Data security function verification system oriented to Internet of Things and based on data driving

By designing a data-driven data security function verification system in the Internet of Things system and using AOP technology to dynamically verify data security, the problem that the existing technology is difficult to fully cover the execution path in complex scenarios is solved, and the completeness and efficiency of data security verification is achieved.

CN120144429APending Publication Date: 2025-06-13THE THIRD RES INST OF MIN OF PUBLIC SECURITY +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202411891095.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2024-12-19
Filing Date
2024-12-20
Publication Date
2025-06-13

AI Technical Summary

Technical Problem

Existing formal verification and analysis technologies are difficult to fully cover the execution path in complex scenarios such as the Internet of Things, resulting in incomplete identification of data security vulnerabilities.

Method used

Design a data-driven data security function verification system for the Internet of Things. Through the process control module, security policy management module, security policy annotation AOP module, AOP section code module and runtime verification module, we realize the addition and dynamic verification of security labels of application variables and data.

Benefits of technology

The system can fully capture data flow throughout the entire life cycle of data in the Internet of Things, ensure the completeness of data security verification coverage, avoid the defects in the inability to cover runtime behaviors, and improve verification efficiency and accuracy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120144429A_ABST
    Figure CN120144429A_ABST
Patent Text Reader

Abstract

The invention provides a data security function verification system based on data driving for the Internet of Things, and the system mainly comprises a security policy management module which is used for defining a variable name and a data security label mode, and a data security rule verification model; the security policy labeling AOP module is used for adding security labels for all variable names and data in the application program to be verified and analyzed, and the security labels are used as entry points of the aspect-oriented programming AOP data security verification aspect; the AOP section code module is used for generating a section-oriented programming AOP data security verification section code, and the AOP data security verification section code is configured to execute an enhanced logic of a data security rule verification model and a log record according to an activation state and a path of a security label; and the runtime verification module is used for executing the enhanced logic of the data security rule verification model and the log record by the AOP data security verification section code according to the activation state and the path of the security label during runtime so as to realize data security rule verification.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the technical field of formal verification and analysis, and more particularly to a data-driven data security function verification system for the Internet of Things (IoT). Background Art

[0002] Currently, formal verification and analysis techniques have been widely applied to hardware and software systems with extremely high security requirements, such as chips, aerospace, bank payments, medical devices, and IoT wearable devices, covering multiple aspects including system design, functional and security analysis, and verification of functions and security. Static formal verification and analysis refers to the formal representation and verification of system functions and security features based on design documents or source code after the system design and development are completed. However, the formal data security verification models generated by static verification and analysis are often too large, making it difficult to construct usable models in the actual formal verification and analysis process. Currently, formal verification and analysis face problems such as overly broad coverage and excessive complexity, resulting in the explosion of the states of the formal model to be constructed and the inability to obtain effective verification results within reasonable time and resource constraints.

[0003] To solve this problem, some dynamic formal verification and analysis methods during system operation have emerged. Dynamic verification and analysis is to formally represent and verify the system functions and their security features based on the data and code execution flow and states of the actual system when the hardware and software systems are actually running, testing, and in use. However, this runtime dynamic verification method depends on the prior syntactic and semantic analysis of static code and has the defect of being unable to fully cover the execution paths in actual operations. Especially in complex scenarios such as the IoT that need to consider multiple factors such as user behavior, device interaction, and external input, its verification coverage may be incomplete. As a result, the data flow monitored during the runtime of the program code may be missing, making it difficult to fully simulate the variable behaviors in actual execution and comprehensively identify potential data security vulnerabilities. Summary of the Invention

[0004] The present disclosure provides a data-driven data security function verification system for the IoT, which can not only ensure the code coverage of the data-driven data security function verification system for the IoT, but also provide a formal verification and analysis system that can be applied in actual scenarios.

