Portable entity root and cloud host security control method based on portable entity root

By designing a portable physical root, using its password security chip, system-on-chip and Ethernet interfaces to interact with the trusted root of the cloud host for interactive authentication and joint security control, the trust risk and portability problems in cloud host security control are solved, and effective security authentication and control of cloud hosts are achieved.

CN120017270AActive Publication Date: 2025-05-16NANJING HUADUN ELECTRIC POWER INFORMATION SAFETY EVALUATION CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510465871.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-05-16
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

The trusted root of cloud hosts is provided by cloud service providers, which poses a trust risk, and the user's mobile office needs to require security control equipment to have portable mobile features. How to effectively control cloud hosts has become an urgent problem for technicians to solve.

Method used

A portable entity root is designed, including a password security chip, a system on chip and an Ethernet interface. Through these components, public-private key generation, data encryption, and digital signature functions are realized, and communication and interactive authentication is carried out with the trusted root of the cloud host to form a consortium for security control.

Benefits of technology

Effectively prevent hacker attacks, reduce trust risks, improve the portability and mobility of security control devices, and ensure secure authentication and control of cloud hosts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017270A_ABST
    Figure CN120017270A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a portable entity root. The portable entity root comprises a password security chip, a system on chip and an Ethernet interface; wherein the password security chip is used for providing public and private key generation, data encryption and digital signature functions; the system on chip is used for providing a software operating system for the portable entity root so as to complete interaction authentication between the portable entity root and the cloud host; and the Ethernet interface is used for accessing the portable entity root to a network and communicating with a trusted root of a cloud host. By adopting the technical scheme of the embodiment of the invention, the constructed portable entity root is used as the security control equipment of the cloud host, and security authentication and security control are performed on the cloud host, so that hacker attack is effectively prevented, the trust risk is reduced, and the portability and mobility of the security control equipment are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the field of information security technology, and in particular to a portable physical root and a cloud host security control method based on the portable physical root. Background Art

[0002] Trust means that if an entity can achieve the expected purpose in the expected way, then the entity is trustworthy. The technology that ensures the trustworthiness of entities is called trusted computing technology, and the core of trusted computing technology is the root of trust. The root of trust does not need to be proven, and the three security aspects of technology, entity and management will together ensure the trustworthiness of the root of trust. With the root of trust as the starting point, a trusted computing environment can be constructed through a step-by-step measurement method.

[0003] The root of trust is usually built into the computing device and is not movable. However, with the development of cloud computing, users deploy their services to the cloud by renting cloud hosts; at the same time, more and more users are sampling mobile office methods. Since the root of trust of the cloud host is provided by the cloud service provider, there is a trust risk, so users cannot rely on the root of trust alone and need to add their own independent security control equipment; in addition, the user's demand for mobile office also requires that the security control equipment has portable and mobile characteristics.

[0004] Therefore, how to perform security control on cloud hosts is a technical problem that needs to be solved urgently by those skilled in the art. Summary of the invention

[0005] The embodiment of the present invention provides a portable physical root and a cloud host security control method based on the portable physical root, so as to realize security authentication and security control of the cloud host, so as to effectively prevent hacker attacks, reduce trust risks, and improve the portability and mobility of security control equipment.

[0006] In a first aspect, an embodiment of the present invention provides a portable physical root, characterized in that the portable physical root includes a cryptographic security chip, a system on chip, and an Ethernet interface; wherein:

[0007] The cryptographic security chip is used to provide public and private key generation, data encryption and digital signature functions;

[0008] The system on chip is used to provide a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host;

[0009] The Ethernet interface is used to connect the portable physical root to the network and communicate with the trusted root of the cloud host.

[0010] In a second aspect, an embodiment of the present invention further provides a cloud host security control method based on a portable physical root, characterized in that the method is implemented using a portable physical root, and the method includes:

[0011] During the cloud host startup phase, the portable physical root is connected to the cloud host trusted root through the Ethernet interface and interactive authentication is completed;

[0012] When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root form a union, through which the external entity is authenticated and authorized to access, so as to perform security control on the cloud host.

