request to the cloud through the first application, the first authentication request including the first current value, and the cloud storing the first initial value of the first characteristic information; and in response to the first application receiving the verification result sent by the cloud, authorizing the second application to access the data, the verification result including that the first current value is consistent with the first initial value.

[0007] According to another aspect of the present disclosure, a data access apparatus executed by an edge device is provided, comprising: a connection establishing unit, configured to establish a secure communication connection with a cloud through a first application; a first verification unit, configured to perform trusted verification on the current first application in response to receiving a data access request from a second application; a first acquisition unit, configured to obtain a first current value of first characteristic information of the second application based on the first application in response to the first application passing the trusted verification, the first characteristic information including at least one of the running directory of the second application, the directory to be accessed, and the device information of the edge device; a first sending unit, configured to send a first authentication request to the cloud through the first application, the first authentication request including the first current value, and the cloud storing the first initial value of the first characteristic information; and a first authorization unit, configured to authorize the second application to access the data in response to the first application receiving a verification result sent by the cloud, the verification result including that the first current value is consistent with the first initial value.

[0008] According to another aspect of the present disclosure, an electronic device is provided, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the data access method performed by the edge device of the present disclosure.

[0009] According to another aspect of the present disclosure, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause a computer to execute the data access method performed by an edge device of the present disclosure.

[0010] According to another aspect of the present disclosure, a computer program product is provided, including a computer program, wherein when the computer program is executed by a processor, the computer program implements the data access method performed by the edge device of the present disclosure.

[0011] According to one or more embodiments of the present disclosure, the security of edge device data access can be improved.

[0012] It should be understood that the contents described in this section are not intended to identify the key or important features of the embodiments of the present disclosure, nor are they intended to limit the scope of the present disclosure. Other features of the present disclosure will become readily understood through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0013] The accompanying drawings illustrate exemplary embodiments and constitute a part of the specification. Together with the description of the specification, they serve to explain exemplary implementation of the embodiments. The illustrated embodiments are for illustrative purposes only and do not limit the scope of the claims. Throughout the drawings, the same reference numerals designate similar, but not necessarily identical, elements.

[0014] Figure 1 A schematic diagram illustrating an exemplary system in which the various methods described herein may be implemented according to an embodiment of the present disclosure;

[0015] Figure 2 A flow chart of a data access method performed by an edge device according to an embodiment of the present disclosure is shown;

[0016] Figure 3 A schematic structural diagram of a data access system according to an exemplary embodiment of the present disclosure is shown;

[0017] Figure 4 A flowchart of establishing a secure communication connection with the cloud according to an embodiment of the present disclosure is shown;

[0018] Figure 5 A flowchart of establishing a secure communication connection with the cloud according to an embodiment of the present disclosure is shown;

[0019] Figure 6 A structural block diagram of a data access apparatus executed by an edge device according to an embodiment of the present disclosure is shown;

[0020] Figure 7 A structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present disclosure is shown. DETAILED DESCRIPTION

[0021] The following description of exemplary embodiments of the present disclosure is made in conjunction with the accompanying drawings, including various details of the embodiments of the present disclosure to facilitate understanding, which should be considered as merely exemplary. Therefore, it should be appreciated by those skilled in the art that various changes and modifications may be made to the embodiments described herein without departing from the scope of the present disclosure. Similarly, for the sake of clarity and conciseness, descriptions of well-known functions and structures are omitted in the following description.

[0022] In this disclosure, unless otherwise specified, the use of terms such as "first" and "second" to describe various elements is not intended to limit the positional relationship, temporal relationship, or importance relationship of these elements. Such terms are only used to distinguish one element from another. In some examples, the first element and the second element may refer to the same instance of the element, while in some cases, based on the context of the description, they may also refer to different instances.

[0023] The terms used in the descriptions of the various examples described in this disclosure are for the purpose of describing specific examples only and are not intended to be limiting. Unless the context clearly indicates otherwise, if the number of elements is not specifically limited, the element may be one or more. In addition, the term "and / or" used in this disclosure encompasses any one and all possible combinations of the listed items.

[0024] The embodiments of the present disclosure will be described in detail below with reference to the accompanying drawings.

[0025] Figure 1 FIG2 is a schematic diagram of an exemplary system 100 in which the various methods and apparatuses described herein may be implemented according to an embodiment of the present disclosure. Figure 1 , the system 100 includes one or more client devices 101, 102, 103, 104, 105, and 106, a server 120, and one or more communication networks 110 coupling the one or more client devices to the server 120. The client devices 101, 102, 103, 104, 105, and 106 can be configured to execute one or more applications.