[0005] The present disclosure provides a data-driven data security function verification system for the IoT, the system comprising: A process control module, configured to register an application program to be verified and analyzed, manage and coordinate the interaction and operation of each module within the data security function verification system, and generate a verification and analysis result report; A security policy management module, which is used to define variable names and the security label patterns of data, and to define a data security rule verification model; A security policy annotation AOP module, which is used to add security labels to all variable names and data in the application program to be verified and analyzed, and serves as the entry point of the AOP data security verification aspect for aspect-oriented programming; An AOP aspect code module, which is used to generate AOP data security verification aspect code. The AOP data security verification aspect code is configured to execute the enhanced logic of the data security rule verification model and logging according to the activation status and path of the security label; A runtime verification module, which is used at runtime. The AOP data security verification aspect code executes the enhanced logic of the data security rule verification model and logging according to the activation status and path of the security label, and realizes the functions of data security rule verification and logging.

[0006] Among them, the security label patterns include: Plaintext labels, ciphertext labels, sensitive data labels, variable name encryption labels, data encryption labels, and classification and grading labels, variable names and data labels used by function interfaces within the program package, variable names and data labels used by user-human interaction, variable names and data labels used by security authentication and protocols, variable names and data labels used by external databases and files connected to the program package, and variable names and data labels used by externally called functions and services outside the program package.

[0007] The logging includes the activation status and path records of the security label and the execution records of the data security rule verification.

[0008] Optionally, the step of adding security labels to all variable names and data in the application program to be verified and analyzed and serving as the entry point of the AOP data security verification aspect for aspect-oriented programming includes: according to the security label patterns of the application program to be verified and analyzed defined by the security policy management module, using the first aspect-oriented programming AOP program developed by this module to add security labels to all variable names and data in the static code application package of the application program to be verified and analyzed, and serving as the entry point of the AOP data security verification aspect.

[0009] Optionally, the step of generating AOP data security verification aspect code, where the AOP data security verification aspect code is configured to execute the enhanced logic of the data security rule verification model and logging according to the activation status and path of the security label includes: the AOP data security verification program developed in advance by this module obtains the security label patterns and the data security rule verification model defined by the security policy management module, and generates the AOP data security verification aspect code.

[0010] Further optionally, the system further includes: A data flow logging module for obtaining the log records generated during the execution of a runtime verification module; A global security policy execution module for integrally analyzing the activation status and path records of security tags in the log records of the data flow logging module, determining data flows that depend on the entire data link and the entire life cycle of the data, and performing data security verification on the data flows that depend on the entire data link and the entire life cycle of the data according to the data security rule verification model.

[0011] The beneficial effects of the present disclosure are as follows. Compared with the prior art, the present disclosure has the following advantages: 1) By tagging all variable names and data in the static code application package of the application to be verified and analyzed, including data, databases, module - to - module call parameters and their data, data in human - machine interaction, data and their variables in security authentication and protocols, etc., as the entry points of the AOP aspect, when the system runs (runtime) and passes through and uses variables, data, and their related functions, the AOP aspect data security verification code responds to the activation status and path of the tag to execute the data security verification enhancement logic, realizing rule verification, data flow tracking, and log recording functions. It can completely capture the data flows of the entire life cycle of the data oriented to users and their data behaviors, ensuring the completeness of the data security verification coverage, especially covering the execution paths such as external input, user behavior, and database interaction that need to be considered in the Internet of Things. Its data security verification scope includes not only the front - end App, back - end applications and services, but also comprehensive platforms such as databases, file systems, big data platforms, and message queues, and can fully simulate the variable behaviors of system data in actual execution, ensuring the completeness of the coverage and avoiding the defect that the prior art cannot completely cover the runtime behavior due to the prior syntax and semantic analysis of static code.

[0012] This method not only ensures the code coverage of the data - driven data security function verification system for the Internet of Things, but also provides a formal verification analysis system that can be actually applied.

[0013] 2) The data - driven data security function verification system solution provided by the present disclosure reduces the runtime data flow path set by nearly ten thousand to one hundred thousand times compared with the set of various possible data circulation paths in static analysis, thus greatly compressing the formal verification space and improving the verification efficiency and accuracy.

