Kernel parameter protection method and system based on multi-stage parameter application mechanism

Through the kernel parameter protection method combined with a multi-stage parameter application mechanism and a trade secret algorithm, the security and flexibility of kernel parameter transmission are solved, and the secure transmission and dynamic encryption adaptation of kernel parameters are realized, ensuring the complete configuration and key isolation storage during the kernel initialization process.

CN120337264APending Publication Date: 2025-07-18QILIN XINAN (GUANGDONG) TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510501195.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The existing operating system kernel parameter transmission has clear text transmission security problems, lacks flexible encryption solutions, cannot adapt to the needs of different security scenarios, and parameter initialization during kernel startup is not flexible and comprehensive enough.

Method used

The multi-stage parameter application mechanism is adopted, combining the trade secret algorithm and traditional encryption algorithm, and the dual hybrid encrypted kernel parameter ciphertext is obtained in each kernel initialization stage through user-state tools, and decrypted in the kernel state to realize dynamic encryption algorithm selection and switching, and the key management storage area is used for key isolation storage and access control.

Benefits of technology

It realizes the secure transmission of kernel parameters, avoids information leakage, ensures that complete configuration information is obtained in each initialization stage, supports dynamic adaptation of multiple encryption algorithms, is compatible with trade secret standards, and reduces the risk of key leakage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120337264A_ABST
    Figure CN120337264A_ABST
Patent Text Reader

Abstract

The invention discloses a kernel parameter protection method and system based on a multi-stage parameter application mechanism, and the method comprises the following steps: dividing a kernel initialization process of an operating system into a plurality of stages, in each stage, transmission parameters which are transmitted by a user mode tool and comprise kernel parameter ciphertexts which are subjected to double hybrid encryption by adopting a commercial encryption algorithm and a traditional encryption algorithm are firstly obtained, original kernel parameters are obtained through decryption by utilizing a decryption module, and the kernel parameters in the stage are applied after the original kernel parameters are successfully obtained through decryption. Then entering the next stage until the process of kernel initialization is completed; and after kernel initialization is completed, the kernel dynamically acquires encrypted kernel parameters and executes decryption and application to realize dynamic selection and switching of an encryption algorithm during operation. The invention aims to realize combination of a commercial encryption algorithm and a traditional encryption algorithm, realize flexible and staged parameter activation at a kernel level, and realize effective protection of kernel parameters.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of computer system security, and particularly relates to a kernel parameter protection method and system based on a multi-stage parameter application mechanism. Background Art

[0002] At present, the kernel parameter transmission of operating systems mostly uses the plaintext method, which has the following defects: (1) Security issues: The kernel parameter transmission of existing mainstream operating systems (including Linux, Windows, etc.) generally uses the non-encrypted plaintext transmission mode, and its technical implementation has systematic security risks. The bootloader (GRUB) directly transmits key parameters such as debug (debugging) and init (initialization) through command-line parameters. An attacker can easily obtain the unencrypted parameters through physical access or UEFI firmware vulnerabilities. Sensitive information such as kernel debug parameters (such as kgdboc) and hardware configuration parameters (such as PCIe BAR addresses) is exposed, which may leak the core intellectual property rights of enterprises. (2) Fixed encryption scheme: There is a lack of a mechanism to dynamically select encryption algorithms for different security scenarios, and it is impossible to flexibly meet the requirements of commercial encryption algorithms and different security level requirements. (3) Lack of flexibility: The existing method encrypts the menu of the bootloader (GRUB) as a whole, lacking flexibility. Moreover, during the existing kernel startup process, there are initializations of stage parameters such as early_param (early parameters), arch_init (architecture initialization), and device_init (device initialization). It is of a certain technical difficulty to ensure the correct application of the decrypted parameters in all stages. At the same time, with the wide application of commercial encryption algorithms in the domestic security field, how to combine commercial encryption algorithms such as SM2 and SM4 with traditional encryption algorithms and achieve flexible and phased parameter activation at the kernel level has become a technical problem to be solved urgently. Summary of the Invention

[0003] The technical problem to be solved by the present invention: Aiming at the above problems of the prior art, the present invention provides a kernel parameter protection method and system based on a multi-stage parameter application mechanism. The present invention aims to combine commercial encryption algorithms with traditional encryption algorithms, and achieve flexible and phased parameter activation at the kernel level to effectively protect kernel parameters.

