Data processing device and method for runtime attestation

CN120035826APending Publication Date: 2025-05-23HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202280101057.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2025-05-23

AI Technical Summary

Technical Problem

Microcontrollers in IoT devices are susceptible to malicious firmware tampering attacks, and existing runtime proof methods are difficult to effectively detect attacks that affect software integrity during software execution.

Method used

A data processing device is designed, including a processing unit and a memory. The processing unit runs a real-time operating system to realize the kernel, prove core and multiple tasks, monitor the integrity of the isolated memory compartment of the tasks through multiple capabilities defined by the security capability architecture, and generate task integrity metric data.

Benefits of technology

It ensures the integrity of isolated memory compartment for multiple tasks of the data processing device at runtime, provides an efficient runtime proof mechanism, and enhances the security of IoT devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120035826A_ABST
    Figure CN120035826A_ABST
Patent Text Reader

Abstract

A data processing apparatus (110) for performing a plurality of tasks is disclosed. The apparatus (110) comprises a processing unit (111) for operating the RTOS according to a security capability architecture. The RTOS implements a kernel, an attestation core, and a plurality of tasks. Each task uses a plurality of capabilities defined by the secure capability architecture. Furthermore, the apparatus (110) comprises a memory (115) comprising a plurality of memory compartments, the plurality of memory compartments comprising a memory compartment of the attestation core and a respective isolated memory compartment for each task. The memory compartment for each task is defined by a plurality of capabilities of the task and data of the task operation. The processing unit (111) is configured to monitor the integrity of the memory compartment of the task to generate task integrity metric data (125) indicative of the integrity of the memory compartment of the task.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to security technology. More specifically, the present invention relates to a data processing device and method for runtime attestation. In addition, the present invention relates to a remote attestation system including such a data processing device. Background Art

[0002] A key challenge in IoT security is that constrained microcontrollers are vulnerable to malicious firmware tampering. This can be caused by an attacker with physical access to the device to perform a reprogramming attack or a remote attack that exploits a vulnerability in the software implementation. A popular approach to mitigate such attacks is called attestation, which verifies that the device is running a known firmware, i.e., the device is in a trusted state. Attestation is generally defined as a process between two parties, a prover and a verifier. The prover can be, for example, a resource-constrained IoT device, while the verifier is usually a device with more computational power, such as a server backend. From the prover's perspective, attestation consists of two stages: (1) generating evidence about the prover's trustworthiness and (2) delivering that evidence to the verifier via a secure protocol. These two stages, especially the first stage of the attestation process (i.e., generating attestation evidence), are usually best performed at runtime in order to detect attacks that may affect the integrity of the software during its execution.

[0003] Some runtime attestation methods are called "dynamic integrity measurement" and "control flow attestation". In the "dynamic integrity measurement" method, a hash value (fingerprint) is periodically extracted from the predictable / static memory (i.e., code segment) of the process running on the "prover" device, and the hash value is compared with the reference fingerprint generated at build time on the "remote verifier" device. The "control flow attestation" method attempts to monitor the execution flow of the process and record the sequence of edges (branches) that the process passes through in order to check whether the execution flow is as expected based on the known good control flow graph generated at build time. This method mainly covers return-oriented or jump-oriented programming attacks, which are the mainstream types of memory-based attacks today. Summary of the invention

[0004] The object of the present invention is to provide an improved data processing apparatus and method for runtime proof.

[0005] The above and other objects are achieved by the subject matter of the independent claims. Other implementations are apparent from the dependent claims, the description and the drawings.

[0006] According to a first aspect, a data processing device for performing multiple tasks is provided. The data processing device may be an IoT device, a smart phone, a network device, an electronic control unit, etc. The multiple tasks may include a sensor task for controlling one or more sensors in the data processing device, an actuator task for driving one or more actuators in the data processing device, and a network task for providing wireless communication between the data processing device and other network devices, etc.

[0007] The data processing device includes a processing unit for running a real-time operating system (RTOS) according to a security capability architecture. The processing unit may include one or more central processing units (CPU) and / or one or more microcontrollers, etc. The RTOS implements a kernel, a certification core, and the multiple tasks, each of which uses one or more of the multiple capabilities defined by the security capability architecture when executed. The "security capability architecture" used in this article may include an instruction set and a data structure in the form of capabilities and hardware and / or software that supports such an architecture. The security capability architecture of a data processing device may include an instruction set called capability hardware enhanced RISC instruction (CHERI), etc.

[0008] In addition, the data processing device includes a memory having a plurality of isolated memory compartments (sometimes also referred to as "protection domains"), the plurality of isolated memory compartments including an isolated memory compartment of the certification core and a corresponding isolated memory compartment of each task. The isolated memory compartment of each task is defined by the one or more of the plurality of capabilities of the corresponding task and the data operated by the one or more of the plurality of capabilities of the corresponding task. Each isolated memory compartment of each task can be regarded as completely encapsulating the corresponding task.

[0009] The processing unit in the data processing device is also used to monitor the integrity of the isolated memory compartments of the multiple tasks to generate task integrity measurement data indicating the integrity of the isolated memory compartments of the multiple tasks, thereby providing a data processing device capable of ensuring integrity at runtime. The "proof core" used in this article is a dedicated security task running in its own memory compartment, which is completely isolated from other tasks or RTOS kernels. More specifically, the proof core is a dedicated task isolated from the rest of the system, and can be called through the trampoline module when capabilities are exchanged between other tasks to record the exchanged capabilities and report them securely to the remote verifier.

