TrustZone-based 5G clouded base station trusted starting method

By building a hardware trusted root in 5G cloud base station, building a trust chain and performing trustworthiness measurement throughout the process, the problem of imperfect trust chain in the 5G base station system is solved, and the comprehensive security protection of the base station system is achieved, ensuring the trustworthiness and communication security of the base station startup process.

CN120343550APending Publication Date: 2025-07-18INSTITUTE OF INFORMATION ENGINEERING CHINESE ACADEMY OF SCIENCES
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510556938.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-07-18

AI Technical Summary

Technical Problem

The prior art lacks the construction of trust chains from hardware to operating system and above in the 5G base station system, and the existing trusted startup method is only for program integrity detection, failing to fully guarantee the trustworthiness of the application, and there is a problem of insufficient security protection.

Method used

The hardware trusted root is built in the 5G cloud base station, and a trust chain is built through the TrustZone architecture to realize the full process of trustworthy measurement of RAN components and cloud environment, including integrity and security compliance detection, ensuring the secure startup from the hardware to the operating system and upper-level components.

Benefits of technology

It realizes all-round security protection of the base station system, ensures the credibility of the base station startup process, expands the trustworthiness scope of the 5G communication network, and provides comprehensive security guarantees for RAN components and cloud environment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120343550A_ABST
    Figure CN120343550A_ABST
Patent Text Reader

Abstract

The invention discloses a 5G cloud base station trusted starting method based on TrustZone. The method comprises the following steps: 1) a hardware trusted root is built in a CPU (Central Processing Unit) of a 5G clouded base station server, and the hardware trusted root is operated to measure and verify a boot loader and a TEE operating system of the 5G clouded base station server in sequence when the 5G clouded base station server is powered on, so that the construction of a TEE security world is completed; 2) setting an RAN trusted measurement application in the TEE safe world, and completing trusted measurement starting of the RAN trusted measurement application by a TEE operating system; 3) performing measurement verification on the REE operating system by the TEE operating system, loading the REE operating system after the verification is passed, and completing the construction of the REE common world; 4) calling the RAN trusted measurement application in the REE common world to measure and construct the clouded environment required by the operation of the RAN component and the RAN component in sequence; and starting the RAN component in the clouded environment to complete the credible starting of the 5G clouded base station.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of communication technology and relates to a 5G cloud base station trusted startup method based on TrustZone. Background Art

[0002] As the core equipment for providing 5G network services, 5G base stations are mainly used to provide 5G air interface protocol functions and support communication with terminal devices and core networks. In traditional access networks, the functions of base stations are concentrated on physical devices. In the 5G era, a variety of new technologies such as software-defined networking (SDN) and network function virtualization (NFV) realize the software and hardware decoupling of the wireless access network RAN. The functions of base stations are migrated from proprietary hardware platforms to general servers and can be virtualized and centrally processed. 5G cloud base stations can be realized through cloud computing platforms. However, this also brings new security risks to base stations, including a larger attack surface. These risks may pose a potential threat to the stability and security of 5G networks. The existing security protection for communication systems as a whole belongs to the plug-in, patch-type, and passive security enhancement on the standard system. There are problems such as solidified security mechanisms that are easy to be bypassed, and insufficient dynamic defense and active defense capabilities. Therefore, it is necessary to establish a base station system with built-in active security defense for 5G communication systems to provide stronger security protection.

[0003] Trusted computing technology is a common method of active defense. It is a computer security technology based on cryptography. Its core goal is to ensure the integrity of hardware, operating systems, applications and other components, thereby ensuring that the business runs in a trusted environment. It is mainly used for data privacy protection and integrity verification. The existing trusted technology applications in base station systems face the following technical challenges:

[0004] 1) Existing trusted technologies based on ARM chips are mostly used in terminal devices, and their application in base stations remains to be studied.

[0005] 2) The TrustZone architecture based on ARM chips mainly focuses on the trusted measurement startup from the trusted root to the operating system, and the trust chain construction for the parts above the operating system has not yet been perfected.

