Trusted control system and method based on trusted computing system

Through a trusted control system based on a trusted computing system, fine-grained permission management and real-time monitoring are achieved, solving the problems of insufficient authentication security and insufficiently granular permission management, improving the security and defense capabilities of the system, and adapting to the security needs of complex business scenarios.

CN120785586APending Publication Date: 2025-10-14CHINA SOUTHERN POWER GRID COMPANY
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510887500.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-30
Publication Date
2025-10-14

AI Technical Summary

Technical Problem

Existing technologies in trusted computing have problems such as insufficient authentication security, insufficiently granular permission management, and limited monitoring capabilities of server operating status and suspicious nodes, leading to data loss and insufficient system security.

Method used

A trusted control system based on a trusted computing system is adopted, including a main control unit, a server information management and control unit, a cloud storage unit, an information management unit, a trusted data setting unit, a user authentication module, a policy execution unit, an authority authentication unit, etc. It performs dual authentication through an advanced verification login module and an identity key, and combines fine-grained authority settings to monitor server status in real time and perform operations, forming a complete authentication-execution-monitoring closed loop.

Benefits of technology

It improves the security and defense capabilities of the trusted control system, ensures the trusted execution of control commands, enhances the judgment and authority management of trusted information, prevents the easy loss of encrypted content, and adapts to changes in security requirements in complex business scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785586A_ABST
    Figure CN120785586A_ABST
Patent Text Reader

Abstract

The invention discloses a trusted control system and method based on a trusted computing system, and the system comprises a main control unit. The main control unit comprises a server information management and control unit, a cloud storage unit, an information management unit, a trusted data setting unit, a user side, a user authentication module, a strategy execution unit, an authority authentication unit, an advanced verification login module, an identity key, a display module, a monitoring side and a server side. Through collaborative design of multiple units or modules, fine-grained permission division and effective integration of credible information can be realized, and the credibility and security degree of the credible control system can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the control of a trusted computing system, in particular to a trusted control system and method based on a trusted computing system. BACKGROUND

[0002] Trusted computing is a technical method to fundamentally improve security to solve the insecurity of computer and network structure, technical innovation from logical correctness verification, computing architecture and computing mode, etc. to solve the problem that logical defects are not used by attackers, form the unity of attack and defense contradiction, ensure that the logical combination of completing the computing task is not tampered and destroyed, and realize correct computing.

[0003] Trusted computing is a trusted computing platform supported by a hardware security module widely used in computing and communication systems, and its signing key is a 2048-bit RSA public and private key pair, which is randomly generated when the chip is shipped and cannot be changed. This private key is always in the chip, and the public key is used to authenticate and encrypt sensitive data sent to the chip. However, the prior art has vulnerabilities in the identity verification of the control subject and the device control program, the single identity verification method is insufficient in security, and the monitoring capability of the server running state, the complete state and the suspicious node is limited. In the control of the server and the system, and in the browsing, the data may be lost in an emergency. At the same time, in the multi-level permission management and complex information management and control, the existing scheme is difficult to realize the effective integration of fine-grained permission division and trusted information, and the security and defense capability of the system needs to be improved. SUMMARY

[0004] The purpose of the present application is to provide a trusted control system and method based on a trusted computing system, which realizes the effective integration of fine-grained permission division and trusted information, and improves the trust and security of the trusted control system.

[0005] To achieve the above purpose, the present application provides a trusted control system based on a trusted computing system, which comprises a main control unit, the main control unit comprises a server information management and control unit, a cloud storage unit, an information management unit, a trusted data setting unit, a user end, a user authentication module, a policy execution unit, a permission authentication unit, a high-level verification login module, an identity secret key, a display module, a monitoring end and a server end.

[0006] The server information management unit is used for monitoring and managing the currently used server; the cloud storage unit is used for storing the information of the main control unit; the information management unit is used for managing the information stored in the cloud storage unit; the trusted data setting unit is used for setting the trusted data of the main control unit based on the information stored in the cloud storage unit; the user authentication module is used for authenticating the user logged in by the user end; the policy execution unit is used for executing the operation of the user end and the monitoring end; the permission authentication unit is used for authenticating the operation permission of the user end; the high-level verification login module and the identity secret key are used for identity authentication by the permission authentication unit; and the display module is used for displaying the operation permission of the currently logged in user.