[0026] In an embodiment of the present disclosure, the server 120 may run one or more services or software applications that enable the data access method of the present disclosure to be performed by the edge device.

[0027] In some embodiments, server 120 may also provide other services or software applications, which may include non-virtualized environments and virtualized environments. In some embodiments, these services may be provided as web-based services or cloud services, such as provided to users of client devices 101, 102, 103, 104, 105, and / or 106 under a software as a service (SaaS) model.

[0028] exist Figure 1 In the configuration shown, the server 120 may include one or more components that implement the functions performed by the server 120. These components may include software components, hardware components, or a combination thereof that can be executed by one or more processors. Users operating client devices 101, 102, 103, 104, 105, and / or 106 may, in turn, utilize one or more client applications to interact with the server 120 to utilize the services provided by these components. It should be understood that a variety of different system configurations are possible, which may differ from the system 100. Therefore, Figure 1 is one example of a system for implementing the various methods described herein and is not intended to be limiting.

[0029] A user may submit a data access request using client devices 101, 102, 103, 104, 105, and / or 106. The client device may provide an interface that enables a user of the client device to interact with the client device. The client device may also output information to the user via the interface. Figure 1 Only six client devices are depicted, but one skilled in the art will appreciate that the present disclosure can support any number of client devices.

[0030] Client devices 101, 102, 103, 104, 105, and / or 106 may include various types of computer devices, such as portable handheld devices, general-purpose computers (such as personal computers and laptops), workstation computers, wearable devices, smart screen devices, self-service terminal devices, service robots, gaming systems, thin clients, various messaging devices, sensors or other sensing devices, etc. These computer devices may run various types and versions of software applications and operating systems, such as Microsoft Windows, Apple iOS, UNIX-like operating systems, Linux, or Linux-like operating systems (such as Google Chrome OS); or include various mobile operating systems, such as Microsoft Windows Mobile OS, iOS, Windows Phone, and Android. Portable handheld devices may include cellular phones, smartphones, tablet computers, personal digital assistants (PDAs), etc. Wearable devices may include head-mounted displays (such as smart glasses) and other devices. Gaming systems may include various handheld gaming devices, internet-enabled gaming devices, etc. Client devices are capable of executing a variety of different applications, such as various internet-related applications, communication applications (such as email applications), and short message service (SMS) applications, and may use various communication protocols.

[0031] The network 110 may be any type of network known to those skilled in the art that can support data communications using any of a variety of available protocols, including but not limited to TCP / IP, SNA, IPX, etc. By way of example only, the one or more networks 110 may be a local area network (LAN), an Ethernet-based network, a token ring, a wide area network (WAN), the Internet, a virtual network, a virtual private network (VPN), an intranet, an extranet, a blockchain network, a public switched telephone network (PSTN), an infrared network, a wireless network (e.g., Bluetooth, WIFI), and / or any combination of these and / or other networks.

[0032] Server 120 may include one or more general-purpose computers, specialized server computers (e.g., PC (personal computer) servers, UNIX servers, mid-range servers), blade servers, mainframe computers, server clusters, or any other suitable arrangement and / or combination. Server 120 may include one or more virtual machines running virtual operating systems, or other computing architectures involving virtualization (e.g., one or more flexible pools of logical storage devices that may be virtualized to maintain a server's virtual storage device). In various embodiments, server 120 may run one or more services or software applications that provide the functionality described below.

[0033] The computing units in the server 120 may run one or more operating systems including any of the operating systems described above as well as any commercially available server operating systems. The server 120 may also run any of a variety of additional server applications and / or middle-tier applications, including HTTP servers, FTP servers, CGI servers, JAVA servers, database servers, and the like.

[0034] In some implementations, server 120 may include one or more applications to analyze and consolidate data feeds and / or event updates received from users of client devices 101, 102, 103, 104, 105, and / or 106. Server 120 may also include one or more applications to display the data feeds and / or real-time events via one or more display devices of client devices 101, 102, 103, 104, 105, and / or 106.

[0035] In some embodiments, server 120 may be a distributed system server or a server integrated with blockchain. Server 120 may also be a cloud server, or an intelligent cloud computing server or intelligent cloud host equipped with artificial intelligence technology. A cloud server is a host product within the cloud computing service system that addresses the management difficulties and poor scalability of traditional physical hosts and virtual private servers (VPS) services.

