Trusted certification method based on target equipment and related equipment thereof
By using TCM in the protective components of the target equipment for PCR expansion operations and national secret algorithm signatures, verification information is generated, and the high cost problem caused by the additional opening of a trusted network port is solved, and the economic and security of remote trusted proofs are realized.
Patent Information
- Application Number
- CN202410183917.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-18
- Publication Date
- 2025-08-19
AI Technical Summary
In the prior art, in order to ensure that the measurement results of the target device are trustworthy, an additional trusted network port is required to be opened in the protective components, resulting in excessive network deployment and hardware costs.
By using a trusted password module (TCM) in the protective components of the target device, TCM is used to perform expansion operations of the platform configuration register (PCR) and signature operations of the national secret algorithm, to generate verification information of the measurement results, and send it to the management device through the non-trusted network port of the computing components of the target device, avoiding the additional opening of a trusted network port.
Remote trusted proof is realized, saving the network deployment and hardware costs of the target device, while ensuring data security without requiring an additional trusted network port.
Smart Images

Figure CN120509023A_ABST
Abstract
Description
Technical Field
[0001] The embodiments of the present application relate to the field of computer technology, and in particular to a target device-based trusted certification method and related devices. Background Art
[0002] Active immune trusted computing (also known as Trusted Computing 3.0) technology allows devices to protect themselves while performing computations. This means that devices can instantly identify the data they process, distinguishing between "own" and "non-own" data, thereby ensuring data security within the device. This technology can improve the security of devices within a network system, enabling the entire network to provide users with highly secure network services.
[0003] Active immune trusted computing technology provides a dual architecture of computing components and protection components, that is, the devices in the network system can be built based on computing components and protection components, and the protection components can perform trust measurement on the computing components to obtain the measurement results of the devices. In related technologies, the network system may include a management device and a target device. In order to ensure that the target device is trustworthy in the system, the management device may require the target device to perform trustworthy certification. Specifically, after the computing component of the target device receives the trustworthy certification request from the management device, it can forward it to the protection component of the target device. The protection component can obtain the measurement results of the target device based on the request, and send it to the management device through the trusted network port, so that the management device can determine whether the target device is trustworthy based on the measurement results of the target device.
[0004] In the above process, to ensure that the target device's measurement results transmitted by the protection component are trustworthy, a dedicated trusted network port can be established on the protection component. The management device can then determine the target device's measurement results received from the trusted network port as trustworthy, and can directly use the target device's measurement results to determine whether the target device is trustworthy. However, this approach requires establishing an additional trusted network port on the protection component, resulting in higher network deployment and hardware costs. Summary of the Invention
[0005] The embodiment of the present application provides a trusted attestation method based on a target device and related devices thereof, which can save the network deployment cost and hardware cost of the target device on the basis of realizing remote trusted attestation from the target device to the management device.
[0006] A first aspect of an embodiment of the present application provides a target device-based trusted attestation method. The target device used to implement the method includes a computing component and a protection component, and the method includes:
[0007] When the management device requires a target device to remotely attest to its trustworthiness, it can send a trustworthiness attestation request to the target device's computing component. Upon receiving the trustworthiness attestation request, the target device's computing component can determine, based on the trustworthiness attestation request, that it needs to prove to the management device that the target device is trustworthy. The computing component of the target device can then send the trustworthiness attestation request to the target device's protection component.
[0008] After receiving the trust attestation request, the target device's protection component determines, based on the trust attestation request, that it needs to prove to the management device that the target device is trustworthy. The target device's protection component then obtains the target device's measurement results, which were obtained by performing a trust measurement on the target device's computing component.
[0009] After obtaining the target device's measurement results, the target device's protection component can process the target device's measurement results to obtain verification information for the target device's measurement results. After obtaining the verification information, the target device's protection component can send the target device's measurement results and verification information to the target device's calculation component. The calculation component of the target device can then send the target device's measurement results and verification information to the management device.
[0010] In this way, the management device can determine whether the target device's measurement results are trustworthy based on the verification information. If the target device's measurement results are trustworthy based on the verification information, the management device can then determine whether the target device is trustworthy based on the target device's measurement results. This completes remote trustworthiness attestation.
[0011] It can be seen from the above method that: when the management device needs to make the target device perform remote trust certification, the protection component of the target device can obtain the measurement result of the target device and the verification information of the measurement result of the target device, and provide it to the computing component of the target device. Based on this, the computing component of the target device can not only provide the measurement result of the target device to the management device, but also provide the verification information of the measurement result of the target device, so that the management device can determine whether the measurement result of the target device is trustworthy based on the verification information, and then confirm whether the target device is trustworthy. It can be seen that the embodiment of the present application provides a new remote trust certification method. This remote trust certification method no longer requires the additional opening of a dedicated trusted network port. It only needs to reuse the existing conventional network port of the computing component of the target device to ensure that the measurement result of the target device provided to the management device is trustworthy, which is conducive to saving the network deployment cost and hardware cost of the target device.
[0012] In one possible implementation, the protection component includes a trusted cryptography module (TCM). The protection component processes the measurement result to obtain verification information of the measurement result, including: the protection component performs an expansion operation based on the platform configuration register (PCR) on the measurement result through the TCM to obtain a PCR reference value of the measurement result; the protection component performs a signature operation on the PCR reference value based on the private key of the national secret algorithm through the TCM to obtain a signature of the PCR reference value, and the verification information includes the PCR reference value, the signature, and the public key of the national secret algorithm; wherein the public key and the signature are used for the management device to determine whether the PCR reference value is credible, the PCR reference value and the PCR verification value of the measurement result are used for the management device to determine whether the measurement result is credible, and the PCR verification value is obtained by the management device performing an expansion operation based on the PCR on the measurement result. In the aforementioned implementation, the protection component of the target device can perform an expansion operation based on the PCR on the measurement result of the target device through the TCM to obtain the PCR reference value of the measurement result of the target device. Next, the target device's protection component can use the TCM to perform a signature operation on the PCR reference value of the target device's measurement result based on the private key of the national secret algorithm, thereby obtaining the signature of the PCR reference value of the target device's measurement result. The PCR reference value of the target device's measurement result, the signature of the PCR reference value of the target device's measurement result, and the public key of the national secret algorithm constitute the verification information of the target device's measurement result. Therefore, the target device's protection component can return the target device's measurement result and verification information to the target device's computing component via the TCM. After the computing component of the target device sends this information to the management device, the management device can first verify the signature of the PCR reference value of the target device's measurement result using the public key of the national secret algorithm, thereby obtaining a signature verification result. If the signature verification result indicates that the verification is successful, the management device can determine that the PCR reference value of the target device's measurement result is authentic. The management device can then perform a PCR-based expansion operation on the target device's measurement result to obtain the PCR verification value of the target device's measurement result. By comparing the PCR reference value of the target device's measurement result with the PCR verification value of the target device's measurement result, the management device can determine whether the target device's measurement result is authentic. Afterwards, the management device can confirm whether the target device is trustworthy based on the measurement results of the target device. Therefore, it can be seen that the protection component of the target device includes TCM that complies with the relevant national encryption standards.The protection component of the target device can use the PCR expansion function and signature function provided by TCM to formulate the verification information of the measurement results of the target device, which is conducive to the management device using the verification information to confirm that the measurement results of the target device are credible. There is no need to set up an additional trusted network port on the protection component of the target device to confirm that the measurement results of the target device are credible. This can save the hardware cost and network deployment cost required for the target device.
[0013] In one possible implementation, the computing component includes a non-trusted network port, and the computing component sends the measurement results and verification information to the management device, including: the computing component sends the measurement results and verification information to the management device through the non-trusted network port. In the aforementioned implementation, in the related art, in order to ensure that the measurement results of the target device are trustworthy, it is necessary to use a trusted network port. Since the trusted network port is set in the protective component of the target device, the protective component will be exposed to the outside, and there is a certain data security risk. In the embodiment of the present application, there is no need to set up a special trusted network port. What needs to be reused is the non-trusted network port of the computing component of the target device. This not only saves the hardware cost and network deployment cost required for the target device, but also helps to ensure the data security of the target device.
[0014] In one possible implementation, the measurement result is a measurement result of target data in a computing component. The method further includes: the computing component sending a trusted measurement request for the target data to the protection component; the protection component performing a digest operation based on a national secret algorithm on the target data via a TCM based on the trusted measurement request to obtain a measurement value for the target data; and the protection component obtaining the measurement result for the target data based on the measurement value and a reference value for the target data. In the aforementioned implementation, the computing component of the target device can initiate a trusted measurement for the target data, so the computing component of the target device can send a trusted measurement request for the target data to the protection component of the target device. After receiving the trusted measurement request for the target data, the protection component of the target device can perform a non-initial digest operation based on a national secret algorithm on the target data via a TCM to obtain a measurement value for the target data. The protection component of the target device can then compare the measurement value of the target data with the reference value of the target data to obtain a measurement result for the target data. If the measurement value of the target data and the reference value of the target data are not equal, the measurement result of the target data indicates that the target data is untrustworthy. If the measurement value of the target data and the reference value of the target data are equal, the measurement result of the target data indicates that the target data is trustworthy. It can be seen from this that the protection component of the target device can also use the summary calculation function provided by TCM to achieve trusted measurement of the target data on the computing component side of the target device. The measurement results of the target data obtained can be stored as the measurement results of the target device for subsequent use in remote attestation.