[0014] 3) Since programming languages that support the AOP security enhancement modification mechanism implement their security verification and analysis by uniformly applying the same security verification and analysis strategy for label and code modification, the data-driven data security function verification system solution provided by the present disclosure is adapted to multiple programming languages and development standards (such as JNI, FFI) to achieve cross-language security verification and analysis. Brief Description of the Drawings

[0015] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with the present disclosure, and are used together with the specification to explain the principles of the present disclosure.

[0016] Figure 1 Schematic diagram of a data-driven data security function verification system for the Internet of Things provided by an embodiment of the present disclosure; Figure 2 Schematic diagram of an example of a runtime data security function verification process provided by an embodiment of the present disclosure.

[0017] Through the above accompanying drawings, specific embodiments of the present disclosure have been shown, and there will be more detailed descriptions hereinafter. These drawings and textual descriptions are not intended to limit the scope of the concept of the present disclosure in any way, but to illustrate the concept of the present disclosure to those skilled in the art by referring to specific embodiments. Detailed Embodiments

[0018] The present disclosure will be further described below with reference to the accompanying drawings. The following embodiments are only used to more clearly illustrate the technical solutions of the present disclosure and should not be used to limit the protection scope of the present disclosure.

[0019] Figure 1 It is a schematic diagram of a data-driven data security function verification system for the Internet of Things provided by an embodiment of the present disclosure.

[0020] As Figure 1 shown, the data-driven data security function verification system 100 for the Internet of Things includes: a process control module 101, a security policy management module 102, a security policy annotation AOP module 103, an AOP aspect code module 104, and a runtime verification module 105.

[0021] The process control module 101 is used to register the application program to be verified and analyzed, manage and coordinate the interaction and operation of each module in the data security function verification system, and generate a verification and analysis result report.

[0022] Optionally, the application program to be verified and analyzed includes Internet of Things devices and their related application programs, as well as backend service systems that support the operation of Internet of Things devices, etc.

[0023] The security policy management module 102 includes a security label definition module 1021 and a verification rule definition module 1022.

[0024] Specifically, the security label definition module 1021 is used to define variable names and the security label patterns of data. The security label patterns may include: 1) Plaintext label: Marks the data as plaintext and must not contain sensitive information.

[0025] 2) Ciphertext label: Marks the data as encrypted and needs to be used through a decryption algorithm.

[0026] 3) Sensitive data label: Marks the data that needs to be tracked or protected in the application and combines with the verification rules to help the system perform compliance verification on the data.

[0027] 4) Encrypted variable name label: Marks the variable name as encrypted to prevent the leakage of data usage.

[0028] 5) Data encryption label: Marks that the data content has been encrypted.

[0029] 6) Classification and grading label: Classifies, grades, and labels the data according to the importance or sensitivity of the data, and combines with the verification rules to help the system perform compliance verification on the data.

[0030] 7) Variable names and data labels used by function interfaces within the package: Marks the data belonging to the internal function interfaces of the program.

[0031] 8) Variable names and data labels used for user-human interaction: Marks the data for interaction with the user.

[0032] 9) Variable names and data labels used for security authentication and protocols: Marks the data related to security authentication and protocols.

[0033] 10) Variable names and data labels used for external databases and files connected to the package: Marks the data related to external databases or files.

[0034] 11) Variable names and data labels used for external function calls and services outside the package: Marks the data related to external function calls and services.

[0035] The verification rule definition module 1022 is used to define a data security rule verification model. Specifically, in the scenario of formal verification analysis of the security functions of data, the data security rule verification model mainly includes: 1. The data does not fall locally; 2. Users with low security permission levels are prohibited from accessing data with high security permission levels; 3. The data can only be uploaded along the specified path and there should be no backdoors for stealing data; 4. Human-computer interaction with sensitive data should be desensitized; 5. Important and sensitive data needs to be encrypted for uploading; 6. User authentication information needs to be cleared in a timely manner after use, etc.

