System customization method and device for code auditing and mobile storage equipment
By integrating a detection module and auditing toolchain into a mobile storage device, environmental fingerprint information is collected, and the target auditing toolchain and security execution strategy are dynamically loaded, solving the problems of low efficiency and difficult environment adaptation in traditional code auditing, and realizing convenient and efficient code auditing.
Patent Information
- Application Number
- CN202510763275.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-09
- Publication Date
- 2025-10-28
AI Technical Summary
In traditional code auditing, engineers need to manually complete complex environment configurations and tool deployments, which is inefficient, error-prone, and lacks adaptability to the operating environment. The existing solutions are also weak in terms of security isolation mechanisms, making it difficult to meet the growing demands for security and flexibility.
By integrating a detection module and audit toolchain into mobile storage devices, environmental fingerprint information is collected. Based on the policy rule base, the target audit toolchain and security execution policy are determined, dynamically loaded, and code auditing is performed in the current running environment, supporting hot updates and real-time adjustments.
It achieves consistency across cross-platform environments, avoids the tedious process of repeated tool configuration, improves the efficiency and security of code audits, and ensures the convenience and accuracy of portable code audits.
Smart Images

Figure CN120850283A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of mobile storage device technology, and in particular to a system customization method, apparatus, and mobile storage device for code auditing. Background Technology
[0002] In the context of digital transformation, code auditing, as a core component of software supply chain security, faces stringent physical isolation requirements and complex environmental adaptation challenges.
[0003] In traditional code auditing, engineers need to manually complete complex environment configuration and tool deployment, which is inefficient, error-prone, and existing solutions generally lack adaptability to the operating environment. Furthermore, the tool update process required for auditing is cumbersome and the security isolation mechanism is weak, making it difficult to meet the growing demands for security and flexibility.
[0004] Currently, no effective solution has been proposed to address the issue of low code auditing efficiency caused by deploying auditing environments in existing technologies. Summary of the Invention
[0005] Therefore, it is necessary to provide a system-customized method, apparatus, and mobile storage device for code auditing to address the aforementioned technical issues.
[0006] In a first aspect, this application provides a system customization method for code auditing, applied to mobile storage devices, the method comprising:
[0007] Based on the detection module integrated in the mobile storage device, environmental fingerprint information of the current operating environment to which the mobile storage device is connected is collected; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated;
[0008] Based on a pre-defined policy rule base, the target audit toolchain and security execution policy corresponding to the environment fingerprint information are determined; among them, the security execution policy represents the trust level of the current operating environment;
[0009] The target audit toolchain and security execution policy are dynamically loaded into the mobile storage device, and after the target audit toolchain and security execution policy are loaded, the code to be audited is audited through the mobile storage device in the current running environment.
[0010] In one embodiment, environmental fingerprint information of the current operating environment is collected, including:
[0011] At least the following environmental information of the current operating environment should be collected: hardware characteristics, firmware information, network environment information, system time status, and disk usage status;
[0012] The current operating environment information is hashed to generate a unique environment fingerprint.
[0013] In one embodiment, the mobile storage device further includes:
[0014] According to the preset classification strategy, at least two partition types and at least two system types are set in the storage space of the mobile storage device, where different system types are used to adapt to different operating environments.
[0015] In one embodiment, determining the secure execution policy includes:
[0016] Based on the trust level of the current operating environment, a corresponding security execution strategy is determined. The security execution strategy includes at least the following three types: Trusted Mode, Standard Mode, and Sandbox Mode. Trusted Mode represents the permission to fully access data in the mobile storage device. Standard Mode represents the isolation of data in the mobile storage device based on a preset standard isolation mechanism. Sandbox Mode represents the isolation of data in the mobile storage device based on a preset sandbox isolation mechanism.
[0017] In one embodiment, after auditing the code to be audited, the method further includes:
[0018] Save the target audit toolchain and security execution policy corresponding to the current operating environment to a removable storage device.
[0019] In one embodiment, after the target audit toolchain and security execution policy are loaded, the code to be audited is audited in the current runtime environment via a removable storage device, including:
[0020] Real-time monitoring of the current operating environment;
[0021] If a change in the current operating environment is detected, the corresponding current audit toolchain and current security execution policy are determined after the change. The current audit toolchain and current security execution policy are dynamically loaded and executed. The code to be audited is then audited via a mobile storage device based on the current audit toolchain and current security execution policy.
[0022] Secondly, this application also provides a system customization device. The device includes:
[0023] The acquisition module is used to connect the mobile storage device to the preset current operating environment and collect the environmental fingerprint information of the current operating environment based on the detection module integrated in the mobile storage device; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated.
[0024] The calculation module is used to determine the target audit toolchain and security execution policy corresponding to the environment fingerprint information based on the preset policy rule base; wherein, the security execution policy represents the trust level of the current operating environment;
[0025] The generation module is used to dynamically load the target audit toolchain and security execution policy into the mobile storage device, and perform audit processing on the code to be audited based on the loaded mobile storage device and the current operating environment.
