Security verification method, system, server, medium and computer program product

By verifying the server environment status and hardware identification information, combined with dynamic fingerprint verification, the hardware protection problem that the existing technology cannot cope with complex threat environments is solved, and the full life cycle protection and security improvement of server hardware is achieved.

CN119885148BActive Publication Date: 2025-06-10INSPUR SUZHOU INTELLIGENT TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510364689.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-26
Publication Date
2025-06-10
Estimated Expiration
2045-03-26

AI Technical Summary

Technical Problem

Existing hardware trusted verification technology cannot effectively respond to the full life cycle protection needs of server hardware in complex threat environments. Especially in situations such as supply chain attacks and hardware counterfeiting, the static whitelist cannot perceive the risks of the physical environment and network status, and a single identification verification is easily forged or replayed attacks.

Method used

By verifying the server's environment status data, the risk level is determined; the hardware identification information of the server hardware device is verified, and the random incentive information is sent to the hardware device and the response information is obtained to perform dynamic fingerprint verification. The verification information is weighted based on the risk level, a security verification result is generated, and a server function permission control policy is generated based on the results.

Benefits of technology

It realizes full life cycle protection of server hardware, improves the system's attack resistance and security, and can adapt to protection needs in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885148B_ABST
    Figure CN119885148B_ABST
Patent Text Reader

Abstract

The present application discloses a security verification method, system, server, medium and computer program product, relating to the technical field of servers, including verifying environmental status data of a server to determine the risk level of the server; verifying hardware identification information of server hardware devices to determine a first verification information; sending random excitation information to the server hardware devices, and obtaining response information fed back by the server hardware devices based on the random excitation information, verifying the response information to determine a second verification information; performing weight assignment on the first verification information and the second verification information based on the risk level to determine a security verification result; generating a server function permission control policy based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level. The present application introduces a decision-making method of dynamic environment perception, multi-dimensional hardware information collection and fusion verification, which can improve the security of server hardware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of servers, and particularly to a security verification method, system, server, medium, and computer program product. Background Art

[0002] Server hardware security is the foundation for ensuring the trustworthy operation of digital infrastructure. Traditional hardware trust verification technologies mostly rely on static whitelist verification of PN (Part Number) and SN (Serial Number).

[0003] However, in the context of threats such as supply chain attacks and hardware counterfeiting, the verification of existing solutions has many deficiencies. For example, the static whitelist cannot perceive the risks of the physical environment and network status, and single-identifier verification is vulnerable to forgery or replay attacks, and cannot meet the full-life cycle protection requirements of server hardware in complex threat environments. Summary of the Invention

[0004] This application provides a security verification method, system, server, medium, and computer program product to at least solve the problem in related technologies that the full-life cycle protection requirements of server hardware in complex threat environments cannot be met.

[0005] In a first aspect, this application provides a security verification method, including:

[0006] Verifying the environmental status data of the server to determine the risk level of the server;

[0007] Verifying the hardware identification information of the server hardware device to determine the first verification information;

[0008] Sending random excitation information to the server hardware device, and obtaining the response information fed back by the server hardware device based on the random excitation information, and verifying the response information to determine the second verification information;

[0009] Based on the risk level, assigning weights to the first verification information and the second verification information to determine the security verification result;

[0010] Based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level, generating a server function permission control policy.

[0011] In a second aspect, this application further provides a security verification system, including:

[0012] An environmental status data acquisition module configured to acquire the environmental status data of the server;

[0013] The hardware information acquisition module is configured to obtain the hardware identification information of the server hardware device and send the response information fed back by the server hardware device based on the random excitation information to the hardware information verification module;

[0014] The hardware information verification module is configured to: verify the environmental status data of the server to determine the risk level of the server; verify the hardware identification information of the server hardware device to determine the first verification information; send random excitation information to the server hardware device, and obtain the response information fed back by the server hardware device based on the random excitation information, verify the response information to determine the second verification information; perform weight allocation on the first verification information and the second verification information based on the risk level to determine the security verification result; generate a server function permission control policy based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level.

[0015] In a third aspect, the present application further provides a server, including the security verification system as described in the second aspect.

[0016] In a fourth aspect, the present application further provides a computer-readable storage medium, in which a computer program is stored, and when the computer program is executed by a processor, the steps of the security verification method as described in the first aspect are implemented.

[0017] In a fifth aspect, the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the security verification method as described in the first aspect are implemented.

[0018] The present application integrates environmental perception and multi-dimensional hardware information. For example, by verifying the environmental status data of the server to determine the risk level of the server, environmental perception is realized; by verifying the hardware identification information of the server hardware device to determine the first verification information, static fingerprint verification of hardware information is realized; by sending random excitation information to the server hardware device, and obtaining the response information fed back by the server hardware device based on the random excitation information, verifying the response information to determine the second verification information, dynamic fingerprint verification of hardware information is realized. Then, the risk level, the first verification information, and the second verification information are integrated, weight allocation is performed on the first verification information and the second verification information according to different risk levels to obtain the security verification result, and a server function permission control policy is generated according to the comparison result between the security verification result and the security verification threshold corresponding to the risk level, so as to realize hierarchical response to the server. By introducing a decision-making method of dynamic environmental perception, multi-dimensional hardware information acquisition and fusion verification, the present application can meet the full-life cycle protection requirements of server hardware in complex environments and improve the security of server hardware. Description of the Drawings

[0019] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0020] Figure 1 Schematic structural diagram of a security verification system provided by an embodiment of the present application;

[0021] Figure 2 Schematic structural diagram of another security verification system provided by an embodiment of the present application;

[0022] Figure 3 Flowchart of a security verification method provided by an embodiment of the present application;

[0023] Figure 4 Specific example of a security verification method provided by an embodiment of the present application;

[0024] Figure 5 Schematic structural diagram of a server provided by an embodiment of the present application. Specific implementation manners

[0025] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.

[0026] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and not to describe a specific order or sequence.

[0027] To enable those skilled in the art of the present technology to better understand the solution of the present application, the following further elaborates on the present application with reference to the accompanying drawings and specific implementation manners.

[0028] Embodiments of the present application provide a security verification system. Figure 1 Schematic structural diagram of a security verification system provided by an embodiment of the present application, as Figure 1As shown, the security verification system includes an environmental status data acquisition module 10, a hardware information acquisition module 20, and a hardware information verification module 30.

[0029] The environmental status data acquisition module 10 is configured to acquire the environmental status data of the server.

[0030] The hardware information acquisition module 20 is configured to obtain the hardware identification information of the server hardware device and send the response information fed back by the server hardware device based on the random excitation information to the hardware information verification module.

[0031] The hardware information verification module 30 is configured to verify the environmental status data of the server to determine the risk level of the server; verify the hardware identification information of the server hardware device to determine the first verification information; send random excitation information to the server hardware device, and obtain the response information fed back by the server hardware device based on the random excitation information, verify the response information to determine the second verification information; perform weight assignment on the first verification information and the second verification information based on the risk level to determine the security verification result; generate a server function permission control policy based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level.

[0032] Exemplarily, the environmental status data of the server may be, for example, the server environmental temperature, the location information of the server, the network IP address, etc. The hardware information verification module 30 verifies the above environmental status data to determine the risk level of the server. In the actual application process, the number of risk levels can be set according to requirements. For example, the risk levels are divided into low risk, medium risk, and high risk.

