Privacy measurement and control method and system based on trusted execution environment
By conducting software evaluation in the trusted execution environment of the evaluated party and using confidential calculations to generate verifiable proofs, the high cost and unreliability problems of traditional software evaluation are solved, and the credibility of the evaluation results and verification during the software use process are achieved.
Patent Information
- Application Number
- CN202510751741.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-07-08
- Estimated Expiration
- 2045-06-06
AI Technical Summary
Traditional software evaluation methods are costly and cannot guarantee the credibility of the evaluation results, and it is difficult to verify whether the software has been tampered with in the production environment.
The privacy testing and control method based on a trusted execution environment is adopted, and the software evaluation is performed using the trusted execution environment TEE, and the evaluation is conducted on the evaluated party through confidential computing remote authentication services, and a chip-level verified certificate is generated to ensure the credibility of the evaluation results, and software information comparison and verification is carried out at the user.
While reducing the evaluation cost, it ensures the credibility of the evaluation results, and through the unique feature information verification software, it has not been tampered with during use, solving the problem of taking into account both the credibility and cost of the evaluation results.
Smart Images

Figure CN120277680A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of software evaluation, and in particular, relates to a privacy measurement and control method and system based on a trusted execution environment. Background Art
[0002] In scenarios such as software development outsourcing, the developer needs a third party to conduct software evaluation before delivering the software to the client to ensure that the developed software meets the client's needs. During the software evaluation process, the evaluator needs to deploy the system, evaluate the software in the authorized system, test each function agreed in the software, and draw a corresponding conclusion report. Traditional software evaluation methods have the following two main disadvantages: 1) The evaluation party needs to build an environment and try to make it consistent with the production environment of the evaluated end, which is relatively costly.
[0003] The most ideal situation is to conduct the corresponding evaluation in the deployment environment being evaluated, which can greatly save the deployment cost of the evaluation party. The party being evaluated already has a test environment, which will not increase the cost much. However, this will face the possibility of tampering by the party being evaluated, and the credibility of the evaluation results cannot be strictly guaranteed.
[0004] 2) It is difficult to determine whether the evaluated software is actually the evaluated software during its actual use in the production environment. Although the version number of the implemented software provided by some software vendors is consistent with the software version during the evaluation, the actual code has been adjusted, which makes it difficult for users to verify in actual applications. Summary of the invention
[0005] The purpose of the present invention is to provide a privacy measurement and control method and system based on a trusted execution environment to address the above-mentioned problems. By using the trusted execution environment (confidential computing) technology, the software test is delegated to the software being evaluated, which has its own deployment environment, under the premise of ensuring trustworthiness. The software is evaluated in the trusted execution environment, and a chip-level verifiable proof is generated to prove the legality, validity and credibility of the evaluation. At the same time, for the software user, based on the proposed software evaluation method for the software evaluator, it can be effectively verified whether the software being used is the software being evaluated or has been modified based on the evaluated version.
[0006] In order to achieve the above object, the present invention adopts the following technical solutions: A privacy measurement and control method based on a trusted execution environment, the method comprising the following process performed by a software evaluator: The software evaluation party sends the evaluation management software M to the evaluated party; The software evaluator deploys and starts the confidential computing remote authentication service RS; The software evaluator obtains the measured value of the trusted execution environment TEE of the evaluated party, and the measured value includes the measured value of the measurement information of the evaluation management software M; The software evaluation party's confidential computing remote authentication service RS initiates a remote authentication process with the party to be evaluated based on the measurement value; In response to a valid authentication, a trusted connection is established with the evaluation management software M running in the trusted execution environment TEE of the party to be evaluated, and a secret key E and a signature private key S are assigned to the evaluation management software M. The secret key E and the signature private key S are trusted and sealed by the evaluation management software M; The software evaluation party sends an evaluation instruction to the evaluation management software M and receives E(I) and S(E(I)) returned by the evaluation management software M; E(I) is obtained by the evaluation management software M encrypting the test information I based on the secret key E; E(I) can be written to disk or temporarily stored in the TEE secure memory.
[0007] S(E(I)) is obtained by the evaluation management software M signing E(I) based on the signature private key S; The test information I is generated by the evaluation management software M based on the situation of the software C to be evaluated being evaluated according to the evaluation instruction in the trusted execution environment; In response to the validity of the signature of S(E(I)), decrypt E(I), and the software evaluation party obtains the plaintext test information; In response to passing the test, the software evaluation party records the software information of the software C to be evaluated and distributes an evaluation certificate.
