Trusted report judgment method and device, equipment and storage medium

By generating and applying target adjudication strategies in the Trusted Management Center, the issue of ruling errors caused by the lack of ruling strategies in the metrics in the trusted report is solved, and security control of trusted terminal devices is achieved.

CN120012103APending Publication Date: 2025-05-16CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510063393.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-15
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

In the Trusted Management Center, if the metric items in the trusted report have not yet formulated a corresponding adjudication strategy, it may cause the metric items to be awarded incorrectly, and the abnormal metric items will continue to run, threatening the security of the terminal equipment.

Method used

By obtaining a trusted report uploaded by a trusted terminal device, the analysis report is analyzed to generate the current report analysis results, and using this result and the adjudication strategy to generate rules to generate a target adjudication strategy. This adjudication strategy is used to add or modify the adjudication strategy of the metric to ensure accurate adjudication.

Benefits of technology

Accurate rulings on credible reports are achieved, errors caused by lack of ruling strategies for metric items are avoided, effective control of abnormal metric items is ensured, and the security of terminal devices is protected.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012103A_ABST
    Figure CN120012103A_ABST
Patent Text Reader

Abstract

The invention relates to a trusted report judgment method and device, equipment and a storage medium. When the credible report is judged, firstly, the credible report uploaded by the credible terminal equipment is obtained, and the credible report is analyzed to obtain a current report analysis result; generating a target judgment strategy by using the current report analysis result and a judgment strategy generation rule; wherein the decision strategy generation rule is used for adding a decision strategy of a new measurement item, and / or modifying a decision strategy of an original measurement item; and judging the credible report by using the target judgment strategy. Visibly, according to the method and the device, accurate judgment of the credible report can be realized through the judgment strategy generation rule, the judgment strategy of adding the newly added measurement item and the judgment strategy of modifying the original measurement item, the judgment error phenomenon caused by the lack of the judgment strategy of the measurement item is avoided, the abnormal measurement item can be effectively controlled, and the reliability of the credible report is improved. And security threats of the trusted terminal equipment are avoided.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method, device, equipment and storage medium for adjudicating a credible report. Background Art

[0002] In the Trusted Computing 3.0 technology system, the Trusted Management Center plays an important role in the centralized management of the defense-in-depth environment. As the Trusted Computing 3.0 technology is increasingly used in actual projects, the role of the Trusted Management Center is becoming more and more prominent. The Trusted Management Center includes functional modules such as device management, benchmark management, policy management, report management, and audit management, which are used to uniformly manage device information. At the same time, the Trusted Management Center can also make further decisions on the measurement items in the trusted report based on its own data foundation and decision strategy. However, during the operation of the Trusted Management Center, if the measurement items in the trusted report have not yet formulated corresponding decision strategies, it may lead to measurement item decision errors, allowing abnormal measurement items to continue to run. If the control method in the measurement item decision strategy is not set reasonably, it will also lead to the inability to effectively control abnormal measurement items, threatening the security of terminal devices.

[0003] Therefore, how to accurately judge credible reports is a technical problem that those skilled in the art need to solve. Summary of the invention

[0004] The present application provides a method, apparatus, device and storage medium for adjudicating a credible report, which can be used to make accurate adjudications based on credible reports.

[0005] In a first aspect, the present application provides a method for adjudicating credible reports, comprising:

[0006] Obtaining trusted reports uploaded by trusted terminal devices;

[0007] Analyzing the credible report to obtain a current report analysis result; the current report analysis result is generated after matching the credible report with a historical report analysis result;

[0008] Generate a target decision strategy using the current report analysis results and decision strategy generation rules; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or modify a decision strategy for an original metric item;

[0009] The trusted report is adjudicated using the target adjudication policy.

[0010] Optionally, the using the current report analysis result and the decision strategy generation rule to generate a target decision strategy includes:

[0011] Determine the benchmark value and exception handling method corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule; wherein the target metric item includes a newly added metric item and an original metric item;

[0012] The application scope of the decision strategy for each target metric item is determined according to the decision strategy generation rule, and a target decision strategy is generated.

[0013] Optionally, determining a reference value corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule includes:

[0014] Determine a first metric value corresponding to each newly added metric item, and a second metric value and a historical benchmark value corresponding to each original metric item;

[0015] Determine a reference value of the newly added metric item by using the number of occurrences of each first metric value corresponding to each newly added metric item;

[0016] The historical benchmark value is adjusted using the number of occurrences of each second metric value corresponding to each original metric item.

[0017] Optionally, determining an exception handling method corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule includes:

[0018] Using the adjudication strategy to generate rules, determine the device level, the metric level of each target metric item, and the application level corresponding to the target metric item;

[0019] According to the arbitration strategy generation rules and at least one of the metric item level, application level and device level corresponding to each target metric item, an exception handling method corresponding to each target metric item is determined.

[0020] Optionally, the arbitration strategy is used to generate rules to determine the device level, the metric item level of each target metric item, and the application level corresponding to the target metric item, including:

[0021] Determining an initial level of a device according to the device information and the adjudication strategy generation rule;

[0022] Using the total number of the first metric item in the current report analysis result and the total number of the second metric item in the historical report analysis result, the initial level of the device is adjusted to determine the level of the device;

[0023] Determining the initial level of each target metric item and the application level corresponding to each target metric item according to the adjudication strategy generation rule;

[0024] According to the application level corresponding to each target metric item, the initial metric item level of each target metric item is adjusted to determine the metric item level of each target metric item.