[0010] In another possible implementation, the data processing device further comprises a communication interface for sending the task integrity measurement data (in the form originally generated by the processing unit or in a further processed form) to a proof server, so that the proof server can perform runtime proof of the integrity of the isolated memory compartments of the plurality of tasks of the data processing device based on the task integrity measurement data.

[0011] In another possible implementation, the attestation core is used to record the task integrity measurement data of the memory compartment of each task, and send the task integrity measurement data of the memory compartment of each task to the attestation server regularly and / or in an event-driven manner through the communication interface. Therefore, the task integrity measurement data can be efficiently reported.

[0012] In another possible implementation, the attestation core is used to encrypt and protect the sent task integrity measurement data according to one or more encryption keys, and the communication interface is used to send the encrypted and protected task integrity measurement data to the attestation server. In this way, the task integrity measurement data can be protected from any attack in an encrypted manner.

[0013] In another possible implementation, the communication interface is used to receive a random number from the proof server, the proof core is further used to encrypt and protect the task integrity measurement data and the random number using the one or more encryption keys, and the communication interface is used to send the encrypted task integrity measurement data and the random number to the proof server. This enables detection of replay attacks.

[0014] In another possible implementation, the one or more encryption keys are stored in the isolated memory compartment of the attestation core. By storing the encryption keys in a highly secure attestation core, the encryption keys can be well protected from any attack attempting to extract these keys from the data processing device.

[0015] In another possible implementation, the processing unit is used to define the plurality of isolated memory compartments. For example, the processing unit can securely manage the address ranges of the plurality of isolated memory compartments. Therefore, the memory in the data processing device can be a low-cost memory without a dedicated memory management unit.

[0016] In another possible implementation, the processing unit is used to monitor the integrity of the isolated memory compartments of the multiple tasks according to a trampoline module implemented by trampoline code. The trampoline module is called at each conversion between the isolated memory compartments of the multiple tasks, and is used to report one or more capabilities exchanged between the isolated memory compartments of the multiple tasks to the proof core. In this way, the integrity of the isolated memory compartments of the multiple tasks can be efficiently monitored.

[0017] In another possible implementation, the processing unit is further configured to initially scan the memory to determine the plurality of isolated memory compartments of the memory, so that the memory compartments, ie, protection domains, of a plurality of tasks can be efficiently determined.

[0018] In another possible implementation, the processing unit is further configured to store the task integrity measurement data in the isolated memory compartment of the attestation core. By storing the task integrity measurement data in the high-security memory compartment of the attestation core, the task integrity measurement data can be protected from any attack, for example, from a compromised task in a device under the control of an attacker who attempts to modify the task integrity measurement data.

[0019] In another possible implementation, the task integrity measurement data includes the one or more capabilities of each corresponding task in the plurality of tasks. In this way, the task integrity measurement data can be efficiently generated according to the security capability architecture of the data processing device.

[0020] In another possible implementation, the one or more capabilities of the multiple capabilities of each task include pointers and pointer metadata (also called "wide pointers"), so that task integrity measurement data can be efficiently generated according to the security capability architecture of the data processing device.

[0021] In another possible implementation, the RTOS of the data processing device is a single address space RTOS. Therefore, the data processing device can implement the RTOS without complex and expensive processing resources.

[0022] In another possible implementation, the security capability architecture is based on hardware and / or software. As described above, the security capability architecture may include an instruction set and data structure in the form of capabilities and hardware and / or software supporting such an architecture. The security capability architecture of the data processing device may include an instruction set called capability hardware enhanced RISC instruction (CHERI), etc.

[0023] According to a second aspect, a remote attestation system is provided. The remote attestation system according to the second aspect comprises at least one data processing device according to the first aspect and an attestation server, the attestation server being used to receive the task integrity measurement data from the at least one data processing device and attest the integrity of the at least one data processing device based on the task integrity measurement data.

[0024] In another possible implementation, one or more reference capabilities of each task of the at least one data processing device are defined by a task policy, and the attestation server is used to attest the integrity of the at least one data processing device based on the task integrity measurement data and the task policy. In this way, the integrity of the at least one data processing device can be efficiently attested based on the task integrity measurement data and the task policy.

[0025] According to a third aspect, there is provided a method for attesting the integrity of a data processing device. The data processing device is configured to perform a plurality of tasks and comprises: a processing unit configured to run a real-time operating system (RTOS) according to a security capability architecture, wherein the RTOS implements a kernel, an attestation core, and a plurality of tasks, each task using one or more of a plurality of capabilities defined by the security capability architecture when executed; and a memory. The method comprises the following steps:

[0026] providing a plurality of isolated memory compartments of the memory, wherein the plurality of isolated memory compartments include an isolated memory compartment of the attestation core and a corresponding isolated memory compartment of each task, the isolated memory compartment of each task being defined by the one or more of the plurality of capabilities of the task and data operated by the one or more of the plurality of capabilities of the task;

[0027] The integrity of the isolated memory compartments of the plurality of tasks is monitored to generate task integrity metric data indicative of the integrity of the memory compartments of the plurality of tasks.

[0028] The method provided in the third aspect of the present invention can be performed by the data processing device provided in the first aspect of the present invention. Therefore, other features of the method provided in the third aspect of the present invention are directly implemented by the functions of the data processing device provided in the first aspect of the present invention and the above-mentioned and below-mentioned different implementation modes thereof.

[0029] According to a fourth aspect, a computer program product is provided, comprising a computer-readable storage medium, wherein the computer-readable storage medium is used to store program code, and when the program code is executed by a computer or a processor, the computer or the processor executes the method provided by the third aspect.

