Firmware simulation method based on data encryption and active defense

By building a sandbox-like environment in the system environment and configuring encryption and access control modules, the problems of insufficient data encryption performance and active defense response lag in the existing technology are solved, and a firmware simulation method with high reliability and security is realized.

CN120046170AActive Publication Date: 2025-05-27SHANGHAI ANBAN INFORMATION TECH CO LTD
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
CN202510164018.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-27
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

Existing data encryption technologies have insufficient performance management, resulting in system performance degradation; active defense tools lag in response to advanced persistent threats and are unable to respond quickly to and deal with all potential security incidents.

Method used

A firmware simulation method based on data encryption and active defense is proposed. By building an independent sandbox environment in the system environment, the main sandbox program is configured, including encryption module, access control module, simulation module and fuzzy testing module, the active defense of reliable data encryption and access control is realized.

Benefits of technology

Improves the reliability and security of firmware simulation processes, ensures data security, reduces the risk of system performance degradation, and improves response to advanced persistent threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120046170A_ABST
    Figure CN120046170A_ABST
Patent Text Reader

Abstract

The invention discloses a firmware simulation method based on data encryption and active defense, and the method comprises the following steps: constructing an independent sandbox-like environment in a system environment, and configuring a sandbox main program in the sandbox-like environment; the sandbox main program comprises an encryption module, an access control module, a simulation module and a fuzzy test module; a security policy is configured in the sand box-like environment; the simulation module loads firmware to carry out firmware simulation; when a certain functional block of the simulation firmware needs to access specific resources outside the sandbox-like environment, whether access is allowed or not is confirmed through the access control module; if the access is allowed, carrying out identity authentication on resources outside the sandbox environment and then calling the resources; if access is not allowed, the block is skipped to conduct simulation of the next block until firmware simulation is finished; when data transmission is carried out in the simulation process, the data are encrypted through the encryption module; in the simulation process, the firmware is subjected to fuzz testing through the fuzz testing module.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present invention relate to the technical field of fuzz testing, and in particular to a firmware simulation method based on data encryption and active defense. Background Art

[0002] Currently, data encryption and active defense technologies are two major pillars in the field of information security, aiming to protect sensitive information and systems from various network threats. The current state of encryption technology shows maturity and widespread application. Especially the popularity of end-to-end encryption has become a standard configuration for communication applications, protecting user privacy and security. On the other hand, active defense technologies are constantly evolving to cope with increasingly complex security threats. By analyzing traffic and detecting abnormal behaviors, the system can respond quickly. Next-generation firewalls (NGFWs) combine multiple security measures, enhancing the ability to handle complex threats. With the introduction of threat intelligence platforms, security systems can utilize shared threat data to strengthen defense measures. In the current state of simulation technology, the improvement of computing power and algorithms has made high-fidelity simulation possible, which can accurately simulate the dynamic behavior of complex systems.

[0003] However, the above technologies still have the following obvious deficiencies:

[0004] Although data encryption technology plays an important role in protecting information security, it has significant deficiencies in performance management. The encryption and decryption processes require additional computing resources, which may lead to a decline in system performance when dealing with a large amount of data.

[0005] Active defense tools need to rely on a large amount of data and analysis capabilities, which have relatively high requirements for resources, and the real-time response ability is often limited. Even so, these systems may still have a problem of delayed response when facing advanced persistent threats (APTs), which may result in the inability to quickly respond to and handle all potential security incidents.

[0006] Therefore, it is necessary to provide a firmware simulation method based on data encryption and active defense to solve the above problems. Summary of the Invention

[0007] The purpose of the embodiments of the present application is to propose a firmware simulation method based on data encryption and active defense. The present invention realizes reliable data encryption and active defense of access control in the firmware simulation process, improving reliability and security.

