Trusted platform control system and method based on redundant heterogeneous execution environment

By adopting a trusted platform control system based on a redundant heterogeneous execution environment in microgrid terminal equipment, the problem of difficult to achieve high real-time and high security requirements in the prior art is solved, and a comprehensive defense against user-level, kernel-level and physical side channel attacks is achieved.

CN120017284APending Publication Date: 2025-05-16CHINA ELECTRIC POWER RESEARCH INSTITUTE CO LTD +2
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510165893.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The prior art is difficult to meet the needs of high real-time and high security in the microgrid, especially on terminal devices such as microgrid energy gateways and energy aggregation controllers, which face the problems of heterogeneous resource limitation, high risk of attack intrusion and lack of effective defense measures.

Method used

A trusted platform control system based on a redundant heterogeneous execution environment is adopted, and a trusted computing operation environment with heterogeneous redundancy is realized by setting up at least three heterogeneous trusted operation submodules, scheduling management modules and dynamic voting modules. The system improves its resistance to user-level and kernel-level attacks through synchronous alignment and consistency discrimination, and increases its defense against physical side channel attacks through signal redundancy superposition.

Benefits of technology

Effectively resist user-level and kernel-level attacks, enhance the heterogeneous redundancy capabilities of trusted components, improve the defense capabilities of physical side channel attacks, and improve the real-time and security of microgrid terminal devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017284A_ABST
    Figure CN120017284A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network communication and information security, and discloses a trusted platform control system and method based on a redundant heterogeneous execution environment, and the system comprises at least three trusted operation sub-modules which are used for carrying out trusted measurement operation according to the state information of a trusted measurement object to obtain a trusted operation result; wherein different trusted operation sub-modules are heterogeneous; the scheduling management module is used for acquiring state information of the trusted measurement object, distributing the state information to each trusted operation sub-module, synchronously aligning trusted operation results of each trusted operation sub-module, and issuing a trusted voting result; and the dynamic voting module is used for carrying out consistency judgment on the credible operation results of the synchronously aligned credible operation sub-modules to obtain a credible voting result and transmitting the credible voting result to the scheduling management module. Aiming at the attack risk faced by the current trusted architecture, a heterogeneous redundant trusted computing operation environment is provided, and effective resistance to the existing three types of attacks aiming at the trusted architecture is realized through scheduling management and dynamic voting.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of network communication and information security, and relates to a trusted platform control system and method based on redundant heterogeneous execution environment. Background Art

[0002] With the widespread access of multiple entities such as distributed power sources, new energy storage, electric vehicles, and multiple loads, the scaled development of microgrids has led to the new form of multi-level coordination between the main power grid, the distribution grid, and the microgrid. In the new power system main power grid, the real-time requirements for interactive control are extremely high, and data flows and shares more frequently across regions and domains, which puts forward higher requirements for the high real-time and secure computing capabilities of terminal equipment such as microgrid energy gateways and energy aggregation controllers.

[0003] In the multi-level collaborative network of power main and micro-grids, the heterogeneous resources of terminal devices such as microgrid energy gateways and energy aggregation controllers are limited. The existing security protection technology based on special hardware such as cryptographic chips and isolation devices is difficult to adapt to the flexible adaptation requirements of multiple services, and the energy efficiency utilization rate of means such as security monitoring and perception analysis based on software is low, which cannot meet the high real-time requirements of main and micro-cooperative interactive control. On the other hand, the above-mentioned terminals carry many types of control-related services and are generally deployed in untrusted environments. They are easy to become a springboard for attacks and intrusions into power grid network systems. However, due to the unequal situation of attack and defense, there is a lack of effective defense measures for unknown vulnerabilities and unknown attacks, which leads to a low level of autonomous and controllable security protection of power grid information infrastructure. Based on the requirements for reliability in the host era, fault-tolerant experts first proposed the concept of trusted computing, which mainly emphasizes software reliability. As a basic attribute of the system, trustworthiness is a synonym for fault tolerance, which characterizes the ability of the system to provide users with continuous and stable services.

[0004] At present, trusted computing has developed to the 3.0 stage, which adopts a dual architecture of parallel computing and defense, performs security protection while computing, combines trusted computing technology with access control mechanisms, and establishes an immune system for the computing environment, which can timely identify and prohibit unauthorized behavior, so that attackers cannot use defects and loopholes to illegally operate the system, and kill known and unknown viruses without detection. However, a major problem facing trusted computing at present is the security protection capability of the trusted nodes themselves. Although trusted nodes are protected by security methods such as proprietary hardware and encrypted storage, there is still a lack of solutions to support the security of trusted nodes themselves from a theoretical method level. The current trusted computing architecture faces a variety of software and hardware side channel attack risks. Summary of the invention

[0005] The purpose of the present invention is to overcome the above-mentioned shortcomings of the prior art and provide a trusted platform control system and method based on redundant heterogeneous execution environment.