[0006] 3) Conventional trusted boot measurements only detect program integrity. In addition, for application trust measurements, some methods rely on PCR register storage in TPM and use remote attestation. Summary of the invention

[0007] Aiming at the problems existing in the prior art, the purpose of the present invention is to provide a trusted startup method for 5G cloudified base stations based on TrustZone, with a hardware trusted root built into the base station system, having a secure trusted chain based on the hardware trusted root, ensuring the trusted startup of the base station from hardware to the operating system and then to the base station system protocol stack components, and forming the security capabilities of 5G cloudified base station equipment that can prevent software and hardware vulnerability risks and ensure the communication service experience.

[0008] The present invention has the following key points:

[0009] 1) A trusted startup method for 5G cloudified base stations is proposed to implement the application of trusted technology in the base station system, meet the trusted requirements of the access network, and achieve the trusted protection of the base station.

[0010] 2) On the basis of constructing the trust chain from the hardware trusted root to the operating system in the conventional trusted startup, the trusted measurement for RAN components (distributed unit CU / centralized unit DU) and cloudified environment is further realized, achieving the trusted measurement and startup of the whole process.

[0011] 3) The trusted measurement of the server REE operating system layer, RAN components and cloudified environment is realized by constructing a RAN trusted measurement application in the secure world, and the measurement value is saved in the secure world to avoid data leakage. At the same time, the RAN trusted measurement application also needs to be trusted measured and started to ensure the security and trust of the application itself and the measurement verification process.

[0012] 4) On the basis of the integrity detection of the measurement content for the trusted startup of RAN components and cloudified environment, security compliance detection is introduced to ensure that it meets the security regulations in both operation security and communication security aspects.

[0013] The advantages of the present invention are as follows:

[0014] 1) The trusted startup on the base station side is realized in the access network to ensure the security and trust of the base station startup process. Compared with the existing 5G trusted protection measures, the trusted protection is no longer limited to terminal devices, and the application of the trusted field of 5G communication network is expanded.

[0015] 2) The step-by-step measurement and verification from the hardware trusted root to the whole process of RAN component operation are realized during the base station startup process. Compared with the existing trusted startup methods, the trust chain is further extended and constructed above the REE operating system layer to realize the whole process construction of the trust chain and provide all-round security protection.

[0016] 3) The measurement and verification of upper-layer RAN components and cloudified environments are carried out by building a RAN trusted measurement application in the secure world. At the same time, the trusted measurement startup of this application is also ensured. Compared with the existing application startup measurement methods, the measurement process and storage are more secure, and the security and trustworthiness of the measurement application itself are ensured.

[0017] 4) In the measurement process of the base station, the measurement content is not limited to traditional integrity detection. At the same time, through setting configuration data standards, security compliance detection can be carried out. Compared with traditional trusted measurement methods, the measurement content is more complete and comprehensive, and can detect whether RAN components and cloudified environments comply with security regulations, ensuring the security of the started application and communication security. Description of the Drawings

[0018] Figure 1 It is the overall flowchart of the trusted startup of the 5G cloudified base station.

[0019] Figure 2 It is the chain diagram of the trusted measurement startup of the 5G cloudified base station.

[0020] Figure 3 It is the flowchart of the startup phase of the TEE operating system.

[0021] Figure 4 It is the flowchart of the construction phase of the RAN trusted measurement application.

[0022] Figure 5 It is the flowchart of the startup phase of the REE operating system.

[0023] Figure 6 It is the flowchart of the construction phase of the cloudified environment and RAN components.

[0024] Figure 7 It is the process diagram of the trusted measurement service call of the REE operating system.

[0025] Figure 8 It is the process diagram of the trusted measurement service call of the virtual machine manager / virtual machine operating system.

[0026] Figure 9 It is the module diagram of the RAN trusted measurement application.

[0027] Figure 10 It is the flowchart of the RAN trusted measurement. Detailed Implementation Manner

[0028] The present invention will be further described in detail below with reference to the accompanying drawings. The examples given are only used to explain the present invention and are not intended to limit the scope of the present invention.