[0033] The hardware information acquisition module 20 reads and analyzes the hardware identification information of the hardware device. In addition, the hardware information verification module 30 sends random excitation information to the hardware device through the hardware information acquisition module 20. The hardware information acquisition module 20 obtains the response information fed back by the hardware device based on the random excitation information and sends it to the hardware information verification module 30. The hardware information verification module 30 verifies the above hardware identification information to determine the first verification information and verifies the above response information to determine the second verification information.

[0034] Embodiments of the present application can determine the risk level of the server by verifying the environmental status data of the server, achieving environmental awareness; verify the hardware identification information of the server hardware device to determine the first verification information, achieving static fingerprint verification of hardware information; verify the response information to determine the second verification information, achieving dynamic fingerprint verification of hardware information. Then, the hardware information verification module 30 fuses the risk level, the first verification information, and the second verification information, assigns weights to the first verification information and the second verification information according to different risk levels, obtains a security verification result, and generates a server function permission control policy based on the comparison result between the security verification result and the security verification threshold corresponding to the risk level, which can achieve hierarchical response to the server. Therefore, by introducing a decision-making method of dynamic environmental awareness, multi-dimensional hardware information collection and fusion verification, the present application can meet the full-life cycle protection requirements of server hardware in complex environments, significantly improve the system's anti-attack ability, and enhance the security of server hardware.

[0035] In some embodiments, when the hardware information verification module assigns weights to the first verification information and the second verification information according to different risk levels, it can be that the higher the risk level, the greater the weight coefficient of the second verification information and the smaller the weight coefficient of the first verification information.

[0036] Since different random excitation information is used for each verification when determining the second verification information, it can prevent attackers from conducting replay attacks by recording historical responses, so it is more difficult to imitate than the first verification information. Therefore, as the risk level increases, a higher weight coefficient can be assigned to the second verification information, thereby enhancing the security of server hardware under higher risks. That is, the higher the risk level, the greater the proportion of the weight coefficient of the second verification information in the overall, and the smaller the proportion of the weight coefficient of the first verification information in the overall. For example, the weight coefficient corresponding to the first verification information under low risk is 0.5, and the weight coefficient corresponding to the second verification information is 0.5. After the risk level is raised to medium risk, the weight coefficient corresponding to the first verification information under medium risk is 0.4, and the weight coefficient corresponding to the second verification information is 0.6.

[0037] Exemplarily, the weight coefficient range of the second verification information can be set to 0.5 to 0.9. Correspondingly, the weight coefficient range of the first verification information can be set to 0.1 to 0.5.

[0038] The first verification information reflects the static fingerprint of the hardware device. Since it reflects the static fingerprint of the hardware device, it has high stability but is easy to be replicated. When determining the second verification information, different random excitation information is used for each verification, which reflects the dynamic fingerprint of the hardware device. Therefore, it is more difficult to imitate compared with the first verification information, but its stability may be lower. The dynamic fingerprint is more difficult to be attacked, and its characteristic of real-time change increases the security. Although the dynamic fingerprint is secure, it sometimes has certain instability. For example, environmental factors may affect the recognition and cause errors. Therefore, it is necessary to balance security and reliability. Although the static fingerprint is stable, it is easy to be stolen or cloned, so its weight is low. However, the dynamic fingerprint may sometimes not be available. Therefore, the two are used in combination, with the dynamic fingerprint as the main and the static fingerprint as the auxiliary, which not only ensures security but also increases the robustness of the system.

[0039] In actual use, the requirements of different application scenarios can be considered. For example, in scenarios with high security requirements, more emphasis can be placed on the weight coefficient of the second verification information, while in scenarios with high stability requirements, the weight coefficient of the first verification information can be appropriately increased. When setting the weight coefficient of the first verification information and the weight coefficient of the second verification information, the high security and real-time nature of the dynamic fingerprint, the stability and vulnerability of the static fingerprint, and the overall system performance optimization after the combination of the two can be comprehensively considered.

[0040] It is found through testing that the weight coefficient range of the second verification information is from 0.5 to 0.9, and the weight coefficient range of the first verification information is from 0.1 to 0.5, which can effectively balance security and false alarm rate. If the weight coefficient corresponding to the first verification information is too low, it may not provide sufficient basic verification, while if it is too high, it will reduce the overall security.

[0041] The dynamic fingerprint depends on real-time environmental parameters and may be affected by factors such as noise and temperature drift, resulting in verification failure. If the weight coefficient of the second verification information is too high, it may cause misjudgment or service interruption. Therefore, setting the upper limit of the weight coefficient of the second verification information to 0.9 can avoid over-relying on the dynamic fingerprint and reduce the vulnerability of the system. The weight coefficient of the second verification information is not set to 1 to avoid complete failure of verification due to extreme environments and retain redundant verification capabilities for the system. The lower limit of the weight coefficient of the second verification information is set to 0.5 to ensure its dominant position and prevent attackers from bypassing verification by forging static fingerprints.

[0042] In some embodiments, the environmental state data acquisition module includes an environmental state data cluster and an environmental state data processing module. The environmental state data cluster includes sensors, a network module, and a trusted platform module.

[0043] Figure 2 This is a schematic structural diagram of another security verification system provided by the embodiments of the present application, for Figure 2For example, the environmental status data acquisition module 10 includes an environmental status data cluster 11 and an environmental status data processing module 12. The environmental status data cluster 11 includes a sensor 111, a network module 112, and a trusted platform module 113.

[0044] The environmental status data cluster 11 is used to collect environmental status data. The sensor 111 includes, for example, a temperature sensor, a GPS sensor, etc. The temperature sensor is used to indicate the server environmental temperature, and the GPS sensor is used to indicate the location information of the server. The network module 112 can obtain the current network IP address and the firewall policy status.

[0045] The trusted platform module 113 (Trusted Platform Module, TPM) is used to monitor the firmware integrity and compliance of hardware devices. The TPM includes a Platform Configuration Register (PCR) for storing security measurement values (such as hash values), which are used to record the hash values of key components during the device startup process to ensure the trustworthiness of the entire process from firmware to system.

[0046] The environmental status data processing module 12 obtains the environmental status data and the security measurement value (PCR value) of the trusted platform module TPM, and generates a timestamped environmental snapshot based on the environmental data and the security measurement value. That is, the environmental snapshot includes environmental status data, security measurement values, and timestamps. The trusted platform module TPM encrypts the environmental snapshot to generate an immutable environmental tag.

[0047] When obtaining the security measurement value, the environmental status data processing module 12 can, for example, call TPM2_PCR_Read to obtain the current security measurement value (PCR value). The trusted platform module TPM can, for example, use the private key of the AIK (Attestation Identity Key, "attestation identity key") to sign the environmental snapshot to generate an encrypted environmental tag, which is stored in the NV (Non-Volatile Storage) area of the trusted platform module TPM. Encryption using the trusted platform module TPM and storage in the NV area can further enhance data security and prevent tampering.

[0048] The hardware information verification module 30 can read the environmental tag from the trusted platform module, decrypt and extract the environmental status data and the security measurement value of the trusted platform module, and determine the risk level of the server based on the comparison results of the environmental status data and the security measurement value of the trusted platform module with the preset baseline values.

[0049] When the hardware information verification module 30 reads the environment label from the trusted platform module, for example, it can send the TPM2_NV_Read command to the trusted platform module TPM to read the environment label, verify the signature using the pre-set AIK public key, confirm the data integrity and source. The hardware information verification module 30 will compare the decrypted and extracted environment status data and the security measurement value of the trusted platform module with the pre-set baseline value, and determine the risk level of the server according to the comparison result.

