Integrity measurement method, device, computing equipment and system

The integrity measurement baseline value is determined by the server receiving and combining the intermediate baseline value of the patch activation situation, which solves the problem of low metric efficiency of program code segments under the hot patch mechanism, and achieves efficient integrity measurement.

CN120389869APending Publication Date: 2025-07-29HUAWEI TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410128760.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-29
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In systems that introduce hot patch mechanism, the integrity measurement of program code segments is inefficient, mainly due to the large number of patch functions, the number of baseline values increases exponentially, resulting in too long traversal.

Method used

The server receives the integrity metric value of the target code segment, and combines the patch activation situation and the preset intermediate baseline value to determine the integrity metric baseline value of the target code segment, reduce the number of offline calculated baseline values, and improve measurement efficiency.

Benefits of technology

When a large number of hot patches are configured in the program code segment, the number of offline calculation of baseline values is significantly reduced, improving the efficiency of integrity measurements and the reliability of results.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389869A_ABST
    Figure CN120389869A_ABST
Patent Text Reader

Abstract

The invention discloses an integrity measurement method and device, computing equipment and a system, and belongs to the technical field of network security. The method is applied to an integrity measurement system comprising a server and a client. At a server side, the method comprises the following steps: receiving an integrity metric value of a target code segment; determining an integrity measurement baseline value of the target code segment according to a patch activation condition of a function in the target code segment when the integrity measurement value of the target code segment is obtained through calculation and a plurality of intermediate baseline values preset by the server; and comparing the integrity metric value of the target code segment with the integrity metric baseline value of the target code segment to determine the integrity of the target code segment. Wherein the target code segment comprises a plurality of sub-code segments, and the plurality of intermediate baseline values comprise an integrity measurement baseline value calculated according to each of the plurality of sub-code segments under an offline condition. The method can improve the integrity measurement efficiency of the program code segment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technologies, and particularly to an integrity measurement method, apparatus, computing device, and system. Background Art

[0002] Dynamic Integrity Measurement (DIM) is a trusted technology. DIM can detect whether the program code segments in the system of a computing device have been tampered with or maliciously injected when the system of the computing device is running online, and based on this, it can determine whether a malicious attack has occurred on the system of the computing device. Among them, the basic idea of implementing DIM is: first, calculate the integrity measurement baseline value of the program code segments in the system of the computing device offline, and then calculate the integrity measurement value of the program code segments in the system of the computing device when the system is running online with the same algorithm. Furthermore, compare whether the integrity measurement value of the program code segments in the system of the computing device is the same as the integrity measurement baseline value calculated offline, so as to determine whether the program code segments in the system of the computing device have been tampered with or maliciously injected, and thus can evaluate the integrity of the program code segments in the system of the computing device.

[0003] In order to support the ability of a computing device to quickly repair process problems without restarting the process, many current computing device systems have introduced a hot patch mechanism. Among them, the hot patch mechanism modifies the first instruction of the function with problems (referred to as problem function) in the process to a jump instruction when the process is running, so that after the process executes the first instruction of the problem function, it can jump to execute the patch function of the problem function, thereby enabling the hot repair of the problem function in the process.

[0004] Since the hot patch mechanism introduces dynamic modification to the program code segments, when performing dynamic integrity measurement on the program code segments in a system with the hot patch mechanism introduced, in related technical solutions, it is necessary to calculate offline the integrity measurement baseline value of the program code segments under all combinations of the states (including activated and unactivated) of all patch functions in the program code segments. When the number of patch functions in the program code segments is large, the number of integrity measurement baseline values of the program code segments will increase exponentially, which will lead to extremely low integrity measurement efficiency for the program code segments. Summary of the Invention

[0005] This application provides an integrity measurement method, apparatus, computing device, and system, which can reduce the number of baseline values of the program code segments that need to be calculated offline and improve the integrity measurement efficiency of the program code segments.

[0006] The technical solutions provided by this application are as follows:

[0007] In a first aspect, the present application provides an integrity measurement method, which is applied to a server. The method includes: receiving an integrity measurement value of a target code segment, where the target code segment is a code segment corresponding to any process in a client; determining an integrity measurement baseline value of the target code segment according to the patch activation situation of functions in the target code segment when calculating the integrity measurement value of the target code segment and multiple intermediate baseline values preset in the server; comparing the integrity measurement value of the target code segment with the integrity measurement baseline value of the target code segment to determine the integrity of the target code segment. Among them, the target code segment includes multiple sub-code segments, and the multiple intermediate baseline values include integrity measurement baseline values calculated according to each sub-code segment among the multiple sub-code segments in an offline situation. When the function of the first sub-code segment in the target code segment is configured with a first patch, the integrity measurement baseline value calculated according to the first sub-code segment includes the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is active, and the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is inactive. The first sub-code segment is any one of the sub-code segments in the target code segment.

[0008] When the server performs integrity measurement based on the method provided by the present application, the server only needs to determine a baseline value corresponding to the measurement value of the program code segment running on the client based on the patch status of the program code segment function and the preset intermediate baseline value when calculating the measurement value of the program code segment running on the client, and implement the integrity measurement of the program code segment by comparing the measurement value of the program code segment with the baseline value. Compared with the related technology where the server needs to spend more time traversing the baseline value file, the solution of the present application can improve the efficiency of the server in performing integrity measurement of the program code segment.

[0009] In a possible design, when the function of the above-mentioned first sub-code segment is also configured with a second patch, the integrity measurement baseline value calculated according to the first sub-code segment includes: the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch and / or the second patch is active, and the integrity measurement baseline value calculated according to the first sub-code segment when the statuses of both the first patch and the second patch are inactive.

[0010] Through this possible design, when the program code segment running on the client includes multiple hot patches, the server presets baseline values of each sub-code segment in the program code segment in different patch statuses calculated offline. In this way, when the program code segment running on the client is configured with a large number of hot patches for hot fixing, when calculating the baseline values that need to be preset on the server by the method of the present application, the number of baseline values calculated offline for the program code segment in different patch status combinations can be greatly reduced.

[0011] In another possible design, when determining the integrity measurement baseline value of the target code segment based on the patch activation situation of the functions in the target code segment obtained through calculation and multiple intermediate baseline values preset on the server side, it includes: determining a target combination from the multiple intermediate baseline values according to the patch activation situation, where the target combination includes: when the patch status of the functions in the multiple sub-code segments is the status indicated by the patch activation situation, the integrity measurement baseline values calculated based on each of the multiple sub-code segments; calculating the integrity measurement baseline value of the target code segment according to the integrity measurement baseline values in the target combination. In this way, it is possible to calculate the integrity measurement baseline value of the target code segment based on the current patch activation situation of the target code segment and the intermediate baseline values pre-calculated in this application.

[0012] In yet another possible design, when the patch activation situation indicates that the patch status of at least one function in the multiple sub-code segments is activated, the target combination includes: the integrity measurement baseline values calculated based on each of the multiple sub-code segments when the patch status of the at least one function is activated.

[0013] In yet another possible design, when the patch activation situation indicates that the patch status of the functions in the multiple sub-code segments are all deactivated, the target combination includes: the integrity measurement baseline values calculated based on each of the multiple sub-code segments when the patch status of the functions in the multiple sub-code segments are all deactivated.

[0014] In yet another possible design, before determining the integrity measurement baseline value of the target code segment, the method further includes: receiving the patch activation information of the target code segment sent by the client to determine the patch activation situation. The patch activation information includes the identifier (ID) of at least one function, and the patch activation information is used to indicate that the patch status of the at least one function is activated. When measuring the integrity of the program code segment through the method of this application, it is necessary to obtain the patch activation situation of the program code segment, so that the integrity measurement baseline value of the program code segment can be calculated based on the patch activation situation of the program code segment and the intermediate baseline values of each sub-code segment in the corresponding situation.

[0015] In yet another possible design, before determining the integrity measurement baseline value of the target code segment, the method further includes: performing an integrity check on the integrity measurement value of the target code segment.

[0016] In yet another possible design, the integrity verification of the integrity measurement value of the target code segment includes: receiving the value of the platform configuration register (PCR) of the hardware trusted root in the client; performing integrity verification on the integrity measurement value of the received target code segment according to the value of the PCR.

[0017] Through the above two possible designs, the reliability of the integrity measurement value used to measure the integrity of the target code segment obtained by the server can be ensured, thereby ensuring the reliability of the measurement result when measuring the integrity of the target code segment.

[0018] In yet another possible design, the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment by function granularity, or the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment in an equal division manner.

[0019] In yet another possible design, the target code segment is a binary code segment. Alternatively, the target code segment is a decimal code segment or a hexadecimal code segment. Through this possible design, the application scope of the method provided by this application can be improved.

[0020] In a second aspect, this application provides an integrity measurement method. This method is applied to the client. When the client is running online, this method includes: calculating the integrity measurement value of each sub-code segment in the target code segment; calculating the integrity measurement value of the target code segment according to the integrity measurement value of each sub-code segment; sending the integrity measurement value of the target code segment to the server, and the integrity measurement value of the target code segment is used to measure the integrity of the target code segment. Among them, the target code segment is the code segment corresponding to any process in the client, and the target code segment includes multiple sub-code segments.

[0021] In a client with a hot patch mechanism introduced, when a large number of patches for hot repair are configured in the program code segment of the client, through the method of calculating the baseline value provided by this application, the number of baseline values calculated offline in advance for different state combinations of the patches in the program code segment can be greatly reduced.

[0022] In a possible design, multiple functions in the target code segment are configured with patches. The above method further includes: obtaining the patch activation information of the target code segment when calculating the integrity metric value of each sub-code segment, where the patch activation information includes the IDs of at least one function among the aforementioned multiple functions, and the patch activation information is used to indicate that the status of the patch of the at least one function is active. The above sending the integrity metric value of the target code segment to the server includes: sending the integrity metric value of the target code segment and the patch activation information to the server, and the patch activation information is used to determine the integrity metric baseline value of the target code segment when measuring the integrity of the target code segment according to the integrity metric value of the target code segment.

[0023] When measuring the integrity of a program code segment by the method of this application, it is necessary to obtain the patch activation situation of the program code segment. In this way, the integrity metric baseline value of the program code segment can be calculated based on the patch activation situation of the program code segment and the intermediate baseline value of each sub-code segment in the corresponding situation.

[0024] In another possible design, after calculating the integrity metric value of the target code segment according to the integrity metric value of each sub-code segment, the above method further includes: updating the value of the PCR of the hardware trusted root in the client according to the integrity metric value of the target code segment, and the updated value of the PCR is used to perform integrity verification on the integrity metric value of the target code segment. The above sending the integrity metric value of the target code segment to the server includes: sending the integrity metric value of the target code segment and the updated value of the PCR to the server.

[0025] Through this possible design, the reliability of the integrity metric value used by the server to measure the integrity of the target code segment can be ensured, and thus the reliability of the measurement result when measuring the integrity of the target code segment is ensured.

[0026] In another possible design, the above method further includes: receiving a challenge request sent by the server, where the challenge request is used to request the measurement of the integrity of the target code segment. The above sending the integrity metric value of the target code segment to the server includes: in response to the challenge request, sending the integrity metric value of the target code segment to the server.

[0027] In another possible design, the above multiple sub-code segments are multiple code segments obtained by dividing the target code segment at the function granularity, or the above multiple sub-code segments are multiple code segments obtained by dividing the target code segment in an equal division manner.

[0028] In another possible design, the target code segment is a binary code segment. Or, the target code segment is a decimal code segment or a hexadecimal code segment. Through this possible design, the application scope of the method provided by this application can be improved.

[0029] In a third aspect, the present application provides an integrity measurement device, which is applied to a server. The integrity measurement device is used to execute any of the methods provided in the first aspect above. The present application can divide the functional modules of the integrity measurement device according to any of the methods provided in the first aspect above. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. Exemplarily, the present application can divide the integrity measurement device into a transceiver unit, a processing unit, etc. according to functions. The descriptions of the possible technical solutions and beneficial effects executed by each of the above-divided functional modules can all refer to the solutions provided in the first aspect and any possible design manner in the first aspect, and will not be elaborated here.

[0030] In a fourth aspect, the present application provides an integrity measurement device, which is applied to a client. The integrity measurement device is used to execute any of the methods provided in the second aspect above. The present application can divide the functional modules of the integrity measurement device according to any of the methods provided in the second aspect above. For example, each functional module can be divided corresponding to each function, or two or more functions can be integrated into one processing module. Exemplarily, the present application can divide the integrity measurement device into a transceiver unit, a processing unit, etc. according to functions. The descriptions of the possible technical solutions and beneficial effects executed by each of the above-divided functional modules can all refer to the solutions provided in the second aspect and any possible design manner in the first aspect, and will not be elaborated here.

