Implementation method and system for secure operating system of power embedded device

By using trusted computing, separation of power and audit log technologies in embedded devices of power systems, we ensure that the operating system operates in a trusted environment and implements full audits, the problem of lack of effective security protection in the existing technology is solved, and the security of the system is significantly improved.

CN119989312APending Publication Date: 2025-05-13BEIJING SIFANG JIBAO ENG TECH +1
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411983019.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-13

AI Technical Summary

Technical Problem

The embedded devices of existing power system lack effective security protection measures, cannot effectively protect the system when the system is started, and cannot actively protect it, resulting in the system being vulnerable to malicious attacks and code intrusion.

Method used

Trusted computing technology, separation of powers and audit log technology are used to measure the operating system's boot program through the TPCM hardware module to ensure that the operating system runs in a trusted environment, and to implement full-process audit trails to limit the access rights of malicious users.

Benefits of technology

It effectively improves the security of the operating system, prevents malicious code from intrusion, protects the system's critical data and resources, records the system's operation records in real time, and discovers and prevents security problems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119989312A_ABST
    Figure CN119989312A_ABST
Patent Text Reader

Abstract

The invention discloses a method and a system for realizing a secure operating system of an electric power embedded device. The method comprises the steps that a mainboard is connected to a TPCM hardware module, and the TPCM hardware module controls a CPU through an I / O pin and carries out safe interaction with the CPU through an SPI bus; before an SFOS operating system is started, a bootstrap program of the operating system is measured through a TPCM hardware module, if measurement succeeds, the bootstrap program normally loads the operating system, and if measurement fails, the TPCM organizes operation of the operating system; the trusted basic software module is operated, the TPCM module is managed, the SFOS and the application program are protected, active interception is carried out in an SFOS operating system, and transparent and trusted support for the application program is realized; a security management center is created, system management, security management and audit management are realized, comprehensive security policy management is performed on a computing environment, a region boundary and a communication network, user operation authority is determined, and whole-course audit tracking is implemented. According to the scheme, the safety of the automatic secondary equipment of the power system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of embedded devices in power systems, and in particular relates to a method and system for implementing a secure operating system of an embedded power device. Background Art

[0002] With the continuous development of power systems, the safety requirements for power system automation are getting higher and higher, and the safe operating environment of secondary equipment is particularly important. The operating system is the core software for the normal operation of the equipment. It manages computer hardware and software resources and provides expenditures for applications. If the operating system is maliciously attacked or tampered with, it may cause serious security problems. Therefore, the development of security technology for the operating system is crucial.

[0003] At present, due to system resource problems, all security protection tools in substations are deployed on host devices, and embedded devices cannot be installed, which account for 93.8% of substation equipment. Most embedded device security protections also rely on boundary protection such as firewalls and vertical density, and there are no systematic protection measures for the devices themselves. Moreover, these security protection measures are deployed on the system, and cannot provide effective protection when the system is started, nor can they provide active protection.

[0004] The Chinese patent "CN1183129548A A method for protecting the integrity of the Linux system" obtains the kernel with integrity protection function through modification and stores it in the storage medium, and the Linux operating platform loads and runs it. This method does not perform a security check on the Linux boot program, and needs to download the kernel from the storage medium, which is not suitable for power embedded devices.

[0005] The Chinese patent "CN114840863B A secure storage method and system based on trusted embedded devices and FTP" builds a trusted embedded device and host environment, and the host and embedded device are accessed and transmitted through FTP. In the host environment, after successful authentication, the embedded device is accessed through the FTP function. In power embedded devices, there are generally dozens of devices in a substation, and there is no one-master-multiple-slave management method. In addition, in the power system specification requirements, the FTP port is not safe and is prohibited from being opened. Summary of the invention

[0006] In order to address the deficiencies in the prior art, the present invention provides a method and system for implementing a secure operating system for an electric embedded device to prevent malicious attacks and code intrusions, protect key data and resources of the system, and prevent power accidents caused by system misoperation, thereby improving the safety of secondary equipment in the power system automation.

[0007] In order to solve the above technical problems, the present invention adopts the following technical solutions.

