Security measurement method, security architecture system and computer equipment
By integrating and distributing TCM, TPM, and TPCM modules in the processor architecture, the problems of insufficient hardware resource consumption and security are solved, and more efficient and flexible security measurement is achieved, which is suitable for security needs in different application scenarios.
Patent Information
- Application Number
- CN202510525872.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2022-12-16
- Publication Date
- 2025-08-08
AI Technical Summary
In prior art In computer equipment, the implementation methods of external TPM, TCM and TPCM increase hardware resource consumption, and the security and flexibility of TEE and SE are insufficient, making it difficult to meet the security measurement needs of different applications and users.
The trusted cryptographic module TCM, the trusted platform module TPM and the trusted platform control module TPCM are integrated in the processor architecture, and their modules and service modules are run in different subsystems respectively. Security measurement services are provided through TCM and/or TPM, and combined with the different distribution settings of the TCM driver module and the TPM driver module in REE and TEE, the security measurement of the target object is achieved.
It improves the security and versatility of the processor architecture, reduces design complexity, saves processor resources, enhances the security of the cryptographic module and the applicability of the system, and meets the security measurement needs of different application scenarios.
Smart Images

Figure CN120449182A_ABST
Abstract
Description
[0001] This application is a divisional application of the invention entitled "Security Measurement Method, Security Architecture System and Computer Equipment", application number 202211623848.0, and the application date of the parent case is December 16, 2022. Technical Field
[0002] The present application relates to the field of processor technology, and in particular to a security measurement method, a security architecture system, and a computer device. Background Art
[0003] As users' demands for device security continue to rise, more and more security technologies are being applied to computer devices. As device software functionality becomes increasingly richer and the amount of device data continues to increase, more and more diverse data and programs are running in the device's chip architecture system. Consequently, ensuring the security of this chip architecture system has become a crucial component of computer device security. Therefore, it is necessary to research technical solutions that can ensure the security of this chip architecture system to improve device security. Summary of the Invention
[0004] Based on the above technical status, this application proposes a security measurement method, a security architecture system and a computer device to achieve the purpose of providing security measurement services for the target object compatible with TCM, TPM and TPCM, and can realize the security measurement of the processor architecture system, thereby facilitating the security of the processor architecture system and the device.
[0005] To achieve the above technical objectives, this application proposes the following technical solutions:
[0006] In a first aspect, the present application proposes a security measurement method, which is applied to a security architecture system, wherein the security architecture system includes a normal execution environment subsystem (REE), a trusted execution environment subsystem (TEE), and a secure element subsystem (SE). A trusted computing service support platform is constructed in subsystems other than the REE, and the trusted computing service support platform includes a trusted cryptographic module (TCM), a trusted platform module (TPM), and a trusted platform control module (TPCM); the TCM includes a TCM service module and a TCM cryptographic module, and the TPM includes a TPM service module and a TPM cryptographic module; the TCM cryptographic module and the TCM service module respectively run in different subsystems other than the REE, and / or the TPM cryptographic module and the TPM service module respectively run in different subsystems other than the REE; the method includes: when an active security measurement function is triggered and a security service request is received at the same time, using the TPCM to perform security measurement on a target object to obtain a security measurement result, and, in response to the received security service request, using the TCM and / or the TPM to provide security measurement services for the target object to obtain a security measurement result; the target object includes a running object in the REE and / or TEE, and the security measurement result indicates the trustworthiness of the target object. This solution enables security measurement of running objects within the chip architecture system, enabling timely identification of the security of running objects and the identification of dangerous running objects, thus helping to ensure the security of the processor architecture. Furthermore, this solution integrates the Trusted Cryptographic Module (TCM), Trusted Platform Module (TPM), and Trusted Platform Control Module (TPCM) within the chip architecture system, providing a variety of security measurement services to meet the security measurement needs of different applications or users. This ensures the security of the processor architecture while also improving the versatility of the processor architecture system.
[0007] In addition, it should be noted that in the relevant existing technologies, the implementation of external TPM, TCM and TPCM will increase the consumption of hardware resources in computer devices. However, the inventive concept proposed in this application can directly upgrade the settings of the processor in traditional technologies in scenarios that do not involve trusted computing; in scenarios that involve trusted computing, it can directly update the settings of trusted technology in the processor. Here, the implementation scheme of trusted technology may include: one or more of external TPM, TCM and TPCM; or, a TPM integrated inside the processor; or, a TCM integrated inside the processor; or, a TPM and a TCM integrated inside the processor, etc.
[0008] In one implementation, the TPM cryptographic module and the TCM cryptographic module run in the same subsystem, rather than running separately on different processor cores. This saves processor resources. In addition, setting them up in a homogeneous manner can reduce design complexity.
[0009] In one implementation, the TPCM, TCM service module, and TPM service module run in the TEE, while the TCM cryptographic module and TPM cryptographic module run in the SE. Separating the service and cryptographic modules effectively improves the security of the cryptographic modules and increases the flexibility of software product development for the TPCM, TPM, and TCM service modules.
[0010] In one implementation, the TEE and SE run on a first processor core, or alternatively, the TEE runs on a first processor core and the SE runs on a second processor core. The TEE and SE run on the same processor core, rather than separately on different processor cores. This saves processor resources; furthermore, setting up in a homogeneous manner reduces design complexity. The TEE and SE run on different processor cores, respectively, enabling the SE to independently process tasks and respond to requests. This allows the SE's task execution to be completely independent and unaffected by the execution environments of other subsystems, which is beneficial for improving the security of the security architecture system and also for improving the SE's task execution efficiency.
[0011] In one implementation, the TCM service module is further configured to directly respond to security service requests and provide security services for the target object; the TPM service module is further configured to directly respond to security service requests and provide security services for the target object; in response to the security service request, providing security measurement services for the target object using the TCM and / or TPM includes: selecting a security service module corresponding to the security service request to provide the security measurement service for the target object; the security service module includes at least one of a TCM cryptographic module, a TCM service module, a TPM cryptographic module, and a TPM service module; the security service request includes at least one of a first-type TCM security service request, a second-type TCM security service request, a first-type TPM security service request, and a second-type TPM security service request; the first-type TCM security service request corresponds to the TCM cryptographic module, the second-type TCM security service request corresponds to the TCM service module, the first-type TPM security service request corresponds to the TPM cryptographic module, and the second-type TPM security service request corresponds to the TPM service module. Based on this implementation, the security architecture system can implement more security measurement methods, improving the applicability of security measurement.
[0012] In one implementation, the target objects include trusted applications and standard applications, with standard applications running in the REE and trusted applications running in the TEE. Security service requests include TCM security service requests and / or TPM security service requests. The TCM also includes a TCM driver module, and the TPM also includes a TPM driver module. The TCM driver module is configured to respond to TCM service initiation requests from standard applications or trusted applications and initiate TCM security service requests. The TPM driver module is configured to respond to TPM service initiation requests from standard applications or trusted applications and initiate TPM security service requests. Based on this implementation, the TCM driver module and the TPM driver module can meet the needs of applications initiating security service requests, enabling the smooth triggering of security service requests.
[0013] In one implementation, TCM security service requests include first-type TCM security service requests and / or second-type TCM security service requests, and TPM security service requests include first-type TPM security service requests and / or second-type TPM security service requests. The TCM service module is further configured to directly respond to the second-type TCM security service requests and provide security measurement services for the target object. The TPM service module is further configured to directly respond to the second-type TPM security service requests and provide security measurement services for the target object. In this implementation, the TCM service module and the TPM service module can provide security measurement services, thereby further improving the system's security measurement performance and applicability.
[0014] In one implementation, the TCM driver module is located in the REE and / or TEE, and the TPM driver module is located in the REE and / or TEE. The placement of the TCM driver module and the TPM driver module in the REE and / or TEE can implement security architecture systems with different structures and enable applications in the REE and / or TEE to initiate security service requests in various ways.
[0015] In one implementation, when a TCM driver module and a TPM driver module are provided in the REE, security service requests include at least one of: a first-category TCM security service request directly initiated by a common application to the TCM cryptographic module via the TCM driver module; a first-category TPM security service request directly initiated by a common application to the TPM cryptographic module via the TPM driver module; a first-category TCM security service request or a second-category TCM security service request initiated by a common application to the TCM service module via the TCM driver module; and a first-category TPM security service request or a second-category TPM security service request initiated by a common application to the TPM service module via the TPM driver module. In this implementation, common applications in the REE can send security service requests to the SE in a hierarchical or cross-level manner, thereby implementing different security measurement modes and meeting the security measurement requirements of common applications in different scenarios.
[0016] In one implementation, when a TCM driver module and a TPM driver module are provided in the REE, and a TCM driver module and a TPM driver module are provided in the TEE, the security service request also includes: a first-class TCM security service request directly initiated by a trusted application to the TCM cryptographic module via the TCM driver module in the TEE, a first-class TCM security service request or a second-class TCM security service request initiated by a trusted application to the TCM service module via the TCM driver module in the TEE, a first-class TPM security service request directly initiated by a trusted application to the TPM cryptographic module via the TPM driver module in the TEE, and a first-class TPM security service request or a second-class TPM security service request initiated by a trusted application to the TPM service module via the TPM driver module in the TEE. Based on this implementation, the TCM driver module and the TPM driver module are provided in both the REE and the TEE, so that ordinary applications in the REE and trusted applications in the TEE can each independently initiate security service requests, thereby improving the efficiency of security measurement.
[0017] In one implementation, when a TCM driver module and a TPM driver module are provided in the REE, and a TCM driver module is provided in the TEE, the security measurement service request also includes: at least one of a first-type TCM security service request directly initiated by a trusted application to the TCM cryptographic module via the TCM driver module in the TEE, and a first-type TCM security service request or a second-type TCM security service request initiated by a trusted application to the TCM service module via the TCM driver module in the TEE. In this implementation, not only can ordinary applications in the REE initiate TCM security service requests and / or TPM security service requests, but trusted applications in the TEE can also initiate TCM security service requests, thus taking into account the security measurement requirements of different applications and scenarios, and improving the applicability of the solution.
[0018] In one implementation, when a TCM driver module and a TPM driver module are provided in the REE, and a TPM driver module is provided in the TEE, the security service request also includes at least one of: a first-category TPM security service request directly initiated by a trusted application to the TPM cryptographic module via the TPM driver module in the TEE, and a first-category TPM security service request or a second-category TPM security service request initiated by a trusted application to the TPM service module via the TPM driver module in the TEE. In this implementation, not only can ordinary applications in the REE initiate TCM security service requests and / or TPM security service requests, but trusted applications in the TEE can also initiate TPM security service requests, thus taking into account the security measurement requirements of different applications and scenarios, and improving the applicability of the solution.