[0008] According to one aspect of the present invention, a firmware simulation method based on data encryption and active defense is provided, including the following steps:

[0009] Build an independent class sandbox environment in the system environment, and configure the sandbox main program in the class sandbox environment; the sandbox main program includes an encryption module, an access control module, a simulation module, and a fuzz testing module;

[0010] Configure security policies in the class sandbox environment and initialize the security policies;

[0011] The simulation module loads the firmware for simulation of the firmware;

[0012] When a certain functional block of the firmware being simulated needs to access specific resources outside the class sandbox environment, confirm whether to allow access through the access control module; if access is allowed, authenticate the resources outside the class sandbox environment and then call the resources; if access is not allowed, skip this block and proceed to the simulation of the next block until the firmware simulation ends;

[0013] During data transmission in the simulation process, encrypt the data through the encryption module;

[0014] During the simulation process, perform fuzz testing on the firmware through the fuzz testing module to discover firmware vulnerabilities.

[0015] Preferably, the access control module includes a program monitor and an access rule engine; the program monitor monitors the operation of the sandbox main program in the class sandbox environment and submits the monitored behaviors to the access rule control engine, and the access rule control engine determines whether to allow the sandbox main program to use specific resources outside the class sandbox environment according to the set access rules.

[0016] Preferably, when the program monitor discovers that the sandbox main program runs for more than the set time or set memory, or discovers dangerous system calls, it terminates the operation of the sandbox main program and stops the simulation.

[0017] Preferably, after the access control module confirms that it allows access to specific resources outside the class sandbox environment, it includes the following steps:

[0018] The access control module sends an identity authentication request to the resources outside the class sandbox environment that are data providers, and the resources outside the class sandbox environment send an identity ID to the access control module;

[0019] The access control module confirms that the identity ID of the resources outside the class sandbox environment is qualified and sends an identity authentication qualified message to the encryption module;

[0020] The encryption module sends the encryption algorithm and key to the resource, the proxy server, and the simulation module that is the data user respectively;

[0021] The resources outside the class sandbox environment encrypt the data according to the encryption algorithm and key and upload the ciphertext to the cloud server;

[0022] After obtaining the ciphertext from the cloud server, the simulation module decrypts it according to the encryption algorithm and the key to obtain the decrypted ciphertext, or obtains the ciphertext through the proxy server, decrypts it, and sends the decrypted ciphertext to the simulation module.

[0023] Preferably, the encryption module sends the encryption key PK to the resources outside the sandbox-like environment, sends the attribute key AA-key to the proxy server, and sends the user global key UGSK to the simulation module.

[0024] Preferably, obtaining the ciphertext through the proxy server, decrypting it, and sending the decrypted ciphertext to the simulation module includes:

[0025] The simulation module sends a partial outsourcing decryption request to the proxy server;

[0026] The proxy server sends a ciphertext acquisition request to the cloud server according to the partial outsourcing decryption request;

[0027] The cloud server sends the ciphertext to the proxy server according to the ciphertext acquisition request;

[0028] The proxy server decrypts the ciphertext and returns the decrypted ciphertext to the simulation module.

[0029] Preferably, the encryption algorithm of the encryption module includes multiple rounds of calculation processes, and each round of calculation process includes multiple basic operations, and the basic operations include byte substitution, row shift transformation, column mixing transformation or round key addition transformation.

[0030] Preferably, the encryption algorithm of the encryption module adopts a symmetric block cipher algorithm, the block length is 128 bits, the number of calculation rounds of the encryption algorithm corresponds to the key length, the key length is 128 bits, 192 bits or 256 bits, and the corresponding number of calculation rounds of the encryption algorithm is 10 rounds, 12 rounds or 14 rounds.

[0031] Preferably, the row shift transformation and column mixing transformation operations adopt a Boolean mask, and the input of each round is XORed with the mask value; the column mixing transformation operation adopts a combination of a multiplication mask and a Boolean mask.

[0032] Preferably, the access rules are preset in the security policy.

[0033] A firmware simulation method based on data encryption and active defense disclosed in this application constructs an independent sandbox-like environment in the system environment, configures a sandbox main program in the sandbox-like environment, and configures system resources in the sandbox-like environment to meet the conditional resources required for simulation, so that only the system resources required for firmware operation exist in the simulation environment, and the rest of the resource information of the system will not be accessed by the firmware, which is safer; the sandbox main program includes an encryption module, an access control module, a simulation module, and a fuzz testing module. When accessing some resources outside the sandbox, the access control module is used to restrict the access process to achieve the active defense of access control; when data is transmitted, the encryption module encrypts the data to ensure data security; during the simulation process, the fuzz testing module performs fuzz testing on the firmware to detect firmware vulnerabilities.