[0015] In one possible implementation, before the computing component sends a trust measurement request for the target data to the protection component, the method further includes: the computing component sends a baseline value acquisition request for the target data to the protection component; based on the baseline value acquisition request, the protection component performs a summary operation based on the national secret algorithm on the target data through TCM to obtain the baseline value of the target data. In the aforementioned implementation, the computing component of the target device can initiate baseline value acquisition for the target data, so the computing component of the target device can send a baseline value acquisition request for the target data to the protection component of the target device. After receiving the baseline value acquisition request for the target data, the protection component of the target device can perform the first summary operation based on the national secret algorithm on the target data through TCM to obtain the baseline value of the target data. It can be seen from this that the protection component of the target device can also obtain the baseline value of the target data in a snapshot manner, that is, the result of the first trust measurement performed on the target data is used as the baseline value of the target data, which can quickly and accurately complete the baseline value acquisition, which is conducive to the subsequent non-first trust measurement of the target data.
[0016] In one possible implementation, before the computing component sends a request to obtain a benchmark value for target data to the protection component, the method further includes: the computing component sends the address information of the target memory area serving the computing component to the protection component; the protection component performs a digest operation based on the national secret algorithm on the data in the target memory area based on the address information to obtain the benchmark value of the computing component; after a preset time period, the protection component again performs a digest operation based on the national secret algorithm on the data in the target memory area to obtain the measurement value of the computing component; the protection component obtains the measurement result of the computing component based on the benchmark value of the computing component and the measurement value of the computing component, and if the measurement result of the computing component is used to indicate that the computing component is trustworthy, the protection component allows the computing component to send a benchmark value acquisition request and a trustworthy measurement request to the protection component. In the aforementioned implementation, when the computing component of the target device needs to prove that it is trustworthy to the protection component of the target device, the computing component of the target device can send the address information of the target memory area serving the computing component to the protection component of the target device. Next, the target device's protection component can locate the target memory area within the target device's computing component based on the target memory area's address information and read all data within the target memory area to perform a digest operation on the data using a national secret algorithm, thereby obtaining a baseline value for the target device's computing component. After a preset duration, the target device's protection component again performs a digest operation on the data using a national secret algorithm to obtain a measurement value for the target device's computing component. After obtaining the target device's computing component's baseline value and the measurement value, the target device's protection component compares the baseline value and the measurement value to obtain a measurement result for the target device's computing component. When the target device's computing component's baseline value equals the measurement value of the target device's computing component, the measurement result indicates that the target device's computing component is trustworthy. In this case, the target device's protection component allows the target device's computing component to send a baseline value acquisition request and a trustworthy measurement request for the target data to the target device's protection component. It can be seen from this that since the computing component of the target device is exposed to the outside, the computing component of the target device can actively initiate a trust measurement to the protection component of the target device, so that the protection component can perform an overall trust measurement on the computing component to ensure that the computing component is trustworthy (secure), and only then will the computing component be allowed to execute subsequent steps (for example, obtaining a baseline value for the target data and trust measurement, etc.).
[0017] In one possible implementation, the computing component sending a trust measurement request for target data to the protection component includes: after the computing component determines that the target data satisfies a preset trust measurement condition, the computing component sending the trust measurement request for the target data to the protection component, the trust measurement condition including any one of the following: the target data is accessed or the target data is periodically detected. In the aforementioned implementation, after the computing component of the target device determines that the target data satisfies the preset trust measurement condition (for example, the target data carries a Linux security module (LMS) hook, and when the target data is accessed by the computing component of the target device, the LMS hook is triggered, so the computing component of the target device can determine that the target data satisfies the preset trust measurement condition. For another example, when the target data is periodically detected by the computing component of the target device, the computing component of the target device can determine that the target data satisfies the preset trust measurement condition), the computing component of the target device can initiate trust measurement for the target data, so the computing component of the target device can send the trust measurement request for the target data to the protection component of the target device.
[0018] In one possible implementation, the method further includes: the computing component receiving a trusted measurement policy from the management device, the trusted measurement policy including target data and control operations on the target data; the computing component sending the trusted measurement policy to the protection component; and if the measurement results of the target data indicate that the target data is untrustworthy, the protection component performing the control operations on the target data. In the aforementioned implementation, the management device may formulate a trusted measurement policy for the target device and send the trusted measurement policy to the computing component of the target device, wherein the trusted measurement policy includes the target data and control operations on the target data in the computing component of the target device. After obtaining the trusted measurement policy, the computing component of the target device sends the trusted measurement policy to the protection component of the target device. Subsequently, when the protection component of the target device subsequently obtains measurement results of the target data, if the measurement results indicate that the target data is untrustworthy, the protection component of the target device may perform the control operations on the target data as indicated by the trusted measurement policy. Therefore, since the target data is formulated by the management device, the target device, after obtaining the measurement results of the target data, can use them as the measurement results of the target device to remotely attest to the management device.
[0019] A second aspect of an embodiment of the present application provides a target device, which includes a computing component and a protection component; the computing component is used to receive a trusted proof request for the target device from a management device and send the trusted proof request to the protection component, and the management device is used to manage the target device; the protection component is used to obtain a measurement result of the target device based on the trusted proof request, and the measurement result is obtained by the protection component performing a trusted measurement on the computing component; the protection component is also used to process the measurement result, obtain verification information of the measurement result, and send the measurement result and verification information to the computing component; the computing component is also used to send the measurement result and verification information to the management device, the verification information is used for the management device to determine whether the measurement result is trustworthy, and the measurement result is used for the management device to determine whether the target device is trustworthy.
[0020] In one possible implementation, the protection component includes a TCM, and the protection component is used to: perform an extension operation based on the platform configuration register PCR on the measurement result through the TCM to obtain a PCR reference value of the measurement result; perform a signature operation on the PCR reference value based on the private key of the national secret algorithm through the TCM to obtain a signature of the PCR reference value, and the verification information includes the PCR reference value, the signature and the public key of the national secret algorithm; wherein the public key and the signature are used for the management device to determine whether the PCR reference value is credible, and the PCR reference value and the PCR verification value of the measurement result are used for the management device to determine whether the measurement result is credible, and the PCR verification value is obtained by the management device performing an extension operation based on PCR on the measurement result.
[0021] In a possible implementation, the computing component includes an untrusted network port, and the computing component is configured to send the measurement result and the verification information to the management device through the untrusted network port.
[0022] In one possible implementation, the measurement result is the measurement result of the target data in the computing component. The computing component is further used to send a trusted measurement request for the target data to the protection component; the protection component is further used to perform a summary operation based on the national secret algorithm on the target data through TCM based on the trusted measurement request to obtain the measurement value of the target data; the protection component is further used to obtain the measurement result of the target data based on the measurement value of the target data and the baseline value of the target data.
[0023] In one possible implementation, the computing component is also used to send a request for obtaining a baseline value for the target data to the protection component; the protection component is also used to perform a summary operation based on the national secret algorithm on the target data through TCM based on the baseline value acquisition request to obtain the baseline value of the target data.
[0024] In one possible implementation, the computing component is further used to send address information of a target memory area serving the computing component to the protection component; the protection component is further used to perform a summary operation based on a national secret algorithm on the data in the target memory area based on the address information to obtain a baseline value of the computing component; the protection component is further used to perform a summary operation based on a national secret algorithm on the data in the target memory area again after a preset period of time to obtain a measurement value of the computing component; the protection component is further used to obtain a measurement result of the computing component based on the baseline value of the computing component and the measurement value of the computing component. If the measurement result of the computing component is used to indicate that the computing component is trustworthy, the protection component allows the computing component to send a baseline value acquisition request and a trusted measurement request to the protection component.
[0025] In one possible implementation, the computing component is configured to send a trust metric request for the target data to the protection component after determining that the target data satisfies a preset trust metric condition. The trust metric condition includes any one of the following: the target data is accessed or the target data is periodically detected.
[0026] In one possible implementation, the computing component is further used to receive a trusted measurement policy from a management device, where the trusted measurement policy includes target data and control operations on the target data; the computing component is further used to send the trusted measurement policy to the protection component; and the protection component is further used to perform control operations on the target data if a measurement result of the target data indicates that the target data is untrustworthy.
[0027] A third aspect of an embodiment of the present application provides a target device, comprising a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the target device executes the method described in the first aspect or any possible implementation method of the first aspect.
[0028] A fourth aspect of an embodiment of the present application provides a computer storage medium storing one or more instructions, which, when executed by one or more computers, enables the one or more computers to implement the method described in the first aspect or any possible implementation method of the first aspect.
[0029] A fifth aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect or any possible implementation method of the first aspect.