[0031] In a fifth aspect, the present application provides a computing device. The computing device includes: a memory, a network interface, and one or more processors. Among them, the one or more processors receive or send data through the network interface, and the one or more processors are configured to read program instructions stored in the memory to execute the methods provided in the first aspect and any possible design manner in the first aspect, or execute the methods provided in the second aspect and any possible design manner in the second aspect.

[0032] In a sixth aspect, the present application provides an integrity measurement system, which includes a server and a client. Among them, the server is used to execute the methods provided in the first aspect and any possible design manner in the first aspect, and the client is used to execute the methods provided in the second aspect and any possible design manner in the second aspect.

[0033] In a seventh aspect, the present application provides a computer-readable storage medium, which is a non-volatile computer-readable storage medium. The computer-readable storage medium includes program instructions. When the program instructions are executed by a computing device, a computer system, or a processor, the computing device, the computer system, or the processor executes the method provided in the first aspect and any possible design manner in the first aspect, or executes the method provided in the second aspect and any possible design manner in the second aspect.

[0034] In an eighth aspect, the present application provides a computer program product containing instructions. When the instructions are run by a computing device, a computer system, or a processor, the computing device, the computer system, or the processor is caused to execute the method provided in the first aspect and any possible design manner in the first aspect, or execute the method provided in the second aspect and any possible design manner in the second aspect.

[0035] In a ninth aspect, the present application provides a chip. The chip includes a processor for running program instructions or code. The chip or a device including the chip can be used to execute the method provided in the first aspect and any possible design manner in the first aspect, or used to execute the method provided in the second aspect and any possible design manner in the second aspect. Exemplarily, the chip further includes: an input interface, an output interface, and a memory. Among them, the input interface, the output interface, the processor, and the memory of the chip are connected through an internal connection path of the chip. The memory in the chip is used to store program instructions or code run by the processor, and the input interface and the output interface of the chip are used for connection and communication between the chip and other chips or devices.

[0036] It can be understood that any of the above-provided integrity measurement devices, computing devices, integrity measurement systems, computer-readable storage media, computer program products, or chips, etc. can be applied to the corresponding methods provided above. Therefore, the beneficial effects that can be achieved can refer to the beneficial effects in the corresponding methods, which will not be elaborated here.

[0037] In the present application, the names of the above integrity measurement devices, integrity measurement systems, computing devices, etc. do not constitute limitations on the devices or functional modules themselves. In actual implementation, these devices or functional modules may appear under other names. As long as the functions of each device or functional module are similar to those of the present application, they all fall within the protection scope of the present application. BRIEF DESCRIPTION OF THE DRAWINGS

[0038] Figure 1 is a schematic diagram of the principle of implementing integrity measurement through a jump island method;

[0039] Figure 2It is a schematic diagram of an implementation environment provided by an embodiment of the present application for the provided method;

[0040] Figure 3 It is a schematic diagram of a method for calculating the baseline value of a computing program code segment provided by an embodiment of the present application;

[0041] Figure 4 It is a schematic diagram of a sub-code segment under different state combinations of a patch provided by an embodiment of the present application;

[0042] Figure 5 It is another schematic diagram of a sub-code segment under different state combinations of a patch provided by an embodiment of the present application;

[0043] Figure 6 It is another schematic diagram of a method for calculating the baseline value of a computing program code segment provided by an embodiment of the present application;

[0044] Figure 7 It is a schematic flowchart of an integrity measurement method provided by an embodiment of the present application;

[0045] Figure 8 It is a schematic flowchart of a process for determining the baseline value of a target code segment provided by an embodiment of the present application;

[0046] Figure 9 It is another schematic flowchart of a complete measurement method provided by an embodiment of the present application;

[0047] Figure 10 It is a schematic structural diagram of an integrity measurement device provided by an embodiment of the present application;

[0048] Figure 11 It is another schematic structural diagram of an integrity measurement device provided by an embodiment of the present application;

[0049] Figure 12 It is yet another schematic structural diagram of an integrity measurement device provided by an embodiment of the present application;

[0050] Figure 13 It is a schematic structural diagram of a computing device provided by an embodiment of the present application. Detailed implementation manners

[0051] To make the objectives, technical solutions, and advantages of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.

[0052] For ease of understanding, the technologies and backgrounds involved in the embodiments of the present application will be explained first below.

[0053] 1), Dynamic Integrity Measurement (DIM)

[0054] DIM is a trusted technology used to evaluate the integrity of program code segments in a computing device system, thereby enabling determination of whether the program code segments in the computing device system have been tampered with or maliciously injected, and thus enabling determination of whether a malicious attack has occurred on the system of the computing device.

[0055] Among them, a program code segment refers to the code segment that implements a process, generally including the code segment that implements the process itself and the code segments of the library files on which the process depends. The code segment that implements the process itself is also referred to as the original code segment of the process.

[0056] When implementing DIM, it is necessary to calculate the integrity measurement baseline value and the integrity measurement value of the program code segment based on the same algorithm. Among them, the integrity measurement baseline value is calculated based on the offline program code segment, and the integrity measurement value is calculated based on the program code segment during online operation. It should be understood that offline means not connected to the network, and online means connected to the network. For simplicity of description, in the embodiments of the present application hereinafter, the "integrity measurement baseline value" will be abbreviated as the "baseline value", and the "integrity measurement value" will be abbreviated as the "measurement value".

[0057] Taking the algorithm for calculating the baseline value and the measurement value as the secure hash algorithm (SHA), for example, the typical SHA256, for code segment 0, when code segment 0 is offline, SHA256 can be used to perform a hash calculation on code segment 0 and obtain the corresponding hash value (or referred to as digest, digest value, etc.), and this hash value is used as the baseline value for performing DIM on code segment 0. When code segment 0 is running online in the computing device, the computing device can perform a hash calculation on the running code segment 0 through SHA256 and obtain the corresponding hash value, and this hash value is used as the measurement value for performing DIM on code segment 0. Then, compare whether the measurement value and the baseline value of code segment 0 are the same. When the measurement value and the baseline value of code segment 0 are the same, it indicates that code segment 0 has not been changed when running online in the computing device. When the measurement value and the baseline value of code segment 0 are different, it indicates that code segment 0 has been changed when running online in the computing device, and this change is usually caused by tampering or malicious injection due to a malicious attack.

[0058] 2) Hot patch mechanism

[0059] A patch is some code used to repair process problems / vulnerabilities. According to the impact of the patch on the operation of the service / process, patches are divided into hot patches and cold patches. Among them, the hot patch takes effect without interrupting the service / process and does not affect the operation of the service / process, so it can reduce the device upgrade cost and avoid upgrade risks. The cold patch takes effect by restarting the device, thus affecting the operation of the service / process.

[0060] The hot patch mechanism is a mechanism for repairing process problems / vulnerabilities through hot patches without restarting the process.

[0061] Taking the process 1 in a computing device including the following function A (denoted as FunA) as an example:

[0062] FunA: push

[0063] move

[0064] …

[0065] ret

[0066] Among them, "push" is a push instruction, "ret" is a return instruction, and "move" is an instruction to transfer data from one storage area to another storage area, or an instruction to assign data to a variable, without limitation. When there is a vulnerability in FunA, and the computing device includes a patch function A' (denoted as FunA') for repairing the problem of FunA, and the logical address of FunA' is x, the process of repairing FunA through the hot patch mechanism includes: when process 1 is running, modifying the first instruction "push" of FunA to a jump instruction "jump x" for indicating a jump to the logical address x. At this time, FunA after modifying the first instruction is:

[0067] FunA: jump x

[0068] move

[0069] …

[0070] ret

[0071] In this way, when the computing device runs process 1 and executes to FunA, by executing the first instruction "jump x" of FunA, it can jump to the logical address x of FunA' and execute FunA' stored at the logical address x, so as to realize the repair of the problematic FunA in process 1, and this repair is called hot repair.

[0072] 3), Platform Configuration Register (PCR)

[0073] PCR is one of the basic components of a trusted platform module (TPM) chip. Its main purpose is to provide a cryptography-based method for measuring the software state. The measurement objects include the software running on the platform and the configuration data used by the software. The value of the PCR cannot be modified but only overwritten. The caller can only update the value of the PCR through an operation called "extend", which is a one-way hash calculation. Among them, the TPM essentially isolates an area with independent processing and storage capabilities on the host in the form of a security chip.

[0074] Since the hot patching mechanism introduces dynamic modification of the program code segment of the process, and in related technologies, the system of the computing device generally introduces a code layout randomization mechanism to improve the anti-attack ability. That is, the starting addresses of the code segment and the patch function are random and change each time the process running on the computing device starts the program. This results in the jump address of the jump instruction inserted when repairing the problem function through hot patching (i.e., the address "x" mentioned above) cannot be determined offline, thus leading to the inability to calculate the baseline value of the program code segment after activating the hot patch offline.

[0075] In related technologies, the above problem is solved by the way of jump island. As Figure 1 shown, Figure 1 shows a schematic diagram of the principle of integrity measurement implemented by the jump island method. As Figure 1 shown, for any process in the computing device that needs to perform integrity measurement (referred to as the target process), the computing device pre-allocates a space of a preset size in the storage space of the original data segment of the target process as the jump island, and reserves corresponding spaces for each function of the target process in the jump island, and the order of the spaces corresponding to the functions in the target process in the jump island is preset. For any function in the target process, such as FunA, assume that the relative address of the space corresponding to FunA in the jump island relative to the space where FunA is located is x, and the address of the patch function FunA' of FunA is y. Then when the computing device performs hot repair on FunA, first modify the first instruction of FunA to a jump instruction "jump x" that jumps to the relative address x. Among them, the space indicated by the relative address x includes a jump instruction "jump y" that jumps to the address y where the patch function FunA' of FunA is located. Therefore, when the computing device executes to FunA, it will jump to the relative address x of the jump island according to the jump instruction "jump x", and execute the jump instruction "jump y" in the space indicated by the relative address x, jump to the address y of the patch code segment of the target process, and execute FunA' at the address y, so as to achieve the hot repair of FunA.

[0076] Among them, since the jump island is located in the space where the original data segment corresponding to the original code segment of the target process is located, the relative address x is fixed and unchanged every time the target process starts. Although the address of the patched code segment of the target process changes every time the target process starts, resulting in the address y of FunA' (which can also be called the absolute address y) changing every time the target process starts, it is only necessary to synchronously update the latest address y to the jump instruction in the jump island every time the target process starts or the patch is loaded. Since the jump island is located in the original data segment corresponding to the original code segment of the target process, even if the address indicating the space where the patched function is located in the jump instruction of the jump island changes, it will not cause the baseline value calculated based on the original code segment to change when the patch is activated.

[0077] By introducing the jump island, the problem that hot patching randomly and unpredictably modifies the program code segment can be solved. Therefore, the possible baseline values of the program code segment of the process can be calculated in advance offline after the hot patch is activated. In this way, when performing integrity measurement on the original code segment after activating the hot patch, the integrity measurement will not fail and trigger an integrity warning due to the modification of the program code segment caused by activating the hot patch of the program code segment. Among them, the "possible baseline values" include the baseline values of the program code segment under all state combinations (including activated and non-activated) of all patched functions in the program code segment. For example, if the program code segment includes Patch 1 and Patch 2, the "possible baseline values" include: the baseline value 1 calculated based on the program code segment when both Patch 1 and Patch 2 are activated, the baseline value 2 calculated based on the program code segment when Patch 1 is activated but Patch 2 is not activated, the baseline value 3 calculated based on the program code segment when Patch 1 is not activated but Patch 2 is activated, and the baseline value 4 calculated based on the program code segment when neither Patch 1 nor Patch 2 is activated.

[0078] Since each hot patch has two states, including activated and non-activated, in the solution based on the jump island, for a certain process in the computing device, such as Process A, when Process A needs to perform hot patch repair on n (n is a positive integer) functions at the same time, the total number of state combinations of the hot patches of the n functions is 2 n , so the number of baseline values calculated offline for measuring the integrity of the program code segment of Process A is also 2 n . As shown in Table 1, Table 1 shows the corresponding relationship between the number of functions that need to be hot patch repaired in a certain program code segment, the number of baseline values of the program code segment calculated offline, and the size of the corresponding baseline value file.

[0079] Table 1

[0080] Number of functions that need hot patch repair Number of baseline values Size of the baseline value file 2 <![CDATA[4(2 2 )]]> 128 bytes (byte, B) 10 <![CDATA[1024(2 10 )]]> 32 kilobytes (kilobyte, KB) 20 <![CDATA[1048576(2 20 )]]> 32 megabytes (megabyte, MB) 100 <![CDATA[2 100 > <![CDATA[2 75 gigabyte (GB)

[0081] It can be seen that as the number of functions in the program code segment that need to be hot-patched for repair increases, the number of baseline values and the size of the baseline value file used to measure the integrity of the program code segment will increase exponentially, resulting in an exponential increase in the time spent traversing the baseline value file based on the measurement value calculated when the program code segment is online to determine whether the baseline value file includes the same baseline value as the measurement value, which in turn leads to extremely low efficiency in measuring the integrity of the program code segment.