[0025] Optionally, determining an exception handling method corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule includes:

[0026] Determine the total number of abnormal results for each target metric;

[0027] Determining whether the total number of abnormal results is less than a predetermined threshold;

[0028] If so, lower the processing level of the exception handling method of the target metric item.

[0029] Optionally, after generating the target adjudication strategy, the method further includes:

[0030] Presenting the target adjudication strategy;

[0031] If a policy modification instruction is received, modifying the target adjudication policy according to the policy modification instruction, and using the modified target adjudication policy to adjudicate the trusted report;

[0032] If a policy confirmation instruction is received, the step of using the target arbitration policy to adjudicate the trustworthy report is performed.

[0033] In a second aspect, the present application provides a credible report adjudication device, comprising:

[0034] An acquisition module is used to acquire a trusted report uploaded by a trusted terminal device;

[0035] An analysis module, configured to analyze the credible report to obtain a current report analysis result; the current report analysis result is generated by matching the credible report with a historical report analysis result;

[0036] A strategy generation module, used to generate a target decision strategy using the current report analysis results and decision strategy generation rules; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or to modify a decision strategy for an original metric item;

[0037] The adjudication module is used to adjudicate the trusted report using the target adjudication strategy.

[0038] In a third aspect, the present application provides an electronic device, including:

[0039] A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the steps of the above-mentioned method for determining a trustworthy report of the present application through the computer program.

[0040] In a fourth aspect, the present application provides a computer storage medium storing computer executable instructions for executing the steps of the above-mentioned credible report adjudication method of the present application.

[0041] The above technical solution provided by the embodiment of the present application has the following advantages compared with the prior art: when the present application makes a ruling on a trusted report, the trusted report uploaded by the trusted terminal device is first obtained, and the trusted report is analyzed to obtain the current report analysis result; the target ruling strategy is generated using the current report analysis result and the ruling strategy generation rule; wherein the ruling strategy generation rule is used to add a ruling strategy for a newly added measurement item, and / or, to modify the ruling strategy for the original measurement item; and the trusted report is ruled using the target ruling strategy. It can be seen that the present application can achieve accurate ruling on the trusted report by adding a ruling strategy generation rule for a newly added measurement item and modifying the ruling strategy for the original measurement item, avoiding the phenomenon of wrong ruling due to the lack of a ruling strategy for the measurement item, so that abnormal measurement items can be effectively controlled, and security threats to the trusted terminal device can be avoided. BRIEF DESCRIPTION OF THE DRAWINGS

[0042] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate embodiments consistent with the invention and, together with the description, serve to explain the principles of the invention.

[0043] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0044] One or more embodiments are exemplarily described by pictures in the corresponding drawings, and these exemplified descriptions do not constitute limitations on the embodiments. Elements with the same reference numerals in the drawings represent similar elements, and unless otherwise stated, the figures in the drawings do not constitute proportional limitations.

[0045] Figure 1 A schematic diagram of the structure of a decision strategy generation system provided in an embodiment of the present application;

[0046] Figure 2 A flow chart of a method for determining a trustworthy report provided in an embodiment of the present application;

[0047] Figure 3A flow chart of a trusted report generation process provided in an embodiment of the present application;

[0048] Figure 4 A flow chart of a trusted report analysis provided in an embodiment of the present application;

[0049] Figure 5 A flow chart of another method for determining a credible report provided in an embodiment of the present application;

[0050] Figure 6 Schematic diagram of the decision strategy generation process provided in the embodiment of the present application

[0051] Figure 7 A schematic diagram of the structure of a credible report adjudication device provided in an embodiment of the present application;

[0052] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0053] In order to make the purpose, technical solution and advantages of the embodiments of the present application clearer, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.

[0054] The disclosure below provides many different embodiments or examples to implement different structures of the present invention. In order to simplify the disclosure of the present invention, the parts and settings of specific examples are described below. Of course, they are only examples, and the purpose is not to limit the present invention. In addition, the present invention can repeat reference numbers and / or letters in different examples. This repetition is for the purpose of simplification and clarity, and does not itself indicate the relationship between the various embodiments and / or settings discussed.

[0055] The embodiments of the present application provide a method, apparatus, device and storage medium for adjudicating a credible report, so as to make accurate adjudications based on credible reports.

[0056] See also Figure 1 , Figure 1 A schematic diagram of the structure of a decision strategy generation system provided in an embodiment of the present application. Figure 1It can be seen that this system mainly includes two parts: trusted terminal equipment and trusted management center. Among them, the TPCM (Trusted Platform Control Module) in the trusted terminal equipment measures the computing component behavior, files, etc. according to the trusted strategy, obtains the data of the startup measurement, static measurement, and dynamic measurement objects, measures and controls them, and generates verification information. The TSB (Trusted Software Base) obtains the verification results and device information to generate a trusted report, and calls the TCM (Trusted Cryptography Module) to sign the trusted report and report it to the trusted management center.