[0036] The system 100 may also include one or more databases 130. In some embodiments, these databases may be used to store data and other information. For example, one or more of the databases 130 may be used to store information such as audio files and video files. The databases 130 may reside in a variety of locations. For example, the database used by the server 120 may be local to the server 120, or may be remote from the server 120 and communicate with the server 120 via a network-based or dedicated connection. The databases 130 may be of different types. In some embodiments, the databases used by the server 120 may be, for example, relational databases. One or more of these databases may store, update, and retrieve data to and from the databases in response to commands.

[0037] In some embodiments, one or more of the databases 130 may also be used by applications to store application data. The databases used by the applications may be different types of databases, such as a key-value store, an object store, or a conventional store backed by a file system.

[0038] Figure 1 The system 100 may be configured and operated in various ways to enable application of the various methods and apparatuses described in accordance with the present disclosure.

[0039] According to the embodiments of the present disclosure, Figure 2 As shown, a data access method performed by an edge device is provided, including: step S201, establishing a secure communication connection with the cloud through a first application; step S202, in response to receiving a data access request from a second application, performing trusted verification on the current first application; step S203, in response to the first application passing the trusted verification, obtaining a first current value of the first characteristic information of the second application based on the first application, the first characteristic information including at least one of the running directory of the second application, the directory to be accessed, and the device information of the edge device; step S204, sending a first authentication request to the cloud through the first application, the first authentication request including the first current value, and the cloud storing the first initial value of the first characteristic information; and step S205, in response to the first application receiving the verification result sent by the cloud, authorizing the second application to access the data, the verification result including that the first current value is consistent with the first initial value.

[0040] Therefore, after establishing a secure communication connection with the cloud, when the second application on the edge device needs to access data, it first verifies the credibility of the first application, and on the basis of the credibility of the first application, collects and uploads the first current value of the first feature information of the second application based on the first application, thereby further improving the security and credibility of the first current value. Verifying data access rights based on the first current value can further improve the security of edge device data access.

[0041] Figure 3 A structural diagram of a data access system according to an exemplary embodiment of the present disclosure is shown.

[0042] In some embodiments, the first application may be a file management system used to enable edge devices, especially edge devices located in a third-party network environment, to access data stored in cloud services through the first application in edge computing scenarios.

[0043] In some exemplary embodiments, the first application can be a file management system based on the Filesystem in Userspace (FUSE) framework. Based on the first application, the edge device and the second application deployed on it can be trusted and authenticated. After the authentication is passed, the user can access and read data from the cloud.

[0044] In some embodiments, the second application can be any application deployed on the edge device, such as a neural network model or document editing software, etc., without limitation herein.

[0045] In some embodiments, see Figure 3 , one or more second applications can be deployed on the same edge device.

[0046] In some embodiments, the cloud may be a cloud database or a cloud object storage service (OSS) service, which may provide services including but not limited to data storage, identity authentication, and key management.

[0047] In some embodiments, establishing a secure communication connection with the cloud through the first application may be based on the first application uploading a client certificate stored on the edge device to the cloud for identity authentication.

[0048] In some embodiments, in response to receiving a data access request from a second application, trust verification of the current first application may include obtaining relevant information (e.g., program code) of the first application and comparing it with corresponding initial information. If the information is consistent with the initial information, the first application may be deemed to have passed the trust verification. The initial information may be obtained and stored when the first application is deployed.

[0049] In some embodiments, the initial information may be stored in a hard disk on the edge device. In some embodiments, the initial information may also be stored in a secure storage device on the edge device to prevent tampering.

[0050] In response to the first application passing the trusted verification, the first current value of the first characteristic information of the second application can be obtained based on the first application, wherein the first characteristic information may include one or more of the running directory of the second application, the directory to be accessed by the second application, and the device information of the edge device.

[0051] In some embodiments, the first feature information may include the running directory of the second application, the target directory to be accessed by the second application, and device information of the edge device (such as CPU information, etc.).

[0052] In some embodiments, the first feature information may further include program code of the second application.

[0053] In some embodiments, the first initial value of the first feature information may be obtained and uploaded to the cloud by the first application that has undergone trustworthy verification when the second application is deployed.

[0054] In some embodiments, the first current value and the first initial value may be hash values ​​obtained by performing hash calculation on the original data of the corresponding first feature information collected.

[0055] After the first application obtains the first current value, it can send a first authentication request to the cloud to request the authentication center in the cloud to compare the first current value and the first initial value of the first characteristic information to verify the identity and authority of the second application, determine whether the current second application has been tampered with, and whether the current second application has the authority to access the target directory to be accessed.

[0056] In response to the cloud determining that the first current value of the second application is completely consistent with the first initial value, the second application is judged to have passed the verification and the verification result is sent to the edge device. After the first application in the edge device receives the verification result sent by the cloud, it can authorize the second application to access data in the target directory.