[0082] Based on this, an embodiment of the present application provides an integrity measurement method, which greatly reduces the number of baseline values of the program code segments that need to be calculated offline when performing integrity measurement on program code segments in a system that introduces a hot patch mechanism, and can improve the efficiency of comparing the baseline value and measurement value of the program code segment, thereby improving the efficiency of integrity measurement of the program code segment.

[0083] refer to Figure 2 , Figure 2 A schematic diagram showing an implementation environment of the method provided in the embodiment of the present application is shown. Figure 2 As shown, the implementation environment includes a server and at least one client ( Figure 2 The integrity measurement system of only one client is shown as an example. In which, one or more of the at least one client supports a hot patch mechanism.

[0084] In the above-described integrity measurement system, the server pre-stores a baseline value calculated offline based on a target code segment, and the client calculates the measurement value of the target code segment at runtime. The target code segment is any program code segment running on the client and for which integrity measurement is required. For example, the program code segment can be the original code segment of any process running on the client, or the code segment of any library file that any process running on the client depends on, but is not limited to these.

[0085] In some embodiments, after calculating the metric value of the target code segment, the client sends a metric request including the metric value to the server, and the server then performs integrity measurement on the target code segment based on a pre-stored baseline value and the received metric value.

[0086] In some other embodiments, when the server needs to perform integrity measurement on the program code segment of the client, it sends a challenge request to the client. In response, the client sends the measurement value of the target code segment to the server so that the server can perform integrity measurement on the target code segment according to the pre-stored baseline value and the received measurement value. Exemplarily, in a network 0 including multiple packet forwarding devices, the network manager of the network 0 acts as the server, and each packet forwarding device in the network 0 acts as a client. When the network manager performs integrity measurement on the program code segment running on the packet forwarding device in the network 0 to detect whether the packet forwarding device as a whole is secure and reliable, the network manager of the network 0 pre-stores the baseline value of each program code segment running on each packet forwarding device in the network 0, and when each packet forwarding device in the network 0 is running online, it periodically calculates the measurement value of each program code segment running on itself. Further, when the network manager needs to forward data streams with high security requirements through some packet forwarding devices in the network 0, it can first send a challenge request to these packet forwarding devices to request integrity measurement of the program code segments in these packet forwarding devices, so as to implement the measurement of the reliability of these packet forwarding devices. In response, these packet forwarding devices send the measurement values of all program code segments calculated in the latest period to the network manager, and the network manager performs integrity measurement on each program code segment running in these packet forwarding devices according to the pre-stored baseline value and the received measurement value, so as to determine whether these packet forwarding devices are secure and reliable. It can be understood that when the server determines that a program code segment is incomplete according to the measurement value of any program code segment running on a certain packet forwarding device and the baseline value of this program code segment, the server can determine that this program code segment has been tampered with or maliciously injected, that is, it can be determined that this packet forwarding device is unreliable.

[0087] Optionally, the server and the client in the integrity measurement system are independent devices, or the functions implemented by the server in the integrity measurement system can be implemented by one or more clients in the integrity measurement system, and this is not limited.

[0088] The client and the server in the above integrity measurement system can be any computing device with computing capabilities, and the specific implementation form of this computing device is not limited in the embodiments of the present application. Exemplarily, the computing device acting as the client can be any network device, such as a packet forwarding device (router, switch, etc.), a gateway, etc., and is not limited thereto. Or, the computing device acting as the client can be a terminal device, such as a mobile phone, a laptop computer, a general-purpose computer, a tablet, etc., and is not limited thereto. Again exemplarily, the computing device acting as the server can be implemented as a server (such as a remote attestation server), a network manager in a network, a cloud security platform, etc., and is not limited thereto. Among them, the remote attestation server is a server used to verify the credibility of network devices.

[0089] It should be understood that the above content is an exemplary description of the implementation environment of the method provided by the embodiments of the present application, and does not constitute a limitation on the implementation environment of the method. Those of ordinary skill in the art will know that with the change of business requirements, the implementation environment of the method can be adjusted according to actual needs, and the embodiments of the present application will not list them one by one.

[0090] The embodiments of the present application also provide an integrity measurement device. This device can be applied to the above-mentioned client and is used to execute the part of the method provided by the embodiments of the present application that is executed by the client. Or, this device is applied to the above-mentioned server and is used to execute the part of the method provided by the embodiments of the present application that is executed by the server. Optionally, this device can be any computing device with computing capabilities, or a functional module in this computing device, and no limitation is made thereto. In one example, this computing device can be any network device, such as a packet forwarding device (router, switch, etc.), gateway, server, network management in the network, cloud security platform, etc., not limited thereto. In another example, this computing device can be a terminal device, such as a mobile phone, laptop computer, general computer, tablet, etc., not limited thereto.

[0091] The implementation process of the integrity measurement method provided by the embodiments of the present application will be described below.

[0092] First, before performing integrity measurement on the program code segment of the client, it is necessary to calculate offline the baseline value for measuring the integrity of the program code segment. Here, the device used to calculate this baseline value offline can be any computing device with computing capabilities. As an example, this computing device can be the computing device of the client described above, or the computing device of the server described above, or a third-party computing device other than the client and the server, and no limitation is made thereto.

[0093] In one scenario, when the program code segment whose integrity needs to be measured is configured with a patch function (hereinafter referred to as a patch), refer to Figure 3 , Figure 3 FIG. shows a schematic diagram of a method for calculating the baseline value of a program code segment provided by the embodiments of the present application. Optionally, this method is executed by a computing device with the hardware structure described below Figure 13 The method includes the following steps.

[0094] Step 101: Divide the target code segment into multiple sub-code segments.

[0095] Among them, the target code segment is any program code segment running on the client and whose integrity needs to be measured. For example, this any program code segment is the original code segment of any process running on the client, or the code segment of any library file relied on by any process running on the client, not limited thereto.

[0096] In one example, when it is necessary to perform reliability verification on the entire client, each program code segment of each process in the client is used as a target code segment. That is, the number of target code segments is the same as the number of program code segments included in all processes in the client. It can be understood that the program code segments of a process include the original code segments of the process and at least one library file code segment on which the process depends.

[0097] In another example, when it is necessary to perform reliability verification on a target process in the client, each program code segment of the target process is used as a target code segment. That is, the number of target code segments is the same as the number of program code segments included in the target process. Among them, the program code segments of the target process include the original code segments of the target process and at least one library file code segment on which the target process depends.

[0098] Optionally, the target code segment is a binary code segment. Optionally, the target code segment can also be a decimal code segment or a hexadecimal code segment, and there is no limitation on this.

[0099] For any target code segment, the computing device can divide the target code segment into multiple sub-code segments in any of the following ways.

[0100] Method 1: The computing device divides the target code segment into multiple sub-code segments with functions as the granularity.

[0101] Optionally, the computing device divides the target code segment into multiple sub-code segments with a single function or multiple functions as the unit granularity.

[0102] Taking the case where the computing device divides the target code segment into multiple sub-code segments with a single function as the unit granularity as an example, in an example where the target code segment includes n functions, the computing device can use the last instruction of each function in the target code segment as the boundary to divide the target code segment into multiple sub-code segments. In one possible case, when the last instruction of the last function in the target code segment is the last instruction of the target code segment, the computing device can use the last instruction of each function in the target code segment as the boundary to divide the target code segment into n sub-code segments, and each sub-code segment in the n sub-code segments includes one function. In another possible case, when the last instruction of the last function in the target code segment is not the last instruction of the target code segment, the computing device can use the last instruction of each function in the target code segment as the boundary to divide the target code segment into n + 1 sub-code segments. Among the n + 1 sub-code segments, each of the first n sub-code segments includes one function, and the (n + 1)th sub-code segment does not include a function.

[0103] Still taking the example that the computing device divides the target code segment into multiple sub-code segments with a single function as the unit granularity. In the example where the target code segment includes n functions, the computing device can also divide the target code segment into multiple sub-code segments with the first instruction of each function in the target code segment as the boundary. In one possible case, when the first instruction of the first function in the target code segment is the first instruction of the target code segment, the computing device can divide the target code segment into n sub-code segments with the first instruction of each function in the target code segment as the boundary, and each sub-code segment in the n sub-code segments includes one function. In another possible case, when the first instruction of the first function in the target code segment is not the first instruction of the target code segment, the computing device can divide the target code segment into n + 1 sub-code segments with the first instruction of each function in the target code segment as the boundary. Among the n + 1 sub-code segments, the first sub-code segment does not include a function, and each of the second to the (n + 1)th sub-code segments includes one function.

[0104] Method 2: The computing device divides the target code segment into multiple sub-code segments in an equal division manner.

[0105] Optionally, the computing device divides the target code segment into multiple sub-code segments with a preset value. Among them, the preset value can represent the number of instruction lines of a preset quantity, or the preset value can represent an instruction of a preset size.

[0106] In the example where the target code segment includes j instructions, assuming the preset value is k and represents k instructions, both j and k are integers, and k is less than j. Then, when the value of (j / k) is an integer, the computing device can divide the target code segment into (j / k) sub-code segments, and each sub-code segment includes k instructions. When the value of (j / k) is a non-integer, the computing device can divide the target code segment into sub-code segments. Among them, represents rounding up the value of (j / k). And, in sub-code segments, each of the first sub-code segments includes k instructions, and the number of instructions in the th sub-code segment is less than k.

[0107] In the example where the size of the target code segment is s, when the preset value is t and t is less than s. Then, when the value of (s / t) is an integer, the computing device can divide the target code segment into (s / t) sub-code segments, and the size of each sub-code segment is t. When the value of (s / t) is a non-integer, the computing device can divide the target code segment into sub-code segments. And, in sub-code segments, each of the first sub-code segments has a size of t, and the The size of each sub - code segment is less than t.

[0108] It should be noted that the division of the target code segment into multiple sub - code segments by Method 1 and Method 2 in the embodiments of the present application is only for exemplary illustration and does not constitute a limitation on the protection scope of the present application. Any method capable of dividing the target code segment into multiple sub - code segments is within the protection scope of the present application.

[0109] Step 102: Calculate the intermediate baseline value of each sub - code segment in the multiple code segments.

[0110] Among them, the intermediate baseline value of each sub - code segment in the multiple sub - code segments obtained by dividing the target code segment is the baseline value required when using the method provided in the embodiments of the present application to perform integrity measurement on the target code segment.

[0111] Among them, the baseline value of a sub - code segment refers to the integrity measurement baseline value calculated for the sub - code segment through a first preset algorithm. The first preset algorithm refers to any algorithm used to calculate the baseline value and measurement value of a program code segment when performing integrity measurement on the program code segment. For example, the first preset algorithm is the SHA256 algorithm, but is not limited thereto. The embodiments of the present application do not elaborate on the process of calculating, through the first preset algorithm, the baseline value for any program code segment (such as a certain sub - code segment) for integrity measurement of the program code segment.

[0112] In one case, for any one of the multiple sub - code segments obtained by dividing the target code segment, such as the first sub - code segment, when the first sub - code segment includes at least one function and one or more of the at least one function are configured with patches, the intermediate baseline value of the first sub - code segment includes: the baseline values calculated for the first sub - code segment in each state combination of all patches of the functions in the first sub - code segment through the first preset algorithm. Among them, the state of the patch includes activated and unactivated. Therefore, when the computing device calculates the intermediate baseline value of each sub - code segment in the multiple code segments, it includes: in each state combination of all patches of the functions in the first sub - code segment, the computing device calculates the first sub - code segment in each state combination through the first preset algorithm to obtain the baseline value of the first sub - code segment in each state combination, and the baseline value of the first sub - code segment in each state combination is used as the intermediate baseline value of the first sub - code segment.

[0113] It can be understood that, in this case, the number of intermediate baseline values of the first sub-code segment is the same as the number of state combinations of all patches of the functions in the first sub-code segment. That is, when there are multiple patches configured for the functions in the first sub-code segment of the target code segment, the computing device can calculate multiple intermediate baseline values of the first sub-code segment. For example, when the function in the first sub-code segment is configured with a first patch, the multiple intermediate baseline values include the baseline value calculated according to the first sub-code segment when the state of the first patch is active, and the baseline value calculated according to the first sub-code segment when the state of the first patch is inactive. When the function in the first sub-code segment is configured with a second patch in addition to the first patch, the multiple intermediate baseline values include: the baseline value calculated according to the first sub-code segment when the state of the first patch and / or the second patch is active, and the baseline value calculated according to the first sub-code segment when the states of both the first patch and the second patch are inactive. Among them, the baseline value calculated according to the first sub-code segment when the state of the first patch and / or the second patch is active includes: the baseline value calculated according to the first sub-code segment when the state of the first patch is active, the baseline value calculated according to the first sub-code segment when the state of the second patch is active, and the baseline value calculated according to the first sub-code segment when the states of both the first patch and the second patch are active. It should be understood that one function in the code segment corresponds to one patch.