[0026] Thirdly, this application also provides a mobile storage device, which includes at least one storage partition and a control center, wherein the storage partition stores a preset audit toolchain and a detection module; the control center is connected to the storage partition;
[0027] The control center is used to execute the methods described above.
[0028] In one embodiment, the storage partition includes a persistent storage partition for storing an audit toolchain, a probe module, and a control system corresponding to the mobile storage device. The mobile storage device is equipped with a USB toolchain, which supports hot-update target audit toolchains and security execution policies.
[0029] Fourthly, this application also provides a computer-readable storage medium. The computer-readable storage medium stores a computer program thereon, which, when executed by a processor, performs the following steps:
[0030] Based on the detection module integrated in the mobile storage device, environmental fingerprint information of the current operating environment to which the mobile storage device is connected is collected; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated;
[0031] Based on a pre-defined policy rule base, the target audit toolchain and security execution policy corresponding to the environment fingerprint information are determined; among them, the security execution policy represents the trust level of the current operating environment;
[0032] The target audit toolchain and security execution policy are dynamically loaded into the mobile storage device, and after the target audit toolchain and security execution policy are loaded, the code to be audited is audited through the mobile storage device in the current running environment.
[0033] The aforementioned system customization method, apparatus, and mobile storage device for code auditing, based on a detection module integrated into the mobile storage device, collects environmental fingerprint information of the current operating environment accessed by the mobile device. Based on a preset policy rule base, it determines the target audit toolchain and security execution policy corresponding to the environmental fingerprint information. The target audit toolchain and security execution policy are dynamically loaded into the mobile storage device. After loading, the code to be audited is audited through the mobile storage device in the current operating environment. This solution deeply integrates the code audit toolchain, constructing a ready-to-use portable code auditing environment. Users only need to carry a mobile storage device such as a USB flash drive to conduct code auditing on any bootable device, ensuring cross-platform consistency and avoiding the cumbersome process of repeatedly configuring tools, thus improving the efficiency of code auditing. Attached Figure Description
[0034] Figure 1 This is a flowchart illustrating a system customization method in one embodiment;
[0035] Figure 2 This is a flowchart illustrating the system customization method in a preferred embodiment;
[0036] Figure 3 This is a structural block diagram of a system-customized device in one embodiment. Detailed Implementation
[0037] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0038] In one embodiment, such as Figure 1 As shown, a system customization method for code auditing, applied to mobile storage devices, is provided, including the following steps:
[0039] Step S110: Based on the detection module integrated in the mobile storage device, collect the environmental fingerprint information of the current operating environment to which the mobile storage device is connected; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated.
[0040] The aforementioned mobile storage device can be a device such as a USB flash drive or a portable hard disk. In this application, by integrating the required detection modules, static code analysis, dynamic debugging, and dependency scanning audit toolchains, as well as the system required for the mobile storage device to run, a ready-to-use portable code auditing environment is constructed. In practical applications, users only need to carry a mobile storage device to carry out code auditing work on any device that supports booting, thereby improving the efficiency of code auditing.
[0041] Specifically, the aforementioned mobile storage device integrates a detection module. This module can automatically identify key information such as hardware and firmware characteristics of the current operating environment, thereby obtaining the environmental fingerprint information of the current operating environment. The environmental fingerprint information is a key feature uniquely corresponding to the current operating environment, forming a multi-dimensional information model. This environmental fingerprint information includes, but is not limited to, hardware characteristics, firmware information, network environment information, system time status, and disk usage status of the current application environment. Furthermore, the mobile storage device pre-integrates an audit toolchain. This toolchain includes most commonly used audit tools in existing technologies, and various audit tools are combined according to common audit needs to obtain multiple audit toolchains. For example, combining the existing CodeQL Static Analysis Engine and VS Code (Visual Studio Code) tools results in one audit toolchain. CodeQL tools are used for vulnerability scanning, custom vulnerability patterns, and precise path analysis, while Visual Studio Code tools are used for code editing and debugging. The combination of the two enables a complete audit loop from static code analysis to dynamic debugging verification, significantly improving the efficiency and accuracy of vulnerability detection. For example, the Fortify static code analysis tool can be integrated with IntelliJ IDEA to create an auditing toolchain. Fortify is used for vulnerability scanning (such as command injection, information leakage, insecure deserialization, etc., including but not limited to common security vulnerability detection), supporting deep semantic analysis, vulnerability path tracing, and detailed remediation suggestions. IntelliJ IDEA, on the other hand, is used for efficient code writing, refactoring, and debugging. The combination of the two enables deep integration of security auditing with the daily development environment, creating a closed-loop process from vulnerability discovery and location to remediation, significantly improving the timeliness of vulnerability identification and the efficiency of remediation.
[0042] Step S120: Based on the preset policy rule base, determine the target audit toolchain and security execution policy corresponding to the environment fingerprint information; wherein, the security execution policy represents the trust level of the current operating environment.