[0019] In one implementation, when a TCM driver module and a TPM driver module are provided in the TEE, the security service request includes: a first-class TCM security service request directly initiated by a trusted application to the TCM cryptographic module through the TCM driver module, a first-class TCM security service request or a second-class TCM security service request initiated by a trusted application to the TCM service module through the TCM driver module, a first-class TPM security service request directly initiated by a trusted application to the TPM cryptographic module through the TPM driver module, and at least one of a first-class TPM security service request or a second-class TPM security service request initiated by a trusted application to the TPM service module through the TPM driver module. In this implementation, the TCM driver module and the TPM driver module are provided in the TEE. Thanks to the higher security of the TEE, the TCM driver module and the TPM driver module can be placed in a more secure execution environment, which is conducive to improving the security of triggering security service requests.
[0020] In one implementation, when a TCM driver module and a TPM driver module are provided in the TEE, and a TCM driver module is provided in the REE, the security service request also includes: at least one of a first-category TCM security service request directly initiated by a normal application to the TCM cryptographic module via the TCM driver module in the REE, and a first-category TCM security service request or a second-category TCM security service request initiated by a normal application to the TCM service module via the TCM driver module in the REE. In this implementation, not only can trusted applications in the TEE initiate TCM security service requests and / or TPM security service requests, but normal applications in the REE can also initiate TCM security service requests step by step or across levels, thus taking into account the security measurement requirements of different applications and scenarios, and improving the applicability of the solution.
[0021] In one implementation, when a TCM driver module and a TPM driver module are provided in the TEE, and a TPM driver module is provided in the REE, the security measurement service request also includes at least one of: a first-category TPM security service request directly initiated by a normal application to the TPM cryptographic module via the TPM driver module in the REE, and a first-category TPM security service request or a second-category TPM security service request initiated by a normal application to the TPM service module via the TPM driver module in the REE. In this implementation, not only can trusted applications in the TEE initiate TCM security service requests and / or TPM security service requests, but normal applications in the REE can also initiate TPM security service requests step by step or across levels, thus taking into account the security measurement requirements of different applications and scenarios, and improving the applicability of the solution.
[0022] In one implementation, when a TCM driver module is set in the REE and a TPM driver module is set in the TEE, the security service request includes at least one of the following: a first-category TPM security service request directly initiated by a trusted application to the TPM cryptographic module via the TPM driver module in the TEE, a first-category TPM security service request or a second-category TPM security service request initiated by a trusted application to the TPM service module via the TPM driver module in the TEE, a first-category TCM security service request directly initiated by a common application to the TCM cryptographic module via the TCM driver module in the REE, and a first-category TCM security service request or a second-category TCM security service request initiated by a common application to the TCM service module via the TCM driver module in the REE. In this implementation, common applications in the REE can send TCM security service requests to the SE step by step or across levels, while trusted applications in the TEE can send TPM security service requests directly to the SE. This balances the security and execution efficiency of TCM security service requests initiated by common applications in different scenarios, thereby improving the applicability of the solution.
[0023] In one implementation, when a TPM driver module is set in the REE and a TCM driver module is set in the TEE, the security measurement service request includes at least one of the following: a first-class TCM security service request directly initiated by a trusted application to the TCM cryptographic module via the TCM driver module in the TEE, a first-class TCM security service request or a second-class TCM security service request initiated by a trusted application to the TCM service module via the TCM driver module in the TEE, a first-class TPM security service request directly initiated by a common application to the TPM cryptographic module via the TPM driver module in the REE, and a first-class TPM security service request or a second-class TPM security service request initiated by a common application to the TPM service module via the TPM driver module in the REE. In this implementation, common applications in the REE can send TPM security service requests to the SE step by step or across levels, while trusted applications in the TEE can send TCM security service requests directly to the SE. This balances the security and execution efficiency of TPM security service requests initiated by common applications in different scenarios, thereby improving the applicability of the solution.
[0024] In one implementation, the TEE and SE run in the first processor core, or the TEE runs in the first processor core and the SE runs in the second processor core; the first processor core is virtualized as a security core; if the TCM driver module runs on the security core, the TCM driver module is further used to: when the TCM service initiation request is a first type of service initiation request, directly respond to the TCM service initiation request and provide security measurement services for the target object; if the TPM driver module runs on the security core, the TPM driver module is further used to: when the TPM service initiation request is a second type of service initiation request, directly respond to the TPM service initiation request and provide security measurement services for the target object. In this implementation, the TCM driver module and the TPM driver module can respond to specific service initiation requests in specific circumstances, thereby improving security measurement efficiency.
[0025] In one implementation, the TPM driver module further includes a first key table, and the TCM driver module further includes a second key table. The first key table includes a first key and key types supported by the TPM, and the second key table includes a second key and key types supported by the TCM. The TPM driver module is further configured to determine the key type requested in a TPM service initiation request, and when the determined key type is not in the first key table, update the key type requested in the TPM service initiation request to the first key. The TCM driver module is further configured to determine the key type requested in a TCM service initiation request, and when the determined key type is not in the second key table, update the key type requested in the TCM service initiation request to the second key. Based on this implementation, the support and adaptation of security measurement methods and security architecture systems to newly added key types can be improved.
[0026] In one implementation, when a security service request includes a TCM security service request and a TPM security service request, providing a security measurement service for a target object using the TCM and TPM includes: responding to the TCM security service request, providing a security measurement service using the TCM to obtain a first security measurement result; and responding to the TPM security service request, providing a security measurement service using the TPM to obtain a second security measurement result; and using the first security measurement result and the second security measurement result as the security measurement result. This implementation allows for the simultaneous execution of two different types of passive security measurements, improving the comprehensiveness of the passive security measurements.
[0027] In a second aspect, the present application proposes a security architecture system, which includes a normal execution environment subsystem REE, a trusted execution environment subsystem TEE and a secure element subsystem SE. A trusted computing service support platform is constructed in subsystems other than the REE, and the trusted computing service support platform includes a trusted cryptographic module TCM, a trusted platform module TPM and a trusted platform control module TPCM; the TCM includes a TCM service module and a TCM cryptographic module, and the TPM includes a TPM service module and a TPM cryptographic module; the TCM cryptographic module and the TCM service module respectively run in different subsystems other than the REE, and / or the TPM cryptographic module and the TPM service module respectively run in different subsystems other than the REE; the trusted computing service support platform is configured to: when the active security measurement function is triggered and a security service request is received at the same time, use the TPCM to perform security measurement on the target object to obtain a security measurement result, and, in response to the received security service request, use the TCM and / or the TPM to provide security measurement services for the target object to obtain a security measurement result; the target object includes a running object in the REE and / or TEE, and the security measurement result indicates the trustworthiness of the target object.
[0028] In a third aspect, the present application proposes a computer device comprising the above-mentioned security architecture system.
[0029] Based on the second and / or third aspects above, it is possible to implement security measurement of running objects in the chip architecture system, thereby enabling timely clarification of the security of running objects and identification of dangerous running objects, thereby facilitating the security of the processor architecture. Furthermore, the above solution integrates a trusted cryptographic module (TCM), a trusted platform module (TPM), and a trusted platform control module (TPCM) into the chip architecture system, thereby providing multiple types of security measurement services, meeting the security measurement needs of different applications or users, and improving the versatility of the processor architecture system. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without any creative work.
[0031] Figure 1 A schematic diagram of the structure of a secondary processor architecture provided in an embodiment of the present application;
[0032] Figure 2 A schematic diagram of the structure of a three-level processor architecture provided in an embodiment of the present application;
[0033] Figure 3 A schematic diagram of the structure of a three-level security architecture system compatible with TCM, TPM and TPCM provided in an embodiment of the present application;
[0034] Figure 4 A schematic diagram of the structure of another three-level security architecture system compatible with TCM, TPM and TPCM provided in an embodiment of the present application;
[0035] Figure 5(a)-Figure 5(i) Schematic diagram of various distribution settings of the TCM driver module and the TPM driver module in the REE and TEE provided in the embodiments of the present application;
[0036] Figure 6-Figure 14 Schematic diagram of various different secure calling methods provided in the embodiments of the present application;
[0037] Figure 15 A schematic diagram of a safety measurement method provided in an embodiment of the present application;
[0038] Figure 16A schematic diagram of the structure of a computer device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0039] The following will describe the technical solutions in the embodiments of this application in conjunction with the accompanying drawings. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative work are within the scope of protection of this application.
[0040] Generally speaking, the processor architecture of a computer device can be composed of three types of subsystems: the Rich Execution Environment (REE) subsystem, the Trusted Execution Environment (TEE) subsystem, and the Secure Element (SE) subsystem.
[0041] The general execution environment subsystem (REE) can include a general operating system running on a general-purpose embedded processor, in which applications are installed. Applications running in the REE can be called general applications (Client Application, CA), which have low security and are vulnerable to attacks. For example, the application running in the REE can be a program involved in payment scenarios, which implements basic services such as browsing products, selecting products, and submitting orders. Although many security measures are taken in the REE, such as device access control, device data encryption mechanism, application runtime isolation mechanism, and access control based on permission verification, the security of important data in the application cannot be guaranteed.
[0042] The Trusted Execution Environment (TEE) subsystem can be an independent operating environment running outside of the general operating system. It can provide trusted services to, for example, REEs and is isolated from the REEs. The TEE can execute one or more trusted applications (TEE Applications, TAs), which provide a trusted operating environment for the general execution environment subsystem REEs. End-to-end security is ensured by protecting confidentiality, integrity, and controlling data access rights. In addition, the TEE can run in parallel with the REE, and, for example, the TEE interacts with the REE through a secure application programming interface (API).
[0043] The TEE provides a higher-security operating environment than the REE, but it cannot provide hardware-level isolation for secure key storage and key execution. Generally, the TEE can provide the REE with numerous application programming interfaces (APIs), allowing the REE to access TEE resources. The more APIs a TEE provides for service provision, the greater the risk the TEE faces. It is difficult to guarantee that the APIs themselves are free of security risks, such as vulnerabilities, which in turn could lead to security risks for keys and other resources within the TEE. Furthermore, multiple trusted applications (TAs) will run within the TEE, and these trusted applications (TAs) rely entirely on the isolation mechanisms provided by the TEE operating system, lacking hardware-level isolation. This poses significant security risks to sensitive resources such as keys if a trusted application (TA) itself contains security vulnerabilities or actively accesses the keys or root keys of other trusted applications (TAs).
[0044] The software system in the secure element subsystem (SE) is relatively simple, including fewer hardware components. This makes it easier to establish physical protection and implement security assurance, thereby enhancing the security strength of the secure element subsystem (SE) to serve security systems with higher security requirements. For example, the TEE can transmit security service requests to the SE to request the provision of corresponding security services and respond based on the requests. For example, a security service may be a request to the SE to perform cryptographic operations.