[0036] Optionally, the above-mentioned expression ways of the data security rule verification model can adopt various forms, including but not limited to: model rule expressions or formulas, data semantic expressions or formulas, data general form expressions or formulas, data symbol expressions or formulas, and data security general form expressions or formulas.

[0037] Model rule expressions or formulas, which represent formal descriptions of data security behaviors in the form of mathematical formulas or logical expressions based on predefined security policy models. For example, model rules for data flow direction, encryption requirements, or access permissions. Specifically, taking the data flow direction rule as an example, define the verification rule that data is not stored on the local disk. Another example is taking the data encryption rule as an example, define the verification rule that all sensitive data must be encrypted before transmission or storage.

[0038] Data semantic expressions or formulas, which are used to describe the business semantics and functional semantics of data in the system, and help verify whether the data conforms to the expected usage and permission scope. Exemplarily, define the verification rule that the data file upload path must be in the specified directory.

[0039] Data general form expressions or formulas, which refer to the standardized form expressions of data and are used for consistent verification of data in different contexts. As an example, define the verification rule that all time data must be in the ISO 8601 format.

[0040] Data symbol expressions or formulas, which are used to represent the constraints and relationships of data flows through symbolic methods, facilitating global analysis and verification. For example, the verification rule that the flow path of sensitive data is limited to specific services can be described by symbolizing the data flow path.

[0041] Data security general form expressions or formulas, which are general verification expressions for various data security checks and abstract a general rule framework. Exemplarily, define the verification rule that the HTTPS protocol must be used when transmitting sensitive data.

[0042] It can be understood that not all of the above label modes and data security rule verification models need to be specified. When verifying different application systems, different label modes and data security rule verification models can be selected according to the different security specifications that the data in the application system needs to meet, so as to achieve the purpose of appropriate verification methods.

[0043] The security policy annotation AOP module 103 is used to add security labels to all variable names and data in the application to be verified and analyzed, serving as the entry point for the AOP data security verification aspect.

[0044] Specifically, according to the security label pattern of the application to be verified and analyzed defined by the security policy management module 102, all variable names and data in the static code application package (Java application package) of the application to be verified and analyzed are added with security labels through the first AOP (Aspect-Oriented Programming) program, serving as the entry point for the AOP data security verification aspect. The AOP data security verification aspect code in the AOP aspect code module 104 executes the enhanced logic of the data security rule verification model and logging in response to the activation status and path of these security labels.

[0045] Among them, the first AOP (Aspect-Oriented Programming) program is the AOP (Aspect-Oriented Programming) program developed by this module, which is used to add security labels to all variable names and data in the static code application package (Java application package) of the application to be verified and analyzed. Specifically, the first AOP (Aspect-Oriented Programming) program parses the static code of the application to be verified and analyzed to determine all variable names and data, and then adds the corresponding security labels to them.

[0046] For example, for the sensitive data label and the ciphertext label, the label implementation code example is as follows: public class UserData { @SensitiveData private String userName; / / The user name is sensitive data @SensitiveData @Encrypted @Shall not be decrypted private String userPassword; / / The user password is both sensitive data and encrypted data The AOP aspect code module 104 is used to generate the AOP data security verification aspect code, and the AOP data security verification aspect code is configured to execute the enhanced logic of the data security rule verification model and logging according to the activation status and path of the security labels.

[0047] Specifically, the AOP (Aspect-Oriented Programming) data security verification aspect code is determined according to the pre-developed AOP data security verification program and the label patterns and verification rules of the application programs to be verified and analyzed defined by the security policy management module 102. The AOP data security verification aspect code is configured to execute the enhanced logic of the data security rule verification model and logging according to the activation status and path of the security label, where the logging includes the activation status and path (data flow direction) record of the security label and the execution record of the data security rule verification.