[0029] 1. Overall Process of the Trusted Startup of the 5G Cloudified Base Station

[0030] AsFigure 1 As shown in the figure, the overall trusted startup process of the 5G cloudified base station proposed by the present invention can be divided into four stages:

[0031] 1) The first stage is the TEE operating system startup stage. A hardware trusted root is built into the CPU of the ARM chip of the 5G cloudified base station server; when the 5G cloudified base station server is powered on, the hardware trusted root runs based on the TrustZone technology of the ARM architecture to measure and verify the bootloader and TEE operating system of the 5G cloudified base station server in sequence. After the measurement and verification are successful, the bootloader and TEE operating system are started and loaded to complete the construction of the TEE secure world;

[0032] 2) The second stage is the RAN trusted measurement application construction stage. Set the RAN trusted measurement application within the TEE secure world, and the TEE operating system completes the trusted measurement startup of the RAN trusted measurement application.

[0033] 3) The third stage is the REE operating system startup stage. The TEE operating system of the 5G cloudified base station server measures and verifies the REE operating system of the 5G cloudified base station server. After the verification passes, the REE operating system of the 5G cloudified base station server is started and loaded to complete the construction of the REE normal world.

[0034] 4) The fourth stage is the 5G base station cloudified environment and cloudified base station (Cloud RAN) component construction stage. Call the RAN trusted measurement application program built within the TEE secure world within the REE normal world of the 5G cloudified base station server, and measure and construct the cloudified environment and RAN components required for the operation of the RAN components in sequence. After starting the RAN components within the cloudified environment, the trusted startup process of the 5G cloudified base station is completed.

[0035] The trusted measurement startup chain of the 5G cloudified base station is as Figure 2 shown. Among them, the first stage corresponds to Figure 2 steps ① to ④ in the figure. In this stage, the hardware trusted root in the ARM built-in CPU performs trusted measurement on the bootloader. After the measurement and verification pass, the bootloader is started; then the bootloader performs trusted measurement on the TEE operating system, and after passing, the TEE operating system is started. The second stage corresponds to Figure 2 steps ⑤ to ⑥ in the figure. The TEE operating system performs trusted measurement on the RAN trusted measurement application program. After the trusted measurement passes, the RAN trusted measurement application program is started. The third stage corresponds to Figure 2 steps ⑦ to ⑧ in the figure. The TEE operating system performs trusted measurement on the REE operating system. After the trusted measurement passes, the REE operating system is started. The fourth stage corresponds to Figure 2 steps ⑨ to step The REE operating system performs a trusted measurement on the virtual machine manager, and after passing the measurement, the virtual machine manager is started; then the virtual machine manager performs a trusted measurement on the virtual machine operating system, and after passing the measurement, the virtual machine operating system is started; finally, the virtual machine operating system performs a trusted measurement on the RAN components (central unit CU / distribution unit DU), and after passing the measurement, the RAN components (CU / DU) are started. After the above steps are completed, the trusted measurement startup chain of the 5G cloudified base station is constructed.

[0036] 2. Specific processes for each stage

[0037] 2.1 Process flow in the TEE operating system startup stage

[0038] As Figure 3 shown, the process flow in the TEE operating system startup stage is as follows.

[0039] 1) The 5G cloudified base station server is powered on, and the hardware trust root (i.e., the ROM program) inside the CPU built into the ARM chip starts to run.

[0040] 2) The hardware trust root inside the CPU obtains the image data of the boot loader and its electronic signature, and obtains the signature public key of the boot loader from the OTP (one-time programmable memory) / efuse (electronic fuse storage unit) of the server.

[0041] 3) The ROM program uses the digital signature verification method to measure and verify the boot loader. If the verification is successful, the boot loader starts to run, and the pre-boot process is completed. If the verification fails, the server startup fails, and the server returns to the shutdown state.

[0042] 4) The boot loader obtains the image data of the TEE operating system and its electronic signature, and obtains the signature public key of the TEE operating system.

[0043] 5) The boot loader uses the digital signature verification method to measure and verify the TEE operating system. If the verification is successful, the TEE boot loader starts to run, and the TEE operating system startup process is completed. If the verification fails, the server startup fails, and the server returns to the shutdown state.

[0044] 2.2 Process flow in the RAN trusted measurement application construction stage

[0045] As Figure 4 shown, the process flow in the RAN trusted measurement application construction stage is as follows.

[0046] 1) The TEE operating system obtains the image data of the RAN trusted measurement application and its electronic signature, and obtains the signature public key of the RAN trusted measurement application.

