Computing equipment, security service calling method, fTPM starting method and related equipment

By introducing a trusted execution environment into the computing device, the fTPM manager that manages the target TEE instances is solved, and the existing fTPM is poor security is achieved, achieving higher security and a smaller attack surface.

CN120020779APending Publication Date: 2025-05-20HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311550931.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-11-17
Publication Date
2025-05-20

Smart Images

  • Figure CN120020779A_ABST
    Figure CN120020779A_ABST
Patent Text Reader

Abstract

The invention provides a computing device, a security service calling method, a method for starting an fTPM (Secure Trusted Platform Module) and a related device. Wherein the computing device comprises a processor, the processor comprises a trusted execution environment, and the processor comprises a trusted execution environment and an untrusted execution environment. When the computing device runs, the fTPM manager and the target TEE instance run in the trusted execution environment. Wherein the fTPM manager is used for managing a target TEE instance, and the target TEE instance is used for realizing the function of the fTPM and providing security service for a program running in the untrusted execution environment. In the implementation mode, the fTPM is implemented based on the target TEE instance. And the target TEE instance is managed by the fTPM manager. The fTPM manager may only be used to manage the target TEE instance. In this way, since only the target TEE instance needs to be managed, the volume of the fTPM manager may be small. Therefore, the TEE instance of the fTPM is realized through lightweight application program management, the trusted base of the fTPM is reduced, the attack surface of the fTPM is reduced, and the security of the fTPM is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data processing, and in particular, to a computing device, a method for invoking a security service, a method for starting fTPM, and related devices. Background Art

[0002] A Trusted Platform Module (TPM) is a standard security cryptographic processor defined by the Trusted Computing Group (TCG). It provides security functions for computing devices based on cryptographic keys and is the trusted root of computing devices. The trusted root refers to highly reliable hardware, firmware, and software components that perform key security functions in computing devices.

[0003] In some computing devices, the TPM can be implemented by hardware. For example, a dedicated microcontroller compliant with the TPM standard can be used to implement the TPM. The above dedicated microcontroller compliant with the TPM standard can be referred to as a TPM chip. A TPM chip is a small chip system containing cryptographic operation components and storage components. Alternatively, in some computing devices, the TPM can be implemented by firmware. The TPM implemented by firmware can be referred to as a firmware TPM (fTPM).

[0004] However, the current fTPM has the problem of poor security. Summary of the Invention

[0005] In view of this, embodiments of the present application provide a computing device, a method for invoking a security service, a method for starting fTPM, and related devices, which are used to optimize the implementation manner of fTPM. The present application also provides corresponding apparatuses, a computing device cluster, a computer-readable storage medium, and a computer program product.

[0006] In a first aspect, an embodiment of the present application provides a computing device, which includes a processor. The processor includes a trusted execution environment and an untrusted execution environment. When the computing device is running, an fTPM manager and a target TEE instance are running in the trusted execution environment. Among them, the fTPM manager is used to manage the target TEE instance, and the target TEE instance is used to implement the function of fTPM and provide security services for programs running in the untrusted execution environment. In the above implementation, fTPM is implemented based on the target TEE instance. And the target TEE instance is managed by the fTPM manager. The fTPM manager can be only used to manage the target TEE instance. In this way, since only the target TEE instance needs to be managed, the size of the fTPM manager can be relatively small. Thus, by implementing the TEE instance of fTPM through lightweight application management, the trusted base of fTPM is reduced, the attack surface of fTPM is decreased, and the security of fTPM is improved. That is to say, if there are multiple TEE instances running in the trusted execution environment, the fTPM manager can be only used to manage the target TEE instance. In this way, since the fTPM manager can be only used to manage the only TEE instance, the function of the fTPM manager is less, the structure is relatively simple, and the possibility of being attacked is also smaller. Thus, the trusted base of fTPM (i.e., the target TEE instance) is reduced, the attack surface is decreased, and the security of the computing device is improved.

[0007] In some possible implementation manners, an untrusted domain operating system (OS) is running in the untrusted execution environment. The untrusted domain OS can run multiple programs in the untrusted execution environment, and the multiple programs can include a first untrusted program. The above security services can include a measurement reporting service. When the first untrusted program is running in the trusted domain OS, the untrusted domain OS can obtain a measurement value of the first untrusted program, and this measurement value can be referred to as a first measurement value. The untrusted domain OS can send the first measurement value to the fTPM manager. The fTPM manager can obtain the first measurement value sent by the untrusted domain OS and send the first measurement value to the target TEE instance, so that the target TEE instance can perform a security measurement on the first untrusted program according to the first measurement value to obtain a first measurement result.

[0008] In some possible implementation manners, the target TEE instance can also provide security services for the untrusted domain OS. Specifically, before the untrusted domain OS runs, the fTPM manager can obtain the measurement value of the untrusted domain OS and send the measurement value of the untrusted domain OS to the target TEE instance, so that the target TEE instance can perform a security measurement on the untrusted domain OS according to the measurement value of the untrusted domain OS to obtain a second measurement result. The above measurement value of the untrusted domain OS can be referred to as a second measurement value.

[0009] In some possible implementation manners, the target TEE instance can also be used to provide security services for the bootloader. The bootloader is used to start the untrusted domain OS, and the second measurement value can be sent by the bootloader to the fTPM manager. Specifically, before the bootloader runs, the fTPM manager can obtain the measurement value of the bootloader and send the measurement value of the bootloader to the target TEE instance, so that the target TEE instance performs a security measurement on the bootloader according to the measurement value of the bootloader to obtain a third measurement result. The measurement value of the bootloader can be referred to as the third measurement value.

[0010] In some possible implementation manners, the fTPM manager can be used to provide information interaction services and management services for the target TEE instance. Specifically, the fTPM manager can include a communication unit and a management unit. The communication unit can be used to communicate with programs in the untrusted execution environment. The management unit can be used to implement any one or more of initialization, startup, shutdown, and destruction of the target TEE instance.

[0011] In some possible implementation manners, the fTPM manager can further include an fTPM management application programming interface (API). The fTPM management API can be used to implement information interaction between the fTPM manager and the target TEE instance.

[0012] In some possible implementation manners, the mirror files of the fTPM manager and the target TEE instance can be pre-stored in a storage device and loaded into the memory after the computing device is started. Specifically, the computing device can include a memory, a storage module, and a startup firmware. The memory can include a trusted domain memory and an untrusted domain memory. Before the computing device is started, the mirror files of the fTPM manager and the target TEE instance can be stored in the memory. When the computing device is started, the startup firmware can load the mirror files of the fTPM manager and the target TEE instance from the storage module into the trusted domain memory, so that the trusted execution environment of the processor can read the instructions of the fTPM manager and the instructions of the target TEE instance from the trusted domain memory.

[0013] In some possible implementation manners, the target TEE instance can specifically be started by the fTPM manager. Specifically, after the startup firmware loads the mirror files of the fTPM manager and the target TEE instance into the memory, the fTPM manager is first started. Then, the fTPM manager can start the target TEE instance according to the mirror file of the target TEE instance loaded into the memory.

[0014] Second aspect, this application provides a security service invocation method. The method is applied to an fTPM manager, and the fTPM manager includes the function of managing fTPM. The method includes:

[0015] Obtain a security service invocation request sent by the untrusted domain OS;

[0016] Send a security service invocation task to the target TEE instance, where the target TEE instance is used to implement the function of fTPM, and the management device is the management program of the target TEE instance;

[0017] Receive the security service processing result of the security service invocation task sent by the target TEE instance;

[0018] Send the security service processing result to the untrusted domain OS.