[0048] The pre-developed AOP (Aspect-Oriented Programming) data security verification program of this module obtains the security label patterns and verification rules of the application programs to be verified and analyzed defined by the security policy management module 102, and generates the AOP data security verification aspect code. The AOP aspect data security verification code will be dynamically "woven" into the application program code to be verified and analyzed during runtime. It can be understood that in AOP, "weaving" means embedding the AOP aspect code into the target running code.

[0049] When the application program to be verified and analyzed uses variables, data, and their related functions during runtime, the AOP data security verification aspect code executes the enhanced logic of the data security rule verification model and logging according to the activation status and path (data flow direction) of the security labels added by the security policy annotation AOP module 103.

[0050] As is well known in the art, in AOP aspect-oriented security authentication programming, it generally includes a pointcut and AOP security authentication aspect code (i.e., "advice" and "execution"). The AOP security authentication aspect code is the security authentication enhanced logic inserted at the specified pointcut, and the specific location and timing of the enhancement are determined by the pointcut. In the embodiments of the present disclosure, the security label is used as the pointcut of the AOP aspect, and the AOP data security verification aspect code executes the enhanced logic of the data security rule verification and logging in response to the activation status and path of these security labels. Specifically, an implementation example of the AOP data security verification aspect code is as follows: @Aspect @Component public class SecurityAspect { / / Define the pointcut through the @Around annotation to intercept all operations involving sensitive data and encrypted data @Around("execution(*com.example.ProveDataSecured.UserData.*(..))") In the @Around aspect, the method intercepted currently can be obtained through joinPoint.getSignature().getName(), and the security verification rule model to be executed can be determined in combination with the method.

[0051] Exemplarily, in the @Around aspect, if the method is saveCredentials, the security rule verification model of "data not falling to the local disk" is executed; if the method is uploadCredentials, the security rule verification model of "encrypting and uploading sensitive and important data" is executed.

[0052] Thus, through the AOP aspect code module 104, the data security function verification system can complete the corresponding security rule verification analysis, as well as the data flow tracking and its logging function, based on the activation status and path (data flow direction) of the security label, and at the same time, ensure that the code will not go wrong during runtime due to additional label information.

[0053] The runtime verification module 105 is used to execute the enhanced logic of the data security rule verification model and logging according to the activation status and path (data flow direction) of the security label by the AOP data security verification aspect code during runtime, so as to implement the data security rule verification and logging functions.

[0054] Specifically, during runtime, when variables, data, and their related functions are passed and used, the corresponding security label is activated, that is, it presents an activated state. The AOP data security verification aspect code executes the enhanced logic of the data security rule verification model and logging according to the activation status and path (data flow direction) of the security label, so as to implement the rule verification, data flow tracking, and its logging functions, and return the verification analysis result to the process control module 101.

[0055] As Figure 2 shown, taking the security rule verification model of "data not falling to the local disk" as an example, if the data does not fall to the local disk, the security rule verification is passed; if the data flows to the local disk for storage, the security rule verification fails. Taking the security rule verification model of "encrypting and uploading sensitive and important data" as an example, if the encrypted data is submitted to the data service after encryption, the security rule verification is passed; if the encrypted data is submitted in plaintext, the security rule verification fails.

[0056] It can be seen that by using the runtime verification module 105, the system can automatically capture data streams through the activation status and path of security labels, and perform security verification through the AOP data security verification aspect code, realizing runtime data verification analysis based on data-driven.

[0057] Further optionally, the system may further include a data stream log module 106 and a global security policy execution module 107.

[0058] The data stream log module 106 is used to obtain the log records generated when the runtime verification module 105 executes. At the same time, it can also record the operation and function execution of the data security function verification system, providing log information for the security audit of the system. Among them, the log records include the activation status and path (data flow direction) records of security labels and the execution records of data security rule verification.