[0047] 2) The TEE operating system uses digital signature verification to measure and verify the RAN trusted measurement application. If the verification is successful, it starts running the RAN trusted measurement application and completes the startup process of the RAN trusted measurement application. If the verification fails, the RAN trusted measurement service cannot be provided, and according to the high-trust requirement, the server resumes the shutdown state.

[0048] 2.3 REE Operating System Startup Phase Process

[0049] As Figure 5 shown, the REE operating system startup phase process is as follows.

[0050] 1) The TEE operating system obtains the image data and its electronic signature of the REE operating system, and obtains the signature public key of the REE operating system.

[0051] 2) The TEE operating system uses digital signature verification to measure and verify the REE operating system. If the verification is successful, it starts running the REE bootloader and completes the startup process of the REE operating system. If the verification fails, the server startup fails and the server resumes the shutdown state.

[0052] 2.4 Cloudified Environment and RAN Component Construction Phase Process

[0053] As Figure 6 shown, the cloudified environment and RAN component construction phase process is as follows.

[0054] 1) The REE operating system obtains the image data of the virtual machine manager and calls the measurement verification service provided by the RAN trusted measurement application.

[0055] 2) The RAN trusted measurement application performs integrity detection on the image data of the virtual machine manager by using the check value comparison method, and performs security compliance detection on the image data of the virtual machine manager by using the configuration data standard comparison method, completes the measurement verification of the virtual machine manager and returns the verification result. If the verification is successful, it starts running the virtual machine manager and completes the startup process of the virtual machine manager. If the verification fails, the RAN component startup fails, and according to the high-trust requirement, the server resumes the shutdown state.

[0056] 3) The virtual machine manager obtains the image data of the virtual machine operating system and calls the measurement verification service provided by the RAN trusted measurement application.

[0057] 4) The RAN trusted measurement application performs integrity detection on the image data of the virtual machine operating system by using the check value comparison method, and performs security compliance detection on the image data of the virtual machine operating system by using the configuration data standard comparison method, completes the measurement verification of the virtual machine operating system and returns the verification result. If the verification is successful, the virtual machine operating system starts running, and the startup process of the virtual machine operating system is completed. If the verification fails, the RAN component startup fails, and according to the high-trust requirement, the server resumes the shutdown state. Completing the startup of the virtual machine manager and the virtual machine operating system completes the startup of the cloudified environment.

[0058] 5) The virtual machine operating system obtains the image data of the RAN component and invokes the measurement verification service provided by the RAN trusted measurement application.

[0059] 6) The RAN trusted measurement application performs integrity detection on the image data of the RAN component by using the check value comparison method, and performs security compliance detection on the image data of the RAN component by using the configuration data standard comparison method, completes the measurement verification of the RAN component and returns the verification result. If the verification is successful, the RAN component starts running, and the startup process of the RAN component is completed. If the verification fails, the RAN component startup fails, and according to the high-trust requirement, the server resumes the shutdown state.

[0060] 3. The RAN trusted measurement application invokes

[0061] 3.1 The REE operating system invokes the RAN trusted measurement application service

[0062] As Figure 7 shown, the REE operating system invokes the corresponding security monitoring call SMC instruction to switch to the security monitoring mode, and then the security monitor switches to the TEE kernel in the secure world. The TEE kernel invokes the RAN trusted measurement application through the internal API. After the RAN trusted measurement application completes the trusted measurement, it switches to the TEE operating system through the internal API, then the TEE operating system switches to the security monitoring mode, and the security monitor switches to the REE operating system and returns the call result.

[0063] 3.2 The virtual machine manager / virtual machine operating system invokes the RAN trusted measurement application

[0064] As Figure 8As shown in the figure, the virtual machine monitor / virtual machine operating system switches to the REE operating system through the TZAPI (TrustZone API). The REE operating system calls the corresponding SMC security monitor call instruction to switch to the security monitor mode, and then the security monitor switches to the TEE kernel in the secure world. The TEE kernel calls the RAN trusted measurement application through the internal API. After the RAN trusted measurement application completes the trusted measurement, it switches to the TEE operating system through the internal API, and then the TEE operating system switches to the security monitor mode. The security monitor switches to the REE operating system, and the REE operating system switches to the virtual machine monitor / virtual machine operating system through the TZAPI to return the call result.

