Reference value acquisition method and device, computer equipment and storage medium

Through the virtual trusted root and virtual trusted software base calculation and saving the startup and operation reference values ​​of the virtual machine, the problem of not being able to collect the virtual machine reference values ​​in the prior art is solved, and the trustworthy measurement of the virtual machine is realized.

CN120012102APending Publication Date: 2025-05-16CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510063386.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art cannot effectively collect the benchmark values ​​of the startup and operation stages of virtual machines, affecting the trustworthy metrics of the virtual machines.

Method used

Through the virtual trusted root and virtual trusted software base, the startup reference value of each level of measurement object and the running benchmark value of the trusted executor program are calculated and encrypted during the startup and operation of the virtual machine, and stored in the host operating system.

Benefits of technology

The benchmark value acquisition of virtual machine startup and operation stages is realized, ensuring the trustworthy measurement of the virtual machine, and solving the problem that the benchmark value cannot be collected in the prior art.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012102A_ABST
    Figure CN120012102A_ABST
Patent Text Reader

Abstract

The invention relates to a reference value acquisition method and device, computer equipment and a storage medium. The method comprises the steps that in the process that a virtual machine is started according to a starting signal, a virtual trusted root in the virtual machine calculates starting reference values corresponding to all levels of measurement objects according to collected object data of all levels of measurement objects; a virtual trusted software base, corresponding to the virtual machine, in a virtual machine operating system calculates operation reference values corresponding to the trusted execution programs according to the collected application data of the trusted execution programs; and encrypting and storing the starting reference value corresponding to each level of measurement object and the running reference value corresponding to each trusted execution program into a host machine operating system corresponding to the virtual machine. Therefore, the problem of how to collect the reference value in the starting and running stages of the virtual machine is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of information security technology, and in particular to a reference value collection method, device, computer equipment and storage medium. Background Art

[0002] For cloud computing environments, currently trusted virtual machines are mostly built by virtual trusted roots in hardware virtualization, and virtual trusted software base agents are deployed in the virtual machine operating system layer. Under the support of the virtual trusted root, the trusted verification agent in the virtual machine actively obtains the virtual machine measurement object data and passes it to the virtual trusted root, calculates its hash value and compares it with the stored trusted reference value to achieve trusted measurement of the virtual machine. The trusted reference value is the basis for determining the trusted measurement of the virtual machine, and is a digital representation of the expected execution code. The collection of trusted reference values ​​is a key technology for achieving trusted measurement of virtual machines.

[0003] The trusted measurement of virtual machines depends on the trusted benchmark value, which includes static measurement in the startup phase and dynamic measurement in the running phase. Therefore, the trusted benchmark value should include the startup benchmark value and the running benchmark value. Currently, the measurement of virtual machines is mostly completed by the trusted software base agent of the host operating system, which cannot realize the benchmark value collection of the virtual machine startup and running phase. Summary of the invention

[0004] The present application provides a benchmark value collection method, apparatus, computer equipment and storage medium to solve the problem of how to realize benchmark value collection during the startup and operation stages of a virtual machine.

[0005] In a first aspect, the present application provides a reference value acquisition method, the method comprising:

[0006] In the process of starting the virtual machine according to the start signal, the virtual trusted root in the virtual machine calculates the start reference value corresponding to each level of measurement objects according to the collected object data of each level of measurement objects;

[0007] The virtual trusted software base in the virtual machine operating system corresponding to the virtual machine calculates the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program;

[0008] The startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program are encrypted and saved in the host machine operating system corresponding to the virtual machine.

[0009] In a second aspect, the present application provides a reference value acquisition device, the device comprising:

[0010] A first calculation module is used for calculating the startup reference values ​​corresponding to the measurement objects at various levels according to the collected object data of the measurement objects at various levels when the virtual machine is started according to the startup signal;

[0011] A second calculation module is used for calculating the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program by the virtual trusted software base in the virtual machine operating system corresponding to the virtual machine;

[0012] The storage module is used to encrypt and save the startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program into the host operating system corresponding to the virtual machine.

[0013] In a third aspect, the present application provides a computer device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the above-mentioned benchmark value acquisition method when executing the computer program.

[0014] In a fourth aspect, the present application also provides a computer storage medium storing computer executable instructions, wherein the computer executable instructions are used to execute the above-mentioned benchmark value acquisition method.