[0057] The target directory can be a cloud storage directory or a directory on an edge device, and there is no restriction here.

[0058] Therefore, after establishing a secure communication connection with the cloud, when the second application on the edge device needs to access data, it first verifies the credibility of the first application, and on the basis of the credibility of the first application, collects and uploads the first current value of the first feature information of the second application based on the first application, thereby further improving the security and credibility of the first current value. Verifying data access rights based on the first current value can further improve the security of edge device data access.

[0059] In some embodiments, in response to the first application failing the trusted verification, no subsequent verification operation is performed, and a corresponding prompt message may be sent to relevant technical personnel.

[0060] In some embodiments, as Figure 4 As shown, establishing a secure communication connection with the cloud through the first application may include: step S401, in response to receiving a communication connection establishment request, based on the secure storage device in the edge device, determining whether the third current value of the third characteristic information of the edge device is consistent with the third initial value of the third characteristic information, the third characteristic information including the environmental information relied on during the operation of the edge device; step S402, in response to the secure storage device determining that the third current value is consistent with the third initial value, performing data unsealing on the key stored in the secure storage device; step S403, decrypting the target ciphertext based on the key to obtain the client certificate of the edge device; and step S404, sending the client certificate to the cloud to establish a secure communication connection with the cloud.

[0061] Therefore, the key used to decrypt the client certificate is sealed in a secure storage device through the initial value of the third characteristic information of the edge device. Only when the current third characteristic information of the edge device is consistent with the initial value can the key and the client certificate be obtained, thereby further improving the security of the communication connection with the cloud.

[0062] In some embodiments, during the deployment stage of the edge device, a public key and a private key can be first generated based on the current environmental information of the edge device, and the client certificate of the edge device can be encrypted based on the public key. The public key and the unencrypted client certificate are then destroyed, and the encrypted client certificate (that is, the target ciphertext mentioned above) is stored on the hard disk of the edge device.

[0063] The generated private key (ie, the key described above) may be stored in a secure storage device of the edge device, and data sealing may be performed on the private key based on the third characteristic information of the edge device.

[0064] In some embodiments, the secure storage device involved in the present disclosure may be a Trusted Platform Module (TPM), a USB dongle, or other security chip with similar functions. The following description will take TPM as an example to describe the solution.

[0065] In some embodiments, since TPM has a size limit of 128 bytes when sealing data, the public key and the private key may be generated based on an ECC algorithm to reduce the length of the private key.

[0066] In some embodiments, data sealing of private keys based on TPM can be performed by determining the third characteristic information of the edge device to be collected based on the device information of the edge device, wherein the third characteristic information includes the environment information (including software information and hardware information, etc.) that the edge device relies on during operation. The third characteristic information of different types of edge devices may be different, and the third characteristic information of the edge device can be determined based on the specific type of the edge device.

[0067] In some embodiments, during the stage of deploying the edge device, the startup of the edge device can be guided based on a boot loader (such as UEFI SecureBoot), and during the system startup process, relevant information (i.e., third characteristic information) of various firmware, system files, applications, etc. that the system startup depends on is collected, and a third initial value of the third characteristic information is obtained based on the collected information. The third initial value can be obtained by performing hash calculation on each piece of information.

[0068] In some embodiments, the third initial value may be stored in a hard disk of the edge device.

[0069] In some embodiments, the third initial value may also be stored in the secure storage device. Storing the third initial value in the secure storage device can prevent the third initial value from being tampered with based on the hardware protection of the secure storage device, thereby further improving the security of data sealing and data access.

[0070] In some embodiments, the third initial value may be stored in a platform configuration register (PCR) in the TPM.

[0071] After obtaining the third initial value, data sealing can be performed on the key in the TPM based on the third initial value. In some embodiments, data sealing the key in the TPM based on the third initial value may include: first creating the key as a parent object, then creating a data sealing policy based on the determined third characteristic information and the third initial value (for example, determining whether the current value of the third characteristic information is completely consistent with the initial value to determine whether to unseal the data), and then performing data sealing on the key based on this. That is, if the current value of the third characteristic information is inconsistent with the initial value, the key cannot be obtained.

[0072] In some exemplary embodiments, the third characteristic information may include but is not limited to: core system firmware executable code, core system firmware data / host platform configuration, extended or pluggable executable code, extended or pluggable firmware data, boot loader and additional drivers, GPT / partition table, secure boot status, system commands and kernel command lines, files read by the system, etc., without limitation here.