[0007] Optionally, the information management unit comprises a trusted computing unit, and the trusted computing unit comprises an information labeling module, an information receiving module, an information judging module, an information comparing module and an information authenticating module.

[0008] The information labeling module is used for labeling trusted information; the information receiving module is used for receiving the labeled trusted information; the information judging module is used for judging and processing the received labeled trusted information to obtain an information judging processing result; the information comparing module compares the trusted information based on the information judging processing result; and the information authenticating module authenticates the current information as trusted information.

[0009] Optionally, the information judging processing result comprises trusted and safe, trusted but risky, untrusted but not malicious, or untrusted and threatening.

[0010] Optionally, the information comparing module is specifically used for:

[0011] When the information judging processing result is trusted and safe, the digital fingerprint of the current information is compared with the pre-stored trusted information reference value in the cloud storage unit to judge the allowed range of the current information;

[0012] When the judging result is trusted but risky, the difference between the current operation permission and the user's level of authority is compared to judge the allowed range of the current information;

[0013] When the judging result is untrusted but not malicious, the current information is compared with the pre-set low-risk untrusted information library to judge the allowed range of the current information;

[0014] When the judging result is untrusted and threatening, the current information is matched with a threat feature library after connecting to the network to judge the allowed range of the current information.

[0015] Optionally, the information management unit further comprises a customer information management unit, the customer information management unit comprising a customer management unit, a device information management unit, an internal information management unit, a service management module, an information management module, and a cooperation management module;

[0016] The customer management unit is configured to manage customer information; the device information management unit is configured to manage device information; the internal information management unit is configured to manage internal information; the service management module is configured to manage corresponding services based on the customer management unit, the device information management unit, and the internal information management unit; the information management module is configured to uniformly manage information based on the customer management unit, the device information management unit, and the internal information management unit; and the cooperation management module is configured to manage overall cooperation based on the customer management unit, the device information management unit, and the internal information management unit.

[0017] Optionally, the policy execution unit comprises a rejection execution module, an application module, a feedback module, and an execution module.

[0018] The rejection execution module is configured to reject execution of an operation to obtain a rejection execution result; the application module is configured to perform an application operation based on the rejection execution result to obtain an application result; the feedback module is configured to perform feedback based on the application result to obtain a feedback result; and the execution module is configured to perform re-execution of the rejection execution module based on the feedback result.

[0019] Optionally, the trusted data setting unit comprises a trusted secret key setting module, a trusted decryption setting module, a trusted user setting module, a trusted user adding module, a permission setting module, a browsable content setting module, and an encrypted content setting module.

[0020] The trusted secret key setting module is configured to set a trusted secret key of the master unit; the trusted decryption setting module is configured to set a decryption system of the master unit; the trusted user setting module is configured to set a trusted user of the master unit; the trusted user adding module is configured to add a trusted user of the master unit; the permission setting module is configured to set permissions of a management layer, an operation layer, and an execution layer; the browsable content setting module is configured to set browsable content based on the permissions set by the permission setting module; and the encrypted content setting module is configured to view encrypted content based on the permissions set by the permission setting module.

[0021] Optionally, the permission authentication unit comprises a login permission setting module, an access permission setting module, an application permission setting module, a management and control permission setting module, an adding permission setting module, and a deletion permission setting module.

[0022] The login permission setting module is used for setting login permissions of the master unit; the access permission setting module is used for setting access permissions of the master unit; the application permission setting module is used for setting application permissions of the master unit; the control permission setting module is used for setting control permissions of the master unit; the adding permission setting module is used for adding permissions of the master unit; and the deleting permission setting module is used for deleting permissions of the master unit.

[0023] Optionally, the server information control unit comprises a running state control module, a complete state detection module and a suspicious node monitoring module.

[0024] The running state control module is used for controlling a running state of a currently used server; the complete state detection module is used for detecting a state of the currently used server; and the suspicious node monitoring module is used for monitoring suspicious nodes in use of the currently used server.