[0114] As an example, assume that the target code segment is divided into 6 sub-code segments, and the 6 sub-code segments include sub-code segment 1, sub-code segment 2, sub-code segment 3, sub-code segment 4, sub-code segment 5, and sub-code segment 6. Among them. Sub-code segment 1 includes FunA configured with a patch, sub-code segment 2 includes FunB configured with a patch, and sub-code segment 5 includes FunC and FunD configured with patches.

[0115] For sub-code segment 1, since the state of one patch includes two states: active and inactive, and there is only one function (i.e., FunA) in sub-code segment 1 configured with a patch, that is, the number of patches in sub-code segment 1 is 1, so the number of state combinations of all patches of the function in sub-code segment 1 is 2 1 , that is, 2. In this case, referring to Figure 4 , Figure 4 shows a schematic diagram of a sub-code segment under different state combinations of patches provided by an embodiment of the present application.

[0116] As Figure 4 shown, when the state of the patch of FunA is inactive, the first instruction of FunA in sub-code segment 1 is "push". At this time, the computing device passes the first preset algorithm to Figure 4Perform calculations on the "sub - code segment 1 when the patch of FunA is not activated" shown, to obtain an intermediate baseline value of sub - code segment 1, denoted as baseline value 11. When the status of the patch of FunA is activated, the first instruction of FunA in sub - code segment 1 is modified from "push" to a jump instruction "jump x", where x is the address of the patch of FunA. At this time, the computing device uses the first preset algorithm to Figure 4 Perform calculations on the "sub - code segment 1 when the patch of FunA is activated" shown, to obtain another intermediate baseline value of sub - code segment 1, denoted as baseline value 12. It can be seen that when the number of status combinations of all patches of the function in sub - code segment 1 is 2, the number of intermediate baseline values of sub - code segment 1 is also 2 (including baseline value 11 and baseline value 12).

[0117] Similarly, for sub - code segment 2, the sub - code segment only includes one function (i.e., FunB) configured with a patch. Therefore, the number of status combinations of all patches of the function in sub - code segment 2 is 2. Thus, the computing device, under the two status combinations of all patches of the function in sub - code segment 2, uses the first preset algorithm to perform calculations on sub - code segment 2 under these two status combinations respectively, and can calculate 2 intermediate baseline values of sub - code segment 2, denoted as baseline value 21 and baseline value 22.

[0118] For sub - code segment 5, since the status of a patch includes two states: activated and not activated, and sub - code segment 5 includes two functions (i.e., FunC and FunD) configured with patches, that is, the number of patches in sub - code segment 5 is 2. Therefore, the number of status combinations of all patches of the function in sub - code segment 5 is 2 2 , that is, 4. In this case, referring to Figure 5 , Figure 5 shows another schematic diagram of the sub - code segment under different status combinations of the patch provided by the embodiment of the present application.

[0119] As Figure 5 shown, when the statuses of the patches of FunC and FunD are both not activated, the first instructions of FunC and FunD in sub - code segment 5 are both "push". At this time, the computing device uses the first preset algorithm to Figure 5 Perform calculations on the "sub - code segment 5 when the patches of FunC and FunD are not activated" shown, to obtain an intermediate baseline value of sub - code segment 5, denoted as baseline value 51. When the statuses of the patches of FunC and FunD are both activated, the first instruction of FunC in sub - code segment 5 is modified from "push" to a jump instruction "jump c", and the first instruction of FunD in sub - code segment 5 is modified from "push" to a jump instruction "jump d", where c is the address of the patch of FunC and d is the address of the patch of FunD. At this time, the computing device uses the first preset algorithm to Figure 5Perform calculations on "Sub - code segment 5 when patching FunC and FunD are activated" as shown, to obtain another intermediate baseline value of Sub - code segment 5, denoted as baseline value 52. When the status of the patch of FunC is not activated and the status of the patch of FunD is activated, the first instruction of FunC in Sub - code segment 5 is "push", and the first instruction of FunD in Sub - code segment 5 is modified from "push" to a jump instruction "jump d". At this time, the computing device uses the first preset algorithm to Figure 5 Perform calculations on "Sub - code segment 5 when FunC's patch is not activated and FunD's patch is activated" as shown, to obtain another intermediate baseline value of Sub - code segment 5, denoted as baseline value 53. When the status of the patch of FunC is activated and the status of the patch of FunD is not activated, the first instruction of FunC in Sub - code segment 5 is modified from "push" to a jump instruction "jump c", and the first instruction of FunD in Sub - code segment 5 is "push". At this time, the computing device uses the first preset algorithm to Figure 5 Perform calculations on "Sub - code segment 5 when FunC's patch is activated and FunD's patch is not activated" as shown, to obtain another intermediate baseline value of Sub - code segment 5, denoted as baseline value 54. It can be seen that when the number of status combinations of all patches of the functions in Sub - code segment 5 is 4, the number of intermediate baseline values of Sub - code segment 5 is also 4 (including baseline value 51, baseline value 52, baseline value 53, and baseline value 54).

[0120] In another case, for the first sub - code segment, when the first sub - code segment does not include a function, or when the first sub - code segment includes at least one function and none of the at least one function is configured with a patch, the intermediate baseline value of the first sub - code segment includes: the baseline value obtained by calculating the first sub - code segment through the first preset algorithm. Therefore, the computing device calculates the intermediate baseline value of each sub - code segment in multiple code segments, including: the computing device calculates the first sub - code segment through the first preset algorithm to obtain the baseline value of the first sub - code segment, and this baseline value is the intermediate baseline value of the first sub - code segment. It can be understood that in this case, the number of intermediate baseline values of the first sub - code segment is unique.

[0121] As an example, in combination with Figure 4 or Figure 5 , for Figure 4 or Figure 5 The sub - code segment 3 shown in, the sub - code segment 3 does not include a function or does not include a function configured with a patch. Therefore, the sub - code segment 3 has only one state. Furthermore, the computing device can calculate the sub - code segment 3 through this first preset algorithm to obtain the baseline value of the sub - code segment 3, and this baseline value is the only intermediate baseline value of the sub - code segment 3, denoted as baseline value 3.

[0122] Similarly, forFigure 4 or Figure 5 The sub-code segments 4 and 6 shown in Figure 5 each have only one state because the sub-code segments 4 and 6 do not include functions or functions configured with patches. Furthermore, the computing device can calculate the sub-code segment 4 through the first preset algorithm to obtain the unique intermediate baseline value of the sub-code segment 4, denoted as baseline value 4. And the computing device can calculate the sub-code segment 6 through the first preset algorithm to obtain the unique intermediate baseline value of the sub-code segment 6, denoted as baseline value 6.

[0123] Thus, for the target code segment divided into the above sub-code segments 1, 2, 3, 4, 5, and 6, referring to Table 2, Table 2 shows the intermediate baseline value corresponding to each sub-code segment in the target code segment under different state combinations of all patches of each sub-code segment itself.

[0124] Table 2

[0125]

[0126] It should be understood that the first preset algorithms used by the computing device to calculate the intermediate baseline value of each sub-code segment in the target code segment can be the same or different, and this is not limited. For the first sub-code segment in the target code segment, the first preset algorithms used by the computing device to calculate each intermediate baseline value of the first sub-code segment under each patch state combination are the same. For example, the first preset algorithms used by the computing device to calculate baseline value 51, baseline value 52, baseline value 53, and baseline value 54 for the sub-code segment 5 are the same.

[0127] Step 103 (optional): Calculate the baseline value of the target code segment according to the multiple intermediate baseline values corresponding to the target code segment when the patches of the functions in the target code segment are not activated.

[0128] The baseline value of the target code segment is the integrity measurement baseline value required for measuring the integrity of the target code segment. The multiple intermediate baseline values corresponding to the target code segment when the patches of the functions in the target code segment are not activated are composed of the intermediate baseline values of each sub-code segment in the target code segment when the states of the patches of the functions in the target code segment are all activated.

[0129] Optionally, the computing device calculates the baseline value of the target code segment according to the multiple intermediate baseline values corresponding to the target code segment when the patches of the functions in the target code segment are not activated, including: the computing device splices the intermediate baseline values of each sub-code segment in the target code segment when the states of the patches of the functions in the target code segment are all activated in a preset order, and calculates the spliced result through the second preset algorithm to obtain the baseline value of the target code segment.

[0130] Among them, the second preset algorithm refers to any algorithm used to calculate the baseline value and measurement value of a program code segment when performing integrity measurement on the program code segment. For example, the second preset algorithm is the SHA256 algorithm, but it is not limited thereto. It can be understood that the second preset algorithm may be the same as or different from the first preset algorithm used to calculate the intermediate baseline value of each sub-code segment in the above text, and this is not limited.

[0131] In addition, the preset order may be the arrangement order of multiple sub-code segments from front to back in the target code segment, or the arrangement order of multiple sub-code segments from back to front in the target code segment, or the order after multiple sub-code segments are sorted according to any preset rule, and this is not limited.

[0132] It should be understood that when none of the patches of the functions in the target code segment are activated during runtime, or the functions in the target code segment are not configured with patches (indicating that there are no functions that need to be hot-fixed in the current target code segment, so there is no patch activation situation in the target code segment at this time), the computing device calculates the baseline value of the target code segment offline based on the intermediate baseline values of multiple sub-code segments in the target code segment, which can improve the efficiency of subsequent integrity measurement by the server when none of the patches of the functions in the target code segment are activated.

[0133] Step 104: Import the intermediate baseline value of each sub-code segment in the target code segment into the server.

[0134] Exemplarily, the computing device can send the calculated intermediate baseline value of each sub-code segment in the target code segment and the baseline value of the target code segment to the server through its own network interface.

[0135] Another example is to copy the intermediate baseline value of each sub-code segment of the target code segment calculated by the computing device and the baseline value of the target code segment to the server through an external storage device.

[0136] Through steps 101 to 104, the server can obtain the baseline value required for performing integrity measurement on the target code segment running on the client using the method provided in the embodiments of the present application. Combining the example in Table 2, when there are 4 functions (FunA, FunB, FunC, and FunD) that need to be hot-fixed in the target code segment, the number of corresponding intermediate baseline values of the target code segment is 11, that is, the number of baseline values that need to be calculated when performing integrity measurement on the target code segment using the method in the embodiments of the present application is 11. In addition, when there are 4 functions that need to be hot-fixed in the target code segment, 2 need to be calculated using the related technology 4(i.e., 16) baseline values are used to measure the integrity of the target code segment. It can be seen that, compared with the number of baseline values that need to be calculated when measuring the integrity of the target code segment using related technologies, the number of baseline values that need to be calculated when measuring the integrity of the target code segment using the method provided in the embodiments of the present application is smaller. That is, the method provided in the embodiments of the present application can reduce the number of baseline values required for measuring the integrity of the target code segment.

[0137] In another scenario, when the program code segment whose integrity needs to be measured is not configured with patches, refer to Figure 6 , Figure 6 which shows a schematic diagram of another method for calculating the baseline value of a program code segment provided by the embodiments of the present application. Optionally, this method is executed by a computing device having the hardware structure described below Figure 13 . This method first executes steps 101 to 102 described above. It should be understood that in this scenario, since none of the functions in the target code segment are configured with patches, in step 102, each sub-code segment in the target code segment calculates an intermediate baseline value.

[0138] Next, the computing device executes steps 203 to 204.

[0139] Step 203: Calculate the baseline value of the target code segment according to the intermediate baseline values of each sub-code segment in the target code segment.

[0140] Optionally, the computing device splices the intermediate baseline values of each sub-code segment in the target code segment in a preset order, and calculates the spliced result through a second preset algorithm, and then the baseline value of the target code segment can be obtained.

[0141] Among them, for the detailed descriptions of the second preset algorithm and the preset order, reference can be made to the relevant descriptions in step 103, and details will not be repeated here.

[0142] Step 204: Import the baseline value of the target code segment into the server.

[0143] Exemplarily, the computing device can send the calculated baseline value of the target code segment to the server through its own network interface.

[0144] Another example is to import the baseline value of the target code segment calculated by the computing device into the server through an external storage device.

[0145] In this way, through steps 101 to 102 and steps 203 to 204, the computing device can calculate the baseline value required for measuring the integrity of the target code segment. Thus, when measuring the integrity of the target code segment without a configured patch, the measured value calculated in step 301 below can be directly compared with the baseline value calculated in step 203, and the integrity of the target code segment can be determined according to the comparison result.

[0146] During the subsequent operation of the target code segment, when it is necessary to configure a patch for the target code segment, only the intermediate baseline value of the target code segment needs to be calculated offline according to steps 101 - 102, and the calculated intermediate baseline value is imported into the server. In this way, when measuring the integrity of the target code segment with a configured patch, the measured value calculated in step 301 below can still be used for measuring the integrity of the target code segment. The specific process refers to the description of steps 301 to 305 below and will not be elaborated here. In this way, the general applicability of the integrity measurement method provided by the embodiments of the present application can be improved.