[0006] In order to achieve the above object, the present invention adopts the following technical solutions:

[0007] In a first aspect, the present invention provides a trusted platform control system based on a redundant heterogeneous execution environment, comprising: at least three trusted operation submodules, for performing trusted measurement operations according to the state information of a trusted measurement object to obtain a trusted operation result; wherein different trusted operation submodules are heterogeneous; a scheduling management module, for obtaining the state information of the trusted measurement object and distributing it to each trusted operation submodule, synchronously aligning the trusted operation results of each trusted operation submodule, and issuing a trusted voting result; a dynamic voting module, for performing consistency judgment on the trusted operation results of each trusted operation submodule after synchronous alignment, obtaining a trusted voting result and transmitting it to the scheduling management module.

[0008] Optionally, the trusted operation submodule is programmed based on a reconfigurable processor according to hardware configuration information.

[0009] Optionally, the trusted operation submodule, the scheduling management module and the dynamic voting module exchange data via an internal bus; each trusted operation submodule is connected to the scheduling management module via an independent interface.

[0010] Optionally, the synchronous alignment of the trusted operation results of each trusted operation sub-module includes: parsing the trusted operation results of each trusted operation sub-module to obtain the data to be compared, the timestamp and the protocol type of the trusted operation results; comparing and analyzing the protocol packet headers of different levels of the trusted operation results based on the protocol type of the trusted operation results; when the comparison and analysis of the protocol packet headers of different levels of the trusted operation results are consistent, based on a multi-level response queue, caching the data to be compared of the trusted operation results to obtain a plurality of cache queues of each trusted operation sub-module, and obtaining the timestamp of the cache queue based on the timestamp of the trusted operation results; and synchronously aligning the plurality of cache queues according to the timestamps of the cache queues.

[0011] Optionally, parsing the trusted operation results of each trusted operation submodule includes: parsing the trusted operation results of each trusted operation submodule by means of a hardware protocol parsing engine.

[0012] Optionally, when caching the data to be compared of the trusted operation results, a hybrid storage method combining hash search, linked list queue and bitmap method is adopted, and storage is performed by combining on-chip static random access memory and off-chip double data rate synchronous dynamic random access memory.

[0013] Optionally, the consistency judgment of the trusted operation results of each trusted operation sub-module after synchronization and alignment includes: using a hardware protocol parsing engine to parse the trusted operation results of each trusted operation sub-module to obtain the data type of the trusted operation result; obtaining the data type of the cache queue based on the data type of the trusted operation result, and obtaining a comparison and analysis order of the cache queue according to the data type of the cache queue, and performing consistency judgment on several cache queues of each trusted operation sub-module according to the comparison and analysis order of the cache queue.

[0014] Optionally, when performing consistency determination on a plurality of cache queues of each trusted operation submodule, a comparison method based on a hash algorithm is used to perform consistency determination on a plurality of cache queues of each trusted operation submodule.

[0015] Optionally, the scheduling management module is further used to obtain the trusted state of each trusted operation submodule according to the trusted voting result, and to clean or restore the trusted operation submodule whose trusted state is an error according to the trusted state of each trusted operation submodule.

[0016] In a second aspect, the present invention provides a trusted platform control method based on the above-mentioned trusted platform control system based on redundant heterogeneous execution environment, including: obtaining the status information of the trusted measurement object through the scheduling management module and distributing it to each trusted operation sub-module; performing trusted measurement operation according to the status information of the trusted measurement object by each trusted operation sub-module to obtain a trusted operation result; synchronizing the trusted operation results of each trusted operation sub-module through the scheduling management module; and performing consistency judgment on the trusted operation results of each trusted operation sub-module after synchronization and alignment through the dynamic voting module to obtain a trusted voting result and transmit it to the scheduling management module for distribution.