[0050] Exemplarily, different environment status data correspond to different pre-set baseline values. When making a comparison, the collected environment status data can be compared with the corresponding pre-set baseline values. If the security measurement value of the trusted platform module does not match the pre-set security measurement baseline value, it is marked as "firmware anomaly". If the GPS coordinates in the environment status data do not match the authorized area baseline value, it is marked as "location risk".

[0051] Through the cooperation of the various components in the above system architecture in the embodiments of the present application, the environmental perception of the server hardware devices is realized, the risk status of each hardware device is sensed in real time, and the corresponding risk level is determined, so as to perform hierarchical control according to different risk levels. Therefore, dynamic trusted environment verification can be achieved.

[0052] The present application can monitor the physical environment in real time, obtain the physical state data during the operation of the hardware through the environmental sensor cluster (such as temperature and humidity, voltage sensors), and combine with the PCR value of the trusted platform module TPM to realize the double verification of the hardware environment and software status. If an attacker attempts to trigger a hardware failure or bypass the security mechanism by changing the physical environment (such as increasing the server temperature), the abnormality of the environment status data will be immediately captured. Therefore, environmental tampering attacks can be resisted. The environmental snapshot is encrypted by the trusted platform module TPM to generate an environment label and stored in the NV area of the trusted platform module TPM. The hardware security characteristics of the trusted platform module TPM can ensure that the data cannot be tampered with or forged. The environmental snapshot in the present application contains a time stamp, combined with the dynamically generated encrypted label, which can effectively prevent the attacker from bypassing the verification by replaying historical data. The hardware information verification module compares the real-time environment status data, PCR value with the pre-set baseline value, and can automatically identify abnormalities (such as hardware configuration changes, environmental status data exceeding the limit). The present application can also divide the risk level according to the comparison result (such as low, medium, high), and support the system to adopt different response strategies according to subsequent policies (such as recording logs, triggering alarms, isolating devices, restricting some function permissions).

[0053] In some embodiments, the hardware information verification module 30 can also record the comparison result of the environment status data and the security measurement value of the trusted platform module with the pre-set baseline value into the log.

[0054] In some embodiments, the security verification system may further include a hardware information storage module. The hardware information storage module is configured to store the identification code, digital signature, and preset response information of the hardware device.

[0055] As Figure 2 shown, the hardware information acquisition module 20 is configured to obtain the identification code, digital signature, and preset response information of the hardware device stored in the hardware information storage module 40 through the bus, and control the trusted platform module TMP to perform signature verification.

[0056] The hardware information verification module 30 is configured to determine the first verification information according to the signature verification result of the trusted platform module TPM; and send random excitation information to the server hardware device through the hardware information acquisition module 20, obtain the response information fed back by the server hardware device based on the random excitation information, and determine the second verification information according to the verification result of the response information and the preset response information.

[0057] Exemplarily, the hardware information storage module 40 may be located in each hardware device and is used to store the identification code of the hardware device, such as the unique identification information PN, SN, digital signature, and preset response information. The hardware information storage module 40 may also be a storage module independent of the hardware device. The hardware information storage module 40 may be set in one-to-one correspondence with the hardware device, and each hardware setting may also share a hardware information storage module 40. The present application does not limit the setting method of the hardware information storage module 40.

[0058] The hardware information acquisition module 20 may obtain the identification code, digital signature, and preset response information of the hardware device stored in the hardware information storage module 40 through the I2C / SPI bus. The hardware information storage module 40 may be, for example, an EEPROM (Electrically Erasable Programmable Read-Only Memory) or a Flash chip (flash memory chip).

[0059] The hardware information acquisition module 20 may call the TPM2_VerifySignature command of TPM2.0 to verify the SN signature using the preset vendor public key. The hardware information verification module 30 may determine whether PN and SN are legal according to the above signature verification result, that is, obtain the first verification information.

[0060] Through unique identifiers such as PN and SN in the hardware information storage module, combined with digital signatures, this application establishes a static fingerprint for the hardware device to ensure that the identity of each hardware device cannot be forged. If an attacker attempts to replace components, the TPM verification will fail due to signature mismatch. The digital signature in the hardware information storage module is generated by the manufacturer's private key, and the TPM uses the public key to verify the validity of the signature. If the PN or SN is tampered with, the signature verification will fail, ensuring that the data has not been tampered with.

[0061] The hardware information verification module 30 generates random excitation information and sends it to the server hardware device through the hardware information acquisition module 20. The server hardware device generates corresponding response information upon receiving the random excitation information and sends it to the hardware information verification module 30 through the hardware information acquisition module 20. The hardware information verification module 30 compares the received response information with the preset response information to obtain the second verification information.

[0062] Optionally, in this application, the random excitation information can be, for example, a physical unclonable function challenge random code.

[0063] Based on the uniqueness of the physical characteristics of the hardware device, this application generates a unique response using the physical manufacturing differences of the hardware device (such as transistor threshold voltage and wire length deviation), which cannot be replicated or reverse-engineered, ensuring that the identity of each hardware device cannot be forged. For example, the preset response information PUF response can be solidified into the storage module during factory production to establish a reference feature library, providing a trusted anchor for subsequent verification. The hardware information verification module 30 dynamically generates random excitation information, and different random excitation information is used for each verification, which can prevent attackers from conducting replay attacks by recording historical responses. This application compares the real-time response information with the pre-stored response information to determine the second verification information, which can monitor whether the hardware device has been replaced or tampered with, and is especially suitable for scenarios with extremely high requirements for anti-tampering and anti-cloning.

[0064] In some embodiments, the hardware information acquisition module is configured to add a time stamp to the response information generated by the hardware device based on the random excitation information and send it to the hardware information verification module.

[0065] After the server hardware device receives the random excitation information and generates the corresponding response information, it sends the response information to the hardware information acquisition module 20. The hardware information acquisition module 20 attaches a time stamp to the response information and then transmits it to the hardware information verification module 30, thereby ensuring the real-time nature of the data.

[0066] In some embodiments, the security verification system may further include a control module, and the control module is used to obtain and execute the server function permission control policy.

[0067] For example, see Figure 2, the control module 50 and the hardware information verification module 30 can perform data interaction, and the control module 50 can execute the server function permission control policy generated by the hardware information verification module 30. Exemplarily, the control module can control the power on and off of the entire server, and perform hierarchical response according to the server function permission control policy generated by the hardware information verification module 30, such as controlling the server power status, the function permissions of each hardware, etc.

[0068] In some embodiments, the security verification system may further include a power supply module, and the control module is configured to control the power supply situation of the power supply module according to the server function permission control policy.

[0069] As Figure 2 shown, the power supply module 60 is connected to the control module 50, and the control module 50 can control the power supply situation of the power supply module 60 according to the server function permission control policy. For example, if the function of certain hardware devices is restricted according to the server function permission control policy, then the power supply module 50 can be controlled to no longer supply power to the hardware devices with restricted functions.

[0070] In addition, the power supply module 60 can also provide independent and stable power supply for the hardware components required to perform security verification, such as supplying power to the environmental status data acquisition module 10, the hardware information acquisition module 20, the hardware information verification module 30, the hardware information storage module 40, and the control module 50, to ensure continuous monitoring under abnormal conditions.

[0071] Based on the above security verification system, the present application also provides a security verification method. Figure 3 is a flowchart of a security verification method provided by an embodiment of the present application. The security verification method provided by the embodiment of the present application can be applied to the hardware information verification module of the security verification system. The hardware information verification module can be, for example, a Baseboard Management Controller (BMC).