[0019] In some possible implementation manners, the security service invocation request is used to request to invoke the measurement reporting service;

[0020] Obtaining the security service invocation request sent by the untrusted domain operating system OS includes:

[0021] Obtain the first measurement value sent by the untrusted domain OS, where the first measurement value is the measurement value of the first untrusted program, and the first untrusted program is an application program running in the untrusted execution environment;

[0022] Sending a security service invocation task to the target trusted execution environment TEE instance includes:

[0023] Send the first measurement value to the target trusted execution environment TEE instance, where the target TEE instance is used to implement the function of fTPM, and the management device is the management program of the target TEE instance;

[0024] Receiving the security service processing result sent by the target TEE instance includes:

[0025] Receive the first measurement result for the first measurement value returned by the target TEE instance;

[0026] Sending the security service processing result to the untrusted domain OS includes:

[0027] Send the first measurement result to the untrusted domain OS.

[0028] In some possible implementation manners, before obtaining the first measurement value, the method further includes:

[0029] In response to the mirror text reaching the target TEE instance being loaded into the trusted domain memory, start the target TEE instance through the mirror file.

[0030] In some possible implementation manners, the mirror file of the target TEE instance is loaded into the trusted domain memory by the startup firmware.

[0031] In some possible implementations, the mirror file of the management device is loaded into the trusted domain memory by the boot firmware before the mirror file of the target TEE instance.

[0032] In some possible implementations, the mirror file of the target TEE instance is loaded into the trusted domain memory earlier than the mirror file of the untrusted domain OS is loaded into the untrusted domain memory.

[0033] Before obtaining the first measurement value, the method further includes:

[0034] Obtaining a second measurement value, where the second measurement value is the measurement value of the untrusted domain OS;

[0035] Sending the second measurement value to the target TEE instance;

[0036] Receiving a second measurement result for the second measurement value returned by the target TEE instance.

[0037] In some possible implementations, the mirror file of the target TEE instance is loaded into the trusted domain memory earlier than the mirror file of the bootloader is loaded into the untrusted domain memory, and the bootloader is used to load the mirror file of the untrusted domain OS into the untrusted domain memory.

[0038] Before obtaining the second measurement value, the method further includes:

[0039] Obtaining a third measurement value, where the third measurement value is the measurement value of the bootloader;

[0040] Sending the third measurement value to the target TEE instance;

[0041] Receiving a third measurement result for the third measurement value returned by the target TEE instance.

[0042] In some possible implementations, the privilege level of the target TEE instance is lower than the privilege level of the fTPM manager.

[0043] In some possible implementations, the target TEE instance and the management device run on a processor. The target TEE instance corresponds to the first secure partition (Secure Partition, SP) of the processor, and the management device corresponds to the secure partition manager (SP Manager, SPM) of the first secure partition.

[0044] In a third aspect, the present application provides a method for starting fTPM. The method includes:

[0045] The boot firmware loads the fTPM manager into the trusted domain memory;

[0046] The startup firmware loads the target Trusted Execution Environment (TEE) instance into the trusted domain memory, and the target TEE instance is used to implement fTPM.

[0047] The fTPM manager starts the target TEE instance.

[0048] In some possible implementation manners, after loading the target TEE instance into the trusted domain memory, the method further includes:

[0049] The startup firmware performs digital signature verification on the target TEE instance.

[0050] In a fourth aspect, the present application provides a security service call device. The device is applied to the fTPM manager, and the fTPM manager includes the function of managing fTPM. The device includes: an acquisition module, configured to acquire a security service call request sent by the untrusted domain OS; a first sending module, configured to send a security service call task to the target TEE instance, where the target TEE instance is used to implement the function of fTPM, and the management device is the management program of the target TEE instance; a receiving module, configured to receive the security service processing result of the security service call task sent by the target TEE instance; and a second sending module, configured to send the security service processing result to the untrusted domain OS.

[0051] In some possible implementation manners, the security service call request is used to request to call the measurement reporting service; the acquisition module is specifically configured to acquire a first measurement value sent by the untrusted domain OS, where the first measurement value is the measurement value of a first untrusted program, and the first untrusted program is an application program running in the untrusted execution environment; the first sending module is specifically configured to send the first measurement value to the target Trusted Execution Environment (TEE) instance, where the target TEE instance is used to implement the function of fTPM, and the management device is the management program of the target TEE instance; the receiving module is specifically configured to receive a first measurement result for the first measurement value returned by the target TEE instance; and the second sending module is specifically configured to send the first measurement result to the untrusted domain OS.

[0052] In some possible implementation manners, the device further includes a startup module, and the startup module is configured to start the target TEE instance through the image file in response to the image text of the target TEE instance being loaded into the trusted domain memory.

[0053] In some possible implementation manners, the image file of the target TEE instance is loaded into the trusted domain memory by the startup firmware.

[0054] In some possible implementation manners, the image file of the management device is loaded into the trusted domain memory by the startup firmware before the image file of the target TEE instance.

[0055] In some possible implementations, the time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the untrusted domain OS is loaded into the untrusted domain memory; the obtaining module is further configured to obtain a second measurement value, where the second measurement value is the measurement value of the untrusted domain OS; the first sending module is further configured to send the second measurement value to the target TEE instance; the receiving module is further configured to receive a second measurement result returned by the target TEE instance for the second measurement value.

[0056] In some possible implementations, the time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the bootloader is loaded into the untrusted domain memory, and the bootloader is used to load the image file of the untrusted domain OS into the untrusted domain memory; the obtaining module is further configured to obtain a third measurement value, where the third measurement value is the measurement value of the bootloader; the first sending module is further configured to send the third measurement value to the target TEE instance; the receiving module is further configured to receive a third measurement result returned by the target TEE instance for the third measurement value.

[0057] In some possible implementations, the privilege level of the target TEE instance is lower than the privilege level of the fTPM manager.

[0058] In some possible implementations, the target TEE instance and the management device run on a processor, the target TEE instance corresponds to the first SP of the processor, and the management device corresponds to the SPM of the first security partition.

[0059] In a fifth aspect, the present application provides a computing device cluster, where the computing device includes at least one computing device, and the at least one computing device includes at least one processor and at least one memory; the at least one memory is used to store instructions, and the at least one processor executes the instructions stored in the at least one memory, so that the computing device cluster executes the security service call method in the second aspect or any possible implementation manner of the second aspect, or executes the fTPM management method in the third aspect or any possible implementation manner of the third aspect. It should be noted that the memory may be integrated into the processor or may be independent of the processor. The at least one computing device may further include a bus. Wherein, the processor is connected to the memory through the bus. Wherein, the memory may include a readable memory and a random access memory.

[0060] In a sixth aspect, the present application provides a computer-readable storage medium, where instructions are stored in the computer-readable storage medium, and when the instructions are run on at least one computing device, the at least one computing device is caused to execute the security service call method in the second aspect or any possible implementation manner of the second aspect, or execute the fTPM management method in the third aspect or any possible implementation manner of the third aspect.

[0061] In a seventh aspect, the present application provides a computer program product including instructions, which when running on at least one computing device, causes the at least one computing device to execute the security service call method in the above-mentioned second aspect or any possible implementation manner of the second aspect, or execute the fTPM management method in the above-mentioned third aspect or any possible implementation manner of the third aspect.

[0062] Based on the implementation manners provided in the above aspects of the present application, further combinations can be made to provide more implementation manners. Description of the Drawings

[0063] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the drawings in the following description are only some embodiments recorded in the present application. For those of ordinary skill in the art, other drawings can also be obtained based on these drawings.