[0008] The present invention first discloses a method for implementing a secure operating system for an electric embedded device, the method comprising the following steps:

[0009] Step 1: Connect the mainboard to the TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through the SPI bus;

[0010] Step 2: Before the SFOS operating system is started, the boot program of the operating system is measured by the TPCM hardware module. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system.

[0011] Step 3: Run the trusted basic software module to manage the TPCM module, protect SFOS and applications, and actively intercept inside the SFOS operating system to achieve transparent and trusted support for applications;

[0012] Step 4: Create a security management center, which implements system management, security management, and audit management, performs comprehensive security policy management on computing environments, regional boundaries, and communication networks, determines user operating permissions, and implements full audit tracking.

[0013] The present invention further includes the following preferred embodiments:

[0014] The construction of the TPCM hardware module further includes:

[0015] The TPCM hardware module is constructed using a domestic cryptographic chip based on EAL5 certification. The cryptographic chip stores algorithm IP, static logic for directly controlling the CPU through I / O pins, and dynamic logic for interacting with the CPU for security functions through the SPI bus.

[0016] The CPU directly controls the reset of the TPCM hardware module through the GPIO pin and accesses the state of the TPCM hardware module. The TPCM hardware module controls the reset state of the CPU through the CPU_RESET pin and selects the SPI bus for communication.

[0017] The step of measuring the boot program of the operating system by the TPCM hardware module further includes:

[0018] Initialize power-on and use the public key HASH in the storage area to verify the boot program. The CPU_RESET signal of the TPCM hardware module resets the CPU. At the same time, the SPI2 bus is selected, and the M_SPI of the TPCM hardware module starts measurement for the boot flash program.

[0019] The operation of the operating system organized by TPCM further includes:

[0020] Load the boot flash program to start the CPU. A core-based bare-metal program first runs the initialization, loads and verifies the SFOS program stored in the flash, and the bare-metal program and the TPCM hardware module jointly measure the SFOS program. If the measurement is successful, SFOS runs successfully.

[0021] The granting of corresponding permissions to each type of administrator further includes:

[0022] The system management subsystem implements centralized management and maintenance of computing nodes, security area boundaries, and secure communication networks in the security protection environment, including user identity management, resource management, and emergency response, providing basic protection for the security of the information system; the security management subsystem implements tag management, authorization management, and policy management; the audit subsystem formulates audit strategies and audits the behavior of the entire information system.

[0023] The recording, monitoring and analysis of the behavior activities of the SFOS operating system through the audit service further includes:

[0024] Actively identify the deletion and tampering of applications and important configuration parameter files, generate audit records and issue alarms, and include measurement time, measurement object, and measurement results in the measurement results, which are then encrypted and saved.

[0025] The present invention also discloses a system for implementing a secure operating system for an electric embedded device using the aforementioned method for implementing a secure operating system for an electric embedded device, comprising:

[0026] A trusted computing module, used to connect the mainboard to a TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through an SPI bus;

[0027] An operating system boot module, used to measure the boot program of the operating system through the TPCM hardware module before the SFOS operating system is started. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system;

[0028] A trusted basic software module is used to manage the TPCM module, protect SFOS and applications, and actively intercept inside the SFOS operating system to achieve transparent and trusted support for applications; the trusted basic software module runs in parallel with the SFOS operating system to form a trusted node framework. By triggering at the node, the SFOS operating system actively obtains monitoring information and transmits it to the trusted basic software module. The trusted basic software module accesses the trusted root of the TPCM module, measures the behavior of the SFOS operating system according to the trusted policy of the security management center, and uploads the audit information to the security management center;

[0029] The Security Management Center is used to implement system management, security management, and audit management, conduct comprehensive security policy management of computing environments, regional boundaries, and communication networks, determine user operating permissions, and implement full audit tracking.

[0030] Accordingly, the present application also discloses a terminal, including a processor and a storage medium;

[0031] The storage medium is used to store instructions;

[0032] The processor is used to operate according to the instructions to execute the steps of the method for implementing the secure operating system of the power embedded device.

[0033] Correspondingly, the present application also discloses a computer-readable storage medium on which a computer program is stored, and when the program is executed by a processor, the steps of the aforementioned method for implementing a secure operating system for a power embedded device are implemented.