[0015] The above technical solution provided by the embodiment of the present application has the following advantages over the prior art: the method provided by the embodiment of the present application, in the process of starting the virtual machine according to the startup signal, the virtual trusted root in the virtual machine calculates the startup reference value corresponding to each level of measurement objects based on the object data of each level of measurement objects collected; the virtual trusted software base in the virtual machine operating system corresponding to the virtual machine calculates the running reference value corresponding to each trusted execution program based on the application data of each trusted execution program collected; the startup reference value corresponding to each level of measurement objects and the running reference value corresponding to each trusted execution program are encrypted and saved in the host operating system corresponding to the virtual machine.

[0016] Based on the above method, the startup baseline value and the running baseline value are calculated and generated according to the acquired object data and application data through the virtual trusted root and the virtual trusted software base, and saved to the host operating system, thereby completing the secure collection of the virtual machine's trusted baseline value, thereby solving the problem of how to realize the baseline value collection during the startup and running stages of the virtual machine. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0018] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0019] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0020] Figure 1 A flowchart of a reference value acquisition method provided in an embodiment of the present application;

[0021] Figure 2 A flowchart of a reference value acquisition method provided in an embodiment of the present application;

[0022] Figure 3 A flowchart of a reference value acquisition method provided in an embodiment of the present application;

[0023] Figure 4 A structural block diagram of a reference value acquisition device provided in an embodiment of the present application;

[0024] Figure 5 A schematic diagram of the internal structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0025] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0026] The disclosure below provides many different embodiments or examples to implement different structures of the present invention. In order to simplify the disclosure of the present invention, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present invention. In addition, the present invention can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.

[0027] In one embodiment, Figure 1A schematic diagram of a reference value acquisition method in an embodiment, referring to Figure 1 , a reference value collection method is provided. This embodiment mainly uses the method applied to a reference value collection device as an example, and the reference value collection device can be implemented by one or more servers. The reference value collection method specifically includes the following steps:

[0028] Step S210, when the virtual machine is started according to the start signal, the virtual trusted root in the virtual machine calculates the start reference value corresponding to each level of measurement objects according to the collected object data of each level of measurement objects.

[0029] Specifically, in the process of the virtual machine starting up according to the startup signal, the virtual trusted root starts working before the virtual processor (virtual CPU) based on the physical trusted root, and the virtual trusted root collects object data of measurement objects at all levels to calculate the startup reference values ​​corresponding to the measurement objects at all levels. The measurement objects at all levels are loaded and started in sequence according to their levels, and the corresponding startup reference values ​​are generated in sequence according to the levels of the measurement objects at all levels. The startup reference values ​​are used to implement trusted measurement during the startup process.

[0030] Step S220: The virtual trusted software base in the virtual machine operating system corresponding to the virtual machine calculates the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program.

[0031] Specifically, the virtual trusted software base collects application data of each trusted execution program, and calculates the operation benchmark value corresponding to each trusted execution program based on each application data, and the operation benchmark value is used to achieve the trust measurement of the trusted execution program during operation.

[0032] Step S230: encrypt and save the startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program into the host operating system corresponding to the virtual machine.

[0033] Specifically, the startup reference value and the running reference value are encrypted and saved in the host operating system, so that the host operating system can use the startup reference value and the running reference value to perform startup trusted measurement and running trusted measurement on the measurement objects or trusted execution programs corresponding to different reference values.

[0034] Based on the above method, the startup baseline value and the running baseline value are calculated and generated according to the acquired object data and application data through the virtual trusted root and the virtual trusted software base, and saved to the host operating system, thereby completing the secure collection of the virtual machine's trusted baseline value, thereby solving the problem of how to realize the baseline value collection during the startup and running stages of the virtual machine.

[0035] In one embodiment, during the process of starting the virtual machine according to the start signal, the virtual trusted root in the virtual machine calculates the start reference values ​​corresponding to the measurement objects at each level according to the collected object data of the measurement objects at each level, including:

[0036] When the virtual machine is started according to the start signal, loading the virtual trusted root corresponding to the virtual machine;

[0037] The communication module of the virtual trusted root is used to collect object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels.

[0038] Specifically, refer to Figure 2 In step ①, the QEMU program is started according to the startup signal to start the virtual machine. Before starting the virtual CPU, the virtual trusted root is loaded and started. The communication module in the virtual trusted root is used to collect object data of measurement objects at all levels, and perform hash operations on the object data of measurement objects at all levels, so as to obtain the startup reference values ​​corresponding to the measurement objects at all levels, thereby realizing the collection of startup reference values.