[0013] The embodiment of the present invention provides a portable physical root, which includes a cryptographic security chip, a system on chip, and an Ethernet interface; wherein the cryptographic security chip is used to provide public and private key generation, data encryption, and digital signature functions; the system on chip is used to provide a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host; the Ethernet interface is used to connect the portable physical root to the network and communicate with the trusted root of the cloud host. In the embodiment of the present invention, the constructed portable physical root is used as a security control device for the cloud host to perform security authentication and security control on the cloud host to effectively prevent hacker attacks, reduce trust risks, and improve the portability and mobility of the security control device. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Other features, objects and advantages of the present invention will become more apparent by reading the detailed description of non-limiting embodiments made with reference to the following drawings. The drawings are only for the purpose of illustrating preferred embodiments and are not to be considered as limiting the present invention. Also, the same reference symbols are used throughout the drawings to represent the same parts. In the drawings:

[0015] Figure 1 is a schematic diagram of the structure of a portable physical root provided in an embodiment of the present invention;

[0016] Figure 2 is a schematic diagram of the structure of another portable physical root provided in an embodiment of the present invention;

[0017] Figure 3 It is a structural diagram of a portable entity root participating in the working process of a cloud host provided in an embodiment of the present invention;

[0018] Figure 4 A flowchart of a cloud host security control method based on a portable physical root provided in an embodiment of the present invention;

[0019] Figure 5A flowchart of a method for performing security control on a cloud host during the cloud host startup phase provided in an embodiment of the present invention;

[0020] Figure 6 A flowchart of a method for performing security control on a cloud host during an external entity access phase provided in an embodiment of the present invention;

[0021] Figure 7 A schematic diagram of the structure of another portable entity root participating in the working process of a cloud host provided in an embodiment of the present invention;

[0022] Figure 8 A schematic diagram of the structure of a cloud host security control device based on a portable physical root provided in an embodiment of the present invention;

[0023] Fig. 9 The present invention is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] The present invention will be further described in detail below in conjunction with the accompanying drawings and embodiments. It is to be understood that the specific embodiments described herein are only used to explain the present invention, rather than to limit the present invention. It should also be noted that, for ease of description, only parts related to the present invention, rather than all structures, are shown in the accompanying drawings.

[0025] Before discussing the exemplary embodiments in more detail, it should be mentioned that some exemplary embodiments are described as processes or methods depicted as flow charts. Although the flow charts describe the operations (or steps) as sequential processes, many of the operations (or steps) therein can be implemented in parallel, concurrently or simultaneously. In addition, the order of the operations can be rearranged. The process can be terminated when its operation is completed, but can also have additional steps not included in the accompanying drawings. The process can correspond to a method, function, procedure, subroutine, subprogram, etc.

[0026] Among them, the acquisition, storage, use and processing of data in the technical solution of this application are in compliance with the relevant provisions of national laws and regulations. It should be noted that in the embodiments of this application, some existing solutions in the industry such as certain software, components or models may be mentioned, which should be considered as exemplary, and their purpose is only to illustrate the feasibility of the implementation of the technical solution of this application, but it does not mean that the applicant has or will necessarily use the solution.

[0027] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the numbers used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein.

[0028] Embodiment 1

[0029] Figure 1 is a schematic diagram of the structure of a portable physical root provided in an embodiment of the present invention. This embodiment is applicable to the case where a user rents a cloud host and uses the portable physical root to perform security control on the cloud host, such as Figure 1 As shown, the portable physical root 100 provided in the embodiment of the present invention may include: a cryptographic security chip 110, a system on chip 120 and an Ethernet interface 130; wherein:

[0030] The cryptographic security chip 110 is used to provide public and private key generation, data encryption and digital signature functions;

[0031] The system on chip 120 is used to provide a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host;

[0032] The Ethernet interface 130 is used to connect the portable physical root to the network and communicate with the trusted root of the cloud host.

[0033] When a user rents a cloud host and deploys a service to the cloud, the portable physical root constructed by the embodiment of the present invention is used to perform security control on the rented cloud host. The portable physical root may refer to a security control device for performing security control on the cloud host. The portable physical root is a compact and independently operable card-type device with a password security function, which can be connected to the network through an Ethernet interface.

[0034] Among them, the portable entity root includes a cryptographic security chip, which is a device that can independently generate keys and encrypt and decrypt. It has an independent processor and storage unit inside, which can store keys and feature data, and provide encryption and security authentication services for the device. The cryptographic security chip is an integrated circuit chip that implements one or more cryptographic algorithms and directly or indirectly uses cryptographic technology to protect keys and sensitive information. As the bottom-level security guarantee for smart terminals, its application can effectively prevent security threats such as hacker attacks. In an embodiment of the present invention, the cryptographic security chip has the functions of providing public and private key generation, data encryption, and digital signature, so that when the portable entity is connected to the cloud host, the cloud host can be authenticated and securely controlled to effectively prevent hacker attacks and reduce trust risks.

[0035] The system on chip may refer to a technology that integrates a complete system on a single chip and groups all or part of the necessary electronic circuits. In an embodiment of the present invention, the system on chip provides a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host.