[0008] After receiving M, the software party to be evaluated starts M in the trusted execution environment.
[0009] In the above privacy measurement and control method based on the trusted execution environment, the evaluation management software M is deployed in the file system of initrd during the system startup process of the party to be evaluated; Alternatively, the evaluation management software M is deployed in the file operating system OS loaded by the trusted execution environment TEE of the party to be evaluated.
[0010] In the above privacy measurement and control method based on the trusted execution environment, the party to be evaluated obtains the measurement value through confidential computing for chip-level measurement. The measurement value includes the underlying trusted base TCB measurement information, kernel layer measurement information, and initrd measurement information of the trusted execution environment TEE; When the evaluation management software M is deployed in the file system of initrd during the system startup process of the party to be evaluated, the confidential computing service provided by the trusted execution environment measures initrd, including the measurement information of the evaluation management software M; When the evaluation management software M is deployed in the file operating system OS loaded by the trusted execution environment TEE of the party to be evaluated, the measurement information of the evaluation management software M running in the file operating system OS is obtained through TPM or virtual TPM.
[0011] The measurement information of the underlying trusted base TCB, kernel layer measurement information, and initrd measurement information of the trusted execution environment TEE are obtained by measuring the entire trusted execution environment through the confidential computing service provided by the trusted execution environment. When the evaluation management software M is deployed in the file system of initrd during the system startup process of the evaluated party, the initrd measurement information includes the measurement information of the evaluation management software M. The correctness of the initrd measurement information means that the information of M is legal and correct.
[0012] In the above privacy measurement and control method based on the trusted execution environment, the evaluation software T is sent to the evaluated party. The evaluation management software M includes the startup information of the evaluation software T, or the confidential computing remote authentication service RS sends the startup information of the evaluation software T to the evaluation management software M based on the secure connection established by remote authentication between the evaluation management software M and the confidential computing remote authentication service RS. The evaluated party's user evaluates the evaluated software C manually according to the evaluation instructions by the evaluation software T, or the evaluation software T automatically evaluates the evaluated software C based on the evaluation instructions.
[0013] In the above privacy measurement and control method based on the trusted execution environment, the test information includes the hash value, version number, test result, test status, and screen recording information of the evaluated software C. When it is a manual evaluation, it also includes the operation record information of the manual evaluation, such as mouse and keyboard operations, screen recording information, etc. The software information includes the unique feature information (such as hash value, etc.) of the evaluated software C.
[0014] In the above privacy measurement and control method based on the trusted execution environment, a secret key E and a signature private key S are assigned to the evaluation management software M, specifically including: Based on the trusted secure connection established between the evaluation party's confidential computing remote authentication service RS and the evaluation management software M running in the trusted execution environment TEE of the evaluated party, the confidential computing remote authentication service RS sends the secret key authorization token Token to the evaluation management software M. The key management service KMS receives the secret key authorization token Token sent by the evaluation management software M based on the key request, and provides the corresponding secret key E and signature private key S to the evaluation management software M based on the legality of the secret key authorization token Token.
[0015] In the above privacy measurement and control method based on the trusted execution environment, this method also includes the software usage process: Establish a trusted secure connection with the software user, and also establish a trusted secure connection through the confidential computing remote authentication service RS. Receive a hardware signature report sent by the verification software R, which contains software verification information of the software C' to be used; After the hardware signature report is verified, the software verification information is obtained; The verification software R is authorized by the software evaluation party or provided to the software user, or developed by the software user itself. The verification software R includes the startup information of the software C' to be used, and the software C' to be used has been evaluated by the above method; The software verification information is obtained by the software user through the verification software R triggering the startup of the software to be used C' in the trusted execution environment TEE and measuring the reading of the software to be used C'. The software verification information includes the unique feature information of the software to be used C' (such as hash value, etc.); Compare the software verification information with the software information recorded in the evaluation phase and feed back the verification results to the verification software R; The verification software R decides whether to continue to start and use the software C' to be used according to the verification result.
[0016] In the above-mentioned privacy measurement and control method based on a trusted execution environment, the verification software R performs periodic or random real-time measurement and reads the verification information of the software C' to be used after the software C' to be used is started to perform life cycle verification on the software C' to be used; The evaluation instructions are sent intermittently in real time according to the evaluation status.
[0017] A privacy measurement and control system based on a trusted execution environment includes a software evaluator and an evaluated party. The software evaluator establishes a trusted connection with the evaluated party and is controlled by the software evaluator through the above method to perform software evaluation on the evaluated software C in the trusted execution environment of the evaluated party, record software information and distribute evaluation certificates.