[0039] In one embodiment, the communication module of the virtual trusted root is used to collect object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels, including:

[0040] The communication module of the virtual trusted root is used to collect firmware data of the virtual interface firmware. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the firmware data to obtain a startup reference value corresponding to the virtual interface firmware, wherein the first-level measurement object among the various levels of measurement objects is the virtual interface firmware, and the object data of the first-level measurement object is the firmware data.

[0041] Specifically, refer to Figure 2 In step ②, the communication module of the virtual trusted root first collects the firmware data of the virtual interface firmware (virtual BIOS firmware). The virtual trusted root calls the cryptographic engine algorithm (SM3 algorithm) of the physical trusted root through the host operating system to perform a hash operation on the firmware data, and uses the operation result as the startup reference value corresponding to the virtual interface firmware, that is, the first-level measurement object among the measurement objects at all levels is the virtual interface firmware. After the virtual trusted root is started, the startup reference value corresponding to the virtual interface firmware is first calculated, thereby realizing the collection of the startup reference value of the first-level measurement object.

[0042] In one embodiment, after obtaining the startup reference value corresponding to the virtual interface firmware, the communication module using the virtual trusted root collects object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain the startup reference value corresponding to the measurement objects at various levels, including:

[0043] After the startup reference value corresponding to the virtual interface firmware is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual processor through the communication module to load and start the firmware program corresponding to the virtual interface firmware;

[0044] When the virtual interface firmware is started, the communication module of the virtual trusted root is used to collect system data of the virtual machine operating system. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the system data to obtain a startup reference value corresponding to the virtual machine operating system, wherein the second-level measurement object in each level of measurement objects is the virtual machine operating system, and the object data of the second-level measurement object is the system data.

[0045] Specifically, after calculating the startup reference value corresponding to the virtual interface firmware, the startup reference value is saved in the reference library of the virtual trusted root, and then referenced Figure 2 In step ③, the virtual trusted root notifies the virtual processor through the communication module to load and start the firmware program corresponding to the virtual interface firmware. When the virtual interface firmware is started, refer to Figure 2 In step ④, the communication module of the virtual trusted root collects the system data of the virtual machine operating system, and calls the cryptographic engine algorithm of the physical trusted root through the trusted software of the host operating system to perform a hash operation on the collected system data, and uses the operation result as the startup reference value of the virtual machine operating system, that is, after collecting the startup reference value corresponding to the virtual interface firmware, the startup reference value corresponding to the virtual machine operating system is collected, thereby forming the collection of the startup reference value of the two-level measurement object.

[0046] In one embodiment, after obtaining the startup reference value corresponding to the virtual machine operating system, the communication module using the virtual trusted root collects object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain the startup reference value corresponding to the measurement objects at various levels, including:

[0047] After the startup reference value corresponding to the virtual machine operating system is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual interface firmware to load and start the virtual machine operating system through the communication module;

[0048] When the virtual machine operating system is started, the communication module of the virtual trusted root is used to collect program data of the virtual machine application. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the program data to obtain a startup reference value corresponding to the virtual machine application, wherein the third-level measurement object in each level of measurement objects is the virtual machine application, and the object data of the third-level measurement object is the program data.

[0049] Specifically, after calculating the startup reference value corresponding to the virtual machine operating system, the startup reference value is saved in the virtual trusted root reference library, and then referenced Figure 2 In step ⑤, the virtual trusted root notifies the virtual processor through the communication module to load and start the virtual machine operating system. When the virtual machine operating system is started, refer to Figure 2 In step ⑥, the communication module of the virtual trusted root collects the program data of the virtual machine application, and calls the cryptographic engine algorithm of the physical trusted root through the trusted software of the host operating system to perform a hash operation on the collected program data, and uses the operation result as the startup reference value of the virtual machine application, that is, after collecting the startup reference value corresponding to the virtual interface firmware and the startup reference value corresponding to the virtual machine operating system in batches according to the level, the startup reference value corresponding to the virtual machine application is collected, thereby forming the collection of the startup reference value of the three-level measurement object.

[0050] Refer to later Figure 2 In step ⑦, the virtual trusted root notifies the virtual machine operating system through the communication module to load and start the virtual machine application.

[0051] In one embodiment, encrypting and saving the running benchmark values ​​corresponding to the respective trusted execution programs to the host operating system corresponding to the virtual machine includes:

[0052] Encapsulating the operation benchmark values ​​of each of the trusted execution programs into a trusted policy by using the virtual trusted software base, and sequentially passing the policy to the virtual trusted root through the virtual machine trusted software stack, database middleware, and virtual trusted root communication driver in the virtual trusted software base;

[0053] The trusted policy is verified using the virtual trusted root, and the running reference value obtained based on the successful verification of the trusted policy is encrypted and saved in the host operating system.