[0036] The Ethernet interface connects the portable physical root to the network and communicates with the trusted root of the cloud host. Since the cloud host is deployed in the cloud, it is impossible to insert a physical root device such as a USB, and it is also impossible to transmit all the data of the cloud server to the physical root through the network; therefore, the embodiment of the present invention connects the portable physical root to the cloud host through the Ethernet interface, and performs collaborative cryptographic calculations with the cloud host through the Ethernet interface to jointly complete the trusted authentication process. Optionally, the Ethernet interface supports the trusted security function of remote servers across the network, has more resources and computing power than other physical roots in the prior art, and supports network operations.

[0037] In an optional solution of the embodiment of the present invention, the portable physical root further includes a closed shell, and the closed shell encloses the cryptographic security chip and the system on chip inside the portable physical root.

[0038] Among them, see Figure 2 , Figure 2 On the left side is the internal module structure of the portable physical root M1, which is composed of a cryptographic security chip, a chip operating system (COS) and an Ethernet interface. Figure 2 The middle right side is a schematic diagram of the appearance of the portable physical root M1, including a compact closed shell and an Ethernet interface. When using the portable physical root, the portable physical root is plugged into the network cable for power-on startup; after use, the portable physical root is unplugged from the network cable and carried with you to improve the portability of the portable physical root.

[0039] In an optional scheme of an embodiment of the present invention, the portable physical root is an independently operated card-type device, the portable physical root is connected to a preset network through an Ethernet interface, and forms a consortium with the cloud host trusted root; wherein the consortium is used to complete the interactive authentication between the portable physical root and the cloud host trusted root.

[0040] Among them, see Figure 3, the portable physical root M1 is connected to the preset network through the Ethernet interface, and forms a union LI with the cloud host trusted root M2, and the union is used to complete the interactive authentication between the portable physical root and the cloud host trusted root. When the cloud server is started, the portable physical root needs to be connected to the network. Any step in the startup process needs to be completed together using the union, otherwise it cannot be completed. For example, when the portable physical root is connected to the cloud host, the union needs to be used to interactively authenticate the portable physical root and the cloud host trusted root. After the interactive authentication is successful, it is determined that the portable physical root has been successfully connected, otherwise the access is unsuccessful. After the portable physical root is connected, the portable physical root shown is used to perform security control on the cloud host.

[0041] The embodiment of the present invention provides a portable physical root, which includes a cryptographic security chip, a system on chip, and an Ethernet interface; wherein the cryptographic security chip is used to provide public and private key generation, data encryption, and digital signature functions; the system on chip is used to provide a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host; the Ethernet interface is used to connect the portable physical root to the network and communicate with the trusted root of the cloud host. The portable physical root constructed using the embodiment of the present invention performs security authentication and security control on the cloud host to effectively prevent hacker attacks, reduce trust risks, and improve portability.

[0042] Embodiment 2

[0043] Figure 4 This is a flowchart of a cloud host security control method based on a portable physical root provided in an embodiment of the present invention. This embodiment is applicable to the case where a user rents a cloud host and uses a portable physical root to perform security control on the cloud host. The method of this embodiment can be executed by a cloud host security control device based on a portable physical root, and the device can be implemented using a constructed portable physical root. The device can be configured in a server for cloud host security control based on a portable physical root. The method specifically includes the following steps:

[0044] S410: During the cloud host startup phase, the portable physical root is connected to the cloud host trusted root through an Ethernet interface, and interactive authentication is completed.

[0045] In the cloud host, the root of trust can build a platform trust chain from hardware to software, from the bottom to the top. The root of trust can measure and verify the software stack through the algorithms and keys implanted in the trusted hardware by the chip manufacturer, as well as the integrated dedicated microcontroller, to ensure the trustworthiness of the cloud host system and provide basic security for the cloud host.

[0046] In real life, users deploy services to the cloud by renting cloud hosts; however, since the trusted root of the cloud host is provided by the cloud service provider, there are certain risks. Therefore, the embodiment of the present invention uses a portable physical root to perform security control on the cloud host to reduce the trust risk, and the portable physical root has certain portable and mobile characteristics.

[0047] During the cloud host startup phase, the portable physical root communicates with the cloud host trusted root through Ethernet and completes interactive authentication. The interactive authentication is completed in the union of the portable physical root and the cloud host trusted root. Figure 3 The portable physical root and the cloud host trusted root form a union, and a joint password verification is performed in the union to communicatively connect the portable physical root with the cloud host trusted root to perform security control on the cloud host.

[0048] S420: When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root form a union, and the external entity is authenticated and authorized through the union to perform security control on the cloud host.

[0049] The external entity may refer to an entity that interacts with the cloud host for data. When the external entity accesses the cloud host, the portable entity root and the cloud host trusted root are first combined to form a union, and interactive authentication is performed to perform security control on the cloud host. The union is used to perform access authentication and access authorization on the external entity to perform security control on the cloud host.