[0025] To achieve the above object, the application further provides a trusted control method based on a trusted computing system, applied to the trusted control system based on the trusted computing system, and comprising the following steps:

[0026] The advanced verification login module and the identity secret key are set, and after the setting is completed, the permission setting is performed through the permission authentication unit;

[0027] The trusted data is set through the trusted data setting unit;

[0028] The current server is managed through the server information control unit;

[0029] When a user input by the user end is authenticated through the permission authentication unit, corresponding policy execution is performed according to the permission of the user through the policy execution unit, the permission of the user is displayed through the display module, and all user operations are monitored through the monitoring end;

[0030] When the user end operation is rejected, the policy execution unit initiates an application request and judges an execution state of the operation.

[0031] Compared with the prior art, the application provides a trusted control system and method based on a trusted computing system, which verifies the identity of a control subject and a device control program, ensures trusted execution of a control command, can enhance the security and defense capability of the trusted control system, solves the trusted problem of the control program in an emergency, provides an effective control mechanism for the trusted computing field, and further improves the overall trusted and security level based on the management and control of customers, devices and internal information, can mark and authenticate trusted information based on the environment and needs, effectively improves the judgment of trusted information, sets the permission based on the trusted level, and ensures that the encrypted content will not be easily lost. BRIEF DESCRIPTION OF DRAWINGS

[0032] In order to more clearly illustrate the technical solutions of the application, the drawings used in the embodiments will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the application, and other drawings can be obtained by those skilled in the art without creative effort based on these drawings.

[0033] Figure 1 is a structural block diagram of a trusted control system based on a trusted computing system provided by an embodiment of the application;

[0034] Figure 2 is a structural block diagram of a server information management and control unit provided by an embodiment of the application;

[0035] Figure 3 is a structural block diagram of an information management unit provided by an embodiment of the application;

[0036] Figure 4 is a structural block diagram of a trusted data setting unit provided by an embodiment of the application;

[0037] Figure 5 is a structural block diagram of a policy execution unit provided by an embodiment of the application;

[0038] Figure 6 is a structural block diagram of a permission authentication unit provided by an embodiment of the application;

[0039] Figure 7 is a flowchart of a trusted control method based on a trusted computing system provided by an embodiment of the application. DETAILED DESCRIPTION

[0040] With reference to the drawings of the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments of the present application, all the other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of the present application.

[0041] Referring to Figure 1 , Figure 1 is a structural block diagram of a trusted control system based on a trusted computing system provided by the embodiments of the present application. The trusted control system based on the trusted computing system comprises a master control unit 100, which comprises a server information management and control unit 101, a cloud storage unit 102, an information management unit 103, a trusted data setting unit 104, a user end 105, a user authentication module 106, a policy execution unit 107, an authority authentication unit 108, an advanced verification login module 109, an identity secret key 110, a display module 111, a monitoring end 112 and a server end 113.

[0042] The output end of the cloud storage unit 102 is connected with the input end of the information management unit 103 and the input end of the trusted data setting unit 104 respectively. The output end of the user end 105 is connected with the input end of the user authentication module 106. The output end of the user authentication module 106 is connected with the input end of the user end 105 and the input end of the policy execution unit 107. The output end of the policy execution unit 107 is connected with the input end of the authority authentication unit 108. The output end of the identity secret key 110 is connected with the input end of the advanced verification login module 109. The output end of the advanced verification login module 109 is connected with the input end of the authority authentication unit 108. The output end of the authority authentication unit 108 is connected with the input end of the display module 111. The output ends of the authority authentication unit 108 and the display module 111 are connected with the input end of the monitoring end 112. The output end of the monitoring end 112 is connected with the input end of the server end 113.