[0017] Compared with the prior art, the present invention has the following beneficial effects:

[0018] The present invention is based on a trusted platform control system with redundant heterogeneous execution environment. Aiming at the attack risks faced by the current trusted architecture, the present invention constructs multiple execution environments for implementing heterogeneity for the trusted base by setting at least three trusted operation submodules and different trusted operation submodules are heterogeneous, thereby realizing a trusted computing operation environment with heterogeneous redundancy, thereby increasing the heterogeneous redundancy capability of the trusted components. Then, the trusted operation results of each trusted operation submodule are synchronously aligned by the scheduling management module, and the dynamic voting module performs consistency judgment to obtain the trusted voting result. By increasing the voting of multiple trusted operation results, user-level and kernel-level attacks can be effectively resisted; at the same time, the complexity of signal changes during operation is increased by redundant superposition of multiple signals, which interferes with attackers who use physical devices to detect trusted operation information, resulting in the inability of attackers to associate and reversely analyze the superimposed signal changes with the operation logic in each submodule, thereby achieving effective resistance to physical side channel attacks. BRIEF DESCRIPTION OF THE DRAWINGS

[0019] Figure 1 The figure is a structural block diagram of a trusted platform control system based on a redundant heterogeneous execution environment according to an embodiment of the present invention.

[0020] Figure 2 This is a structural block diagram of a trusted platform control module according to an embodiment of the present invention.

[0021] Figure 3 It is a schematic diagram of the architecture of the scheduling management module and the dynamic voting module according to an embodiment of the present invention.

[0022] Figure 4 Schematic diagram of the principle of consistency verification of trusted computing results according to an embodiment of the present invention.

[0023] Figure 5 This is a flow chart of a trusted platform control method according to an embodiment of the present invention. DETAILED DESCRIPTION

[0024] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of the present invention.

[0025] It should be noted that the terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged where appropriate, so that the embodiments of the present invention described herein can be implemented in an order other than those illustrated or described herein. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions, for example, a process, method, system, product or device that includes a series of steps or units is not necessarily limited to those steps or units that are clearly listed, but may include other steps or units that are not clearly listed or inherent to these processes, methods, products or devices.

[0026] The present invention is further described in detail below in conjunction with the accompanying drawings:

[0027] See also Figure 1 In one embodiment of the present invention, a trusted platform control system based on a redundant heterogeneous execution environment is provided, specifically a trusted platform control system based on a redundant heterogeneous execution environment that can be applied to a station control terminal to achieve effective defense of the station control terminal against trusted attacks.

[0028] Specifically, the trusted platform control system based on redundant heterogeneous execution environment includes at least three trusted operation submodules, a scheduling management module and a dynamic voting module. Among them, the trusted operation submodule is used to perform trusted measurement operation according to the state information of the trusted measurement object to obtain the trusted operation result; among them, different trusted operation submodules are heterogeneous; the scheduling management module is used to obtain the state information of the trusted measurement object and distribute it to each trusted operation submodule, synchronously align the trusted operation results of each trusted operation submodule, and issue the trusted voting result; the dynamic voting module is used to perform consistency judgment on the trusted operation results of each trusted operation submodule after synchronous alignment, obtain the trusted voting result and transmit it to the scheduling management module.

[0029] Explanatory, in the Trusted Computing 3.0 system, the system's root of trust is the Trusted Platform Control Module (TPCM).

[0030] like Figure 2 As shown in Figure 1, TPCM is a hardware module integrated on a trusted platform, including a trusted cryptography module (TCM), trusted active control logic, and various controllers. In addition to providing cryptographic services, TPCM can also control the startup of the CPU through control logic and controllers. The controller of TPCM is linked to the low-speed bus, high-speed bus, power supply, and I / O devices of the system, and can obtain bus information for analysis and judgment before uploading the results to the trusted active control logic. Through these controllers, the trusted active control logic can also control the bus, power supply, and I / O devices. Therefore, when the system starts, TPCM runs before the CPU starts to actively verify the trustworthiness of the BIOS, which can also prevent the CPU from starting first and then skipping the trusted measurement stage. After verification, TPCM allows the CPU to start through the power supply and corresponding bus control mechanism, but TPCM can continue to monitor and measure the bus and devices. When used as the trusted root of the system, TPCM can provide hardware support for active immune trusted mechanisms.

[0031] Although the mainstream trusted execution environment (TEE) technology can protect applications from software attacks or physical attacks at the circuit board level through hardware-level isolation technology, they do not isolate at the processor microarchitecture level. From the perspective of cost and efficiency, modern processors use many sharing and optimization mechanisms at the microarchitecture level. System operation will leave some side effect information in the microarchitecture. Software side channel attackers can extract the side effect information at the microarchitecture level and infer confidential information during software runtime by constructing side channel attacks on the microarchitecture.