[0030] The details of one or more embodiments are set forth in the accompanying drawings and the description below. Other features, objects, and advantages are apparent from the description, drawings, and claims. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] The embodiments of the present invention are described in detail below with reference to the accompanying drawings, in which:

[0032] Figure 1 A schematic diagram of a certification system including a data processing device and a certification server provided by an example in an embodiment of the present invention is shown;

[0033] Figure 2 A schematic diagram showing isolated memory compartments of a memory in a data processing device provided by an example in an embodiment of the present invention is shown;

[0034] Figure 3 A schematic diagram showing multiple tasks implemented by a data processing device provided by an example in an embodiment of the present invention;

[0035] Figure 4 A schematic diagram of a trampoline module and a proof core implemented by a data processing device and used to monitor the integrity of memory compartments of multiple tasks provided by an example in an embodiment of the present invention is shown;

[0036] Figure 5 A schematic diagram showing a security architecture implemented by a data processing device and used for encrypting and protecting task integrity measurement data provided by an example in an embodiment of the present invention;

[0037] Figure 6 A flowchart of a method for proving the integrity of a data processing device provided by an example in an embodiment of the present invention is shown.

[0038] In the following, identical reference signs refer to identical or at least functionally equivalent features. DETAILED DESCRIPTION

[0039] In the following description, reference is made to the accompanying drawings that form a part of the present invention, which illustrate specific aspects of embodiments of the present invention or specific aspects in which embodiments of the present invention may be used by way of illustration. It should be understood that embodiments of the present invention may be used in other aspects and include structural or logical changes that are not depicted in the accompanying drawings. Therefore, the following detailed description should not be understood in a restrictive sense, and the scope of the present invention is defined by the appended claims.

[0040] For example, it should be understood that the disclosure related to describing a method may also be applicable to a corresponding device or system for performing the method, and vice versa. For example, if one or more specific method steps are described, the corresponding device may include one or more units (e.g., functional units) to perform the one or more method steps described (e.g., one unit performs one or more steps, or multiple units perform one or more steps of multiple steps respectively), even if such one or more units are not explicitly described or illustrated in the drawings. On the other hand, for example, if a specific device is described based on one or more units (e.g., functional units), the corresponding method may include a step to perform the function of one or more units (e.g., one step performs the function of one or more units, or multiple steps perform the function of one or more units of multiple units respectively), even if such one or more steps are not explicitly described or illustrated in the drawings. In addition, it is understood that, unless otherwise explicitly stated, the features of the various exemplary embodiments and / or aspects described herein may be combined with each other.

[0041] Figure 1 A schematic diagram of a certification system 100 provided by an embodiment is shown. The certification system 100 includes a data processing device 110 provided by an embodiment (in Figure 1 110) and the certification server 120 (referred to as the device 110 in Figure 1 The proof system 100 may also include a configuration server 130 of a supplier or manufacturer of the data processing device 110, and the configuration server 130 is used to configure software 135, such as firmware or software image, for the data processing device 110. The data processing device 110 may be an IoT device, a smart phone, a network device, an electronic control unit, etc.

[0042] like Figure 1As shown and described in detail below, the data processing device 110 includes a processing unit 111, which may include one or more central processing units (CPUs) and / or one or more microcontrollers, etc. The processing unit 111 can be implemented in hardware and / or software, and may include digital circuits, or both analog circuits and digital circuits. The digital circuit may include components such as an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), a digital signal processor (DSP), or a general-purpose processor. In addition, the data processing device 110 includes an electronic memory 115 for storing data, such as a flash memory 115. The memory 115 can store executable program code, which, when executed by the processing unit 111, enables the data processing device 110 to perform the functions and methods described herein. The data processing device 110 may also include a communication interface 113, in particular a wireless communication interface and / or a wired communication interface that enables the data processing device 110 to communicate with the certification server 120, the configuration server 130, and / or other network devices.

[0043] Further references Figure 2 and Figure 3 The processing unit 111 is used to execute a plurality of software tasks, for example, these software tasks may include a sensor task 305a for controlling one or more sensors in the data processing device 110, an actuator task 305b for driving one or more actuators in the data processing device 110, and a network task 305c for providing wireless communication between the data processing device 110 and other network devices (together with the communication interface 113). Figure 3 As shown, the processing unit 111 is used to run a real-time operating system (RTOS) 300 according to the security capability architecture to implement a software environment of a kernel 301, a proof core 303 and multiple tasks 305a to 305c. In one embodiment, the RTOS 300 of the data processing device 110 is a single address space RTOS 300.

[0044] Each of the multiple tasks 305a to 305c uses one or more of the multiple capabilities defined by the security capability architecture when executed. The "security capability architecture" used in this article may include an instruction set and data structure in the form of capabilities and hardware and / or software that supports such an architecture. The security capability architecture of the data processing device may include an instruction set called capability hardware enhanced RISC instruction (CHERI), etc. For more detailed information about CHERI, please refer to "Capability Hardware Enhanced RISC Instructions: CHERI Instruction-Set Architecture (Version 8)", Technical Report, No. 951, UCAM-CL-TR-951, ISSN 1476-2986, University of Cambridge, the entire contents of which are incorporated herein by reference.