[0034] Further, the simulation module can request the proxy server to perform outsourcing decryption. The proxy server obtains the ciphertext and decrypts it, and then sends the decrypted ciphertext to the simulation module, so that the decryption process will not occupy too much computing resources and will not affect the simulation speed.

[0035] Further, the operation of the sandbox main program in the sandbox-like environment is monitored by a program monitor. When the program monitor finds that the sandbox main program runs for more than the set time or set memory, or finds dangerous system calls, it terminates the operation of the sandbox main program and stops the simulation to achieve the active defense of program monitoring. Brief Description of the Drawings

[0036] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention, rather than all embodiments. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0037] Figure 1 is a flowchart of a firmware simulation method based on data encryption and active defense according to an embodiment of the present invention;

[0038] Figure 2 is an architecture diagram of a firmware simulation method based on data encryption and active defense according to an embodiment of the present invention. Detailed Embodiments

[0039] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Apparently, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0040] The following uses specific embodiments to elaborate in detail on the technical solutions of the present invention. These several specific embodiments below can be combined with each other, and for the same or similar concepts or processes, they may not be repeated in some embodiments.

[0041] In view of the problems existing in the prior art, the embodiments of the present invention provide a firmware simulation method based on data encryption and active defense. The present invention realizes reliable data encryption and active defense of access control during the firmware simulation process, improving reliability and security.

[0042] Figure 1 is a flowchart of the firmware simulation method based on data encryption and active defense according to an embodiment of the present invention; Figure 2 is an architecture diagram of the firmware simulation method based on data encryption and active defense according to an embodiment of the present invention.

[0043] As Figure 1 - Figure 2 shown, a firmware simulation method based on data encryption and active defense provided by the embodiments of the present invention includes the following steps:

[0044] S101: Construct an independent sandbox-like environment in the system environment, and configure a sandbox main program in the sandbox-like environment; the sandbox main program includes an encryption module, an access control module, a simulation module, and a fuzz testing module;

[0045] S102: Configure a security policy in the sandbox-like environment and initialize the security policy;

[0046] S103: The simulation module loads the firmware for firmware simulation; when a certain functional block of the simulated firmware needs to access specific resources outside the sandbox-like environment, it is confirmed by the access control module whether access is allowed; if access is allowed, the resources outside the sandbox-like environment are authenticated and then the resources are called; if access is not allowed, the block is skipped and the simulation of the next block is carried out until the firmware simulation ends; during the data transmission in the simulation process, the encryption module encrypts the data;

[0047] S104: During the simulation process, the fuzz testing module performs fuzz testing on the firmware to detect firmware vulnerabilities.

[0048] In some embodiments, the access control module includes a program monitor and an access rule engine; the program monitor monitors the operation of the sandbox main program in the class sandbox environment and submits the monitored behaviors to the access rule control engine, and the access rule control engine determines whether to allow the sandbox main program to use specific resources outside the class sandbox environment according to the set access rules.

[0049] In some embodiments, the access rules are preset in the security policy.

[0050] In some embodiments, when the program monitor discovers that the sandbox main program runs for more than the set time or set memory or discovers a dangerous system call, it terminates the operation of the sandbox main program and stops the simulation.

[0051] In some embodiments, after the access control module confirms that access to specific resources outside the class sandbox environment is allowed, the following steps are included:

[0052] The access control module sends an identity authentication request to the resources outside the class sandbox environment that are data providers, and the resources outside the class sandbox environment send an identity ID to the access control module;

[0053] The access control module confirms that the identity ID of the resources outside the class sandbox environment is qualified and sends identity authentication qualified information to the encryption module;

[0054] The encryption module sends an encryption algorithm and a key to the resource, the proxy server, and the simulation module that is the data user respectively;

[0055] The resources outside the class sandbox environment encrypt the data according to the encryption algorithm and the key and upload the ciphertext to the cloud server;

[0056] After the simulation module obtains the ciphertext from the cloud server, it decrypts the ciphertext according to the encryption algorithm and the key to obtain the decrypted ciphertext, or obtains the ciphertext through the proxy server, decrypts it, and sends the decrypted ciphertext to the simulation module.