[0018] In the above-mentioned privacy measurement and control system based on a trusted execution environment, the system also includes a software user, and the software evaluator also establishes a trusted connection with the software user. The software evaluator uses the above-mentioned method to compare and verify whether the software C' to be used is consistent with the software C to be evaluated, and decides whether to continue to start and use the software C' to be used based on the verification result.
[0019] The advantages of the present invention are: This solution proposes to conduct the evaluation within the scope of the evaluated party, which can greatly save the deployment cost of the evaluator. At the same time, through a series of means, it can strictly guarantee the security and reliability of the evaluation results even if the evaluation is conducted within the scope of the evaluated party, solving the problem of not being able to balance the cost and the high reliability of the evaluation results. While achieving high credibility of the evaluation results evaluated by the evaluated party, it is further proposed to locally save the software information containing the unique and unchangeable feature information of the software to be evaluated, and provide a verification software to the user. When the user uses the software, the verification software obtains the software information of the used software as the verification information. By comparing and verifying it with the software information stored in the evaluation stage, it can be ensured that the software used by the user is the software to be evaluated, further solving the problem that in the current situation, users cannot guarantee that the software they use has not been modified and is consistent with the evaluated software. Brief Description of the Drawings
[0020] Figure 1 It is a schematic diagram of the data flow of each relevant party of the privacy measurement and control system based on the trusted execution environment of the present invention. The dotted arrows in the figure are the data flows based on the trusted secure connection.
[0021] Figure 2 It is a method flow chart of the privacy measurement and control method based on the trusted execution environment in the first embodiment of the present invention; Figure 3 It is a method flow chart of the trusted verification of the software used by the user based on privacy measurement and control in the privacy measurement and control method based on the trusted execution environment in the first embodiment of the present invention; Figure 4 It is a method flow chart in the privacy measurement and control method based on the trusted execution environment in the fourth embodiment of the present invention. Detailed Embodiments
[0022] Embodiment 1 As Figure 1 and Figure 2 shown, the present invention provides a privacy measurement and control method based on the trusted execution environment. This method involves three parties: the software evaluation party, the evaluated party, and the software user. The implementation process is as follows: 1. The software evaluation party sends the evaluation management software M and the evaluation software T to the evaluated party. The evaluation software T refers to some test software examples, such as Seleniu, JMeter, etc. The evaluation management software M is provided by the evaluation party, connects with the evaluation party, and manages the evaluation process accordingly. The evaluation software T is selected by the software evaluation party. The specific performance, function, and other tests are not within the scope of this solution, so no restrictions and elaborations are made on this.
[0023] 2. The software evaluation party deploys and starts the confidential computing remote authentication service RS. The application is started within the trusted execution environment, and the trusted execution environment and the application are measured and signed by the hardware (chip) to generate a chip-level signature report (Report). The report is sent to the remote user. Here, the application is started within the trusted execution environment of the party to be evaluated, and the remote user is the software evaluation party. The remote user verifies the legality of the report based on the relevant verification mechanism, extracts the measured value from the report, and compares it with the expected measured value saved on the user side. If they match, a secure connection is continued to be established with the trusted environment. Such a process is the confidential computing remote authentication service.
[0024] 3. The evaluation management software M is deployed in the initrd file system during the startup process of the system of the party to be evaluated. The party to be evaluated starts the TEE, and the TEE loads the initrd and the file operating system OS, and triggers the evaluation management software M.
[0025] 4. The party to be evaluated measures the entire trusted execution environment at the chip level based on the confidential computing service provided by the trusted execution environment TEE, including the underlying trusted root of trust TCB, the kernel layer, the initrd, the file operating system OS, etc. The object of measurement includes the initrd, and the initrd includes information about the software evaluation management software M. Therefore, the object of measurement includes information about the software evaluation management software M.
[0026] 5. Based on the measured value obtained in step 4, the confidential computing remote authentication process is started. That is, by performing chip-level signature on this measured value and related parameters, the signature is sent to the confidential computing remote authentication service RS of the software evaluation party for signature verification, and the validity of the measured value is verified for legality. If it is valid, it means that the evaluation management software M running within the trusted execution environment TEE of the party to be evaluated is a software recognized and authorized as valid by the software evaluation party and meets the requirements of the evaluation party. Then the confidential computing remote authentication service RS directly establishes a trusted secure connection with the evaluation management software M running in the trusted execution environment TEE of the party to be evaluated. For the existing relevant remote authentication processes in the industry, reference can be made to, for example, Intel RA-TLS, which will not be elaborated here.