[0050] The embodiment of the present invention provides a cloud host security control method based on a portable physical root. In the cloud host startup phase, the portable physical root is connected to the cloud host trusted root through an Ethernet interface and interactive authentication is completed; in the external entity access to the cloud host phase, the portable physical root and the cloud host trusted root form a union, and the external entity is authenticated and authorized through the union to perform security control on the cloud host. The technical solution of the embodiment of the present invention is adopted to form a union with the portable physical root and the cloud host trusted root, and the portable physical root and the cloud host trusted root are interactively authenticated through the union to perform security control on the cloud host; the external entity is securely authenticated through the union to avoid malicious access by the external entity, thereby improving the security of the cloud host.

[0051] Embodiment 3

[0052] Figure 5The flowchart of a cloud host security control method based on a portable physical root provided in an embodiment of the present invention. The embodiment of the present invention further optimizes the above embodiment on the basis of the above embodiment, and the embodiment of the present invention can be combined with various optional solutions in one or more of the above embodiments. Figure 5 As shown, the cloud host security control method based on the portable physical root provided in the embodiment of the present invention may include the following steps:

[0053] S510: Insert the portable physical root into a network cable through an Ethernet interface to power on and operate the portable physical root.

[0054] Among them, see Figure 7 The cloud service provider deploys a cloud server physical machine on the computing node, generates multiple cloud hosts on the cloud server physical machine, and runs a Linux host operating system and a virtual machine management software (Virtual Machine Monitor, VMM). In the embodiment of the present invention, taking cloud host 1 as an example, the user rents cloud host 1 from the cloud service provider, and the cloud service provider initializes the trusted root in cloud host 1.

[0055] During the cloud host startup phase, the user inserts the portable physical root constructed by the embodiment of the present invention into a network cable, and the portable physical root runs.

[0056] S520: Power on the cloud host to start the built-in trusted root of the cloud host.

[0057] The cloud host 1 rented by the user is powered on and started, so as to power on and run the built-in trusted root of the cloud host 1.

[0058] S530, the cloud host trusted root is connected to the portable physical root to form a union.

[0059] The portable physical root is connected to the trusted root of the cloud host 1 to form a union. Any step in the cloud host startup phase requires the union to complete together to ensure the security of the cloud host.

[0060] S540: In the consortium, the cloud host trusted root and the portable entity root use a preset public key for interactive authentication.

[0061] After the cloud host trusted root is successfully connected to the portable physical root, the system firmware of the portable physical root will be measured for integrity first, and then a signature will be requested. The signature needs to be completed by the consortium through joint cryptographic calculation. After the firmware integrity measurement is completed, the integrity measurement of the cloud host's trusted operating system is performed. Similarly, the signature of this process needs to be completed by the consortium through joint cryptographic calculation. That is, after the calculations of both parties are passed, the subsequent measurements will continue to be executed, otherwise the startup will be stopped and an error will be returned.

[0062] As an optional but non-limiting implementation, the cloud host trusted root and the portable physical root use a preset public key for interactive authentication, including but not limited to steps A1-A3:

[0063] Step A1: The cloud host trusted root verifies the portable physical root according to the first public key pre-configured in the portable physical root to obtain a first verification result; wherein the preset public key includes the first public key, and the first public key is generated by the cloud host trusted root.

[0064] Step A2: The portable entity root verifies the cloud host trusted root according to the second public key pre-configured in the cloud host trusted root to obtain a first verification result; wherein the preset public key includes the second public key, and the second public key is generated by the portable entity root.

[0065] Step A3: Based on the first verification result and the second verification result, interactive authentication is performed on the cloud host trusted root and the portable physical root.

[0066] Among them, when the cloud host trusted root verifies the portable entity root, the cloud host trusted root obtains the first public key pre-configured in the portable entity root from the portable entity root, and the first public key is generated by the cloud host trusted root; the cloud host trusted root determines whether the public key in the portable entity root is provided by the cloud host trusted root, so as to perform a first authentication on the portable entity root. Optionally, the first authentication may refer to the cloud host trusted root generating a first signature, the cloud host trusted root obtaining the first public key, and using the first public key to authenticate the first signature, so as to authenticate the portable entity root.

[0067] In addition to the cloud host trusted root authenticating the portable entity root, the portable entity root also needs to authenticate the cloud host trusted root. Obtain a second public key from the cloud host trusted root, and confirm whether the second public key is a public key generated by the portable entity root to perform a second authentication on the cloud host trusted root. Optionally, the second authentication may refer to the portable entity root generating a second signature, the portable entity root obtaining a second public key, and using the second public key to authenticate the second signature to authenticate the cloud host trusted root.

[0068] After the portable physical root and the cloud host trusted root authentication are completed, the interactive authentication is completed in the union.