[0034] The beneficial effect of the present invention is that, compared with the prior art, the present invention provides a method and system for implementing a secure operating system for an electric embedded device, which combines the SFOS operating system developed by Sifang Company with the underlying security technologies of the operating system such as trusted computing, separation of powers, and audit logs, ensuring that the program runs in a trusted environment, and can effectively improve the security of the operating system. By introducing trusted computing technology, it is possible to ensure that the operating system runs in a trusted environment, thereby preventing the intrusion of malicious code; by introducing separation of powers technology, it is possible to limit the access rights of malicious users, thereby protecting the key data and resources of the system; by introducing audit log technology, it is possible to record the operation records of the system in real time, thereby discovering and preventing security issues. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is the main framework diagram of the secure operating system of the power embedded device in the present invention.

[0036] Figure 2 It is a schematic diagram of the TPCM hardware module in the present invention.

[0037] Figure 3It is a connection pin diagram between the TPCM hardware module and the mainboard in the present invention. DETAILED DESCRIPTION

[0038] In order to make the purpose, technical solution and advantages of the present invention more clear, the technical solution of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention.

[0039] The embodiments described in this application are only some embodiments of the present invention, not all embodiments. Based on the spirit of the present invention, other embodiments obtained by ordinary technicians in this field without creative work are all within the protection scope of the present invention.

[0040] In view of the shortcomings of the prior art, the present invention proposes a method and system for implementing a secure operating system for an electric embedded device. In order to prevent the device from being maliciously attacked and tampered with, resulting in data leakage and malfunction, etc., trusted technology, separation of powers and audit technology are adopted to enable the system to have active protection functions, isolate risks, and ensure the normal operation of power secondary equipment.

[0041] Add TPCM hardware module to the main CPU board hardware of the existing device to ensure the hardware trust environment and provide a static measurement basis for the startup of the operating system. Modify the SFOS operating system startup program and process. The TPCM hardware module measures the boot program of the operating system. If the measurement is successful, the boot program loads the operating system normally; if the measurement fails, TPCM organizes the operation of the operating system. Use the separation of powers and audit mechanism to timely discover and organize malicious behavior.

[0042] Figure 1 The main framework structure diagram of the technical solution of the present invention. The method for implementing a secure operating system for an electric embedded device disclosed in the present invention comprises the following steps:

[0043] Step 1: Connect the mainboard to the TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through the SPI bus.

[0044] In terms of hardware modification, such as Figure 2 As shown in the figure, the TPCM hardware module is composed of a domestic cryptographic chip based on EAL5 certification. The cryptographic chip stores the algorithm IP, static logic for directly controlling the CPU through the I / O pins, and dynamic logic for interacting with the CPU for security functions through the SPI bus. Figure 3 As shown, the main CPU directly controls the TPCM hardware module reset through the GPIO pin and accesses the state of the TPCM hardware module. The TPCM hardware module controls the reset state of the CPU through the CPU_RESET pin and selects the SPI bus for communication.

[0045] Step 2: Before the SFOS operating system is started, the boot program of the operating system is measured by the TPCM hardware module. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system.

[0046] The boot process of the operating system is as follows: initial power-on, use the public key HASH of the storage area to verify the boot program, the CPU_RESET signal of TPCM resets the CPU, and selects the SPI2 bus at the same time. TPCM's M_SPI starts measuring the bootflash program; if the measurement is successful, TPCM releases the CPU_RESET signal, if the measurement fails, TPCM organizes the operation of the operating system. Then, the boot flash program is loaded to start the CPU, a core bare-running program first runs the initialization, loads and verifies the SFOS program stored in the flash, and the bare-running program and the TPCM hardware module jointly measure the SFOS program. If the measurement is successful, SFOS runs successfully.

[0047] After the SFOS operating system is running, monitoring points are set at the application entry, during program execution, and at the kernel system call to actively intercept and obtain operation behaviors, and perform trusted verification based on the trusted policy library algorithm. Trusted application software has a whitelist mechanism that can calculate the summary value of the monitoring program and match it with the whitelist to execute the corresponding management policy.

[0048] Step 3: Run the trusted basic software module to manage the TPCM module, protect SFOS and applications, and actively intercept within the SFOS operating system to achieve transparent and trusted support for applications.