[0027] 6. Based on the established trusted secure connection, the confidential computing remote authentication service RS sends a secret key authorization token Token to the evaluation management software M.
[0028] 7. The evaluation management software M establishes a secure connection with the evaluation party's key management service KMS. The evaluation management software M sends a key authorization token Token to the key management service KMS to request a key. After verifying the legitimacy of Token, the key management service KMS sends the symmetric encryption key E and the signature private key S on behalf of the software evaluation party to the evaluation management software M. The symmetric encryption key E and the signature private key S are pre-generated by the software evaluation party and stored in the key management service KMS. Generating symmetric keys and asymmetric keys is a quite mature existing technology, and there are quite mature cryptographic function libraries, such as calling the openssh package, etc. Here, the method of generating key pairs by the software evaluation party can adopt the existing technology and will not be elaborated.
[0029] 8. The evaluation management software M performs local trusted sealing on S and E based on the trusted execution environment TEE trusted sealing technology. The trusted execution environment TEE trusted sealing means that S and E are encrypted and stored on the hard disk of the evaluated party based on chip-level derived keys. Even the highest authority of the evaluated party's host cannot steal or spy on this encrypted information. The encrypted information can only be loaded and used by the evaluation management software M in the TEE.
[0030] 9. Based on the evaluation party's confidential computing remote authentication service RS, a trusted secure connection is directly established with the evaluation management software M running in the trusted execution environment TEE of the evaluated party. The confidential computing remote authentication service RS sends instructions for relevant evaluation items to the evaluation management software M.
[0031] 10. According to the corresponding evaluation instructions, the evaluation management software M starts the evaluation software T and the software C to be evaluated of the evaluated party. The evaluation instructions can be sent intermittently in real time according to the evaluation situation. For example, after a certain functional unit item is tested, the evaluation management software M will feedback the completion information of the functional unit item to the evaluation party, and the evaluation party can issue new test instructions.
[0032] 11. According to the evaluation requirements and evaluation instructions, an automatic evaluation of the software C to be evaluated is performed by the evaluation software T in the trusted execution environment TEE.
[0033] 12. The evaluation management software M collects and generates test information I. The test information includes but is not limited to: relevant information such as the hash value and version number of the software C to be evaluated, test results, test status, screen recording information, etc.
[0034] 13. The evaluation management software M encrypts the test information I based on the key E and writes it to disk as E(I). The evaluation management software M signs E(I) based on the signature private key S to generate S(E(I)).
[0035] 14. After the evaluation is completely finished, according to the requirements of the evaluation party, the evaluation management software M can be selected to delete the relevant evaluation software T and the key E and the signature private key S.
[0036] 15. The evaluation management software M sends E(I) and S(E(I)) to the evaluation party; 16. The evaluation party verifies the validity of the signature based on the corresponding public key of S. If it is valid, it reads E(I).
[0037] 17. Based on the symmetric key E, decrypt and restore the plaintext data of I, and parse the relevant test information.
[0038] 18. If it passes the test criteria of the evaluation party, register the software information to be evaluated (including hash value, software name, version information, software feature value, etc.) and issue a corresponding certificate.
[0039] 19. The software information to be evaluated is stored in the corresponding database D of the evaluation party.
[0040] So far, the evaluation process is completed. The following is the software usage state process. Figure 3 The following gives the verification method flow chart from the perspective of the software evaluation party: 20. The software user deploys and starts the verification software R authorized by the evaluation party in the trusted execution environment. According to the user's needs, the user can establish a connection with the software evaluation party through remote authentication to verify the legal validity of R. The verification software R can be obtained from the software evaluation party, or from a third party, or developed by the software user himself, as long as it is authorized and trusted by the evaluation party.
[0041] 21. If the user needs to use the software C’, the verification software R can trigger and start the software C’ in the trusted execution environment based on the configuration information. At the same time, the verification software R measures and reads this software information (hash value, software name, version information, software feature value, etc.) as verification information for the user to verify. That is, the user can configure to use the verification software R for verification. Only by passing the verification can the software C’ be used normally. The user can also directly use the software C’ without verification. That is, the user can choose not to verify the software C’ and can start the software at any time through configuration.