[0064] Figure 1a A schematic structural diagram of a computing device provided for an embodiment of the present application;

[0065] Figure 1b Another schematic structural diagram of a computing device provided for an embodiment of the present application;

[0066] Figure 2 A schematic flowchart of a security service call method provided for an embodiment of the present application;

[0067] Figure 3 An interaction schematic diagram of a method for running a first untrusted program provided for an embodiment of the present application;

[0068] Figure 4 A schematic scenario diagram provided for an embodiment of the present application;

[0069] Figure 5 A schematic structural diagram of an object push device provided for an embodiment of the present application;

[0070] Figure 6 A schematic structural diagram of a computing device provided for an embodiment of the present application;

[0071] Figure 7 A schematic structural diagram of a computing device cluster provided for an embodiment of the present application. Detailed Embodiments

[0072] The following will describe the solutions in the embodiments provided by the present application in conjunction with the drawings in the present application.

[0073] In the description, claims, and above-mentioned drawings of this application, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of this application.

[0074] First, some nouns related to the embodiments of this application are introduced.

[0075] TPM: TPM is the basis for a computing device to implement trusted computing. In the process of performing trusted computing, it is premised on "TPM being trusted". If the TPM is not trusted, then the trusted computing is not trusted either. Therefore, to ensure the credibility of trusted computing, the security of the TPM can be guaranteed through design. The TPM has security services such as a key storage service, a device identity task service, a measurement reporting service, and a remote attestation service. Among them, the measurement reporting service includes recording the measurement values of the applications to be measured. The measurement value can be a hash value.

[0076] fTPM: TPM implemented based on firmware.

[0077] TEE: Trusted Execution Environment (TEE). The TEE is a secure area in the processor. The TEE is an isolated execution environment. The execution environment corresponding to the TEE is an untrusted execution environment. For example, the untrusted execution environment can include a Rich Execution Environment (REE). The TEE can also be referred to as a trusted domain, and the untrusted execution environment can also be referred to as an untrusted domain.

[0078] TEE TA: TEE Trusted Application (TEE TA), which can also be simply referred to as TA, refers to an application running in the TEE.

[0079] TEE OS: TEE Operating System (TEE OS), which refers to the operating system running in the TEE. In the embodiments of this application, to distinguish the operating system running in the TEE from the operating system running outside the TEE, the operating system running outside the TEE is simply referred to as an untrusted domain operating system or untrusted domain OS1121. Among them, the above-mentioned operating system running in the untrusted domain can be, for example, a general operating system.

[0080] Boot Firmware: Boot firmware is the firmware for the application programs used to boot a computing device. After the computing device boots up, the Boot Firmware is started. The Boot Firmware can load the image file in the storage module into the memory so that the processor can run the image file in the memory. Optionally, the boot firmware can include, for example, the Basic Input Output System (BIOS).

[0081] Bootloader: A bootloader is a computer program that loads an operating system or other system programs after the computer completes the power-on self-test. The Bootloader can be used to load the OS into the untrusted domain memory. Optionally, the Bootloader can include, for example, the Unified Extensible Firmware Interface (UEFI).

[0082] TCB: Trusted Computing Base (TCB). The trusted computing base can also be referred to as the trusted foundation, which refers to the set of all security protection mechanisms for implementing the security protection of a computer system. The mechanisms can appear in the form of hardware, firmware, and software. Once a component of the trusted computer base has a program error or security risk, it will pose a threat to the security of the entire system. To improve security, the size of the trusted foundation can be reduced.

[0083] In the implementation of fTPM, fTPM can be run in the trusted domain of a computing device. Specifically, the processor system environment can be divided into a trusted domain and an untrusted domain. The fTPM running in the trusted domain can provide an fTPM interface to the untrusted domain. When the operating system and applications running in the untrusted domain need to perform trusted computing, they can communicate with the fTPM through the fTPM interface to invoke the security services provided by the fTPM.

[0084] In some implementations, fTPM can be implemented based on TEE TA. The TA used to implement fTPM can be called fTPM TA. Before the computing device boots up, the image file of fTPM TA can be stored in the storage module, for example, it can be stored in a hard disk or flash memory. After the computing device boots up, the image file of fTPM TA can be loaded into the trusted domain memory. After the image file of fTPM TA in the trusted domain memory is run, fTPM TA is in a running state and can provide security services.

[0085] Optionally, the loading of the fTPM TA image file can rely on the operating system of the trusted domain for implementation. Among them, the operating system of the trusted domain can include, for example. That is to say, after the computing device is started, the Boot Firmware can first load the TEE OS into the trusted domain memory to run the TEE OS. The TEE OS can load the fTPM TA image file into the trusted domain memory.

[0086] In the above implementation, since the fTPM TA image file is stored in the storage module of the untrusted domain, loading the fTPM TA image file requires the assistance of a program in the untrusted domain. For example, in some possible implementations, the fTPM TA can be loaded by the OS in the untrusted domain. For example, the TEE driver in the OS can load the fTPM TA image file into the trusted domain memory.

[0087] In some implementations, there may be multiple TEE TAs. Then, there may be multiple TEE TA image files stored in the storage device. Correspondingly, before loading the fTPM TA, it is possible to determine the TEE TA image file to be loaded into the trusted domain memory. Specifically, the fTPM TA can be determined through the tee-supplicant. Among them, the tee-supplicant is an application running in the untrusted domain and can be used to provide services for the TEE OS.

[0088] That is to say, after the computing device is started, the Boot Firmware can first load the TEE OS into the trusted domain memory and load the Bootloader into the untrusted domain memory. The Bootloader can load the untrusted domain OS1121 into the untrusted domain memory. After the untrusted domain OS1121 enters the running state, it can load the tee-supplicant into the untrusted domain memory. The TEE OS can load the fTPM TA image file into the trusted domain memory through the tee-supplicant and the TEE driver in the OS. Optionally, the TEE OS can also verify the signature of the fTPM TA to ensure the integrity of the fTPM TA.

[0089] After the fTPM TA image file is loaded into the memory, if the untrusted domain OS1121 subsequently needs to load data such as application programs, modules, and components into the memory, it can use the measurement reporting service of the fTPM TA to extend the measurement values of the above data into the fTPM TA, so that the fTPM TA can provide the measurement reporting service to verify the integrity of the above data.

[0090] In the above implementation, although the function of fTPM is realized through the TEE TA, there are still security risks. Specifically, there are at least the following two aspects of security risks.

[0091] Firstly, the loading of the mirror file of the fTPM TA depends on the TEE OS, and the management of the fTPM TA also depends on the TEE OS. However, the TEE OS is used to manage the TAs running in the TEE. Therefore, the TEE OS also includes data such as libraries and driver modules that have nothing to do with the fTPM TA. Therefore, the TEE OS is more vulnerable to attacks. If the TEE OS is attacked, the trustworthiness of the fTPM TA cannot be guaranteed. That is to say, the TEE OS is the trust root of the fTPM TA. However, the TEE OS is large in size and does not meet the requirement of miniaturizing the trust root.

[0092] Secondly, the loading of the mirror file of the fTPM TA also depends on the applications in the untrusted domain, such as it may depend on the Bootloader, the untrusted domain OS 1121, and the tee-supplicant. Therefore, before running the fTPM TA, it is necessary to run the Bootloader, the untrusted domain OS, and the tee-supplicant first. In this way, since the fTPM TA has not run before the Bootloader, the untrusted domain OS 1121, and the tee-supplicant run, the running of the Bootloader, the untrusted domain OS 1121, and the tee-supplicant cannot be protected by the fTPM TA. That is to say, the integrity protection scope of the fTPM may not include the Bootloader, the untrusted domain OS 1121, and the tee-supplicant. Thus, the protection scope of the fTPM TA is limited.