[0072] Figure 3 is a flowchart of the security verification method according to an embodiment of the present invention. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here. As Figure 3 shown, the security verification method provided by the present application includes:

[0073] S101. Verify the environmental status data of the server to determine the risk level of the server.

[0074] This step is to perceive the risk status of each hardware device in real time. By perceiving the environmental status data of the server in real time and verifying it, the risk level of the server is obtained, so as to perform subsequent hierarchical control according to different risk levels, and thus dynamic trusted environment verification can be achieved.

[0075] Optionally, the environmental status data can be collected through the environmental status data cluster in the security verification system. For the specific architecture of the environmental status data cluster, reference can be made to, for example, Figure 2 , the environmental status data cluster includes a sensor 111, a network module 112, and a trusted platform module 113. The sensor 111 includes, for example, a temperature sensor, a GPS sensor, etc. The temperature sensor is used to indicate the server environmental temperature, and the GPS sensor is used to indicate the location information of the server. The network module 112 can obtain the current network IP address and the firewall policy status.

[0076] S102. Verify the hardware identification information of the server hardware device to determine the first verification information.

[0077] The hardware identification information can be, for example, the identification code, digital signature, etc. of the hardware device. The hardware identification information is the static unique identification information of the hardware device and can be regarded as the static fingerprint of the hardware device. Therefore, by verifying the hardware identification information, the first verification information can be obtained from the perspective of static factor verification.

[0078] S103. Send random excitation information to the server hardware device, obtain the response information fed back by the server hardware device based on the random excitation information, and verify the response information to determine the second verification information.

[0079] Since the random excitation information is random, replay attacks can be prevented and the dynamic nature of the verification can be ensured. In this application, by sending random excitation information to the server hardware device and obtaining the response information fed back by the server hardware device based on the random excitation information, the dynamic identification information of the hardware device can be obtained, which can be regarded as the dynamic fingerprint of the hardware device. Therefore, through the excitation-response verification method, the second verification information can be obtained from the perspective of dynamic factor verification.

[0080] S104. Perform weight assignment on the first verification information and the second verification information based on the risk level to determine the security verification result.

[0081] In the embodiments of this application, the weight coefficients of the first verification information and the second verification information under different risk levels can be preset in advance. According to the determined risk level, the weight coefficients corresponding to the first verification information and the second verification information are found, and the security verification result is calculated according to the weight coefficients.

[0082] For example, if the currently determined risk level is the first risk level, the weight coefficient of the first verification information corresponding to the first risk level is 0.5, and the weight coefficient of the second verification information corresponding to the first risk level is 0.5. If the currently determined risk level is the second risk level, the weight coefficient of the first verification information corresponding to the second risk level is 0.4, and the weight coefficient of the second verification information corresponding to the first risk level is 0.6.

[0083] S105. Generate a server function permission control policy based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level.

[0084] In the embodiments of the present application, different risk levels correspond to different overall verification thresholds. For example, if the currently determined risk level is the first risk level, the security verification threshold corresponding to the first risk level is 0.8. If the currently determined risk level is the second risk level, the security verification threshold corresponding to the second risk level is 0.85.

[0085] The present application compares the security verification threshold corresponding to the currently determined risk level with the obtained security verification result, and finally determines the server function permission control policy according to the comparison result. The server function permission control policy can be, for example, making a decision on the boot behavior, a power supply control policy, a hardware function enabling control policy, etc.

[0086] In summary, the present application introduces the risk level of the environment, the static fingerprint of the hardware device, and the dynamic fingerprint of the hardware device, integrates them, realizes the dynamic policy decision function of integrated environment risk analysis and multi-dimensional hardware fingerprint verification, forms a three-dimensional verification system of "the risk level of the environment + the static fingerprint of the hardware device + the dynamic fingerprint of the hardware device", improves the attack threshold, and thus can meet the full life cycle protection requirements of server hardware in a complex environment, significantly improves the system's resistance to physical attacks, configuration tampering, and environmental anomalies, and improves the security of server hardware.

[0087] In some embodiments, the weight allocation for the first verification information and the second verification information based on the risk level can be that the higher the risk level, the larger the weight coefficient of the second verification information and the smaller the weight coefficient of the first verification information.

[0088] Since different random excitation information is used for each verification when determining the second verification information, it is more difficult to imitate than the first verification information. Therefore, as the risk level increases, a higher weight coefficient can be assigned to the second verification information, thereby improving the security of server hardware under higher risks. That is, the higher the risk level, the larger the proportion of the weight coefficient of the second verification information in the whole, and the smaller the proportion of the weight coefficient of the first verification information in the whole.

[0089] Exemplarily, the weight coefficient range of the second verification information can be set from 0.5 to 0.9. Correspondingly, the weight coefficient range of the first verification information can be set from 0.1 to 0.5.

[0090] Through testing, it is found that when the weight coefficient range of the second verification information is from 0.5 to 0.9 and the weight coefficient range of the first verification information is from 0.1 to 0.5, the security and false alarm rate can be effectively balanced. If the weight coefficient corresponding to the first verification information is too low, it may not provide sufficient basic verification, while if it is too high, the overall security will be reduced.

[0091] Optionally, the above control program is written into the hardware information verification module (such as BMC) of the server during server production, and the program can be remotely updated according to the actual situation later.

[0092] In some embodiments, verifying the environmental status data of the server to determine the risk level of the server includes:

[0093] Reading the environmental label and decrypting it to extract the environmental status data and the security measurement value of the trusted platform module;

[0094] Determining the risk level of the server according to the comparison results of the environmental status data and the security measurement value of the trusted platform module with the preset baseline value.

[0095] The embodiment of the present application provides a specific method for verifying the risk level of a server. Exemplarily, the hardware information verification module can obtain the environmental label from the trusted platform module. Among them, the environmental label is generated by encrypting an environmental snapshot including environmental status data, security measurement value, and timestamp by the trusted platform module. The environmental status data can be collected through an environmental status data cluster. An environmental status data processing module can be set in the security verification system of the server. The environmental status data processing module can obtain the security measurement value from the trusted platform module TPM. The environmental status data processing module forms an environmental snapshot with a timestamp from the environmental status data collected by the environmental status data cluster and the security measurement value obtained from the trusted platform module TPM. The environmental status data processing module sends the above environmental snapshot to the trusted platform module TPM, and the trusted platform module TPM encrypts the environmental snapshot to generate an environmental label. The hardware information verification module reads the environmental label from the trusted platform module TPM, decrypts it to extract the environmental status data and the security measurement value of the trusted platform module, and then compares the environmental status data and the security measurement value of the trusted platform module with the preset baseline value, and determines the risk level of the server according to the comparison results.

[0096] The security verification method provided by this application can monitor the physical environment in real time, obtain the physical state data during hardware operation through an environmental sensor cluster (such as temperature and humidity sensors, voltage sensors), and combine it with the PCR value of the Trusted Platform Module (TPM) to achieve dual verification of the hardware environment and software status. For example, multiple sensors such as temperature and humidity, voltage, and electromagnetic radiation collect environmental state data in real time to prevent misjudgment caused by the failure or tampering of a single sensor. The platform configuration registers of the TPM can record the hash values of key components such as the BIOS and operating system to ensure the integrity of the software stack. The TPM encrypts the environmental snapshot (including environmental state data, security measurement values, and timestamps) to generate an environmental tag. The timestamp can prevent replay attacks and ensure the timeliness of verification. The environmental tag encryption key is generated and securely stored inside the TPM to ensure that it cannot be obtained through physical attacks, resisting means such as cold boot attacks and memory sniffing. The environmental state data, security measurement values, and timestamps are bound as a whole during encryption, and any data tampering will cause decryption failure, achieving strong association protection. Comparing the preset baseline values (such as the normal temperature range, standard PCR value) with the decrypted real-time environmental state data and the PCR value of the Trusted Platform Module can detect abnormal environments (such as overheating, voltage fluctuations) or software tampering. For example, the risk level can be divided according to the degree of deviation from the baseline, and then different subsequent response strategies can be triggered.