[0069] The embodiment of the present invention provides a cloud host security control method based on a portable physical root. During the cloud host startup phase, the portable physical root is plugged into a network cable through an Ethernet interface to power on and run the portable physical root; the cloud host is powered on and started to power on and run the built-in trusted root of the cloud host; the cloud host trusted root is connected to the portable physical root in communication and forms a union; in the union, the cloud host trusted root and the portable physical root use a preset public key for interactive authentication. By adopting the technical solution of the embodiment of the present invention, when a user rents a cloud host and starts the cloud host, the portable physical root needs to interactively authenticate with the cloud host trusted root, thereby ensuring the security control of the cloud host; at the same time, the portable physical root is portable and can be carried by the user, making it convenient for the user to use it in mobile office.

[0070] Embodiment 4

[0071] Figure 6 The flowchart of a cloud host security control method based on a portable physical root provided in an embodiment of the present invention. The embodiment of the present invention further optimizes the above embodiment on the basis of the above embodiment, and the embodiment of the present invention can be combined with various optional solutions in one or more of the above embodiments. Figure 6 As shown, the cloud host security control method based on the portable physical root provided in the embodiment of the present invention may include the following steps:

[0072] S610: When an external entity accesses a cloud host, the portable entity root and the cloud host trusted root are combined into a union, and a data signature is generated by the union.

[0073] Among them, the embodiment of the present invention takes the cloud host accessing an external entity as an example to perform security control on the cloud host. Before the external entity accesses the cloud host, the portable entity root and the cloud host trusted root have completed interactive authentication. During the stage of the external entity accessing the cloud host, the portable entity root and the cloud host trusted root form a union, and a data signature is generated by the union. The data signature is jointly generated by the portable entity root and the cloud host trusted root; for example, a part of the data signature is generated by the portable entity root, and the other part is generated by the cloud host trusted root, and the two parts are combined to form a data signature. The data signature is jointly generated by the portable entity root and the cloud host trusted root, which ensures the security of the cloud host.

[0074] S620: Based on the data signature, the consortium performs joint cryptographic authentication with an external entity.

[0075] The joint password authentication is to perform interactive authentication on the consortium and the external entity. After the consortium determines the identity of the external entity and the external entity determines the identity of the consortium, the external entity is connected to the cloud host.

[0076] As an optional but non-limiting implementation, based on the data signature, the consortium and the external entity perform joint cryptographic authentication, including but not limited to steps B1-B2:

[0077] Step B1: The consortium obtains a third public key pre-configured in the external entity, and uses the third public key to verify the data signature to authenticate the access of the external entity; wherein the third public key is a joint public key generated by the portable entity root and the cloud host trusted root.

[0078] Step B2: The external entity obtains a fourth public key pre-configured in the consortium to authenticate the consortium; wherein the fourth public key is generated by the external entity.

[0079] When an external entity accesses the cloud host, the external entity also needs to be authenticated. In the embodiment of the present invention, a consortium is used to authenticate the external entity, and the external entity also needs to authenticate the consortium.

[0080] The consortium obtains the third public key pre-configured in the external entity, and uses the third public key to verify the data signature generated by the consortium. The third public key is generated by the consortium, and the third public key is used to verify the data signature to authenticate the external entity. Similarly, the external entity obtains the fourth public key pre-configured in the consortium, and authenticates the consortium based on the fourth public key. Only after the external entity and the consortium are authenticated, can the external entity be connected to the cloud host.

[0081] S630: After the joint password authentication between the consortium and the external entity is successful, the consortium authorizes access to the external entity to perform security control on the cloud host.

[0082] After the external entity and the federation successfully perform joint password authentication, the federation authorizes access to the external entity.

[0083] As an optional but non-limiting implementation, the method further includes:

[0084] If the portable entity root and the cloud host trusted root have not completed interactive authentication, or the consortium and the external entity have not completed interactive authentication, the portable entity root and the cloud host trusted root will be disconnected, and the cloud server will remain in its original operating state; wherein the cloud server includes a cloud host, a cloud host trusted root and an operating system.

[0085] The communication connection between the portable physical root and the cloud host trusted root, as well as the access and authorization between the cloud host and external entities, all require the participation of the portable physical root. If the portable physical root and the cloud host trusted root have not completed interactive authentication, or the consortium and the external entity have not completed interactive authentication, the portable physical root and the cloud host trusted root will be disconnected, and the cloud server will remain in its original operating state, thus ensuring the security of the cloud host. Keeping the cloud server in its original operating state includes but is not limited to the cloud server being unable to download and update, the system software or user software being unable to add or reduce functions, and being unable to switch the system's working state, such as restarting, suspending, and logging off.