[0057] If the access control module confirms that the identity ID of the resources outside the class sandbox environment is unqualified, it determines that the resources outside the class sandbox environment are malicious users and tracks the malicious users.

[0058] In some embodiments, the encryption module sends an encryption key PK to the resources outside the class sandbox environment, an attribute key AA-key to the proxy server, and a user global key UGSK to the simulation module.

[0059] In some embodiments, obtaining the ciphertext through the proxy server, decrypting it, and sending the decrypted ciphertext to the simulation module includes:

[0060] The simulation module sends a partial outsourcing decryption request to the proxy server;

[0061] The proxy server sends a ciphertext acquisition request to the cloud server according to a partial outsourcing decryption request;

[0062] The cloud server sends the ciphertext to the proxy server according to the ciphertext acquisition request;

[0063] The proxy server decrypts the ciphertext and returns the decrypted ciphertext to the simulation module.

[0064] In some embodiments, the encryption algorithm of the encryption module includes multiple rounds of calculation processes. Each round of calculation process includes multiple basic operations, and the basic operations include byte substitution, row shift transformation, column mixing transformation, or round key addition transformation.

[0065] In some embodiments, the encryption algorithm of the encryption module adopts a symmetric block cipher algorithm. The block length is 128 bits. The number of calculation rounds of the encryption algorithm corresponds to the key length. The key length is 128 bits, 192 bits, or 256 bits, and the corresponding number of calculation rounds of the encryption algorithm is 10 rounds, 12 rounds, or 14 rounds.

[0066] In some embodiments, the row shift transformation and column mixing transformation operations adopt Boolean masks, and the input of each round is XORed with the mask value; the column mixing transformation operation adopts a combination of a multiplication mask and a Boolean mask.

[0067] In summary, a firmware simulation method based on data encryption and active defense disclosed in this application constructs an independent sandbox-like environment in the system environment, configures a sandbox main program in the sandbox-like environment, and configures system resources in the sandbox-like environment to meet the conditional resources required for simulation, so that only the system resources required for firmware operation exist in the simulation environment, and the rest of the resource information of the system will not be accessed by the firmware, which is safer; the sandbox main program includes an encryption module, an access control module, a simulation module, and a fuzz testing module. When accessing some resources outside the sandbox, the access process is restricted through the access control module to achieve the active defense of access control; when data is transmitted, the data is encrypted by the encryption module to ensure data security; during the simulation process, the firmware is fuzz tested through the fuzz testing module to discover firmware vulnerabilities.

[0068] Further, the simulation module can request the proxy server to perform outsourcing decryption. The proxy server obtains the ciphertext, decrypts it, and sends the decrypted ciphertext to the simulation module, so that the decryption process will not occupy too much computing resources and will not affect the simulation speed.

[0069] Further, the operation of the sandbox main program in the sandbox-like environment is monitored by a program monitor. When the program monitor finds that the sandbox main program runs for more than the set time or set memory or finds dangerous system calls, it terminates the operation of the sandbox main program and stops the simulation to achieve the active defense of program monitoring.

[0070] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements on some or all of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A firmware simulation method based on data encryption and active defense, characterized in that: The steps include: Building an independent sandbox-like environment in the system environment, and configuring a sandbox main program in the sandbox-like environment; the sandbox main program includes an encryption module, an access control module, a simulation module, and a fuzz testing module; Configure security policies in a sandbox-like environment and initialize security policies; The simulation module loads the firmware to simulate the firmware; When a functional block of the firmware needs to access a specific resource outside the sandbox environment during simulation, the access control module is used to confirm whether access is allowed; if access is allowed, the resource outside the sandbox environment is authenticated and then called; if access is not allowed, the block is skipped and the simulation of the next block is performed until the firmware simulation is completed; When data transmission is performed during the simulation process, the data is encrypted by the encryption module; During the simulation process, the firmware is fuzz tested through the fuzz testing module to discover firmware vulnerabilities.