[0045] The application running in the secure element subsystem SE can be called a secure element application (Applet), and its security is the highest among these three types of subsystems. Since the secure element subsystem SE has the highest security compared to the ordinary execution environment subsystem REE and the trusted execution environment subsystem TEE, the secure element subsystem SE generally stores important resources, such as root keys and other information. The security of important resources stored in the secure element subsystem SE is guaranteed by means of permission verification, cryptographic technology, etc. As an implementation method, the secure element subsystem SE includes an execution engine, static random access memory (SRAM), non-volatile memory, or may also include a key derivation function (KDF). Among them, important resources such as root keys can be stored in the non-volatile memory within the secure element subsystem SE, and the secure element subsystem SE firmware or hardware ensures that the root key does not have a software or hardware path to pass out of the secure element subsystem SE. In addition, the key derivation module KDF integrated in the secure element subsystem SE can be implemented as software or hardware and used to generate derived keys based on the root key. For example, the key derivation module KDF can be a hash function, which is usually used to turn a short password into a long password.
[0046] In the processor architecture system, the security of the computing environment is ensured through the mutual cooperation between these three subsystems. Specifically, a processor architecture can be composed of REE and TEE, such as Figure 1 The two-level architecture system shown can also be composed of REE, TEE and SE as shown in Figure 2 The three-level architecture system shown.
[0047] See also Figure 1 As shown, the REE in the secondary architecture system runs system firmware, operating system OS or virtual machine VM. Among them, the system firmware can be implemented as an extensible firmware interface (Unified Extensible Firmware Interface, UEFI) for desktops, servers and other fields, or it can be implemented as a boot loader (U-Boot) for the embedded field. In addition, the basic firmware, system firmware and operating system OS can communicate with out-of-band control systems (such as embedded controllers EC, baseboard management controllers BMC, etc.). The TEE can run a secure operating system (TEE OS) that the TEE depends on.
[0048] See also Figure 2 As shown, the structure of the three-level architecture system is relative to Figure 1 The structure of the secondary architecture system shown, with the addition of SE.
[0049] In some implementations, the REE and TEE do not have direct physical access to the SE and can only make requests to the SE through interactive methods such as shared memory, and the SE provides services to the REE and TEE. Regarding the SE, as an implementation, the SE may include an execution engine, static random access memory (SRAM), non-volatile memory, or may also include a key derivation function (KDF). Among them, important resources such as the root key can be stored in the non-volatile memory within the SE, and the SE's firmware or hardware ensures that the root key has no software or hardware path to be transmitted outside the SE. In addition, the key derivation module KDF integrated in the SE can be implemented as software or hardware and used to generate derived keys based on the root key. For example, the key derivation module KDF can be a hash function, which is typically used to convert short passwords into long passwords. Specifically, the above-mentioned shared memory can refer to a large capacity memory that can be accessed by different processors in a multi-processor computer system. In some embodiments, the execution engine and other resources included in the SE can serve as trusted computing resources of the TCM and / or TPM.
[0050] In the three-tier architecture system described above, the TEE and SE can run on the same processor core or on different processor cores. For example, both the TEE and SE can run on the first processor core, thus forming a homogeneous processor architecture system. Alternatively, the TEE can run on the first processor core and the SE can run on the second processor core, thus forming a heterogeneous processor architecture system.
[0051] For the above-mentioned processor architecture system with isomorphic TEE and SE, TEE and SE run on the same processor core (i.e., the first processor core) instead of running separately on different processor cores. In this way, processor resources can be saved; in addition, setting up in an isomorphic manner can reduce design complexity.
[0052] In the aforementioned heterogeneous processor architecture system with TEE and SE, the TEE and SE run on different processor cores. This enables the SE to independently process tasks and respond to requests, making the SE's task execution completely independent and unaffected by the execution environment of other subsystems. This helps improve the security of the security architecture system and also helps improve the SE's task execution efficiency. Furthermore, this implementation can reduce processor hardware resource consumption and improve processor processing performance.
[0053] Whether TEE and SE are set on the same processor core or on different processor cores, it does not affect the security measurement function of the entire processor architecture system and the specific process of the security measurement method implemented. Therefore, the introduction of the structure of various types of security architecture systems in the subsequent embodiments of this application all default to including the situation where TEE and SE are set on the same or different processor cores. At the same time, the security measurement function and security measurement method implemented in the security architecture system introduced in the subsequent embodiments of this application all default to including the security measurement function and security measurement method implemented when TEE and SE are set on the same or different processor cores. In the subsequent embodiments of this application, the specific content of the security measurement function and the security measurement method implemented when TEE and SE are set on the same or different processor cores will no longer be introduced one by one.
[0054] As users' demands for device security continue to rise, more and more security technologies are being applied to computer devices. As device software functionality becomes increasingly richer and the amount of device data continues to increase, more and more diverse data and programs are running on the device's processor architecture. Consequently, ensuring the system security of the processor architecture has become a crucial means of ensuring computer device security. Therefore, it is necessary to research technical solutions that can ensure the system security of the processor architecture to improve device security.
[0055] Trusted Computing (TC) is a technology promoted and developed by the Trusted Computing Group (TCG). One of the core goals of trust is to ensure the integrity of systems and applications, thereby ensuring that the system or software is running in the trusted state expected by the design objectives. Adding trusted verification to systems and applications can reduce the possibility of being attacked due to the use of unknown or tampered systems / software. Taking PC trust as an example, in layman's terms, trust means detecting the integrity and correctness of the BIOS and operating system when each PC is started, ensuring that the hardware configuration and operating system have not been tampered with when you use the PC, and all system security measures and settings will not be bypassed; after startup, all applications, such as social software, music software, video software, etc., can be monitored in real time, and if any application is found to have been tampered with, immediate measures to stop the damage will be taken.
[0056] Trust is primarily achieved through measurement and verification. Measurement involves capturing the status of the software or system being tested, while verification involves comparing the measurement results to reference values to see if they are consistent. If they are consistent, verification passes; if they are inconsistent, verification fails. Trusted computing ensures trust by measuring and verifying the software stack through algorithms and keys embedded in trusted hardware by chip manufacturers and integrated dedicated microcontrollers. Based on the classification of security chips and the trusted software stack running on them, the industry currently has three main trusted computing standards: Trusted Platform Module (TPM), Trusted Cryptography Module (TCM), and Trusted Platform Control Module (TPCM).
[0057] The TPM standard was developed by the TCG, and its technical specifications adhere to international standards. Therefore, it provides standard services that comply with these standards. Specifically, a TPM module consists of two parts: a TPM cryptographic module and a TPM service module. These two modules work together to support the implementation of TPM trusted computing services.
[0058] The TPM cryptographic module is used to provide trusted computing resources for the TPM trusted computing service. These trusted computing resources specifically include storage space for data such as keys and random numbers, and hardware resources such as algorithm modules for various cryptographic algorithms. For example, under normal circumstances, the TPM cryptographic module can support digest algorithm units SHA-1 and SHA-256, signature verification and encryption and decryption algorithm units RSA, ECC, and AES, and in future evolutionary iterations, it can also support new algorithms. The TPM specification is evolving, and the types of algorithms supported and the underlying technical methods differ somewhat between different versions of the specification. However, the essential security technology implementation objectives and methods are the same. Therefore, the solutions mentioned in this article are applicable to different versions of the TPM specification.
[0059] The TPM service module is used to provide TPM trusted computing services by calling the computing resources of the TPM cryptographic module. The TPM service module mainly includes programs and algorithms that call TPM trusted computing resources to execute TPM trusted computing services.
[0060] Typically, the TPM service module responds to security service requests by invoking the computing resources of the TPM cryptographic module. Specifically, when the TPM service module receives a security service request, it invokes the TPM cryptographic module's computing resources to implement security measurements and provide security measurement services. In some cases, the TPM cryptographic module can directly respond to certain security service requests and provide security measurement services. Alternatively, the TPM service module can independently respond to certain security service requests and provide security measurement services through its own software computations.
[0061] In actual applications, the TPM cryptographic module and the TPM service module can be set in the same operating environment to form an integrated TPM module; alternatively, the TPM cryptographic module and the TPM service module can be set in different operating environments. When the TPM service module responds to a security service request, if it needs to call the computing resources of the TPM cryptographic module, it can call the computing resources of the TPM cryptographic module through a cross-operating environment call.
[0062] To maintain technological and industrial dominance in trusted computing and ensure core technologies for international information security are in China's hands, my country has introduced the Trusted Cryptography Module (TCM) standard. Specifically, the TCM module comprises a TCM cryptographic module and a TCM service module. These two modules work together to support the implementation of TCM trusted computing services.
[0063] The TCM cryptographic module is an independent cryptographic algorithm module with protected storage. It securely provides the essential hardware computing resources for trusted computing, including cryptographic operations, TRNG, root of trust, and storage. The TCM cryptographic module's algorithms include the digest algorithm unit (SM3), signature verification, and encryption and decryption algorithm units (SM2 and SM4). Future iterations will also support new algorithms. As the TCM specification evolves, the types of algorithms supported and the underlying technical methods differ between versions. However, the underlying security technical implementation objectives and methods remain the same. Therefore, the solutions described in this article are applicable to all versions of the TCM specification.
[0064] The TCM service module can provide security services such as trusted measurement, trusted reporting, and trusted storage to applications by calling the hardware resources of the TCM cryptographic module.
[0065] Typically, the TCM service module responds to security service requests by invoking the computing resources of the TCM cryptographic module. Specifically, when the TCM service module receives a security service request, it invokes the TCM cryptographic module's computing resources to implement security measurements and provide security measurement services. In some cases, the TCM cryptographic module can directly respond to certain security service requests and provide security measurement services. Alternatively, the TCM service module can independently respond to certain security service requests and provide security measurement services through its own software computing.
[0066] In actual applications, the TCM cryptographic module and the TCM service module can be set in the same operating environment to form an integrated TCM module; alternatively, the TCM cryptographic module and the TCM service module can also be set in different operating environments. When the TCM service module responds to a security service request, if it needs to call the computing resources of the TCM cryptographic module, it can call the computing resources of the TCM cryptographic module through a cross-operating environment call.
[0067] For example, both the TPM and TCM mentioned above can serve as the core of trusted computing. Their specific implementation can be a system-on-chip (SoC) installed on a motherboard, comprising a hardware module (cryptographic module) and a software module (service module). This system provides secure and reliable key storage, integrity reporting, and basic cryptographic operations for trusted computing. The difference lies in the fact that the TPM and TCM are based on different technical approaches and use different algorithms to provide security services and achieve system security measurement.
[0068] The security measurement services provided by TPM and TCM are both passive security measurement services. When the system starts, the BIOS must be started first. After the hardware and system are checked, the BIOS loads the TPM chip or TCM chip to play a security measurement role. This provides hackers with opportunities to invade and attack the BIOS.
[0069] In order to further improve the protection of the system by security measurement, my country has studied the TPCM standard that can perform active security measurement on the system.
[0070] TPCM can measure the integrity of the firmware before the CPU runs the firmware code, ensuring that the firmware has not been tampered with. TPCM technology includes a TPCM software (hereinafter referred to as the TPCM module) and a TCM module. The TPCM software must be combined with the TCM module to implement cryptographic support for the trusted software base. The TPCM module is a secure, independent module that uses TCM to implement active measurement. It contains two types of measurement processes: one is during the system power-on and startup process, when the TPCM module must be powered on first to actively measure and verify the firmware; the other is when the system is running, when the TPCM module will actively measure, verify, and record the application at a certain frequency.
