Credible controller optimization method and system based on core sealing security module
By adopting the dual asymmetric key mechanism based on the nuclear encapsulation security module in the trusted controller of the decentralized control system, the hardware resource consumption, system compatibility and security issues are solved, and more efficient and secure trusted controller optimization is achieved.
Patent Information
- Application Number
- CN202510015294.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-06
- Publication Date
- 2025-06-10
AI Technical Summary
When a trusted controller uses a CPU with trusted startup function and an external trusted computing engine, it will increase hardware resource consumption and requires modification of the circuit structure of the controller motherboard, resulting in inconvenient system compatibility and maintenance. In addition, the initialization of the trustworthiness of the first power-on is insufficient, and there are security risks in data consistency and trust chain file upgrades.
Using a trusted controller optimization method based on the nuclear encrypted security module, by generating two pairs of asymmetric keys, the public key of the first pair of keys is stored in the nuclear encrypted security module, and the public key and file of the second pair of keys are signed using the private keys of the first pair of keys and stored in the storage module. In response to the initial power-on command, the key is read in turn for full trust chain verification, and the core block security module reference value is set based on the verification result, and the trust chain measurement value is verified to start the business process. In response to the update command, the first pair of keys is updated through the nuclear enclosure security module, and the second pair of keys is updated by signing.
It reduces the consumption of controller hardware resources, avoids modification of the circuit structure of the controller motherboard, and improves system compatibility and maintenance convenience. The system's security is enhanced through the dual asymmetric key mechanism, ensuring the security and consistency of first power-up and trust chain file upgrades.
Smart Images

Figure CN120124093A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of trusted security technology, and in particular, to an optimization method and system for a trusted controller based on a kernel seal security module. Background Art
[0002] At present, the trusted controller of a distributed control system (DCS) uses a CPU with a trusted startup function combined with an external trusted computing engine to achieve basic trusted functions. The CPU is responsible for implementing the trusted verification of the controller startup program Uboot. After the Uboot program is successfully started, the subsequent trusted verification functions will be implemented by the external trusted computing engine.
[0003] However, this implementation method of the external trusted computing engine will additionally increase the consumption of hardware resources in the computer device, and at the same time, it is necessary to modify the circuit structure of the controller motherboard, thereby increasing the controller version branches, which is not conducive to system compatibility and maintenance. At the same time, regarding the specific implementation method of the kernel seal security module, current research mostly focuses on the encapsulation method of the trusted computing engine in the CPU, and there is little research on the actual application and implementation method in the trusted controller of the distributed control system. When the controller is powered on for the first time, the reference value in the kernel seal security module is reset, and the files in the trusted trust chain need to be upgraded, the processing method has insufficient credibility initialization and an imperfect recovery mechanism, resulting in data inconsistency problems. Moreover, the public key part of the asymmetric key used in the startup process of the trusted controller of the distributed control system is mostly solidified in the non-volatile area of the TPCM module. When it is necessary to modify the public key part of the asymmetric key, the modification method has a complex update mechanism, authentication failure, or other compatibility problems. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides an optimization method and system for a trusted controller based on a kernel seal security module to solve the problems that the trusted controller of the current distributed control system using a CPU with a trusted startup function combined with an external trusted computing engine will additionally increase the consumption of hardware resources, and at the same time, it is necessary to modify the circuit structure of the controller motherboard, which is not conducive to system compatibility and maintenance, and there are problems such as insufficient credibility initialization during the first power-on, security risks in data consistency and trust chain file upgrade.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides an optimization method for a trusted controller based on a kernel seal security module, including: generating two pairs of asymmetric keys, and storing the public key of the first pair of keys in the kernel seal security module;
[0008] Sign the public key of the second pair of keys with the private key of the first pair of keys, and sign the first type of file with the private key of the second pair of keys, and store them in the first storage module;
[0009] Sign the second type of file with the private key of the second pair of keys and store it in the second storage module;
[0010] In response to the initial power-on command, sequentially read the public keys of the two pairs of keys for full trust chain verification signature, and set the kernel seal security module reference value based on the measurement value of the full trust chain;
[0011] After the kernel seal security module reference value is assigned and set, verify the measurement value of the full trust chain through the kernel seal security module reference value, and start the service process based on the verification result;
[0012] In response to the update command, update the first pair of secret keys through the kernel seal security module, and update the second pair of keys by signing the second pair of keys.
[0013] As a preferred solution of the trusted controller optimization method based on the kernel seal security module of the present invention, wherein: the generation of the two pairs of asymmetric keys includes:
[0014] Generate two pairs of asymmetric keys respectively through the sm2 algorithm;
[0015] The private key of the first pair of keys is used to encrypt the public key of the second pair of keys;
[0016] Store and solidify the public key of the first pair of key pairs in the non-volatile area of the kernel seal security module in the CPU;
[0017] The private key of the first pair of key pairs signs and stores the public key of the second pair of key pairs in the first storage module;
[0018] The private keys of the two pairs of asymmetric keys are stored separately by a third party.