[0093] Based on this, the embodiments of the present application provide a computing device, a method for starting fTPM, and a method for calling a security service. Among them, the computing device includes a processor, and the processor includes a trusted execution environment and an untrusted execution environment. When the computing device runs, an fTPM manager and a target TEE instance run in the trusted execution environment. Among them, the fTPM manager is used to manage the target TEE instance, and the target TEE instance is used to implement the function of fTPM and provide security services for the programs running in the untrusted execution environment. In the above implementation, fTPM is implemented based on the target TEE instance, and the target TEE instance is managed by the fTPM manager. The fTPM manager can be only used to manage the target TEE instance. In this way, since only the target TEE instance needs to be managed, the fTPM manager can be small in size. Thus, by managing the TEE instance of fTPM through a lightweight application, the trust root of fTPM is reduced, the attack surface of fTPM is reduced, and the security of fTPM is improved.

[0094] That is to say, if there are multiple TEE instances running in the trusted execution environment, the fTPM manager can be used only to manage the target TEE instance. In this way, since the fTPM manager can be used only to manage a single TEE instance, the functions of the fTPM manager are fewer, the structure is relatively simple, and the possibility of being attacked is also smaller. Thus, the trusted base of the fTPM (i.e., the target TEE instance) is reduced, the attack surface is decreased, and the security of the computing device 100 is enhanced.

[0095] The computing device also includes a boot firmware. The method for starting the fTPM can be implemented by the boot firmware. Specifically, after the computing device starts, first, the boot firmware can load the fTPM manager into the trusted domain memory. Then, the boot firmware can load the target TEE instance into the trusted domain memory. Next, the fTPM manager can start the target TEE instance to provide security services. In this way, since the loading of the fTPM does not depend on programs running in the untrusted domain such as the untrusted domain OS 1121, the target TEE instance can be loaded before loading the untrusted domain OS 1121. In this way, the target TEE instance can also provide security services for programs running in the untrusted domain such as the untrusted domain OS 1121, improving the security of the computing device.

[0096] After the target TEE instance starts, a program running in the untrusted execution environment can call the security services provided by the target TEE instance through the fTPM manager. Specifically, the fTPM manager can obtain a security service call request sent by the untrusted domain OS 1121 and send a security service call task to the target TEE instance. Among them, the security service call request can be used to request to call the security services provided by the target TEE instance, and the security services can be targeted at application programs running in the untrusted execution environment. After obtaining the security service call task, the target TEE instance can provide security services according to the security service call task and return a security service processing result to the fTPM manager. After obtaining the security service processing result sent by the target TEE instance, the security service processing result can be sent to the untrusted domain OS 1121.

[0097] For example, in Figure 1aIn the application scenario shown, the computing device 100 includes a processor 110, a memory 120, a boot firmware 130, and a storage module 140. Among them, the processor 110 includes a trusted execution environment 111 and an untrusted execution environment 112. The trusted execution environment 111 can run an fTPM manager 1111 and a target TEE instance 1112. The untrusted execution environment 112 can run an untrusted domain OS 1121 and at least one untrusted program. The memory 120 includes a trusted domain memory and an untrusted domain memory. The trusted domain memory corresponds to the trusted execution environment 111, and the untrusted domain memory corresponds to the untrusted execution environment 112. The storage module 140 stores the image file of the target TEE instance 1112 and the image file of the fTPM manager 1111.

[0098] After the computing device 100 is started, the boot firmware 130 is started. The fTPM startup device 131 first loads the image file of the fTPM manager 1111 from the storage module 140 into the trusted domain memory. Then, the fTPM startup device 131 loads the image file of the target TEE instance 1112 from the storage module 140 into the trusted domain memory. After being loaded into the trusted domain memory, the fTPM manager 1111 enters the running state, starts the target TEE instance 1112 according to the image file of the target TEE instance 1112 in the trusted domain memory, and manages the target TEE instance 1112.

[0099] After the target TEE instance 1112 is started, it can provide security services for the untrusted domain OS 1121 and untrusted programs.

[0100] In the embodiments of the present application, the computing device 100 can be a device with data processing capabilities. For example, it can be a terminal device or a server. Optionally, the processor can be a Central Processing Unit (CPU) for implementing the data processing functions of the computing device 100.

[0101] In some possible implementation manners, the processor can be a processor based on the Advanced Reduced Instruction Set Computer Machine (ARM) architecture. Correspondingly, the above-mentioned target TEE instance 1112 can correspond to a Secure Partition (SP) in the processor 110, and the above-mentioned fTPM manager 1111 can correspond to a Secure Partition Manager (SPM) in the processor 110. Optionally, the processor can be a Central Processing Unit (CPU).

[0102] If the processor is an ARM architecture-based processor, the computing device 100 can be as Figure 1b shown. In the Figure 1b illustrated implementation, in the trusted execution environment of the processor, fTPM Manager and fTPM SP are running. fTPM Manager corresponds to the above-mentioned SPM and is used to implement the functions of the fTPM manager in the embodiments of the present application. fTPM SP is used to implement the functions of the fTPM in the embodiments of the present application and corresponds to the target instance described below. Moreover, fTPM Manager may include an untrusted domain - SP communication module, an SP lifecycle management module, and an fTPM Manager API. Among them, the untrusted domain - SP communication module is used to implement the information interaction between the fTPM and the untrusted domain, which is equivalent to the communication unit in the fTPM manager in the embodiments of the present application. The SP lifecycle management module is used to manage the lifecycle of fTPM SP, which is equivalent to the management unit in the fTPM manager in the embodiments of the present application. fTPM Manager API is used to implement the information interaction between fTPM Manager and fTPM SP.

[0103] Next, various non-limiting specific embodiments of the process of providing security services to the target TEE instance will be described in detail.

[0104] Refer to Figure 2 , which is a schematic flowchart of a method for invoking security services in the embodiments of the present application. This method can be applied to the above Figure 1a or Figure 1b illustrated application scenarios, or it can also be applied to other applicable application scenarios. Hereinafter, taking the application scenario illustrated in Figure 1a as an example for illustration.

[0105] Figure 2 The method illustrated in

[0106] specifically may include:

[0107] S201: The fTPM manager 1111 obtains a security service invocation request sent by the untrusted domain OS 1121.

[0108] Optionally, the security services provided by the target TEE instance 1112 may include a measurement reporting service. Optionally, the security service call request sent by the untrusted domain OS 1121 to the fTPM manager 1111 may include a measurement value. The measurement value may be, for example, the hash value of an application. That is, if it is necessary to measure a program running in the untrusted execution environment, the untrusted domain OS 1121 may send the measurement value corresponding to the program to the fTPM manager.

[0109] Taking the first untrusted program as an example for illustration. Herein, the first untrusted program is an application running in the untrusted execution environment, and the measurement value of the first untrusted program may be referred to as the first measurement value.

[0110] Specifically, before starting the first untrusted program, the data corresponding to the first untrusted program (such as the code of the first untrusted program) is stored in the storage module 140. After obtaining the instruction to start the first untrusted program, the untrusted domain OS 1121 may load the data corresponding to the first untrusted program into the untrusted memory. The untrusted domain OS 1121 may also obtain the measurement value of the first untrusted program and send the measurement value of the first untrusted program to the fTPM manager. In the embodiments of the present application, the measurement value of the first untrusted program may include, for example, the hash value of the first untrusted program.