[0030] In an embodiment of the present application, when a management device needs to require a target device to prove its trustworthiness to the management device, the management device may send a trustworthiness certification request for the target device to the target device's computing component. The target device's computing component may then send the trustworthiness certification request to the target device's protection component. The target device's protection component may then, based on the trustworthiness certification request, obtain the target device's measurement results. The target device's measurement results are obtained by the target device's protection component performing a trustworthiness measurement on the target device's computing component. The target device's protection component may then perform a series of processing on the target device's measurement results to obtain verification information for the target device's measurement results, and send the target device's measurement results and the verification information to the target device's computing component. Finally, the target device's computing component may send the target device's measurement results and the verification information to the management device. In this way, the management device may determine whether the target device's measurement results are trustworthy based on the verification information, and further determine whether the target device is trustworthy based on the target device's measurement results. In the aforementioned process, when the management device requires the target device to perform remote trustworthiness certification, the target device's protection component may obtain the target device's measurement results and the verification information for the target device's measurement results and provide them to the target device's computing component. Based on this, the computing component of the target device can not only provide the measurement results of the target device to the management device, but also provide verification information of the measurement results of the target device, so that the management device can determine whether the measurement results of the target device are credible based on the verification information, and then confirm whether the target device is credible. It can be seen that the embodiment of the present application provides a new remote trusted certification method. This remote trusted certification method no longer requires the establishment of an additional dedicated trusted network port. It only needs to reuse the existing conventional network port of the computing component of the target device to ensure that the measurement results of the target device provided to the management device are credible, which is conducive to saving the network deployment cost and hardware cost of the target device. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 A schematic diagram of the structure of the network system provided in an embodiment of the present application;
[0032] Figure 2 A schematic diagram of the structure of the target device provided in the embodiment of the present application;
[0033] Figure 3 Another structural diagram of the target device provided in an embodiment of the present application;
[0034] Figure 4 Another structural diagram of the target device provided in an embodiment of the present application;
[0035] Figure 5 A flowchart of a target device-based trusted authentication method provided in an embodiment of the present application;
[0036] Figure 6 Another structural diagram of the target device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0037] The embodiment of the present application provides a trusted attestation method based on a target device and related devices thereof, which can save the network deployment cost and hardware cost of the target device on the basis of realizing remote trusted attestation from the target device to the management device.
[0038] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0039] Active immune trusted computing technology allows devices to protect themselves while performing computations. This means that devices can instantly identify the data they process, distinguishing between "own" and "non-own" data, thereby ensuring data security within the device. This technology can improve the security of devices within a network system, enabling the entire system to provide users with highly secure network services.
[0040] Active immune trusted computing technology provides a dual architecture of computing components and protection components, that is, the devices in the network system can be built based on computing components and protection components, and the protection components can perform trust measurement on the computing components to obtain the measurement results of the devices. In related technologies, the network system may include a management device and a target device. In order to ensure that the target device is trustworthy in the system, the management device may require the target device to perform trustworthy certification. Specifically, after the computing component of the target device receives the trustworthy certification request from the management device, it can forward it to the protection component of the target device. The protection component can obtain the measurement results of the target device based on the request, and send it to the management device through the trusted network port, so that the management device can determine whether the target device is trustworthy based on the measurement results of the target device.
[0041] In the above process, an algorithm engine is deployed in the protection component. Although the measurement results of the target device are obtained by the protection component through the algorithm engine to measure the computing component, the algorithm engine is often developed by the manufacturer of the target device. Therefore, the algorithm engine is not trustworthy to the management device. In order to ensure that the measurement results of the target device obtained by the protection component through the algorithm engine are trustworthy to the management device, a trusted network port can be specially opened in the protection component. Therefore, the management device can determine that the measurement results of the target device received from the trusted network port are trustworthy, and directly use the measurement results of the target device to determine whether the target device is trustworthy. However, this method requires the opening of an additional trusted network port in the protection component, resulting in high network deployment costs and hardware costs.
[0042] In order to solve the above problems, the present invention provides a trustworthy certification method, which can be applied to a network system. Figure 1 A schematic diagram of the network system provided in the embodiment of the present application is shown in FIG. Figure 1 As shown, the network system includes a management device, a network device (for example, a router and a gateway, etc.) and a terminal device (for example, a server and a smart phone, etc.). Among them, the management device can manage all network devices and all terminal devices in the system, and any two terminal devices can communicate through the network device. It should be noted that in order to ensure the security and reliability of the entire system, the management device can make each network device and each terminal device prove to the management device in real time that it is a trusted device, that is, any network device and any terminal device can be used to implement the trusted certification method provided in the embodiment of the present application, that is, any network device and any terminal device can be used as the target device for executing the method.
[0043] To further understand Figure 1 The target device in the following is combined with Figure 2 Provide further information on the target device. Figure 2 A structural diagram of the target device provided in the embodiment of the present application is shown as follows: Figure 2 As shown, the target device 200 includes: an application processor 201, a microcontroller unit (MCU) 203, a memory 205, a modem 207, a radio frequency (RF) module 209, a wireless fidelity (Wi-Fi) module 211, a Bluetooth module 213, a sensor 214, a positioning module 250, an input / output (I / O) device 235 and other components. These components can communicate through one or more communication buses or signal lines. Those skilled in the art will understand that Figure 1The hardware structure shown in the figure does not constitute a limitation on the target device. The target device 200 may include more or fewer components than shown in the figure, or combine certain components, or arrange the components differently.
[0044] The following combination Figure 2 The following describes each component of the target device 200 in detail:
[0045] The application processor 201 is the control center of the target device 200, and uses various interfaces and buses to connect various components of the target device 200. In some embodiments, the processor 201 may include one or more processing units.
[0046] The memory 205 stores computer programs such as Figure 2 The operating system 261 and application 263 shown are shown. The application processor 201 is configured to execute the computer program in the memory 205, thereby implementing the functions defined by the computer program, for example, the application processor 201 executes the operating system 261 to implement various functions of the operating system on the target device 200. The memory 205 also stores other data besides the computer program, such as data generated during the operation of the operating system 261 and the application 263. The memory 205 is a non-volatile storage medium, generally including internal memory and external memory. Internal memory includes but is not limited to random access memory (RAM), read-only memory (ROM), or cache, etc. External memory includes but is not limited to flash memory, hard disk, optical disk, universal serial bus (USB) disk, etc. Computer programs are usually stored in external memory, and the processor loads the program from the external memory to the internal memory before executing the computer program.
[0047] The memory 205 may be independent and connected to the application processor 201 via a bus; the memory 205 may also be integrated with the application processor 201 into a chip subsystem.
[0048] MCU 203 is a coprocessor used to acquire and process data from sensor 214. While its processing power and power consumption are lower than those of application processor 201, MCU 203 is "always on," enabling it to continuously collect and process sensor data even when application processor 201 is in sleep mode, ensuring normal sensor operation with extremely low power consumption. In one embodiment, MCU 203 may be a sensor hub chip. Sensor 214 may include a light sensor and a motion sensor. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of display 251 based on ambient light levels, while the proximity sensor can shut off the display screen when the target device 200 is brought to the ear. An accelerometer, a type of motion sensor, can detect acceleration in all directions (typically three axes) and, when stationary, can detect the magnitude and direction of gravity. Sensor 214 may also include other sensors, such as a gyroscope, barometer, hygrometer, thermometer, and infrared sensor, which are not described in detail here. The MCU 203 and the sensor 214 may be integrated into the same chip, or may be separate components connected via a bus.
[0049] Modem 207 and RF module 209 constitute the communication subsystem of target device 200, which is used to implement the main functions of wireless communication standard protocols such as 3GPP and ETSI. Modem 207 is used for encoding and decoding, signal modulation and demodulation, and equalization. RF module 209 is used to receive and transmit wireless signals and includes, but is not limited to, an antenna, at least one amplifier, a coupler, a duplexer, etc. RF module 209 cooperates with modem 207 to implement wireless communication functions. Modem 207 can be a standalone chip or combined with other chips or circuits to form a system-on-chip or integrated circuit. These chips or integrated circuits can be applied to all target devices that implement wireless communication functions, including mobile phones, computers, laptops, tablets, routers, wearable devices, automobiles, and household appliances.
[0050] The target device 200 can also use Wi-Fi module 211, Bluetooth module 213, etc. to carry out wireless communication. The Wi-Fi module 211 is used to provide the target device 200 with network access that complies with Wi-Fi related standard protocols. The target device 200 can access the Wi-Fi access point through the Wi-Fi module 211 and then access the Internet. In some other embodiments, the Wi-Fi module 211 can also serve as a Wi-Fi wireless access point and can provide Wi-Fi network access for other target devices. The Bluetooth module 213 is used to achieve short-range communication between the target device 200 and other target devices (such as mobile phones, smart watches, etc.). The Wi-Fi module 211 in the embodiment of the present application can be an integrated circuit or a Wi-Fi chip, etc., and the Bluetooth module 213 can be an integrated circuit or a Bluetooth chip, etc.