[0019] As a preferred solution of the trusted controller optimization method based on the kernel seal security module of the present invention, wherein: the signing includes:
[0020] Calculate the digest of the signing object through the sm3 algorithm to generate the corresponding file digest;
[0021] Perform digital signature on the corresponding file digest using the private key of the key matching the signing object and the private key signing algorithm of sm2 to generate the corresponding signature value.
[0022] As a preferred solution of the trusted controller optimization method based on the kernel seal security module of the present invention, wherein: the sequentially reading the public keys of the two pairs of keys for full trust chain verification signature includes:
[0023] When reading the public key of the second pair of keys signed in the first storage module, the second pair of keys and its first digest are obtained through the public key of the first pair of keys and the signature verification algorithm of SM2.
[0024] The first digest is recalculated through the SM3 algorithm in the kernel seal security module, and it is checked whether the first digest is the same before and after recalculation. If they are the same, the signature verification passes; otherwise, the signature verification fails.
[0025] Before executing the first type of file and the second type of file, the corresponding file digest is obtained through the public key of the second pair of keys and the signature verification algorithm of SM2, the corresponding file digest is recalculated through the SM3 algorithm in the kernel seal security module, and it is checked whether the corresponding file digest is the same before and after recalculation. If they are the same, the signature verification passes; otherwise, the signature verification fails.
[0026] As a preferred solution of the trusted controller optimization method based on the kernel seal security module according to the present invention, wherein: setting the benchmark value of the kernel seal security module based on the measurement value of the full trust chain includes:
[0027] The public key of the second pair of keys signed, the first type of file, the second type of file, and the measurement values of the critical processes are stored in the kernel seal security module as the benchmark value of the kernel seal security module.
[0028] Set the flag for assigning the benchmark value of the kernel seal security module.
[0029] As a preferred solution of the trusted controller optimization method based on the kernel seal security module according to the present invention, wherein: verifying the measurement value of the full trust chain through the benchmark value of the kernel seal security module and starting the service process based on the verification result includes:
[0030] When the benchmark value of the kernel seal security module is the same as the measurement value, continue to start the next service of the trust chain.
[0031] If the benchmark value of the kernel seal security module is different from the measurement value, re-verify the relevant files.
[0032] If the signature verification is successful, re-assign the benchmark value of the relevant files in the kernel seal security module and continue to start the next service of the trust chain.
[0033] If the signature verification fails, suspend the start, repair the relevant files, and then power on again.
[0034] After all service processes are started, perform periodic dynamic trusted verification on the service processes to achieve the measurement verification of the full trusted chain of the trusted controller.
[0035] As a preferred solution of the trusted controller optimization method based on the kernel seal security module according to the present invention, wherein: in response to an update command, the first pair of secret keys is updated through the kernel seal security module, and the second pair of keys is updated by signing the second pair of keys, including:
[0036] In response to the first update command from the CPU and a third party, the public key of the first pair of keys is jointly updated in the non-volatile area of the kernel seal security module;
[0037] In response to the second update command from the third party, the private key of the first pair of keys re-signs the public key of the second pair of keys, and the relevant files in the trust chain are started by combining the signature of the private key of the second pair of keys to achieve the update of the second pair of keys.
[0038] In a second aspect, the present invention provides a trusted controller optimization system based on a kernel seal security module, including: a secret key generation module for generating two pairs of asymmetric keys, and the public key of the first pair of secret keys is stored in the kernel seal security module;
[0039] A first signature module for signing the public key of the second pair of keys with the private key of the first pair of keys and signing the first type of file with the private key of the second pair of keys, and storing them in the first storage module;
[0040] A second signature module for signing the second type of file with the private key of the second pair of keys and storing it in the second storage module;
[0041] A signature verification module for, in response to an initial power-on command, sequentially reading the public keys of the two pairs of keys for full trust chain signature verification, and setting the reference value of the kernel seal security module based on the measurement value of the full trust chain;
[0042] A comparison module for, after the reference value of the kernel seal security module is assigned and set, verifying the measurement value of the full trust chain through the reference value of the kernel seal security module, and starting a service process based on the verification result;
[0043] An update module, in response to an update command, updates the first pair of secret keys through the kernel seal security module, and updates the second pair of keys by signing the second pair of keys.
[0044] In a third aspect, the present invention provides an electronic device, including:
[0045] A memory and a processor;
[0046] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, and when the computer-executable instructions are executed by the processor, the steps of the trusted controller optimization method based on the kernel seal security module are implemented.
[0047] Fourthly, the present invention provides a computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the method for optimizing a trusted controller based on a core-sealed security module.