[0065] 4. RAN Trusted Measurement Application

[0066] 4.1 Function of RAN Trusted Measurement Application

[0067] As Figure 9 shown in the figure, the specific modules of the RAN trusted measurement application proposed by the present invention are as follows.

[0068] 1) Data Acquisition Module

[0069] The data acquisition module is used to receive the data to be measured and verified provided by the RAN trusted measurement service caller, including: the check value and configuration data of the object to be measured. Among them, the real-time check value of the object to be measured and verified is the hash calculation of the executable file of the object to be measured and verified by the caller when calling the RAN trusted measurement application, and the real-time check value for integrity detection is obtained through the hash calculation. The configuration data of the object to be measured and verified is the configuration data of the object to be measured and verified by the caller when calling the RAN trusted measurement application.

[0070] 2) Data Storage Module:

[0071] The data storage is used to store the data used in the RAN trusted measurement, and the specific functions include measurement verification standard information data and measurement result records.

[0072] a) Measurement Verification Standard Information Data: The measurement standard data required for the measurement verification process is set and stored in advance. It includes the original check value of the object to be measured and verified and the security compliance configuration data. The original check value of the object to be measured and verified is the hash calculation of its executable file when the object to be measured and verified is installed and compiled into an executable file. The original check value for integrity detection is obtained through the hash calculation. The security compliance configuration data of the object to be measured and verified is the configuration data standard that meets the 5G communication security and application security, including but not limited to whether the RAN components enable confidentiality and integrity protection.

[0073] b) Measurement result recording: Store the calculated values of the data to be measured during the measurement verification process, which can be used for subsequent further verification and proof processes.

[0074] 3) Measurement verification module

[0075] The measurement verification module is used to perform measurement verification on the data to be measured and verified, including integrity detection and security compliance detection.

[0076] a) Integrity detection: Obtain the real-time check value of the executable file of the object to be measured and verified and its original check value, and perform integrity detection using a comparison method. If the two are the same, the detection passes, and the object to be measured and verified is saved and security detection is performed. If the two are different, the detection fails, and the measurement verification fails and the calling party is notified that the data may have been maliciously tampered with.

[0077] b) Security compliance detection: Obtain the configuration data of the object to be measured and verified and compare it with the configuration data standard to detect whether the configuration data of the object to be measured and verified is the reference value or within the reference value range. Among them, the configuration data includes the communication configuration data and startup configuration data of the RAN component, the startup configuration data and management configuration data of the virtual machine manager, and the startup configuration data and kernel configuration data of the virtual machine operating system. If the configuration data meets the standard, the detection passes, and the configuration data of the object to be measured and verified is saved and the measurement verification is successful is returned. If the configuration data does not meet the standard, the detection fails, and the measurement verification fails and the calling party is notified that the data configuration does not comply with the security regulations.

[0078] 4.2 RAN Trusted Measurement Application Process

[0079] As Figure 10 shown, the RAN trusted measurement process is as follows.

[0080] 1) The calling party calls the RAN trusted measurement application and passes the data to be measured and verified to the data acquisition module in the RAN trusted measurement. The data to be measured and verified includes the real-time check value and configuration data of the object to be measured and verified.

[0081] 2) The data acquisition module receives the data to be measured and verified and passes it to the data storage module to store the data to be measured and verified.

[0082] 3) The data storage module stores the data to be measured and verified.

[0083] 4) The measurement verification module determines the type of the object to be measured and verified according to the data to be measured and verified. According to the type of the object to be measured and verified, obtain the original check value and security compliance configuration data of the object to be measured and verified from the data storage module.

[0084] 5) The measurement verification module first performs integrity detection on the object to be measured and verified, compares the original verification value and the real-time verification value of the object to be measured and verified. If the two are the same, the detection passes, and the real-time verification value is stored in the data storage module and security compliance detection is performed. If the two are different, the detection fails, and a measurement verification failure result is returned and the calling party is notified that the data may have been maliciously tampered with.