[0045] like Figure 2 and Figure 3 As shown, due to the presence of a security capability architecture in the data processing device 110, especially an architecture based on CHERI, the memory 115 in the data processing device 110 includes a plurality of isolated memory compartments (sometimes also referred to as "protection domains"), which include an isolated memory compartment of the proof core 303 and corresponding isolated memory compartments 115a to 115c of each task 305a to 305c. The isolated memory compartment of each task is defined by one or more of the plurality of capabilities of the corresponding task and data operated by one or more of the plurality of capabilities of the corresponding task. In one embodiment, one or more of the plurality of capabilities of each task 305a to 305c may include pointers and pointer metadata (also referred to as "wide pointers").

[0046] like Figure 2 As shown in the schematic diagram, each isolated memory compartment 115a to 115c of each task 305a to 305c can be considered to completely encapsulate the corresponding task 305a to 305c. In one embodiment, the processing unit 111 in the data processing device 110 is used to define a plurality of isolated memory compartments of the proof core 303 and isolated memory compartments 115a to 115c of a plurality of tasks 305a to 305c. For example, the processing unit 111 can be used to securely manage the address ranges of the plurality of isolated memory compartments 115a to 115c.

[0047] As described in detail below, the processing unit 111 in the data processing device 110 is also used to monitor the integrity of the isolated memory compartments 115a to 115c of the plurality of tasks 305a to 305c to generate task integrity metric data 125 indicating the integrity of the isolated memory compartments 115a to 115c of the plurality of tasks 305a to 305c. In one embodiment, the processing unit 111 in the data processing device 110 is also used to store the task integrity metric data 125 in the isolated memory compartment of the attestation core 303. As described in detail below, in one embodiment, the task integrity metric data 125 may include one or more capabilities of each respective task 305a to 305c of the plurality of tasks 305a to 305c, such as wide pointers.

[0048] like Figure 1 As shown in the embodiment, the communication interface 113 in the data processing device 110 can be used to send task integrity measurement data 125 (in a form initially collected and / or generated by the processing unit 111 or in a further processed form) to the attestation server 120. In this way, the attestation server 120 can perform runtime attestation on the integrity of the isolated memory compartments 115a to 115c of multiple tasks 305a to 305c of the data processing device 110 based on the task integrity measurement data 125 and a reference value defined by a task policy 145 provided by a configuration server 130 or the like in one embodiment.

[0049] Further reference below Figure 4 and Figure 5 Other embodiments of the data processing device 110 and the certification system 100 are described in detail.

[0050] As described above, the embodiments disclosed herein are capable of "runtime attestation" of the data processing device 110, that is, providing an attestation system 100 that is capable of attesting the integrity of multiple tasks 305a to 305c and the operating system kernel 301 of the data processing device 110 when the data processing device 110 is executed. For example, if the tasks 305a to 305c run as expected after startup, the attestation system 100 is capable of providing credible and verifiable evidence about their integrity, and an external verifier instance can verify the evidence and decide whether to trust the data processing device 110 and / or the tasks 305a to 305c running on the data processing device 110. If the tasks 305a to 305c of the data processing device 110 do not run as expected, the data processing device 110 (which may be controlled by a malicious attacker) will not be able to forge such evidence. In addition, according to one embodiment, the data processing device 110 can even provide contextual information, that is, the location where the unknown (potentially malicious) task behavior deviates from the expected behavior.

[0051] As described above, according to the embodiments disclosed herein, the data processing device 110 may be a low-end device 110 based on a microcontroller (MCU), which supports a security capability architecture (e.g., CHERI) and implements a microcontroller-level real-time OS 300, such as FreeRTOS or Huawei LiteOS. According to other embodiments, the data processing device 110 may be a high-end device 110 based on a CPU, which supports a similar security capability architecture and implements a more complex RTOS 300, such as a Linux operating system 300.

[0052] The embodiments disclosed herein take a new approach to evaluating the runtime integrity of a program (i.e., a plurality of tasks 305a to 305c). Unlike the traditional approach of looking inside the memory of a task / program and trying to understand it (which is difficult, complex, and computationally expensive), the embodiments disclosed herein of the data processing apparatus 110 can monitor the internals of a given task / program 305a to 305c from the perspective of other processes running within the data processing apparatus 110. This radically different approach, such as Figure 2 As shown. According to the embodiments disclosed herein, if no other tasks 305a to 305c or processes attempt to access various parts of the memory 115 (except for the parts that are allowed to be accessed) (i.e., the corresponding isolated memory compartments 115a to 115c) on the data processing device 110, it can be inferred that a given task 305a to 305c is running as expected (i.e., it has not been tampered with by a malicious attacker). In other words, according to the embodiments disclosed herein, the data processing device 110 is used to detect whether the isolation between different memory compartments 115a to 115c of multiple tasks 305a to 305c is destroyed during runtime. Therefore, by providing evidence of the isolation between multiple tasks 305a to 305c and whether the isolation is maintained in the form of task integrity measurement data 125, efficient runtime proof can be achieved.

[0053] As described above, the processing unit 111 in the data processing device 100 is used to implement a security capability architecture, such as a CHERI-based architecture that provides spatial memory security and memory isolation through "capabilities". The security capability architecture (e.g., a CHERI-based architecture) extends the traditional instruction set architecture (ISA) to achieve fine-grained memory protection and highly scalable software separation. For example, in the case of a single address space, the CHERI-based architecture implemented by the data processing device 110 provided by one embodiment can provide memory isolation without the need for a memory management unit (MMU). In one embodiment, the RTOS 300 of the data processing device 110 can be a CHERI FreeRTOS 300, which is a variant of FreeRTOS and provides isolation between different memory compartments 115a to 115c of multiple tasks 305a to 305c in a single address space system. The CHERI FreeRTOS 300 uses the features of the CHERI-based architecture to limit the set of memory areas accessible to each memory compartment 115a to 115c. In one embodiment, each memory compartment 115a-115c may be as small as a function or as large as some code spanning several source files.