[0048] Compared with the prior art, the beneficial effects of the present invention are as follows: Through the design of two pairs of asymmetric key pairs, the present invention uses the first pair of keys to verify the public key of the second pair of keys, so that DCS manufacturers can update the public and private keys of the second pair of keys by modifying the data in the first storage module (external startup module), without modifying the core-sealed security module in the CPU chip, nor requiring engineers to manually operate and modify each time, improving the convenience of key update for the trusted controller. At the same time, the risk of key leakage is reduced by using two pairs of keys; and through the trusted controller of the core-sealed security module, the trusted computing technology is integrated into the CPU of the trusted controller, eliminating the need for an external trusted computing engine, thus eliminating the need to modify the circuit structure of the controller motherboard and reducing the hardware resource consumption of the controller; it is possible to distinguish between a trusted controller and an untrusted controller by only modifying the operation mode of the controller, i.e., the software part, without the need to distinguish the hardware part of the controller, reducing the system compatibility and maintenance costs; by supporting the verification of signatures of all static files in the trusted trust chain, it is possible to provide processing methods for the first power-on, reset of the core-sealed security module reference value, and upgrade of the trust chain node files, without the need for human intervention. Description of the Drawings
[0049] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0050] Figure 1 It is a schematic diagram of the overall process of the method for optimizing a trusted controller based on a core-sealed security module according to an embodiment of the present invention;
[0051] Figure 2 It is a schematic diagram of the architecture of a trusted controller in the method for optimizing a trusted controller based on a core-sealed security module according to an embodiment of the present invention;
[0052] Figure 3 It is a flowchart of a trusted controller assigning a reference value to a security server module after power-on in the method for optimizing a trusted controller based on a core-sealed security module according to an embodiment of the present invention;
[0053] Figure 4 It is a flowchart of a trusted controller after power-on after writing the reference value in the method for optimizing a trusted controller based on a core-sealed security module according to an embodiment of the present invention. Detailed implementation manners
[0054] To make the above objects, features and advantages of the present invention more obvious and understandable, the following detailed description of the specific implementation manners of the present invention will be given with reference to the accompanying drawings of the specification. Obviously, the described embodiments are part of the embodiments of the present invention, rather than all embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0055] Embodiment 1
[0056] Referring to Figure 1 , an embodiment of the present invention provides an optimization method for a trusted controller based on a kernel seal security module, including:
[0057] S100: Generate two pairs of asymmetric keys, and store the public key of the first pair of keys in the kernel seal security module;
[0058] S200: Sign the public key of the second pair of keys with the private key of the first pair of keys, and sign the first type of files with the private key of the second pair of keys, and store them in the first storage module;
[0059] S300: Sign the second type of files with the private key of the second pair of keys, and store them in the second storage module;
[0060] S400: In response to the initial power-on command, sequentially read the public keys of the two pairs of keys for full trust chain signature verification, and set the kernel seal security module reference value based on the measurement value of the full trust chain;
[0061] S500: After the kernel seal security module reference value is assigned and set, verify the measurement value of the full trust chain through the kernel seal security module reference value, and start the service process based on the verification result;
[0062] S600: In response to the update command, update the first pair of keys through the kernel seal security module, and update the second pair of keys by signing the second pair of keys.
[0063] It should be noted that in order to improve the active network security protection ability of the distributed control system, build a hierarchical protection core technology system based on trusted computing technology, and enhance the endogenous security, active immunity and active defense capabilities of the distributed control system, the controller based on trusted computing has become an important solution.
[0064] Currently, the trusted controller in the distributed control system is responsible for ensuring the integrity, confidentiality, and availability of the system. When it comes to the first power-on, reference value reset, and trust chain file upgrade, if the security state is not correctly initialized during the first power-on, it may not be able to provide a reliable starting point to establish the subsequent trust chain; the lack of an effective mechanism to verify or restore to a known security state results in the system operating in a potentially insecure environment; at the same time, if there is no correct synchronization mechanism during the reset process, it may lead to data consistency problems, for example, different parts of the system may work based on different reference values, thus undermining the overall security; if there are not enough security measures during the upgrade process, such as digital signature verification, etc., malware or tampered code may be mixed into the system, threatening the security of the entire trust chain.
[0065] Therefore, through the technical solutions of steps S100 - S600, two pairs of asymmetric keys are introduced, and combined with the kernel seal security module, the kernel seal security module, and the storage module, a highly secure trust chain mechanism is constructed; the dual asymmetric key mechanism makes it more difficult for attackers to crack or tamper with the key data in the system. Each step from the initial power-on to the start of the service process depends on the verification results of the previous steps, ensuring the integrity and immutability of the entire trust chain; by signing the files and keys, unauthorized modifications can be effectively prevented, ensuring the authenticity and integrity of the files.