[0054] Specifically, refer to Figure 3, before this, the virtual trusted software base (vTSB) scans each trusted execution program to obtain the application data of each trusted execution program, and calculates and generates the corresponding operation benchmark value of each trusted execution program based on the application data. The virtual trusted software base encapsulates the operation benchmark value of each trusted execution program into a trusted policy. The virtual trusted software base sequentially transmits the trusted policy to the virtual trusted root communication driver in the virtual trusted root through the internal virtual machine trusted software stack, database middleware (TDDL) and virtual trusted root communication driver. The virtual trusted root verifies the trusted policy to determine the integrity and correctness of the trusted policy, thereby ensuring the data security of the trusted policy during transmission. The virtual trusted root encrypts and saves the successfully verified operation benchmark value to the host operating system, thereby saving the secure and trusted operation benchmark value to the host operating system, and realizing the secure collection of the operation benchmark value.

[0055] In one embodiment, the trusted policy is verified by using the virtual trusted root, and the running reference value obtained based on the successful verification of the trusted policy is encrypted and saved to the host operating system, including:

[0056] Distributing the trusted policy to the corresponding trusted policy management module according to the policy type using the virtual trusted root;

[0057] Using a trusted policy management module corresponding to the trusted policy to perform signature verification processing on the trusted policy, and using the operating benchmark value obtained based on the successful signature verification of the trusted policy to update the benchmark library of the virtual trusted root;

[0058] The storage management service interface of the virtual trusted root is called to encrypt and save the running benchmark value to the host operating system.

[0059] Specifically, refer to Figure 3 , the policy type is used to indicate different types of trusted execution programs, and each trusted policy carries a corresponding program type. Therefore, the policy type corresponding to the trusted policy can be determined based on the program type. The virtual trusted root distributes the received trusted policy to the trusted policy management module corresponding to the policy type inside the virtual trusted root according to the policy type. The trusted policy management module verifies the signature of the received trusted policy to determine the integrity of the trusted policy. After the trusted policy is successfully verified, the operating baseline value parsed by the trusted policy is used to update the benchmark library of the virtual trusted root, that is, the operating baseline value corresponding to the trusted execution program in the benchmark library is updated with the newly received operating baseline value. That is, the benchmark library will be updated every time the virtual machine is turned on to ensure that the benchmark value in the benchmark library corresponds to the updated status of the trusted execution program, thereby ensuring the reliability and security of the trusted measurement of the trusted execution program during operation.

[0060] After the benchmark library is updated with the running benchmark value, the storage management service interface of the virtual trusted root is called to encrypt and save the running benchmark value to the host operating system to complete the collection of the running benchmark values ​​of each trusted execution program, so that during the operation of each trusted execution program, the subsequent host operating system can use the running benchmark value of each trusted execution program to measure its trustworthiness.

[0061] Figure 1-Figure 3 FIG. 1 is a flow chart of a method for collecting a reference value in one embodiment. It should be understood that although Figure 1-Figure 3 The steps in the flowchart are shown in sequence as indicated by the arrows, but these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified in this document, there is no strict order restriction for the execution of these steps, and these steps can be executed in other orders. Moreover, Figure 1-Figure 3 At least part of the steps may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed in turn or alternately with other steps or at least part of the sub-steps or stages of other steps.

[0062] In one embodiment, Figure 4 As shown, a reference value acquisition device is provided, comprising:

[0063] The first calculation module 310 is used for calculating the startup reference values ​​corresponding to the measurement objects at various levels according to the collected object data of the measurement objects at various levels when the virtual machine is started according to the startup signal;

[0064] The second calculation module 320 is used for calculating the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program in the virtual trusted software base in the virtual machine operating system corresponding to the virtual machine;

[0065] The storage module 330 is used to encrypt and store the startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program in the host operating system corresponding to the virtual machine.

[0066] In one embodiment, the first calculation module 310 is further configured to:

[0067] When the virtual machine is started according to the start signal, loading the virtual trusted root corresponding to the virtual machine;

[0068] The communication module of the virtual trusted root is used to collect object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels.

[0069] In one embodiment, the first calculation module 310 is further configured to:

[0070] The communication module of the virtual trusted root is used to collect firmware data of the virtual interface firmware. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the firmware data to obtain a startup reference value corresponding to the virtual interface firmware, wherein the first-level measurement object among the various levels of measurement objects is the virtual interface firmware, and the object data of the first-level measurement object is the firmware data.