[0057] The trusted management center includes a decision strategy management module and a trusted report decision module. The trusted report decision module decomposes and decides on the trusted report information reported by the terminal, and the decision strategy management module generates policies. The decision strategy management module pre-fabricates decision strategy generation rules, which include: measurement item level, measurement item addition and modification rules, measurement item application scope, exception handling methods, etc. The decision strategy management module has the ability to analyze trusted reports, and can obtain the trusted report information decomposition results of the trusted report decision module for trusted report analysis. The decision strategy generation generates a decision strategy based on the decision strategy generation rules and the current report analysis results, and reminds the manager to confirm the decision strategy in real time after generation.

[0058] In summary, when the trusted terminal device uploads the trusted report to the trusted management center, it is first received and decomposed by the trusted report adjudication module. The trusted report analysis module of the adjudication strategy management module reads the decomposition results and analyzes the measurement items, abnormal contents, etc. When the number of newly added measurement items or the number of abnormalities meets the adjudication strategy generation rules, the adjudication strategy is automatically generated and the trusted report is adjudicated.

[0059] See also Figure 2 , Figure 2 A flowchart of a method for determining a credible report provided in an embodiment of the present application, through Figure 2 It can be seen that this method specifically includes the following steps:

[0060] S101, obtaining a trust report uploaded by a trusted terminal device;

[0061] In this embodiment, the trusted report mainly includes the following contents: device information, current device form, current device location, report generation time, startup time, measurement type, measurement item sequence number, measurement item, measurement item trusted status, and measurement value of the measurement item; wherein, the device information can specifically be a device ID (Identity document, unique code).

[0062] See also Figure 3 , Figure 3 A flow chart of a trusted report generation process provided by an embodiment of the present application; Figure 3 It can be seen that the trusted terminal device is obtained by TPCM according to the trusted policy, and the data of the startup measurement, static measurement, and dynamic measurement objects are measured and controlled to generate verification information. When TSB generates a trusted report, it first obtains the current trusted status of the device from TPCM, and then obtains the measurement verification information stored therein, fills it into the trusted report in the form of a trusted report, and then obtains the basic information of the device, including the device ID, current time, current device form, current device location, etc., and fills it into the trusted report to form a complete trusted report. After the trusted report is generated, TSB calls the identity key of TCM to sign the trusted report, and sends the signature file and the trusted report to the management center, so that after the trusted management center receives the trusted report, it can successfully verify the signature of the trusted report, decompose the trusted report information, and generate a ruling strategy to rule on the trusted report.

[0063] S102, analyzing the credible report to obtain a current report analysis result; the current report analysis result is generated by matching the credible report with the historical report analysis result;

[0064] It should be noted that after receiving the trusted report, the trusted management center needs to perform report decomposition and report analysis operations to obtain the current report analysis results. Figure 4 , Figure 4 A flow chart of a trusted report analysis provided in an embodiment of the present application; Figure 4 It can be seen that the trusted report adjudication module of the trusted management center first needs to decompose the trusted report and extract the decomposition results to be obtained by the trusted report analysis module. Then the decomposition results are obtained through the trusted report analysis module of the trusted management center, and the current report analysis results are generated based on the historical report analysis results. The analysis process is: match the historical report analysis results of the historical trusted report in the system according to the device information of the trusted report, then split the measurement items in the decomposition results, and match the split measurement items with the historical report analysis results to generate the current report analysis results, and finally initiate the generation of the adjudication strategy based on the current report analysis results.

[0065] Specifically, this solution mainly implements the following analysis operations: analyzing the device information and measurement item information of the trusted report; the measurement item information includes: newly added measurement items, original measurement items, the total number of normal results, the total number of abnormal results, the statistical information of the measurement value, the processing method of abnormal measurement items, the change of the total measurement items, etc. In other words, as long as it is the data used in the adjudication strategy generation rules, it can be generated through the analysis process. Here, only the following analysis process is taken as an example to illustrate the generation process of the current report analysis results:

[0066] 1. First, determine the newly added measurement items and original measurement items in the trusted report, and determine the normal measurement items and abnormal measurement items therein, and generate the total number of normal results and the total number of abnormal results;

[0067] Specifically, if the metric item exists in the historical report analysis results, the metric item is the original metric item. If the metric item does not exist in the historical report analysis results, it means that the metric item is a newly added metric item. The metric value of the original metric item is compared with the corresponding benchmark value. If the metric value of the original metric item is the benchmark value, the original metric item is determined to be a normal metric item, otherwise it is an abnormal metric item. For the newly added metric item, since there is no benchmark value, the metric results of other metric items in the same process as the newly added metric item are used to determine whether the newly added metric item is abnormal. For example, if all other metric items in the same process are normal metric items, the metric result of the newly added metric item is assumed to be a normal result, that is, the newly added metric item is a normal metric item. If all other metric items in the same process have abnormal metric items, the newly added metric item is assumed to be abnormal, that is, the newly added metric item is an abnormal metric item.

[0068] It should be noted that, in this embodiment, the total number of normal results and the total number of abnormal results are set for each metric item. The total number of normal results refers to the total number of times that the metric item is a normal metric item in the current trusted report and the historical trusted report, and the total number of abnormal results refers to the total number of times that the metric item is an abnormal metric item in the current trusted report and the historical trusted report. If the metric item is a normal metric item in the current trusted report, it is necessary to add one to the total number of historical normal results of the metric item. If the metric item is an abnormal metric item, it is necessary to add one to the total number of historical abnormal results of the metric item. If the metric item is a newly added metric item, the total number of historical normal results and the total number of historical abnormal results of the metric item are both zero.