[0097] In some embodiments, verifying the hardware identification information of the server hardware device to determine the first verification information includes:

[0098] Obtaining the identification code and digital signature of the server hardware device;

[0099] Determining the first verification information according to the verification results of the identification code and the digital signature.

[0100] The hardware identification information may include, for example, the identification code and digital signature of the hardware device. The identification code of the hardware device may be the unique identification information PN, SN of the hardware device. The above-mentioned identification code and digital signature of the hardware device are unique. Therefore, the first verification information can be determined according to the verification results of the identification code and the digital signature, realizing security verification from the static fingerprint dimension of the hardware device.

[0101] In some embodiments, determining the first verification information according to the verification results of the identification code and the digital signature includes:

[0102] Determining the first verification information according to the first preset weight assignment value, the comparison result of the identification code and the authorized hardware device list, and the verification result of the digital signature.

[0103] When determining the first verification information in this application, the existence of the identification code and the validity of the signature can be comprehensively considered by means of weight assignment. A first preset weight assignment value can be preset, and the first preset weight assignment value represents the weight coefficients corresponding to the existence of the identification code and the validity of the signature respectively. The existence of the identification code refers to the comparison result between the identification code and the authorized hardware device list, and the validity of the signature refers to the verification result of the digital signature.

[0104] This application can set the weight coefficients corresponding to the comparison result between the identification code and the authorized hardware device list, and the verification result of the digital signature according to actual needs. For example, if higher accuracy is required for the comparison result between the identification code and the authorized hardware device list, a higher weight coefficient can be set for the comparison result between the identification code and the authorized hardware device list. If higher accuracy is required for the verification result of the digital signature, a higher weight coefficient can be set for the verification result of the digital signature. This application can adjust and set the first preset weight assignment value according to actual needs, so that when determining the first verification information based on the identification code and the verification result of the digital signature, an accurate first verification information that better meets its own needs can be obtained based on the requirements.

[0105] Exemplarily, the comparison result between the identification code and the authorized hardware device list, and the verification result of the digital signature can be determined in the following manner:

[0106] Comparison result between the identification code and the authorized hardware device list: Check whether the identification code (such as PN, SN) exists in the authorized list. If it exists in the authorized list, it is 1; otherwise, it is 0.

[0107] Verification result of the digital signature: Verify whether the digital signature is issued by a legitimate supplier. If it is legitimate, it is 1; otherwise, it is 0.

[0108] Exemplarily, a weighted calculation is performed on the comparison result between the identification code and the authorized hardware device list and the verification result of the digital signature. For example, the weight coefficient corresponding to the comparison result between the identification code and the authorized hardware device list in the first preset weight assignment value is 0.5, and the weight coefficient corresponding to the verification result of the digital signature in the first preset weight assignment value is 0.5.

[0109] Correspondingly, the first verification information = (comparison result between the identification code and the authorized hardware device list × 0.5) + (verification result of the digital signature × 0.5)

[0110] It should be noted that the first preset weight assignment value can be set according to the actual situation. In this application, only an example is given that the weight coefficient corresponding to the comparison result between the identification code and the authorized hardware device list in the first preset weight assignment value is 0.5, and the weight coefficient corresponding to the verification result of the digital signature in the first preset weight assignment value is 0.5.

[0111] In some embodiments, sending random excitation information to a server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, and verifying the response information to determine second verification information, including:

[0112] Sending multiple random excitation information to the server hardware device, obtaining respective response information fed back by the server hardware device corresponding one by one to the respective random excitation information, and verifying the respective response information to determine respective second verification information corresponding one by one to the respective response information.

[0113] In the embodiments of the present application, the hardware information verification module, as a trusted source, sends random excitation information to the server hardware device. Due to differences in manufacturing processes and the like of the server hardware device, each server hardware device will have different responses to the random excitation information based on its own physical characteristics. The response information fed back by the hardware device based on its own physical characteristics for the random excitation information can be regarded as the dynamic fingerprint of the hardware device.

[0114] The embodiments of the present application can use multiple random excitation information. For each random excitation information, the response information of the hardware device corresponding to the random excitation information can be obtained, and then the respective response information can be verified to determine respective second verification information corresponding one by one to the respective response information.

[0115] For example, the hardware information verification module sends first random excitation information to the hardware device, the hardware device feeds back first response information based on the first random excitation information, and the hardware information verification module verifies the first response information to obtain second verification information C1. The hardware information verification module sends second random excitation information to the hardware device, the hardware device feeds back second response information based on the second random excitation information, and the hardware information verification module verifies the second response information to obtain second verification information C2.

[0116] By obtaining the response information corresponding to the respective random excitation information and determining the second verification information corresponding to the respective random excitation information, the embodiments of the present application can achieve the collection and verification of multiple dynamic fingerprints of the hardware device, further improving the security verification accuracy of the hardware device.

[0117] In some embodiments, sending random excitation information to a server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, and verifying the response information to determine second verification information, including:

[0118] Sending a physical unclonable function challenge random code to the server hardware device, and obtaining response information fed back by the server hardware device based on the physical unclonable function challenge random code;

[0119] Determining second verification information according to the verification result of the response information and the preset response information.

[0120] In the embodiments of the present application, the random excitation information may be a physical unclonable function challenge random code.

[0121] Exemplarily, the hardware information verification module in the embodiments of the present application may dynamically generate a unique physical unclonable function challenge random code, and transmit the physical unclonable function challenge random code to the hardware information acquisition module. The hardware information acquisition module sends the physical unclonable function challenge random code to the PUF (Physical Unclonable Function) interface of hardware devices such as a processor, an FPGA (Field-Programmable Gate Array), etc. After receiving the physical unclonable function challenge random code, the PUF circuit in the hardware device generates response information based on physical characteristics. The hardware fingerprint acquisition module reads the response information, and after attaching a timestamp, transmits it to the hardware information verification module. The hardware information verification module reads the pre-stored preset response information (which can be written into the storage module at the time of factory, for example), compares the verification result of the obtained response information with the preset response information, and determines the second verification information based on this verification result.

[0122] The physical unclonable function challenge random code generated by the hardware information verification module has randomness, so replay attacks can be prevented and the dynamics of verification can be ensured. Due to the slight differences in materials and processes (such as semiconductor doping concentration deviation) during the manufacturing process of each hardware device, a unique "physical fingerprint" can be formed. The PUF circuit of the hardware device performs non-linear physical calculations on the challenge code based on physical manufacturing deviations (such as microscopic differences in transistor threshold voltage, metal wire resistance, etc.), and generates a unique response value (such as a 64 / 128-bit binary string). The PUF response depends on the non-linear characteristics of the physical structure (such as signal delay, voltage noise), and cannot be pre-calculated through a mathematical model. Even if the challenge code and part of the response are known, it is impossible to infer the responses of other challenges. Therefore, the response information is unique. Compared with the situation where traditional static fingerprints (such as serial numbers) are easily stolen, the response information in the present application changes with the physical unclonable function challenge random code, and can resist man-in-the-middle attacks. If the hardware device is physically tampered with, the physical structure of the PUF changes, resulting in the response deviating from the reference value, and thus the tampering behavior can be detected. The hardware information verification module in the present application confirms the real-time response of the hardware device through the physical unclonable function challenge random code, rather than a statically stored key, which can avoid the risk of key leakage.