[0147] The above is the description of calculating the baseline value required for measuring the integrity of the target code segment in an offline scenario. Next, the integrity measurement method provided by the embodiments of the present application will be introduced. Refer to Figure 7 , Figure 7 which shows a schematic flowchart of an integrity measurement method provided by the embodiments of the present application. This method is executed by the client and the server described above, and the target code segment to be measured for integrity runs in the client. As Figure 7 shown, when the client is running online, the method includes the following steps.

[0148] Step 301: When the client is running, calculate the measured value of each sub - code segment in the target code segment, and calculate the measured value of the target code segment according to the measured value of each sub - code segment.

[0149] The measured value of the target code segment is used to measure the integrity of the target code segment.

[0150] Specifically, the client first divides the target code segment into multiple sub - code segments. For the detailed description of how the client divides the target code segment into multiple sub - code segments, reference can be made to the description of how the computing device divides the target code segment into multiple sub - code segments in step 101, which will not be elaborated here. It should be noted that the division method used by the client to divide the target code segment into multiple sub - code segments is the same as the division method used by the computing device to divide the target code segment into multiple sub - code segments in step 101.

[0151] Next, the client calculates each sub - code segment among the multiple sub - code segments through the first preset algorithm described above, so as to obtain the metric value of each sub - code segment. It should be noted that for the first sub - code segment in the target code segment, the first preset algorithm used by the client to calculate the metric value of the first sub - code segment in step 301 is the same as the first preset algorithm used by the computing device to calculate the intermediate baseline value of the first sub - code segment under different patch state combinations in the offline case in step 102.

[0152] Then, the client calculates the metric value of the target code segment according to the metric values of each sub - code segment in the target code segment. In some embodiments, the client can first splice the metric values of each sub - code segment in the target code segment in a preset order, and then calculate the spliced result through the second preset algorithm described above, so as to obtain the metric value of the target code segment. Among them, the detailed description of the preset order can refer to the description of the preset order in step 103 above, and will not be repeated here.

[0153] In a possible implementation manner, when the client determines that it is necessary to perform integrity measurement on the target code segment, it calculates the metric value of each sub - code segment in the target code segment. For example, the client receives a challenge request sent by the server for requesting integrity measurement of the target code segment, or the client receives a measurement request input by the user for indicating integrity measurement of the target code segment. In response, the client calculates the metric value of each sub - code segment in the target code segment, calculates the metric value of the target code segment according to the metric values of each sub - code segment, and records the calculated metric value in the measurement log.

[0154] In another possible implementation manner, the client can calculate the metric value of each sub - code segment in the target code segment periodically at a preset time interval during runtime, and calculate the metric value of the target code segment according to the metric values of each sub - code segment. The present application embodiment does not make a specific limitation on the value of this preset time interval.

[0155] In this case, for each metric value of each target code segment calculated by the client, when the client calculates each metric value, the calculated metric value is recorded in the metric log. For example, when the client calculates each metric value, the calculated metric value is written into the metric log in real time. Among them, the metric log of the client includes multiple logs, and one log is used to record a metric value calculated by the client for a target code segment within a period. Exemplarily, any log in the metric log, such as the first log, is used to record the first metric value calculated by the client for the first target code segment within a certain period. Among them, the first target code segment is any target code segment in the client that needs to measure integrity. At this time, the first log includes the identifier (identifier, ID) of the first target code segment and the first metric log. Optionally, the first log also includes the timestamp when the client calculates the first log.

[0156] In some examples, the client can periodically calculate the metric values of each target code segment through the dynamic integrity measurement (DIM) module running in the kernel state of the client.

[0157] In some embodiments, since when the client is running, the above-mentioned metric log recorded by the client may be tampered with due to malicious attacks. Therefore, to ensure the integrity (or understood as reliability) of the metric values of the target code segments, after the client calculates a metric value of a target code segment, in addition to recording the metric value in the metric log, the client also updates the value of the PCR of the hardware trusted root in the client according to the metric value. The updated value of the PCR is used to perform integrity verification on the metric value of the target code segment.

[0158] When there are multiple target code segments in the client, within each period, after the client calculates a metric value in a target code segment, a preset calculation is performed on the metric value and the current value of the PCR, and the calculation result is used to overwrite the current value of the PCR. In this way, the value of the PCR can be updated according to the metric value. This process is called the process of extending the metric value to the PCR. Similarly, after the client calculates the metric value of the next target code segment, a preset calculation is performed on the metric value and the latest value of the PCR, and the calculation result is used to overwrite the PCR, so as to update the value of the PCR according to the metric value. In this way, the client can extend each calculated metric value to the PCR one by one. Among them, the preset calculation can be a preset hash calculation, and the specific calculation method of the preset calculation is not limited in the embodiments of the present application.

[0159] As an example, assume that the client includes two target code segments, namely target code segment 1 and target code segment 2, and the initial value of the PCR is 0. Then, within a certain cycle, after the client calculates that the measurement value of target code segment 1 is 11, it writes the measurement value 11 into the measurement log, and performs a pre-designed calculation on the measurement value 11 and the initial value 0 of the PCR to obtain a calculation result 12, and uses the calculation result 12 to overwrite the PCR. At this time, the value of the PCR is 12. Next, when the client calculates that the measurement value of target code segment 2 is 21, it writes the measurement value 21 into the measurement log, and performs a pre-designed calculation on the measurement value 21 and the latest value 12 of the PCR to obtain a calculation result 22, and uses the calculation result 22 to overwrite the PCR. At this time, the value of the PCR is 22. In this way, the purpose of expanding the measurement value 11 of target code segment 1 and the measurement value 12 of target code segment 2 to the PCR one by one can be achieved.

[0160] It can be understood that within each cycle, when the client expands the measurement value of each target code segment calculated in this cycle to the PCR one by one, when the client expands the measurement value of the first calculated target code segment in this cycle to the PCR, the client also needs to record the initial value of the PCR at this time. For example, the initial value of the PCR at this time can be recorded in the log used to record this measurement value in the measurement log, or the initial value of the PCR at this time can be recorded separately as the initial value for verifying the measurement value of the target code segment calculated in this cycle, and there is no limitation on this.

[0161] Step 302: The client sends the measurement value of the target code segment to the server.

[0162] In a possible implementation, the client receives the challenge request sent by the server, and in response to the challenge request, sends the measurement value of the target code segment recorded in the measurement log to the server, so that the server can perform integrity measurement on the target code segment according to the measurement value of the target code segment. The detailed process can refer to the description in steps 304 to 305 below and will not be elaborated here.

[0163] As an example, in response to the challenge request, the client sends the latest recorded log in the measurement log to the server according to the timestamp of the log used to record the measurement value of the target code segment in the measurement log. Among them, the "latest recorded log in the measurement log" refers to the log used to record the measurement value of the target code segment calculated in the most recent cycle. Exemplarily, the client sends the latest recorded log in the measurement log to the server through its own network interface.

[0164] Optionally, when the client updates the PCR value according to the measurement value of the target code segment in step 301, the client sends the measurement value of the target code segment to the server, including: the client reads the updated PCR value, and sends the measurement value of the target code segment (such as the above-mentioned "latest record in the measurement log") and the updated PCR value to the server, so that the server performs integrity verification on the measurement value of the target code segment according to the updated PCR value. The updated PCR value is the latest value of the PCR after the client extends the measurement value of the target code segment calculated in the most recent cycle to the PCR one by one. In one example, the client sends the measurement value of the target code segment and the updated PCR value to the server via a message message. In another example, the client sends the measurement value of the target code segment and the updated PCR value to the server via two message messages.

[0165] In another possible implementation, after calculating the metric value of the target code segment, the client proactively sends the metric value of the target code segment to the server, so that the server can perform an integrity measurement on the target code segment based on the metric value of the target code segment. The detailed process can be found in the description of steps 304 to 305 below and will not be repeated here. For example, after calculating the metric value of the target code segment, the client first records the metric value of the target code segment in a metric log. The client then proactively sends the metric log to the server, so that the server can perform an integrity measurement on the target code segment based on the metric value of the target code segment recorded in the metric log.

[0166] In some embodiments, multiple functions in a target code segment running in a client are configured with patches, and the patch status of at least one of the multiple functions is activated during runtime. Therefore, before the client sends the measurement value of the target code segment to the server, the client also needs to obtain the patch activation information of the target code segment when calculating the measurement value of each sub-code segment in the target code segment. The patch activation information is used to determine the baseline value of the target code segment when measuring the integrity of the target code segment based on the measurement value of the target code segment.

[0167] In one example, the patch activation information of the target code segment includes the ID of at least one function among the multiple functions obtained by dividing the target code segment, and is used to indicate that the patch status of the at least one function is activated. At this time, it means that the patch status of other functions among the multiple functions except the at least one function is inactivated. Optionally, the patch activation information may also include the IDs of functions other than the aforementioned at least one function among the multiple functions obtained by dividing the target code segment, and is used to indicate that the patch status of these functions is inactivated. For the sake of simplicity, the embodiments of the present application are described below using the example of the patch activation information including only the IDs of functions with activated patch status.

[0168] In another example, the patch activation information of the target code segment includes the IDs of at least one function among multiple functions obtained by dividing the target code segment, and is used to indicate that the status of the patches for the at least one function is not activated. At this time, it means that the patch status of the other functions among the multiple functions except the at least one function is activated.

[0169] For simplicity of description, in the following text of the embodiments of the present application, an example will be described in which the patch activation information only includes the IDs of functions with the patch status being activated.

[0170] In some possible implementation manners, the client records the patch activation information of each target code segment configured with a patch during runtime. Optionally, the client sets a corresponding patch status file for each target code segment, and updates the corresponding patch status file in real time according to the activation status of the patches of the functions in each target code segment during the running process, so as to implement the recording of the patch activation information. Exemplarily, the client sets up a patch management process in the user state. Thus, when the patch management process receives a patch activation instruction for a certain function in the first target code segment, in response to this instruction, it modifies the first instruction of the corresponding function in the first target code segment to a jump instruction that jumps to the patch corresponding to this function, and records the ID of this function in the patch status file configured for the first target code segment, so as to implement the recording of the patch activation information of the first target code segment.

[0171] Thus, the patch activation information of the target code segment when the client obtains the metric value of each sub-code segment in the target code segment includes: the client reads the patch activation information of the target code segment from the patch log file corresponding to the target code segment.

[0172] Furthermore, the client sends the metric value of the target code segment to the server, including: the client sends the metric value of the target code segment (such as the "latest record in the metric log" mentioned above) and the patch activation information to the server. In one example, the client sends the metric value and the patch activation information of the target code segment to the server through a single message packet. In another example, the client sends the metric value and the patch activation information of the target code segment to the server through two message packets.

[0173] Optionally, when the client updates the value of the PCR according to the measurement value of the target code segment in step 301, the client sends the measurement value of the target code segment to the server, including: the client sends the measurement value of the target code segment (such as the "latest record in the measurement log" mentioned above), the patch activation information, and the value of the PCR after the update. In one example, the client sends the measurement value of the target code segment, the patch activation information, and the value of the PCR after the update to the server through a message packet. In another example, the client sends the measurement value of the target code segment, the patch activation information, and the value of the PCR after the update to the server through at least two message packets, which is not limited herein.

[0174] Step 303: The server receives the measurement value of the target code segment.

[0175] Exemplarily, the server receives the measurement log for recording the measurement value of the target code segment sent by the client through its own network interface, and parses the received measurement log to obtain the measurement value of the target code segment. It should be understood that after the server parses the received measurement log, in addition to obtaining the measurement value of the target code segment, the ID of the target code segment can also be obtained.

[0176] Optionally, to ensure the reliability of the received measurement value of the target code segment, the server can perform integrity verification on the measurement value of the target code segment. The specific implementation manner of this integrity verification is not specifically limited in the embodiments of the present application.

[0177] In one example, when the client updates the value of the PCR according to the measurement value of the target code segment in step 301, the server can also receive the value of the PCR after the update of the hardware trust root in the client based on the received measurement value of the target code segment. Then, the server performs integrity verification on the measurement value of the target code segment according to the received value of the PCR.

[0178] When the server performs integrity verification on the measurement value of the target code segment according to the received PCR value, it needs to first obtain the initial value of the PCR when the client updates the PCR according to the measurement value of the target code segment. For example, the server reads the initial value of the PCR from the first log of the measurement log for recording the measurement value of the target code segment received. Then, the server uses the pre-designed calculation described above to complete the integrity verification of the measurement value of the target code segment according to the measurement value of the target code segment parsed from the received measurement log and the initial value of the PCR.