[0066] Embodiment 2
[0067] Refer to Figures 1-4 , which is an embodiment of the present invention. Based on the above embodiment, an optimization method for a trusted controller based on the kernel seal security module is provided.
[0068] In the embodiment of the present application, in step S100, two pairs of asymmetric keys are generated, including the following steps: two pairs of asymmetric keys are respectively generated through the SM2 algorithm;
[0069] The public key of the first pair of keys is stored in the kernel seal security module;
[0070] The private key of the first pair of keys is used to encrypt the public key of the second pair of keys;
[0071] The public key of the first pair of key pairs is stored and solidified in the non-volatile area of the kernel seal security module in the CPU;
[0072] The private key of the first pair of key pairs signs and stores the public key of the second pair of key pairs in the first storage module;
[0073] The private keys of the two pairs of asymmetric keys are stored separately by a third party.
[0074] Specifically, the confidentiality level of the private key of the first pair of keys is higher than that of the private key of the second pair of keys.
[0075] In the embodiment of the present application, the core seal security module is preferably a TPCM chip, which focuses on capabilities such as active measurement; the third party is the DCS manufacturer. The DCS manufacturer uses the SM2 algorithm to determine the elliptic curve parameters to be used, initializes the key generator, and generates two pairs of key pairs respectively. The private keys of the two pairs of keys are separately stored by the DCS manufacturer; the private key of the first pair of keys is used to encrypt the public key of the second pair of keys, and the private key of the second pair of keys is used to encrypt the Uboot-related files. The DCS manufacturer notifies the CPU manufacturer of the public key of the first pair of key pairs, and the CPU manufacturer stores this public key in the CPU and solidifies it in the non-volatile area of the core seal security module. The DCS manufacturer signs and stores the public key of the second pair of key pairs with the private key of the first pair of key pairs in the first storage module of the controller. The first storage module supported by the controller is a Flash chip, that is, an external startup module.
[0076] In an alternative embodiment, the core seal security module can be replaced by an external trusted chip, and the corresponding hardware circuit is modified to implement storage and subsequent steps.
[0077] In another alternative embodiment, the third party can also be an independent security service provider or a hosting service provider, etc., which can be determined according to specific security requirements, organizational structures, regulations and other factors.
[0078] In the embodiment of the present application, as Figure 2 shown, the signing in steps S200 and S300 includes the following steps A1 - A2:
[0079] A1: Calculate the digest of the signing object through the sm3 algorithm to generate the corresponding file digest;
[0080] A2: Use the private key of the key matching the signing object and the private key signing algorithm of sm2 to perform digital signature on the corresponding file digest to generate the corresponding signature value.
[0081] Exemplarily, calculating the digest of the signing object through the sm3 algorithm to generate the corresponding file digest can be:
[0082] Signing the public key of the second pair of keys with the private key of the first pair of keys includes the following steps:
[0083] Calculate the digest of the public key of the second pair of keys through the sm3 algorithm to generate the first digest;
[0084] Use the private key of the first pair of keys and the private key signing algorithm of sm2 to perform digital signature on the first digest to generate the signature value;
[0085] Signing the first type of file with the private key of the second pair of keys includes the following steps:
[0086] Calculate the digest of the Uboot file through the SM3 algorithm to generate a second digest;
[0087] Perform a digital signature operation on the second digest using the private key of the second key pair and the private key signing algorithm of SM2 to generate a signature value.
[0088] Package the public key of the second key pair after signing and the Uboot-related files into the first storage module of the controller, namely the Flash chip.
[0089] Sign the second type of file using the private key of the second key pair, including the following steps:
[0090] Calculate the digest of the operating system file through the SM3 algorithm to generate a third digest;
[0091] Perform a digital signature on the third digest using the private key of the second key pair and the private key signing algorithm of SM2 to generate a signature value;
[0092] Calculate the digest of the business software through the SM3 algorithm to generate a fourth digest;
[0093] Perform a digital signature on the fourth digest using the private key of the second key pair and the private key signing algorithm of SM2 to generate a signature value.
[0094] Store the above-mentioned second type of file and the signature in the second storage module, namely the SD card.
[0095] In an alternative embodiment, the signing operations in steps S200 and S300 can also be implemented through the SHA-256 and RSA algorithms. Use the SHA-256 algorithm to replace the SM3 algorithm to calculate the digest of the signing object, and use the RSA algorithm to perform a digital signature on the digest generated by SHA-256.
[0096] In another alternative embodiment, the signing operations in steps S200 and S300 can also be implemented by using the SHA-3 algorithm (Keccak function) to calculate the digest of the signing object; use the Elliptic Curve Digital Signature Algorithm (ECDSA) to perform a digital signature on the digest generated by SHA-3.