[0069] For example: in this trusted report, metric item A is an abnormal metric item, and the total number of historical abnormal results of metric item A is 2, then the total number of abnormal results after analysis is 2+1=3; if metric item B is an abnormal metric item in this trusted report, and metric item B is a newly added metric item, so the total number of historical abnormal results of metric item B is 0, then the total number of abnormal results after analysis is 1.

[0070] 2. Analyze the statistical information of the measurement value:

[0071] In this embodiment, the statistical information of the metric value includes: the metric value of each metric item, and the number of occurrences of each metric value. Specifically, this solution needs to match the metric value of each metric item in the current trusted report with the historical report analysis result. If the metric value of the metric item is the same as the metric value of the metric item in the historical report analysis result, the number of occurrences of the metric value is increased by one; if they are not the same, the metric value is added.

[0072] For example, in the historical report analysis results, the measurement values ​​of measurement item A are 3, 4, and 5, of which 3 appears once, 4 appears twice, and 5 appears three times. In this trusted report, if the measurement value of measurement item A is 3, the number of occurrences of measurement value 3 is increased from 1 to 2; if the measurement value of measurement item A is 1, since measurement value 1 does not appear in the historical report analysis results, measurement value 1 is added to the measurement value of measurement item A, that is, the updated measurement values ​​of measurement item A are 1, 3, 4, and 5.

[0073] 3. Analyze the processing methods of abnormal measurement items:

[0074] In this embodiment, the analysis of the processing method of the abnormal measurement item mainly analyzes the processing method of the abnormal measurement item in the current trusted report, matches it with the historical abnormal processing method of the abnormal measurement item in the historical report analysis result, checks whether it conforms to the historical processing method, and records the historical abnormal processing method, such as: which processing methods are included in the historical abnormal processing method of the abnormal measurement item, the number of occurrences of each processing method, etc.

[0075] 4. Analyze the changes in the total measurement items:

[0076] This analysis refers to determining the total number of measurement items in the current trusted report and the total number of measurement items in the historical report analysis results, and comparing the two data to see whether there is an increase or decrease.

[0077] S103, using the current report analysis results and the decision strategy generation rules to generate a target decision strategy; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or modify a decision strategy for an original metric item;

[0078] In this embodiment, a target decision strategy can be generated based on the current report analysis results and decision strategy generation rules; the decision strategy generation rules are used to add a decision strategy for a newly added measurement item, or to modify the decision strategy for an original measurement item, or to both add a decision strategy for a newly added measurement item and modify the decision strategy for an original measurement item, which is not specifically limited here.

[0079] It should be noted that the decision strategy generation rules are in the decision strategy management module, and the administrator can manage the decision strategy generation rules. The strategy generation rules include the following:

[0080] 1. Metric item level determination rule: The metric item level determination rule is used to set the device level, application level and metric item level, which is the importance level, so that the decision strategy can be generated according to the device level, application level and metric item level. Specifically, by setting the application level, the metric item level of the subsequently added metric item can be set according to the application level, or the metric item level of the metric item under the application can be modified according to the application level. By setting the metric item level, the decision strategy can be generated according to its level combined with the analysis results of the metric item in the trusted report.

[0081] 2. Rules for adding and modifying measurement items: The rules for adding and modifying measurement items are used to set rules for adding and modifying applications or measurement items, including: automatically adding and modifying policies when the application level is higher than the specified level, prompting managers to confirm additions and modifications when the application level is at the specified level, etc.

[0082] 3. Application scope of measurement items: Set the application scope of measurement items, including all, PC (Personal Computer), servers, power devices, cloud platforms, etc.

[0083] 4. Exception handling method: Set the handling method when the measurement item is abnormal, including: stopping the measurement item, stopping the application to which it belongs, forcibly deleting the application, issuing an alarm to the management center, continuing to run and recording logs, etc.

[0084] S104: Use the target adjudication strategy to adjudicate the credible report.

[0085] In this embodiment, after the latest target adjudication strategy is generated, the trusted report can be adjudicated according to the latest target adjudication strategy, and the abnormal items that are judged and controlled to be unreasonable by the trusted terminal device can be controlled.

[0086] In summary, this application can quickly sort out the key information in the trusted report through a standardized trusted report analysis method, and intuitively integrate the required data in the trusted report through data analysis and statistics, thereby improving the operating efficiency of the trusted report analysis capability, thereby improving the speed of generating the adjudication strategy. In addition, this application can set adjudication strategy generation rules in the trusted management center, and generate a target adjudication strategy that meets the device security requirements through the adjudication strategy generation rules and the analysis results of the trusted report, so as to adjudicate the trusted report of the trusted terminal device through a more appropriate adjudication strategy, thereby improving the security of the terminal device.