[0032] The current software side-channel attacks against TEE include three types of attackers with different capabilities: user-level attackers, kernel-level attackers, and physical attackers. User-level attackers do not need to have any privileged permissions and can launch attacks through malicious applications at the user level. Kernel-level attackers require system kernel-level permissions to perform privileged attacks, and physical attackers need to physically contact the target device with the attacking device.

[0033] Specifically, a user-level attacker is usually an unprivileged application that does not have any privileged permissions. It can leak the victim's confidential information into the microarchitecture by executing a piece of malicious code or executing a system call. A notable feature of user-level attackers is that the attacker only needs to run unprivileged code to destroy the memory isolation between different privilege levels and address spaces in the TEE. For example, Foreshadow attacks, ZombieLoad attacks, RIDL attacks, and DRAMA attacks are all user-level attackers. Taking the Foreshadow attack as an example, a malicious application outside the enclave uses the "mprotect" system call to clear the current bit in the enclave PTE, so that any access to the page will cause a pagefault. After the operating system captures the pagefault, it turns to execute the exception handling function. The time when the system executes the exception handling function creates an out-of-order execution window for the attacker.

[0034] Kernel-level attackers usually control the privileged software of the target device and launch attacks on trusted applications by calling privileged instructions and kernel functions provided by the operating system. The characteristic of kernel-level attackers is that they need to control the operating system kernel. Common kernel-level attackers include SgxPectre attack, LVI attack, BranchShadowing attack, BranchScope attack, Prime+Count cache side channel attack, CacheZoom attack, Controlled-Channel attack and SPM attack. Taking BranchShadowing attack as an example, the attacker is a malicious operating system. By manipulating the virtual address space of the enclave process, it can create branch shadow instructions that conflict with the branch instructions in the target enclave. During the operation of the victim enclave, the attacker frequently interrupts the execution of the target enclave to run the branch shadow code, thereby inferring the fine-grained control flow inside the victim.

[0035] Physical attackers need to use attack devices that can physically detect the hardware of the attacked device, and then use the collected information to infer the victim's confidential information. The difference between physical attackers and the above two types of attackers is that user-level attackers and kernel-level attackers are software attacks, while physical attackers need to use physical devices to detect device information. A typical physical attacker is the Membuster attack, which collects signal changes generated by DRAM during the victim's execution process, reverse-engineers the processor's addressing algorithm, and then uses cache side-channel attacks to obtain fine-grained confidential information of the enclave.

[0036] The present invention is based on a trusted platform control system of a redundant heterogeneous execution environment, and performs heterogeneous processing on the hardware implementation of the trusted active control logic and the trusted cryptographic module in the trusted execution environment, namely, a trusted operator module, so as to enhance the trusted platform control module's ability to resist trusted attacks. Heterogeneous redundancy transformation is performed on the trusted active control logic module, and the trusted operator module is realized by introducing a multi-channel differentiated hardware circuit, and the input originally transmitted to the trusted active control logic module is first distributed to the multi-channel trusted operator module through the scheduling management module, and the trusted measurement operation is synchronously performed in the multi-channel trusted operator module, and the trusted operation result is synchronously aligned through the scheduling management module, and then handed over to the dynamic voting module for consistency judgment. By increasing the voting of the multi-channel trusted operation results, the two types of attacks at the user level and the kernel level can be effectively resisted; the multi-channel trusted operator module is realized by differentiated hardware circuits and logic gates, and the signal change complexity of the overall operation process of the trusted platform control system is increased by the redundant superposition of multi-channel signals, which causes interference to the attacker who uses physical devices to detect the trusted operation information, so that the attacker cannot associate and reversely analyze the superimposed signal changes with the operation logic in each trusted operator module, thereby realizing effective resistance to physical side channel attacks.

[0037] Explanatory, the trusted operation results of each trusted operation submodule after synchronization and alignment are subjected to consistency judgment to obtain a trusted voting result, and the majority of the trusted operation results of each trusted operation submodule after synchronization and alignment can be used as the trusted voting result.

[0038] In a possible implementation, the trusted operation submodule is obtained by programming based on a reconfigurable processor according to hardware configuration information.

[0039] Explanatory, reconfigurable processor is a highly flexible computing chip, which is unique in that it can dynamically adjust its computing structure according to different computing tasks. This processor is not only highly flexible and can quickly adapt to changes in various algorithms and application requirements, but also achieves a perfect combination of high performance and low power consumption through dynamic reconstruction technology. By utilizing the software flexible orchestration feature of the reconfigurable processor, multiple heterogeneous trusted computing submodules can be constructed. The heterogeneity here refers to the differences between these submodules at the hardware level, which is not only reflected in the specific functions they perform, but also in their architectural design and interface specifications.