[0097] In the embodiment of the present application, the initial power-on command in step S400 is the initial power-on command generated by the controller when the controller is powered on for the first time or when the reference value of the core seal security module is in the reset state; the core seal security module starts first. When the core seal security module of the CPU starts first as a trusted root, at this time the Uboot has not started. The CPU can read the public key of the first key pair through the one-time programmable memory or the non-volatile area of the core seal security module, and then perform the verification of the full trust chain and set the reference value of the core seal security module.
[0098] In the embodiments of the present application, as Figure 3 shown, in step S400, the public keys of two pairs of keys are read in sequence for full trust chain signature verification, including the following steps B1 - B2:
[0099] B1: When reading the public key of the second pair of keys signed in the first storage module, obtain the second pair of keys and its first digest through the public key of the first pair of keys and the sm2 signature verification algorithm; recalculate the first digest through the sm3 algorithm in the kernel seal security module, and compare whether the first digest is the same before and after recalculation. If it is the same, the signature verification passes; if it is different, the signature verification fails.
[0100] It should be noted that if the signature verification passes, it proves that the digital signature of the second pair of keys is signed by the private key holder of the first pair of keys, and it is confirmed that the public key of the second pair of keys has not been tampered with, and the public key of the second pair of keys can be obtained.
[0101] If the signature verification fails, it proves that this public key has been tampered with, and the system pauses to start.
[0102] B2: Before executing the first - type file and the second - type file, obtain the corresponding file digest through the public key of the second pair of keys and the sm2 signature verification algorithm, recalculate the corresponding file digest using the sm3 algorithm in the kernel seal security module, and compare whether the corresponding file digest is the same before and after recalculation. If it is the same, the signature verification passes; if it is different, the signature verification fails.
[0103] Exemplarily, in step B2, before executing the first - type file and the second - type file, for full trust chain signature verification, it may specifically include the following steps:
[0104] B21: Before executing the first - type file, obtain the second digest through the public key of the second pair of keys and the sm2 signature verification algorithm, recalculate the second digest using the sm3 algorithm in the kernel seal security module, and compare whether the second digest is the same before and after recalculation. If it is the same, the signature verification passes; if it is different, the signature verification fails.
[0105] It should be noted that if the signature verification passes, it proves that the digital signature of the first - type file is signed by the private key holder of the second pair of keys, and it is confirmed that the first - type file has not been tampered with.
[0106] If the signature verification fails, it proves that the first - type file has been tampered with, and the system pauses to start.
[0107] B22: Before executing the second type of file, obtain the third digest (operating system file digest) and the fourth digest (business software file digest) through the public key of the second pair of keys and the sm2 signature verification algorithm. Use the sm3 algorithm in the kernel seal security module to recalculate the second digest, and compare whether the second digest is consistent before and after recalculation. If it is consistent, the signature verification passes; if it is inconsistent, the signature verification fails. It should be noted that if the signature verification passes, it proves that the digital signature of the second type of file is signed by the private key holder of the second pair of keys, and it is confirmed that the operating system-related files have not been tampered with.
[0108] If the signature verification fails, the second type of file has been damaged, and the system suspends startup.
[0109] In an alternative embodiment, in step S400, sequentially reading the public keys of two pairs of keys for full trust chain signature verification can also be performed by calculating multiple digests of the same signing object using a multi-hash algorithm combination, and verifying through a multi-signature verification mechanism.
[0110] In another alternative embodiment, in step S400, sequentially reading the public keys of two pairs of keys for full trust chain signature verification can also be performed by, during signature verification, checking the timestamp information of each signature to confirm that the signature is completed within the valid period; or introducing a certificate chain, and during signature verification, not only verifying the directly associated public key but also tracing back to the root certificate authority (CA).
[0111] It should be noted that after all business processes are started, it is determined whether the signature verification of all files is successful. If all are successful, proceed to the next step. If there are unsuccessful files, display the log information, locate the specific failed files, and then repair the relevant information in the SD card and power on again. The method of displaying the log information can be implemented through a trusted management platform or a DCS monitoring platform.
[0112] In the embodiment of the present application, in step S400, setting the kernel seal security module reference value based on the measurement value of the full trust chain includes:
[0113] Store the measurement values of the public key of the second pair of signed keys, the first type of file, the second type of file, and the critical process as the reference value of the kernel seal security module into the kernel seal security module;
[0114] Set the flag for assigning the kernel seal security module reference value.
[0115] Exemplarily, the above steps are to store the measurement values of the public key of the second pair of signed keys, Uboot-related files, operating system-related files, business system-related files, and critical processes as the reference value into the kernel seal security module, and set the flag for assigning the kernel seal security module reference value.
[0116] It should be noted that the above steps are used to implement the entire process of the trusted controller assigning the reference value to the kernel seal security module after power-on and to implement the periodic dynamic trusted measurement of the system's key processes.