[0051] The positioning module 250 is used to determine the geographic location of the target device 200. It is understood that the positioning module 250 can specifically be a receiver of a positioning system such as the Global Positioning System (GPS), the Beidou Satellite Navigation System, or the Russian GLONASS.
[0052] The Wi-Fi module 211, the Bluetooth module 213, and the positioning module 250 can each be a separate chip or integrated circuit, or they can be integrated together. For example, in one embodiment, the Wi-Fi module 211, the Bluetooth module 213, and the positioning module 250 can be integrated into the same chip. In another embodiment, the Wi-Fi module 211, the Bluetooth module 213, the positioning module 250, and the MCU 203 can also be integrated into the same chip.
[0053] The input / output device 235 includes but is not limited to a display 251 , a touch screen 253 , an audio circuit 255 and the like.
[0054] The touch screen 253 can collect touch events on or near the target device 200 (e.g., operations performed by a user using a finger, stylus, or any other suitable object on or near the touch screen 253) and transmit the collected touch events to other devices (e.g., the application processor 201). The user's operation near the touch screen 253 is referred to as a hover touch; through hover touch, the user can select, move, or drag an object (e.g., an icon) without directly contacting the touch screen 253. Furthermore, the touch screen 253 can be implemented using various types, including resistive, capacitive, infrared, and surface acoustic wave.
[0055] The display (also called a display screen) 251 is used to display information input by the user or information presented to the user. The display can be configured in the form of a liquid crystal display, an organic light emitting diode, etc. The touch screen 253 can cover the display 251. When the touch screen 253 detects a touch event, it transmits it to the application processor 201 to determine the type of touch event. The application processor 201 can then provide corresponding visual output on the display 251 based on the type of touch event. Although Figure 2 In the embodiment, the touch screen 253 and the display 251 are two independent components to implement the input and output functions of the target device 200. However, in some embodiments, the touch screen 253 and the display 251 can be integrated to implement the input and output functions of the mobile phone 200. In addition, the touch screen 253 and the display 251 can be configured in a full-panel manner on the front of the target device 200 to achieve a borderless structure.
[0056] The audio circuit 255, speaker 226, and microphone 217 provide an audio interface between the user and the target device 200. The audio circuit 209 can convert the received audio data into an electrical signal and transmit it to the speaker 213, which converts it into a sound signal for output. On the other hand, the microphone 214 converts the collected sound signal into an electrical signal, which is received by the audio circuit 209 and converted into audio data. The audio data is then sent via the modem 207 and the radio frequency module 209 to, for example, another target device, or the audio data is output to the memory 205 for further processing.
[0057] In addition, the target device 200 may also have a fingerprint recognition function. For example, a fingerprint acquisition device may be configured on the back of the target device 200 (e.g., below the rear camera), or on the front of the target device 200 (e.g., below the touch screen 253). For another example, a fingerprint acquisition device may be configured in the touch screen 253 to implement the fingerprint recognition function, that is, the fingerprint acquisition device may be integrated with the touch screen 253 to implement the fingerprint recognition function of the target device 200. In this case, the fingerprint acquisition device is configured in the touch screen 253, may be a part of the touch screen 253, or may be configured in the touch screen 253 in other ways. The main component of the fingerprint acquisition device in the embodiment of the present application is a fingerprint sensor, which may use any type of sensing technology, including but not limited to optical, capacitive, piezoelectric, or ultrasonic sensing technology.
[0058] Furthermore, the operating system 261 carried by the target device 200 may be Or other operating systems, the embodiments of the present application do not impose any restrictions on this.
[0059] To carry Taking the target device 200 of the operating system as an example, Figure 2 As shown, target device 200 can be logically divided into a hardware layer, an operating system 261, and an application layer. The hardware layer includes hardware resources such as the hardware processor 201, microcontroller unit 205, modem 207, Wi-Fi module 211, sensor 214, and positioning module 250, as described above. The application layer includes one or more application programs, such as application 263. Application 263 can be any type of application, such as a social application, an e-commerce application, or a browser. Operating system 261, serving as the software middleware between the hardware and application layers, is a computer program that manages and controls hardware and software resources.
[0060] In one embodiment, the operating system 261 includes a kernel, a hardware abstraction layer (HAL), libraries and runtime, and a framework. The kernel provides underlying system components and services, such as power management, memory management, thread management, and hardware drivers. Hardware drivers include Wi-Fi drivers, sensor drivers, and positioning module drivers. The hardware abstraction layer encapsulates the kernel driver, providing an interface to the framework and shielding low-level implementation details. The hardware abstraction layer 25 runs in user space, while the kernel driver runs in kernel space.
[0061] The library and runtime are also called runtime libraries, which provide the required library files and execution environment for the executable program at runtime. In one embodiment, the library and runtime include Android Runtime (ART), library, and scene package runtime. ART is a virtual machine or virtual machine instance that can convert the bytecode of an application into machine code. The library is a program library that provides support for the executable program at runtime, including a browser engine (such as webkit), a script execution engine (such as JavaScript engine), a graphics processing engine, etc. The scene package runtime is the operating environment of the scene package, mainly including a page execution environment (page context) and a script execution environment (script context), wherein the page execution environment parses page codes in formats such as html and css by calling the corresponding library, and the script execution environment parses and executes codes or executable files implemented in scripting languages such as JavaScript by calling the corresponding function library.
[0062] The framework is used to provide various basic common components and services for each application in the application layer, such as window management, location management, etc. In one embodiment, the framework may include a geo-fence service, a policy service, a notification manager, etc.
[0063] The functions of the various components of the operating system 261 described above may be implemented by the application processor 201 executing a program stored in the memory 205 .
[0064] To further understand Figure 2 The target device in the following is combined with Figure 3 Provides further information on the target device. Figure 3 Another structural diagram of the target device provided in the embodiment of the present application is as follows Figure 3 As shown ( Figure 3 Another structural diagram of the target device provided in the embodiment of the present application) The target device can be simplified as a device including a computing component and a protection component. From the hardware layer, the computing component can include a processor (set at Figure 2 processor in the ) and regular network ports (that is, non-trusted network ports, set in Figure 2 In the input and output devices, Figure 2 The network port is not shown in the figure), the protection component may include a processor (set at Figure 2 The processor in the system) and the trusted cryptography module (TCM).
[0065] When the processor of the computing component boots up, the software layers it presents include: the application layer running in the rich execution environment (REE), the REE operating system kernel, and the unified extensible firmware interface (UEFI) / basic input and output system (BIOS). When the processor of the protection component boots up, the software layers it presents include: the trusted platform control module (TCPM) running in the trusted execution environment (TEE).
[0066] In the computing component, the application layer agent includes modules such as the remote attestation module, the trusted software stack, the client application (CA) and trusted application (TA) communication module, the policy management module, and the benchmark library module. The REE operating system kernel's measurement agent module includes modules such as the measurement data module, the CA and TA communication module, and the trusted cryptographic service driver.
[0067] Among the protection components, TCPM includes REE and TEE communication module, policy management module, verification module, benchmark library module, report generation module, trusted cryptographic service module, control module, TEE operating system kernel, TEE secure storage, ARM trusted firmware (ATF), external secure boot code (ESBC) and secure boot code (bootROM secure boot code, BSBC).
[0068] The following is a preliminary introduction to the functions of these modules:
[0069] (1) Startup measurement: When the system starts, the BSBC of TCPM is powered on, and then the BSBC can perform an integrity check on the ESBC (based on the national encryption algorithm SM2 or SM3), and start the ESBC after the check passes. Then, the ESBC can perform an integrity check on the UEFI / BIOS and ATF, and after the check passes, the UEFI / BIOS and ATF can be started (if the check fails, the system will be hung or reset). Subsequently, the ATF performs an integrity check on the TEE operating system through the TEE extended measurement module (including Figure 3 The TEE OS is booted after verification. UEFI / BIOS also performs integrity checks on the REE OS kernel. If the verification passes, the REE OS kernel can be booted (if the verification fails, the system will be suspended or reset). This way, a complete chain of trust can be established.
[0070] (2) TCM is a security module that complies with the relevant standards of national cryptographic modules. It is usually presented as a chip or some kind of firmware. The functions provided by TCM may include platform configuration register (PCR) expansion, summary calculation based on national cryptographic algorithm and other functions, etc. These functions can be used by modules on the protection component side and modules on the computing component side. Since TCM is located in the protection component, when the module in the computing component needs to call TCM, it can access TCM through the trusted software stack, trusted cryptographic service driver, trusted cryptographic service module and TCM communication chain, such as Figure 4 As shown ( Figure 4 Another structural schematic diagram of the target device provided in an embodiment of the present application).