[0179] As an example, when the server parses the measurement values of 2 target code segments from the received measurement log, which are the measurement value of target code segment 1 and the measurement value of target code segment 2 respectively, and obtains that the initial value of the PCR is 0 when the PCR is updated in sequence according to the measurement value of target code segment 1 and the measurement value of target code segment 2, the server performs a pre-designed calculation on the measurement value of target code segment 1 and the initial value 0 of the PCR to obtain calculation result 1. Then, the server performs a pre-designed calculation on the measurement value of target code segment 2 and calculation result 1 to obtain calculation result 2. When the server determines that calculation result 2 is the same as the received PCR value, it determines that the measurement values of target code segment 1 and target code segment 2 parsed from the received measurement log are reliable, that is, the integrity verification of the measurement values of target code segment 1 and target code segment 2 passes. When the server determines that calculation result 2 is different from the received PCR value, it determines that the measurement values of target code segment 1 and target code segment 2 parsed from the received measurement log are unreliable, that is, the integrity verification of the measurement values of target code segment 1 and target code segment 2 fails.

[0180] When the server determines that the reliability verification of the measurement value of the target code segment parsed from the received measurement log passes, the service continues to execute the subsequent steps.

[0181] Optionally, when the server determines that the reliability verification of the measurement value of the target code segment parsed from the received measurement log fails, the service segment can request the client again to obtain the measurement value of the target code segment. Alternatively, the server outputs an alarm message to prompt the user that the measurement value of the target code segment from the client is unreliable.

[0182] Step 304: The server determines the baseline value of the target code segment according to a plurality of preset intermediate baseline values and the patch activation situation of the target code segment when calculating the measurement value of the target code segment.

[0183] It should be understood that in the scenario where the target code segment is configured with patches, the server is pre-configured (for example, imported) with a plurality of intermediate baseline values of the target code segment (or referred to as a plurality of intermediate baseline values corresponding to the target code segment). Therefore, in this scenario, the server needs to determine the baseline value of the target code segment according to the plurality of intermediate baseline values and the patch activation situation of the target code segment when calculating the measurement value of the target code segment. Among them, the plurality of intermediate baseline values include the baseline values calculated for each sub-code segment obtained by dividing the target code segment in the offline case. The process by which the server pre-obtains the plurality of intermediate baseline values of the target code segment can refer to the descriptions in steps 101 to 104 and will not be elaborated here.

[0184] Specifically, the server determines the baseline value of the target code segment based on a plurality of preset intermediate baseline values and the patch activation status of the target code segment when calculating the metric value of the target code segment. This includes: First, the server determines a plurality of intermediate baseline values corresponding to the target code segment from all the preset intermediate baseline values in the server according to the ID of the target code segment obtained when receiving the metric value of the target code segment. Then, the server determines the baseline value of the target code segment based on the plurality of intermediate baseline values and the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment. Among them, the process of "the server determines the baseline value of the target code segment based on the plurality of intermediate baseline values and the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment" can be achieved through Figure 8 the steps 3041 to 3043 described above.

[0185] Step 3041: The server determines the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment.

[0186] Optionally, when the server receives the metric value of the target code segment from the client and also receives the patch activation information of the target code segment sent by the client, the server determines the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment according to the received patch activation information of the target code segment.

[0187] For example, when the patch activation information received by the server includes the IDs of at least one function in the target code segment and the patch activation information indicates that the patch status of the at least one function is activated, the server determines the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment as follows: The patch status of the at least one function in the target code segment is activated, and it is determined that the patch status of other functions in the target code segment except the at least one function is not activated.

[0188] Another example is that when the patch activation information received by the server is blank, the server determines the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment as follows: The patch status of the functions in the target code segment is not activated.

[0189] Still another example is that when the server does not receive the patch activation information of the target code segment sent by the client when receiving the metric value of the target code segment from the client, the server determines the patch activation status of the target code segment when calculating the metric values of multiple sub-code segments in the target code segment as follows: The patch status of the functions in the target code segment is not activated.

[0190] Step 3042: The server determines a target combination from multiple preset intermediate baseline values according to the patch activation status of the target code segment when calculating the measurement values of multiple sub-code segments in the target code segment.

[0191] Among them, the multiple intermediate baseline values are the multiple intermediate baseline values corresponding to the target code segment. The target combination includes the baseline values calculated based on multiple sub-code segments in the target code segment in the target state. Here, the target state refers to the state of the patch indicated by the above patch activation status, and specifically, it is the state of the patch of the function in the target code segment when the client calculates the measurement values of multiple sub-code segments in the target code segment. For example, in combination with the example described in Table 2, when the patch activation status determined by the server in Step 3041 is that the patch statuses of FunA and FunC in the target code segment are active, and it is determined that the patch statuses of other functions in the target code segment except FunA and FunC are inactive, the target state is: the patch status of FunA is active, the patch status of FunB is inactive, the patch status of FunC is active, and the patch status of FunD is inactive.

[0192] The server can, according to the target state indicated by the patch activation status, search in the intermediate baseline values of the target code segment preset by itself for the multiple intermediate baseline values obtained by calculating based on multiple sub-code segments of the target code segment in the target state, and these multiple intermediate baseline values constitute the target combination.

[0193] In an example, when the server determines that the patch status of at least one function in the multiple sub-code segments obtained by dividing the target code segment indicated by the above patch activation status is active, the target combination includes: the baseline values calculated based on each sub-code segment in the multiple sub-code segments when the patch status of the at least one function is active. In combination with the example described in Table 2, when the target state indicated by the patch activation status is that the patch status of FunA is active, the patch status of FunB is inactive, the patch status of FunC is active, and the patch status of FunD is inactive, the server searches in the intermediate baseline values shown in Table 2 and determines the baseline value 12 of sub-code segment 1 in the target code segment when the patch status of FunA is active, the baseline value 21 of sub-code segment 2 in the target code segment when the patch status of FunB is inactive, the baseline value 3 of sub-code segment 3 in the target code segment, the baseline value 4 of sub-code segment 4 in the target code segment, the baseline value 54 of sub-code segment 5 in the target code segment when the patch status of FunC is active and the patch status of FunD is inactive, and the baseline value 6 of sub-code segment 6 in the target code segment as the target combination.

[0194] In another example, when the server determines that the patch statuses of the functions in the multiple sub-code segments obtained by dividing the target code segment according to the above patch activation status indication are all inactive, the target combination includes: when the patch statuses of the functions in the multiple sub-code segments are all inactive, the baseline values calculated based on each sub-code segment in the multiple sub-code segments. Combining with the example described in Table 2, when the target status is that the patch statuses of FunA, FunB, FunC, and FunD are inactive, the server searches in the intermediate baseline values shown in Table 2, and takes the baseline value 11 of sub-code segment 1 in the target code segment when the patch status of FunA is inactive, the baseline value 21 of sub-code segment 2 in the target code segment when the patch status of FunB is inactive, the baseline value 3 of sub-code segment 3 in the target code segment, the baseline value 4 of sub-code segment 4 in the target code segment, the baseline value 51 of sub-code segment 5 in the target code segment when the patch statuses of FunC and FunD are inactive, and the baseline value 6 of sub-code segment 6 in the target code segment, and determines them as the target combination.

[0195] Step 3043: The server calculates the baseline value of the target code segment according to the intermediate baseline values in the target combination.

[0196] In some embodiments, the server may first splice the baseline values of each sub-code segment in the target combination in a preset order, and then calculate the spliced result through the second preset algorithm described above, so as to obtain the baseline value of the target code segment. For the detailed description of the preset order, reference can be made to the description of the preset order in step 103 above.

[0197] It should be noted that the preset order for the server to splice the baseline values of each sub-code segment in the target combination is the same as the preset order for the client to splice the measurement values of the multiple sub-code segments obtained by dividing the target code segment in step 301.

[0198] Step 305: The server compares the measurement value and the baseline value of the target code segment to determine the integrity of the target code segment.

[0199] In the scenario where the target code segment is configured with a patch, the server compares the measurement value of the target code segment received in step 303 with the baseline value of the target code segment calculated in step 304 to determine the integrity of the target code segment. For example, when the server determines that the measurement value and the baseline value of the target code segment are the same, it determines that the target code segment is complete. Another example is that when the server determines that the measurement value and the baseline value of the target code segment are different, it determines that the target code segment has been modified, and this modification may be caused by malicious attacks such as tampering or malicious injection. At this time, optionally, the server outputs an alarm message to notify the user to handle the malicious attack in a timely manner.

[0200] In some embodiments, when the patch activation status determined by the server in step 3041 indicates that the statuses of the patches of the functions in the target code segment are all inactive, and the server has previously imported, through step 104, the baseline value of the target code segment when the patches of the functions in the target code segment calculated based on steps 101 to 103 are all inactive, the server can directly compare the measured value of the target code segment with the preset baseline value of the target code segment to determine the integrity of the target code segment. At this time, the server does not need to execute steps 3042 to 3043.

[0201] In the scenario where no patch is configured for the target code segment, since the server has previously imported the baseline value of the target code segment calculated based on Figure 6 the above process, the server can first look up the baseline value of the target code segment in the baseline values preset by the server according to the ID of the target code segment obtained when receiving the measured value of the target code segment. Then, the server compares the measured value of the target code segment received in step 303 with the found baseline value of the target code segment to determine the integrity of the target code segment. Details are not described again.

[0202] So far, through the method described in steps 301 to 305, the integrity measurement of the target code segment running on the client is realized, so that it is possible to timely detect whether the target code segment has been tampered with or maliciously injected in the scenario where multiple patches are configured for the target code segment, thereby determining whether a malicious attack event has occurred on the client. In a client with a hot patch mechanism introduced, when a large number of patches for hot fixing are configured in the program code segment of the client, by the way of calculating the baseline value (steps 101 to 102) in the method provided by the embodiments of the present application, the number of baseline values of the program code segment calculated offline in advance under different state combinations of the patches can be greatly reduced. Thus, when the server performs integrity measurement, the server only needs to determine the baseline value corresponding to the measured value of the program code segment running on the client based on the patch status of the program code segment function and the preset intermediate baseline value when calculating the measured value of the program code segment running on the client, and realize the integrity measurement of the program code segment by comparing the measured value of the program code segment with the baseline value. Compared with the related art solution in which the server needs to spend a lot of time traversing the baseline value file, the solution of the present application can improve the efficiency of the server in performing integrity measurement of the program code segment.

[0203] Moreover, by using the method described in the embodiments of the present application, it is also possible to realize the integrity measurement of a program code segment that is not currently configured with a patch but will be configured with a patch in the future, that is, the method provided by the embodiments of the present application has strong general applicability.

[0204] To further deepen the understanding of the method provided by the embodiments of the present application, the following is further described in combination with examples.

[0205] Reference Figure 9 , Figure 9 shows another schematic flowchart of the complete measurement method provided by the embodiments of the present application.

[0206] As shown in Figure 9 , on the server side, the server pre-downloads the baseline value of the target process from the cloud computing platform. The target process includes the original code segment, the library file code segment 1 on which the target process depends, and the library file code segment 2 on which the target process depends, and patches are configured for the original code segment, the library file code segment 1 on which the target process depends, and the library file code segment 2 on which the target process depends. The "baseline value of the target process" includes the baseline values of each sub-code segment in the original code segment, the library file code segment 1, and the library file code segment 2 calculated by the cloud computing platform when the target process is offline. Among them, regarding the original code segment of the target process, the library file code segment 1 on which the target process depends, and the library file code segment 2 on which the target process depends as the target code segments described above, the process of calculating the baseline values of each sub-code segment in the original code segment, the library file code segment 1, and the library file code segment 2 by the cloud computing platform when the target process is offline can refer to the descriptions in steps 101 to 103 and will not be elaborated here. As an example, the library file code segment 1 can be the code segment of the library file liba.so, and the library file code segment 2 can be the code segment of the library file libb.so.

[0207] When the target process runs in the user mode of the Figure 9 shown client, during the operation of the client, the DIM module in the client kernel mode periodically calculates the measurement values of the original code segment, the measurement value of the library file code segment 1, and the measurement value of the library file code segment 2, and sequentially records the calculated measurement values in the measurement log. The DIM module also expands each calculated measurement value to the PCR of the hardware trusted root one by one. The detailed process can refer to the relevant description in step 301 and will not be elaborated here. In addition, the patch management process in the client is used to activate the patches of the functions in each program code segment of the target process and record the ID of the function when activating the patch of a certain function, so as to record the patch activation information of the patches of the functions in each program code segment of the target process. The detailed process can refer to the relevant description in step 302 and will not be elaborated here.

[0208] When the server determines that it is necessary to perform integrity measurement on the program code segments of the target process running on the client, the server sends a challenge request to the client. In response, the integrity measurement module of the client reads: the patch activation information of each program code segment in the target process, the measurement log recording the measurement values of each program code segment of the target process calculated in the most recent period, and the value of the PCR, and reports the patch activation information of each program code segment in the target process read, the measurement log recording the measurement values of each program code segment of the target process calculated and recorded in the most recent period, and the value of the PCR to the server. For the detailed process, reference can be made to the relevant description in step 302 and will not be elaborated here.