[0087] See also Figure 5 , Figure 5 A flowchart of another method for determining a credible report provided in an embodiment of the present application, wherein Figure 5 It can be seen that this method specifically includes the following steps:

[0088] S201, obtaining a trust report uploaded by a trusted terminal device;

[0089] S202, analyzing the credible report to obtain a current report analysis result; the current report analysis result is generated by matching the credible report with the historical report analysis result;

[0090] S203, according to the current report analysis results and the decision strategy generation rules, determine the benchmark value and exception handling method corresponding to each target metric item in the decision strategy; wherein the target metric item includes a newly added metric item and an original metric item;

[0091] S204, determining the application scope of the arbitration strategy of each target metric item according to the arbitration strategy generation rule, and generating the target arbitration strategy; wherein the arbitration strategy generation rule is used to add the arbitration strategy of the newly added metric item and / or modify the arbitration strategy of the original metric item;

[0092] S205: Use the target adjudication strategy to adjudicate the credible report.

[0093] In this embodiment, when generating a target decision strategy, the main thing is to determine the benchmark value, exception handling method and application scope of each target metric item in the decision strategy. Figure 6 , Figure 6 A schematic diagram of a decision strategy generation process provided in an embodiment of the present application; in this embodiment, only the determination process of the exception handling method, the reference value and the application scope is taken as an example to illustrate the decision strategy generation process:

[0094] 1. Exception handling method determination process:

[0095] 1. Use the adjudication strategy to generate rules to determine the device level, the metric item level of each target metric item, and the application level corresponding to the target metric item; determine the exception handling method corresponding to each target metric item based on the adjudication strategy to generate rules and at least one of the metric item level, application level and device level corresponding to each target metric item.

[0096] In this embodiment, the device level, the metric level of each target metric item, and the application level corresponding to the target metric item can be determined by the arbitration strategy generation rule. In addition, in this embodiment, the process specifically includes the following steps: determining the initial level of the device according to the device information and the arbitration strategy generation rule; adjusting the initial level of the device using the total number of the first metric items in the current report analysis result and the total number of the second metric items in the historical report analysis result to determine the device level; determining the initial level of the metric item of each target metric item and the application level corresponding to each target metric item according to the arbitration strategy generation rule; adjusting the initial level of the metric item of each target metric item according to the application level corresponding to each target metric item to determine the metric item level of each target metric item.

[0097] See also Figure 6 It can be seen that in this embodiment, it is first necessary to obtain the device information in the current report analysis result, and then match the device information with the measurement item level rule of the ruling strategy generation rule to determine the initial level of the device; and when determining the device level, it is also possible to compare the total number of the first measurement items in the current report analysis result with the total number of the second measurement items in the historical report analysis result, and determine the final device level according to the comparison result. For example: if the total number of the first measurement items is greater than the total number of the second measurement items, or the total number of the first measurement items is greater than the total number of the second measurement items, and the difference between the total number of the first measurement items and the total number of the second measurement items is greater than a predetermined value, it means that the number of applications or scripts of the trusted terminal device has increased. Since the more things installed in the trusted terminal device may be less secure, after the total number of measurement items increases, the level of the trusted terminal device needs to be upgraded, otherwise, the level of the trusted terminal device is reduced, so as to determine the final device level.

[0098] Furthermore, this solution also needs to obtain the metric items in the current report analysis results, match the metric items with the metric item level rules in the adjudication strategy generation rules, determine the application level and the initial level of the metric items; and, according to the application level, the initial level of the metric items can also be adjusted to determine the final metric item level of each target metric item. For example: if the application level is high, but the initial level of the metric items under the application is low, then the initial level of the metric items is increased, and the initial level of the metric items is increased by one level to obtain the final metric item level; if the application level is low, but the initial level of the metric items under the application is high, then the level of the metric items is kept unchanged, and the initial level of the metric items is used as the final metric item level; or, it can also be detected whether the total number of abnormal results of the metric item is less than a predetermined threshold, and if so, the metric item level of the metric item is reduced; if the target metric item is a newly added metric item, the corresponding metric item level can be determined according to the application level of the application to which the newly added metric item belongs, such as: the higher the application level, the higher the metric item level is matched, and the lower the application level, the lower the metric item level is matched.

[0099] After determining the device level, the metric level of each target metric item, and the application level corresponding to the target metric item through the above process, the exception handling method corresponding to each target metric item can be adjusted according to the metric addition and modification rules in the adjudication strategy generation rules. For example: if the target metric item is a newly added metric item, the corresponding handling method is matched according to the device level, application level, and metric level. If the device level, application level, and metric level are relatively high, a more stringent exception handling method is matched; if the device level, application level, and metric level are relatively low, a lighter exception handling method is matched; at the same time, the total number of abnormal results of the metric item can also be introduced in the matching process. If the total number of abnormal results is higher, a more stringent exception handling method is matched; if the total number of abnormal results is lower, a lighter exception handling method is matched; if the target metric item is an original metric item, it can be determined whether the exception handling method needs to be modified based on the device level, application level, metric level, and the total number of abnormal results.

[0100] For example, if the newly added metric item E belongs to application C, and the level of application C is level 3 (important), then a policy is added for the newly added metric item E. When matching the exception handling method for the newly added metric item E, a strict exception handling method is matched according to the level 3 of application C to which it belongs; if the level of metric item F is level 1 (general), a lighter exception handling method is matched for metric item F.

[0101] 2. Determine the total number of abnormal results for each target metric item; determine whether the total number of abnormal results is less than a predetermined threshold; if so, reduce the processing level of the abnormal processing method of the target metric item.