[0071] (3) The benchmark library module on the computing component side can work with the benchmark library module on the protection component side to generate benchmark values for each measurable data (also known as an object) in the computing component. These data include static data (also known as static objects) and dynamic data (also known as dynamic objects), but there are certain differences in the way the benchmark values of the two are obtained. For example, for static data, the benchmark library module on the computing component side can obtain a preset benchmark library file, which contains the benchmark value of each static data, the type of each static data (binary file, dynamic library, script, kernel module, etc.), the path of the file, and other contents, and store the benchmark library file in the benchmark library module on the protection component side. For another example, for static data, the benchmark library module on the computing component side can scan the entire disk to determine each static data, and call the TCM through the verification module to perform the digest calculation based on the national secret algorithm SM3 for these static data for the first time (that is, the first trustworthy measurement of these static data), thereby obtaining and returning the benchmark values of these static data to the benchmark library module on the computing component side, and generating the corresponding benchmark library file to be stored in the benchmark library module on the protection component side. For example, for dynamic data, the computing component side can determine each dynamic data, and call TCM through the verification module to perform summary calculations on these dynamic data based on the national secret algorithm SM3 for the first time, thereby obtaining and returning the benchmark values of these dynamic data to the benchmark library module on the computing component side, and generating corresponding benchmark library files to be stored in the benchmark library module on the protection component side.
[0072] It should be noted that after the baseline library file is generated, the baseline library module on the computing component side can call TCM to use the private key of the TCM Chinese cryptographic algorithm SM2 to perform a signature operation on the baseline library file to obtain the signature of the baseline library file, thereby ensuring that the baseline library file has not been tampered with. Before the baseline library module on the protection component side saves the baseline library file, it can use the root certificate in the TEE secure storage and the Chinese cryptographic algorithm SM2 to verify the signature of the baseline library file, thereby ensuring that the source of the baseline library file is credible and has not been tampered with, and then save the baseline library file.
[0073] (4) The policy management module on the computing component side can receive the trusted measurement policy from the management device and send it to the policy management module on the protection component side. The policy management module on the protection component side will first verify the signature of the trusted measurement policy using the root certificate or public key provided by the national secret algorithm SM2 to ensure that the source of the trusted measurement policy is trusted and has not been tampered with, and then save the trusted measurement policy to the TEE secure storage. It should be noted that the trusted measurement policy may include various static data and dynamic data in the computing component of the target device formulated by the management device, and after the trusted measurement of these data, if the trusted measurement of these data indicates that these data are untrustworthy, the protection component can perform control operations on these data (IO read and write restriction operations, device shutdown / reset operations, process termination / reset operations, no control operations, etc.) and so on.
[0074] (5) Active measurement: The measurement agent module can send a request and the measurement agent module's memory information (which may include the start and end addresses of the memory code segment, the start and end addresses of the memory constant data segment, the memory address of the key variable requested to save the trust measurement policy, and the kernel memory address of other key variables) to the verification module, so that the verification module can perform trust measurement on the measurement agent module based on this memory information, thereby obtaining a trust measurement result of the measurement agent module, so that the verification module can confirm that the measurement agent module is trustworthy based on this result. The measurement agent module can also receive the trust measurement policy sent by the policy management module on the protection component side, and start the measurement function for each static data and each dynamic data based on this policy.
[0075] (6) The objects of static measurement include: binary files, dynamic libraries, scripts, kernel module files, kernel files and other static data. The measurement module can use the Linux security module (LMS) hook to hang on each static data. When the LMS hook of these static data is triggered, the measurement agent module can (through the aforementioned communication chain) call TCM to perform summary calculations based on the national secret algorithm SM3 on these static data, thereby obtaining the measurement values of these static data and sending the measurement values of these static data to the verification module. Then, the verification module can obtain the baseline values of these static data from the benchmark library module to generate the measurement results of these static data based on the measurement values and baseline values of these static data. If the measurement results indicate that these static data are credible, the verification module can return success to the measurement agent. Otherwise, the verification module calls the report generation module to record the measurement results of these static data and obtains the trusted measurement policy from the TEE secure storage to call the control module to execute the control operations specified in the policy on these static data.
[0076] The objects of dynamic measurement include: application process memory code segments, kernel module memory code segments, operating system memory code segments, and operating system key data. Optionally, the objects of dynamic measurement may also include dynamic data such as application process control flow, kernel module control flow, process or kernel module key behavior, and network cluster key data. The operating system key data includes at least: system call table, MMU enable bit, page table read and write execution control bit, interrupt description table, SELinux enable bit, etc. The measurement agent module can periodically measure each dynamic data. After entering a certain cycle, the measurement agent module can call the TCM to perform summary calculations on these dynamic data based on the national secret algorithm SM3, thereby obtaining the measurement values of these dynamic data and sending the measurement values of these dynamic data to the verification module. The verification module can then obtain the baseline values of these dynamic data from the benchmark library module to generate measurement results for these dynamic data based on the measurement values and baseline values of these dynamic data. If the measurement results indicate that these dynamic data are credible, the verification module can return success to the measurement agent. Otherwise, the verification module calls the report generation module to record the measurement results of these dynamic data, and obtains the trusted measurement policy from the TEE secure storage to call the control module to execute the control operations specified in the policy on these dynamic data.
[0077] (7) Remote Trusted Attestation: The remote attestation module can receive a trusted attestation request from the management device, and based on the request, obtain the measurement results of each static data and each dynamic data from the report generation module, and call the TCM to process these measurement results (for example, expansion operations based on PCR, signature operations based on the national secret algorithm SM2, etc.), thereby obtaining verification information of these measurement results and returning it to the remote attestation module. Then, the remote attestation module can feed back the measurement results and verification information of these data to the management device through the regular network port of the computing component, so that the management device can confirm whether the measurement results of these data are trustworthy based on the verification information, and then confirm whether the target device is trustworthy based on the measurement results of these data.
[0078] The above is a preliminary introduction to the various modules of the target device and their functions. In order to further understand the workflow of the target device when performing remote attestation to the management device, the following is combined with Figure 5 This workflow is further described. Figure 5 A flow chart of a target device-based trusted authentication method provided in an embodiment of the present application is shown as follows: Figure 5 As shown, the target device includes a computing component and a protection component, and the method includes:
[0079] 501. The computing component receives a trustworthy certification request for a target device from a management device, and sends the trustworthy certification request to the protection component. The management device is used to manage the target device.
[0080] In this embodiment, when the management device requires the target device to remotely authenticate itself to the management device, the management device may send a trusted authentication request to the target device's computing component. Upon receiving the trusted authentication request, the target device's computing component may determine, based on the trusted authentication request, that it needs to authenticate itself to the management device as a trusted device. The computing component of the target device may then send the trusted authentication request to the target device's protection component, causing the protection component to perform subsequent operations based on the trusted authentication request.
[0081] Specifically, the computing component of the target device may receive the trusted attestation request in the following manner:
[0082] The untrusted network port (regular network port) of the computing component of the target device can be exposed to the management device, so the computing component of the target device can receive the trusted certification request sent by the management device through the untrusted network port.
[0083] For example, Figure 3 As shown, when the management device needs to ask the target device to prove that it is a trusted device, it can send a trusted attestation request to the target device's remote attestation module through the target device's untrusted network port. Based on the trusted attestation request, the management device can determine that the target device needs to be proven to be a trusted device. The remote attestation module can then send the trusted attestation request to the TEE operating system via the REE and TEE communication module, allowing the modules within the TEE operating system to perform subsequent operations.
[0084] 502. The protection component obtains the measurement result of the target device based on the trusted proof request. The measurement result is obtained by the protection component performing trusted measurement on the computing component.
[0085] After receiving the trusted proof request, the protection component of the target device can obtain the measurement result of the target device based on the trusted proof request. The measurement result of the target device is obtained by the protection component of the target device performing trusted measurement on the computing component of the target device.
[0086] As in the above example, after receiving the trusted attestation request, the report generation module in the TEE operating system can obtain the measurement results representing the entire target device based on the trusted attestation request, and send the trusted attestation request and the measurement results of the target device to the TCM.
[0087] Specifically, the measurement result of the target device usually refers to the measurement result of the target data in the computing component of the target device (there are usually multiple target data, and the multiple target data are the aforementioned multiple static data and / or multiple dynamic data). Therefore, before the management device sends a trusted proof request to the computing component of the target device, the computing component and the protection component of the target device can obtain the measurement result of the target data in advance by the following methods:
[0088] In some cases, the computing component of the target device can initiate a trusted measurement for the target data, so the computing component of the target device can send a trusted measurement request for the target data to the protection component of the target device. After receiving the trusted measurement request for the target data, the protection component of the target device can determine based on the request that a trusted measurement needs to be performed on the target data, so the protection component of the target device can perform a non-first digest operation based on the national secret algorithm on the target data through TCM, thereby obtaining the measurement value of the target data. Then, the protection component of the target device can compare the measurement value of the target data with the baseline value of the target data, thereby obtaining the measurement result of the target data. If the measurement value of the target data and the baseline value of the target data are not equal, the measurement result of the target data is used to indicate that the target data is untrustworthy. If the measurement value of the target data and the baseline value of the target data are equal, the measurement result of the target data is used to indicate that the target data is trustworthy.