[0004] To solve the above technical problems, the technical solution adopted by the present invention is as follows: A kernel parameter protection method based on a multi-stage parameter application mechanism includes the following steps: Divide the process of initializing the kernel of the operating system into multiple stages. In each stage, first obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-space tool, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the kernel parameters of this stage, and then enter the next stage until the process of kernel initialization is completed; The traditional encryption algorithm is an encryption algorithm that maps the ciphertext encrypted by the commercial cipher algorithm to a specified character set; After completing the kernel initialization, dynamically obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-space tool through the kernel, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the dynamically obtained kernel parameters to achieve dynamic selection and switching of the encryption algorithm during runtime.

[0005] Optionally, the obtaining the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-space tool and using the decryption module to decrypt and obtain the original kernel parameters includes: S101, receive the transmission parameters passed in by the user-space tool through the kernel, including metadata and the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm, and the encryption method of the kernel parameter ciphertext is included in the metadata; perform integrity verification on the passed-in transmission parameters through a digital signature or checksum mechanism. If the integrity verification passes, jump to the next step; otherwise, end and exit. S102, parse the transmission parameters to read the encryption method in the metadata, and first decode the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm using the traditional encryption algorithm to obtain the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm, and send the encryption method and the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm to the decryption module; S103, the decryption module sends a request to obtain the decryption key to the key management storage area through a secure interface; S104, the decryption module receives the decryption key returned from the key management storage area through a secure interface, and uses the decryption key to perform a decryption operation on the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm to recover the original kernel parameters; S105, the decryption module returns the original kernel parameters to the kernel. Optionally, the traditional encryption algorithm refers to the Base64 encryption algorithm, and the commercial cipher algorithm includes one or more of the SM2 encryption algorithm and the SM4 encryption algorithm.

[0006] Optionally, the key management storage area uses isolated memory allocated by kmalloc_cma to store the decryption key, and the isolated memory is set with some or all of the attributes of VM_IO, VM_DONTDUMP, and VM_DONTEXPAND to physically and logically protect the decryption key stored in the isolated memory.

[0007] Optionally, it further includes a timing execution automatic update mechanism to periodically update the decryption key stored in the key management storage area, erase and destroy the expired decryption key. The key management storage area is a memory area isolated by hardware isolation technology based on the trusted execution environment TEE, and uses the trusted platform module TPM as the trust root to periodically detect the integrity of the key management storage area, and update the decryption key stored in the key management storage area, erase and destroy the expired decryption key when the integrity verification of the key management storage area fails.

[0008] Optionally, after the decryption module sends a request to obtain the decryption key to the key management storage area through the security interface in step S103, the response of the key management storage area to the request includes: parsing the request to obtain the decryption key to obtain the subject and object of the request, where the subject is the decryption module and the object is the requested decryption key; matching the subject and object of the request with the preset access control policy to verify the legitimacy of the request. If the legitimacy verification of the request passes, read the requested decryption key from the isolated memory and return the requested decryption key; otherwise, reject and exit.

[0009] Optionally, it further includes the step of the user-state tool passing the transmission parameter including the ciphertext of the kernel parameter to the kernel: S201, using the user-state preprocessing module as an independent tool or embedded in the hypervisor, obtain the original kernel parameters defined in advance by developers according to system security requirements and kernel configuration requirements in the application program or script during the system development stage, including some or all of the debug level, device configuration, and security policy; S202, obtain the candidate commercial encryption algorithms according to the security policy in the system configuration file; S203, obtain the current system running environment and security requirements, and select the final encryption method for the kernel parameter ciphertext from the candidate commercial encryption algorithms according to the current system running environment and security requirements and the preset encryption method selection policy; S204, perform an encryption operation on the original kernel parameters using the final encryption method for the kernel parameter ciphertext; S205, encode and encrypt the kernel parameter ciphertext using the traditional encryption algorithm to map it to the specified character set, so as to obtain the kernel parameter ciphertext encrypted by the dual hybrid of the commercial encryption algorithm and the traditional encryption algorithm; S206, generate metadata including the encryption method of the final encrypted kernel parameters, encapsulate the encrypted kernel parameters using the dual hybrid encryption of commercial encryption algorithm and traditional encryption algorithm and the metadata into transmission parameters in a structured data format, and store them in the kernel startup parameters, device tree nodes or dedicated kernel interfaces to be passed into the kernel.