[0073] In some embodiments, after receiving a request to establish a secure communication connection between the edge device and the cloud, the third current value of the third characteristic information of the edge device can be determined to be consistent with the third initial value of the third characteristic information based on the secure storage device in the edge device. If they are consistent, it can be determined that the current environmental information of the edge device matches the data sealing, that is, the current edge device has not been illegally invaded or tampered with. The key stored in the secure storage device can be unsealed to obtain the key. Subsequently, the target ciphertext can be decrypted based on the key to obtain the client certificate of the edge device, and the client certificate can be used for security verification with the cloud. After the verification is passed, a secure communication connection can be established with the cloud.

[0074] In some embodiments, the application of client certificates for secure authentication with the cloud can be based on the mTLS (MutualTLS, two-way Transport Layer Security) protocol for two-way authentication between the cloud and the edge device. In some embodiments, authentication between the edge device and the cloud can also be based on one-way TLS protocols, IPSec protocols, SSH protocols, etc. It is understandable that relevant personnel can determine the protocol to be used based on actual circumstances and are not limited here.

[0075] If the security storage device determines that the third current value is inconsistent with the third initial value, it can be determined that the current edge device may have been illegally invaded or tampered with. In order to ensure data security, the key data will no longer be unsealed, and a corresponding prompt message will be sent to the relevant technical personnel.

[0076] In some embodiments, the aforementioned data sealing and unsealing operations based on the secure storage device can be implemented by calling the data sealing and unsealing interfaces of corresponding tools. Taking the TPM as an example, the aforementioned tools can be obtained by repackaging the TPM2-TSS using the Rust programming language. Thus, the functional integration of the TPM is achieved through this repackaging, further improving development efficiency and reducing security risks caused by improper use of the TPM.

[0077] In some embodiments, secondary packaging can be used to further integrate the data sealing and data unsealing functions of various different security storage devices (such as TPM modules, USB dongles, etc.), thereby unifying the calling interfaces of various different security storage devices and further improving the portability of the solution.

[0078] In some embodiments, the communication connection establishment request may be initiated by a user by operating the first application. In some embodiments, the communication connection establishment request may also be automatically initiated in response to the startup of the edge device or in response to the startup of the first application, which is not limited here.

[0079] In some embodiments, the third current value of the third characteristic information may be collected in response to receiving a communication connection establishment request.

[0080] In some embodiments, the third current value may also be pre-stored in a secure storage device, and obtaining the third current value may include: in response to detecting a change in the system file of the edge device, re-obtaining the current value of the third characteristic information to update the third current value in the secure storage device.

[0081] Therefore, by updating the third current value in the secure storage device in real time, direct comparison can be performed when data decryption is required, thereby improving the efficiency of key decryption.

[0082] In some exemplary embodiments, the third current value may be pre-stored in a platform configuration register in the TPM.

[0083] In some embodiments, as Figure 5 As shown, establishing a secure communication connection with the cloud through the first application may also include: step S501, generating an identity identification code for the first application based on the application information of the first application and the device information of the edge device; step S502, verifying the access rights of the first application to the secure storage device based on the identity identification code; and step S503, in response to the access rights verification of the first application being passed, determining whether the third current value is consistent with the third initial value based on the secure storage device.

[0084] Therefore, by further verifying the identity identification code of the first application, the access rights of the secure storage device are further restricted, thereby improving the security of data access.

[0085] In some embodiments, a preset identity code for accessing the secure storage device can be set during the deployment phase to restrict access by users and applications. The preset identity code can be generated based on the application information of the deployed first application (e.g., program code, runtime directory, etc.) and the device information of the edge device (e.g., CPU information, etc.), using a preset key derivation algorithm.

[0086] After receiving a request to establish a communication connection, the identity identification code can be first derived based on the application information of the current first application and the device information of the edge device using the same algorithm as the above-mentioned key derivation algorithm, and compared with the preset identity identification code. If they are consistent, it is determined that the current first application has the authority to access the secure storage device, and further based on the secure storage device, it is determined whether the third current value is consistent with the third initial value.

[0087] In some exemplary embodiments, for a TPM, relevant technicians may execute TPM2_HierarchyChangeAuth during the deployment phase to set a preset identity identification code for the Owner Hierarchy (OH) for accessing the TPM, thereby improving TPM access security.

[0088] In some embodiments, in response to receiving a data access request from a second application, performing trust verification on the current first application may include: obtaining a second current value of the second characteristic information of the first application in response to receiving the data access request, the second characteristic information including at least one of the program code of the first application and the device information of the edge device; and determining whether the second current value is consistent with the second initial value of the second characteristic information to determine whether the current first application is trustworthy.