[0086] The embodiment of the present invention provides a cloud host security control method based on a portable entity root. When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root form a union, and a data signature is generated by the union; based on the data signature, the union and the external entity perform joint password authentication; wherein, the joint password authentication is to perform interactive authentication on the union and the external entity; after the joint password authentication between the union and the external entity is successful, the union authorizes the external entity to access the cloud host, so as to perform security control on the cloud host. By adopting the technical solution of the embodiment of the present invention, when an external entity accesses the cloud host, a union is formed by the portable entity root and the cloud host trusted root, and the external entity and the union perform interactive authentication, so as to ensure the security of the cloud host and reduce the risk of hacker attacks.

[0087] Embodiment 5

[0088] Figure 8 This is a schematic diagram of the structure of a cloud host security control device based on a portable physical root provided in an embodiment of the present invention. The technical solution of this embodiment can be applied to the situation where a user rents a cloud host and uses a portable physical root to perform security control on the cloud host. The device can be implemented by software and / or hardware and is generally integrated on any electronic device with network communication function, including but not limited to: servers, computers, personal digital assistants and other devices. Figure 8 As shown, the cloud host security control device based on the portable physical root provided in this embodiment may include: a cloud host startup authentication module 810 and an external entity access authentication module 820; wherein,

[0089] The cloud host startup authentication module 810 is used to connect the portable physical root to the cloud host trusted root through the Ethernet interface during the cloud host startup phase and complete the interactive authentication;

[0090] The external entity access authentication module 820 is used to perform access authentication and access authorization on the external entity through the association when the external entity accesses the cloud host, so as to perform security control on the cloud host.

[0091] Based on the above embodiment, optionally, the cloud host starts an authentication module, which is specifically used to:

[0092] Insert the portable physical root into a network cable through an Ethernet interface to power on and operate the portable physical root;

[0093] Power on the cloud host to start the built-in trusted root of the cloud host;

[0094] The cloud host trusted root is connected to the portable physical root through communication and forms a union;

[0095] In the consortium, the cloud host trusted root and the portable entity root use a preset public key for interactive authentication.

[0096] Based on the above embodiment, optionally, the cloud host starts an authentication module, which is specifically used to:

[0097] The cloud host trusted root verifies the portable physical root according to the first public key pre-configured in the portable physical root to obtain a first verification result; wherein the preset public key includes the first public key, and the first public key is generated by the cloud host trusted root;

[0098] The portable physical root verifies the cloud host trusted root according to the second public key pre-configured in the cloud host trusted root to obtain a first verification result; wherein the preset public key includes the second public key, and the second public key is generated by the portable physical root;

[0099] According to the first verification result and the second verification result, the cloud host trusted root and the portable physical root are interactively authenticated.

[0100] Based on the above embodiment, optionally, the external entity access authentication module is specifically used to:

[0101] When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root are combined into a union, and a data signature is generated by the union;

[0102] Based on the data signature, the consortium and the external entity perform joint cryptographic authentication; wherein the joint cryptographic authentication is to perform interactive authentication on the consortium and the external entity;

[0103] After the joint password authentication between the consortium and the external entity is successful, the consortium authorizes access to the external entity to perform security control on the cloud host.

[0104] Based on the above embodiment, optionally, the external entity access authentication module is further specifically used for:

[0105] The consortium obtains a third public key pre-configured in the external entity, and uses the third public key to verify the data signature to authenticate the access of the external entity; wherein the third public key is a joint public key generated by the portable entity root and the cloud host trusted root;

[0106] The external entity obtains a fourth public key pre-configured in the union to authenticate the union; wherein the fourth public key is generated by the external entity.

[0107] Based on the above embodiment, optionally, the data signature is jointly generated by the portable physical root and the cloud host trusted root.

[0108] On the basis of the above embodiment, optionally, the portable physical root-based cloud host security control device further includes a connection disconnection module, which is specifically used to:

[0109] If the portable entity root and the cloud host trusted root have not completed interactive authentication, or the consortium and the external entity have not completed interactive authentication, the portable entity root and the cloud host trusted root will be disconnected, and the cloud server will remain in its original operating state; wherein the cloud server includes a cloud host, a cloud host trusted root and an operating system.

[0110] The portable physical root-based cloud host security control device provided in the embodiments of the present invention can execute the portable physical root-based cloud host security control method provided in any of the above-mentioned embodiments of the present invention, and has the corresponding functions and beneficial effects of executing the portable physical root-based cloud host security control method. For detailed processes, please refer to the relevant operations of the portable physical root-based cloud host security control method in the above-mentioned embodiments.

[0111] Embodiment 6

[0112] Fig. 9 1 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present invention. The electronic device 10 is intended to represent various forms of digital computers, such as laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device may also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices (such as helmets, glasses, watches, etc.) and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present invention described and / or required herein.