[0209] Furthermore, the server receives the patch activation information of each program code segment in the target process, the measurement log recording the measurement values of each program code segment of the target process calculated in the most recent period, and the value of the PCR. The server performs integrity verification on the measurement values of each program code segment of the target process parsed from the received measurement log according to the received value of the PCR, and after the integrity verification of the measurement values of each program code segment of the target process passes, according to the received patch activation information of each program code segment in the target process, the measurement values of each program code segment of the target process, and the "baseline value of the target process" pre-downloaded from the cloud computing platform, performs integrity measurement on each program code segment of the target process. For the detailed process, reference can be made to the relevant description in steps 304 to 305 and will not be elaborated here.

[0210] The above mainly introduces the solution provided by the embodiments of the present application from the perspective of the method.

[0211] To implement the above functions, as Figure 10 shown, Figure 10 FIG. shows a schematic structural diagram of an integrity measurement device provided by an embodiment of the present application. The integrity measurement device 1000 is applied to the server and is used to execute the part of the integrity measurement method executed by the server described above, for example, used to execute Figure 3 , Figure 6 , Figure 7 or Figure 8 the methods shown. The integrity measurement device 1000 may include a receiving unit 1001, a determining unit 1002, and a comparing unit 1003.

[0212] A receiving unit 1001 is configured to receive the integrity measurement value of a target code segment, where the target code segment is a code segment corresponding to any process in the client. A determining unit 1002 is configured to determine the integrity measurement baseline value of the target code segment according to the patch activation situation of the functions in the target code segment when calculating the integrity measurement value of the target code segment and a plurality of intermediate baseline values preset in the server. A comparing unit 1003 is configured to compare the integrity measurement value of the target code segment with the integrity measurement baseline value of the target code segment to determine the integrity of the target code segment. Wherein, the target code segment includes a plurality of sub-code segments, and the foregoing plurality of intermediate baseline values include the integrity measurement baseline values calculated according to each of the plurality of sub-code segments in an offline scenario. When the function of the first sub-code segment in the target code segment is configured with a first patch, the integrity measurement baseline value calculated according to the first sub-code segment includes the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is activated, and the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is not activated. The first sub-code segment is any one of the sub-code segments in the target code segment.

[0213] As an example, in combination with Figure 7 , the receiving unit 1001 can be configured to execute step 303, the determining unit 1002 can be configured to execute step 304, and the comparing unit 1003 can be configured to execute step 305.

[0214] Optionally, when the function of the first sub-code segment is further configured with a second patch, the integrity measurement baseline value calculated according to the first sub-code segment includes: the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch and / or the second patch is activated, and the integrity measurement baseline value calculated according to the first sub-code segment when the statuses of both the first patch and the second patch are not activated.

[0215] Optionally, the determining unit 1002 is specifically configured to determine a target combination from the plurality of intermediate baseline values according to the patch activation situation, and calculate the integrity measurement baseline value of the target code segment according to the integrity measurement baseline values in the target combination. Wherein, the target combination includes: the integrity measurement baseline values calculated according to each of the plurality of sub-code segments when the patch status of the functions in the foregoing plurality of sub-code segments is the status indicated by the patch activation situation.

[0216] As an example, in combination with Figure 8 , the determining unit 1002 can be configured to execute step 3042 and step 3043.

[0217] Optionally, when the patch activation situation indicates that the status of the patch of at least one function in the above-mentioned multiple sub-code segments is activated, the above-mentioned target combination includes: the integrity metric baseline value calculated based on each of the above-mentioned multiple sub-code segments when the status of the patch of the at least one function is activated.

[0218] Optionally, when the patch activation situation indicates that the patch statuses of the functions in the above-mentioned multiple sub-code segments are all deactivated, the above-mentioned target combination includes: the integrity metric baseline value calculated based on each of the above-mentioned multiple sub-code segments when the patch statuses of the functions in the above-mentioned multiple sub-code segments are all deactivated.

[0219] Optionally, the receiving unit 1001 is further configured to receive the patch activation information of the target code segment sent by the client before determining the integrity metric baseline value of the target code segment, so as to determine the patch activation situation. The patch activation information includes the IDs of at least one function, and the patch activation information is used to indicate that the status of the patch of the at least one function is activated.

[0220] As an example, in combination with Figure 8 , the receiving unit 1001 may be used to execute step 3041.

[0221] Optionally, the integrity metric device 1000 further includes a verification unit 1004, configured to perform integrity verification on the integrity metric value of the target code segment before determining the integrity metric baseline value of the target code segment.

[0222] Optionally, the receiving unit 1001 is further configured to receive the value of the PCR of the hardware trust root in the client. The verification unit 1004 is specifically configured to perform integrity verification on the received integrity metric value of the target code segment according to the value of the PCR.

[0223] Optionally, the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment by function granularity, or the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment in an equal division manner.

[0224] Optionally, the target code segment is a binary code segment. Alternatively, the target code segment is a decimal code segment or a hexadecimal code segment.

[0225] For the specific description of the above optional manners, reference may be made to the foregoing method embodiments, which will not be elaborated herein. In addition, the explanations and descriptions of the beneficial effects of any of the above-provided integrity metric devices 1000 may refer to the corresponding method embodiments above and will not be elaborated.

[0226] As an example, in combination with the following Figure 13, the functions implemented by the receiving unit 1001 in the integrity measurement device 1000 can be implemented by Figure 13 the network interface 1303 shown. The functions implemented by the determination unit 1002, the comparison unit 1003, and the verification unit 1004 in the integrity measurement device 1000 can be implemented by Figure 13 the processor 1301 in Figure 13 executing the program code in the memory 1302.

[0227] As shown in Figure 11 , Figure 11 shows a schematic structural diagram of another integrity measurement device provided by an embodiment of the present application. The integrity measurement device 1100 is applied to the client and is used to execute the part of the integrity measurement method executed by the client above, for example, used to execute Figure 3 , Figure 6 , Figure 7 or Figure 8 the method shown. The integrity measurement device 1100 may include a calculation unit 1101 and a sending unit 1102.

[0228] When the client is running online, the calculation unit 1101 is used to calculate the integrity measurement value of each sub-code segment in the target code segment, and, based on the integrity measurement value of each sub-code segment, calculate the integrity measurement value of the target code segment. Among them, the target code segment is the code segment corresponding to any process in the client, and the target code segment includes multiple sub-code segments. The sending unit 1102 is used to send the integrity measurement value of the target code segment to the server, and the integrity measurement value of the target code segment is used to measure the integrity of the target code segment.

[0229] As an example, in combination with Figure 7 , the calculation unit 1101 can be used to execute step 301, and the sending unit 1102 can be used to execute step 302.

[0230] Optionally, multiple functions in the target code segment are configured with patches, and the integrity measurement device 1100 further includes an acquisition unit 1103, which is used to acquire the patch activation information of the target code segment when calculating the integrity measurement value of each sub-code segment. The patch activation information includes the IDs of at least one function among the foregoing multiple functions, and the patch activation information is used to indicate that the status of the patch of the at least one function is activated. The sending unit 1102 is specifically used to send the integrity measurement value of the target code segment and the patch activation information to the server, and the patch activation information is used to determine the integrity measurement baseline value of the target code segment when measuring the integrity of the target code segment according to the integrity measurement value of the target code segment.

[0231] As an example, in combination with Figure 7 , the sending unit 1102 can be used to execute step 302.

[0232] Optionally, the integrity measurement device 1100 further includes an update unit 1104, configured to update the value of the PCR of the hardware trust root in the client according to the integrity measurement value of the target code segment after calculating the integrity measurement value of the target code segment based on the integrity measurement values of each sub-code segment. The updated value of the PCR is used to perform an integrity check on the integrity measurement value of the target code segment. The sending unit 1102 is specifically configured to send the integrity measurement value of the target code segment and the updated value of the PCR to the server.

[0233] As an example, in combination with Figure 7 , the sending unit 1102 can be used to execute step 302.

[0234] Optionally, the integrity measurement device 1100 further includes a receiving unit 1105, configured to receive a challenge request sent by the server, where the challenge request is used to request an integrity measurement of the target code segment. The sending unit 1102 is specifically configured to send the integrity measurement value of the target code segment to the server in response to the challenge request.

[0235] As an example, in combination with Figure 7 , the sending unit 1102 can be used to execute step 302.

[0236] Optionally, the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment by function granularity, or the above-mentioned multiple sub-code segments are multiple code segments obtained by dividing the target code segment in an equal division manner.

[0237] Optionally, the target code segment is a binary code segment. Or, the target code segment is a decimal code segment or a hexadecimal code segment.

[0238] For the specific descriptions of the above optional manners, reference may be made to the foregoing method embodiments, which will not be elaborated herein. In addition, the explanations and descriptions of the beneficial effects of any of the above-provided integrity measurement devices 1100 may refer to the corresponding method embodiments above and will not be elaborated.

[0239] As an example, in combination with what is described below Figure 13 , the functions implemented by the sending unit 1002 and the receiving unit 1005 in the integrity measurement device 1100 can be implemented through Figure 13 the network interface 1303 shown. The functions implemented by the calculation unit 1101, the acquisition unit 1103, and the update unit 1104 in the integrity measurement device 1100 can be implemented by the processor 1301 in Figure 13 executing the program code in the memory 1302 in Figure 13 .

[0240] As Figure 12As shown Figure 12 shows a schematic structural diagram of another integrity measurement device provided by an embodiment of the present application. The integrity measurement device 1200 is applied to an integrity measurement system including a client and a server, and is used to execute the integrity measurement method described above. For example, it is used to execute Figure 3 , Figure 6 , Figure 7 or Figure 8 the method shown. In one example, the integrity measurement device 1200 can be applied to the server and is used to execute the part of the integrity measurement method executed by the server described above. In another example, the integrity measurement device 1200 can also be applied to the client and is used to execute the part of the integrity measurement method executed by the client described above. The integrity measurement device 1200 includes a transceiver unit 1201 and a processing unit 1202.

[0241] The transceiver unit 1201 is used to execute the operations related to receiving and / or sending in the integrity measurement method described above. The processing unit 1202 is used to execute other operations except the operations related to receiving and / or sending in the integrity measurement method described above.

[0242] For the specific description of the above optional methods, reference can be made to the foregoing method embodiments, which will not be elaborated here. In addition, the explanations and descriptions of the beneficial effects of any of the above-provided integrity measurement devices 1200 can refer to the corresponding method embodiments above and will not be elaborated.

[0243] As an example, in combination with Figure 13 described below, the functions implemented by the transceiver unit 1201 in the integrity measurement device 1200 can be implemented through Figure 13 the network interface 1303 shown. The functions implemented by the processing unit 1202 in the integrity measurement device 1200 can be implemented by the processor 1301 in Figure 13 executing the program code in the memory 1302 in Figure 13 .

[0244] Those skilled in the art should easily realize that, in combination with the units and algorithm steps of the examples described in the embodiments disclosed herein, the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a certain function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.

[0245] It should be noted that Figure 10 , Figure 11 and Figure 12The division of modules / units is illustrative and is only a logical function division. In actual implementation, there may be other division methods. For example, two or more functions can also be integrated into one processing module. The above integrated module can be implemented in the form of hardware or in the form of a software function module.

[0246] The embodiments of the present application provide a computing device, which is used to implement some or all of the functions in the integrity measurement method provided by the embodiments of the present application. Figure 13 It is a schematic structural diagram of a computing device provided by the embodiments of the present application. As Figure 13 shown, the computing device 1300 includes a processor 1301, a memory 1302, a network interface 1303, and a bus 1304. Among them, the processor 1301, the memory 1302, and the network interface 1303 are communicatively connected to each other through the bus 1304.

[0247] The processor 1301 may include a general-purpose processor and / or a dedicated hardware chip. The general-purpose processor may include: a central processing unit (CPU), a microprocessor, or a graphics processing unit (GPU). The CPU is, for example, a single-core processor (single-CPU) or a multi-core processor (multi-CPU). The dedicated hardware chip is a high-performance processing hardware module. The dedicated hardware chip includes at least one of a digital signal processor (DSP), a data processing unit (DPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, a neural processing unit (NPU), a tensor processing unit (TPU), an artificial intelligent chip, or a network processor (NP). The processor 1301 may also be an integrated circuit chip with signal processing capabilities. In the implementation process, some or all of the functions of the method provided by the embodiments of the present application can be completed by the integrated logic circuit in the hardware of the processor 1301 or by instructions in software form.