[0043] The server information management unit 101 is used for monitoring and managing the currently used server; the cloud storage unit 102 is used for storing the information of the main control unit; the information management unit 103 is used for managing the information stored in the cloud storage unit 102, wherein the information includes the operation of the user terminal 105, the monitoring data of the monitoring terminal 112 and the log and operation of the server terminal 113; the trusted data setting unit 104 is used for setting the trusted data of the main control unit based on the information stored in the cloud storage unit 102; the user authentication module 106 is used for authenticating the user logged in by the user terminal 105; the policy execution unit 107 is used for executing the operation of the user terminal 105 and the monitoring terminal 112; the permission authentication unit 108 is used for authenticating the operation permission of the user terminal 105; the advanced verification login module 109 and the identity secret key 110 are used for identity authentication through the permission authentication unit 108; and the display module 111 is used for displaying the operation permission of the currently logged-in user.

[0044] Exemplarily, first, the security administrator can obtain the latest system configuration from the cloud storage unit through the trusted data setting unit, configure a new trusted user fingerprint template, and upload it to the cloud storage unit. Then, the new trusted user template is synchronized to the user authentication module of each server through the information management unit. The user authentication module uses the new fingerprint template in subsequent login verification.

[0045] Further, when the user inputs the username / password through the mobile terminal application user terminal, the user authentication module is triggered. The user authentication module verifies the validity of the username / password, and requests the user to perform fingerprint identification. After verification, the user authentication module generates a temporary token and sends it to the policy execution unit. If the user is a senior management personnel, the system automatically triggers the advanced verification login module, requiring the insertion of the USB Key and the input of the dynamic password. The permission authentication unit verifies the identity secret key in the USB Key and the dynamic password, and grants higher permission after confirming the legality. The display module displays the permission range of the user in the interface. When the user initiates a data query request, the policy execution unit verifies the permission and executes the operation, and returns the result to the user terminal.

[0046] Referring to Figure 2 , Figure 2 is a structural block diagram of a server information management unit provided by an embodiment of the present application. As shown in Figure 2 , the server information management unit 101 comprises a running state management module 1011, a complete state detection module 1012 and a suspicious node monitoring module 1013;

[0047] An output end of the running state management module 1011 is connected with an input end of the complete state detection module 1012 and an input end of the suspicious node monitoring module 1013.

[0048] The running state management module 1011 is used for managing the running state of the currently used server; the complete state detection module 1012 is used for detecting the state of the currently used server; and the suspicious node monitoring module 1013 is used for monitoring the suspicious node when the currently used server is used.

[0049] Exemplarily, the server information management unit collects the CPU usage rate of the database server in real time, and when it is found that the CPU usage rate suddenly rises and exceeds the preset threshold, it is determined that an exception occurs, and the exception information is sent to the monitoring end, and the monitoring end automatically triggers an alarm.

[0050] Referring to Figure 3 , Figure 3 is a structural block diagram of an information management unit provided by an embodiment of the application, as Figure 3 shown, the information management unit 103 includes a trusted computing unit 1031, and the trusted computing unit 1031 includes an information labeling module 10311, an information receiving module 10312, an information judging module 10313, an information comparing module 10314 and an information authentication module 10315.

[0051] An output end of the information labeling module 10311 is connected with an input end of the information receiving module 10312, an output end of the information receiving module 10312 is connected with an input end of the information judging module 10313, an output end of the information judging module 10313 is connected with an input end of the information comparing module 10314, an output end of the information comparing module 10314 is connected with an input end of the information authentication module 10315, and an output end of the information authentication module 10315 is connected with an input end of the information labeling module 10311.

[0052] The information labeling module 10311 is used for labeling trusted information; the information receiving module 10312 is used for receiving the labeled trusted information; the information judging module 10313 is used for judging and processing the received labeled trusted information to obtain an information judging processing result; the information comparing module 10314 compares the trusted information based on the information judging processing result; and the information authentication module 10315 is used for authenticating the current information as trusted information.

[0053] In an optional embodiment, the information judging processing result includes trusted and safe, trusted but risky, untrusted but not malicious, or untrusted and threatening.