[0010] In addition, the present invention also provides a kernel parameter protection system based on a multi-stage parameter application mechanism, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism.

[0011] In addition, the present invention also provides a computer-readable storage medium, in which a computer program or instruction is stored, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism through a processor.

[0012] In addition, the present invention also provides a computer program product, including a computer program or instruction, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism through a processor.

[0013] Compared with the prior art, the present invention can mainly achieve the following beneficial effects: 1. Secure parameter transmission: Avoid the risk of information leakage caused by plaintext transmission. 2. Multi-stage parameter application: Ensure that the kernel can obtain complete and effective configuration information in each initialization stage, and avoid configuration omissions. 3. Dynamic encryption algorithm adaptation: Implement dynamic selection and switching of encryption algorithms during operation, support multiple encryption algorithms such as SM2 / SM4 and AES, and be compatible with the requirements of commercial encryption standards. 4. Key isolation storage: Establish a key security storage and access control mechanism, place the key in a dedicated isolated memory, and prevent key leakage. Brief Description of the Drawings

[0014] For the convenience of intuitively understanding the overall structure and core technical process of the present invention, the patent drawings of the present invention adopt various diagram forms such as flowcharts and timing diagrams to describe the system architecture, user-state parameter encryption, kernel-state decryption, and multi-stage parameter application processes in detail. The following describes the main drawings one by one: Figure 1 It is a schematic diagram of the basic process of the method in the embodiment of the present invention.

[0015] Figure 2 It is a schematic diagram of the interaction process of the method in the embodiment of the present invention.

[0016] Figure 3 It is a schematic diagram of the process of decrypting the kernel parameters in the embodiment of the present invention.

[0017] Figure 4 Schematic diagram of the process for encrypting kernel parameters in an embodiment of the present invention. Specific implementation manners

[0018] The present invention aims to solve the following key technical problems: Parameter transmission security: Avoid the risk of information leakage caused by plaintext transmission. Multi-stage parameter application: Ensure that complete and valid configuration information can be obtained in each initialization stage of the kernel, and avoid configuration omissions. Dynamic encryption algorithm adaptation: Implement dynamic selection and switching of encryption algorithms during operation, support multiple algorithms such as SM2 / SM4 and AES, and be compatible with the requirements of commercial cipher standards. Key isolation storage: Establish a key security storage and access control mechanism, place the key in a dedicated isolated memory, and prevent key leakage. In order to enable those skilled in the art of the present technology to better understand the technical solutions of the present invention, the technical solutions of the present invention will be further described in detail below with reference to the accompanying drawings in the embodiments of the present invention.

[0019] As Figure 1 shown, the kernel parameter protection method based on the multi-stage parameter application mechanism in this embodiment includes the following steps: Divide the process of initializing the kernel of the operating system into multiple stages. In each stage, first obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by both the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-state tool, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the kernel parameters of this stage, and then enter the next stage until the process of kernel initialization is completed; The traditional encryption algorithm is an encryption algorithm that maps the ciphertext encrypted by the commercial cipher algorithm to a specified character set; After completing the kernel initialization, dynamically obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by both the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-state tool through the kernel, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the dynamically obtained kernel parameters to achieve dynamic selection and switching of the encryption algorithm during operation.