[0089] Still as in the above example, in some cases, the measurement agent module can initiate a trusted measurement for the target data (for example, each static data and each dynamic data). The measurement agent module can send a trusted measurement request for the target data to the TCM through the aforementioned communication link, so the TCM can perform a non-first digest operation based on the national secret algorithm SM3 on the target data (that is, a non-first trusted measurement of the target data), thereby obtaining the measurement value of the target data, and providing the measurement value of the target data to the verification module. After obtaining the measurement value of the target data, since the benchmark library module on the protection component side stores the benchmark value of the target data, the verification module can obtain the benchmark value of the target data from the benchmark library module on the protection component side, and compare the measurement value of the target data and the benchmark value of the target data, thereby obtaining the measurement result of the target data. If the measurement value of the target data and the benchmark value of the target data are not equal, the measurement result of the target data is used to indicate that the target data is untrustworthy. If the measurement value of the target data and the benchmark value of the target data are equal, the measurement result of the target data is used to indicate that the target data is trustworthy.
[0090] More specifically, the computing component and the protection component of the target device can also obtain the measurement results of the target data in advance in the following ways:
[0091] After the computing component of the target device determines that the target data meets the preset trust measurement conditions, the computing component of the target device can initiate trust measurement for the target data. Therefore, the computing component of the target device can send a trust measurement request for the target data to the protection component of the target device. For example, when the target data is static data, the target data carries an LMS hook. When the target data is accessed by the computing component of the target device, the LMS hook will be triggered. Therefore, the computing component of the target device can determine that the target data meets the preset trust measurement conditions. For another example, when the target data is dynamic data, when the target data is periodically detected by the computing component of the target device, the computing component of the target device can determine that the target data meets the preset trust measurement conditions.
[0092] As in the previous example, if the target data is static, it carries an LMS hook. When an application uses the target data, the LMS hook is triggered. Once the measurement agent detects that the LMS hook has been triggered, it can initiate a trusted measurement of the target data. If the target data is dynamic, the measurement agent periodically checks each dynamic data item. When a certain period of time passes, the target data will be detected by the measurement agent, and the measurement agent can initiate a trusted measurement of the target data.
[0093] More specifically, since the benchmark value of the target data is preset in advance by the computing component and the protection component of the target device, before the computing component of the target device sends a trust measurement request for the target data to the protection device of the target device, the computing component and the protection component of the target device can obtain the benchmark value of the target data in advance in the following manner:
[0094] In some cases, the target device's computing component may initiate a baseline value acquisition for the target data. Therefore, the target device's computing component may send a baseline value acquisition request for the target data to the target device's protection component. Upon receiving the baseline value acquisition request for the target data, the target device's protection component may determine, based on the request, that a baseline value acquisition is required for the target data. The target device's protection component may then perform an initial digest operation on the target data using the National Security Criteria (NSC) algorithm, thereby obtaining the target data's baseline value and storing the target data's baseline value.
[0095] Still as in the above example, at the request of the measurement agent module on the computing component side, the benchmark library module on the computing component side can initiate benchmark value acquisition for the target data (for example, various static data and various dynamic data). The benchmark library module on the computing component side can send a benchmark value acquisition request for the target data to the TCM through the aforementioned communication link, so the TCM can perform the first summary operation based on the national secret algorithm SM3 on the target data (that is, the first trusted measurement of the target data), thereby obtaining the benchmark value of the target data, and store the benchmark value of the target data in the benchmark library module on the protection component side in a certain way.
[0096] More specifically, before the target device's protection component allows the target device's computing component to invoke the TCM, it must confirm that the target device's computing component is trustworthy. Therefore, before the target device's computing component sends a request to the target device's protection component to obtain the benchmark value for the target data, the target device's computing component can proactively prove its trustworthiness to the target device's protection component:
[0097] When the computing component of the target device needs to prove that it is trustworthy to the protection component of the target device, the computing component of the target device can send the address information of the target memory area serving the computing component to the protection component of the target device. Then, the protection component of the target device can find the target memory area located in the computing component of the target device based on the address information of the target memory area, and read all the data in the target memory area to perform a summary operation based on the national secret algorithm on these data, thereby obtaining the baseline value of the computing component of the target device. After a preset period of time (the length of this period can be set according to actual needs and is not limited here), the protection component of the target device again performs a summary operation based on the national secret algorithm on these data, thereby obtaining the measurement value of the computing component of the target device.
[0098] After obtaining the baseline value of the target device's computing component and the measurement value of the target device's computing component, the target device's protection component compares the baseline value of the target device's computing component and the measurement value of the target device's computing component to obtain the measurement result of the target device's computing component. When the baseline value of the target device's computing component is equal to the measurement value of the target device's computing component, the measurement result of the target device's computing component is used to indicate that the target device's computing component is trustworthy. In this case, the target device's protection component allows the target device's computing component to send a baseline value acquisition request and a trusted measurement request for the target data to the target device's protection component, that is, allows the target device's computing component to initiate the acquisition of the baseline value and the trusted measurement for the target data.
[0099] Continuing with the above example, the metric agent module can initiate an active trust measurement from the verification module. Specifically, the metric agent module can send a request and its memory information (i.e., the address of the target memory area) to the verification module. Based on this memory information, the verification module locates the memory area corresponding to the metric agent module in the computing component's memory, retrieves all data representing the metric agent module, and invokes the TCM to perform a digest operation based on the national secret algorithm SM3 on this data, thereby obtaining a baseline value for the metric agent module. After a period of time, the verification module can again invoke the TCM to perform a digest operation based on the national secret algorithm SM3 on this data, thereby obtaining the metric agent module's measurement value. The verification module can then compare the metric agent module's baseline value with the metric agent module's measurement value to obtain a trust measurement result for the metric agent module. If this result confirms that the metric agent module is trustworthy, the verification module allows the metric agent module to initiate baseline value acquisition and trust measurement for the target data.
[0100] More specifically, the target data is data specified by the management device. The management device can specify the target data to the target device in the following ways:
[0101] The management device can formulate a trusted measurement policy for the target device and send it to the target device's computing component. The trusted measurement policy includes the target data in the target device's computing component and the control operations applied to the target data. After obtaining the trusted measurement policy, the target device's computing component sends it to the target device's protection component. Subsequently, when the target device's protection component obtains measurement results for the target data, if the measurement results indicate that the target data is untrustworthy, the target device's protection component can execute the control operations directed by the trusted measurement policy on the target data.
[0102] Continuing with the above example, the policy management module on the computing component side can receive the trusted measurement policy from the management device and send it to the policy management module on the protection component side, so that the policy management module on the protection component side can store the trusted measurement policy. Because the trusted measurement policy includes target data and control operations on the target data, after the verification module obtains the measurement results of the target data, if the measurement results of the target data indicate that the target data is untrustworthy, the verification module can call the policy management module on the protection component side to query the trusted measurement policy for the control operations on the target data, and then call the control module to execute the control operations on the target data.
[0103] 503. The protection component processes the measurement result, obtains verification information of the measurement result, and sends the measurement result and the verification information to the calculation component.
[0104] 504. The calculation component sends the measurement result and verification information to the management device. The verification information is used by the management device to determine whether the measurement result is credible, and the measurement result is used by the management device to determine whether the target device is credible.
[0105] After obtaining the measurement results of the target device, the protection component of the target device can process the measurement results of the target device to obtain verification information of the measurement results of the target device. Then, the protection component of the target device can send the measurement results and verification information of the target device to the calculation component of the target device. Then, the calculation component of the target device can send the measurement results and verification information of the target device to the management device (through the non-trusted network port). In this way, the management device can determine whether the measurement results of the target device are credible based on the verification information. If the measurement results of the target device are credible, the management device will then determine whether the target device is a credible device based on the measurement results of the target device. At this point, remote trusted attestation is completed.
[0106] As in the previous example, after the TCM receives the trusted attestation request and the target device's measurement results, it processes the target device's measurement results based on the trusted attestation request to obtain verification information for the measurement results and returns the target device's measurement results and verification information to the remote attestation module. The remote attestation module then sends the target device's measurement results and verification information to the management device, allowing the management device to confirm the trustworthiness of the target device's measurement results based on the verification information and, further, to confirm the trustworthiness of the target device based on the target device's measurement results.
[0107] Specifically, the protection component of the target device can obtain verification information in the following ways:
[0108] The protection component of the target device can perform a PCR-based expansion operation on the measurement result of the target device (the target data of the computing component) through TCM, thereby obtaining the PCR reference value of the measurement result of the target device. Then, the protection component of the target device can perform a signature operation on the PCR reference value of the measurement result of the target device based on the private key of the national secret algorithm through TCM, thereby obtaining the signature of the PCR reference value of the measurement result of the target device. Then, the PCR reference value of the measurement result of the target device, the signature of the PCR reference value of the measurement result of the target device, and the public key of the national secret algorithm and other information constitute the verification information of the measurement result of the target device. Therefore, the protection component of the target device can return the measurement result of the target device and the verification information to the computing component of the target device through TCM.