[0089] Therefore, by integrating the program code of the first application and the device information of the edge device to perform trusted verification of the first application, the accuracy of trusted verification and the security of data access can be further improved.

[0090] In some embodiments, after the first application is deployed, a second initial value of the second characteristic information corresponding to the first application can be obtained. The second characteristic information includes application code, running directory, device information of the edge device, etc.

[0091] In some embodiments, the second initial value may be stored in a hard disk of the edge device.

[0092] In some embodiments, the second initial value can be stored in a secure storage device of the edge device. Thus, by storing the second initial value in the secure storage device, it is possible to prevent the second initial value from being illegally tampered with, thereby further improving the accuracy of trusted verification and the security of data access.

[0093] In some exemplary embodiments, the second initial value may be pre-stored in a platform configuration register in the TPM.

[0094] In some exemplary embodiments, the Linux IMA (Integrity Measurement Architecture) module can be used to measure the current integrity of the first application based on the second initial value of the second characteristic information pre-stored in the TPM, so that an external entity (such as the cloud) can further verify the credibility of the first application and kernel module loaded at runtime on the basis of establishing a secure communication connection with the first application, thereby further improving the security of edge devices when accessing data.

[0095] In some embodiments, as Figure 6 As shown, a data access device 600 executed by an edge device is provided, and the device 600 includes: a connection establishment unit 610, configured to establish a secure communication connection with the cloud through a first application; a first verification unit 620, configured to perform trusted verification on the current first application in response to receiving a data access request from a second application; a first acquisition unit 630, configured to obtain a first current value of the first characteristic information of the second application based on the first application in response to the first application passing the trusted verification, the first characteristic information including at least one of the running directory of the second application, the directory to be accessed, and the device information of the edge device; a first sending unit 640, configured to send a first authentication request to the cloud through the first application, the first authentication request including the first current value, and the cloud storing the first initial value of the first characteristic information; and a first authorization unit 650, configured to authorize the second application to access the data in response to the first application receiving the verification result sent by the cloud, the verification result including that the first current value is consistent with the first initial value.

[0096] Among them, the operations performed by units 610-650 in the data access device 600 executed by the edge device and the effects that can be achieved are similar to steps S201 to S205 in the data access method executed by the edge device in the present disclosure, and are not repeated here.

[0097] In some embodiments, the first verification unit may include: a first acquisition sub-unit, configured to obtain a second current value of the second characteristic information of the first application in response to receiving a data access request, the second characteristic information including at least one of the program code of the first application and the device information of the edge device; and a first judgment sub-unit, configured to judge whether the second current value is consistent with the second initial value of the second characteristic information to determine whether the current first application is trustworthy.

[0098] In some embodiments, the second initial value may be stored in a secure storage device of the edge device.

[0099] In some embodiments, the connection establishment unit may include: a second judgment sub-unit, configured to, in response to receiving a communication connection establishment request, determine whether the third current value of the third characteristic information of the edge device is consistent with the third initial value of the third characteristic information based on the secure storage device in the edge device, the third characteristic information including environmental information relied on during the operation of the edge device; an unsealing sub-unit, configured to, in response to the secure storage device determining that the third current value is consistent with the third initial value, perform data unsealing on the key stored in the secure storage device; a decryption sub-unit, configured to decrypt the target ciphertext based on the key to obtain the client certificate of the edge device; and a first sending sub-unit, configured to send the client certificate to the cloud to establish a secure communication connection with the cloud.

[0100] In some embodiments, the third initial value may be stored in a secure storage device.

[0101] In some embodiments, the third current value can be stored in a secure storage device, and obtaining the third current value can include: in response to detecting a change in the system file of the edge device, re-obtaining the current value of the third characteristic information to update the third current value in the secure storage device.

[0102] In some embodiments, the connection establishment unit may also include: a generation subunit, configured to generate an identity identification code for the first application based on the application information of the first application and the device information of the edge device; a verification subunit, configured to verify the access rights of the first application to the secure storage device based on the identity identification code; and a second judgment subunit, configured to judge whether the third current value is consistent with the third initial value based on the secure storage device in response to the access rights verification of the first application being passed.

[0103] In the technical solutions disclosed herein, the collection, storage, use, processing, transmission, provision and disclosure of user personal information involved comply with the provisions of relevant laws and regulations and do not violate public order and good morals.

[0104] According to an embodiment of the present disclosure, an electronic device, a readable storage medium, and a computer program product are also provided.