[0042] 22. Based on the remote authentication process, this verification information is hardware-signed and transmitted to the verification service TS of the software evaluation party through a secure connection. Based on its database D, compare and verify the legality of this software information, extract the software information saved by this software C’ during the evaluation stage. If the verification information is consistent with the software information, especially the unique feature information of the software is consistent, such as the hash value, etc., it is considered that the software C’ has not been changed and is the version at the time of evaluation.
[0043] 23. The verification service TS returns the result of whether the legality verification passes to the verification software R.
[0044] 24. The verification software R decides whether to continue to start and use the software C’ according to the verification result.
[0045] In this way, it can be ensured that the software dynamically used by the user is always the software recognized and valid by the evaluation party.
[0046] As an option, steps 21-24 above can, according to the requirements of the user or the evaluation party, perform periodic or random real-time measurement and read software information after the software is started, so as to verify and ensure the security and credibility of the entire software life cycle in real time.
[0047] Embodiment 2 This embodiment is similar to Embodiment 1, except that in this embodiment, the evaluation management software M is deployed in the file operating system OS loaded by the trusted execution environment (TEE) of the evaluated party. Correspondingly, in process 4, the objects to be measured include the information of the software evaluation management software M running in the file operating system OS. At this time, the measurement operation of the software evaluation management software M running in the file operating system OS can be implemented based on the confidential computing service provided by the TPM evaluation management software M or the VirtualTPM evaluation management software M.
[0048] Embodiment 3 This embodiment is similar to Embodiment 1, except that in this embodiment, the evaluation of the evaluated party is carried out by the staff of the evaluated party through manual operations (manual operations with interactive tools such as a mouse and keyboard). Correspondingly, in this embodiment, the test information I also includes manual test mouse and keyboard recording information, screen recording information and other manually related information to ensure that the evaluation process meets the evaluation requirements. The software evaluation party can send the evaluation software T according to needs, or can not send the evaluation software.
[0049] Embodiment 4 As Figure 4 shown, this embodiment is similar to Embodiment 1, except that in this embodiment, after the software evaluation party passes the verification of the measured value, the secret key E and the signature private key S are assigned to the evaluated party, and the secret key E and the signature private key S are sent to the evaluation management software M running in the trusted execution environment of the evaluated party, without the need for the evaluation management software M to request the secret key according to the secret key authorization token Token. Figure 4 The flowchart of the method from the perspective of the software evaluation party is given.
[0050] The specific embodiments described herein are merely illustrative of the spirit of the present invention. Those skilled in the art to which the present invention pertains can make various modifications or supplements to the described specific embodiments or use similar ways to replace them, but will not deviate from the spirit of the present invention or exceed the scope defined by the appended claims.
[0051] Although terms such as evaluation management software M, confidential computing remote authentication service RS, key authorization token Token, key E, signature private key S, evaluation software T, software under evaluation C, software to be used C', and verification software R are used more frequently in this article, the possibility of using other terms is not excluded. The use of these terms is only for the purpose of more conveniently describing and explaining the essence of the present invention; interpreting them as any additional limitation is contrary to the spirit of the present invention.
Claims
1. A privacy measurement and control method based on a trusted execution environment, characterized in that, The method includes: Sending the evaluation management software M to the party to be evaluated; Deploying and starting the confidential computing remote authentication service RS; Obtaining the measured value of the trusted execution environment TEE of the party to be evaluated, including the measured information of the evaluation management software M; Based on the measured value, the confidential computing remote authentication service RS starts the remote authentication process with the party to be evaluated; In response to a valid authentication, a trusted connection is established with the evaluation management software M running in the trusted execution environment TEE of the party to be evaluated, and a secret key E and a signature private key S are assigned to the evaluation management software M. The secret key E and the signature private key S are trusted and sealed by the evaluation management software M; Sending an evaluation instruction to the evaluation management software M, and receiving E(I) and S(E(I)) returned by the evaluation management software M; E(I) is obtained by the evaluation management software M encrypting the test information I based on the secret key E; S(E(I)) is obtained by the evaluation management software M signing E(I) based on the signature private key S; The test information I is generated by the evaluation management software M based on the situation of the software C to be evaluated according to the evaluation instruction in the trusted execution environment; In response to a valid signature of S(E(I)), decrypt E(I) to obtain the plaintext test information; In response to passing the test, record the software information of the software C to be evaluated and distribute the evaluation certificate.
2. The privacy measurement and control method based on a trusted execution environment according to claim 1, wherein The evaluation management software M is deployed in the initrd file system during the system startup process of the party to be evaluated; Alternatively, the evaluation management software M is deployed in the file operating system OS loaded by the trusted execution environment TEE of the party to be evaluated.