[0040] In a possible implementation manner, the trusted operation submodule, the scheduling management module and the dynamic voting module exchange data via an internal bus.

[0041] Explanatory, as an efficient and flexible communication method, the internal bus can achieve fast and reliable data transmission between modules. It reduces the complexity of direct connection between modules and improves the scalability and maintainability of the system. At the same time, the standardized interface of the internal bus enables different modules to be easily connected, promoting the versatility and interchangeability of modules. In addition, data interaction through the internal bus also helps to achieve physical and logical isolation between modules, further enhancing the security and stability of the system.

[0042] Optionally, each trusted operation submodule is connected to the scheduling management module via an independent interface.

[0043] Explanatory, the scheduling management module is in a connecting position in the heterogeneous redundancy transformation. Figure 3 As shown, the scheduling management module has a multi-channel uplink interface and a single-channel downlink interface. The uplink interface is connected to the trusted operation submodule to realize the data distribution function of the system input from the scheduling management module to the trusted operation submodule; the downlink interface is the interactive interface between the trusted module and the CPU external device and the network, which can realize the issuance of instructions corresponding to the trusted voting results. The uplink interface and the downlink interface have multiple physical implementations such as PCIe (Peripheral Component Interconnect Express), XGE (10Gigabit Ethernet), GE (Gigabit Ethernet) and UART (Universal Asynchronous Receiver / Transmitter). The rich and diverse communication protocol implementations bring convenience to the diversified system adaptation. Each trusted operation submodule is connected to the scheduling management module through an independent interface to realize the physical isolation of each trusted operation submodule.

[0044] Optionally, the scheduling management module and the dynamic voting module can also be constructed in the reconfigurable processor.

[0045] In one possible implementation, see Figure 4 The synchronous alignment of the trusted operation results of each trusted operation submodule includes: parsing the trusted operation results of each trusted operation submodule to obtain the data to be compared, the timestamp and the protocol type of the trusted operation results; comparing and analyzing the protocol packet headers of different levels of the trusted operation results based on the protocol type of the trusted operation results; when the comparison and analysis of the protocol packet headers of different levels of the trusted operation results are consistent, based on the multi-level response queue method, caching the data to be compared of the trusted operation results to obtain a plurality of cache queues of each trusted operation submodule, and obtaining the timestamp of the cache queue based on the timestamp of the trusted operation results; and synchronously aligning the plurality of cache queues according to the timestamps of the cache queues.

[0046] Explanatory, the main function of the scheduling management module and the dynamic voting module is to perform consistency checks on the outputs of the heterogeneous and redundant trusted operation submodules, i.e., the trusted operation results, so as to reduce the probability of the trusted platform outputting erroneous instructions under malicious attacks, improve the security level of the trusted platform, and enable the trusted platform to have the ability to resist unknown vulnerabilities and threats. However, due to the heterogeneous design between different trusted operation submodules, it is impossible to implement consistency checks by directly comparing the output interfaces of the trusted operation submodules cycle by cycle.

[0047] Therefore, the information of CPU and external modules can be checked from different levels such as data message and response sequence to prevent attacks and errors from being transmitted to the trusted operation submodule, and physical isolation and other means are used between each trusted operation submodule to prevent network attack behaviors from interfering with other normal execution bodies. In addition, in order to realize the consistency check of multiple heterogeneous trusted operation submodules by dynamic voting, it is necessary to consider the differences in pipeline, external memory access, branch prediction and protocol processing of each trusted operation submodule. For the difference of response messages caused by the upper layer communication protocol of the heterogeneous trusted operation submodule itself, the response message is first parsed to determine its protocol type, and then the protocol packet headers of different levels are compared and analyzed based on the protocol type. In addition, the delay of the overall trust measurement needs to be considered. Therefore, it is proposed to unload the hardware parsing of the downlink data of the heterogeneous trusted operation submodule, and cache the downlink data based on queue storage and other methods. At the same time, the priority of the uplink data is determined according to the real-time nature of the response message, so as to meet the heterogeneous redundant trust measurement of deterministic delay.

[0048] In a possible implementation, parsing the trusted computing results of each trusted computing submodule includes: parsing the trusted computing results of each trusted computing submodule by using a hardware protocol parsing engine.