[0054] As described above, each task 305a to 305c is limited to its "protection domain", i.e., isolated memory compartments 115a to 115c. For a security capability architecture, for example, a security capability architecture based on CHERI, a protection domain (i.e., memory compartments 115a to 115c) refers to a set of capabilities that tasks 305a to 305c can access. For example, if tasks 305a to 305c have the ability to point to a stack in one of their registers, a data processing device 110 provided by one embodiment is used to check the memory area pointed to to determine any other capabilities pointing to other areas in the memory 115. The data processing device 110 provided by one embodiment can be used to recursively search for these other pointed memory areas until a complete set of all capabilities that the corresponding tasks 305a to 305c can access is found. This is the protection domain, i.e., the isolated memory compartments 115a to 115c of the corresponding tasks 305a to 305c. All protection domains (ie memory compartments 115a to 115c) are distinct, ie isolated from each other, which means that a task 305a to 305c cannot access the memory compartments 115a to 115c of other tasks 305a to 305c.

[0055] In one embodiment, tasks 305a-305c may control exclusive areas of memory 115. In addition, tasks 305a-305c may have pointers to specific functions of other tasks 305a-305c. Two tasks 305a-305c may share a portion of memory 115 if the capabilities of the memory area prohibit reading or storing a certain capability. In one embodiment, kernel 301 may have full access to memory 115 (except for the memory compartment associated with attestation core 303).

[0056] Typically, the protection domain (i.e., the isolated memory compartments 115a to 115c of each task 305a to 305c) is known in advance. For example, a network task 305c can share a buffer with other tasks 305a, 305b, but cannot share its internal state. In this case, there may be a strategy for how to set the protection domain (i.e., the memory compartments 115a to 115c).

[0057] In one embodiment, all memory compartments 115a-115c may be initially measured and determined by scanning the entire memory 115 and inferring the different compartments based on the register files of each task 305a-305c.

[0058] In a security capability architecture (e.g., a security capability architecture based on CHERI), it is not possible for tasks 305a to 305c to extend their own isolated memory compartments 115a to 115c, i.e., protection domains, without passing control to other isolated memory compartments. This inherent feature of the security capability architecture implemented by the data processing device 110 makes it unnecessary to continuously monitor isolated memory compartments, but only needs to monitor when tasks 305a to 305c pass control to other isolated memory compartments (i.e., in an event-driven manner).

[0059] In one embodiment, if tasks 305a to 305c communicate only with kernel 301, kernel 301 may be used to record capabilities passed to other tasks 305a to 305c. Figure 4As shown, for example, if task 305a calls the malloc function, the kernel 301 of the data processing device 110 is used to allocate a portion of the memory 115 and thus build a certain capability. In addition, the kernel 301 of the data processing device 110 can update the isolated memory compartment 115a of task 305a to take into account the new capability that task 305a has acquired. The capability can then be passed to task 305a. It is understandable that this approach may cause an over-approximation to the isolated memory compartment 115a of task 305a. However, it is more complicated to detect that tasks 305a to 305c have deleted a certain capability, because this may require scanning the entire memory 115. Therefore, depending on the specific use case, the data processing device 110 provided by an embodiment can implement one of these two methods.

[0060] More specifically, if Figure 4 As shown by the circle with the number 1 in it, tasks 305a to 305c may have the ability to point to their code and stack. Figure 4 As shown in the circle with the number 2 in it, tasks 305a to 305c can call the malloc function and switch to the kernel memory compartment through the trampoline module 401. Figure 4 As shown in the circle with the number 3 in it, the malloc function can generate a new capacity limited by the size of the requested area and return the capacity. Figure 4 As shown in the circle with the number 4 in it, the trampoline module 401 is used to provide the capability to the attestation core 303, and the attestation core 303 updates the protection domain measurement, that is, the task integrity measurement data 125. Then, the trampoline module 401 can return. The boxes called "pcc", "csp" and "cao" in the figure are exemplary CPU registers implemented by the CHERI-based architecture according to an embodiment of the data processing device 110.

[0061] As described above, the attestation core 303 of the data processing device 110 is associated with a secure area of ​​the memory 115, i.e., its own isolated memory compartment (similar to the elastic engine). In one embodiment, the attestation core 303 has full control over the memory 115 in the data processing device 110, but the kernel 301 and multiple tasks 305a to 305c cannot tamper with the isolated memory compartment of the attestation core 303. In one embodiment, the memory compartment of the attestation core 303 is used to securely store the task integrity measurement data 125 (even if the kernel 301 is not trusted). In one embodiment, in order to transfer to the memory compartment of the attestation core 303, the corresponding task 305a to 305c or the kernel 301 can use the "CInvoke" mechanism provided by the CHERI-based architecture, which can perform secure transfers between different memory compartments.

[0062] As described above, in one embodiment, the task policy 145 may be defined by a vendor by listing all expected memory compartments 115a to 115c (i.e., protection domains of the data processing device 110). In one embodiment, the task policy 145 may define what each memory compartment 115a to 115c should have access to. The task policy 145 may be created and provided by a vendor via a configuration server 130 or the like. As described above, the attestation server 120 may compare the task policy 145 with the current task integrity metric data 125 (provided by the data processing device 110) to detect whether there are any integrity violations in the isolated memory compartments 115a to 115c of the plurality of tasks 305a to 305c.