[0111] Optionally, the untrusted domain OS 1121 may send a security service call request to the fTPM manager 1111 through the TEE driver. Correspondingly, the fTPM manager 1111 may receive the data sent by the TEE driver. Moreover, the fTPM manager may also send data to the TEE driver to provide security services for the programs running in the untrusted execution environment.

[0112] In some possible implementation manners, security services may also be provided for the untrusted domain OS 1121 and / or the boot program. For example, a measurement reporting service may be provided for the untrusted domain OS 1121 and / or the boot program. For the introduction of this part of the content, reference may be made to Figure 3 , which will not be elaborated here.

[0113] S202: The fTPM manager 1111 sends a security service call task to the target TEE instance 1112.

[0114] After obtaining a security service call request, the fTPM manager 1111 can generate a security service call task according to the security service call request and send the security service call task to the target TEE instance 1112. The security service call task is used to instruct the target TEE instance 1112 to provide a security service. When the target TEE instance provides multiple types of security services, the security service call request may include the type of security service called by the untrusted domain OS 1121.

[0115] Optionally, the fTPM manager 1111 may include an Application Programming Interface (API). The fTPM manager 1111 can send the security service call task to the target TEE instance 1112 through the fTPM management API.

[0116] S203: The fTPM manager 1111 receives the security service processing result of the security service call task sent by the target TEE instance 1112.

[0117] After obtaining the security service call task, the target TEE instance 1112 can provide a security service according to the security service call task. For example, if the untrusted domain OS 1121 requests to call the measurement reporting service, the target TEE instance 1112 can record the measurement value sent by the untrusted domain OS 1121. After completing the security service call task, the target TEE instance 1112 can send the security service processing result to the fTPM manager 1111.

[0118] S204: The fTPM manager 1111 sends the security service processing result to the untrusted domain OS 1121.

[0119] After obtaining the security service processing result sent by the target TEE instance 1112, the fTPM manager 1111 can send the security service processing result to the untrusted domain OS 1121 so that the untrusted domain OS 1121 can perform corresponding operations according to the security service processing result.

[0120] For example, if the security service call request is used to request to provide a measurement reporting service for the first untrusted program, then the security service processing result can be used to indicate the credibility of the first untrusted program. For example, the security service processing result can be used to indicate whether the first untrusted program passes the verification. If the first untrusted program passes the verification, the untrusted domain OS 1121 can continue to run the first untrusted program. If the first untrusted program fails to pass the verification, the untrusted domain OS 1121 can refuse to run the first untrusted program or run the first untrusted program in other ways.

[0121] The following combines Figure 1a, taking an actual application scenario as an example, introduce the process from the startup of the computing device 100 to the running of the first untrusted program.

[0122] Refer to Figure 3 , which is a schematic flowchart of a method for running the first untrusted program in an embodiment of the present application. This method can be applied to the Figure 1a application scenario shown above, or it can also be applied to other applicable application scenarios. The following takes the application scenario shown in Figure 1a as an example for illustration. And for the functions of each module, specifically refer to the relevant descriptions in the following embodiments.

[0123] Figure 3 The method shown can specifically include:

[0124] S301: The startup firmware 130 is started.

[0125] Before the computing device 100 is started, each program running on the computing device 100 can be in a closed state. The processor 110 is in a closed state and no application program is running. In order to run an application program on the computing device 100, the computing device 100 can be started first. After the computing device 100 is started, the startup firmware 130 is started.

[0126] Optionally, the computing device 100 can enter the startup state according to a startup operation. Among them, the startup operation can, for example, include obtaining a startup instruction, or can also include an operation to trigger the power-on of the computing device 100. For example, the user can turn on the computing device 100 by pressing the power-on button. Correspondingly, the above startup operation can include the operation of the user pressing the power-on button. After entering the startup state, each module or device in the computing device 100 can enter the startup state in sequence to complete the startup of the computer device 100.

[0127] S302: The startup firmware 130 loads the mirror file of the fTPM manager 1111 from the storage module 140 into the trusted domain memory.

[0128] After the startup firmware 130 is started, the startup firmware 130 can load the mirror file from the storage module 140 into the memory. In the embodiment of the present application, the startup firmware 130 can load the mirror file of the fTPM manager 1111 from the storage module 140 into the trusted domain memory.

[0129] In an embodiment of the present application, the boot firmware 130 can be used to load multiple image files into the trusted domain memory. For example, the boot firmware 130 can be used to load the runtime firmware into the trusted domain memory. For another example, the boot firmware 130 can be used to load the image file of the TEE instance into the trusted domain memory. For still another example, the boot firmware 130 can be used to load the bootloader into the untrusted domain memory. Optionally, before loading the image file of the fTPM manager 1111 into the trusted domain memory, the boot firmware 130 can first load the runtime firmware into the trusted domain memory.

[0130] After the image file is loaded into the trusted domain memory, the processor 110 can run the fTPM manager 111 in the trusted execution environment according to the image file in the trusted memory.

[0131] S303: The boot firmware 130 loads the image file of the target TEE instance 1112 from the storage module 140 into the trusted domain memory.

[0132] After loading the image file of the fTPM manager 1111 from the storage module 140 into the trusted domain memory, the boot firmware 130 can load the image file of the target TEE instance 1112 from the storage module 140 into the trusted domain memory so that the fTPM manager 1111 can start the target TEE instance 1112.

[0133] In an embodiment of the present application, there may be multiple TEE instances running in the trusted execution environment. Correspondingly, there may be image files of multiple TEE instances stored in the storage module 140. When loading the image file, the boot firmware 130 can load the image file of a specific TEE instance into the trusted domain memory. This specific TEE instance is the above-mentioned target TEE instance, which is used to implement the function of fTPM. Correspondingly, if there are multiple TEE instances running in the trusted execution environment, the fTPM manager can be only used to manage the target TEE instance. In this way, since the fTPM manager can be only used to manage a single TEE instance, the function of the fTPM manager is less, the structure is relatively simple, and the possibility of being attacked is also smaller. Thus, the security of the fTPM (i.e., the target TEE instance) of the computing device 100 is improved.

[0134] S304: The fTPM manager 1111 starts the target TEE instance 1112.

[0135] After the startup firmware 130 loads the image file of the target TEE instance 1112 from the storage device 140 into the trusted domain memory, the fTPM manager can start the target TEE instance 1112. Starting the target TEE instance 1112 means running the target TEE instance 1112 in the trusted execution environment of the processor 110 and providing security services through the target TEE instance 1112.

[0136] In the embodiment of the present application, the fTPM manager 1111 can be used to manage the target TEE instance 1112 and can also be used to implement information interaction between the target TEE instance 1112 and the programs running in the untrusted execution environment. Correspondingly, in some possible implementation manners, the fTPM manager 1111 can include a communication unit and a management unit. The communication unit is used to implement information interaction between the target TEE instance 1112 and the programs running in the untrusted execution environment. The management unit is used to manage the target TEE instance 1112. Optionally, the management unit can be used to be responsible for operations such as initialization, startup, shutdown, and destruction of the target TEE instance. Then after the image file of the target TEE instance 1112 is loaded into the trusted domain memory, the management unit can start the target TEE instance.

[0137] In some possible implementation manners, the processor can have multiple privilege levels. Different program components can run at different privilege levels. Programs running at a high privilege level can manage programs running at a low privilege level. For example, the privilege level of the OS can be higher than the privilege level of the programs running on the OS. Correspondingly, in the embodiment of the present application, in order to implement the management of the target TEE instance 1112, the priority of the fTPM manager 1111 can be higher than the priority of the target TEE instance 1112.