[0102] In this embodiment, the total number of abnormal results for each target metric item needs to be determined. If the total number of abnormal results is less than a predetermined threshold, the metric item level of this metric item is appropriately reduced, or the abnormal handling method is reduced. The predetermined threshold can be customized according to actual conditions.

[0103] It should be noted that when adjusting the exception handling method, you can also adjust it according to the exception handling method in the historical report analysis results. For example, in a trusted report, if a metric item has a new handling method, you can generate a new adjudication strategy based on the new handling method; you can also modify the exception handling method of the metric item based on the historical exception handling method corresponding to the metric item in the historical report analysis results, such as selecting the historical exception handling method that appears the most times in the historical exception handling methods as the exception handling method of the metric item.

[0104] 2. Benchmark value determination process:

[0105] Determine the first metric value corresponding to each newly added metric item, as well as the second metric value and historical baseline value corresponding to each original metric item; determine the baseline value of the newly added metric item using the number of occurrences of each first metric value corresponding to each newly added metric item; adjust the historical baseline value using the number of occurrences of each second metric value corresponding to each original metric item.

[0106] It should be noted that this embodiment is mainly divided into two processes when determining the benchmark value: if the metric item is a newly added metric item, then there is no benchmark value corresponding to the metric item, so this solution can determine the benchmark value of the newly added metric item according to the number of occurrences of each first metric value corresponding to the newly added metric item, and when determining the benchmark value of the newly added metric item according to the number of occurrences of the first metric value, the first metric value with the largest number of occurrences can be used as the benchmark value. If there are multiple first metric values ​​with the largest number of occurrences, the first metric value with the most recent measurement time is selected as the benchmark value. For example, a newly added metric item K has metric values ​​of 1, 2, and 3, respectively, where metric value 1 appears 3 times, metric value 2 appears 4 times, and metric value 3 appears 6 times. Then a policy is generated for the newly added metric item K: its benchmark value is set to 3. After the subsequent adjudication policy is generated, the administrator needs to confirm whether the benchmark value is 3, and the administrator can manually modify the benchmark value.

[0107] If the metric item is an original metric item, the baseline value is adjusted using the number of occurrences of each second metric value corresponding to each original metric item. During the adjustment, the second metric value with the most occurrences can be used as the new baseline value; if there are multiple second metric values ​​with the most occurrences, the second metric value with the most recent measurement time is selected as the baseline value. For example, the metric values ​​of the original metric item Y are A, B, and C; among them, the metric value A appears 5 times, the metric value B appears 2 times, and the metric value C appears 1 time; it can be seen that the metric value with the most occurrences is metric value A. If the baseline value is metric value A, it means that the baseline value is correct and does not need to be modified; if the baseline value is not A, a new policy is added to modify the baseline value to A. After the subsequent policy generation is completed, the administrator confirms whether the baseline can be modified to A.

[0108] It should be noted that after the target adjudication policy is generated, the administrator needs to be reminded to confirm the new baseline values ​​of the newly added metrics and original metrics in the target adjudication policy. The policy will be enabled only after the administrator confirms it. It is not enabled by default.

[0109] 3. Application scope determination process:

[0110] The target adjudication policy is generated by determining the application scope of the adjudication policy for each target metric item according to the adjudication policy generation rules. Specifically, this solution can match the application scope of the adjudication policy according to the device information in the current report analysis results, the application to which the metric item belongs, etc. For example: the adjudication policy generation rule sets the application scope of a certain metric item to PC, so the policy of a certain metric item is only used when the trusted terminal device is a PC; if the adjudication policy generation rule sets the application scope of a certain metric item to all devices, then the policy of a certain metric item can be used regardless of the type of device the trusted terminal device is.

[0111] In this embodiment, after generating the target adjudication policy, it also includes: displaying the target adjudication policy; if a policy modification instruction is received, modifying the target adjudication policy according to the policy modification instruction, and using the modified target adjudication policy to adjudicate the trusted report; if a policy confirmation instruction is received, using the target adjudication policy to adjudicate the trusted report.

[0112] It should be noted that after the target adjudication strategy is generated in this application, it can be determined whether to directly add or modify the target adjudication strategy based on the measurement item addition and modification rules, that is, whether the generated target adjudication strategy can be used directly. If it can be used directly, the trusted report is directly adjudicated through the target adjudication strategy; if it cannot be used directly, it is necessary to remind the management personnel to confirm whether the target adjudication strategy needs to be used, or whether the target adjudication strategy needs to be modified. Only after the management personnel confirms, the target adjudication strategy can be used. Among them, in the measurement item addition and modification rules, it is necessary to set which types of adjudication strategies need to be determined by the management personnel when they are added or modified, and which types of adjudication strategies do not need to be determined by the management personnel when they are added or modified. For example, in the present embodiment, when adding or modifying the benchmark value in the target adjudication strategy, the administrator needs to be reminded to confirm. If the benchmark value is not added or modified in the target adjudication strategy, the administrator does not need to confirm.

[0113] It should be noted that since the arbitration policy generation rules are customizable rules, the arbitration policy generated by the arbitration policy generation rules is not fixed. In this embodiment, only the above embodiment is taken as an example to illustrate the process of adding and modifying the exception handling method, benchmark value and application scope in the arbitration policy, but it is not limited to this.