[0109] After the computing component of the target device sends the measurement result and verification information of the target device to the management device, the management device can first use the public key of the national secret algorithm to verify the signature of the PCR reference value of the measurement result of the target device, thereby obtaining a signature verification result. If the signature verification result is used to indicate that the verification is passed, the management device can determine that the PCR reference value of the measurement result of the target device is credible. Then, the management device can perform a PCR-based expansion operation on the measurement result of the target device to obtain the PCR verification value of the measurement result of the target device. If the PCR reference value of the measurement result of the target device and the PCR verification value of the measurement result of the target device are the same, the management device can determine that the measurement result of the target device is credible. Then, the management device can confirm whether the target device is credible based on the measurement result of the target device.
[0110] As in the above example, after the TCM receives the trusted proof request and the measurement result of the target device, the TCM can perform a PCR-based expansion operation on the measurement result of the target device based on the trusted proof request, thereby obtaining the PCR reference value of the measurement result of the target device. Next, the TCM can perform a signature operation on the PCR reference value of the measurement result of the target device based on the private key of the national secret algorithm SM2, thereby obtaining the signature of the PCR reference value of the measurement result of the target device. Then, the PCR reference value of the measurement result of the target device, the signature of the PCR reference value of the measurement result of the target device, and the public key of the national secret algorithm SM2 constitute the verification information of the measurement result of the target device, so the TCM returns this information to the remote proof module.
[0111] After the remote attestation module sends this information to the management device, the management device can first use the public key of the national secret algorithm SM2 to perform a verification operation on the signature of the PCR reference value of the measurement result of the target device, thereby obtaining a signature verification result. If the signature verification result is used to indicate that the verification is passed, the management device can determine that the PCR reference value of the measurement result of the target device is credible. Next, the management device can perform a PCR-based expansion operation on the measurement result of the target device to obtain the PCR verification value of the measurement result of the target device. If the PCR reference value of the measurement result of the target device and the PCR verification value of the measurement result of the target device are the same, the management device can determine that the measurement result of the target device is credible. Then, the management device can confirm whether the target device is credible based on the measurement result of the target device.
[0112] In an embodiment of the present application, when a management device needs to require a target device to prove its trustworthiness to the management device, the management device may send a trustworthiness certification request for the target device to the target device's computing component. The target device's computing component may then send the trustworthiness certification request to the target device's protection component. The target device's protection component may then, based on the trustworthiness certification request, obtain the target device's measurement results. The target device's measurement results are obtained by the target device's protection component performing a trustworthiness measurement on the target device's computing component. The target device's protection component may then perform a series of processing on the target device's measurement results to obtain verification information for the target device's measurement results, and send the target device's measurement results and the verification information to the target device's computing component. Finally, the target device's computing component may send the target device's measurement results and the verification information to the management device. In this way, the management device may determine whether the target device's measurement results are trustworthy based on the verification information, and further determine whether the target device is trustworthy based on the target device's measurement results. In the aforementioned process, when the management device requires the target device to perform remote trustworthiness certification, the target device's protection component may obtain the target device's measurement results and the verification information for the target device's measurement results and provide them to the target device's computing component. Based on this, the computing component of the target device can not only provide the measurement results of the target device to the management device, but also provide verification information of the measurement results of the target device, so that the management device can determine whether the measurement results of the target device are credible based on the verification information, and then confirm whether the target device is credible. It can be seen that the embodiment of the present application provides a new remote trusted certification method. This remote trusted certification method no longer requires the establishment of an additional dedicated trusted network port. It only needs to reuse the existing conventional network port of the computing component of the target device to ensure that the measurement results of the target device provided to the management device are credible, which is conducive to saving the network deployment cost and hardware cost of the target device.
[0113] Furthermore, in related technologies, to ensure that the measurement results of the target device are credible, a trusted network port is required. Since the trusted network port is located in the protective component of the target device, the protective component is exposed to the outside world, posing certain data security risks. In the embodiment of the present application, the computing component of the target device is deployed with a remote attestation module, which can complete the overall docking with the management device. This process reuses the regular network port (non-trusted network port) of the computing component of the target device, which is conducive to ensuring the data security of the target device.
[0114] Furthermore, in an embodiment of the present application, whether for static data or dynamic data, a snapshot method can be used to obtain the baseline value of these data, that is, the value obtained by the first trust measurement of these data is used as the baseline value of these data, which is conducive to quickly generating a baseline value to achieve subsequent trust measurement of these data, and use the measurement results of these data as the measurement results of the target device, thereby completing remote trust proof.
[0115] Furthermore, in an embodiment of the present application, the trusted software stack, trusted cryptographic service driver, trusted cryptographic service module and TCM in the target device constitute a communication chain across the computing component and the protection component, which allows each module in the computing component to call the TCM in the protection component through the communication chain to use the various functional services provided by the TCM.
[0116] The above is a detailed description of the trusted certification method based on the target device provided in the embodiment of the present application. The target device provided in the embodiment of the present application will be introduced below. Figure 6 Another structural diagram of the target device provided in the embodiment of the present application is as follows Figure 6 As shown, the target device includes a computing component 601 and a protection component 602:
[0117] The computing component 601 is configured to receive a trustworthy certification request for a target device from a management device and send the trustworthy certification request to the protection component 602 , where the management device is configured to manage the target device.
[0118] The protection component 602 is used to obtain the measurement result of the target device based on the trustworthy proof request. The measurement result is obtained by the protection component 602 performing trustworthy measurement on the computing component 601;
[0119] The protection component 602 is further configured to process the measurement result, obtain verification information of the measurement result, and send the measurement result and verification information to the calculation component 601;
[0120] The calculation component 601 is further configured to send the measurement result and verification information to the management device. The verification information is used by the management device to determine whether the measurement result is credible, and the measurement result is used by the management device to determine whether the target device is credible.
[0121] In an embodiment of the present application, when a management device needs to require a target device to prove its trustworthiness to the management device, the management device may send a trustworthiness certification request for the target device to the target device's computing component. The target device's computing component may then send the trustworthiness certification request to the target device's protection component. The target device's protection component may then, based on the trustworthiness certification request, obtain the target device's measurement results. The target device's measurement results are obtained by the target device's protection component performing a trustworthiness measurement on the target device's computing component. The target device's protection component may then perform a series of processing on the target device's measurement results to obtain verification information for the target device's measurement results, and send the target device's measurement results and the verification information to the target device's computing component. Finally, the target device's computing component may send the target device's measurement results and the verification information to the management device. In this way, the management device may determine whether the target device's measurement results are trustworthy based on the verification information, and further determine whether the target device is trustworthy based on the target device's measurement results. In the aforementioned process, when the management device requires the target device to perform remote trustworthiness certification, the target device's protection component may obtain the target device's measurement results and the verification information for the target device's measurement results and provide them to the target device's computing component. Based on this, the computing component of the target device can not only provide the measurement results of the target device to the management device, but also provide verification information of the measurement results of the target device, so that the management device can determine whether the measurement results of the target device are credible based on the verification information, and then confirm whether the target device is credible. It can be seen that the embodiment of the present application provides a new remote trusted certification method. This remote trusted certification method no longer requires the establishment of an additional dedicated trusted network port. It only needs to reuse the existing conventional network port of the computing component of the target device to ensure that the measurement results of the target device provided to the management device are credible, which is conducive to saving the network deployment cost and hardware cost of the target device.
[0122] In one possible implementation, the protection component 602 includes a TCM, and the protection component 602 is used to: perform an extension operation based on the platform configuration register PCR on the measurement result through the TCM to obtain a PCR reference value of the measurement result; perform a signature operation on the PCR reference value based on the private key of the national secret algorithm through the TCM to obtain a signature of the PCR reference value, and the verification information includes the PCR reference value, the signature and the public key of the national secret algorithm; wherein the public key and the signature are used for the management device to determine whether the PCR reference value is credible, and the PCR reference value and the PCR verification value of the measurement result are used for the management device to determine whether the measurement result is credible, and the PCR verification value is obtained by the management device performing an extension operation based on the PCR on the measurement result.
[0123] In a possible implementation, the computing component 601 includes an untrusted network port, and the computing component 601 is configured to send the measurement result and verification information to the management device through the untrusted network port.
[0124] In one possible implementation, the measurement result is the measurement result of the target data in the calculation component 601. The calculation component 601 is also used to send a trusted measurement request for the target data to the protection component 602; the protection component 602 is also used to perform a summary operation based on the national secret algorithm on the target data through TCM based on the trusted measurement request to obtain the measurement value of the target data; the protection component 602 is also used to obtain the measurement result of the target data based on the measurement value of the target data and the baseline value of the target data.
[0125] In one possible implementation, the computing component 601 is also used to send a request for obtaining a benchmark value for the target data to the protection component 602; the protection component 602 is also used to perform a summary operation based on the national encryption algorithm on the target data through TCM based on the benchmark value acquisition request to obtain the benchmark value of the target data.
[0126] In one possible implementation, the computing component 601 is further used to send the address information of the target memory area serving the computing component 601 to the protection component 602; the protection component 602 is further used to perform a summary operation based on the national secret algorithm on the data in the target memory area based on the address information to obtain a reference value of the computing component 601; the protection component 602 is further used to perform a summary operation based on the national secret algorithm on the data in the target memory area again after a preset period of time to obtain a measurement value of the computing component 601; the protection component 602 is further used to obtain a measurement result of the computing component 601 based on the reference value of the computing component 601 and the measurement value of the computing component 601. If the measurement result of the computing component 601 is used to indicate that the computing component 601 is trustworthy, the protection component 602 allows the computing component 601 to send a reference value acquisition request and a trusted measurement request to the protection component 602.