[0059] The global security policy execution module 107 is used to integrally analyze the activation status and path (data flow direction) records of security labels in the log records of the data stream log module 106, determine the data streams that depend on the entire data link and the entire life cycle, and perform data security verification on the data streams that depend on the entire data link and the entire life cycle according to the verification rules defined by the verification rule definition module 1022. And, return the verification analysis result to the process control module 101.

[0060] Through the global security policy execution module 107, the verification and analysis functions that the runtime verification module 105 cannot execute in real time can be completed, realizing the security verification of data streams that need to depend on the entire data link and the entire life cycle, and returning the verification analysis result to the process control module 101.

[0061] Among them, the global security policy execution module 107 can be a self-developed system, or an existing security rule model verification system that can be purchased or open-sourced. The embodiments of the present disclosure do not make specific limitations on this.

[0062] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they may be located in one place, or may be distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0063] It should be understood that the above embodiments are only used to illustrate the technical solutions of the present disclosure, rather than limiting them; although the present disclosure has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present disclosure.

Claims

1. A data-driven data security function verification system for the Internet of Things, characterized in that: The system comprises: A process control module (101) is used to register the application to be verified and analyzed, manage and coordinate the interaction and operation of various modules in the data security function verification system, and generate a verification and analysis result report; A security policy management module (102), used to define variable names and data security label patterns, and to define a data security rule verification model; The security policy annotation AOP module (103) is used to add security labels to all variable names and data in the application program to be verified and analyzed, serving as an entry point for the aspect-oriented programming AOP data security verification aspect; An AOP aspect code module (104) is used to generate aspect-oriented programming (AOP) data security verification aspect code, where the AOP data security verification aspect code is configured to execute data security rule verification model and log record enhancement logic according to the activation state and path of the security tag; The runtime verification module (105) is used to execute the data security rule verification model and the enhanced logic of logging according to the activation status and path of the security tag at runtime, so as to realize the data security rule verification and logging functions.

2. The data-driven data security function verification system for the Internet of Things according to claim 1 is characterized in that: The security tag mode includes: Plaintext labels, ciphertext labels, sensitive data labels, variable name encryption labels, data encryption labels and classification and grading labels.

3. The data-driven data security function verification system for the Internet of Things according to claim 2 is characterized in that: The security tag mode further includes: The variable names and data labels used by the function interface within the program package, the variable names and data labels used by user-computer interaction, the variable names and data labels used by security authentication and protocols, the variable names and data labels used by the program package's external databases and files, and the variable names and data labels used by the program package's external functions and services.

4. The data-driven data security function verification system for the Internet of Things according to claim 1 is characterized in that: The method for adding security labels to all variable names and data in the application to be verified and analyzed as an entry point for the aspect-oriented programming (AOP) data security verification aspect includes: according to the security label mode of the application to be verified and analyzed defined by the security policy management module (102), adding security labels to all variable names and data in the static code application package of the application to be verified and analyzed through the first aspect-oriented programming (AOP) program developed by this module as an entry point for the AOP data security verification aspect.

5. The data-driven data security function verification system for the Internet of Things according to claim 1 is characterized in that: The log records include activation status and path records of security tags and data security rule verification execution records.

6. The data-driven data security function verification system for the Internet of Things according to claim 1 is characterized in that: The method is used to generate aspect-oriented programming (AOP) data security verification aspect code, where the AOP data security verification aspect code is configured to execute a data security rule verification model and enhanced log record logic according to the activation status and path of the security label, including: the AOP data security verification program pre-developed in this module obtains the security label mode and data security rule verification model defined by the security policy management module (102), and generates the AOP data security verification aspect code.

7. The data-driven data security function verification system for the Internet of Things according to claim 1 is characterized in that: The system further comprises: A data flow log module (106), used to obtain the log record generated when the runtime verification module (105) is executed; The global security policy execution module (107) is used to integrate and analyze the activation status and path records of the security tags in the log records of the data flow log module (106), determine the data flow that depends on the entire link and the entire life cycle of the data, and perform data security verification on the data flow that depends on the entire link and the entire life cycle of the data according to the data security rule verification model.