[0054] It should be noted that, after the trusted computing unit is verified, the digital signature carried by the certain document matches the preset trusted secret key, and the content is not tampered, it is determined that the information is trusted and safe; if the user terminal applies to access the encrypted file, the identity is authenticated by the trusted user (trusted), but the current operation period exceeds the user authority range (risk), it is determined that the information is trusted but there is risk, and further verification is required; if the external device accesses the system, it does not carry a trusted secret key (untrusted), but no virus or attack behavior is detected (no maliciousness), it is determined that the information is untrusted but no maliciousness, and the access can be temporarily monitored; if a certain IP address frequently attempts unauthorized login and carries abnormal code, it is determined that the information is untrusted and there is threat, and the access is directly refused.

[0055] The information comparison module 10314 is specifically configured to:

[0056] When the information judgment processing result is trusted and safe, the digital fingerprint of the current information is compared with the pre-stored trusted information reference value in the cloud storage unit to determine the allowed range of the current information;

[0057] When the judgment result is trusted but there is risk, the difference between the current operation authority and the user's level authority is compared to determine the allowed range of the current information;

[0058] When the judgment result is untrusted but no maliciousness, the current information is compared with the pre-set low-risk untrusted information library to determine the allowed range of the current information;

[0059] When the judgment result is untrusted and there is threat, the current information is matched with the threat feature library after connecting to the network to determine the allowed range of the current information.

[0060] It should be noted that the relationship between the current information and the compared information is a reference comparison relationship. The pre-stored trusted information in the cloud storage unit, such as the trusted secret key, the legal user authority list, and the safe instruction template, is the reference for information comparison. The current information needs to match these reference data or be within the allowed difference range to pass the authentication. During the comparison process, real-time data such as the user's current operation environment and device state can be combined to adjust the comparison strategy. For example, when the same user applies for authority on a commonly used device, the comparison process is simplified; when applying on a strange device, the device trustworthiness needs to be verified additionally.

[0061] As shown in Figure 3 The information management unit 103 further includes a customer information management unit 1032, which includes a customer management unit 10321, a device information management unit 10322, an internal information management unit 10323, a service management module 10324, an information management module 10325, and a collaboration management module 10326.

[0062] The output ends of the customer management unit 10321, the equipment information management unit 10322 and the internal information management unit 10323 are connected with the input ends of the service management module 10324, the information management module 10325 and the cooperation management module 10326;

[0063] The customer management unit 10321 is used for managing customer information; the equipment information management unit 10322 is used for managing equipment information; the internal information management unit 10323 is used for managing internal information; the service management module 10324 is used for managing corresponding services based on the customer management unit 10321, the equipment information management unit 10322 and the internal information management unit 10323; the information management module 10325 is used for uniformly managing information based on the customer management unit 10321, the equipment information management unit 10322 and the internal information management unit 10323; and the cooperation management module 10326 is used for managing overall cooperation based on the customer management unit 10321, the equipment information management unit 10322 and the internal information management unit 10323.

[0064] It is worth noting that the customer information management unit can realize service automation, cross-department cooperation and data-driven decision-making by integrating customer, equipment and internal information, so as to improve operation efficiency and service quality and adapt to multi-industry scenarios.

[0065] Referring to Figure 4 , Figure 4 is a structural block diagram of a trusted data setting unit provided by an embodiment of the present application. As shown in Figure 4 , the trusted data setting unit 104 includes a trusted key setting module 1041, a trusted decryption setting module 1042, a trusted user setting module 1043, a trusted user adding module 1044, a permission setting module 1045, a browsable content setting module 1046 and an encrypted content setting module 1047;

[0066] The output end of the trusted user setting module 1043 is connected with the input end of the trusted user adding module 1044, and the output end of the permission setting module 1045 is connected with the input end of the browsable content setting module 1046 and the input end of the encrypted content setting module 1047;

[0067] The trusted key setting module 1041 is configured to set a trusted key of the master unit; the trusted decryption setting module 1042 is configured to set a decryption system of the master unit; the trusted user setting module 1043 is configured to set a trusted user of the master unit; the trusted user adding module 1044 is configured to add a trusted user of the master unit; the permission setting module 1045 is configured to set permissions of a management layer, an operation layer and an execution layer; the browsable content setting module 1046 is configured to set browsable content based on the permissions set by the permission setting module; and the encrypted content setting module 1047 is configured to view encrypted content based on the permissions set by the permission setting module.