[0049] Explanatory, in view of the problems of complex data message parsing process, large storage requirements, frequent task switching and high network processing delay in the traditional software communication protocol stack, the comparison of the response messages, i.e., the trusted operation results, issued by multiple heterogeneous trusted operation submodules in the scheduling management module is not a simple byte-by-byte comparison of data. The response messages sent by the heterogeneous trusted operation submodules sometimes contain detailed timestamps, sequence numbers, CRC checksums and other information. According to different protocol requirements, the response messages sent by these heterogeneous trusted operation submodules will also produce local differences. Therefore, before the comparison, the response messages sent by the heterogeneous trusted operation submodules need to be parsed by protocol, including the second-layer MAC header, the third-layer IP header, the fourth-layer TCP / UDP header and the upper-layer protocol header, in order to quickly strip out the effective influencing data, i.e., the data to be compared, and make subsequent comparison judgments.

[0050] However, traditional protocol parsing is mostly based on the communication protocol stack software implementation on the operating system. Software protocol parsing has the defects of complicated protocol layer processing, frequent copying of message data in memory, high memory occupancy rate and extended network protocol processing. Therefore, in this embodiment, a hardware protocol parsing engine is used to implement the communication protocol parsing of the data sent down by the heterogeneous trusted operation submodule and the encoding and distribution process of the uplink data.

[0051] In a possible implementation, when caching the data to be compared of the trusted operation results, a hybrid storage method combining hash search, linked list queue and bitmap method is adopted, and storage is performed by combining on-chip static random access memory (SRAM) and off-chip double data rate synchronous dynamic random access memory (DDR).

[0052] Explanatory, in order to solve the problems of disordered response messages and inconsistent timing caused by differences in performance and pipeline of heterogeneous trusted operation sub-modules, a multi-level response queue is used to cache the sent messages first, and a hybrid storage method of the response queue is designed using hash search, linked list queue and bitmap methods. The queue cache management of the response messages is completed in combination with the on-chip SRAM of the scheduling and distribution module and the off-chip DDR.

[0053] In one possible implementation, the consistency judgment of the trusted operation results of each trusted operation sub-module after synchronization and alignment includes: using a hardware protocol parsing engine to parse the trusted operation results of each trusted operation sub-module to obtain the data type of the trusted operation result; obtaining the data type of the cache queue based on the data type of the trusted operation result, and obtaining a comparison and analysis order of the cache queue according to the data type of the cache queue, and performing consistency judgment of several cache queues of each trusted operation sub-module according to the comparison and analysis order of the cache queue.

[0054] Explanatory, in order to address the real-time requirements of consistency judgment in dynamic voting, based on the data type of the response message after decoding by the hardware parsing engine, the cache queue is scheduled and managed according to its priority, timestamp, and on-chip and off-chip queue space occupancy information, so that all heterogeneous trusted operation submodules can obtain scheduling decisions within their latency requirements and meet the real-time requirements of the system. In addition, in the face of response messages from highly concurrent heterogeneous trusted operation submodules, response message scheduling can also be quickly implemented based on methods such as pipeline operations.

[0055] In a possible implementation, when performing consistency determination on a plurality of cache queues of each trusted operation submodule, a comparison method based on a hash algorithm is used to perform consistency determination on a plurality of cache queues of each trusted operation submodule.

[0056] Explanatory, the comparison method based on hash algorithm is used to determine the consistency of several cache queues of each trusted operation submodule. First, the hash function is applied to the data in the cache queue of each trusted operation submodule to generate a unique hash value; the hash function is one-way and anti-collision, which can ensure that different data generates different hash values. Then, these hash values ​​are compared one by one. If all hash values ​​are equal, it means that the data content in each cache queue is consistent; if there is a difference in the hash value, it means that the data in at least one cache queue is different from that in other queues, and further verification is required to ensure data consistency. The comparison method based on hash algorithm can efficiently and accurately determine whether the data in each cache queue is consistent. By generating a unique hash value for rapid comparison, it not only simplifies the judgment process, but also improves the accuracy and reliability of the judgment, providing a strong guarantee for the data consistency and stability of the system.

[0057] In a possible implementation, the scheduling management module is further used to obtain the trusted state of each trusted operation submodule according to the trusted voting result, and to clean or restore the trusted operation submodule with an erroneous trusted state according to the trusted state of each trusted operation submodule.