[0071] When TPM or TCM is applied to a processor architecture system, TPM or TCM is the called resource, and the application implements security measurement of the target object by requesting security services from TPM or TCM.
[0072] Applications calling the TPM or TCM require the use of corresponding driver modules. Specifically, the TPM includes a TPM driver module, through which applications call the TPM; the TCM also includes a TCM driver module, through which applications call the TCM.
[0073] The TPM driver module, also known as the TPM client-side protocol unit or firmware-TPM (fTPM for short), is responsible for responding to applications' TPM service initiation requests and initiating TPM security service requests. The TCM driver module, also known as the TCM client-side protocol unit or firmware-TCM (fTCM for short), is responsible for responding to applications' TCM service initiation requests and initiating TCM security service requests. When an application needs to call the TPM or TCM, it first sends a TPM service initiation request or a TCM service initiation request to the TPM driver module or TCM driver module. Upon receiving the TPM service initiation request or the TCM service initiation request, the TPM driver module or the TCM driver module sends a TPM security service request to the TPM or the TCM. Upon receiving the TPM security service request or the TCM security service request, the TPM or TCM responds to the request and provides security measurement services. In actual applications, the TPM driver module can be set up together with the TPM or separately. Similarly, the TCM driver module can be set up together with the TCM or separately.
[0074] TPCM, on the other hand, is more proactive, proactively measuring system security according to pre-set rules. For example, during system startup, the TPCM module proactively measures and verifies firmware; or while the system is running, the TPCM module periodically measures, verifies, and records application programs.
[0075] In summary, TPM, TCM, and TPCM can all achieve security measurement of the system. Therefore, applying TPM, TCM, and TPCM to processor architecture systems, such as the above-mentioned two-level architecture system and three-level architecture system, can achieve trusted computing of the processor architecture system, which will be beneficial to ensuring system security and solving processor system security issues. Therefore, this application studies the application of the above-mentioned TPM, TCM, and TPCM to the processor architecture system, thereby obtaining a more secure security architecture system, and based on the specific system structure of the security architecture system, proposes a corresponding security measurement method to achieve security measurement of the security architecture system and ensure system security.
[0076] Because the TPCM requires the cryptographic support provided by the TCM, when the TPCM, TCM, and TPM are integrated into the same processor architecture, the TPCM can be a purely software module that implements active security measurements in conjunction with the cryptographic support provided by the TCM. Alternatively, the TPCM can include the TCM independently without relying on any other TCM functions or resources. In other words, the TPM and TCM are both hardware and software modules that can independently respond to security services, while the TPCM can be a software module that implements active security measurements by leveraging the TCM's hardware resources.
[0077] In the related prior art, the implementation of external TPM, TCM, and TPCM will increase the consumption of hardware resources in computer devices. However, the inventive concept proposed in this application can directly upgrade the settings of the processor in traditional technology in scenarios that do not involve trusted computing; in scenarios that involve trusted computing, it can directly update the settings of the trusted technology in the processor. Here, the implementation scheme of trusted technology may include: one or more of external TPM, TCM, and TPCM; or, a TPM integrated inside the processor; or, a TCM integrated inside the processor; or, a TPM and a TCM integrated inside the processor, etc.
[0078] Below, an exemplary introduction is given to the settings of TPM (including TPM cryptographic module, TPM service module, TPM driver module), TCM (including TCM cryptographic module, TCM service module, TCM driver module), and TPCM in a three-level processor architecture system, as well as various implementation methods of security measurement methods that can be achieved based on these settings.
[0079] The three-tier architecture system includes the common execution environment (REE), the trusted execution environment (TEE), and the secure element (SE). Common applications run in the REE, while trusted applications run in the TEE. Both common and trusted applications can be used as targets for security measurements.
[0080] By integrating the TPM, TCM, and TPCM into a trusted computing service support platform and implementing trusted computing within the three-tier architecture system, a secure architecture system with security measurement capabilities can be formed, thereby improving the security of the architecture system. Generally speaking, the security of the REE is lower than that of the TEE, which in turn is lower than that of the SE. Therefore, the trusted computing service support platform composed of the TPM, TCM, and TPCM is preferably installed within the TEE and / or SE, while the TPM driver module and TCM driver module can be installed in the REE and / or TEE based on actual needs and design requirements.
[0081] When the TPM and / or TCM are set in the TEE and / or SE, the service module and cryptographic module respectively included in the TPM and / or TCM can be dispersedly set in the TEE and / or SE.
[0082] Referring to the above description, since the TPM service module, TPM cryptographic module, TCM service module, and TCM cryptographic module can all independently respond to security service requests in some cases, the security architecture system of the above structure can respond to different types of security service requests.
[0083] In order to facilitate the distinction between various situations, the embodiment of the present application first classifies the security service requests that the above-mentioned security architecture system can respond to, specifically classifying them into first-class TCM security service requests, second-class TCM security service requests, first-class TPM security service requests and second-class TPM security service requests.
[0084] The first type of TCM security service request is a security service request corresponding to the TCM cryptographic module, specifically a security service request that requires the trusted computing resources provided by the TCM cryptographic module to respond to. In practice, the first type of TCM security service request can be sent directly to the TCM cryptographic module for a direct response, or sent to the TCM service module for a response by invoking the TCM cryptographic module's computing resources.
[0085] The second type of TCM security service request is a security service request corresponding to a TCM service module, specifically a security service request that can be independently responded to by the TCM service module.
[0086] The first type of TPM security service request is a security service request specific to the TPM cryptographic module. Specifically, it requires the trusted computing resources provided by the TPM cryptographic module to respond. In practice, the first type of TPM security service request can be sent directly to the TPM cryptographic module for a direct response, or sent to the TPM service module for a response by invoking the TPM cryptographic module's computing resources.
[0087] The second type of TPM security service request is a security service request corresponding to the TPM service module, specifically a security service request that can be independently responded to by the TPM service module.
[0088] In actual operation, ordinary applications in REE and / or trusted applications in TEE may issue any of the above-mentioned types of security service requests. The trusted computing service support platform can first identify the type of security service request obtained, and then select the corresponding security service module from the TCM service module, TCM cryptographic module, TPM service module and TPM cryptographic module to respond to the security service request. This may involve the design of processing such as the service module calling the cryptographic module and forwarding the security service request. The specific process will be introduced in subsequent embodiments.
[0089] In some cases, in order to adapt to the computing device type or certain application scenarios, the TCM cryptographic module and TCM service module included in the TCM may be set in different subsystems respectively, and the TPM cryptographic module and TPM service module included in the TPM may be set in different subsystems respectively. At the same time, TPCM can also be flexibly set in TEE or SE.
[0090] Specifically, in some embodiments, a security architecture system is composed of an ordinary execution environment subsystem REE, a trusted execution environment subsystem TEE and a security element subsystem SE, and a trusted computing service support platform is constructed in subsystems other than the REE, and the trusted computing service support platform includes a trusted cryptographic module TCM, a trusted platform module TPM and a trusted platform control module TPCM; the TCM includes a TCM service module and a TCM cryptographic module, and the TPM includes a TPM service module and a TPM cryptographic module; the TCM cryptographic module and the TCM service module run in different subsystems other than the REE, and / or the TPM cryptographic module and the TPM service module run in different subsystems other than the REE.
[0091] TPCM can be set in TEE or SE.
[0092] The trusted computing service support platform in the above-mentioned security architecture system is configured to: when the active security measurement function is triggered, use the TPCM to perform security measurement on the target object to obtain a security measurement result; or, in response to a security service request, use the TCM and / or the TPM to provide security measurement services for the target object to obtain a security measurement result;
[0093] The target object includes a running object in the REE and / or the TEE, and the security measurement result represents the credibility of the target object.
[0094] That is, the trusted computing service support platform in the above-mentioned security architecture system can execute the following security measurement method: when the active security measurement function is triggered, using the TPCM to perform security measurement on the target object to obtain a security measurement result; or, in response to a security service request, using the TCM and / or the TPM to provide security measurement services for the target object to obtain a security measurement result;
[0095] The target object includes a running object in the REE and / or the TEE, and the security measurement result represents the credibility of the target object.
[0096] The embodiment of the present application proposes a security measurement method for a security architecture system. The security architecture system is equipped with a common execution environment subsystem (REE) and a trusted execution environment subsystem (TEE). The trusted execution environment subsystem (TEE) includes a trusted cryptographic module (TCM), a trusted platform module (TPM), and a trusted platform control module (TPCM). Based on the above configuration, the security architecture system can use the TPCM to perform security measurement on the target object when the active security measurement function is triggered to obtain a security measurement result, or, in response to a security service request, provide security measurement services to the target object through the TCM and / or TPM to obtain a security measurement result. This solution can achieve security measurement of running objects in the processor architecture system, thereby being able to promptly clarify the security of the running objects and identify dangerous running objects, thus helping to ensure the security of the processor architecture system.
[0097] Furthermore, the embodiment of the present application integrates a trusted cryptographic module TCM, a trusted platform module TPM and a trusted platform control module TPCM in the processor architecture system, thereby providing passive security measurement services based on TCM and / or TPM and active security measurement services based on TPCM, which can meet the security measurement requirements of different applications or different users and improve the versatility of the processor architecture system.
[0098] Furthermore, in this embodiment, the cryptographic modules (TCM cryptographic modules and TPM cryptographic modules) used to provide trusted computing resources and the service modules (TPM service modules and TCM service modules) used to call the cryptographic modules are set in different subsystems. On the basis of providing security services for the target objects, the security isolation characteristics between different subsystems can be utilized to improve the isolation characteristics between the cryptographic modules and the service modules, thereby ensuring the security of the security architecture system.
[0099] Generally speaking, the deployment of TPM service module, TPM cryptographic module, TCM service module, TCM cryptographic module and TPCM in TEE and SE can be divided into two aspects: on the one hand, the deployment of TPM service module, TPM cryptographic module, TCM service module and TCM cryptographic module in TEE and SE; on the other hand, the deployment of TPCM in TEE or SE.
[0100] Among them, deploying TPCM in TEE or SE does not affect the functions and working methods of TPM service module, TPM cryptographic module, TCM service module and TCM cryptographic module; moreover, the deployment of TPM service module, TPM cryptographic module, TCM service module and TCM cryptographic module in TEE and SE does not affect the functions and working methods of TPCM.
[0101] On the basis of various security architecture system structures obtained by distributing the TCM service module, TCM cryptographic module, TPM service module and TPM cryptographic module in TEE and SE, TPCM is further set in the TEE or SE of the security architecture system, that is, the specific structure of various security architecture systems obtained by distributing the TPM service module, TPM cryptographic module, TCM service module, TCM cryptographic module and TPCM in TEE and SE is obtained.