[0020] The kernel parameter protection method based on the multi-stage parameter application mechanism in this embodiment implements a multi-stage parameter application mechanism. In each initialization stage (such as memory management, device driver loading, security module activation), the kernel security parsing engine reloads and decrypts the parameters to prevent incomplete or invalid parameter loading in a single stage. Through phased re-verification, the consistency of the parameters is ensured throughout the startup process. The key components of this mechanism include: (1) Checkpoint setting: The process of initializing the operating system kernel is divided into multiple stages, and key checkpoints for multiple stages are set during the kernel initialization process to ensure that the decrypted parameters can be reloaded and applied in each stage. The multiple stages can include: the initialization stage of the memory management subsystem, the device driver loading stage, and the security subsystem activation stage; (2) Phased re-verification: In each stage, not only are the parameters repeatedly applied, but also the validity of the parameters is secondarily verified to ensure that there are no problems with parameter invalidation or tampering in subsequent stages. As shown in Figure 2 Steps ⑥, ⑦, and ⑧ in [reference] respectively show the steps of applying the original kernel parameters in each of the N stages into which the process of initializing the operating system kernel is divided, and each time the original kernel parameters are applied, it includes an independent step of obtaining and decrypting the original kernel parameters, that is, Figure 2 Steps ① to ⑤ in [reference]. The parameter application operation is repeatedly executed at multiple key checkpoints during kernel initialization (such as memory management initialization, device driver loading, security module activation) to ensure that the kernel parameters can be correctly loaded and verified in all stages. After each stage completes the parameter application, the system records the application results and related status for subsequent auditing and security monitoring. At the same time, if an anomaly is detected, the correction process or alarm mechanism will be automatically triggered.

[0021] Figure 2 The user-state parameter generation and encrypted transmission process is described in detail in the form of a flowchart. Figure 3 It is a flowchart for decryption and parameter application in the kernel state, elaborating on the key steps in the system during kernel initialization. As shown in Figure 2 and Figure 3 In this embodiment, obtaining the transmission parameter including the encrypted kernel parameter ciphertext encrypted by both the commercial cipher algorithm and the traditional encryption algorithm passed in by the user-state tool and decrypting it using the decryption module to obtain the original kernel parameters includes: S101, receiving the transmission parameter passed in by the user-state tool through the kernel. As shown in Figure 2 ① in [reference], it includes metadata and the encrypted kernel parameter ciphertext encrypted by both the commercial cipher algorithm and the traditional encryption algorithm. The encryption method of the kernel parameter ciphertext (field name encrypted_method in this embodiment) is included in the metadata; the integrity of the passed-in transmission parameter is verified through a digital signature or checksum mechanism. If the integrity verification passes, proceed to the next step; otherwise, end and exit. S102, Parse the transmission parameters to read the encryption method in the metadata, and first decode the kernel parameter ciphertext encrypted by the dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm using the traditional encryption algorithm to obtain the kernel parameter ciphertext encrypted by the commercial cipher algorithm, and send the encryption method and the kernel parameter ciphertext encrypted by the commercial cipher algorithm to the decryption module, as Figure 2 shown in ② of S103, The decryption module sends a request to obtain the decryption key to the key management storage area through the security interface, as Figure 2 shown in ③ of S104, The decryption module receives the decryption key returned from the key management storage area through the security interface, and uses the decryption key to perform a decryption operation on the kernel parameter ciphertext encrypted by the commercial cipher algorithm to restore the original kernel parameters, as Figure 2 shown in ④ of ; Using the obtained decryption key, the decryption module in the kernel state performs a decryption operation on the ciphertext to restore the original kernel parameters. The decryption process depends on the same algorithm as when encrypting in the user state to ensure data consistency and correctness; During the decryption process, if it is found that the ciphertext is damaged or the key does not match, the system will trigger an error handling mechanism, record detailed logs, and process according to the set policy (such as retry, rollback, or interrupt startup). S105, The decryption module returns the original kernel parameters to the kernel, as Figure 2 shown in ⑤ of In this embodiment, the transmission parameters including the kernel parameter ciphertext encrypted by the dual hybrid encryption of the commercial cipher algorithm and the traditional encryption algorithm passed in by the user state tool are obtained, and the original kernel parameters are obtained by decrypting using the decryption module, which implements the (2) dynamic encryption method transfer mechanism, including: (1) Encrypted metadata separation transfer: The encryption algorithm identifier is clearly passed through the encryption method (encrypted_method), allowing the kernel to dynamically select the corresponding decryption logic at runtime according to the transmitted information, and the encryption policy can be switched without restarting the system. (2) Algorithm dynamic adaptation process: a. The user state selects the encryption algorithm according to the system configuration before transmission. b. The transmitted parameters after encryption include encrypted_method and the ciphertext encoded in Base64. c. The kernel security parsing engine reads encrypted_method, loads the corresponding decryption key from the isolated memory and performs decryption.