[0049] The trusted basic software module uses the TPCM module as the trusted root to build a basic trust base, control mechanism, measurement mechanism, judgment mechanism, support mechanism and trusted benchmark library; the basic trust base provides trusted verification and trusted assurance of the initial state for the trusted basic software module and the SFOS system application; the control mechanism, measurement mechanism, judgment mechanism and trusted benchmark library jointly complete the active measurement of the SFOS system operating environment and applications; the support mechanism provides trusted cryptographic services to support the trusted basic software module's access and management of the TPCM module, the management of trusted policies and the management of trusted benchmark information.

[0050] The trusted basic software module monitors application behavior through system call hooks, virtual machine monitors, and underlying library functions according to the trusted policy; a hook mechanism is set at the operating system, VMM, or underlying middleware level to submit the monitored information to the trusted basic software module, and actively intercepts untrusted behavior based on trusted policy measurements.

[0051] The trusted policy measurement further measures the code segment of the process in a triggering manner to reduce CPU power consumption.

[0052] Step 4: Create a security management center, which implements system management, security management, and audit management, performs comprehensive security policy management on computing environments, regional boundaries, and communication networks, determines user operating permissions, and implements full audit tracking.

[0053] The system management subsystem implements centralized management and maintenance of computing nodes, security area boundaries, and secure communication networks in the security protection environment, including user identity management, resource management, and emergency response, providing basic protection for the security of the information system; the security management subsystem implements tag management, authorization management, and policy management; the audit subsystem formulates audit strategies and audits the behavior of the entire information system.

[0054] The system startup script creates three accounts: system administrator, security administrator, and audit administrator; divides the relevant administrator permissions, different administrators access paths and files, and modify the sudo configuration. The system management subsystem implements centralized management and maintenance of computing nodes, security area boundaries, and secure communication networks in the security protection environment, including user identity management, resource management, and emergency response, providing basic protection for the security of the information system; the security management subsystem implements tag management, authorization management, and policy management; the audit subsystem formulates audit strategies and audits the behavior of the entire information system. The minimum privilege separation of administrators and users is achieved.

[0055] Trusted programs add audit functions to proactively identify the deletion and tampering of applications and important configuration parameter files, generate audit records and issue alerts, and include measurement time, measurement object, and measurement results in the measurement results, which are then encrypted and saved.

[0056] Start the auditd service in the SFOS system to record, monitor and analyze SFOS system activities. The audit log file is recorded in / var / log / audit. The security module verifies the operating system behavior to ensure that the system behavior is credible.

[0057] The beneficial effect of the present invention is that, compared with the prior art, the present invention provides a method and system for implementing a secure operating system for an electric embedded device, which combines the SFOS operating system developed by Sifang Company with the underlying security technologies of the operating system such as trusted computing, separation of powers, and audit logs, ensuring that the program runs in a trusted environment, and can effectively improve the security of the operating system. By introducing trusted computing technology, it is possible to ensure that the operating system runs in a trusted environment, thereby preventing the intrusion of malicious code; by introducing separation of powers technology, it is possible to limit the access rights of malicious users, thereby protecting the key data and resources of the system; by introducing audit log technology, it is possible to record the operation records of the system in real time, thereby discovering and preventing security issues.

[0058] The present invention may be a system, a method and / or a computer program product. The present invention also discloses a secure operating system implementation system for a power embedded device based on the aforementioned secure operating system implementation method for a power embedded device, comprising:

[0059] A trusted computing module, used to connect the mainboard to a TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through an SPI bus;

[0060] An operating system boot module, used to measure the boot program of the operating system through the TPCM hardware module before the SFOS operating system is started. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system;

[0061] A trusted basic software module is used to manage the TPCM module, protect SFOS and applications, and actively intercept inside the SFOS operating system to achieve transparent and trusted support for applications; the trusted basic software module runs in parallel with the SFOS operating system to form a trusted node framework. By triggering at the node, the SFOS operating system actively obtains monitoring information and transmits it to the trusted basic software module. The trusted basic software module accesses the trusted root of the TPCM module, measures the behavior of the SFOS operating system according to the trusted policy of the security management center, and uploads the audit information to the security management center;

[0062] The Security Management Center is used to implement system management, security management, and audit management, conduct comprehensive security policy management of computing environments, regional boundaries, and communication networks, determine user operating permissions, and implement full audit tracking.