[0138] For example, in some implementation manners, the processor 110 can include four priority levels: PL0, PL1, PL2, and PL3. Among them, the priority of the priority level PL3 is higher than the priority of the priority level PL2, the priority of the priority level PL2 is higher than the priority of the priority level PL1, and the priority of the priority level PL1 is higher than the priority of the priority level PL0. Then the target TEE instance 1112 can run at the priority level PL0, and the fTPM manager 1111 can run at the priority level PL3. In this way, the priority of the fTPM manager 1111 is higher than the priority of the target TEE instance 1112, and the fTPM manager 1111 can manage the target TEE instance 1112.

[0139] In an embodiment of the present application, the target TEE instance 1112 is started by the fTPM manager 1111. The image files of the fTPM manager 1111 and the target TEE instance 1112 are both loaded by the startup firmware 130 from the storage device 140 into the trusted domain memory. Therefore, in order to ensure that the fTPM manager 1111 can start the target TEE instance 1112, the startup firmware 130 can first load the image file of the fTPM manager 1111. After the image file of the fTPM manager 1111 is loaded, the image file of the target TEE instance 1112 is then loaded.

[0140] After the target TEE instance 1112 is started, the target TEE instance 1112 can provide security services for programs running in the untrusted execution environment to implement the functions of the fTPM. Optionally, the target TEE instance 1112 can provide security services for application programs (such as the aforementioned first untrusted program) running in the untrusted execution environment, can also provide security services for the untrusted domain OS 1121, and can also provide security services for the boot program. Hereinafter, an example of the target TEE instance 1112 providing a measurement reporting service will be introduced.

[0141] After step S304 is completed, the target TEE instance 1112 is started, and the target TEE instance 1112 can act as the fTPM to provide a security service side for programs running in the processor. In the above process, the transfer methods of the target TEE instance 1112 and the fTPM manager 1111 in the memory and the memory can be as Figure 4 shown.

[0142] Refer to Figure 4 , Figure 4 which is a scenario schematic diagram provided by an embodiment of the present application. As Figure 4 shown, before the computing device 100 is started, the image files of the fTPM manager 1111 and the target instance 1112 can be stored in the storage module 140. After the computing device 100 is started, according to the image files, the programs of the fTPM manager 1111 and the target instance 1112 can be loaded into the trusted domain memory. During the operation of the computing device 100, the instructions of the fTPM manager 1111 and the target instance 1112 can be loaded into the processor 110 so that the processor 110 runs the instructions of the fTPM manager 1111 and the target instance 1112 to implement the functions of the fTPM manager 1111 and the target instance 1112.

[0143] S305: The startup firmware 130 loads the boot program into the untrusted domain memory.

[0144] After the startup firmware 130 is started, the startup firmware 130 can also start the bootloader of the computing device 100 so that the bootloader starts the untrusted domain OS 1121. Specifically, the startup firmware 130 can load the bootloader into the untrusted domain memory so that the bootloader runs in the untrusted execution environment of the processor 110.

[0145] In order for the target TEE instance 1112 to provide a measurement reporting service for the bootloader, in some possible implementation manners, the time when the startup firmware 130 loads the bootloader into the untrusted domain memory can be later than the time when the fTPM manager 1111 starts the target TEE instance 1112. That is to say, step S305 can run after step S304. It can be understood that, in some other possible implementation manners, if the target TEE instance 1112 does not provide a measurement reporting service for the bootloader, then step S305 can also run before step S304.

[0146] S306: The startup firmware 130 sends the measurement value of the bootloader to the target TEE instance 1112 through the fTPM manager 1111.

[0147] In order to provide a measurement reporting service for the bootloader, the target TEE instance 1112 can obtain the measurement value of the bootloader. Specifically, the startup firmware 130 can obtain the measurement value of the bootloader and then send the measurement value of the bootloader to the target TEE instance 1112 through the fTPM manager 1111. The fTPM manager 1111 can obtain the measurement value of the bootloader sent by the startup firmware 130 and send the measurement value of the bootloader to the target TEE instance 1112 through the fTPM management API so that the target TEE instance 1112 performs measurement reporting according to the measurement value of the bootloader.

[0148] S307: The bootloader loads the untrusted domain OS 1121 into the untrusted domain memory.

[0149] After the processor 110 runs the bootloader in the untrusted execution environment, the bootloader can start the untrusted domain OS 1121 so that untrusted applications run in the untrusted domain OS 1121. First, the bootloader can load the untrusted domain OS 1121 into the untrusted domain memory.

[0150] To provide a measurement reporting service for the untrusted domain OS 1121 by the target TEE instance 1112, in some possible implementation manners, the time when the startup firmware 130 loads the untrusted domain OS 1121 into the untrusted domain memory can be later than the time when the fTPM manager 1111 starts the target TEE instance 1112. That is to say, step S307 can be run after step S304. It can be understood that in some other possible implementation manners, if the target TEE instance 1112 does not provide a measurement reporting service for the bootloader and the untrusted domain OS 1121, then step S307 can also be run before step S304.

[0151] S308: The bootloader sends the measurement value of the untrusted domain OS 1121 to the target TEE instance 1112 through the fTPM manager 1111.

[0152] To provide a measurement reporting service for the untrusted domain OS 1121, the target TEE instance 1112 can obtain the measurement value of the untrusted domain OS 1121. Specifically, the bootloader can obtain the measurement value of the untrusted domain OS 1121, and then send the measurement value of the untrusted domain OS 1121 to the target TEE instance 1112 through the fTPM manager 1111. The fTPM manager 1111 can obtain the measurement value of the untrusted domain OS 1121 sent by the bootloader, and send the measurement value of the untrusted domain OS 1121 to the target TEE instance 1112 through the fTPM management API, so that the target TEE instance 1112 can perform measurement reporting according to the measurement value of the untrusted domain OS 1121.

[0153] S309: The untrusted domain OS 1121 loads the first untrusted program into the untrusted domain memory.

[0154] After the processor 110 runs the untrusted domain OS 1121 in the untrusted execution environment, one or more untrusted applications can be run based on the untrusted domain OS 1121. Before running the untrusted applications, measurement reporting can be performed through the target TEE instance 1112. For example, before running the first untrusted program, the untrusted domain OS 1121 can load the first untrusted program into the untrusted domain memory.

[0155] S310: The untrusted domain OS 1121 sends the measurement value of the first untrusted program to the target TEE instance 1112 through the fTPM manager 1111.

[0156] To provide a measurement reporting service for the first untrusted program, the target TEE instance 1112 can obtain the measurement value of the first untrusted program. Specifically, the untrusted domain OS 1121 can obtain the measurement value of the first untrusted program, and then send the measurement value of the first untrusted program to the target TEE instance 1112 through the fTPM manager 1111. The fTPM manager 1111 can obtain the measurement value of the first untrusted program sent by the untrusted domain OS 1121, and send the measurement value of the first untrusted program to the target TEE instance 1112 through the fTPM management API, so that the target TEE instance 1112 can perform measurement reporting according to the measurement value of the first untrusted program.

[0157] As can be seen from the above introduction, since the target TEE instance 1112 implementing fTPM is started by the startup firmware 130 and the fTPM manager 1111, and the startup of the startup firmware 130 and the fTPM manager 1111 does not depend on the programs running in the untrusted execution environment. Therefore, the target TEE instance 1112 can be started before the programs running in the untrusted execution environment are started. In this way, starting the target TEE instance 1112 can only provide security services for the programs running in the untrusted execution environment. Thus, the coverage of the security service is improved, and the security of the computing device 100 is enhanced.