[0071] In one embodiment, the first calculation module 310 is further configured to:

[0072] After the startup reference value corresponding to the virtual interface firmware is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual processor through the communication module to load and start the firmware program corresponding to the virtual interface firmware;

[0073] When the virtual interface firmware is started, the communication module of the virtual trusted root is used to collect system data of the virtual machine operating system. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the system data to obtain a startup reference value corresponding to the virtual machine operating system, wherein the second-level measurement object in each level of measurement objects is the virtual machine operating system, and the object data of the second-level measurement object is the system data.

[0074] In one embodiment, the first calculation module 310 is further configured to:

[0075] After the startup reference value corresponding to the virtual machine operating system is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual interface firmware to load and start the virtual machine operating system through the communication module;

[0076] When the virtual machine operating system is started, the communication module of the virtual trusted root is used to collect program data of the virtual machine application. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the program data to obtain a startup reference value corresponding to the virtual machine application, wherein the third-level measurement object in each level of measurement objects is the virtual machine application, and the object data of the third-level measurement object is the program data.

[0077] In one embodiment, the storage module 330 is further configured to:

[0078] Encapsulating the operation benchmark values ​​of each of the trusted execution programs into a trusted policy by using the virtual trusted software base, and sequentially passing the policy to the virtual trusted root through the virtual machine trusted software stack, database middleware, and virtual trusted root communication driver in the virtual trusted software base;

[0079] The trusted policy is verified using the virtual trusted root, and the running reference value obtained based on the successful verification of the trusted policy is encrypted and saved in the host operating system.

[0080] In one embodiment, the storage module 330 is further configured to:

[0081] Distributing the trusted policy to the corresponding trusted policy management module according to the policy type using the virtual trusted root;

[0082] Using a trusted policy management module corresponding to the trusted policy to perform signature verification processing on the trusted policy, and using the operating benchmark value obtained based on the successful signature verification of the trusted policy to update the benchmark library of the virtual trusted root;

[0083] The storage management service interface of the virtual trusted root is called to encrypt and save the running benchmark value to the host operating system.

[0084] like Figure 5 As shown, an embodiment of the present application provides a computer device, including a processor 711, a communication interface 712, a memory 713 and a communication bus 714, wherein the processor 711, the communication interface 712, and the memory 713 communicate with each other through the communication bus 714;

[0085] Memory 713, used for storing computer programs;

[0086] The processor 711 is used to implement the reference value acquisition method provided by any one of the aforementioned method embodiments when executing the program stored in the memory 713.

[0087] Those skilled in the art will understand that Figure 5 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.

[0088] In one embodiment, the reference value acquisition device provided by the present application can be implemented in the form of a computer program. The computer program can be Figure 5The computer device shown in the figure is run. The memory of the computer device can store various program modules constituting the reference value acquisition device, for example, Figure 4 The first calculation module 310, the second calculation module 320 and the storage module 330 are shown. The computer program composed of various program modules enables the processor to execute the reference value acquisition method of each embodiment of the present application described in this specification.

[0089] Figure 5 The computer device shown can be Figure 4 The first calculation module 310 in the benchmark value collection device shown is executed in the process of starting the virtual machine according to the startup signal. The virtual trusted root in the virtual machine calculates the startup benchmark values ​​corresponding to the measurement objects at each level according to the object data of the measurement objects at each level collected. The computer device can execute the virtual trusted software base in the virtual machine operating system corresponding to the virtual machine through the second calculation module 320, and calculate the running benchmark values ​​corresponding to each trusted execution program according to the application data of each trusted execution program collected. The computer device can execute the startup benchmark values ​​corresponding to the measurement objects at each level and the running benchmark values ​​corresponding to each trusted execution program through the storage module 330 to encrypt and save them in the host operating system corresponding to the virtual machine.

[0090] An embodiment of the present application further provides a computer-readable storage medium having a computer program stored thereon. When the computer program is executed by a processor, the reference value acquisition method provided by any one of the aforementioned method embodiments is implemented.

[0091] The device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0092] Through the description of the above implementation methods, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a general hardware platform, and of course, by hardware. Based on this understanding, the above technical solution is essentially or the part that contributes to the relevant technology can be embodied in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a disk, an optical disk, etc., including a number of instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0093] It should be understood that the terms used herein are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used herein may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described herein are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative can be used.