[0123] In some embodiments, sending random excitation information to a server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, and verifying the response information to determine the second verification information includes:

[0124] Provide a random active drive signal to the server hardware device and obtain the response information fed back by the server hardware device based on the random active drive signal;

[0125] Determine the second verification information according to the verification result of the response information and the preset response information.

[0126] Exemplarily, a random active drive signal can be provided to the hardware device, such as providing a voltage signal or a current signal. Due to uncontrollable tiny differences generated during the manufacturing process of the hardware device, the response information fed back by the hardware device is different under this random active drive signal. For example, the waveform of the response information it feeds back is different. In the embodiments of the present application, the second verification information can be determined by comparing the response information with the pre-stored preset response information.

[0127] By obtaining the response information fed back by the hardware device in real time, the present application can be regarded as the dynamic fingerprint of the hardware device, such as physical characteristics like voltage fluctuation waveforms and signal noises. The second verification information is generated based on the dynamic fingerprint of the hardware device. The static fingerprints of traditional hardware devices (such as PN and SN) are easily forged or tampered with, while the dynamic fingerprint is based on the physical characteristics during the real-time operation of the hardware (such as current fluctuations during CPU instruction execution), and it is difficult to be replicated or simulated. When hardware components (such as motherboards and storages) are replaced, the dynamic fingerprint will change significantly, so illegal access can be prevented. The technology of obtaining the dynamic fingerprint of the hardware device by providing a random active drive signal and then performing verification in the present application provides a more underlying and more attack-resistant protection means for server security, especially suitable for scenarios with extremely high security requirements.

[0128] In some embodiments, determining the second verification information according to the verification result of the response information and the preset response information includes:

[0129] Determine the second verification information according to the second preset weight assignment value, the response value matching degree between the response information and the preset response information, and the timestamp matching degree of the response information.

[0130] When determining the second verification information in the present application, the response value matching degree between the response information and the preset response information and the timestamp matching degree of the response information can be comprehensively considered by means of weight assignment. The second preset weight assignment value can be set in advance, and the second preset weight assignment value represents the weight coefficients corresponding to the response value matching degree between the response information and the preset response information and the timestamp matching degree of the response information respectively.

[0131] The present application can set weight coefficients corresponding to the response value matching degree between the response information and the preset response information and the timestamp matching degree of the response information according to actual needs. For example, if higher accuracy is required for the response value matching degree between the response information and the preset response information, a higher weight coefficient can be set for the response value matching degree between the response information and the preset response information. If higher accuracy is required for the timestamp matching degree of the response information, a higher weight coefficient can be set for the timestamp matching degree of the response information. The present application can adjust and set the second preset weight allocation value according to actual needs, so that when determining the second verification information based on the verification result of the response information and the preset response information, more accurate second verification information that meets its own needs can be obtained based on the requirements.

[0132] Exemplarily, the response value matching degree between the response information and the preset response information, and the timestamp matching degree of the response information can be determined in the following manner:

[0133] Response value matching degree between the response information and the preset response information: Compare the matching degree between the real-time response information and the pre-stored preset response information to obtain the matching degree percentage.

[0134] Timestamp matching degree of the response information: Verify whether the timestamp of the response information exceeds the threshold. If it does not exceed the threshold, it indicates that the timestamp is valid, and the value is 1; otherwise, it is 0.

[0135] Exemplarily, weighted calculation is performed on the response value matching degree between the response information and the preset response information and the timestamp matching degree of the response information. For example, the weight coefficient corresponding to the response value matching degree between the response information and the preset response information in the second preset weight allocation value is 0.8, and the weight coefficient corresponding to the timestamp matching degree of the response information in the second preset weight allocation value is 0.2.

[0136] Correspondingly, the second verification information = (response value matching degree between the response information and the preset response information × 0.8) + (timestamp matching degree of the response information × 0.2)

[0137] It should be noted that the second preset weight allocation value can be set according to actual situations. In the present application, only an example is given that the weight coefficient corresponding to the response value matching degree between the response information and the preset response information in the second preset weight allocation value is 0.8, and the weight coefficient corresponding to the timestamp matching degree of the response information in the second preset weight allocation value is 0.2.

[0138] In some embodiments, weight allocation is performed on the first verification information and the second verification information based on the risk level to determine the security verification result, including:

[0139] Obtain the weight coefficient corresponding to the first verification information and the weight coefficient corresponding to the second verification information at this risk level;

[0140] Determine the security verification result based on the first verification information, the second verification information, the weight coefficient corresponding to the first verification information, and the weight coefficient corresponding to the second verification information at this risk level.

[0141] This application can allocate different weight coefficients to the first verification information reflecting the static fingerprint of the hardware device and the second verification information reflecting the dynamic fingerprint of the hardware device according to different risk levels. For example, the weight coefficients corresponding to the first verification information and the second verification information at different risk levels can be pre-stored. Table 1 shows the weight coefficients corresponding to the first verification information and the second verification information at different risk levels. Table 1 exemplarily includes 3 risk levels, namely low risk, medium risk, and high risk. Among them, the weight coefficient corresponding to the first verification information under low risk is 0.5, and the weight coefficient corresponding to the second verification information is 0.5. The weight coefficient corresponding to the first verification information under medium risk is 0.4, and the weight coefficient corresponding to the second verification information is 0.6. The weight coefficient corresponding to the first verification information under high risk is 0.3, and the weight coefficient corresponding to the second verification information is 0.7.

[0142] The calculation of the security verification result can be according to the following formula:

[0143] Security verification result = (First verification information × Weight coefficient corresponding to the first verification information) + (Second verification information × Weight coefficient corresponding to the second verification information).

[0144] If the current risk level is low risk, then the security verification result calculated according to Table 1 = (First verification information × 0.5) + (Second verification information × 0.5).

[0145] Table 1: Weight coefficients corresponding to the first verification information and the second verification information at different risk levels

[0146]

[0147] If there are multiple second verification information. Then when calculating the security verification result, it can be according to the following formula:

[0148]

[0149] Among them, M i is any first verification information or second verification information, and N i is the weight coefficient corresponding to M i .

[0150] Exemplarily, the risk level of the server is low risk, the first verification information is M 1 , and the weight coefficient corresponding to the first verification information M 1 is N 1 . The two second verification information are respectively M2 and M 3 The second verification information M 2 The corresponding weight coefficient is N 2 The second verification information M 3 The corresponding weight coefficient is N 3 Then the security verification result = M 1 ×N 1 + M 2 ×N 2 + M 3 ×N 3 .

[0151] In some embodiments, based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level, a function permission control policy for the server is generated, including:

[0152] Based on the security verification result being greater than or equal to the security verification threshold corresponding to the risk level, a server power-on control instruction is generated.