[0113] like Fig. 9 As shown, the electronic device 10 includes at least one processor 11, and a memory connected to the at least one processor 11, such as a read-only memory (ROM) 12, a random access memory (RAM) 13, etc., wherein the memory stores a computer program that can be executed by at least one processor, and the processor 11 can perform various appropriate actions and processes according to the computer program stored in the read-only memory (ROM) 12 or the computer program loaded from the storage unit 18 to the random access memory (RAM) 13. In the RAM 13, various programs and data required for the operation of the electronic device 10 can also be stored. The processor 11, the ROM 12, and the RAM 13 are connected to each other through a bus 14. The input / output (I / O) interface 15 is also connected to the bus 14.

[0114] A number of components in the electronic device 10 are connected to the I / O interface 15, including: an input unit 16, such as a keyboard, a mouse, etc.; an output unit 17, such as various types of displays, speakers, etc.; a storage unit 18, such as a disk, an optical disk, etc.; and a communication unit 19, such as a network card, a modem, a wireless communication transceiver, etc. The communication unit 19 allows the electronic device 10 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks.

[0115] The processor 11 may be a variety of general and / or dedicated processing components with processing and computing capabilities. Some examples of the processor 11 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various processors running machine learning model algorithms, a digital signal processor (DSP), and any appropriate processor, controller, microcontroller, etc. The processor 11 executes the various methods and processes described above, such as a cloud host security control method based on a portable physical root.

[0116] In some embodiments, the cloud host security control method based on the portable physical root can be implemented as a computer program, which is tangibly contained in a computer-readable storage medium, such as a storage unit 18. In some embodiments, part or all of the computer program can be loaded and / or installed on the electronic device 10 via the ROM 12 and / or the communication unit 19. When the computer program is loaded into the RAM 13 and executed by the processor 11, one or more steps of the method described above can be performed. Alternatively, in other embodiments, the processor 11 can be configured to execute the cloud host security control method based on the portable physical root in any other appropriate manner (for example, by means of firmware).

[0117] In particular, according to an embodiment of the present invention, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present invention includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the cloud host security control method based on the portable entity root shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication unit 19, or installed from the storage unit 18, or installed from the ROM 12. When the computer program is executed by the processor 11, the above-mentioned functions defined in the cloud host security control method based on the portable entity root of the embodiment of the present invention are executed.

[0118] Various implementations of the systems and techniques described above herein can be implemented in digital electronic circuit systems, integrated circuit systems, field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), load programmable logic devices (CPLDs), computer hardware, firmware, software, and / or combinations thereof. These various implementations can include: being implemented in one or more computer programs that can be executed and / or interpreted on a programmable system including at least one programmable processor, which can be a special purpose or general purpose programmable processor that can receive data and instructions from a storage system, at least one input device, and at least one output device, and transmit data and instructions to the storage system, the at least one input device, and the at least one output device.

[0119] Computer programs for implementing the methods of the present invention may be written in any combination of one or more programming languages. These computer programs may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that when the computer program is executed by the processor, the functions / operations specified in the flow chart and / or block diagram are implemented. The computer program may be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.

[0120] In the context of the present invention, a computer-readable storage medium may be a tangible medium that may contain or store a computer program for use by or in conjunction with an instruction execution system, device, or equipment. A computer-readable storage medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or equipment, or any suitable combination of the foregoing. Alternatively, a computer-readable storage medium may be a machine-readable signal medium. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0121] To provide interaction with a user, the systems and techniques described herein may be implemented on an electronic device having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or trackball) through which the user can provide input to the electronic device. Other types of devices may also be used to provide interaction with the user; for example, the feedback provided to the user may be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user may be received in any form (including acoustic input, voice input, or tactile input).

[0122] The systems and techniques described herein may be implemented in a computing system that includes backend components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes frontend components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such backend components, middleware components, or frontend components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), a blockchain network, and the Internet.

[0123] A computing system may include a client and a server. The client and the server are generally remote from each other and usually interact through a communication network. The client and server relationship is generated by computer programs running on the corresponding computers and having a client-server relationship with each other. The server may be a cloud server, also known as a cloud computing server or cloud host, which is a host product in the cloud computing service system to solve the defects of difficult management and weak business scalability in traditional physical hosts and VPS services.

[0124] Embodiment 7

[0125] An embodiment of the present invention also provides a computer program product, including a computer program, which, when executed by a processor, implements a cloud host security control method based on a portable physical root as provided in any embodiment of the present application.

[0126] In the process of implementation, the computer program product can be written in one or more programming languages ​​or a combination thereof to perform the computer program code of the present invention, including object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as an independent software package, partially on the user's computer and partially on a remote computer, or completely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, using an Internet service provider to connect through the Internet).