[0022] As an alternative implementation, the traditional encryption algorithm refers to the Base64 encryption algorithm, and the commercial encryption algorithms include one or more of the SM2 encryption algorithm and the SM4 encryption algorithm. The encryption method of the ciphertext of the kernel parameters encrypted by the commercial encryption algorithm can be the encryption of one commercial encryption algorithm, or the combined encryption of multiple commercial encryption algorithms, or the combined encryption of a commercial encryption algorithm and other algorithms, such as the combined encryption of a commercial encryption algorithm and the AES encryption algorithm. This embodiment provides a cascading processing mechanism for commercial encryption algorithms and Base64. During the generation process of encryption parameters, the cascading processing method of the commercial encryption algorithm (SM2 / SM4) and the conventional algorithm (AES) is adopted, and then transmitted after Base64 encoding, which not only meets the requirements of commercial encryption but also facilitates compatibility and cooperation with other systems.

[0023] In this embodiment, a key isolation storage mechanism is also implemented, which mainly includes: (1) Isolated memory segment: In this embodiment, the key management storage area uses the isolated memory allocated by kmalloc_cma to store the decryption key, and the isolated memory is set with some or all of the attributes of VM_IO, VM_DONTDUMP, and VM_DONTEXPAND to protect the decryption key stored in the isolated memory physically and logically, preventing memory dump and illegal access. (2) Secure access control: In this embodiment, it also includes a timed automatic update mechanism to periodically update the decryption key stored in the key management storage area, erase and destroy the expired decryption key. The key management storage area is a memory area isolated by hardware isolation technology based on the trusted execution environment TEE, and the trusted platform module TPM is used as the trust root to periodically detect the integrity of the key management storage area. When the integrity verification of the key management storage area fails, the decryption key stored in the key management storage area is updated, and the expired decryption key is erased and destroyed, so that the kernel ensures that only authorized decryption modules can access this isolated memory area through the access control mechanism, preventing the key from being leaked during operation. Through the above method, the key life cycle management is realized. In the key isolation storage mechanism, the key is not only protected during decryption, but also automatically updated, periodically erased and destroyed, reducing the risk of long-term residence. Combining with the hardware trust root (such as TPM or TEE) technology can further improve the security level of key management.

[0024] In step S103 of this embodiment, after the decryption module sends a request to obtain the decryption key to the key management storage area through the security interface, the response of the key management storage area to the request includes: parsing the request to obtain the decryption key to obtain the subject and object of the request, where the subject is the decryption module and the object is the requested decryption key; matching the subject and object of the request with a preset access control policy to verify the legality of the request. If the legality verification of the request passes, read the requested decryption key from the isolated memory and return the requested decryption key; otherwise, reject and exit.