[0063] Based on the spirit of the present invention, those skilled in the art can easily think that a computer program product can be obtained based on the aforementioned method for implementing a secure operating system for an electric embedded device. The computer program product may include a computer-readable storage medium on which are loaded computer-readable program instructions for enabling a processor to implement various aspects of the present disclosure. That is, the present application also includes a terminal, including a processor and a storage medium; the storage medium is used to store instructions; the processor is used to operate according to the instructions to execute the steps of the aforementioned method for implementing a secure operating system for an electric embedded device.

[0064] Computer readable storage medium can be a tangible device that can keep and store the instructions used by the instruction execution device. Computer readable storage medium can be, for example, - but not limited to - electrical storage device, magnetic storage device, optical storage device, electromagnetic storage device, semiconductor storage device or any suitable combination of the above. More specific examples (non-exhaustive list) of computer readable storage medium include: portable computer disk, hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), static random access memory (SRAM), portable compact disk read-only memory (CD-ROM), digital versatile disk (DVD), memory stick, floppy disk, mechanical encoding device, for example, punch card or groove protrusion structure with instructions stored thereon and any suitable combination of the above. Computer readable storage medium used here is not interpreted as instantaneous signal itself, such as radio wave or other free propagating electromagnetic wave, electromagnetic wave propagated by waveguide or other transmission medium (for example, light pulse by optical fiber cable) or electrical signal transmitted by wire.

[0065] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to each computing / processing device, or downloaded to an external computer or external storage device via a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network can include copper transmission cables, optical fiber transmissions, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. The network adapter card or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.

[0066] The computer program instructions for performing the operation of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-related instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages-such as Smalltalk, C++, etc., and conventional procedural programming languages-such as "C" language or similar programming languages. Computer-readable program instructions may be executed completely on a user's computer, partially on a user's computer, as an independent software package, partially on a user's computer, partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer via any type of network-including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., using an Internet service provider to connect via the Internet). In some embodiments, an electronic circuit, such as a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA) may be personalized by utilizing the state information of a computer-readable program instruction, and the electronic circuit may execute a computer-readable program instruction, thereby realizing various aspects of the present disclosure.

[0067] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents, and any modifications or equivalent replacements that do not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A method for implementing a secure operating system for an electric embedded device, characterized in that: The following steps are involved: Step 1: Connect the mainboard to the TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through the SPI bus; Step 2: Before the SFOS operating system is started, the boot program of the operating system is measured by the TPCM hardware module. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system. Step 3: Run the trusted basic software module to manage the TPCM module, protect SFOS and applications, and actively intercept inside the SFOS operating system to achieve transparent and trusted support for applications; Step 4: Create a security management center to implement system management, security management, and audit management, conduct comprehensive security policy management of computing environments, regional boundaries, and communication networks, determine user operating permissions, and implement full audit tracking.

2. The method for implementing a secure operating system for a power embedded device according to claim 1, characterized in that: The construction of the TPCM hardware module further includes: The TPCM hardware module is constructed using a domestic cryptographic chip based on EAL5 certification. The cryptographic chip stores algorithm IP, static logic for directly controlling the CPU through I / O pins, and dynamic logic for interacting with the CPU for security functions through the SPI bus.

3. The method for implementing a secure operating system for a power embedded device according to claim 2, characterized in that: The CPU directly controls the reset of the TPCM hardware module through the GPIO pin and accesses the state of the TPCM hardware module. The TPCM hardware module controls the reset state of the CPU through the CPU_RESET pin and selects the SPI bus for communication.

4. The method for implementing a secure operating system for a power embedded device according to claim 3, characterized in that: The step of measuring the boot program of the operating system by the TPCM hardware module further includes: Initialize power-on and use the public key HASH in the storage area to verify the boot program. The CPU_RESET signal of the TPCM hardware module resets the CPU. At the same time, the SPI2 bus is selected, and the M_SPI of the TPCM hardware module starts measurement for the boot flash program.