[0117] In the embodiment of the present application, in step S500, the measurement value of the entire trust chain is verified through the reference value of the kernel seal security module, and the business process is started based on the verification result, including the following steps C1 - C5:
[0118] C1: When the reference value of the kernel seal security module is consistent with the measurement value, the next business of the trust chain is continued;
[0119] C2: If the reference value of the kernel seal security module is inconsistent with the measurement value, the relevant files are re-signed;
[0120] C3: If the signature verification is successful, the reference value of the relevant files in the kernel seal security module is re-assigned, and the next business of the trust chain is continued;
[0121] C4: If the signature verification fails, the startup is suspended, and after the relevant files are repaired, the power is turned on again;
[0122] C5: After all business processes are started, periodic dynamic trusted verification is performed on the business processes to implement the measurement verification of the entire trusted chain of the trusted controller.
[0123] Exemplarily, all file verification steps of the reference value and the measurement value are as Figure 4 shown.
[0124] It should be noted that the measurement values of the relevant files of the key business processes are periodically and dynamically verified to check whether they are consistent with the reference values. If the verification result is yes, the periodic dynamic verification of the key business processes is continued. If the verification result is no, the failure log is written into the tcmp chip, and then alarm and exception handling are performed. The exception handling requires the operator to confirm according to the alarm content, and then restart the controller.
[0125] It should also be noted that in the embodiment of the present application, the reference value in the tpcm chip is used to verify the measurement value of the entire trust chain, which can support the static file upgrade process. After the controller is restarted, there is no need to perform the signature verification of the public and private keys, and the reference value in the tpcm chip is directly used to verify the measurement values of the Uboot-related files, the operating system-related files, and the business system-related files.
[0126] In an alternative embodiment, the startup of the service process in step S500 can also be achieved by introducing more layers of verification mechanisms and isolation areas. For cases of inconsistency or the need for re-signature verification, relevant files and processes are placed in an isolation area for execution. The environment within the isolation area is isolated from the main system, allowing repair operations or updates to be performed in a controlled environment, thereby reducing the threat of potential risks to the entire system and allowing the trust levels of these files and processes to be dynamically adjusted.
[0127] In another alternative embodiment, the startup of the service process in step S500 can also be achieved by using smart contracts to define and manage verification rules. When the measured value does not match the reference value, the smart contract can automatically decide whether to re-sign, repair files, or suspend startup. Additionally, data during the verification process can be continuously collected and analyzed using machine learning algorithms to improve future verification strategies. For example, identifying which types of files or processes are more prone to problems, thereby optimizing resource allocation and security measures.
[0128] In the embodiment of the present application, in response to an update command in step S600, the first pair of keys is updated through the kernel seal security module, and the second pair of keys is updated by signing the second pair of keys, including:
[0129] In response to the first update command from the CPU and a third party, the public key of the first pair of keys is jointly updated in the non-volatile area of the kernel seal security module;
[0130] In response to the second update command from the third party, the private key of the first pair of keys re-signs the public key of the second pair of keys, and the relevant files in the trust chain are started by combining the signature of the private key of the second pair of keys to achieve the update of the second pair of keys.
[0131] Exemplarily, for the above reasons, the specific steps of step S600 are as follows:
[0132] When updating the first pair of keys:
[0133] First, the first pair of keys is regenerated to generate an asymmetric public key and private key; then, the CPU manufacturer cooperates to update the public key of the first pair of keys in the non-volatile area of the TPCM module. At the same time, the public key of the second pair of keys is signed with the new private key of the first pair of keys, and the modified file is re-burned into the flash chip;
[0134] After power-on again, if the measured value of the signed public key of the second pair of keys does not match the reference value, the system will reset the reference value assignment flag bit in the tcmp chip, and then enter the process of full-process verification and reference value assignment for the re-verification files.
[0135] When updating the second pair of keys:
[0136] Regenerate the second pair of keys to generate a new asymmetric public key and private key;
[0137] The DCS manufacturer signs the public key of the new second pair of keys with the private key of the first pair of keys, signs the Uboot-related files with the public key of the new second pair of keys, and burns the updated files into the flash chip.
[0138] The DCS manufacturer signs the operating system-related files with the public key of the new second pair of keys, signs the business system-related files with the public key of the new second pair of keys, and downloads the updated files to the SD card.
[0139] After powering on again, if the measured value of the public key of the signed second pair of keys is inconsistent with the reference value, the system will reset the reference value assignment flag bit in the tcmp chip, and then enter the process of fully verifying the signed files and assigning the reference value again.