[0127] In one possible implementation, the computing component 601 is used to determine that the target data meets a preset trust measurement condition, and then the computing component 601 sends a trust measurement request for the target data to the protection component 602. The trust measurement condition includes any one of the following: the target data is accessed or the target data is periodically detected.
[0128] In one possible implementation, the computing component 601 is further used to receive a trusted measurement policy from a management device, where the trusted measurement policy includes target data and control operations on the target data; the computing component 601 is further used to send the trusted measurement policy to the protection component 602; and the protection component 602 is further used to perform control operations on the target data if the measurement result of the target data indicates that the target data is untrustworthy.
[0129] It should be noted that the information interaction, implementation process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.
[0130] The embodiment of the present application also relates to a computer storage medium, including computer-readable instructions, which, when executed, implements the following Figure 5 Method steps of the illustrated embodiment.
[0131] The present application also relates to a computer program product comprising instructions, which, when executed on a computer, causes the computer to execute the following Figure 5 Method steps of the illustrated embodiment.
[0132] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0133] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0134] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0135] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0136] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM, read-only memory), random access memory (RAM, random access memory), disk or optical disk, and other media that can store program code.
Claims
1. A trusted certification method based on a target device, characterized in that: The target device includes a computing component and a protection component, and the method includes: The computing component receives a trustworthy certification request for the target device from a management device, and sends the trustworthy certification request to the protection component, wherein the management device is used to manage the target device; The protection component obtains a measurement result of the target device based on the trusted proof request, where the measurement result is obtained by the protection component performing a trusted measurement on the computing component; The protection component processes the measurement result to obtain verification information of the measurement result, and sends the measurement result and the verification information to the calculation component; The calculation component sends the measurement result and the verification information to the management device, the verification information is used by the management device to determine whether the measurement result is credible, and the measurement result is used by the management device to determine whether the target device is credible.
2. The method according to claim 1, characterized in that The protection component includes a trusted cryptographic module TCM. The protection component processes the measurement result to obtain verification information of the measurement result, including: The protection component performs an expansion operation based on a platform configuration register PCR on the measurement result through the TCM to obtain a PCR reference value of the measurement result; The protection component performs a signature operation on the PCR reference value using the private key of the national secret algorithm by the TCM to obtain a signature of the PCR reference value, wherein the verification information includes the PCR reference value, the signature, and the public key of the national secret algorithm; Among them, the public key and the signature are used by the management device to determine whether the PCR reference value is credible, the PCR reference value and the PCR check value of the measurement result are used by the management device to determine whether the measurement result is credible, and the PCR check value is obtained by the management device performing a PCR-based expansion operation on the measurement result.
3. The method according to claim 1 or 2, characterized in that The computing component includes an untrusted network port, and the computing component sends the measurement result and the verification information to the management device, including: The calculation component sends the measurement result and the verification information to the management device through the untrusted network port.
4. The method according to any one of claims 1 to 3, characterized in that The measurement result is a measurement result of the target data in the calculation component, and the method further includes: The computing component sends a trust metric request for the target data to the protection component; The protection component performs a digest operation based on a national secret algorithm on the target data through the TCM based on the trusted measurement request to obtain a measurement value of the target data; The protection component obtains a measurement result of the target data based on the measurement value of the target data and a reference value of the target data.
5. The method according to claim 4, characterized in that Before the computing component sends the trustworthiness metric request for the target data to the protection component, the method further includes: The calculation component sends a reference value acquisition request for the target data to the protection component; Based on the reference value acquisition request, the protection component performs a digest operation based on a national secret algorithm on the target data through the TCM to obtain a reference value of the target data.
6. The method according to claim 5, characterized in that Before the calculation component sends the reference value acquisition request for the target data to the protection component, the method further includes: The computing component sends address information of a target memory area serving the computing component to the protection component; The protection component performs a digest operation based on a national secret algorithm on the data in the target memory area based on the address information to obtain a reference value of the calculation component; After a preset time period, the protection component again performs a digest operation based on the national secret algorithm on the data in the target memory area to obtain a metric value of the calculation component; The protection component obtains the measurement result of the computing component based on the baseline value of the computing component and the measurement value of the computing component. If the measurement result of the computing component is used to indicate that the computing component is trustworthy, the protection component allows the computing component to send the baseline value acquisition request and the trustworthy measurement request to the protection component.
7. The method according to any one of claims 4 to 6, characterized in that The computing component sending a trustworthiness measurement request for the target data to the protection component includes: After the computing component determines that the target data meets a preset trust metric condition, the computing component sends a trust metric request for the target data to the protection component, where the trust metric condition includes any one of the following: the target data is accessed or the target data is periodically detected.
8. The method according to any one of claims 1 to 7, characterized in that The method further comprises: The computing component receives a trusted measurement policy from the management device, wherein the trusted measurement policy includes the target data and a control operation for the target data; The computing component sends the trust metric policy to the protection component; If the measurement result of the target data indicates that the target data is untrustworthy, the protection component performs the control operation on the target data.
9. A target device, characterized in that: The target device includes a computing component and a protection component; The computing component is configured to receive a trustworthy certification request for the target device from a management device, and send the trustworthy certification request to the protection component, wherein the management device is configured to manage the target device; The protection component is configured to obtain a measurement result of the target device based on the trusted proof request, where the measurement result is obtained by the protection component performing a trusted measurement on the computing component; The protection component is further configured to process the measurement result, obtain verification information of the measurement result, and send the measurement result and the verification information to the calculation component; The calculation component is further configured to send the measurement result and the verification information to the management device, wherein the verification information is used by the management device to determine whether the measurement result is credible, and the measurement result is used by the management device to determine whether the target device is credible.
10. The target device according to claim 9, wherein: The protection component includes a TCM, and the protection component is used to: performing an expansion operation based on a platform configuration register PCR on the measurement result through the TCM to obtain a PCR reference value of the measurement result; Performing a signature operation on the PCR reference value by the TCM based on the private key of the national secret algorithm to obtain a signature of the PCR reference value, wherein the verification information includes the PCR reference value, the signature, and the public key of the national secret algorithm; Among them, the public key and the signature are used by the management device to determine whether the PCR reference value is credible, the PCR reference value and the PCR check value of the measurement result are used by the management device to determine whether the measurement result is credible, and the PCR check value is obtained by the management device performing a PCR-based expansion operation on the measurement result.
11. The target device according to claim 9 or 10, characterized in that: The computing component includes an untrusted network port, and the computing component is configured to send the measurement result and the verification information to the management device through the untrusted network port.
12. The target device according to any one of claims 9 to 11, characterized in that: The measurement result is a measurement result of the target data in the calculation component, and the calculation component is further used to send a trusted measurement request for the target data to the protection component; The protection component is further configured to perform a digest operation based on a national secret algorithm on the target data through the TCM based on the trusted measurement request to obtain a measurement value of the target data; The protection component is further configured to obtain a measurement result of the target data based on the measurement value of the target data and a reference value of the target data.
13. The target device according to claim 12, wherein: The calculation component is further configured to send a reference value acquisition request for the target data to the protection component; The protection component is further configured to perform a digest operation based on a national secret algorithm on the target data through the TCM based on the reference value acquisition request to obtain the reference value of the target data.
14. The target device according to claim 13, wherein: The computing component is further configured to send address information of a target memory area serving the computing component to the protection component; The protection component is further configured to perform a digest operation based on a national secret algorithm on the data in the target memory area based on the address information to obtain a reference value of the calculation component; The protection component is further configured to perform a digest operation based on a national secret algorithm on the data in the target memory area again after a preset period of time to obtain a metric value of the calculation component; The protection component is further used to obtain a measurement result of the computing component based on the baseline value of the computing component and the measurement value of the computing component. If the measurement result of the computing component is used to indicate that the computing component is trustworthy, the protection component allows the computing component to send the baseline value acquisition request and the trustworthy measurement request to the protection component.
15. The target device according to any one of claims 12 to 14, characterized in that: The computing component is configured to send a trust metric request for the target data to the protection component after determining that the target data meets a preset trust metric condition, wherein the trust metric condition includes any one of the following: the target data is accessed or the target data is periodically detected.
16. The target device according to any one of claims 9 to 15, characterized in that: The computing component is further configured to receive a trusted measurement policy from the management device, wherein the trusted measurement policy includes the target data and a control operation for the target data; The computing component is further configured to send the trust measurement policy to the protection component; The protection component is further configured to perform the control operation on the target data if the measurement result of the target data indicates that the target data is untrustworthy.
17. A target device, characterized in that: The target device includes a memory and a processor; the memory stores codes, and the processor is configured to execute the codes. When the codes are executed, the target device executes the method according to any one of claims 1 to 8.
18. A computer storage medium, characterized in that The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 8.
19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 8.