[0068] Referring to Figure 5 , Figure 5 is a structural block diagram of a policy execution unit provided by an embodiment of the present application, as shown in Figure 5 The policy execution unit 107 includes a rejection execution module 1071, an application module 1072, a feedback module 1073 and an execution module 1074.

[0069] An output end of the rejection execution module 1071 is connected to an input end of the application module, an output end of the application module is connected to an input end of the feedback module, and an output end of the feedback module 1073 is connected to an input end of the execution module 1074 and an input end of the rejection execution module 1071.

[0070] The rejection execution module 1071 is configured to reject execution of an operation to obtain a rejection execution result; wherein the rejection operation includes access rejection, login rejection and permission rejection; the application module is configured to perform an application operation based on the rejection execution result to obtain an application result; the feedback module 1073 is configured to perform feedback based on the application result to obtain a feedback result; and the execution module 1074 is configured to perform re-execution of the rejection execution module 1071 based on the feedback result.

[0071] It should be noted that the triggering scenarios of the rejection execution include:

[0072] Insufficient permissions: a user attempts to access content beyond his / her own level (management layer / operation layer / execution layer) (such as an execution layer user accessing encrypted data); failed identity authentication: failed high-level verification login module or identity key check (such as inputting an incorrect password or an expired key); operation risk early warning: the server information management unit detects a suspicious node or abnormal operation (such as multiple applications for sensitive permissions in a short period of time);

[0073] Referring to Figure 6 , Figure 6 is a structural block diagram of a permission authentication unit provided by an embodiment of the present application, as shown in Figure 6As shown, the permission authentication unit 108 includes a login permission setting module 1081, an access permission setting module 1082, an application permission setting module 1083, a control permission setting module 1084, an addition permission setting module 1085, and a deletion permission setting module 1086.

[0074] The login permission setting module 1081 is configured to set the login permission of the master control unit; the access permission setting module 1082 is configured to set the access permission of the master control unit; the application permission setting module 1083 is configured to set the application permission of the master control unit; the control permission setting module 1084 is configured to set the control permission of the master control unit; the addition permission setting module 1085 is configured to add the permission of the master control unit; and the deletion permission setting module 1086 is configured to delete the permission of the master control unit.

[0075] In summary, the trusted control system based on the trusted computing system provided by the embodiments of the present application modularly splits the functions such as server control, data storage, and permission authentication, which can improve the flexibility and maintainability of the system; the trusted data setting unit dynamically configures the trusted benchmark based on the information of the cloud storage unit, supports real-time updating of trusted data, solves the problem of data update lag in traditional static trusted computing, and adapts to changes in security requirements in complex business scenarios; forms a complete closed loop of "identity authentication-permission verification-operation execution-permission display-real-time monitoring", and enhances the security and defense capability of the system.

[0076] The embodiments of the present application verify the identity of the control subject and the device control program, ensure the trusted execution of the control command, can enhance the security and defense capability of the trusted control system, solve the trusted problem of the control program in an emergency, provide an effective control mechanism for the trusted computing field, perform control of customers, devices, and internal information based on the trusted control, can further improve the overall trust and security level, can mark and authenticate trusted information based on the environment and needs, can effectively improve the judgment of trusted information, set the permission based on the trust level, and ensure that the encrypted content will not be easily lost.

[0077] On the basis of the above-mentioned system item, the embodiments of the method item are correspondingly provided.

[0078] Referring to Figure 7 , Figure 7 is a flowchart of a trusted control method based on a trusted computing system provided by the embodiments of the present application. The trusted control method based on the trusted computing system is applied to the trusted control system based on the trusted computing system as described in any of the above embodiments, and includes steps S1 to S5.

[0079] S1, set up the high-level authentication login module and identity secret key, and set up the permission through the permission authentication unit after the setting is completed;

[0080] S2, set up the trusted data through the trusted data setting unit;

[0081] S3, manage the current server through the server information management and control unit;

[0082] S4, when the user input by the user terminal is authenticated through the permission authentication module, the corresponding policy is executed according to the permission of the user through the policy execution unit, the permission of the user is displayed through the display module, and all user operations are monitored through the monitoring terminal;

[0083] S5, when the user terminal operation is rejected, the policy execution unit initiates an application request and judges the execution state of the operation.