[0085] 6) The measurement verification module then performs security compliance detection on the object to be measured and verified, and performs security compliance detection on the configuration data of the object to be measured and verified using a standard comparison method. If the configuration data meets the standard, the detection passes, and the configuration data of the object to be measured and verified is stored in the data storage module and a measurement verification success result is returned. If the configuration data does not meet the standard, the detection fails, and a measurement verification failure result is returned and the calling party is notified that the data configuration does not meet the security regulations.

[0086] Although specific embodiments of the present invention are disclosed for illustrative purposes, which are intended to help understand the content of the present invention and implement it accordingly, those skilled in the art can understand that: without departing from the spirit and scope of the present invention and the appended claims, various substitutions, changes, and modifications are possible. Therefore, the present invention should not be limited to the content disclosed in the best embodiments, and the scope of protection required by the present invention is subject to the scope defined by the claims.

Claims

1. A trusted boot method for a 5G cloudified base station based on TrustZone, the steps of which include: 1) TEE operating system startup phase: A hardware trusted root is built into the CPU of the ARM chip of the 5G cloudified base station server; When the 5G cloudified base station server is powered on, the hardware trusted root runs and uses the TrustZone technology based on the ARM architecture to measure and verify the boot loader and the TEE operating system of the 5G cloudified base station server in sequence. After the measurement and verification are successful, the boot loader and the TEE operating system are started and loaded to complete the construction of the TEE secure world; 2) RAN trusted measurement application construction phase: Set the RAN trusted measurement application in the TEE secure world, and the TEE operating system completes the trusted measurement startup of the RAN trusted measurement application; 3) REE operating system startup phase: The TEE operating system measures and verifies the REE operating system. After the verification passes, the REE operating system is started and loaded to complete the construction of the REE normal world; 4) 5G base station cloudification environment and cloudified base station component construction phase: Call the RAN trusted measurement application in the REE normal world to measure and construct the cloudification environment and RAN components required for the operation of the RAN components in sequence; then start the RAN components in the cloudification environment to complete the trusted boot of the 5G cloudified base station.

2. The method according to claim 1, characterized in that, The REE operating system in the REE normal world calls the RAN trusted measurement application to measure and construct the virtual machine manager required for the operation of the RAN components; among them, the REE operating system calls the security monitor call SMC instruction to switch to the security monitor mode, and then the security monitor switches to the TEE kernel of the TEE secure world; the TEE kernel calls the RAN trusted measurement application through the internal API; when the RAN trusted measurement application completes the trusted measurement, it switches to the TEE operating system through the internal API, then the TEE operating system switches to the security monitor mode, and then the security monitor switches to the REE operating system.

3. The method according to claim 1, wherein The virtual machine monitor within the REE normal world is used to call the RAN trusted measurement application to measure and construct the virtual machine operating system required for the operation of RAN components, and the virtual machine operating system within the REE normal world is used to call the RAN trusted measurement application to measure and construct RAN components; wherein, the virtual machine monitor or the virtual machine operating system switches to the REE operating system through the TZAPI, the REE operating system calls the security monitor to execute the SMC instruction to switch to the security monitor mode, and then the security monitor switches to the TEE kernel in the TEE security world, and the TEE kernel calls the RAN trusted measurement application through the internal API; when the RAN trusted measurement application completes the trusted measurement, it switches to the TEE operating system through the internal API, then switches to the security monitor mode by the TEE operating system, and then switches to the REE operating system by the security monitor, and the REE operating system switches to the corresponding virtual machine monitor or virtual machine operating system through the TZAPI.

4. The method according to claim 1 or 2 or 3, characterized in that, The process of the RAN trusted measurement application is as follows: 41) The data acquisition module in the RAN trusted measurement application receives the data to be measured and verified; the data to be measured and verified includes the real-time check value and configuration data of the object to be measured and verified. 42) The data acquisition module sends the received data to be measured and verified to the data storage module in the RAN trusted measurement application. 43) The data storage module stores the data to be measured and verified. 44) The measurement and verification module in the RAN trusted measurement application obtains the original check value and security compliance configuration data of the object to be measured and verified from the data storage module according to the type of the object to be measured and verified in the data to be measured and verified. 45) The measurement and verification module first performs integrity detection on the object to be measured and verified, compares the original check value and the real-time check value of the object to be measured and verified. If the two are the same, the detection passes, the real-time check value is stored in the data storage module and step 46) is executed; if the two are different, the detection fails and the measurement and verification failure result is returned. 46) The measurement and verification module performs security compliance detection on the object to be measured and verified, and performs security compliance detection on the configuration data of the object to be measured and verified using the standard comparison method. If the configuration data meets the standard, the detection passes, the configuration data of the object to be measured and verified is stored in the data storage module and the measurement and verification success result is returned; if the configuration data does not meet the standard, the detection fails and the measurement and verification failure result is returned.