[0158] This application also provides a security service invocation device. Among them, the security service invocation device can be applied to Figure 1a the fTPM manager in the implementation manner shown to implement the functions of the fTPM manager in the implementation manner such as Figure 2 or Figure 3 shown. Specifically, as Figure 5 shown, the security service invocation device 500 includes:

[0159] An acquisition module 510, configured to acquire a security service invocation request sent by the untrusted domain operating system OS;

[0160] A first sending module 520, configured to send a security service invocation task to a target trusted execution environment TEE instance, where the target TEE instance is used to implement the function of the fTPM, and the management device is the management program of the target TEE instance;

[0161] A receiving module 530, configured to receive the security service processing result of the security service invocation task sent by the target TEE instance;

[0162] A second sending module 540, configured to send the security service processing result to the untrusted domain OS 1121.

[0163] Among them, the above-mentioned acquisition module 510, the first sending module 520, the receiving module 530, and the second sending module 540 can all be implemented by software or by hardware. Exemplarily, next, taking the acquisition module 510 as an example, the implementation manner of the acquisition module 510 will be introduced. Similarly, the implementation manners of the first sending module 520, the receiving module 530, and the second sending module 540 can be the same as that of the acquisition module 510.

[0164] As an example of a software functional unit, the acquisition module 510 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the acquisition module 510 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers for running this code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers for running this code may be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes one data center or multiple geographically proximate data centers. Among them, generally one region may include multiple AZs.

[0165] Similarly, the multiple hosts / virtual machines / containers for running this code may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, generally one VPC is set within one region. For cross-region communication between two VPCs within the same region and between VPCs in different regions, a communication gateway needs to be set in each VPC, and the interconnection between VPCs is achieved through the communication gateway.

[0166] As an example of a hardware functional unit, the obtaining module 510 may include at least one computing device, such as a server, etc. Alternatively, the obtaining module 510 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). Among them, the above PLD may be implemented by a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.

[0167] The multiple computing devices included in the obtaining module 510 may be distributed in the same region or in different regions. The multiple computing devices included in the obtaining module 510 may be distributed in the same availability zone (AZ) or in different AZs. Similarly, the multiple computing devices included in the obtaining module 510 may be distributed in the same virtual private cloud (VPC) or in multiple VPCs. Among them, the multiple computing devices may be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0168] It should be noted that in other embodiments, the obtaining module 510 may be used to execute any step in the security service call method, the first sending module 520 may be used to execute any step in the security service call method, the receiving module 530 may be used to execute any step in the security service call method, and the second sending module 540 may be used to execute any step in the security service call method. The steps to be implemented by the obtaining module 510, the first sending module 520, the receiving module 530, and the second sending module 540 can be specified as needed. The entire function of the security service call device is realized by respectively implementing different steps in the security service call method through the obtaining module 510, the first sending module 520, the receiving module 530, and the second sending module 540.

[0169] This application also provides a computing device 100. As Figure 6 shown, the computing device 100 includes: a bus 102, a processor 104, a memory 106, and a communication interface 108. The processor 104, the memory 106, and the communication interface 108 communicate with each other through the bus 102. The computing device 100 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 100.

[0170] The bus 102 can be a peripheral component interconnect (PCI) bus, an extended industry standard architecture (EISA) bus, or the like. The bus can be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 only one line is used in Figure 6 , but it does not mean that there is only one bus or one type of bus. The bus 102 can include a path for transmitting information between various components of the computing device 100 (for example, the memory 106, the processor 104, and the communication interface 108).

[0171] The processor 104 can include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0172] The memory 106 can include volatile memory, such as random access memory (RAM). The processor 104 can also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0173] The memory 106 stores executable program code, and the processor 104 executes the executable program code to respectively implement the functions of the foregoing acquisition module 510, first sending module 520, receiving module 530, and second sending module 540, so as to implement the security service call method and the fTPM management method. That is, the memory 106 stores instructions for executing this storage method.

[0174] The communication interface 108 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 100 and other devices or communication networks.

[0175] The embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.

[0176] As Figure 7 shown, the computing device cluster includes at least one computing device 100. In the memory 106 of one or more computing devices 100 in the computing device cluster, there can be stored the same instructions for executing the security service call method and the fTPM management method.

[0177] In some possible implementation manners, in the memory 106 of one or more computing devices 100 in the computing device cluster, there can also be respectively stored partial instructions for executing the security service call method and the fTPM management method. In other words, the combination of one or more computing devices 100 can jointly execute the instructions for executing the security service call method and the fTPM management method.

[0178] It should be noted that the memories 106 in different computing devices 100 in the computing device cluster can store different instructions, respectively for executing partial functions of the object storage service layer. That is, the instructions stored in the memories 106 of different computing devices 100 can implement the functions of one or more of the acquisition module 510, the first sending module 520, the receiving module 530, and the second sending module 540.

[0179] The embodiments of the present application also provide another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similarly referred to Figure 7 the connection manner of the computing device cluster. The difference is that in the memory 106 of one or more computing devices 100 in the computing device cluster, there can be stored the same instructions for executing the security service call method and the fTPM management method.

[0180] In some possible implementation manners, in the memory of one or more computing devices 100 in the computing device cluster, there can also be respectively stored partial instructions for executing the security service call method and the fTPM management method. In other words, the combination of one or more computing devices can jointly execute the instructions for executing the security service call method and the fTPM management method.

[0181] The embodiments of the present application also provide a computer program product containing instructions. The computer program product can be software or a program product containing instructions that can run on a computing device or be stored in any available medium. When the computer program product runs on at least one computing device, at least one computing device is caused to execute the security service call method and the fTPM management method.

[0182] The embodiments of the present application also provide a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (for example, a floppy disk, a hard disk, a magnetic tape), an optical medium (for example, a DVD), or a semiconductor medium (for example, a solid-state drive), etc. The computer-readable storage medium includes instructions that instruct the computing device to execute the security service call method and the fTPM management method, or instruct the computing device to execute the security service call method and the fTPM management method.

[0183] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.

Claims

1. A computing device, characterized in that: The computing device includes a processor, the processor including a trusted execution environment and an untrusted execution environment; The trusted execution environment runs a firmware trusted platform module fTPM manager and a target trusted execution environment TEE instance, the fTPM manager is used to manage the target TEE instance, and the target TEE instance is used to provide security services for programs running in the untrusted execution environment.

2. The computing device according to claim 1, wherein: The untrusted execution environment runs an untrusted domain operating system OS, the security service includes a metric reporting service, and the program running in the untrusted execution environment includes a first untrusted program; The fTPM manager is specifically used to obtain a first measurement value sent by the untrusted domain OS, and send the first measurement value to the target TEE instance, where the first measurement value is a measurement value of the first untrusted program; The target TEE instance is used to determine a first measurement result according to the first measurement value.

3. The computing device according to claim 2, characterized in that The program running in the untrusted execution environment includes the untrusted domain OS. Before running the untrusted domain OS, The fTPM manager is further configured to obtain a measurement value of the untrusted domain OS and send the measurement value of the untrusted domain OS to the target TEE instance; The target TEE instance is further used to determine a second measurement result according to the second measurement value of the untrusted domain OS.

4. The computing device according to claim 3, characterized in that The untrusted execution environment also runs a boot program, which is used to start the untrusted domain OS. The program running in the untrusted execution environment includes the boot program. Before running the boot program, The fTPM manager is further configured to obtain a measurement value of the boot program and send the measurement value of the boot program to the target TEE instance; The target TEE instance is further used to determine a third measurement result according to the measurement value of the boot program.