[0102] As a preferred implementation, the TPM cryptographic module and the TCM cryptographic module can be placed in the same subsystem, that is, they can be placed together in the TEE or SE. Other modules, such as the TPCM, TPM service module, and TCM service module, can be distributed arbitrarily in the TEE and SE. For example, the TPCM can be placed in the TEE or SE, the TPM service module and the TCM service module can be placed in both the TEE or SE, or distributed in both the TEE and SE. The specific structure of the security architecture system obtained by these specific configurations will not be described in detail in the figure.
[0103] For example, in Figure 2 The TCM cryptographic module and the TPM cryptographic module are set in the SE of the three-level processor architecture system shown in FIG. , and the TCM service module, the TPM service module and the TPCM are set in the TEE, so that the following can be obtained: Figure 3The security architecture system shown in Figure 2 The TCM cryptographic module, TPM cryptographic module and TPCM are set in the SE of the three-level processor architecture system shown in the figure, and the TCM service module and TPM service module are set in the TEE, so as to obtain the following: Figure 4 The security architecture system shown.
[0104] exist Figure 3 and Figure 4 In the security architecture system shown, the layout of the TCM service module, TCM cryptographic module, TPM service module and TPM cryptographic module, as well as the functions that can be achieved and the specific processes of the security measurement methods executed under different layouts are not affected by the layout and functions of the TPCM; similarly, when the TPCM is set in the TEE or SE, its functions and the specific processes of the security measurement methods implemented are also not affected by the layout of the TCM service module, TCM cryptographic module, TPM service module and TPM cryptographic module.
[0105] Therefore, for the sake of brevity, in the subsequent embodiments, the main focus is on the situations where the TCM service module, TCM cryptographic module, TPM service module and TPM cryptographic module are dispersedly set in TEE and SE, as well as the security measurement functions and security measurement methods that can be achieved in these situations. In each of these introductions, combined with the setting of TPCM in TEE or SE, and the active security measurement function and active security measurement method implemented by TPCM, the specific structure of various security architecture systems obtained by "distributing TPM service module, TPM cryptographic module, TCM service module, TCM cryptographic module and TPCM in TEE and SE" can be obtained. Similarly, the security measurement methods compatible with active security measurement and passive security measurement achieved under these system structures can be clearly defined.
[0106] Regarding the active security measurement function and active security measurement method implemented by the above-mentioned security architecture system, specifically, when the system is powered on, TPCM actively measures and verifies the security of the firmware, or during the system operation, TPCM is periodically started at a certain frequency to perform active security measurement on the application and record the security measurement results.
[0107] In practical applications, the triggering mechanism of the active safety measurement function can be flexibly set, for example, it can be set to event triggering, periodic triggering, specific working state triggering, etc.
[0108] Since the implementation method of active security measurement is not affected by passive security measurement, when introducing the security measurement functions and security measurement methods of the trusted computing service support platform in security architecture systems with different structures, the following text will no longer specifically introduce the active security measurement part, but will specifically introduce various forms of passive security measurement parts.
[0109] Since the processor architecture system proposed in the embodiments of the present application includes TCM, TPM, and TPCM, it is possible that the active security measurement function is triggered and a security service request is received during system operation. In this case, different processing mechanisms can be designed.
[0110] Specifically, security metric priorities may be set in advance for TPCM, TCM, and TPM, and security metric priority information of TPCM, TCM, and TPM may be stored in the security architecture system.
[0111] When the active security measurement function is triggered and a security service request is received at the same time, a security measurement method is determined based on the security measurement priority information of the TPCM, TCM and TPM. The security measurement method specifically includes using the TPCM to perform security measurement on the target object to obtain a security measurement result, and, in response to the received security service request, using the TCM and / or the TPM to provide security measurement services for the target object to obtain one or more security measurement methods in the security measurement result.
[0112] Specifically, by querying the preset security measurement method priority, it is determined to use the TPCM to perform security measurement on the target object and obtain a security measurement result; and / or, in response to a received security service request, the TCM and / or TPM is used to provide security measurement services for the target object and obtain a security measurement result. Specifically, it is determined whether to perform active security measurement and / or passive security measurement. When performing passive security measurement, the TCM and / or TPM can be used to perform the security measurement.
[0113] or,
[0114] When the active security measurement function is triggered and a security service request is received at the same time, active security measurement and passive security measurement are performed simultaneously, that is, TPCM is used to perform security measurement on the target object at the same time to obtain a security measurement result, and, in response to the received security service request, TCM and / or TPM are used to provide security measurement services for the target object to obtain a security measurement result.
[0115] In practical applications, a security measurement priority can be set for the security architecture system, for example, setting the priority of active security measurement higher than the priority of passive security measurement, or setting the priority of passive security measurement higher than the priority of active security measurement.
[0116] If active security measurement is prioritized over passive security measurement, and if both the active security measurement function and a security service request are received, the active security measurement method is prioritized, i.e., the TPCM is used to perform security measurement on the target object and obtain the security measurement result. Subsequently, the TCM and / or TPM can be used to provide security measurement services to the target object in response to the security service request and obtain the security measurement result.
[0117] If the passive security measurement function is prioritized over the active security measurement function, and a security service request is received simultaneously, the passive security measurement function will be prioritized. In response to the security service request, the TCM and / or TPM will be used to provide security measurement services to the target object, obtaining a security measurement result. The TPCM can then be used to perform security measurement on the target object, obtaining a security measurement result.
[0118] Alternatively, the priorities of active security measurement and passive security measurement may not be distinguished. When the active security measurement function is triggered and a security service request is received at the same time, security measurement is performed simultaneously from two aspects, that is, security measurement is performed on the target object using TPCM to obtain a security measurement result, and, in response to the received security service request, security measurement services are provided to the target object using TCM and / or TPM to obtain a security measurement result.
[0119] Figure 3 and Figure 4 The trusted computing service support platform in the security architecture system shown uses the TCM and / or the TPM to provide security measurement services for the target object, which is divided into the following situations: using TCM to provide security measurement services for the target object, using TPM to provide security measurement services for the target object, and using TCM and TPM to provide security measurement services for the target object.
[0120] refer to Figure 3 and Figure 4 To accurately match security service requests, the security architecture system shown in this specification, in one embodiment, subdivides security service requests into TCM security service requests and TPM security service requests, allowing the trusted computing service support platform to respond in a targeted manner. Specifically, the trusted computing service support platform utilizes the TCM and / or TPM to provide security measurement services for the target object, specifically for:
[0121] A security service module corresponding to the security service request is selected to provide a security measurement service for the target object.
[0122] The security service module includes the TCM and / or the TPM, the security service request includes a TCM security service request and / or a TPM security service request, the TCM security service request corresponds to the TCM, and the TPM security service request corresponds to the TPM.
[0123] In this embodiment, when certain applications (trusted applications or common applications) support the TPM or TCM standard, a corresponding TCM security service request or TPM security service request may be initiated to request the corresponding security service module to provide security services.
[0124] In some implementations, there may be some applications that support both TPM and TPM standards, and in some application scenarios, it is necessary to call TPM and TCM at the same time to provide security services. In this case, when the security service request includes both the TCM security service request and the TPM security service request, the trusted computing service support platform uses the TCM and the TPM to provide security services for the target object, specifically for: responding to the TCM security service request, using the TCM to provide security services to obtain a first security measurement result; responding to the TPM security service request, using the TPM to provide security services to obtain a second security measurement result, and using the first security measurement result and the second security measurement result as the security measurement result.
[0125] In this way, the security service requirements of applications supporting both the TPM standard and the TCM standard can be met, thereby improving the applicability of the security service system.
[0126] In some embodiments, after receiving a security service request, the service module will call the cryptographic module to execute the cryptographic algorithm according to the security service request to complete the security measurement service. However, in some embodiments, in order to improve response efficiency, for certain security service requests, the service module can also directly respond and provide security measurement services.
[0127] Specifically, in some embodiments, the TCM service module is further configured to directly respond to the security service request and provide a security measurement service for the target object.
[0128] The TPM service module is further configured to directly respond to the security service request and provide a security measurement service for the target object.
[0129] The trusted computing service support platform uses the TCM and / or the TPM to provide security services for the target object, specifically for:
[0130] A security service module corresponding to the security service request is selected to provide a security measurement service for the target object.
[0131] The security service module includes at least one of the TCM cryptographic module, the TCM service module, the TPM cryptographic module and the TPM service module, and the security service request includes at least one of the first type TCM security service request, the second type TCM security service request, the first type TPM security service request and the second type TPM security service request.
[0132] The first type of TCM security service request corresponds to the TCM cryptographic module, the second type of TCM security service request corresponds to the TCM service module, the first type of TPM security service request corresponds to the TPM cryptographic module, and the second type of TPM security service request corresponds to the TPM service module.
[0133] In this embodiment, TCM security service requests are subdivided into first-class TCM security service requests and second-class TCM security service requests, wherein first-class TCM security service requests (such as requests to measure the security of target objects) are requests that require calling the cryptographic algorithm in the TCM cryptographic module for response, and this type of request corresponds to the TCM cryptographic module.
[0134] The second type of TCM security service request is a request that the TCM service module can directly respond to without calling the TCM cryptographic module. This type of request corresponds to the TCM service module.
[0135] Similarly, TPM security service requests are subdivided into first-class TPM security service requests and second-class TPM security service requests, where first-class TPM security service requests (such as requests to measure the security of target objects) are requests that require calling the cryptographic algorithm in the TPM cryptographic module for response, and this type of request corresponds to the TPM cryptographic module.
[0136] The second type of TPM security service request is a request that the TPM service module can directly respond to without calling the TPM cryptographic module. This type of request corresponds to the TPM service module.
[0137] In this embodiment, by subdividing the types of security service requests, different types of security service requests are respectively mapped to cryptographic modules and service modules, thereby increasing the response rate of the security architecture system to security service requests and improving the execution efficiency of the security architecture system.
[0138] In some embodiments, the security architecture system also includes TCM and TPM service proxy modules: a TCM driver module and a TPM driver module, to meet the needs of applications securely initiating security service requests. Specifically, the target objects include trusted applications and standard applications, the TEE runs the trusted applications, and the REE runs the standard applications. The security service requests include TCM security service requests and / or TPM security service requests.
[0139] The TCM further includes a TCM driver module, and the TPM further includes a TPM driver module.
[0140] The TCM driver module is configured to respond to the TCM service initiation request of the common application or the trusted application and initiate the TCM security service request.
[0141] The TPM driver module is configured to respond to the TPM service initiation request of the common application or the trusted application and initiate the TPM security service request.
[0142] The TCM driver module is part of the TCM and can be built into the REE and / or TEE to meet the needs of standard applications or trusted applications initiating TCM security service requests through the TCM driver module. A TCM service initiation request is a request made by a standard application or trusted application to the TCM driver module to request security services from the TCM in certain scenarios to meet the service requirements of the scenario. Upon receiving this TCM service initiation request, the TCM driver module responds to the request and initiates a TCM security service request to the TCM.