[0153] The security verification threshold corresponding to the risk level can also be stored in advance. For example, it can be stored in the hardware information verification module, and the hardware information verification module can be BMC for example. See Table 1 for example. The security verification threshold corresponding to low risk is 0.8, the security verification threshold corresponding to medium risk is 0.85, and the security verification threshold corresponding to high risk is 0.9. Compare the obtained security verification result with the security verification threshold corresponding to the risk level, and generate a function permission control policy for the server according to the comparison result. If the security verification result is greater than or equal to the security verification threshold corresponding to the risk level, it indicates that the security of the hardware device is relatively high, and a server power-on control instruction is generated to enable the entire server system to power on and run without restricting the functions of the server. A control module can be set in the server's security verification system. The control module can communicate with the hardware information verification module, and the control module can control the entire server system to power on and run according to the server power-on control instruction of the hardware information verification module.

[0154] In some embodiments, it can be set that the higher the risk level, the larger the corresponding security verification threshold. As shown in Table 1, the security verification threshold corresponding to low risk is 0.8, the security verification threshold corresponding to medium risk is 0.85, and the security verification threshold corresponding to high risk is 0.9. As the risk level increases, the security verification threshold increases.

[0155] The security verification result is greater than or equal to the security verification threshold corresponding to the risk level, indicating that the hardware device meets the preset security requirements (such as the hardware device has not been tampered with, etc.). If the security verification threshold is set too low, it may cause devices with low security to be misjudged as trustworthy; if it is too high, it may frequently reject legitimate hardware devices. In high-risk scenarios, stricter verification standards are required. The security verification threshold corresponding to high risk is higher, so a higher security verification result score is required to pass, thereby reducing the probability of security vulnerabilities in high-risk scenarios. The system can flexibly adjust the verification intensity in different risk scenarios and work in coordination with the three-dimensional verification mechanism of "the risk level of the environment + the static fingerprint of the hardware device + the dynamic fingerprint of the hardware device" to form a multi-level security protection system.

[0156] In some embodiments, a function permission control policy for the server is generated based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level, including:

[0157] Based on the security verification result being less than the security verification threshold corresponding to the risk level, a function permission control instruction corresponding to the risk level is generated.

[0158] If the security verification result is less than the security verification threshold corresponding to the risk level, it indicates that the hardware device has a certain security risk. Then, a function permission control instruction corresponding to the current risk level can be generated. The function permission control instructions corresponding to different risk levels can also be preset and stored in advance.

[0159] Exemplarily, if the current risk level is medium risk and the security verification result is less than the security verification threshold corresponding to medium risk, then a function permission control instruction corresponding to medium risk is generated. The function permission control instruction corresponding to medium risk can be, for example, an instruction to close the external interface to avoid problems such as data leakage caused by interaction with the outside.

[0160] In some embodiments, generating a function permission control instruction corresponding to the risk level based on the security verification result being less than the security verification threshold corresponding to the risk level includes:

[0161] Based on the security verification result being less than the security verification threshold corresponding to the risk level and the risk level being the highest risk level, a power-off instruction and / or an alarm instruction is generated.

[0162] If the current risk level is the highest risk level and the security verification result is less than the security verification threshold corresponding to the highest risk level, it indicates that the security risk of the server is very high. The present application can trigger a fuse, generate a power-off instruction, and avoid risks such as component forgery and network attacks caused by running under the condition of high security risk. The present application can also generate an alarm indication, for example, sending an alarm indication to an external management platform to prompt the staff.

[0163] Figure 4 Provide a specific example of a security verification method. As Figure 4 shown, the security verification method provided by the embodiments of the present application includes:

[0164] S201. The power supply module supplies power to the environmental status data acquisition module, the hardware information acquisition module, and the hardware information verification module.

[0165] S202. The environmental status data processing module in the environmental status data acquisition module reads the environmental status data and security measurement values collected by the environmental status data cluster, generates an environmental snapshot with a time stamp, and the trusted platform module TPM in the environmental status data cluster encrypts the environmental snapshot to generate an immutable environmental label.

[0166] S203. The hardware information acquisition module obtains the identification code, digital signature, and preset response information of the hardware device stored in the hardware information storage module through the bus. The hardware information verification module sends random excitation information to the server hardware device through the hardware information acquisition module, and the hardware information acquisition module obtains the response information fed back by the server hardware device based on the random excitation information. The hardware information acquisition module calls the TPM2_VerifySignature command of the trusted platform module and verifies the signature using the preset vendor public key.

[0167] S204. The hardware information verification module reads the environmental label from the trusted platform module, decrypts and extracts the environmental status data and the security measurement value of the trusted platform module, and determines the risk level of the server according to the comparison result between the environmental status data and the security measurement value of the trusted platform module and the preset baseline value. The hardware information verification module determines the first verification information according to the signature verification result of the trusted platform module TPM. The hardware information verification module obtains the response information fed back by the server hardware device based on the random excitation information through the hardware information acquisition module, and determines the second verification information according to the verification result between the response information and the preset response information.

[0168] S205. The hardware information verification module assigns weights to the first verification information and the second verification information according to the risk level, and calculates the security verification result according to the weight assignment. According to the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level, a server function permission control policy is generated.

[0169] S206. The control module executes hierarchical responses according to the server function permission control policy generated by the hardware information verification module, and controls the power state and hardware function permissions of the server.

[0170] This application realizes data fusion, dynamic weight allocation, and real-time response mechanism from three dimensions, namely, the environmental dimension, the static fingerprint dimension of hardware devices, and the dynamic fingerprint dimension of hardware devices, and achieves accurate control of the credibility verification and function permissions of hardware devices. For example, in the environmental dimension, through the encrypted binding of environmental data such as temperature, humidity, and voltage with the PCR value, it is ensured that the hardware operates in a trusted physical environment, preventing device failures or malicious induced attacks caused by abnormal environments. In the static fingerprint dimension of hardware devices, the authenticity of the hardware identity is confirmed based on the digital signature verification of the identification code. In the dynamic fingerprint dimension of hardware devices, based on

[0171] PUF random excitation response, the confirmation of physical unclonability is realized. According to the security verification results and risk levels, the server function permissions are dynamically adjusted. For example, warning-level risk: restricting non-critical functions (such as disabling the USB interface); severe-level risk: isolating the affected hardware or triggering an automatic recovery mechanism; power state intervention: in extreme cases (such as detecting that the hardware has been tampered with), directly controlling the power state to cut off the attack path and prevent continuous damage. Further, the preset response information and baseline values can be written into the hardware at the time of factory, supporting subsequent updates to adapt to new scenarios. The timestamp of the environmental label can be used to trace the specific time point when a security event occurs, assisting in fault location and attack tracing. The security verification method provided by this application realizes the closed-loop management of "risk perception - verification - response control" through a verification strategy driven by dynamic risk grading, dynamically couples the environmental risk level with hardware verification, and superimposes environmental credibility and behavior compliance verification on the basis of hardware static fingerprint and dynamic fingerprint verification. Compared with a single verification mechanism, this solution is applicable to scenarios of resisting advanced hardware attacks and can meet the full-life cycle protection requirements of server hardware in complex threat environments.

[0172] This embodiment also provides a server, Figure 5 which is a schematic structural diagram of a server provided by an embodiment of this application, as Figure 5As shown in the figure, the server includes the security verification system 100 in any of the above embodiments. The security verification system includes an environmental status data acquisition module 10, a hardware information acquisition module 20, and a hardware information verification module 30. The environmental status data acquisition module 10 is configured to acquire the environmental status data of the server. The hardware information acquisition module 20 is configured to obtain the hardware identification information of the server hardware device, and send the response information fed back by the server hardware device based on the random excitation information to the hardware information verification module 30. The hardware information verification module 30 is configured to verify the environmental status data of the server to determine the risk level of the server; verify the hardware identification information of the server hardware device to determine the first verification information; send random excitation information to the server hardware device, and obtain the response information fed back by the server hardware device based on the random excitation information, verify the response information to determine the second verification information; allocate weights to the first verification information and the second verification information based on the risk level to determine the security verification result; generate a server function permission control policy based on the risk level and the comparison result between the security verification result and the security verification threshold corresponding to the risk level. The function description of the security verification system in this server is similar to that in the corresponding above embodiments, and will not be elaborated here.