[0140] It should be noted that the usage frequencies of the two pairs of asymmetric keys are different. The usage frequency of the first pair of keys is lower than that of the second pair of keys. The second pair of keys is required during the system upgrade process. When the system is upgraded, the private key of the second pair of keys is used to sign the Uboot-related files, the operating system kernel, the operating system, and the business software, so the usage frequency is high. The first pair of keys is only used when the second pair of keys is updated. When the second pair of keys is updated, the private key of the first pair of keys is used to sign the public key of the second pair of keys, so the usage frequency is low. Therefore, the update frequency of the first pair of keys is much lower than that of the second pair of keys. Therefore, by adopting the above steps, the confidentiality of the first pair of keys is higher than that of the second pair of keys, and the two-layer key method reduces the risk of key leakage and also improves the convenience of the DCS manufacturer to modify the keys.
[0141] In an alternative embodiment, the process of updating the keys in step S600 can also be implemented by introducing a key escrow and multi-signature mechanism, and using a third-party key escrow service to manage the update of the first and second pairs of keys. The escrow service provider can store the private keys in a highly secure environment and provide the necessary access rights only when receiving a legitimate authorization command; a multi-signature mechanism is introduced during the update process, that is, multiple authorizing parties (such as the CPU, the third party, and possibly other stakeholders) need to jointly sign to complete the update operation.
[0142] In another alternative embodiment, the process of updating the keys in step S600 can also be implemented by adopting a distributed key update protocol and using threshold signatures. In this scenario, only when a certain number of nodes agree and participate in the signature can a new key pair be successfully generated or an existing key be updated.
[0143] Embodiment 3
[0144] The above is a schematic solution of an optimization method for a trusted controller based on a kernel seal security module in this embodiment. It should be noted that the technical solution of the system for optimizing the trusted controller based on the kernel seal security module belongs to the same concept as the technical solution of the above-mentioned optimization method for the trusted controller based on the kernel seal security module. For the details not described in the technical solution of the system for optimizing the trusted controller based on the kernel seal security module in this embodiment, reference can be made to the description of the technical solution of the above-mentioned optimization method for the trusted controller based on the kernel seal security module.
[0145] This embodiment also provides a system for an optimization method for a trusted controller based on a kernel seal security module, including:
[0146] A key generation module, configured to generate two pairs of asymmetric keys, and the public key of the first pair of keys is stored in the kernel seal security module;
[0147] A first signature addition module, configured to sign the public key of the second pair of keys with the private key of the first pair of keys, and sign the first type of file with the private key of the second pair of keys, and store them in the first storage module;
[0148] A second signature addition module, configured to sign the second type of file with the private key of the second pair of keys, and store it in the second storage module;
[0149] A signature verification module, configured to, in response to an initial power-on command, sequentially read the public keys of the two pairs of keys for full trust chain signature verification, and set the kernel seal security module reference value based on the measurement value of the full trust chain;
[0150] A comparison module, configured to, after the kernel seal security module reference value is assigned and set, verify the measurement value of the full trust chain through the kernel seal security module reference value, and start a service process based on the verification result;
[0151] An update module, configured to, in response to an update command, update the first pair of keys through the kernel seal security module, and update the second pair of keys by signing the second pair of keys.
[0152] This embodiment also provides an electronic device, applicable to the situation of optimizing a trusted controller based on a kernel seal security module, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the optimization method for a trusted controller based on a kernel seal security module as proposed in the above embodiment.
[0153] This embodiment also provides a storage medium, on which a computer program is stored, and when the program is executed by a processor, it implements the optimization method for a trusted controller based on a kernel seal security module as proposed in the above embodiment.
[0154] The storage medium proposed in this embodiment and the method for optimizing a trusted controller based on a kernel seal security module proposed in the above embodiment belong to the same inventive concept. Technical details not described in detail in this embodiment can be referred to in the above embodiment, and this embodiment has the same beneficial effects as the above embodiment.
[0155] From the above description of the embodiments, those skilled in the art can clearly understand that the present invention can be implemented by means of software and necessary general-purpose hardware, and of course, it can also be implemented by hardware. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as a floppy disk, read-only memory (ROM), random access memory (RAM), flash memory (FLASH), hard disk, or optical disc of a computer, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of various embodiments of the present invention.
[0156] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A trusted controller optimization method based on a nuclear seal security module, characterized in that: include: Generate two pairs of asymmetric keys, and the public key of the first pair of keys is stored in the core-sealed security module; The public key of the second key pair is signed with the private key of the first key pair, and the first category of files is signed with the private key of the second key pair, and both are stored in the first storage module; Signing the second type of files with the private key of the second pair of keys and storing them in the second storage module; In response to the initial power-on command, the public keys of the two key pairs are read in sequence to perform full trust chain signature verification, and the reference value of the sealed security module is set based on the measurement value of the full trust chain; After the baseline value of the sealed security module is assigned and set, the measurement value of the full trust chain is verified through the baseline value of the sealed security module, and the business process is started based on the verification result; In response to the update command, the first pair of keys is updated through the sealing security module, and the second pair of keys is updated by signing the second pair of keys.