[0143] Similarly, the TPM driver module is part of the TPM and can be built into the REE and / or TEE to meet the needs of ordinary applications or trusted applications initiating TPM security service requests through the TPM driver module. A TPM service initiation request refers to a request made to the TPM driver module by an ordinary application CA or a trusted application TA to request the TPM to provide security services in certain scenarios to meet the service requirements of the scenario. Upon receiving the TPM service initiation request, the TPM driver module responds to the TPM service initiation request and initiates a TPM security service request to the TPM.
[0144] The TCM driver module and the TPM driver module can be built in the REE or the TEE at the same time, or they can be built in the same subsystem at different times. Figure 5(a) to Figure 5(i) The various configuration modes of the TCM driver module and the TPM driver module in REE and TEE shown can be applied to processor architecture systems, for example, Figure 3 In the security architecture system shown, various different types of three-level security architecture systems are obtained.
[0145] The different configuration methods of the TCM driver module and the TPM driver module in the REE and TEE will result in differences in the security measurement method of the entire security architecture system, or the specific execution process of the implemented security measurement method.
[0146] Below is Figure 3 Taking the security architecture system shown in the figure as an example, they are introduced separately with reference to the accompanying drawings.
[0147] refer to Figure 6 and Figure 7 The TCM driver module and the TPM driver module are built in the REE.
[0148] The security service request includes at least one of a first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module, a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module, a second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module, a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module, a first type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module, and a first type of TPM security service request initiated by the common application to the TCM service module through the TCM driver module.
[0149] Figure 6 The initiation and transmission paths of first-class TCM security service requests and first-class TPM security service requests are shown. Taking the first-class TCM security service request as an example, a common application CA initiates a TCM service initiation request to the TCM driver module. The TCM driver module responds to the TCM service initiation request, generates a first-class TCM security service request, and transmits it to the TCM service module or directly to the TCM cryptographic module. If the TCM service module receives the first-class TCM security service request, it forwards it to the TCM cryptographic module. The TCM cryptographic module responds to the first-class TCM security service request forwarded by the TCM service module and returns a security measurement result to the TCM service module. The TCM service module then returns the returned security measurement result to the TCM cryptographic module. If the TCM cryptographic module receives the first-class security service request directly from the TCM driver module, it returns the security measurement result obtained in response directly to the TCM driver module.
[0150] Similarly, for a first-category TPM security service request, a common application CA initiates a TPM service initiation request to the TPM driver module. The TPM driver module responds to the TPM service initiation request, generates a first-category TPM security service request, and transmits it to the TPM service module or directly to the TPM cryptographic module. If the TPM service module receives the first-category TPM security service request, it forwards it to the TPM cryptographic module. The TPM cryptographic module responds to the first-category TPM security service request forwarded by the TPM service module and returns a security measurement result to the TPM service module. The TPM service module receives the returned security measurement result and returns it to the TPM cryptographic module. If the TPM cryptographic module receives the first-category security service request directly from the TPM driver module, it returns the security measurement result obtained in response directly to the TPM driver module.
[0151] Figure 7 The initiation and transmission paths of the second-type TCM security service request and the second-type TPM security service request are shown. For the second-type TCM security service request, the ordinary application CA initiates a TCM service initiation request to the TCM driver module. The TCM driver module responds to the TCM service initiation request and sends the second-type TCM security service request to the TCM service module. The TCM service module directly responds to the second-type TCM security service request and returns the security measurement result to the TCM driver module.
[0152] Similarly, for the second type of TPM security service request, the ordinary application CA initiates a TPM service initiation request to the TPM driver module. The TPM driver module responds to the TPM service initiation request and sends the second type of TPM security service request to the TPM service module. The TPM service module directly responds to the second type of TPM security service request and returns the security measurement result to the TPM driver module.
[0153] exist Figure 7 This situation can quickly respond to the security service needs of common applications and improve the execution efficiency of the security architecture system.
[0154] exist Figure 6 In the two scenarios shown, the first-type TCM / TPM security service request, forwarded via the TCM / TPM service module to the TCM cryptographic module, offers high security. The first-type TCM / TPM security service request, delivered directly to the TCM / TPM cryptographic module, offers high efficiency. The TCM / TPM driver module can select the appropriate delivery path based on the type of TCM / TPM service request, achieving a balance between security and efficiency.
[0155] exist Figure 6 and Figure 7In the scenario shown, the location of the TCM cryptographic module, TCM service module, TPM cryptographic module, and TPM service module does not affect the request call and delivery process. Similarly, the location of the TPCM in the TEE or SE does not affect the request call and delivery process. Figure 6 and Figure 7 The location of the modules is not shown. Figure 6 and Figure 7 The security measurement function and security measurement method represented by the security measurement process shown are not only applicable to Figure 3 and Figure 4 The security architecture system shown is actually applicable to security architecture systems constructed in various situations where the TCM cryptographic module, TCM service module, TPM cryptographic module, TPM service module and TPCM are distributed or centrally set in TEE and SE.
[0156] In some embodiments, as Figure 8 and Figure 9 As shown, the TCM driver module and the TPM driver module are built in the TEE.
[0157] The security service request includes at least one of a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module, the first type of TCM security service request or the second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module, a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TCM driver module, and the first type of TPM security service request or the second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module.
[0158] Figure 8 and Figure 9 In the embodiment shown, the TCM driver module and the TPM driver module are both set in the TEE. If the ordinary application CA wants to initiate a TCM / TPM service initiation request, it needs to first initiate a trusted application request to the trusted application TA in the TEE. The trusted application TA responds to the trusted application request and, when it needs to request the TCM / TPM to provide security services, it initiates a TCM / TPM service initiation request to the TCM / TPM driver module. The subsequent first-class TCM / TPM security service request and the second-class TCM / TPM security service request transmission process are the same as Figure 6 and Figure 7 Similar to the description of Figure 6 and Figure 7 The relevant part description.
[0159] In some optional embodiments, reference Figure 10 , the TCM driver module and the TPM driver module are also built in the REE.
[0160] The security service request also includes: at least one of the following: a first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module in the REE, the first type of TCM security service request or the second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module in the REE, a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module in the REE, and the first type of TPM security service request or the second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module in the REE.
[0161] Figure 10 In the security architecture system shown, TCM driver modules and TPM driver modules are set in both REE and TEE, so that common application CA can initiate corresponding security service requests through multiple paths, meeting the path diversity of common application CA initiating security service requests and improving the applicability of the security architecture system.
[0162] Specifically, a common application CA can initiate a security service request through the TCM / TPM driver module in REE, or send a trusted application request to the trusted application TA in TEE, and the trusted application TA will initiate a security service request to the TCM / TPM driver module in TEE. The transmission process after the security service request is initiated by the TCM / TPM driver module can be referred to Figures 6 to 9 Related description.
[0163] In some embodiments, reference Figure 11 , the TCM driver module is built in the REE, and the TPM driver module is built in the TEE.
[0164] The security service request includes at least one of a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module in the TEE, a first type of TPM security service request or a second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module in the TEE, a first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module, and a first type of TCM security service request or a second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module.
[0165] exist Figure 11 In the illustrated embodiment, the initiation, response, and delivery paths of various security service requests may refer to the relevant descriptions above.
[0166] In this embodiment, the TCM driver module is set in the REE, and the TPM driver module is set in the TEE. The ordinary application CA in the REE can use the TCM driver module to initiate TCM security service requests. It can also request trusted application requests in the TEE to enable the trusted application TA to initiate TPM security service requests through the TPM driver module. The security architecture system provided by this embodiment can meet the needs of ordinary applications CA to directly initiate TCM security service requests to the TCM through the TCM driver module, and can also meet the needs of ordinary applications CA to initiate TCM security service requests through the TCM driver module and forward them through the TEE. It takes into account the security and execution efficiency of ordinary applications initiating TCM security service requests in different scenarios, thereby improving the applicability of the system.
[0167] Optionally, refer to Figure 12 , the TCM driver module is also built in the TEE, and the security service request further includes: at least one of: a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module in the TEE, a first type of TCM security service request or a second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module in the TEE;
[0168] or
[0169] refer to Figure 13, the TPM driver module is also built in the REE, and the security service request also includes: at least one of: a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module located in the REE, a first type of TPM security service request or a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module located in the REE.
[0170] exist Figure 12 In the system, the TCM driver module is set in REE and TEE to meet the needs of ordinary applications CA and trusted applications TA to initiate various security service requests for TCM. That is, the security architecture system can meet the needs of ordinary applications CA to directly initiate TCM security service requests to TCM through the TCM driver module, and can also meet the needs of ordinary applications CA to initiate TCM security service requests through the TCM driver module and forward them through TEE. It takes into account the security and execution efficiency of ordinary applications initiating TCM security service requests in different scenarios, and improves the applicability of the system.
[0171] exist Figure 13 In [1], the TPM driver module is set in both the REE and TEE, meeting the needs of both general applications (CA) and trusted applications (TA) to initiate various security service requests from the TPM. Similarly, this security architecture system can meet the needs of general applications (CA) to directly initiate TPM security service requests to the TPM through the TPM driver module, and can also meet the needs of general applications (CA) to initiate TPM security service requests through the TPM driver module and forward them through the TEE. This balances the security and execution efficiency of general applications initiating TPM security service requests in different scenarios, improving the applicability of the system.
[0172] exist Figures 12 and 13 In the illustrated embodiment, the initiation, response, and delivery paths of various security service requests may refer to the relevant descriptions above.
[0173] Optionally, refer to Figure 14 , the TCM driver module is built in the TEE, and the TPM driver module is built in the REE;
[0174] The security service request includes at least one of a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module in the TEE, a first type of TCM security service request or a second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module in the TEE, a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module, and a first type of TPM security service request or a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module.
[0175] exist Figure 14 In the illustrated embodiment, the initiation, response, and delivery paths of various security service requests may refer to the relevant descriptions above.
[0176] In this embodiment, the TPM driver module is set in the REE, and the TCM driver module is set in the TEE. The ordinary application CA in the REE can use the TPM driver module to initiate TPM security service requests. It can also request trusted application requests in the TEE, allowing the trusted application TA to initiate TCM security service requests through the TCM driver module. The security architecture system provided by this embodiment can meet the needs of ordinary applications CA to directly initiate TPM security service requests to the TPM through the TPM driver module, and can also meet the needs of ordinary applications CA to initiate TPM security service requests through the TPM driver module and forward them through the TEE. It takes into account the security and execution efficiency of ordinary applications initiating TPM security service requests in different scenarios, thereby improving the applicability of the system.
[0177] Optionally, refer to Figure 13 , the TCM driver module is further constructed in the REE, and the security service request further includes: at least one of: a first-type TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module located in the REE, a first-type TCM security service request or a second-type TCM security service request initiated by the common application to the TCM service module through the TCM driver module located in the REE;
[0178] or
[0179] refer to Figure 12, the TPM driver module is also built in the TEE, and the security service request also includes: at least one of the first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module in the TEE, and the first type of TPM security service request or the second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module in the TEE.