[0025] Figure 4 shows the overall architecture of the operating system kernel parameter secure transmission system based on the dynamic encryption policy, and can intuitively understand the basic process of realizing dynamic parameter configuration through encrypted parameter transmission and secure decryption between the user mode and the kernel mode and the mutual cooperation between modules. As Figure 4 shown, this embodiment also includes the step of the user-mode tool passing the transmission parameter including the ciphertext of the kernel parameter to the kernel: S201, use the user-mode preprocessing module, which is either an independent tool or embedded in the hypervisor, to obtain the original kernel parameters defined in advance by developers in the application or script according to the system security requirements and kernel configuration requirements during the system development stage, including some or all of the debug level, device configuration, and security policy; S202, obtain the candidate commercial cipher algorithms according to the security policy in the system configuration file; S203, obtain the current system running environment and security requirements, and select the final encryption method for the ciphertext of the kernel parameters from the candidate commercial cipher algorithms according to the current system running environment and security requirements and the preset encryption method selection policy; S204, perform an encryption operation on the original kernel parameters using the final encryption method for the ciphertext of the kernel parameters; S205, encode and encrypt the ciphertext of the kernel parameters using a traditional encryption algorithm to map it to the specified character set, so as to obtain the ciphertext of the kernel parameters encrypted by both the commercial cipher algorithm and the traditional encryption algorithm; S206, generate metadata including the encryption method (encrypted_method) of the ciphertext of the kernel parameters from the final encryption method for the ciphertext of the kernel parameters, encapsulate the ciphertext of the kernel parameters encrypted by both the commercial cipher algorithm and the traditional encryption algorithm and the metadata in a structured data format to generate transmission parameters, and store them in the kernel startup parameters, device tree (DTS) nodes, or dedicated kernel interfaces to pass them into the kernel, ensuring that the transmission process is fortified to prevent eavesdropping or tampering in the middle.

[0026] As an alternative implementation, during the decryption and application processes in this embodiment, if an error occurs, the corresponding error handling mechanism is triggered, and detailed audit logs are recorded for subsequent tracking and problem troubleshooting.

[0027] This embodiment constructs a user-space and kernel-space collaborative processing system based on the kernel parameter protection method of the multi-stage parameter application mechanism. It consists of two parts: the user space and the kernel space, where: (1) The user space part includes: A parameter preprocessing module: responsible for encrypting and Base64 encoding the parameters to be transmitted. A dynamic encryption selector: supports algorithms such as SM2 / SM4 / AES, and dynamically selects the appropriate algorithm according to the system security policy and configuration. A metadata generation unit: generates parameter information containing the encryption algorithm identifier (encrypted_method) and other necessary metadata. (2) The kernel space part includes: A security parsing engine: responsible for parsing, decrypting, and distributing the parameters. A multi-stage application controller: repeatedly applies the decrypted parameters at different stages of kernel initialization (such as memory management, device driver loading, security subsystem activation). A key management storage area: realizes the secure storage and access control of keys using the key management storage area (for example, allocated through kmalloc_cma and setting the page attribute SECURE_MEM_FLAGS). This embodiment includes a complete security audit record mechanism. The system has a built-in detailed logging mechanism to audit key operations such as encryption, decryption, parameter application, and error handling, ensuring that any abnormal behavior can be traced in a timely manner and provided to security analysts for reference.

[0028] In summary, the kernel parameter protection method based on the multi-stage parameter application mechanism in this embodiment has the following characteristics: Full-process encrypted transmission: Encrypted transmission and secure storage are adopted from user-state parameter generation to kernel parameter application, comprehensively enhancing system security. Dynamic adaptation and switching: The encryption algorithm can be switched during runtime without restarting, meeting the requirements of different security levels and commercial cryptography standards. Multi-stage parameter validity: By applying parameters multiple times in each stage of kernel initialization, the continuous validity of the configuration is ensured. Kernel security protection: Isolated memory is used to store keys, and strict access control is set, greatly reducing the risk of key leakage; parameters are reloaded and verified in each stage of kernel initialization to ensure the validity of the configuration throughout the cycle. Dynamic encryption policy transfer mechanism: For the first time, commercial cryptography algorithms such as SM2 / SM4 are supported during the kernel parameter transfer process, allowing seamless switching of encryption policies during runtime. Key isolation storage scheme: The isolation memory and special page attributes are used to achieve the secure storage of keys in the kernel space, effectively preventing memory leakage and illegal access. Commercial cryptography algorithm and Base64 cascaded processing flow: During parameter encryption and transmission, sensitive data is first encrypted using the commercial cryptography algorithm and then Base64 encoded, taking into account both security and transmission compatibility. Compared with traditional methods, the advantages of the method in this embodiment are compared as shown in Table 1.