[0105] refer to Figure 7 , a block diagram of an electronic device 700 that can serve as a server or client of the present disclosure will now be described, which is an example of a hardware device that can be applied to various aspects of the present disclosure. The electronic device is intended to represent various forms of digital electronic computer devices, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital assistants, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present disclosure described and / or required herein.

[0106] like Figure 7 As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. Various programs and data required for the operation of the electronic device 700 can also be stored in the RAM 703. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0107] Multiple components within electronic device 700 are connected to I / O interface 705, including an input unit 706, an output unit 707, a storage unit 708, and a communication unit 709. Input unit 706 can be any type of device capable of inputting information into electronic device 700. Input unit 706 can receive input numeric or character information and generate key signal input related to user settings and / or function control of the electronic device. It can include, but is not limited to, a mouse, keyboard, touch screen, trackpad, trackball, joystick, microphone, and / or remote control. Output unit 707 can be any type of device capable of presenting information, and can include, but is not limited to, a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. Storage unit 708 can include, but is not limited to, a magnetic disk or an optical disk. Communication unit 709 allows electronic device 700 to exchange information / data with other devices via computer networks such as the Internet and / or various telecommunication networks. It can include, but is not limited to, a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, an 802.11 device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.

[0108] The computing unit 701 can be a variety of general-purpose and / or specialized processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units that run machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The computing unit 701 performs the various methods and processes described above, such as the data access method performed by the edge device of the present disclosure. For example, in some embodiments, the data access method performed by the edge device of the present disclosure can be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as the storage unit 708. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 700 via the ROM 702 and / or the communication unit 709. When the computer program is loaded into the RAM 703 and executed by the computing unit 701, one or more steps of the data access method performed by the edge device of the present disclosure described above can be performed. Alternatively, in other embodiments, the computing unit 701 may be configured in any other appropriate manner (for example, by means of firmware) to execute the data access method performed by the edge device of the present disclosure.

[0109] Various embodiments of the systems and techniques described above can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), system-on-chip systems (SOCs), complex programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various embodiments can include being implemented in one or more computer programs that are executable and / or interpreted on a programmable system that includes at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0110] The program code for implementing the method of the present disclosure can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device so that when the program code is executed by the processor or controller, the functions / operations specified in the flow chart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as a stand-alone software package, partially on the machine and partially on a remote machine, or entirely on a remote machine or server.

[0111] In the context of the present disclosure, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in conjunction with an instruction execution system, device or equipment. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0112] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).

[0113] The systems and techniques described herein can be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer having a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network (LAN), a wide area network (WAN), and the Internet.

[0114] A computer system may include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship arises through computer programs running on the respective computers and having a client-server relationship with each other. The server may be a cloud server, a server in a distributed system, or a server integrated with a blockchain.

[0115] It should be understood that the various forms of the processes shown above can be used to reorder, add, or delete steps. For example, the steps described in this disclosure can be performed in parallel, sequentially, or in a different order, as long as the desired results of the technical solutions disclosed in this disclosure can be achieved. This is not limited herein.

[0116] Although the embodiments or examples of the present disclosure have been described with reference to the accompanying drawings, it should be understood that the above-mentioned methods, systems and devices are merely exemplary embodiments or examples, and the scope of the present invention is not limited by these embodiments or examples, but is only limited by the claims after authorization and their equivalents. Various elements in the embodiments or examples may be omitted or replaced by their equivalents. In addition, the steps may be performed in an order different from that described in this disclosure. Further, the various elements in the embodiments or examples may be combined in various ways. It is important that as technology evolves, many of the elements described herein may be replaced by equivalent elements that appear after this disclosure.

Claims

1. A data access method performed by an edge device, the method comprising: Establish a secure communication connection with the cloud through the first application; In response to receiving a data access request from a second application, performing trustworthy verification on the current first application; In response to the first application passing the trusted verification, obtaining, based on the first application, a first current value of first feature information of the second application, the first feature information including at least one of a running directory of the second application, a directory to be accessed, and device information of the edge device; Sending a first authentication request to the cloud through the first application, where the first authentication request includes the first current value, and the cloud stores a first initial value of the first feature information; as well as In response to the first application receiving the verification result sent by the cloud, the second application is authorized to access the data, and the verification result includes that the first current value is consistent with the first initial value.

2. The method according to claim 1, wherein In response to receiving the data access request from the second application, performing trustworthy verification on the current first application includes: In response to receiving the data access request, obtaining a second current value of second feature information of the first application, the second feature information including at least one of a program code of the first application and device information of the edge device; and It is determined whether the second current value is consistent with the second initial value of the second characteristic information to determine whether the current first application is credible.