5. The method according to claim 1 or 2 or 3, characterized in that The method for sequentially performing measurement and verification on the boot loader and the TEE operating system of the 5G cloudified base station server based on the hardware trusted root is as follows: 11) The hardware trusted root obtains the image data and its electronic signature of the boot loader, and the signature public key of the boot loader; then uses the digital signature verification method to perform measurement and verification on the boot loader. If the verification is successful, the boot loader is run, and then step 12) is executed; if the verification fails, the 5G cloudified base station server fails to start. 12) The bootloader obtains the image data and its electronic signature of the TEE operating system, and obtains the signature public key of the TEE operating system; Then, the bootloader performs measurement verification on the TEE operating system by using digital signature verification. If the verification is successful, the TEE bootloader is run to complete the startup process of the TEE operating system; if the verification fails, the 5G cloudified base station server fails to start.

6. The method according to claim 1 or 2 or 3, characterized in that The method for the TEE operating system to perform measurement verification on the RAN trusted measurement application is as follows: The TEE operating system obtains the image data and its electronic signature of the RAN trusted measurement application, and obtains the signature public key of the RAN trusted measurement application; Then, measurement verification is performed on the RAN trusted measurement application by using digital signature verification. If the verification is successful, the RAN trusted measurement application program is run; if the verification fails, the RAN trusted measurement service cannot be provided.

7. The method according to claim 1 or 2 or 3, characterized in that The method for the TEE operating system to perform measurement verification on the REE operating system is as follows: The TEE operating system obtains the image data and its electronic signature of the REE operating system, and obtains the signature public key of the TEE operating system; Then, the TEE operating system performs measurement verification on the REE operating system by using digital signature verification. If the verification is successful, the REE bootloader is run to complete the startup process of the REE operating system; if the verification fails, the 5G cloudified base station server fails to start.

8. The method according to claim 1 or 2 or 3, characterized in that The method for constructing the cloudified environment required for RAN component operation and RAN components is as follows: 4a) The REE operating system obtains the image data of the virtual machine manager in the REE normal world; 4b) Call the RAN trusted measurement application to perform integrity detection on the image data of the virtual machine manager by using the check value comparison method, and perform security compliance detection on the image data of the virtual machine manager by using the configuration data standard comparison method, complete the measurement verification of the virtual machine manager and return the verification result. If the verification is successful, the virtual machine manager is run; If the verification fails, the RAN component fails to start; 4c) The virtual machine manager obtains the image data of the virtual machine operating system in the REE normal world; 4d) Call the RAN trusted measurement application to perform integrity detection on the image data of the virtual machine operating system by using the check value comparison method, and perform security compliance detection on the image data of the virtual machine operating system by using the configuration data standard comparison method, complete the measurement verification of the virtual machine operating system and return the verification result. If the verification is successful, the virtual machine operating system is run; If the verification fails, the RAN component fails to start; 4e) The virtual machine operating system obtains the image data of the RAN component; 4f) Call the RAN trusted measurement application to perform integrity detection on the image data of the RAN component by using the check value comparison method, and perform security compliance detection on the image data of the RAN component by using the configuration data standard comparison method, complete the measurement verification of the RAN component and return the verification result. If the verification is successful, run the RAN component; if the verification fails, the RAN component fails to start.

9. The method according to claim 1, wherein The hardware trusted root performs measurement verification on the bootloader and the TEE operating system in sequence based on the TrustZone technology of the ARM architecture.

10. The method according to claim 1, characterized in that, The RAN trusted measurement application measures the cloudified environment required for the operation of the RAN component and the RAN component in sequence, and saves the measurement values into the TEE secure world.