[0063] In the CHERI-based architecture that can be implemented by the data processing device 110 provided by one embodiment, the "reachability monotonicity" property means that during the execution of any task 305a to 305c, the memory compartments 115a to 115c of the corresponding tasks 305a to 305c cannot be increased until the execution is transferred to the memory compartments of other tasks 305a to 305c. It can be understood that this is an implicit feature of the security capability architecture (especially the security capability architecture based on CHERI), and is therefore always valid, and the architecture can be implemented by the data processing device 110 provided by one embodiment. Therefore, as described above, in order to monitor each isolated memory compartment 115a to 115c, the embodiments disclosed herein can be considered from a reference point and then monitored, that is, all capabilities that enter the corresponding memory compartments 115a to 115c at runtime are measured. It can be understood that although these measurements can be performed at discrete time points, this provides a continuous view of the corresponding memory compartments, because the security capability architecture based on CHERI has the above-mentioned inherent characteristics, and the corresponding isolated memory compartments cannot increase by themselves.

[0064] As described above, the data processing device 110 provided by one embodiment monitors the corresponding memory compartments 115a to 115c and may overestimate the actual corresponding memory compartments 115a to 115c. However, as described above, this is usually not a problem because the embedded tasks 305a to 305c are likely to rarely use dynamic allocation, resulting in memory idleness.

[0065] It is understood that the data processing device 110 provided by one embodiment monitors the corresponding memory compartments 115a to 115c and should intercept all capabilities entering the corresponding memory compartments 115a to 115c. In one embodiment, this can be implemented by a trampoline module 401, which can be implemented by the data processing device 110 provided by one embodiment and described below. Figure 4 In the context of Figure 4In the illustrated embodiment, the processing unit 111 in the data processing device 110 is used to monitor the integrity of the corresponding isolated memory compartments 115a to 115c of the plurality of tasks 305a to 305c according to the trampoline module 401 implemented by the trampoline code. Figure 4 As shown, the trampoline module 401 is called at each transition between the isolated memory compartments 115a to 115c of multiple tasks 305a to 305c, and is used to report one or more capabilities exchanged between the isolated memory compartments 115a to 115c of multiple tasks 305a to 305c to the proof core 303.

[0066] In one embodiment, the communication interface 113 in the data processing device 110 is used to send the current task integrity measurement data 125 to the certification server 120 whenever one of the memory compartments 115a to 115c of multiple tasks 305a to 305c is reduced, so that the certification server 120 checks the current task integrity measurement data 125 according to the reference value defined by the task policy 145.

[0067] As described above, compared with a conventional RTOS, the RTOS 300 implemented by the data processing device 110 provided by one embodiment adds the attestation core 303 and the trampoline module 401 to generate the task integrity measurement data 125. As described above, the attestation core 303 is associated with its memory compartment, i.e., a secure area in the memory 115 that is isolated from other parts of the system (including the RTOS kernel 301). In one embodiment, the memory compartment of the attestation core 303 is used to store the task integrity measurement data 125 and one or more encryption keys 503 (such as 501) used to digitally sign the task integrity measurement data 125. Figure 5 ). Thus, the attestation core 303 may be viewed as providing an interface for adding capabilities to the respective memory compartments 115a to 115c of the plurality of tasks 305a to 305c.

[0068] Since the isolation between different memory compartments 115a to 115c or between the memory compartments 115a to 115c and the kernel 301 may be destroyed by malicious attackers, the purpose of the attestation core 303 of the data processing device 110 provided by one embodiment is to ensure the integrity of the task integrity measurement data 125 in such a scenario (if the task integrity measurement data 125 is stored in the kernel 301, etc., this is impossible to do).

[0069] As described above, in one embodiment, the trampoline module 401 implemented by the processing unit 111 in the data processing device 110 can be called at each conversion between the isolated memory compartments 115a to 115c of multiple tasks 305a to 305c, and is used to report to the proof core 303 one or more capabilities exchanged between the isolated memory compartments 115a to 115c of multiple tasks 305a to 305c. In other words, the trampoline module 401 is a special function for safely switching to other memory compartments, i.e., protection domains, at runtime. During this switching process, the trampoline module 401 is also used to record each capability passed to the new memory compartment by passing the corresponding capability to the proof core 303 to generate task integrity measurement data 125.

[0070] In one embodiment, the processing unit 111 in the data processing device 110 is used to transfer control from the memory compartment 115a to 115c of the corresponding task 305a to the other memory compartments 115a to 115c by jumping to the trampoline module 401. As described above, in one embodiment, the capabilities passed to the new memory compartment in the process can be forwarded to the attestation core 303. The processing unit 111 in the data processing device 110 is used to add these capabilities to the portion of the task integrity metric data 125 associated with the new memory compartment. Figure 4 In the illustrated embodiment, the task integrity metric data 125 may be provided in the form of memory compartments, i.e., a protection domain table 125 describing which memory regions each memory compartment 115a to 115c can access and the corresponding permissions. This data structure in the form of a memory compartment table 125 may be updated with new capabilities and stored in the memory compartments of the attestation core 303. One embodiment of efficiently storing the protection domain metrics may be a list of memory regions and their permissions, defined by the capabilities recorded by the attestation core 303. When new capabilities are added to the list, the list is updated in place and always maintains its best representation.

[0071] As described above, remote attestation is the process of transmitting trusted evidence to a remote third-party verifier to prove the integrity of a device, such as the data processing device 110. In one embodiment, the communication interface 113 in the data processing device 110 is used to send task integrity measurement data 125 indicating the integrity of the memory compartments 115a to 115c of the plurality of tasks, so that the attestation server 120 checks the authenticity of the task integrity measurement data 125.