3. The method according to claim 2, wherein: The second initial value is stored in a secure storage device of the edge device.

4. The method according to any one of claims 1 to 3, wherein The establishing of a secure communication connection with the cloud through the first application includes: In response to receiving the communication connection establishment request, determining, based on a secure storage device in the edge device, whether a third current value of third characteristic information of the edge device is consistent with a third initial value of the third characteristic information, the third characteristic information including environmental information relied upon during operation of the edge device; In response to the secure storage device determining that the third current value is consistent with the third initial value, performing data unsealing on the key stored in the secure storage device; Decrypt the target ciphertext based on the key to obtain the client certificate of the edge device; and The client certificate is sent to the cloud to establish a secure communication connection with the cloud.

5. The method according to claim 4, wherein The third initial value is stored in the secure storage device.

6. The method according to claim 5, wherein: The third current value is stored in the secure storage device, and obtaining the third current value includes: In response to detecting a change in the system file of the edge device, the current value of the third feature information is reacquired to update the third current value in the secure storage device.

7. The method according to any one of claims 4 to 6, wherein The establishing of a secure communication connection with the cloud through the first application further includes: Generate an identity code for the first application based on the application information of the first application and the device information of the edge device; Verifying the access rights of the first application to the secure storage device based on the identity identification code; and In response to the access authority verification of the first application being passed, it is determined based on the secure storage device whether the third current value is consistent with the third initial value.

8. A data access apparatus executed by an edge device, the apparatus comprising: a connection establishing unit configured to establish a secure communication connection with the cloud through the first application; a first verification unit configured to, in response to receiving a data access request from a second application, perform trustworthy verification on the current first application; a first acquiring unit configured to, in response to the first application passing the trusted verification, acquire, based on the first application, a first current value of first feature information of the second application, the first feature information including at least one of a running directory of the second application, a directory to be accessed, and device information of the edge device; A first sending unit is configured to send a first authentication request to the cloud through the first application, wherein the first authentication request includes the first current value, and the cloud stores a first initial value of the first feature information; as well as The first authorization unit is configured to authorize the second application to access the data in response to the first application receiving a verification result sent by the cloud, wherein the verification result includes that the first current value is consistent with the first initial value.

9. The device according to claim 8, wherein The first verification unit includes: a first acquiring subunit configured to, in response to receiving the data access request, acquire a second current value of second feature information of the first application, where the second feature information includes at least one of a program code of the first application and device information of the edge device; and The first judgment subunit is configured to judge whether the second current value is consistent with the second initial value of the second characteristic information, so as to determine whether the current first application is credible.

10. The device according to claim 9, wherein The second initial value is stored in a secure storage device of the edge device.

11. The device according to any one of claims 8 to 10, wherein The connection establishing unit includes: a second judgment subunit, configured to, in response to receiving the communication connection establishment request, determine, based on a secure storage device in the edge device, whether a third current value of third feature information of the edge device is consistent with a third initial value of the third feature information, the third feature information including environmental information relied upon during operation of the edge device; an unsealing subunit configured to, in response to the secure storage device determining that the third current value is consistent with the third initial value, perform data unsealing on the key stored in the secure storage device; a decryption subunit, configured to decrypt the target ciphertext based on the key to obtain the client certificate of the edge device; and The first sending subunit is configured to send the client certificate to the cloud to establish a secure communication connection with the cloud.

12. The device according to claim 11, wherein The third initial value is stored in the secure storage device.

13. The device according to claim 12, wherein The third current value is stored in the secure storage device, and obtaining the third current value includes: In response to detecting a change in the system file of the edge device, the current value of the third feature information is reacquired to update the third current value in the secure storage device.

14. The device according to any one of claims 11 to 13, wherein The connection establishing unit further includes: a generating subunit, configured to generate an identity identification code of the first application based on the application information of the first application and the device information of the edge device; a verification subunit configured to verify the access rights of the first application to the secure storage device based on the identity identification code; and The second judgment subunit is configured to, in response to the access permission verification of the first application being passed, judge whether the third current value is consistent with the third initial value based on the secure storage device.

15. An electronic device comprising: at least one processor; as well as a memory communicatively coupled to the at least one processor; in The memory stores instructions that can be executed by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the method according to any one of claims 1 to 7.

16. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable a computer to execute the method according to any one of claims 1 to 7.

17. A computer program product comprising a computer program, wherein When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Method and device for configuring edge equipment and storage medium

    CN111416845A

  • Role-based data security access method and device

    CN113468576A