[0248] The memory 1302 is used to store computer programs, which include an operating system 1302a and executable code (i.e., program instructions) 1302b. The memory 1302 is, for example, a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a flash memory, or other types of static storage devices that can store static information and instructions, such as a static random access memory (SRAM), a dynamic random access memory (DRAM), a synchronous dynamic random access memory (SDRAM), a double data rate synchronous dynamic random access memory (DDR SDRAM), an enhanced synchronous dynamic random access memory (ESDRAM), a synchlink dynamic random access memory (SLDRAM), or other types of dynamic storage devices that can store information and instructions, such as a compact disc read-only memory or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices, or any other medium that can be used to carry or store the desired executable code in the form of instructions or data structures and can be accessed by a computer, but is not limited thereto. For example, the memory 1302 is used to store the integrity measurement baseline value described above. The memory 1302 is, for example, independent and connected to the processor 1301 through a bus 1304. Or the memory 1302 and the processor 1301 are integrated together. The memory 1302 can store executable code. When the executable code stored in the memory 1302 is executed by the processor 1301, the processor 1301 is used to execute some or all of the functions of the integrity measurement method provided in the embodiments of the present application. For the implementation manner of the processor 1301 to execute this process, please refer to the relevant descriptions in the foregoing embodiments accordingly. The memory 1302 may also include other software modules and data required for other running processes, such as an operating system.

[0249] The network interface 1303 uses a transceiver module such as, but not limited to, a transceiver to implement communication with other devices or communication networks. For example, the network interface 1303 can be any one or any combination of the following devices: network interfaces (such as Ethernet interfaces), wireless network cards, and other devices with network access functions. Among them, the network interface 1303 includes a receiving unit for receiving data / messages and a transmitting unit for transmitting data / messages.

[0250] The bus 1304 is of any type and is used to implement the interconnection of internal devices (such as the memory 1302, the processor 1301, and the network interface 1303) of the computing device 1300. For example, a system bus. In the embodiments of the present application, the above-mentioned devices inside the computing device 1300 are interconnected through the bus 1304 as an example. Optionally, the above-mentioned devices inside the computing device 1300 can also communicate with each other using other connection methods in addition to the bus 1304. For example, the above-mentioned devices inside the computing device 1300 are interconnected through an internal logical interface.

[0251] It should be noted that the above-mentioned multiple devices can be separately arranged on independent chips, or at least partially or entirely arranged on the same chip. Whether to independently arrange each device on different chips or integrate and arrange them on one or more chips often depends on the needs of product design. The embodiments of the present application do not limit the specific implementation forms of the above-mentioned devices. And the descriptions of the processes corresponding to the above-mentioned respective drawings have different focuses. For parts not detailed in a certain process, reference can be made to the relevant descriptions of other processes.

[0252] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product providing the program development platform includes one or more computer instructions. When these computer program instructions are loaded and executed on the computing device 1300, part or all of the functions of the integrity measurement method provided by the embodiments of the present application are implemented in whole or in part.

[0253] Moreover, the computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center in a wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.) manner. The computer-readable storage medium stores the computer program instructions providing the program development platform.

[0254] The embodiments of the present application also provide an integrity measurement system, which includes the server and the client described above. Among them, the server is used to execute the part of the integrity measurement method described above that is executed by the server, and the client is used to execute the part of the integrity measurement method described above that is executed by the client.

[0255] The embodiments of the present application also provide a computer-readable storage medium, which is a non-volatile computer-readable storage medium. The computer-readable storage medium includes program instructions. When the program instructions are executed by a computing device, a computer system or a processor, the computing device, the computer system or the processor implements the integrity measurement method provided by the embodiments of the present application.

[0256] The embodiments of the present application also provide a computer program product containing instructions. When the instructions are run on a computing device, a computer system or a processor, the integrity measurement method provided by the embodiments of the present application is implemented on the computing device, the computer system or the processor.

[0257] Among them, a computer system is a system with computing and processing capabilities. A computer system generally includes a processor and a memory. The processor is used to call and run the instructions stored in the memory from the memory, so that the computer system implements the integrity measurement method described above. Optionally, the computer system further includes at least one of an input interface or an output interface. Moreover, the processor, the memory, the input interface, and the output interface of the computer system are connected through an internal connection path.

[0258] Those of ordinary skill in the art can understand that all or part of the steps of implementing the above embodiments can be completed by hardware, or can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. The storage medium mentioned above can be a read-only memory, a disk, an optical disc, etc.

[0259] It should be noted that the information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data for analysis, stored data, displayed data, etc.) and signals involved in the present application are all authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0260] An embodiment of the present application also provides a chip, which includes a processor for running program instructions or code. The chip or a device including the chip can be used to execute the integrity measurement method provided by the embodiment of the present application. Exemplarily, the chip further includes: an input interface, an output interface, and a memory. Among them, the input interface, output interface, processor, and memory of the chip are connected through the internal connection path of the chip. The memory in the chip is used to store program instructions or code run by the processor, and the input interface and output interface of the chip are used for connection and communication between the chip and other chips or devices.

[0261] In the embodiments of the present application, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance. The term "at least one" means one or more, and the term "multiple" means multiple, unless otherwise clearly defined.

[0262] The term "and / or" in the present application is merely a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the preceding and following associated objects.

[0263] It should be understood that the terms used in the description of various examples herein are only for describing specific examples and are not intended to be limiting. As used in the description of various examples and the appended claims, the singular forms "a", "an", and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise.

[0264] It should be understood that determining B based on A does not mean determining B only based on A, and B can also be determined based on A and / or other information.

[0265] It should be understood that the term "comprising" (also known as "includes", "including", "comprises", and / or "comprising") when used in this specification specifies the presence of the stated features, integers, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and / or their groups.

[0266] It should also be understood that in the various embodiments of the present application, the magnitude of the serial numbers of the various processes does not mean the sequence of execution, and the execution sequence of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.

[0267] The above are only optional embodiments of the present application and are not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the concept and principle of the present application shall be included within the protection scope of the present application.

Claims

1. An integrity measurement method, characterized in that, Applied to the server side, the method includes: Receiving the integrity measurement value of the target code segment, where the target code segment is the code segment corresponding to any process in the client; Determining the integrity measurement baseline value of the target code segment according to the patch activation situation of the functions in the target code segment when calculating the integrity measurement value of the target code segment and multiple intermediate baseline values preset in the server; wherein, the target code segment includes multiple sub-code segments, and the multiple intermediate baseline values include the integrity measurement baseline values calculated according to each sub-code segment in the multiple sub-code segments in the offline case. When the function of the first sub-code segment in the target code segment is configured with a first patch, the integrity measurement baseline value calculated according to the first sub-code segment includes the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is activated, and includes the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch is not activated, where the first sub-code segment is any one of the sub-code segments in the target code segment; Comparing the integrity measurement value of the target code segment with the integrity measurement baseline value of the target code segment to determine the integrity of the target code segment.

2. The method according to claim 1, characterized in that When the function of the first sub-code segment is also configured with a second patch, the integrity measurement baseline value calculated according to the first sub-code segment includes: the integrity measurement baseline value calculated according to the first sub-code segment when the status of the first patch and / or the second patch is activated, and includes the integrity measurement baseline value calculated according to the first sub-code segment when the statuses of both the first patch and the second patch are not activated.

3. The method according to claim 1 or 2, characterized in that, The determining the integrity measurement baseline value of the target code segment according to the patch activation situation of the functions in the target code segment when calculating the integrity measurement value of the target code segment and the multiple intermediate baseline values preset in the server includes: Determining a target combination from the multiple intermediate baseline values according to the patch activation situation, where the target combination includes: the integrity measurement baseline values calculated according to each sub-code segment in the multiple sub-code segments when the patch status of the functions in the multiple sub-code segments is the status indicated by the patch activation situation; Calculating the integrity measurement baseline value of the target code segment according to the integrity measurement baseline values in the target combination.

4. The method according to claim 3, wherein In the case where the patch activation situation indicates that the patch status of at least one function in the multiple sub-code segments is activated, the target combination includes: the integrity measurement baseline values calculated according to each sub-code segment in the multiple sub-code segments when the patch status of the at least one function is activated.

5. The method according to claim 3, characterized in that, In the case where the patch activation situation indicates that the patch statuses of the functions in the multiple sub-code segments are all not activated, the target combination includes: the integrity measurement baseline values calculated according to each sub-code segment in the multiple sub-code segments when the patch statuses of the functions in the multiple sub-code segments are all not activated.

6. The method according to any one of claims 1 to 5, characterized in that Before determining the integrity measurement baseline value of the target code segment, the method further includes: Receive the patch activation information of the target code segment sent by the client to determine the patch activation situation; wherein, the patch activation information includes the identifier ID of at least one function, and the patch activation information is used to indicate that the status of the patch of the at least one function is activated.

7. The method according to any one of claims 1 to 6, characterized in that, Before determining the integrity measurement baseline value of the target code segment, the method further includes: Perform an integrity check on the integrity measurement value of the target code segment.

8. The method according to claim 7, wherein The performing an integrity check on the integrity measurement value of the target code segment includes: Receive the value of the platform configuration register PCR of the hardware trusted root in the client; Perform an integrity check on the integrity measurement value of the received target code segment according to the value of the PCR.

9. The method according to any one of claims 1 to 8, characterized in that The multiple sub-code segments are multiple code segments obtained by dividing the target code segment by function granularity, or the multiple sub-code segments are multiple code segments obtained by dividing the target code segment by an equal division method.

10. The method according to any one of claims 1 to 9, characterized in that, The target code segment is a binary code segment.

11. An integrity measurement method, characterized in that, Applied to the client, when the client is running online, the method includes: Calculate the integrity measurement value of each sub-code segment in the target code segment, the target code segment is the code segment corresponding to any process in the client, and the target code segment includes multiple sub-code segments; Calculate the integrity measurement value of the target code segment according to the integrity measurement value of each sub-code segment; Send the integrity measurement value of the target code segment to the server, and the integrity measurement value of the target code segment is used to measure the integrity of the target code segment.

12. The method according to claim 11, wherein Multiple functions in the target code segment are configured with patches, and the method further includes: Obtain the patch activation information of the target code segment when calculating the integrity measurement value of each sub-code segment, the patch activation information includes the identifier ID of at least one function in the multiple functions, and the patch activation information is used to indicate that the status of the patch of the at least one function is activated; The sending the integrity measurement value of the target code segment to the server includes: Send the integrity measurement value of the target code segment and the patch activation information to the server, and the patch activation information is used to determine the integrity measurement baseline value of the target code segment when measuring the integrity of the target code segment according to the integrity measurement value of the target code segment.

13. The method according to claim 11 or 12, wherein After calculating the integrity measurement value of the target code segment according to the integrity measurement value of each sub-code segment, the method further includes: Update the value of the platform configuration register PCR of the hardware trusted root in the client according to the integrity measurement value of the target code segment, and the updated value of the PCR is used to perform an integrity check on the integrity measurement value of the target code segment; The sending the integrity measurement value of the target code segment to the server includes: Send the integrity measurement value of the target code segment and the updated value of the PCR to the server.

14. The method according to any one of claims 11 to 13, characterized in that, The method further includes: Receive the challenge request sent by the server, and the challenge request is used to request to measure the integrity of the target code segment. The sending the integrity measurement value of the target code segment to the server includes: In response to the challenge request, the integrity measurement value of the target code segment is sent to the server.

15. The method according to any one of claims 11 to 14, characterized in that The multiple sub-code segments are multiple code segments obtained by dividing the target code segment with functions as the granularity, or the multiple sub-code segments are multiple code segments obtained by dividing the target code segment in an equal amount.

16. The method according to any one of claims 11 to 15, characterized in that The object code segment is a binary code segment.

17. An integrity measurement device, characterized in that: Applied to the server, the device includes: A transceiver unit, configured to perform operations related to receiving and / or sending in the method according to any one of claims 1 to 10; A processing unit, configured to perform other operations other than the operations related to receiving and / or sending in the method according to any one of claims 1 to 10.

18. An integrity measurement device, characterized in that Applied to a client, the device includes: A transceiver unit, configured to perform operations related to receiving and / or sending in the method according to any one of claims 11 to 16; A processing unit, configured to perform operations other than operations related to receiving and / or sending in the method according to any one of claims 11 to 16.

19. A computing device, characterized in that, include: A memory, a network interface, and one or more processors, wherein the one or more processors receive or send data through the network interface, and the one or more processors are configured to read program instructions stored in the memory to execute the method according to any one of claims 1 to 10, or to execute the method according to any one of claims 11 to 16.

20. An integrity measurement system, characterized in that The system includes a server and a client, the server is used to execute the method according to any one of claims 1 to 10, and the client is used to execute the method according to any one of claims 11 to 16.

21. A computer-readable storage medium, characterized in that, The method comprises computer program instructions. When the computer program instructions are executed by a computing device or a processor, the computing device or the processor performs the method according to any one of claims 1 to 10, or performs the method according to any one of claims 11 to 16.

22. A computer program product comprising instructions, characterized in that, When the instructions are executed by a computing device or a processor, the computing device or the processor is caused to execute the method according to any one of claims 1 to 10, or execute the method according to any one of claims 11 to 16.