2. The trusted controller optimization method based on the nuclear sealing security module according to claim 1, characterized in that: The generating of two pairs of asymmetric keys comprises: Generate two pairs of asymmetric keys using the sm2 algorithm; The private key of the first pair of keys is used to encrypt the public key of the second pair of keys; The public key of the first key pair is stored and fixed in the non-volatile area of the core-sealed security module in the CPU; The private key of the first key pair signs the public key of the second key pair and stores it in the first storage module; The private keys of the two asymmetric key pairs are stored separately by a third party.
3. The trusted controller optimization method based on the nuclear sealing security module according to claim 2, characterized in that: The signing includes: The digest of the signed object is calculated using the SM3 algorithm to generate the corresponding file digest; Use the private key that matches the key of the signing object and the private key signing algorithm of sm2 to digitally sign the corresponding file summary line and generate the corresponding signature value.
4. The trusted controller optimization method based on the nuclear sealing security module according to claim 3 is characterized in that: The process of sequentially reading the public keys of the two pairs of keys to perform full trust chain signature verification includes: When reading the public key of the second pair of keys signed in the first storage module, the second pair of keys and the first digest thereof are obtained by using the public key of the first pair of keys and the decryption algorithm of sm2; Recalculate the first digest using the sm3 algorithm in the security module, and compare the first digest before and after the recalculation to see if they are consistent. If they are consistent, the signature verification passes; otherwise, the signature verification fails. Before executing the first and second types of files, obtain the corresponding file digest through the public key of the second pair of keys and the sm2 decryption algorithm, and use the sm3 algorithm in the nuclear sealing security module to recalculate the corresponding file digest. Compare the consistency of the corresponding file digests before and after recalculation. If they are consistent, the signature verification passes; otherwise, the signature verification fails.
5. The trusted controller optimization method based on the nuclear sealing security module according to claim 4, characterized in that: The step of setting the reference value of the nuclear sealing security module based on the measurement value of the full trust chain includes: The public key of the second key pair that is signed, the first type of files, the second type of files and the measurement value of the key process are stored in the nuclear sealing security module as the reference value of the nuclear sealing security module; Set the flag for assigning the baseline value of the nuclear seal safety module.
6. The trusted controller optimization method based on the nuclear sealing security module according to claim 5, characterized in that: Verify the measurement value of the full trust chain through the baseline value of the sealed security module, and start the business process based on the verification result, including: When the baseline value of the sealed security module is consistent with the measured value, the next step of the trust chain is initiated; If the baseline value of the sealing safety module is inconsistent with the measurement value, the relevant documents will be re-verified; If the signature verification is successful, the baseline value of the relevant file in the sealing security module will be reassigned, and the next step of the trust chain will be started; If the signature verification fails, the startup will be suspended, and the relevant files will be repaired and the power will be restarted; After all business processes are started, periodic dynamic trust verification is performed on the business processes to achieve full trust chain measurement verification of the trusted controller.
7. The trusted controller optimization method based on the nuclear sealing security module according to claim 6, characterized in that: In response to the update command, the first pair of keys are updated by the nuclear sealing security module, and the second pair of keys are updated by signing the second pair of keys, including: In response to a first update command from the CPU and a third party, jointly updating a public key of the first pair of keys in a non-volatile area of the core-sealed security module; In response to the second update command from the third party, the private key of the first pair of keys re-signs the public key of the second pair of keys, and starts the relevant files in the trust chain in combination with the signature of the private key of the second pair of keys to update the second pair of keys.
8. A system for the trusted controller optimization method based on a nuclear seal security module according to any one of claims 1 to 7, characterized in that: include: The secret key generation module is used to generate two pairs of asymmetric keys, and the public key of the first pair of secret keys is stored in the nuclear sealing security module; A first signing module, used to sign the public key of the second key pair with the private key of the first key pair, and to sign the first category of files with the private key of the second key pair, and store both in the first storage module; A second signing module, used to sign the second type of file using the private key of the second pair of keys, and store the signed file in the second storage module; The signature verification module is used to respond to the initial power-on command, read the public keys of the two pairs of keys in sequence to perform full trust chain signature verification, and set the reference value of the sealed security module based on the measurement value of the full trust chain; The comparison module is used to verify the measurement value of the full trust chain through the baseline value of the sealed security module after the baseline value of the sealed security module is assigned and set, and the business process is started based on the verification result; The update module, in response to the update command, updates the first pair of keys through the sealing security module, and updates the second pair of keys by signing the second pair of keys.
9. An electronic device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, the steps of the trusted controller optimization method based on the core-sealed security module described in any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium storing computer-executable instructions, which, when executed by a processor, implement the steps of the trusted controller optimization method based on a core-sealed security module as described in any one of claims 1 to 7.