[0094] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A reference value collection method, characterized in that: The method comprises: In the process of starting the virtual machine according to the start signal, the virtual trusted root in the virtual machine calculates the start reference value corresponding to each level of measurement objects according to the collected object data of each level of measurement objects; The virtual trusted software base in the virtual machine operating system corresponding to the virtual machine calculates the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program; The startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program are encrypted and saved in the host machine operating system corresponding to the virtual machine.

2. The method according to claim 1, characterized in that: In the process of starting the virtual machine according to the start signal, the virtual trusted root in the virtual machine calculates the start reference values ​​corresponding to the measurement objects at each level according to the collected object data of the measurement objects at each level, including: When the virtual machine is started according to the start signal, loading the virtual trusted root corresponding to the virtual machine; The communication module of the virtual trusted root is used to collect object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels.

3. The method according to claim 2, characterized in that The communication module of the virtual trusted root is used to collect object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels, including: The communication module of the virtual trusted root is used to collect firmware data of the virtual interface firmware. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the firmware data to obtain a startup reference value corresponding to the virtual interface firmware, wherein the first-level measurement object among the various levels of measurement objects is the virtual interface firmware, and the object data of the first-level measurement object is the firmware data.

4. The method according to claim 3, characterized in that After obtaining the startup reference value corresponding to the virtual interface firmware, the communication module using the virtual trusted root collects object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels, including: After the startup reference value corresponding to the virtual interface firmware is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual processor through the communication module to load and start the firmware program corresponding to the virtual interface firmware; When the virtual interface firmware is started, the communication module of the virtual trusted root is used to collect system data of the virtual machine operating system. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the system data to obtain a startup reference value corresponding to the virtual machine operating system, wherein the second-level measurement object in each level of measurement objects is the virtual machine operating system, and the object data of the second-level measurement object is the system data.

5. The method according to claim 4, characterized in that After obtaining the startup reference value corresponding to the virtual machine operating system, the communication module using the virtual trusted root collects object data of measurement objects at various levels, and the virtual trusted root performs a hash operation on the collected object data of measurement objects at various levels to obtain startup reference values ​​corresponding to measurement objects at various levels, including: After the startup reference value corresponding to the virtual machine operating system is saved in the reference library of the virtual trusted root, the virtual trusted root notifies the virtual interface firmware to load and start the virtual machine operating system through the communication module; When the virtual machine operating system is started, the communication module of the virtual trusted root is used to collect program data of the virtual machine application. The virtual trusted root calls the cryptographic engine algorithm of the physical trusted root through the host operating system to perform a hash operation on the program data to obtain a startup reference value corresponding to the virtual machine application, wherein the third-level measurement object in each level of measurement objects is the virtual machine application, and the object data of the third-level measurement object is the program data.

6. The method according to claim 1, characterized in that Encrypting and saving the running benchmark values ​​corresponding to each of the trusted execution programs to the host operating system corresponding to the virtual machine includes: Encapsulating the operation benchmark values ​​of each of the trusted execution programs into a trusted policy by using the virtual trusted software base, and sequentially passing the policy to the virtual trusted root through the virtual machine trusted software stack, database middleware, and virtual trusted root communication driver in the virtual trusted software base; The trusted policy is verified using the virtual trusted root, and the running reference value obtained based on the successful verification of the trusted policy is encrypted and saved in the host operating system.

7. The method according to claim 6, characterized in that The trusted policy is verified by using the virtual trusted root, and the running reference value obtained by successfully verifying the trusted policy is encrypted and saved to the host operating system, including: Distributing the trusted policy to the corresponding trusted policy management module according to the policy type using the virtual trusted root; Using a trusted policy management module corresponding to the trusted policy to perform signature verification processing on the trusted policy, and using the operating benchmark value obtained based on the successful signature verification of the trusted policy to update the benchmark library of the virtual trusted root; The storage management service interface of the virtual trusted root is called to encrypt and save the running benchmark value to the host operating system.

8. A reference value acquisition device, characterized in that: The device comprises: A first calculation module is used for calculating the startup reference values ​​corresponding to the measurement objects at various levels according to the collected object data of the measurement objects at various levels when the virtual machine is started according to the startup signal; A second calculation module is used for calculating the operation benchmark value corresponding to each trusted execution program according to the collected application data of each trusted execution program by the virtual trusted software base in the virtual machine operating system corresponding to the virtual machine; The storage module is used to encrypt and save the startup reference values ​​corresponding to the measurement objects at each level and the running reference values ​​corresponding to each trusted execution program into the host operating system corresponding to the virtual machine.

9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 1 to 7 is implemented.