5. The method for implementing a secure operating system for a power embedded device according to claim 4, characterized in that: The operation of the operating system organized by TPCM further includes: Load the boot flash program to start the CPU. A core-based bare-metal program first runs the initialization, loads and verifies the SFOS program stored in the flash, and the bare-metal program and the TPCM hardware module jointly measure the SFOS program. If the measurement is successful, SFOS runs successfully.

6. The method for implementing a secure operating system for a power embedded device according to claim 5, characterized in that: The running of the trusted basic software module further includes: The trusted basic software module uses the TPCM module as the trusted root to build a basic trust base, control mechanism, measurement mechanism, judgment mechanism, support mechanism and trusted benchmark library; the basic trust base provides trusted verification and trusted assurance of the initial state for the trusted basic software module and the SFOS system application; the control mechanism, measurement mechanism, judgment mechanism and trusted benchmark library jointly complete the active measurement of the SFOS system operating environment and applications; the support mechanism provides trusted cryptographic services to support the trusted basic software module's access and management of the TPCM module, the management of trusted policies and the management of trusted benchmark information.

7. The method for implementing a secure operating system for a power embedded device according to claim 6, characterized in that: The trusted basic software module provides trusted support for the application operating environment and behavior, further comprising: The trusted basic software module monitors application behavior through system call hooks, virtual machine monitors, and underlying library functions according to the trusted policy; a hook mechanism is set at the operating system, VMM, or underlying middleware level to submit the monitored information to the trusted basic software module, and actively intercepts untrusted behavior based on trusted policy measurements.

8. The method for implementing a secure operating system for a power embedded device according to claim 7, characterized in that: The trusted policy measurement further includes: the trusted policy measurement measures the code segment of the process in a triggering manner to reduce CPU power consumption.

9. The method for implementing a secure operating system for a power embedded device according to claim 8, characterized in that: The construction of the security management center further includes: The system management subsystem implements centralized management and maintenance of computing nodes, security area boundaries, and secure communication networks in the security protection environment, including user identity management, resource management, and emergency response, providing basic protection for the security of the information system; the security management subsystem implements tag management, authorization management, and policy management; the audit subsystem formulates audit strategies and audits the behavior of the entire information system.

10. The method for implementing a secure operating system for a power embedded device according to claim 9, characterized in that: The recording, monitoring and analysis of the behavior activities of the SFOS operating system by the audit subsystem further includes: Actively identify the deletion and tampering of applications and important configuration parameter files, generate audit records and issue alarms, and include measurement time, measurement object, and measurement results in the measurement results, which are then encrypted and saved.

11. A secure operating system implementation system for a power embedded device, characterized in that: include: A trusted computing module, used to connect the mainboard to a TPCM hardware module, which controls the CPU through I / O pins and interacts securely with the CPU through an SPI bus; An operating system boot module, used to measure the boot program of the operating system through the TPCM hardware module before the SFOS operating system is started. If the measurement is successful, the boot program loads the operating system normally. If the measurement fails, the TPCM organizes the operation of the operating system; Trusted basic software module, used to manage the TPCM module, protect SFOS and applications, actively intercept inside the SFOS operating system, and realize transparent and trusted support for applications; The trusted basic software module runs in parallel with the SFOS operating system to form a trusted node framework. By triggering at the node, the SFOS operating system actively obtains monitoring information and transmits it to the trusted basic software module. The trusted basic software module accesses the trusted root of the TPCM module, measures the behavior of the SFOS operating system according to the trusted policy of the security management center, and uploads the audit information to the security management center; The Security Management Center is used to implement system management, security management, and audit management, conduct comprehensive security policy management of computing environments, regional boundaries, and communication networks, determine user operating permissions, and implement full audit tracking.

12. A terminal comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions; The processor is used to operate according to the instructions to execute the steps of the method for implementing a secure operating system for a power embedded device according to any one of claims 1-10.

13. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the program is executed by a processor, the steps of the method for implementing a secure operating system for an electric embedded device as described in any one of claims 1 to 10 are implemented.

Citation Information

Patent Citations

  • A secure storage method and system based on trusted embedded device and FTP

    CN114840863B