[0029] Table 1 Comparison of the advantages of the method in this embodiment and traditional methods

[0030] As can be seen from Table 1, compared with traditional methods, the method in this embodiment has significant advantages in both the risk of parameter leakage and the strength of resistance to brute force cracking. Although there is some additional delay in encryption / decryption processing in its kernel startup latency, this additional delay is completely acceptable in engineering implementation.

[0031] In addition, this embodiment also provides a kernel parameter protection system based on the multi-stage parameter application mechanism, including a microprocessor and a memory connected to each other, and the microprocessor is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism.

[0032] In addition, this embodiment also provides a computer-readable storage medium, in which a computer program or instruction is stored, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism through a processor.

[0033] In addition, this embodiment also provides a computer program product, including a computer program or instruction, and the computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism through a processor.

[0034] Those skilled in the art should understand that the technical solutions provided by the present invention can be in the form of a method, a system, or a computer program product. Therefore, the present invention can be implemented in the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can be in the form of a computer program product implemented on one or more computer-readable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code. The present invention is described with reference to the flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to the embodiments of the present invention. It should be understood that each process and / or block in the flowchart and / or block diagram can be realized by computer program instructions, and the combination of the processes and / or blocks in the flowchart and / or block diagram can also be realized. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate a device for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks. These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including an instruction device, and the instruction device realizes the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks. These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable devices provide steps for realizing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.

[0035] The above is only the preferred embodiment of the present invention, and the protection scope of the present invention is not limited to the above embodiments. All technical solutions within the idea of the present invention belong to the protection scope of the present invention. It should be noted that for those of ordinary skill in the art in this technical field, several improvements and refinements made without departing from the principle of the present invention should also be regarded as within the protection scope of the present invention.

Claims

1. A kernel parameter protection method based on a multi-stage parameter application mechanism, characterized in that, It includes the following steps: Divide the process of initializing the kernel of the operating system into multiple stages. In each stage, first obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of a commercial cipher algorithm and a traditional encryption algorithm passed in by the user-mode tool, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the kernel parameters of this stage, and then enter the next stage until the process of kernel initialization is completed; the traditional encryption algorithm is an encryption algorithm that maps the ciphertext encrypted by the commercial cipher algorithm to a specified character set; after completing the kernel initialization, dynamically obtain the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of a commercial cipher algorithm and a traditional encryption algorithm passed in by the user-mode tool through the kernel, and use the decryption module to decrypt and obtain the original kernel parameters. After successfully decrypting and obtaining the original kernel parameters, apply the dynamically obtained kernel parameters to achieve dynamic selection and switching of the encryption algorithm at runtime.

2. The kernel parameter protection method based on the multi-stage parameter application mechanism according to claim 1, wherein The obtaining of the transmission parameters including the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of a commercial cipher algorithm and a traditional encryption algorithm passed in by the user-mode tool and using the decryption module to decrypt and obtain the original kernel parameters includes: S101, receive the transmission parameters passed in by the user-mode tool through the kernel, including metadata and the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of a commercial cipher algorithm and a traditional encryption algorithm. The encryption method of the kernel parameter ciphertext is included in the metadata; perform integrity verification on the passed-in transmission parameters through a digital signature or checksum mechanism. If the integrity verification passes, jump to the next step; otherwise, end and exit. S102, parse the transmission parameters to read the encryption method in the metadata, and first decode the ciphertext of the kernel parameters encrypted by a dual hybrid encryption of a commercial cipher algorithm and a traditional encryption algorithm using the traditional encryption algorithm to obtain the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm, and send the encryption method and the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm to the decryption module. S103, the decryption module sends a request to obtain the decryption key to the key management storage area through the security interface. S104, the decryption module receives the decryption key returned from the key management storage area through the security interface, and uses the decryption key to perform a decryption operation on the ciphertext of the kernel parameters encrypted by the commercial cipher algorithm to restore the original kernel parameters. S105, the decryption module returns the original kernel parameters to the kernel.