[0084] It should be noted that when the operation is rejected, the user can initiate a second request through the application module, and the specific process is as follows:

[0085] The user submits an application through the system interface, explains the operation purpose, and attaches necessary proof materials (such as approval sheet screenshot, task description document);

[0086] The system automatically extracts the key elements (such as applicant, application permission type, associated operation record) in the application information, and calls the trusted computing unit to verify the credibility of the proof materials (such as checking whether the electronic signature of the approval sheet is valid);

[0087] According to the application type, the approval level is automatically matched, including low-risk application (such as temporary viewing of non-sensitive data): online approval by the immediate superior through the permission authentication unit; high-risk application (such as modifying server configuration, cross-level access): trigger multi-node approval process (management layer + monitoring terminal double confirmation);

[0088] The feedback module informs the user of the approval result (pass / fail) in real time, if it is passed, the execution module automatically updates the temporary permission of the user, and records the operation log for the monitoring terminal to trace back, if it is rejected, the system prompts the reason for rejection, and prohibits re-application until the conditions are met.

[0089] The trusted control method based on the trusted computing system provided by the embodiment of the present application ensures that the user identity is legal and the operation permission is controlled through the dual authentication of the advanced verification login module and the identity secret key, and the fine-grained permission setting of the permission authentication unit, thereby avoiding over-reach access and illegal operation; meanwhile, the server information management and control unit monitors the server state in real time, the policy execution unit executes operation based on the user permission, the display module transparentizes the permission range, the monitoring end audits the user behavior throughout the process, a complete closed loop of 'authentication-execution-monitoring' is formed, and the system defense capability is improved; when the operation is rejected, the application is initiated through the policy execution unit and the permission is dynamically adjusted, the business flexibility is taken into account while the safety is ensured, and the efficiency loss caused by rigid control is reduced; in addition, the trusted data setting unit ensures the trustworthiness of the system core data, combined with the server state monitoring, the data tampering and system anomaly are effectively prevented, and the bottom support is provided for the trusted computing.

[0090] The above is the preferred embodiment of the present application, it should be noted that for those skilled in the art, without departing from the principles of the present application, a number of improvements and refinements can be made, these improvements and refinements are also considered to be within the scope of protection of the present application.

Claims

1. A trusted control system based on a trusted computing system, characterized in that: The main control unit includes a server information management unit, a cloud storage unit, an information management unit, a trusted data setting unit, a user terminal, a user authentication module, a policy execution unit, a permission authentication unit, an advanced verification login module, an identity key, a display module, a monitoring terminal and a server terminal; The server information management and control unit is used to monitor and manage the server currently in use; the cloud storage unit is used to store the information of the main control unit; the information management unit is used to manage the information stored in the cloud storage unit; the trusted data setting unit is used to set the trusted data of the main control unit based on the information stored in the cloud storage unit; the user authentication module is used to authenticate the user logged in by the user terminal; the policy execution unit is used to execute operations of the user terminal and the monitoring terminal; the authority authentication unit is used to authenticate the operation authority of the user terminal; the advanced verification login module and the identity key are used to pass the identity authentication of the authority authentication unit; the display module is used to display the operation authority of the currently logged in user.

2. The trusted control system based on the trusted computing system according to claim 1, characterized in that: The information management unit includes a trusted computing unit, which includes an information marking module, an information receiving module, an information judgment module, an information comparison module and an information authentication module; The information marking module is used to mark the credible information; the information receiving module is used to receive the marked credible information; the information judgment module is used to judge and process the received marked credible information to obtain the information judgment processing result; The information comparison module compares the credible information based on the information judgment processing result; the information authentication module is used to authenticate the credible information of the current information.

3. The trusted control system based on the trusted computing system according to claim 2, characterized in that: The information judgment processing results include credible and safe, credible but with risks, untrustworthy but without malicious intent, or untrustworthy and with threats.