[0114] From the above, it can be seen that after receiving the trusted report, the management center in this solution analyzes the trusted report, generates the latest decision strategy based on the current report analysis results and the decision strategy generation rules, and involves the latest decision strategy in the current trusted report decision process. There is no need to wait for the next trusted report to take effect, and timely control of abnormal content of trusted terminal devices can effectively ensure the security of the equipment.

[0115] See also Figure 7 , Figure 7 A schematic diagram of a structure of a credible report adjudication device provided in an embodiment of the present application, the device specifically comprises:

[0116] An acquisition module 11 is used to acquire a trust report uploaded by a trusted terminal device;

[0117] An analysis module 12 is used to analyze the credible report to obtain a current report analysis result; the current report analysis result is generated after matching the credible report with a historical report analysis result;

[0118] A strategy generation module 13 is used to generate a target decision strategy using the current report analysis results and decision strategy generation rules; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or to modify a decision strategy for an original metric item;

[0119] The adjudication module 14 is configured to adjudicate the credible report using the target adjudication strategy.

[0120] As an optional embodiment, the strategy generation module includes:

[0121] A first determination unit is used to determine a reference value and an exception handling method corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule; wherein the target metric item includes a newly added metric item and an original metric item;

[0122] The second determining unit is used to determine the application scope of the arbitration strategy of each target measurement item according to the arbitration strategy generation rule, and generate a target arbitration strategy.

[0123] As an optional embodiment, the first determining unit includes:

[0124] A first determining subunit, used to determine a first metric value corresponding to each newly added metric item, and a second metric value and a historical benchmark value corresponding to each original metric item;

[0125] A second determining subunit is used to determine a reference value of the newly added metric item by using the number of occurrences of each first metric value corresponding to each newly added metric item;

[0126] The third determining subunit is used to adjust the historical reference value by using the number of occurrences of each second metric value corresponding to each original metric item.

[0127] As an optional embodiment, the first determining unit includes:

[0128] A fourth determination subunit, configured to determine the device level, the metric item level of each target metric item, and the application level corresponding to the target metric item by using the arbitration strategy generation rule;

[0129] The fifth determination subunit is used to determine the exception handling method corresponding to each target metric item based on the arbitration strategy generation rule and at least one of the metric item level, application level and device level corresponding to each target metric item.

[0130] As an optional embodiment, the fourth determining subunit is specifically configured to:

[0131] Determine the initial level of the device based on the device information and the arbitration policy generation rules; use the total number of first measurement items in the current report analysis results and the total number of second measurement items in the historical report analysis results to adjust the initial level of the device to determine the device level; determine the initial level of each target measurement item and the application level corresponding to each target measurement item based on the arbitration policy generation rules; adjust the initial level of each target measurement item based on the application level corresponding to each target measurement item to determine the measurement item level of each target measurement item.

[0132] As an optional embodiment, the first determining unit includes:

[0133] A sixth determination subunit, used to determine the total number of abnormal results for each target metric item;

[0134] A judging subunit, used to judge whether the total number of abnormal results is less than a predetermined threshold; if so, triggering an adjusting subunit;

[0135] The adjustment subunit is used to reduce the processing level of the exception handling method of the target metric item.

[0136] As an optional embodiment, the decision device further includes:

[0137] A display module is used to display the target decision strategy; if a strategy modification instruction is received, the modification module is triggered; if a strategy confirmation instruction is received, the decision module is triggered;

[0138] The modification module is used to modify the target adjudication policy according to the policy modification instruction, and use the modified target adjudication policy to adjudicate the trusted report.

[0139] Regarding the device in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0140] See also Figure 8 , Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application, the electronic device specifically includes:

[0141] The processor 21, the memory 22 and the computer program stored in the memory 22 and executable on the processor 21, the processor 21 executes the steps of the method for adjudicating a trustworthy report described in any of the above method embodiments through the computer program.

[0142] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 may be implemented in at least one hardware form of DSP (Digital Signal Processing), FPGA (Field-Programmable Gate Array), and PLA (Programmable Logic Array). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in the awake state, also known as a CPU (Central Processing Unit); the coprocessor is a low-power processor for processing data in the standby state. In some embodiments, the processor 21 may be integrated with a GPU (Graphics Processing Unit), which is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an AI (Artificial Intelligence) processor, which is used to process computing operations related to machine learning.

[0143] The memory 22 may include one or more computer-readable storage media, which may be non-transitory. The memory 22 may also include high-speed random access memory, and non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 22 is at least used to store the following computer program 221, wherein, after the computer program is loaded and executed by the processor 21, it can implement the relevant steps in the method for adjudicating a trusted report disclosed in any of the aforementioned embodiments. In addition, the resources stored in the memory 22 may also include an operating system 222 and data 223, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 222 may include Windows, Unix, Linux, etc.

[0144] In some embodiments, the electronic device may further include a display screen 23 , an input / output interface 24 , a communication interface 25 , a sensor 26 , a power source 27 , and a communication bus 28 .

[0145] certainly, Figure 8 The structure of the electronic device shown does not constitute a limitation on the electronic device in the embodiments of the present application. In actual applications, the electronic device may include Figure 8 More or fewer components than shown, or combinations of certain components.