3. The kernel parameter protection method based on a multi-stage parameter application mechanism according to claim 2, characterized in that The traditional encryption algorithm refers to the Base64 encryption algorithm, and the commercial cipher algorithm includes one or more of the SM2 encryption algorithm and the SM4 encryption algorithm.

4. The kernel parameter protection method based on a multi-stage parameter application mechanism according to claim 2, wherein The key management storage area stores the decryption key using the isolated memory allocated by kmalloc_cma, and the isolated memory is set with some or all of the attributes of VM_IO, VM_DONTDUMP, and VM_DONTEXPAND to achieve physical and logical protection of the decryption key stored in the isolated memory.

5. The kernel parameter protection method based on a multi-stage parameter application mechanism according to claim 4, wherein, It also includes a timing execution automatic update mechanism to update the decryption key stored in the key management storage area at regular intervals, erase and destroy the expired decryption key. The key management storage area is a memory area isolated by hardware isolation technology based on the trusted execution environment TEE, and the trusted platform module TPM is used as the trust root to regularly detect the integrity of the key management storage area. When the integrity verification of the key management storage area fails, the decryption key stored in the key management storage area is updated, and the expired decryption key is erased and destroyed.

6. The kernel parameter protection method based on a multi-stage parameter application mechanism according to claim 4, characterized in that, After the decryption module sends a request to obtain the decryption key to the key management storage area through the security interface in step S103, the response of the key management storage area to the request includes: parsing the request to obtain the decryption key to obtain the subject and object of the request, where the subject is the decryption module and the object is the requested decryption key; matching the subject and object of the request with the preset access control policy to verify the legality of the request. If the legality verification of the request passes, the requested decryption key is read from the isolated memory and the requested decryption key is returned; otherwise, it is rejected and exited.

7. The kernel parameter protection method based on a multi-stage parameter application mechanism according to claim 1, wherein It also includes the step of the user-state tool passing the transmission parameter including the ciphertext of the kernel parameter to the kernel: S201, using the user-state preprocessing module as an independent tool or embedded in the hypervisor to obtain the original kernel parameters defined in advance by developers in the application program or script according to the system security requirements and kernel configuration requirements during the system development stage, including some or all of the debug level, device configuration, and security policy; S202, obtaining the candidate commercial encryption algorithms according to the security policy in the system configuration file; S203, obtaining the current system running environment and security requirements, and selecting the final encryption method of the kernel parameter ciphertext from the candidate commercial encryption algorithms according to the current system running environment and security requirements and the preset encryption method selection policy; S204, performing an encryption operation on the original kernel parameters using the final encryption method of the kernel parameter ciphertext; S205, encoding and encrypting the kernel parameter ciphertext using the traditional encryption algorithm to map it to the specified character set, so as to obtain the kernel parameter ciphertext encrypted by the dual hybrid encryption of the commercial encryption algorithm and the traditional encryption algorithm; S206, generating metadata including the encryption method of the kernel parameter ciphertext from the final encryption method of the kernel parameter ciphertext, encapsulating the kernel parameter ciphertext encrypted by the dual hybrid encryption of the commercial encryption algorithm and the traditional encryption algorithm and the metadata in a structured data format to generate transmission parameters, and storing them in the kernel startup parameters, device tree nodes, or dedicated kernel interfaces to be passed to the kernel.

8. A kernel parameter protection system based on a multi-stage parameter application mechanism, comprising a microprocessor and a memory connected to each other, characterized in that, The microprocessor is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism according to any one of claims 1 to 7.

9. A computer-readable storage medium storing a computer program or instructions, characterized in that, The computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism according to any one of claims 1 to 7 through the processor.

10. A computer program product, comprising a computer program or instructions, characterized in that, The computer program or instruction is programmed or configured to execute the kernel parameter protection method based on the multi-stage parameter application mechanism according to any one of claims 1 to 7 through the processor.