5. The computing device according to any one of claims 1 to 4, characterized in that: The fTPM manager includes a communication unit and a management unit. The communication unit is used to communicate with the program in the untrusted execution environment; The management unit is used to implement any one or more of the initialization, startup, shutdown and destruction of the target TEE instance.

6. The computing device according to claim 5, characterized in that The fTPM manager also includes an fTPM management application programming interface API; The fTPM management API is used to interact with the target TEE instance.

7. The computing device according to any one of claims 1 to 6, characterized in that: The computing device also includes a memory, a storage module and a startup firmware. The memory includes a trusted domain memory; The storage module is used to store the image file of the fTPM manager and the image file of the target TEE instance; The startup firmware is used to load the image file of the fTPM manager and the image file of the target TEE instance from the storage module to the trusted domain memory when the computing device is started.

8. The computing device according to claim 2, wherein: The fTPM manager is used to start the target TEE instance according to the image file of the target TEE instance after the image file of the target TEE instance is loaded into the trusted domain memory.

9. A method for invoking a security service, characterized in that: The method is applied to a firmware trusted platform module fTPM manager, the fTPM manager includes a function of managing the fTPM, and the method includes: Obtain the security service call request sent by the untrusted domain operating system OS; Sending a security service call task to a target trusted execution environment TEE instance, wherein the target TEE instance is used to implement the function of the fTPM, and the management device is a management program of the target TEE instance; Receive the security service processing result of the security service call task sent by the target TEE instance; The security service processing result is sent to the untrusted domain OS.

10. The method according to claim 9, characterized in that The security service invocation request is used to request the invocation of the metric reporting service; The obtaining of the security service call request sent by the untrusted domain operating system OS comprises: Acquire a first metric value sent by the untrusted domain OS, where the first metric value is a metric value of a first untrusted program, and the first untrusted program is an application program running in an untrusted execution environment; The task of sending a security service call to the target trusted execution environment TEE instance includes: Sending the first metric value to a target trusted execution environment TEE instance, where the target TEE instance is used to implement the function of the fTPM, and the management device is a management program of the target TEE instance; The receiving of the security service processing result sent by the target TEE instance includes: Receiving a first measurement result for the first measurement value returned by the target TEE instance; The sending the security service processing result to the untrusted domain OS includes: The first measurement result is sent to the untrusted domain OS.

11. The method according to claim 9, characterized in that Before obtaining the first metric value, the method further includes: In response to the image text arriving at the target TEE instance being loaded into the trusted domain memory, the target TEE instance is started through the image file.

12. The method according to claim 11, characterized in that The image file of the target TEE instance is loaded into the trusted domain memory by the startup firmware.

13. The method according to claim 12, characterized in that The image file of the management device is loaded into the trusted domain memory by the boot firmware before the image file of the target TEE instance.

14. The method according to claim 12 or 13, characterized in that The time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the untrusted domain OS is loaded into the untrusted domain memory; Before obtaining the first metric value, the method further includes: Acquire a second metric value, where the second metric value is a metric value of the untrusted domain OS; Sending the second metric value to the target TEE instance; Receive a second measurement result for the second measurement value returned by the target TEE instance.

15. The method according to claim 14, characterized in that The time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the boot program is loaded into the untrusted domain memory, and the boot program is used to load the image file of the untrusted domain OS into the untrusted domain memory; Before obtaining the second metric value, the method further includes: Acquire a third measurement value, where the third measurement value is a measurement value of the boot program; Sending the third metric value to the target TEE instance; Receive a third measurement result for the third measurement value returned by the target TEE instance.

16. The method according to any one of claims 9 to 15, characterized in that The privilege level of the target TEE instance is lower than the privilege level of the fTPM manager.

17. The method according to any one of claims 9 to 16, characterized in that: The target TEE instance and the management device run on a processor, the target TEE instance corresponds to a first security partition SP of the processor, and the management device corresponds to a security partition manager SPM of the first security partition.

18. A method for starting a firmware trusted platform module fTPM, characterized in that: The method comprises: The boot firmware loads the fTPM manager into the trusted domain memory; The boot firmware loads a target trusted execution environment TEE instance into the trusted domain memory, and the target TEE instance is used to implement the fTPM; The fTPM manager starts the target TEE instance.

19. The method according to claim 18, characterized in that After loading the target TEE instance into the trusted domain memory, the method further includes: The startup firmware performs digital signature verification on the target TEE instance.

20. A security service calling device, characterized in that: The device is applied to a firmware trusted platform module fTPM manager, the fTPM manager includes a function of managing the fTPM, and the device includes: An acquisition module is used to acquire a security service call request sent by an untrusted domain operating system OS; A first sending module is used to send a security service call task to a target trusted execution environment TEE instance, wherein the target TEE instance is used to implement the function of the fTPM, and the management device is a management program of the target TEE instance; A receiving module, used to receive the security service processing result of the security service call task sent by the target TEE instance; The second sending module is used to send the security service processing result to the untrusted domain OS.

21. The device according to claim 20, characterized in that The security service invocation request is used to request the invocation of the metric reporting service; The acquisition module is specifically used to acquire a first metric value sent by the untrusted domain OS, where the first metric value is a metric value of a first untrusted program, and the first untrusted program is an application program running in an untrusted execution environment; The first sending module is specifically used to send the first measurement value to a target trusted execution environment TEE instance, the target TEE instance is used to implement the function of the fTPM, and the management device is a management program of the target TEE instance; The receiving module is specifically configured to receive a first measurement result for the first measurement value returned by the target TEE instance; The second sending module is specifically configured to send the first measurement result to the untrusted domain OS.

22. The device according to claim 21, characterized in that The device also includes a startup module, which is used to start the target TEE instance through the image file in response to the image text reaching the target TEE instance being loaded into the trusted domain memory.

23. The device according to claim 21, characterized in that The image file of the target TEE instance is loaded into the trusted domain memory by the startup firmware.

24. The device according to claim 23, characterized in that The image file of the management device is loaded into the trusted domain memory by the boot firmware before the image file of the target TEE instance.

25. The device according to claim 23 or 24, characterized in that The time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the untrusted domain OS is loaded into the untrusted domain memory; The acquisition module is further used to acquire a second measurement value, where the second measurement value is a measurement value of the untrusted domain OS; The first sending module is further used to send the second metric value to the target TEE instance; The receiving module is also used to receive a second measurement result for the second measurement value returned by the target TEE instance.

26. The device according to claim 25, characterized in that The time when the image file of the target TEE instance is loaded into the trusted domain memory is earlier than the time when the image file of the boot program is loaded into the untrusted domain memory, and the boot program is used to load the image file of the untrusted domain OS into the untrusted domain memory; The acquisition module is further used to acquire a third measurement value, where the third measurement value is a measurement value of the boot startup program; The first sending module is further used to send the third metric value to the target TEE instance; The receiving module is also used to receive a third measurement result for the third measurement value returned by the target TEE instance.

27. The device according to any one of claims 20 to 26, characterized in that The privilege level of the target TEE instance is lower than the privilege level of the fTPM manager.

28. The device according to any one of claims 20 to 27, characterized in that The target TEE instance and the management device run on a processor, the target TEE instance corresponds to a first security partition SP of the processor, and the management device corresponds to a security partition manager SPM of the first security partition.

29. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores instructions, which, when executed on a computing device, enable the computing device to execute the method according to any one of claims 9 to 19.

30. A computer program product comprising instructions which, when executed on a computing device, cause the computing device to perform the method according to any one of claims 9 to 19.