[0058] Explanatory, once an error is detected in the trusted state of a trusted operator module, the scheduling management module can respond quickly, clean or restore the module to ensure that its trusted state is restored. This function effectively improves the reliability and stability of the system, and ensures the efficient operation and data consistency of the entire system by timely correcting and restoring the erroneous trusted operator module. Exemplarily, taking the application of three trusted operator modules as an example, during the test, two of the three heterogeneous trusted operator modules are selected as the sub-channel executor B and the sub-channel executor C, and their registers are modified to the wrong value (simulating the attack), and the read register value is passed to the dynamic voting module via the internal bus. Since the inconsistency triggers cleaning, the test is whether the attacked trusted operator module can be reset to the recovery state within the specified time limit.

[0059] In a possible implementation, to address the problem that a single fixed voting strategy cannot dynamically respond to changes in the application environment, the system consistency detection algorithm is dynamically updated and adjusted based on the built-in distribution strategy processor of the scheduling management module to achieve dynamic adaptation of dynamic voting to the external environment.

[0060] Explanatory, the dynamic update and adjustment of the consistency detection algorithm includes two types of adjustments: 1. Consistency voting rule adjustment, including strong consistency voting (requiring that the outputs of the three trusted operation submodules must be consistent, which is suitable for scenarios that meet strong security requirements in weak trust environments) and large number voting (requiring that the outputs of two of the three trusted operation submodules be consistent, which is suitable for security protection scenarios with high business continuity requirements); 2. Adjustment of the number of inconsistent votes threshold. In actual use, due to changes in business logic, environmental electromagnetic interference, etc., a single vote may be inconsistent (false alarm). Usually, a threshold for inconsistent votes is set (for example, 10 times). Only when the threshold is reached will the cleaning of heterogeneous modules be triggered. During operation, adjustments are made according to the security requirements of the scenario and the historical voting status of the module. Specifically, as follows: Assume that the initial setting of the number of inconsistent votes threshold is 10 times, the number of inconsistent votes generated by each trusted operation submodule is recorded as Nei, i = 1, 2, 3, each voting cycle is Tn, and the number of inconsistent votes threshold is N = 10. When N = Tn (one voting cycle is completed), Nei is recorded as Nei. ij ,in, i represents the corresponding trusted operator module number, and j represents the voting cycle. The conditions for triggering cleaning are: 1) in a Tn number of times, Nei = n, and the trusted operator module i is cleaned; 2) when , the trusted operator module i is cleaned. For example, in two voting cycles, the number of vote inconsistencies of the trusted operator module 1 is 6 and 4 respectively, and the trusted operator module 1 will be cleaned. When a trusted operator module is cleaned, the threshold of the number of vote inconsistencies is adjusted to 1, and is adjusted cumulatively according to the number of subsequent consistent votes (if there are 9 consecutive consistent votes, the threshold of the number of vote inconsistencies is accumulated to 10) until the initially set threshold of the number of vote inconsistencies is reached. If the trusted operator module is cleaned in the middle, the threshold is adjusted to 1 again.

[0061] See also Figure 5 In another embodiment of the present invention, a trusted platform control method is provided. The trusted platform control method can be implemented based on the above-mentioned trusted platform control system based on redundant heterogeneous execution environment. Specifically, the trusted platform control method includes the following steps:

[0062] S1: Obtain the status information of the trusted measurement object through the scheduling management module and distribute it to each trusted operation sub-module.

[0063] S2: Each trusted operation submodule performs a trusted measurement operation according to the state information of the trusted measurement object to obtain a trusted operation result.

[0064] S3: Synchronously align the trusted computing results of each trusted computing submodule through the scheduling management module.

[0065] S4: The dynamic voting module performs consistency judgment on the trusted operation results of each trusted operation submodule after synchronization and alignment, obtains the trusted voting result and transmits it to the scheduling management module for distribution.

[0066] The trusted platform control method of the present invention can effectively resist the two types of attacks, user-level and kernel-level, by acquiring and voting redundant trusted operation results in view of the attack risks faced by the current trusted architecture. At the same time, by superimposing redundant trusted operation results, the complexity of signal changes in the overall operation process is increased, which interferes with attackers who use physical devices to detect trusted operation information, making it impossible for attackers to associate and reversely analyze the superimposed signal changes with the operation logic in each trusted operation submodule, thereby achieving effective resistance to physical side channel attacks. Finally, comprehensive defense against user-level, kernel-level and physical attacks is achieved.

[0067] Those skilled in the art will appreciate that embodiments of the present invention may be provided as methods, systems, or computer program products. Therefore, the present invention may take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware. Moreover, the present invention may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0068] The present invention is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram, as well as the combination of processes and / or blocks in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0069] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0070] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process in the computer or other programmable device. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0071] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, ordinary technicians in the relevant field should understand that the specific implementation methods of the present invention can still be modified or replaced by equivalents. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the scope of protection of the claims of the present invention.