[0173] An embodiment of the present application also provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any of the above embodiments of the security verification method when running.

[0174] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: USB flash drive, read-only memory (abbreviated as ROM), random access memory (abbreviated as RAM), mobile hard disk, magnetic disk, or optical disc and other various media that can store computer programs.

[0175] An embodiment of the present application also provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the security verification method.

[0176] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the security verification method.

[0177] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.

[0178] The above has introduced in detail a security verification method provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A security verification method, characterized in that: include: Verify the server's environmental status data and determine the server's risk level; Verifying the hardware identification information of the server hardware device to determine first verification information; Sending random excitation information to the server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, verifying the response information, and determining second verification information; Based on the risk level, weights are assigned to the first verification information and the second verification information to determine a security verification result; Generate a server function authority control policy based on the risk level and a comparison result of the security verification result and a security verification threshold corresponding to the risk level; The higher the risk level, the greater the weight coefficient of the second verification information, and the smaller the weight coefficient of the first verification information.

2. The safety verification method according to claim 1, characterized in that: The verifying of the environmental status data of the server to determine the risk level of the server includes: Read the environment tag and decrypt it to extract the environment status data and the security measurement value of the trusted platform module; Determining a risk level of the server based on the comparison result between the environmental status data and the security measurement value of the trusted platform module and a preset baseline value; The environment tag is generated by the trusted platform module by encrypting an environment snapshot including environment status data, security measurement value, and timestamp.

3. The safety verification method according to claim 1, characterized in that: The step of verifying the hardware identification information of the server hardware device to determine the first verification information includes: Obtain the identification code and digital signature of the server hardware device; The first verification information is determined according to the verification result of the identification code and the digital signature.

4. The safety verification method according to claim 3, characterized in that: The determining the first verification information according to the verification result of the identification code and the digital signature includes: The first verification information is determined according to the first preset weight distribution value, the comparison result between the identification code and the authorized hardware device list, and the verification result of the digital signature.

5. The safety verification method according to claim 1, characterized in that: The sending of random excitation information to the server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, verifying the response information, and determining second verification information includes: Send a variety of random excitation information to the server hardware device, obtain each response information fed back by the server hardware device based on the one-to-one correspondence of each random excitation information, verify each response information, and determine each second verification information corresponding to each response information.

6. The safety verification method according to claim 1, characterized in that: The sending of random excitation information to the server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, verifying the response information, and determining second verification information includes: Sending a physical unclonable function challenge random code to the server hardware device, and obtaining response information fed back by the server hardware device based on the physical unclonable function challenge random code; The second verification information is determined according to the verification result of the response information and the preset response information.

7. The safety verification method according to claim 1, characterized in that: The determining the second verification information according to the verification result of the response information and the preset response information includes: The second verification information is determined according to the second preset weight distribution value, the response value matching degree between the response information and the preset response information, and the timestamp matching degree of the response information.

8. The safety verification method according to claim 1, characterized in that: The generating a function permission control policy of the server based on the risk level and a comparison result between the security verification result and a security verification threshold value corresponding to the risk level includes: Based on the security verification result being greater than or equal to the security verification threshold corresponding to the risk level, a server startup control instruction is generated.

9. The safety verification method according to claim 1, characterized in that: The generating a function permission control policy of the server based on the risk level and a comparison result between the security verification result and a security verification threshold value corresponding to the risk level includes: Based on the security verification result being less than a security verification threshold corresponding to the risk level, a function authority control instruction corresponding to the risk level is generated.

10. The safety verification method according to claim 9, characterized in that: The generating a function permission control instruction corresponding to the risk level based on the security verification result being less than the security verification threshold corresponding to the risk level comprises: Based on the fact that the safety verification result is less than the safety verification threshold corresponding to the risk level, and the risk level is the highest risk level, a power-off instruction and / or an alarm instruction is generated.

11. A safety verification system, characterized in that: include: An environmental status data collection module configured to collect environmental status data of a server; A hardware information acquisition module is configured to obtain hardware identification information of a server hardware device, and send response information fed back by the server hardware device based on random stimulus information to a hardware information verification module; The hardware information verification module is configured to: verify the environmental status data of the server to determine the risk level of the server; verify the hardware identification information of the server hardware device to determine the first verification information; Sending random excitation information to the server hardware device, obtaining response information fed back by the server hardware device based on the random excitation information, verifying the response information, and determining second verification information; Based on the risk level, weights are assigned to the first verification information and the second verification information to determine a security verification result; Generate a server function authority control policy based on the risk level and a comparison result of the security verification result and a security verification threshold corresponding to the risk level; The higher the risk level, the greater the weight coefficient of the second verification information, and the smaller the weight coefficient of the first verification information.

12. The safety verification system according to claim 11, characterized in that: The environmental status data acquisition module includes an environmental status data cluster and an environmental status data processing module; the environmental status data cluster includes a sensor, a network module and a trusted platform module; The environment status data cluster is configured to collect environment status data; the environment status data processing module is configured to obtain the environment status data and the security metric value of the trusted platform module, and generate an environment snapshot; the environment snapshot includes the environment status data, the security metric value, and a timestamp; The trusted platform module is configured to encrypt the environment snapshot to generate an environment tag; The hardware information verification module is configured to read the environment tag, decrypt and extract the environment status data and the security measurement value of the trusted platform module, and determine the risk level of the server based on the comparison result of the environment status data and the security measurement value of the trusted platform module with the preset baseline value.

13. The safety verification system according to claim 12, characterized in that: Also includes a hardware information storage module; The hardware information storage module is configured to store identification codes, digital signatures, and preset response information of hardware devices; The hardware information acquisition module is configured to obtain the identification code, digital signature and preset response information of the hardware device stored in the hardware information verification module through the bus, and control the trusted platform module to perform signature verification; The hardware information verification module is configured to determine first verification information according to the signature verification result; And sending random excitation information to the server hardware device through the hardware information acquisition module, obtaining response information fed back by the server hardware device based on the random excitation information, and determining second verification information according to the verification result of the response information and preset response information.

14. The safety verification system according to claim 11, characterized in that: The hardware information acquisition module is configured to add a timestamp to the response information generated by the hardware device based on the random excitation information and send the response information to the hardware information verification module.

15. The safety verification system according to claim 11, characterized in that: It also includes a control module, which is configured to obtain and execute the server function authority control policy.

16. The safety verification system according to claim 15, characterized in that: It also includes a power supply module, and the control module is configured to control the power supply of the power supply module according to the server function authority control policy.

17. A server, characterized in that: Comprising a safety verification system as described in any one of claims 11 to 16.

18. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the security verification method according to any one of claims 1 to 10.

19. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the security verification method according to any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • Cloud server monitoring method, device and equipment and storage medium

    CN111737081A

  • Basic input and output system mirror image verification method, device, equipment and medium

    CN115048655A

  • Method and system for establishing encrypted communication based on remote authentication of trusted hardware, and medium

    CN118074919A