4. The trusted control system based on the trusted computing system according to claim 3, characterized in that: The information comparison module is specifically used to: When the information is judged to be credible and safe, the digital fingerprint of the current information is compared with the credible information reference value pre-stored in the cloud storage unit to determine the allowable range of the current information; When the judgment result is credible but there are risks, the current operation permissions are compared with the permissions of the user's level to determine the allowable range of the current information; When the judgment result is untrustworthy but not malicious, the current information is compared with the preset low-risk untrustworthy information database to determine the allowable range of the current information; When the judgment result is untrustworthy and there is a threat, after connecting to the network, the current information is matched with the threat signature library to determine the allowable range of the current information.

5. The trusted control system based on the trusted computing system according to claim 4, characterized in that: The information management unit further includes a customer information management unit, which includes a customer management unit, a device information management unit, an internal information management unit, a service management module, an information management module and a collaboration management module; The customer management unit is used to manage customer information; the device information management unit is used to manage device information; the internal information management unit is used to manage internal information; the service management module manages corresponding services based on the customer management unit, the device information management unit and the internal information management unit; the information management module performs unified management of information based on the customer management unit, the device information management unit and the internal information management unit; the collaboration management module manages the overall collaboration based on the customer management unit, the device information management unit and the internal information management unit.

6. The trusted control system based on the trusted computing system according to claim 5, characterized in that: The policy execution unit includes a rejection execution module, an application module, a feedback module and an execution module; The rejection execution module is used to reject the execution of the operation and obtain a rejection execution result; the application module performs the application operation based on the rejection execution result and obtains an application result; The feedback module performs feedback based on the application result to obtain a feedback result; the execution module is used to re-execute the rejection execution module based on the feedback result.

7. The trusted control system based on the trusted computing system according to claim 6, characterized in that: The trusted data setting unit includes a trusted key setting module, a trusted decryption setting module, a trusted user setting module, a trusted user adding module, a permission setting module, a browseable content setting module and an encrypted content setting module; The trusted key setting module is used to set the trusted key of the main control unit; the trusted decryption setting module is used to set the decryption system of the main control unit; the trusted user setting module is used to set the trusted users of the main control unit; the trusted user adding module is used to add trusted users of the main control unit; the permission setting module is used to set the permissions of the management layer, the operation layer and the execution layer; the browseable content setting module sets the browseable content based on the permissions set by the permission setting module; the encrypted content setting module views the encrypted content based on the permissions set by the permission setting module.

8. The trusted control system based on the trusted computing system according to claim 7, characterized in that: The authority authentication unit includes a login authority setting module, an access authority setting module, an application authority setting module, a management and control authority setting module, an add authority setting module and a delete authority setting module; The login authority setting module is used to set the login authority of the main control unit; the access authority setting module is used to set the access authority of the main control unit; the application authority setting module is used to set the application authority of the main control unit; The control authority setting module is used to set the control authority of the main control unit; the adding authority setting module is used to add the authority of the main control unit; The deletion permission setting module is used to delete the permission of the main control unit.

9. The trusted control system based on the trusted computing system according to claim 1, wherein: The server information management and control unit includes an operation status management module, a complete status detection module and a suspicious node monitoring module; The operation status control module is used to control the operation status of the currently used server; the complete status detection module is used to detect the status of the currently used server; the suspicious node monitoring module is used to monitor suspicious nodes when the currently used server is in use.

10. A trusted control method based on a trusted computing system, characterized in that: The trusted control system based on the trusted computing system as claimed in any one of claims 1 to 9 comprises: Setting up the advanced authentication login module and identity key, and after the setting is completed, setting up permissions through the permission authentication unit; Setting trusted data through a trusted data setting unit; Manage the current server through the server information management and control unit; When the user input by the user terminal passes the authentication of the authority authentication unit, the policy execution unit executes the corresponding policy according to the authority of the user, the user's authority is displayed through the display module, and all user operations are monitored by the monitoring terminal; When the user-side operation is rejected, the policy execution unit initiates an application request and determines the execution status of the operation.