[0146] In another exemplary embodiment, a computer storage medium is also provided, and when the program instructions are executed by a processor, the steps of the method for adjudicating a trustworthy report described in any of the above method embodiments are implemented. The storage medium may include: a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and other media that can store program codes.

[0147] Optionally, the specific examples in this embodiment may refer to the examples described in the above embodiments, and this embodiment will not be described in detail here.

[0148] It should be understood that the terms used in the text are only for the purpose of describing specific example embodiments and are not intended to be limiting. Unless the context clearly indicates otherwise, the singular forms "one", "an" and "said" as used in the text may also be meant to include plural forms. The terms "include", "comprise", "contain", and "have" are inclusive, and therefore specify the existence of stated features, steps, operations, elements and / or parts, but do not exclude the existence or addition of one or more other features, steps, operations, elements, parts, and / or combinations thereof. The method steps, processes, and operations described in the text are not interpreted as necessarily requiring them to be performed in the specific order described or illustrated, unless the execution order is clearly indicated. It should also be understood that additional or alternative steps may be used.

[0149] The foregoing is merely a specific embodiment of the present invention, which enables those skilled in the art to understand or implement the present invention. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention will not be limited to the embodiments shown herein, but rather to the widest scope consistent with the principles and novel features claimed herein.

Claims

1. A method for adjudicating credible reports, characterized in that: include: Obtaining trusted reports uploaded by trusted terminal devices; Analyzing the credible report to obtain a current report analysis result; The current report analysis result is generated after matching the credible report with the historical report analysis result; Generate a target decision strategy using the current report analysis results and decision strategy generation rules; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or modify a decision strategy for an original metric item; The trusted report is adjudicated using the target adjudication policy.

2. The arbitration method according to claim 1, characterized in that: The method of using the current report analysis result and the decision strategy generation rule to generate a target decision strategy includes: Determine the benchmark value and exception handling method corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule; wherein the target metric item includes a newly added metric item and an original metric item; The application scope of the decision strategy of each target metric item is determined according to the decision strategy generation rule, and the target decision strategy is generated.

3. The arbitration method according to claim 2, characterized in that: Determining a reference value corresponding to each target metric item in the decision strategy according to the current report analysis result and the decision strategy generation rule includes: Determine a first metric value corresponding to each newly added metric item, and a second metric value and a historical benchmark value corresponding to each original metric item; Determine a reference value of the newly added metric item by using the number of occurrences of each first metric value corresponding to each newly added metric item; The historical benchmark value is adjusted using the number of occurrences of each second metric value corresponding to each original metric item.

4. The arbitration method according to claim 2, characterized in that: According to the current report analysis result and the decision strategy generation rule, determine the exception handling method corresponding to each target metric item in the decision strategy, including: Generating rules using the adjudication strategy to determine the device level, the metric level of each target metric item, and the application level corresponding to the target metric item; According to the arbitration strategy generation rules and at least one of the metric item level, application level and device level corresponding to each target metric item, an exception handling method corresponding to each target metric item is determined.

5. The arbitration method according to claim 4, characterized in that: The arbitration strategy is used to generate rules to determine the device level, the metric level of each target metric item, and the application level corresponding to the target metric item, including: Determining an initial level of a device according to the device information and the adjudication strategy generation rule; Using the total number of the first metric item in the current report analysis result and the total number of the second metric item in the historical report analysis result, the initial level of the device is adjusted to determine the level of the device; Determining the initial level of each target metric item and the application level corresponding to each target metric item according to the adjudication strategy generation rule; According to the application level corresponding to each target metric item, the initial metric item level of each target metric item is adjusted to determine the metric item level of each target metric item.

6. The arbitration method according to claim 2, characterized in that: According to the current report analysis result and the decision strategy generation rule, determine the exception handling method corresponding to each target metric item in the decision strategy, including: Determine the total number of abnormal results for each target metric; Determining whether the total number of abnormal results is less than a predetermined threshold; If so, lower the processing level of the exception handling method of the target metric item.

7. The arbitration method according to any one of claims 1 to 6, characterized in that: After the target adjudication strategy is generated, the method further includes: Presenting the target adjudication strategy; If a policy modification instruction is received, modifying the target adjudication policy according to the policy modification instruction, and using the modified target adjudication policy to adjudicate the trusted report; If a policy confirmation instruction is received, the step of using the target arbitration policy to adjudicate the trustworthy report is performed.

8. A credible report adjudication device, characterized in that: include: An acquisition module is used to acquire a trusted report uploaded by a trusted terminal device; An analysis module, used for analyzing the credible report to obtain a current report analysis result; The current report analysis result is generated after matching the credible report with the historical report analysis result; A strategy generation module, used to generate a target decision strategy using the current report analysis results and decision strategy generation rules; wherein the decision strategy generation rules are used to add a decision strategy for a newly added metric item and / or to modify a decision strategy for an original metric item; The adjudication module is used to adjudicate the trusted report using the target adjudication strategy.

9. An electronic device, characterized in that: include: A processor, a memory, and a computer program stored in the memory and executable on the processor, wherein the processor executes the steps of the method for adjudicating a credible report as described in any one of claims 1 to 7 of the present application through the computer program.

10. A computer storage medium, characterized in that: The computer storage medium stores computer executable instructions, and the computer executable instructions are used to execute the steps of the method for adjudicating a credible report as described in any one of claims 1 to 7 of the present application.