2. The firmware simulation method based on data encryption and active defense according to claim 1, characterized in that: The access control module includes a program monitor and an access rule engine; the program monitor monitors the operation of the sandbox main program in the sandbox-like environment, and submits the monitored behavior to the access rule control engine, and the access rule control engine determines whether to allow the sandbox main program to use specific resources outside the sandbox-like environment based on the set access rules.

3. The firmware simulation method based on data encryption and active defense according to claim 2, characterized in that: When the program monitor finds that the running of the sandbox main program exceeds the set time or the set memory or finds a dangerous system call, the running of the sandbox main program is terminated and the simulation is stopped.

4. The firmware simulation method based on data encryption and active defense according to claim 1, characterized in that: After the access control module confirms that access to specific resources outside the sandbox environment is allowed, the following steps are included: The access control module sends an identity authentication request to a resource outside the sandbox environment that is a data provider, and the resource outside the sandbox environment sends an identity ID to the access control module; The access control module confirms that the identity ID of the resource outside the sandbox environment is qualified, and sends identity authentication qualification information to the encryption module; The encryption module sends the encryption algorithm and the key to the resource, the proxy server and the simulation module as the data user respectively; Resources outside the sandbox environment encrypt data according to the encryption algorithm and key and upload the ciphertext to the cloud server; The simulation module obtains the ciphertext from the cloud server and decrypts it according to the encryption algorithm and the key to obtain the decrypted ciphertext, or obtains the ciphertext through the proxy server, decrypts it and sends the decrypted ciphertext to the simulation module.

5. The firmware simulation method based on data encryption and active defense according to claim 4 is characterized in that: The encryption module sends an encryption key PK to resources outside the sandbox-like environment, sends an attribute key AA-key to the proxy server, and sends a user global key UGSK to the simulation module.

6. The firmware simulation method based on data encryption and active defense according to claim 4, characterized in that: Obtaining the ciphertext through the proxy server, decrypting the ciphertext and sending the decrypted ciphertext to the simulation module includes: The simulation module makes a partial outsourcing decryption request to the proxy server; The proxy server makes a ciphertext acquisition request to the cloud server according to the partial outsourced decryption request; The cloud server sends the ciphertext to the proxy server according to the ciphertext acquisition request; The proxy server decrypts the ciphertext and returns the decrypted ciphertext to the simulation module.

7. The firmware simulation method based on data encryption and active defense according to claim 1, characterized in that: The encryption algorithm of the encryption module includes multiple rounds of calculation processes, each round of calculation process includes multiple basic operations, and the basic operations include byte replacement, row shift transformation, column confusion transformation or round key addition transformation.

8. The firmware simulation method based on data encryption and active defense according to claim 7, characterized in that: The encryption algorithm of the encryption module adopts a symmetric block cipher algorithm, the block length is 128 bits, the number of calculation rounds of the encryption algorithm corresponds to the key length, the key length is 128 bits, 192 bits or 256 bits, and the corresponding number of calculation rounds of the encryption algorithm is 10 rounds, 12 rounds or 14 rounds.

9. The firmware simulation method based on data encryption and active defense according to claim 7, characterized in that: The row shift transformation and column confusion transformation operations use Boolean masks to perform XOR operations on the input of each round and the mask value; the column confusion transformation operation uses a combination of multiplication mask and Boolean mask.

10. The firmware simulation method based on data encryption and active defense according to claim 2, characterized in that: The access rules are preset in the security policy.

Citation Information

Patent Citations

  • Cluster virtual user system implementation method based on sandbox mechanism

    CN112084491A

  • Implementation method of global data security sandbox based on environment multi-factor identity authentication

    CN115913717A

  • Remote office access method and system based on zero trust

    CN116032533A

  • Secure network access from sandboxed applications

    CN118869234A

  • Advanced security control implementation of proxied cryptographic keys

    US11223489B1