[0127] It should be understood that the various forms of processes shown above can be used to reorder, add or delete steps. For example, the steps described in the present invention can be executed in parallel, sequentially or in different orders, as long as the desired results of the technical solution of the present invention can be achieved, and this document does not limit this.

[0128] The above specific implementations do not constitute a limitation on the protection scope of the present invention. It should be understood by those skilled in the art that various modifications, combinations, sub-combinations and substitutions can be made according to design requirements and other factors. Any modification, equivalent substitution and improvement made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A portable physical root, characterized in that: The portable physical root includes a cryptographic security chip, a system on chip, and an Ethernet interface; wherein, The cryptographic security chip is used to provide public and private key generation, data encryption and digital signature functions; The system on chip is used to provide a software operating system for the portable physical root to complete the interactive authentication between the portable physical root and the cloud host; The Ethernet interface is used to connect the portable physical root to the network and communicate with the trusted root of the cloud host.

2. The portable physical root according to claim 1, characterized in that: The portable physical root also includes a closed shell, which encloses the cryptographic security chip and the system on chip inside the portable physical root.

3. The portable physical root according to claim 1, characterized in that: The portable physical root is an independently operated card-type device, which is connected to a preset network through an Ethernet interface and forms a union with the cloud host trusted root; wherein the union is used to complete the interactive authentication between the portable physical root and the cloud host trusted root.

4. A cloud host security control method based on a portable physical root, characterized in that: The method is implemented by using a portable entity root, and the method includes: During the cloud host startup phase, the portable physical root is connected to the cloud host trusted root through the Ethernet interface and interactive authentication is completed; When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root form a union, through which the external entity is authenticated and authorized to access, so as to perform security control on the cloud host.

5. The method according to claim 4, characterized in that During the cloud host startup phase, the portable physical root is connected to the cloud host trusted root through an Ethernet interface and interactive authentication is completed, including: Insert the portable physical root into a network cable through an Ethernet interface to power on and operate the portable physical root; Power on the cloud host to start the built-in trusted root of the cloud host; The cloud host trusted root is connected to the portable physical root through communication and forms a union; In the consortium, the cloud host trusted root and the portable entity root use a preset public key for interactive authentication.

6. The method according to claim 5, characterized in that The cloud host trusted root and the portable physical root use a preset public key for interactive authentication, including: The cloud host trusted root verifies the portable physical root according to the first public key pre-configured in the portable physical root to obtain a first verification result; wherein the preset public key includes the first public key, and the first public key is generated by the cloud host trusted root; The portable physical root verifies the cloud host trusted root according to the second public key pre-configured in the cloud host trusted root to obtain a first verification result; wherein the preset public key includes the second public key, and the second public key is generated by the portable physical root; According to the first verification result and the second verification result, the cloud host trusted root and the portable physical root are interactively authenticated.

7. The method according to claim 4, characterized in that In the stage of external entity accessing the cloud host, the portable entity root and the cloud host trusted root form a union, and the external entity is authenticated and authorized through the union to perform security control on the cloud host, including: When an external entity accesses the cloud host, the portable entity root and the cloud host trusted root are combined into a union, and a data signature is generated by the union; Based on the data signature, the consortium and the external entity perform joint cryptographic authentication; wherein the joint cryptographic authentication is to perform interactive authentication on the consortium and the external entity; After the joint password authentication between the consortium and the external entity is successful, the consortium authorizes access to the external entity to perform security control on the cloud host.

8. The method according to claim 7, characterized in that The joint cryptographic authentication between the consortium and the external entity based on the data signature includes: The consortium obtains a third public key pre-configured in the external entity, and uses the third public key to verify the data signature to authenticate the access of the external entity; wherein the third public key is a joint public key generated by the portable entity root and the cloud host trusted root; The external entity obtains a fourth public key pre-configured in the union to authenticate the union; wherein the fourth public key is generated by the external entity.

9. The method according to claim 7, characterized in that: The data signature is jointly generated by the portable physical root and the cloud host trusted root.

10. The method according to claim 4, characterized in that The method further comprises: If the portable entity root and the cloud host trusted root have not completed interactive authentication, or the consortium and the external entity have not completed interactive authentication, the portable entity root and the cloud host trusted root will be disconnected, and the cloud server will remain in its original operating state; wherein the cloud server includes a cloud host, a cloud host trusted root and an operating system.

Citation Information

Patent Citations

  • Trusted mobile storage method based on security chips

    CN102427449A

  • Trustable cipher module chip-based trustable network access authentication system

    CN103368906A

  • Cloud security server based on trusted computing

    CN106656915A

  • Portable secure storage

    CN107209844A

  • Secure communication method and system for host and trusted cryptographic module

    CN112966254A