3. The privacy measurement and control method based on a trusted execution environment according to claim 2, wherein, The party to be evaluated obtains the measured value through chip-level measurement by confidential computing. The measured value includes the measured information of the underlying trusted base TCB of the trusted execution environment TEE, the kernel layer measured information, and the initrd measured information; When the evaluation management software M is deployed in the initrd file system during the system startup process of the party to be evaluated, the initrd measured information includes the measured information of the evaluation management software M, and the confidential computing service provided by the trusted execution environment measures initrd; When the evaluation management software M is deployed in the file operating system OS loaded by the trusted execution environment TEE of the party to be evaluated, the measured information of the evaluation management software M running in the file operating system OS is obtained through TPM or virtual TPM.
4. The privacy measurement and control method based on a trusted execution environment according to claim 1, wherein Sending the evaluation software T to the party to be evaluated. The evaluation management software M contains the startup information of the evaluation software T, or the confidential computing remote authentication service RS sends the startup information of the evaluation software T to the evaluation management software M based on the secure connection between the evaluation management software M and the confidential computing remote authentication service RS; The user of the party to be evaluated manually evaluates the software C to be evaluated according to the evaluation instruction by the evaluation software T, or the evaluation software T automatically evaluates the software C to be evaluated based on the evaluation instruction.
5. The privacy measurement and control method based on a trusted execution environment according to claim 1, wherein The test information includes the hash value, version number, test result, test status, and screen recording information of the software C to be evaluated; When it is a manual evaluation, it also includes the operation record information of the manual evaluation; The software information includes the unique feature information of the software C to be evaluated.
6. The privacy measurement and control method based on a trusted execution environment according to claim 1, wherein Allocate a secret key E and a signature private key S to the evaluation management software M, specifically including: Based on the trusted secure connection established between the remote attestation service RS for confidential computing of the evaluation party and the evaluation management software M running in the trusted execution environment TEE of the evaluated party, the remote attestation service RS for confidential computing sends a secret key authorization token Token to the evaluation management software M; The key management service KMS receives the secret key authorization token Token sent by the evaluation management software M based on the key request, and provides the corresponding secret key E and signature private key S to the evaluation management software M based on the legitimacy of the secret key authorization token Token.
7. The privacy measurement and control method based on a trusted execution environment according to claim 1, characterized in that This method further includes: Establish a trusted secure connection with the software user; Receive a hardware signature report sent by the verification software R containing the software verification information of the to-be-used software C'; Verify the signature of the hardware signature report to obtain the software verification information; The verification software R includes the startup information of the to-be-used software C', and the to-be-used software C' has been evaluated by the method described in any one of claims 1-6; The software verification information is obtained by the software user triggering the startup of the to-be-used software C' in the trusted execution environment TEE through the verification software R and measuring and reading the to-be-used software C', and the software verification information includes the unique feature information of the to-be-used software C'; Compare the software verification information with the software information recorded in the evaluation stage and feedback the verification result to the verification software R; The verification software R decides whether to continue to start and use the to-be-used software C' according to the verification result.
8. The privacy measurement and control method based on a trusted execution environment according to claim 7, wherein The verification software R performs periodic or random real-time measurement and reading of the verification information of the to-be-used software C' after the to-be-used software C' is started to perform life cycle verification on the to-be-used software C'; The evaluation instructions are intermittently sent in real time according to the evaluation status.
9. A privacy measurement and control system based on a trusted execution environment, characterized in that, It includes a software evaluation party and an evaluated party. The software evaluation party establishes a trusted connection with the evaluated party, and is controlled by the software evaluation party through the method described in any one of claims 1-6. The software evaluation is performed on the evaluated software C in the trusted execution environment of the evaluated party, and the software information is recorded and the evaluation certificate is distributed.
10. The privacy measurement and control system based on a trusted execution environment according to claim 9, wherein This system further includes a software user. The software evaluation party also establishes a trusted connection with the software user, and compares and verifies whether the to-be-used software C' is consistent with the evaluated software C by the method described in claim 7, and decides whether to continue to start and use the to-be-used software C' according to the verification result.
Citation Information
Patent Citations
Security chip, mobile terminal and method for achieving mobile terminal system security
CN106156618A
Android software evaluation method and device based on blockchain, and medium
CN111125643A
Method and device for starting application program on target platform
CN112988262A
Host remote monitoring method based on chip hierarchy privacy calculation
CN113569266A
Modular security evaluation of software on devices
US20240143788A1