[0180] As some supplementary embodiments, in the processing of the various security measurement methods introduced in the various embodiments above and / or in the security architecture system, the trusted application in the TEE can also respond to the call of the ordinary application in the REE and issue a corresponding service request to the TCM and / or TPM.
[0181] A normal application in the REE calls a trusted application (TA) in the TEE. For example, a normal application in the REE sends a trusted application request to a trusted application (TA) in the SE. The trusted application (TA) runs in response to the normal application's call and requires trusted computing support from the TCM and / or TPM during runtime. Therefore, the trusted application (TA) sends a security service request to the TCM and / or TPM through the TCM driver module and / or TPM driver module in the TEE. The TCM and / or TPM responds to the security service request sent by the trusted application (TA), provides security measurement services for the target object, and obtains a security measurement result.
[0182] For example, when a shopping application running in REE needs to call the payment application in TEE to complete payment, the shopping application sends a payment application request to the payment application. When the payment application receives the call from the shopping application, it finds that it needs to perform payment environment security measurement first. The payment application then sends a security service request to the TCM and / or TPM. The TCM and / or TPM responds to the request to complete the security measurement of the payment environment and feeds back the measurement results to the payment application. When the payment application confirms that the payment environment is secure, it responds to the call from the shopping application and performs the payment operation.
[0183] The above operating mode is particularly suitable for scenarios where the REE lacks a TCM driver module and / or a TPM driver module, but is only installed in the TEE. In this case, if a standard application in the REE wants to request security services, it cannot directly do so due to the absence of a TCM driver module and / or a TPM driver module in the REE. However, the standard application in the REE can call a trusted application in the TEE, indirectly requesting security services through the trusted application and obtaining security measurement results. The trusted application can then feed these security measurement results back to the standard application in the REE.
[0184] For example, there is no TCM driver module configured in REE, but a TCM driver module is configured in TEE. However, ordinary applications in REE need to request TCM security services to implement certain functions. At this time, the ordinary applications in REE can first initiate a trusted application TA to TEE, that is, call the trusted application TA. When the trusted application TA responds to the call of the ordinary application and runs, it sends a TCM service initiation request to the TCM driver module of TEE, so that the TCM driver module sends a TCM security service request to TCM, thereby realizing the TCM security measurement function.
[0185] Based on the above embodiments, whether in a two-level security architecture system consisting of REE and TEE, or in a three-level security architecture system consisting of REE, TEE, and SE, the TCM driver module and the TPM driver module are either set in the REE or in the TEE. In some cases, the TCM driver module and the TPM driver module can provide some or all of the TCM services and TPM services. However, the TCM driver module and the TPM driver module must be in a highly trusted execution environment in order to provide trusted computing services.
[0186] Based on the two-level security architecture system or the three-level security architecture system proposed in the above embodiments of the present application, TEE applies hardware and software security architectures such as Trustzone, SGX (Software Guard Extensions) and other technologies, which can provide additional execution environment security protection for the entire TCM driver module and / or TPM driver module placed therein. Therefore, when specifically implementing the security architecture system proposed in the above embodiments of the present application, the processor core running the TEE can be virtualized as a security core. For example, when the TEE runs on the first processor core (in this case, the SE can run on the first processor core or the second processor core), the first processor core is virtualized as a security core.
[0187] For example, based on security technology (such as Trustzone or SGX, etc.), the first processor core is virtualized into a secure core and a non-secure core. Objects running on the secure core have the authority to access the resources of the entire first processor core, while objects running on the non-secure core have the authority to access the resources corresponding to the non-secure core.
[0188] On this basis, if the TCM driver module runs on the security core, when the TCM driver module receives a TCM service initiation request of the first type, the TCM driver module directly responds to the TCM service initiation request and provides security measurement services for the target object. The first type of TCM service initiation request is specifically a service request of a type that the TCM driver module can respond to.
[0189] For example, a list of service initiation requests that the TCM driver module can respond to locally is recorded in the TCM driver module. If the TCM service initiation request received by the TCM driver module is a service initiation request in the list, the TCM driver module responds to the service initiation request locally, otherwise a TCM security service request is sent to the TCM.
[0190] If the TPM driver module is running on the security core, then when the TPM service initiation request received by the TPM driver module is a second type of service initiation request, the TPM driver module directly responds to the TPM service initiation request and provides security measurement services for the target object. The second type of TPM service initiation request is specifically a type of service request that the TPM driver module can respond to.
[0191] Exemplarily, a list of service initiation requests that the TPM driver module can respond to locally is recorded in the TPM driver module. If the TPM service initiation request received by the TPM driver module is a service initiation request in the list, the TPM driver module responds to the service initiation request locally; otherwise, a TPM security service request is sent to the TPM.
[0192] Furthermore, the types of cryptographic algorithms required by TPM technology change with evolving security requirements. Frequent replacement of TPM cryptographic module hardware increases the cost of using TPM encryption and decryption operations. Therefore, when designing or deploying a TPM driver module, a mechanism can be added to identify the type of cryptographic algorithm and its version number. If a TPM service request identifies a TPM encryption and decryption algorithm that is not in the configured list, a pre-configured encryption and decryption method will be used.
[0193] Similarly, when designing or deploying a TCM driver module, a mechanism for identifying the type of cryptographic algorithm and its version number can be added. If the TCM encryption and decryption algorithm requested in the TCM service request is not in the configured list, a pre-configured encryption and decryption method will be used.
[0194] Specifically, a first key table may be configured in the TPM driver module, and a second key table may be configured in the TCM driver module. The first key table includes a first key and key types supported by the TPM, and the second key table includes a second key and key types supported by the TCM.
[0195] When the TPM driver module receives a TPM service initiation request, it first determines the key type requested in the received TPM service initiation request. When the key type requested in the received TPM service initiation request is not in the first key table, it updates the key type requested in the received TPM service initiation request to the first key.
[0196] Similarly, when the TCM driver module receives a TCM service initiation request, it first determines the key type requested in the received TCM service initiation request. When the key type requested in the received TCM service initiation request is not in the second key table, the key type requested in the received TCM service initiation request is updated to the second key.
[0197] The first key and the second key are keys applicable to the above-mentioned “pre-set encryption and decryption operation method”.
[0198] Finally, the security measurement methods proposed in the above embodiments of this application are explained.
[0199] This application proposes a security measurement method that can be applied to any of the above-mentioned security architecture systems including TCM, TPM and TPCM, and specifically can be executed by a trusted computing service support platform in any of the above-mentioned security architecture systems including TCM, TPM and TPCM. Figure 15 As shown, the method includes:
[0200] S201: When the active security measurement function is triggered, the TPCM is used to perform security measurement on the target object to obtain a security measurement result;
[0201] or,
[0202] S202: In response to the security service request, provide a security measurement service for the target object using the TCM and / or the TPM to obtain a security measurement result;
[0203] The target object includes a running object in the REE and / or TEE in the above-mentioned security architecture system, and the security measurement result represents the credibility of the target object.
[0204] The functions implemented by the various security architecture systems described in the above embodiments of this application, as well as the security measurement methods implemented in the security architecture systems of various different structures, all belong to the same application concept. The various security architecture systems described in the above embodiments can execute the security measurement methods provided in these embodiments and have the corresponding functional modules and beneficial effects of the execution methods. Therefore, the specific contents of the security measurement methods implemented in the security architecture systems of various different structures and the security measurement functions implemented by the partial structures or platforms of the corresponding security architecture systems can be understood and implemented with reference to each other, and the embodiments of this application will not be described in detail one by one.
[0205] An embodiment of the present application also provides a computer device, which includes the security architecture system provided in any of the above embodiments.
[0206] Another embodiment of the present application further provides a computer device, see Figure 16 As shown, the device includes:
[0207] Memory 200 and processor 210;
[0208] The memory 200 is connected to the processor 210 and is used to store programs;
[0209] The processor 210 is configured to implement the security measurement method disclosed in any of the above embodiments by running the program stored in the memory 200 .
[0210] Specifically, the computer device may further include: a bus, a communication interface 220 , an input device 230 and an output device 240 .
[0211] The processor 210, the memory 200, the communication interface 220, the input device 230 and the output device 240 are interconnected via a bus.
[0212] A bus may include a pathway that transfers information between components of a computer system.
[0213] Processor 210 can be a general-purpose processor, such as a general-purpose central processing unit (CPU), a microprocessor, or the like, or an application-specific integrated circuit (ASIC), or one or more integrated circuits for controlling the execution of the program of the present invention. Alternatively, it can be a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic device, discrete gate or transistor logic device, or discrete hardware components.
[0214] The processor 210 may include a main processor, and may also include a baseband chip, a modem, and the like.
[0215] The memory 200 stores a program for executing the technical solution of the present invention, and may also store an operating system and other key services. Specifically, the program may include program code, which includes computer operating instructions. More specifically, the memory 200 may include read-only memory (ROM), other types of static storage devices that can store static information and instructions, random access memory (RAM), other types of dynamic storage devices that can store information and instructions, disk storage, flash memory, etc.
[0216] The input device 230 may include a device for receiving data and information input by a user, such as a keyboard, a mouse, a camera, a scanner, a light pen, a voice input device, a touch screen, a pedometer, or a gravity sensor.
[0217] Output device 240 may include devices that allow information to be output to a user, such as a display screen, printer, speakers, etc.
[0218] The communication interface 220 may include any device such as a transceiver to communicate with other devices or communication networks, such as Ethernet, Radio Access Network (RAN), Wireless Local Area Network (WLAN), etc.
[0219] The processor 210 executes the program stored in the memory 200 and calls other devices, which can be used to implement each step of any security measurement method provided in the above embodiments of the present application.
[0220] In addition to the above methods and devices, an embodiment of the present application may also be a computer program product, which includes computer program instructions, which, when executed by a processor, enable the processor to execute the steps of the security measurement method described in any of the above embodiments of this specification.
[0221] The computer program product may be written in any combination of one or more programming languages to implement the program code for performing the operations of the embodiments of the present application, including object-oriented programming languages such as Java, C++, and conventional procedural programming languages such as "C" or similar programming languages. The program code may be executed entirely on the user's computing device, partially on the user's computing device, as a standalone software package, partially on the user's computing device and partially on a remote computing device, or entirely on a remote computing device or server.
[0222] In addition, an embodiment of the present application may also be a storage medium on which a computer program is stored, and the computer program is used by a processor to execute the steps of the security measurement method described in any of the above embodiments of this specification.
[0223] For the sake of simplicity, the aforementioned method embodiments are described as a series of action combinations. However, those skilled in the art should be aware that this application is not limited by the order of the actions described, because according to this application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in this specification are all preferred embodiments, and the actions and modules involved are not necessarily required by this application.
[0224] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Similarities between the various embodiments can be referred to in conjunction with each other. For device embodiments, since they are generally similar to method embodiments, their description is relatively simple, and for relevant details, reference can be made to the description of the method embodiments.