[0072] like Figure 5As shown, in one embodiment, the code of the device can be measured at startup, and a cryptographic key bound to the hardware root of trust can be built based on the measurement. The vendor 130 can authenticate the device 110 by issuing a certificate. The key is stored in the attestation core 303 and cannot be obtained from anywhere else in the system. It is understood that in order to trust the information provided by the attestation core 303, the remote verifier 120 needs to attest the integrity of the core 30 itself. To this end, the embodiments disclosed herein can utilize a known device identifier composition engine (DICE) implementation 501, which derives the signature key of the attestation core 303 based on the unique device identifier (unique device secret) and the hash value (representing the measurement) of the code of each boot component sequentially loaded into the attestation core 303 (including the attestation core 303 itself). Considering that the attestation core 303 is isolated from any other tasks 305a to 305c and the kernel 301, it can be believed that once loaded, its integrity remains unchanged. Therefore, the loaded attestation core can use the key derived therefrom to truly sign the measurement / recorded capabilities. Based on the signature, the remote verifier 120 can verify these capabilities once it verifies the combined device and attestation core identity against the signed device certificate provided by the manufacturer 130 .

[0073] At runtime, the attestation server 120 may initiate a challenge response mechanism, and the data processing device 110 digitally signs the task integrity metric data 125 and the random number received from the attestation server 120 and required by the challenge response mechanism. The attestation server 120 receives the data 125 and checks that the key 503 used by the data processing device 110 to digitally sign the data 125 and the random number is based on the certificate received from the vendor (e.g., the configuration server 130). In the final stage of the attestation process, the attestation server compares the task integrity metric data 125 with the reference value defined by the task policy 145 provided by the vendor (e.g., the configuration server 130).

[0074] In one embodiment, the attestation scheme implemented by the data processing device 110 and the attestation server 120 is based on a root of trust for measurement (RTM), which is used to anchor the attestation measurement (i.e., the task integrity measurement data 125) in immutable hardware and report the task integrity measurement data 125 in a trusted manner. To this end, in one embodiment, the Device Identifier Composition Engine (DICE) RTM standard can be adopted, as described above and as shown in Figure 5Alternatively, a Trusted Platform Module (TPM) can be used as the RTM standard. Figure 5 As shown, according to the DICE RTM standard, a unique and random key (also referred to as a unique device key) is stored on the data processing device 110, and a mechanism is provided to prevent the key from being read after the DICE engine is executed.

[0075] Figure 6 1 is a flowchart of a method 600 for proving the integrity of a data processing device 110 provided by an embodiment. As described above, the data processing device 110 is used to execute multiple tasks 305a to 305c and includes a processing unit 111, and the processing unit 111 is used to run an RTOS 300 according to a security capability framework, wherein the RTOS 300 implements a kernel 301, a proof core 303, and multiple tasks 305a to 305c, and each task 305a to 305c uses one or more of the multiple capabilities defined by the security capability framework when being executed. In addition, the data processing device 110 includes a memory 115. The method 600 includes step 601 of providing a plurality of isolated memory compartments of a memory 115, wherein the plurality of isolated memory compartments include an isolated memory compartment of a certification core 303 and a corresponding isolated memory compartment 115a to 115c of each task 305a to 305c, the isolated memory compartment 115a to 115c of each task 305a to 305c being defined by one or more of a plurality of capabilities of the task 305a to 305c and data operating on one or more of a plurality of capabilities of the task 305a to 305c. In addition, the method 600 includes step 603 of monitoring the integrity of the isolated memory compartments 115a to 115c of the plurality of tasks 305a to 305c to generate task integrity metric data 125 indicating the integrity of the memory compartments 115a to 115c of the plurality of tasks 305a to 305c.

[0076] Since the method 600 can be implemented by the data processing device 110 , other features of the method 600 are directly implemented by the functions of the data processing device 110 and its different embodiments described above and below.

[0077] Those skilled in the art will understand that the "boxes" ("units") in the various figures (methods and devices) represent or describe the functions of an embodiment of the present invention (and not necessarily independent "units" in hardware or software), thereby equally describing the functions or features of the device embodiments and the method embodiments (unit = step).

[0078] In several embodiments provided in the present application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. The described device embodiments are merely exemplary. For example, unit division is merely a logical function division, and other division methods may be used in actual implementation. For example, multiple units or components may be merged or integrated into another system, or some features may be ignored or not performed. In addition, the mutual coupling or direct coupling or communication connection shown or described may be implemented through some interfaces. The indirect coupling or communication connection between devices or units may be implemented in electronic, mechanical or other forms.

[0079] Units described as separate components may or may not be physically separate, and components shown as units may or may not be physical units, may be located in one location, or may be distributed over multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the embodiment.

[0080] In addition, the functional units in the embodiments disclosed herein may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit.

Claims

1. A data processing device (110) for performing a plurality of tasks (305a to 305c), It is characterized in that The data processing device (110) comprises: A processing unit (111) for running a real-time operating system (RTOS) (300) according to a security capability framework, wherein the RTOS (300) implements a kernel (301), an attestation core (303), and a plurality of tasks (305a to 305c), each of the plurality of tasks (305a to 305c) using one or more of a plurality of capabilities defined by the security capability framework when executed; a memory (115) comprising a plurality of isolated memory compartments, wherein the plurality of isolated memory compartments include an isolated memory compartment of the attestation core (303) and a corresponding isolated memory compartment (115a to 115c) of each task (305a to 305c), the isolated memory compartment (115a to 115c) of each task (305a to 305c) being defined by one or more of the plurality of capabilities of the task (305a to 305c) and data operated by the one or more of the plurality of capabilities of the task (305a to 305c), The processing unit (111) is also used to monitor the integrity of the isolated memory compartments (115a to 115c) of the multiple tasks (305a to 305c) to generate task integrity measurement data (125) indicating the integrity of the isolated memory compartments (115a to 115c) of the multiple tasks (305a to 305c).