Claims

1. A trusted platform control system based on redundant heterogeneous execution environment, characterized in that: include: At least three trusted operation submodules, used to perform trusted measurement operations according to the state information of the trusted measurement object to obtain trusted operation results; wherein different trusted operation submodules are heterogeneous; The scheduling management module is used to obtain the status information of the trusted measurement object and distribute it to each trusted operation submodule, synchronize the trusted operation results of each trusted operation submodule, and issue the trusted voting results; The dynamic voting module is used to perform consistency judgment on the trusted operation results of each trusted operation sub-module after synchronization and alignment, obtain the trusted voting results and transmit them to the scheduling management module.

2. The trusted platform control system based on redundant heterogeneous execution environment according to claim 1, characterized in that: The trusted operation submodule is programmed based on the reconfigurable processor according to hardware configuration information.

3. The trusted platform control system based on redundant heterogeneous execution environment according to claim 1, characterized in that: The trusted operation submodule, the scheduling management module and the dynamic voting module exchange data via an internal bus; each trusted operation submodule is connected to the scheduling management module via an independent interface.

4. The trusted platform control system based on redundant heterogeneous execution environment according to claim 1, characterized in that: The synchronous alignment of the trusted operation results of each trusted operation submodule includes: Parse the trusted operation results of each trusted operation submodule to obtain the data to be compared, timestamp and protocol type of the trusted operation results; Based on the protocol type of the trusted operation result, the protocol packet headers of different levels of the trusted operation result are compared and analyzed. When the comparison and analysis of the protocol packet headers of different levels of the trusted operation result are consistent, based on the multi-level response queue method, the to-be-compared data of the trusted operation result is cached to obtain several cache queues of each trusted operation submodule, and the timestamp of the cache queue is obtained based on the timestamp of the trusted operation result; Synchronize and align several cache queues according to their timestamps.

5. The trusted platform control system based on redundant heterogeneous execution environment according to claim 4, characterized in that: The analysis of the trusted operation results of each trusted operation submodule includes: The hardware protocol parsing engine is used to parse the trusted operation results of each trusted operation submodule.

6. The trusted platform control system based on redundant heterogeneous execution environment according to claim 4, characterized in that: When caching the data to be compared of the trusted operation results, a hybrid storage method combining hash search, linked list queue and bitmap method is adopted, and storage is performed in a combination of on-chip static random access memory and off-chip double data rate synchronous dynamic random access memory.

7. The trusted platform control system based on redundant heterogeneous execution environment according to claim 4, characterized in that: The consistency determination of the trusted operation results of each trusted operation submodule after synchronization and alignment includes: The hardware protocol parsing engine is used to parse the trusted operation results of each trusted operation submodule to obtain the data type of the trusted operation result; The data type of the cache queue is obtained based on the data type of the trusted operation result, and the comparison and analysis order of the cache queue is obtained according to the data type of the cache queue, and the consistency of several cache queues of each trusted operation submodule is judged according to the comparison and analysis order of the cache queue.

8. The trusted platform control system based on redundant heterogeneous execution environment according to claim 7, characterized in that: When performing the consistency determination of the plurality of cache queues of each trusted operation submodule, a comparison method based on a hash algorithm is used to perform the consistency determination of the plurality of cache queues of each trusted operation submodule.

9. The trusted platform control system based on redundant heterogeneous execution environment according to claim 1, characterized in that: The scheduling management module is further used to obtain the trusted state of each trusted operation submodule according to the trusted voting result, and to clean or restore the trusted operation submodule whose trusted state is an error according to the trusted state of each trusted operation submodule.

10. A trusted platform control method based on the trusted platform control system based on redundant heterogeneous execution environment according to any one of claims 1 to 9, characterized in that: include: Obtain the status information of the trusted measurement object through the scheduling management module and distribute it to each trusted operation submodule; Through each trusted operation submodule, a trusted measurement operation is performed according to the state information of the trusted measurement object to obtain a trusted operation result; Synchronize and align the trusted computing results of each trusted computing submodule through the scheduling management module; The dynamic voting module is used to determine the consistency of the trusted operation results of each trusted operation submodule after synchronization and alignment, and the trusted voting results are obtained and transmitted to the scheduling management module for distribution.

Citation Information

Cited By

  • Self-adaptive memory protection method and device for dynamically adjusting triple modular redundancy voting frequency

    CN121455701A