[0225] The steps in the methods of each embodiment of the present application can be adjusted in sequence, merged, and deleted according to actual needs, and the technical features recorded in each embodiment can be replaced or combined.
[0226] The modules and sub-modules in the devices and terminals of the various embodiments of the present application can be merged, divided, and deleted according to actual needs.
[0227] In the several embodiments provided in this application, it should be understood that the disclosed terminals, devices, and methods can be implemented in other ways. For example, the terminal embodiments described above are merely illustrative. For example, the division of modules or submodules is merely a logical function division. In actual implementation, there may be other division methods, such as multiple submodules or modules can be combined or integrated into another module, or some features can be ignored or not executed. In addition, the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interface, device or module, which can be electrical, mechanical or other forms.
[0228] The modules or submodules described as separate components may or may not be physically separate, and the components of the modules or submodules may or may not be physical modules or submodules, that is, they may be located in one place or distributed across multiple network modules or submodules. Some or all of the modules or submodules may be selected to achieve the purpose of this embodiment according to actual needs.
[0229] In addition, each functional module or submodule in each embodiment of the present application may be integrated into a processing module, or each module or submodule may exist physically separately, or two or more modules or submodules may be integrated into a single module. The above-mentioned integrated modules or submodules may be implemented in the form of hardware or software functional modules or submodules.
[0230] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0231] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, software units executed by a processor, or a combination of the two. The software units may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0232] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0233] The above description of the disclosed embodiments will enable those skilled in the art to implement or use the present application. Various modifications to these embodiments will be apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is to be construed in the widest manner consistent with the principles and novel features disclosed herein.
Claims
1. A security measurement method, characterized in that: Applied to a security architecture system, the security architecture system includes a common execution environment subsystem (REE), a trusted execution environment subsystem (TEE), and a secure element subsystem (SE). A trusted computing service support platform is constructed in the subsystems other than the REE. The trusted computing service support platform includes a trusted cryptographic module (TCM), a trusted platform module (TPM), and a trusted platform control module (TPCM). The TCM includes a TCM service module and a TCM cryptographic module, and the TPM includes a TPM service module and a TPM cryptographic module; the TCM cryptographic module and the TCM service module respectively run in different subsystems other than the REE, and / or the TPM cryptographic module and the TPM service module respectively run in different subsystems other than the REE; The method comprises: When the active security measurement function is triggered and a security service request is received, performing security measurement on a target object using the TPCM to obtain a security measurement result; and, in response to the received security service request, providing security measurement services for the target object using the TCM and / or the TPM to obtain a security measurement result; The target object includes a running object in the REE and / or the TEE, and the security measurement result represents the credibility of the target object.
2. The security measurement method according to claim 1, characterized in that: The TPM cryptographic module and the TCM cryptographic module run in the same subsystem.
3. The security measurement method according to claim 2, characterized in that: The TPCM, the TCM service module, and the TPM service module run in the TEE, and the TCM cryptographic module and the TPM cryptographic module run in the SE.
4. The security measurement method according to any one of claims 1 to 3, characterized in that: The TEE and the SE run in a first processor core, or the TEE runs in the first processor core and the SE runs in a second processor core.
5. The security measurement method according to claim 1, characterized in that: The TCM service module is further configured to directly respond to the security service request and provide security services for the target object; the TPM service module is further configured to directly respond to the security service request and provide security services for the target object; Providing a security measurement service for a target object by using the TCM and / or the TPM in response to a security service request includes: Selecting a security service module corresponding to the security service request to provide a security measurement service for the target object; The security service module includes at least one of the TCM cryptographic module, the TCM service module, the TPM cryptographic module, and the TPM service module; the security service request includes at least one of a first-type TCM security service request, a second-type TCM security service request, a first-type TPM security service request, and a second-type TPM security service request; The first type of TCM security service request corresponds to the TCM cryptographic module, the second type of TCM security service request corresponds to the TCM service module, the first type of TPM security service request corresponds to the TPM cryptographic module, and the second type of TPM security service request corresponds to the TPM service module.
6. The security measurement method according to claim 1, characterized in that: The target object includes a trusted application and a common application, the common application runs in the REE, and the trusted application runs in the TEE, and the security service request includes a TCM security service request and / or a TPM security service request; The TCM further includes a TCM driver module, and the TPM further includes a TPM driver module; The TCM driver module is configured to respond to the TCM service initiation request of the common application or the trusted application and initiate the TCM security service request; The TPM driver module is configured to respond to the TPM service initiation request of the common application or the trusted application and initiate the TPM security service request.
7. The security measurement method according to claim 6, characterized in that: The TCM security service request includes a first-type TCM security service request and / or a second-type TCM security service request, and the TPM security service request includes a first-type TPM security service request and / or a second-type TPM security service request; The TCM service module is further configured to directly respond to the second type of TCM security service request and provide a security measurement service for the target object; The TPM service module is further configured to directly respond to the second type of TPM security service request and provide security measurement services for the target object.
8. The security measurement method according to claim 7, characterized in that: The TCM driver module is disposed in the REE and / or the TEE, and the TPM driver module is disposed in the REE and / or the TEE.
9. The security measurement method according to claim 8, characterized in that: In the case where the TCM driver module and the TPM driver module are provided in the REE, the security service request includes: at least one of the following: a first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module, a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module, a first type of TCM security service request or a second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module, and a first type of TPM security service request or a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module.
10. The security measurement method according to claim 9, characterized in that: In a case where the TCM driver module and the TPM driver module are provided in the REE, and the TCM driver module and the TPM driver module are provided in the TEE, the security service request further includes: at least one of the following: a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module in the TEE, a first type of TCM security service request or a second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module in the TEE, a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module in the TEE, and the first type of TPM security service request or the second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module in the TEE.
11. The security measurement method according to claim 9, characterized in that: In a case where the TCM driver module and the TPM driver module are provided in the REE, and the TCM driver module is provided in the TEE, the security metric service request further includes: At least one of the first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module in the TEE, the first type of TCM security service request or the second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module in the TEE.
12. The security measurement method according to claim 9, characterized in that: In a case where the TCM driver module and the TPM driver module are provided in the REE, and the TPM driver module is provided in the TEE, the security service request further includes: At least one of a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module in the TEE, a first type of TPM security service request or a second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module in the TEE.
13. The security measurement method according to claim 8, characterized in that: In the case where the TCM driver module and the TPM driver module are provided in the TEE, the security service request includes: at least one of the following: a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module; a first type of TCM security service request or a second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module; a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module; and the first type of TPM security service request or the second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module.
14. The security measurement method according to claim 13, characterized in that: In a case where the TCM driver module and the TPM driver module are provided in the TEE, and the TCM driver module is provided in the REE, the security service request further includes: At least one of the first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module in the REE, and the first type of TCM security service request or the second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module in the REE.
15. The security measurement method according to claim 13, characterized in that: In a case where the TCM driver module and the TPM driver module are provided in the TEE, and the TPM driver module is provided in the REE, the security measurement service request further includes: At least one of a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module in the REE, and a first type of TPM security service request or a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module in the REE.
16. The security measurement method according to claim 8, characterized in that: In the case where the TCM driver module is set in the REE and the TPM driver module is set in the TEE, the security service request includes: at least one of the following: a first type of TPM security service request directly initiated by the trusted application to the TPM cryptographic module through the TPM driver module in the TEE, a first type of TPM security service request or a second type of TPM security service request initiated by the trusted application to the TPM service module through the TPM driver module in the TEE, a first type of TCM security service request directly initiated by the common application to the TCM cryptographic module through the TCM driver module in the REE, and a first type of TCM security service request or a second type of TCM security service request initiated by the common application to the TCM service module through the TCM driver module in the REE.
17. The security measurement method according to claim 8, characterized in that: In the case where the TPM driver module is set in the REE and the TCM driver module is set in the TEE, the security measurement service request includes: at least one of the following: a first type of TCM security service request directly initiated by the trusted application to the TCM cryptographic module through the TCM driver module in the TEE, a first type of TCM security service request or a second type of TCM security service request initiated by the trusted application to the TCM service module through the TCM driver module in the TEE, a first type of TPM security service request directly initiated by the common application to the TPM cryptographic module through the TPM driver module in the REE, and a first type of TPM security service request or a second type of TPM security service request initiated by the common application to the TPM service module through the TPM driver module in the REE.
18. The security measurement method according to any one of claims 6 to 17, characterized in that: The TEE and the SE run in a first processor core, or the TEE runs in the first processor core and the SE runs in a second processor core; virtualizing the first processor core as a security core; If the TCM driver module runs on the security core, the TCM driver module is further configured to: when the TCM service initiation request is a first type service initiation request, directly respond to the TCM service initiation request and provide a security measurement service for the target object; If the TPM driver module runs on the security core, the TPM driver module is further configured to: when the TPM service initiation request is a second type service initiation request, directly respond to the TPM service initiation request and provide a security measurement service for the target object.
19. The security measurement method according to any one of claims 6 to 17, characterized in that: The TPM driver module further includes a first key table, and the TCM driver module further includes a second key table, wherein the first key table includes a first key and a key type supported by the TPM, and the second key table includes a second key and a key type supported by the TCM; The TPM driver module is further configured to determine a key type requested in the TPM service initiation request, and when the determined key type is not in the first key table, update the key type requested in the TPM service initiation request to the first key; The TCM driver module is also used to determine the key type requested in the TCM service initiation request, and when the determined key type is not in the second key table, update the key type requested in the TCM service initiation request to the second key.
20. The security measurement method according to claim 1, characterized in that: In a case where the security service request includes a TCM security service request and a TPM security service request, providing a security measurement service for a target object by using the TCM and the TPM includes: In response to the TCM security service request, providing a security measurement service using the TCM to obtain a first security measurement result; and, in response to the TPM security service request, providing a security measurement service using the TPM to obtain a second security measurement result; The first security measurement result and the second security measurement result are used as the security measurement result.
21. A security architecture system, characterized in that: The security architecture system includes a common execution environment subsystem (REE), a trusted execution environment subsystem (TEE), and a secure element subsystem (SE). A trusted computing service support platform is constructed in the subsystems other than the REE. The trusted computing service support platform includes a trusted cryptographic module (TCM), a trusted platform module (TPM), and a trusted platform control module (TPCM). The TCM includes a TCM service module and a TCM cryptographic module, and the TPM includes a TPM service module and a TPM cryptographic module; the TCM cryptographic module and the TCM service module respectively run in different subsystems other than the REE, and / or the TPM cryptographic module and the TPM service module respectively run in different subsystems other than the REE; The trusted computing service support platform is configured to: when the active security measurement function is triggered and a security service request is received at the same time, perform security measurement on the target object using the TPCM to obtain a security measurement result; and, in response to the received security service request, provide security measurement services for the target object using the TCM and / or the TPM to obtain a security measurement result; The target object includes a running object in the REE and / or the TEE, and the security measurement result represents the credibility of the target object.
22. A computer device, characterized in that: The computer device includes the security architecture system of claim 21.