2. The data processing device (110) according to claim 1, It is characterized in that The data processing device (110) also includes a communication interface (113) for sending the task integrity measurement data (125) to a certification server (120).

3. The data processing device (110) according to claim 2, It is characterized in that The attestation core (303) is used to record the task integrity measurement data (125) of the memory compartment (105a to 105c) of each task (305a to 305c), and to send the task integrity measurement data (125) of the memory compartment (105a to 105c) of each task (305a to 305c) to the attestation server (120) via the communication interface (113) periodically and / or in an event-driven manner.

4. The data processing device (110) according to claim 2 or 3, It is characterized in that The attestation core (303) is used to encrypt and protect the task integrity measurement data (125) according to one or more encryption keys (503), and the communication interface (113) is used to send the encrypted and protected task integrity measurement data (125) to the attestation server (120).

5. The data processing device (110) according to claim 4, It is characterized in that The communication interface (113) is used to receive a random number from the proof server (120), and the proof core (303) is also used to encrypt and protect the task integrity measurement data (125) and the random number through the one or more encryption keys (503), and the communication interface (113) is used to send the encrypted and protected task integrity measurement data (125) and random number to the proof server (120).

6. The data processing device (110) according to claim 4 or 5, It is characterized in that The one or more cryptographic keys (503) are stored in the isolated memory compartment of the attestation core (303).

7. The data processing device (110) according to any one of the preceding claims, It is characterized in that The processing unit (111) is used to define the plurality of isolated memory compartments.

8. The data processing device (110) according to any one of the preceding claims, It is characterized in that The processing unit (111) is used to monitor the integrity of the isolated memory compartments (115a to 115c) of the multiple tasks (305a to 305c) according to a trampoline module (401) implemented by trampoline code, and the trampoline module (401) is called at each transition between the isolated memory compartments (115a to 115c) of the multiple tasks (305a to 305c), and is used to report to the proof core (303) one or more capabilities exchanged between the isolated memory compartments (115a to 115c) of the multiple tasks (305a to 305c).

9. The data processing device (110) according to any one of the preceding claims, It is characterized in that The processing unit (111) is also used to initially scan the memory (115) to determine the plurality of isolated memory compartments of the memory (115).

10. The data processing device (110) according to any one of the preceding claims, It is characterized in that The processing unit (111) is also used to store the task integrity metric data (125) in the isolated memory compartment of the attestation core (303).

11. The data processing device (110) according to claim 10, It is characterized in that The task integrity metric data (125) includes the one or more capabilities of each respective task (305a to 305c) of the plurality of tasks (305a to 305c).

12. The data processing device (110) according to any one of the preceding claims, It is characterized in that The one or more capabilities of the plurality of capabilities of each task (305a to 305c) include pointers and pointer metadata.

13. The data processing device (110) according to any one of the preceding claims, It is characterized in that The RTOS (300) is a single address space RTOS (300).

14. The data processing device (110) according to any one of the preceding claims, It is characterized in that The security capability architecture is based on hardware and / or software.

15. A remote attestation system (100), It is characterized in that include: At least one data processing device (110) according to any one of the preceding claims; The attestation server (120) is configured to receive the task integrity measurement data (125) from the at least one data processing device (110), and to attest the integrity of the at least one data processing device (110) based on the task integrity measurement data (125).

16. The remote attestation system (100) according to claim 15, It is characterized in that One or more reference capabilities of each task (305a to 305c) of the at least one data processing device (110) are defined by a task policy (145), and the attestation server (120) is used to attest the integrity of the at least one data processing device (110) based on the task integrity measurement data (125) and the task policy (145).

17. A method (600) for proving the integrity of a data processing device (110), It is characterized in that The data processing device (110) is used to execute a plurality of tasks (305a to 305c); the data processing device (110) comprises: a processing unit (111) for running a real-time operating system (RTOS) (300) according to a security capability framework, wherein the RTOS (300) implements a kernel (301), an attestation core (303) and a plurality of tasks (305a to 305c), each task (305a to 305c) using one or more of a plurality of capabilities defined by the security capability framework when executed; a memory (115); the method (600) comprises: providing (601) a plurality of isolated memory compartments of the memory (115), wherein the plurality of isolated memory compartments include an isolated memory compartment of the attestation core (303) and a corresponding isolated memory compartment (115a to 115c) of each task (305a to 305c), the isolated memory compartment (115a to 115c) of each task (305a to 305c) being defined by data on which the one or more of the plurality of capabilities of the task (305a to 305c) and the one or more of the plurality of capabilities of the task (305a to 305c) operate; The integrity of the isolated memory compartments (115a to 115c) of the plurality of tasks (305a to 305c) is monitored (603) to generate task integrity metric data (125) indicating the integrity of the memory compartments (115a to 115c) of the plurality of tasks (305a to 305c).

18. A computer program product comprising a computer readable storage medium, It is characterized in that The computer-readable storage medium is used to store program codes, which, when executed by a computer or a processor, enable the computer or the processor to perform the method (600) according to claim 17.