[0043] Specifically, the aforementioned policy rule base is a static data resource that stores all rule entries available for decision-making and preset matching logic relationships. In practical applications, the policy rule base includes the mapping relationship between audit toolchains and environmental fingerprint information. Based on the collected environmental fingerprint information of the current operating environment, the corresponding target audit toolchain can be matched.
[0044] Furthermore, the security execution policy is based on environmental fingerprint information and a preset matching logic to determine the trust level requirements. The security execution policy includes execution policies with different protection levels. If the current operating environment is detected to be very secure, the execution policy with the lowest protection level can be matched, such as the trusted mode execution policy. In trusted mode, the audit directory in the mobile storage device is mounted as readable and writable, and the mobile storage device is given full system call permissions. Similarly, if the current operating environment is detected to be highly dangerous, the execution policy with the highest protection level can be matched, such as the isolation mode execution policy. In isolation mode, the information in the mobile storage device is set to readable mode only, and based on Seccomp (Secure Computing Mode) call filtering, only the minimum execution is allowed, etc., thereby preventing information leakage and unauthorized behavior, etc.
[0045] In summary, this embodiment can determine the loading of the target audit toolchain and the switching of security execution strategies corresponding to the trust level by collecting environmental fingerprint information. This application can realize dynamic control and security protection during the operation of mobile storage devices.
[0046] Step S130: Dynamically load the target audit toolchain and security execution policy into the mobile storage device, and after the target audit toolchain and security execution policy are loaded, perform audit processing on the code to be audited in the current running environment through the mobile storage device.
[0047] Specifically, the aforementioned mobile storage device can be equipped with the ToU (Toolchain over USB) protocol, which supports dynamic loading or updating of the audit toolchain on demand during code auditing and has the ability to perform "hot updates" without interrupting operation. In conjunction with the ToU protocol, the selected target audit toolchain and security execution policy are dynamically loaded into the mobile storage device, thereby enabling the auditing of the code to be audited in the current operating environment through the mobile storage device. In practical applications, the code to be audited can be downloaded to the mobile storage device, and the auditing of the code to be audited can be completed with the help of an external operating environment.
[0048] Through steps S110 to S130, the detection module detects the environmental fingerprint information of the current operating environment and determines the corresponding target audit toolchain and security execution policy in the preset policy rule base based on the environmental fingerprint information. Finally, the target design toolchain and security execution policy are dynamically loaded into the mobile storage device. After the target audit toolchain and security execution policy are loaded, the code to be audited is audited in the current operating environment through the mobile storage device. This solution deeply integrates the code audit toolchain, building a portable code audit environment that is ready to use out of the box. Users only need to carry a mobile storage device such as a USB flash drive to carry out code auditing work on any bootable device. This ensures the consistency of the cross-platform environment and avoids the cumbersome process of repeatedly configuring tools, improving the efficiency of code auditing. This application deeply integrates security auditing capabilities with portable devices, meeting enterprise-level code security standards in the field of code auditing.
[0049] In one embodiment, environmental fingerprint information of the current operating environment is collected, including:
[0050] At least the following environmental information of the current operating environment should be collected: hardware characteristics, firmware information, network environment information, system time status, and disk usage status;
[0051] The current operating environment information is hashed to generate a unique environment fingerprint.
[0052] Specifically, this embodiment provides a specific scheme for collecting environmental fingerprint information of the current operating environment, including collecting environmental information of the current operating environment and constructing a multi-dimensional environmental fingerprint model. The collection dimensions include, but are not limited to: hardware feature information, firmware information, network environment information, system time status, and disk usage status. Among them, hardware feature information includes, for example, processor architecture, memory capacity, hard disk type, and read / write bandwidth; firmware information includes, for example, boot mode (BIOS, Basic Input Output System; or UEFI, Unified Extensible Firmware Interface); network environment information includes, for example, whether connected to the network, subnet number, and network management reachability; the above-mentioned system time status includes, but is not limited to, boot time and runtime; the above-mentioned disk usage status includes, but is not limited to, the percentage of available disk space and whether temporary mounting is enabled.
[0053] Based on the above environmental information, a five-tuple model is constructed: Env = (H, F, N, S, T), where H represents hardware characteristic information, F represents firmware information, N represents network environment information, S represents disk usage status, and T represents system time status. A hash value is then calculated based on this five-tuple model to generate a unique identifier, Env_ID, which is the aforementioned environmental fingerprint information. This environmental fingerprint information is used as the retrieval key for subsequent matching. Since the environmental fingerprint information and the corresponding target audit toolchain are stored as key-value pairs in the policy rule base mentioned above, the corresponding target audit toolchain can be efficiently determined after obtaining the unique environmental fingerprint information of the current operating environment.
[0054] In one embodiment, the mobile storage device further includes:
[0055] According to the preset classification strategy, at least two partition types and at least two system types are set in the storage space of the mobile storage device, where different system types are used to adapt to different operating environments.
[0056] Specifically, based on a preset classification strategy, at least two partition types and at least two system types are set in the storage control of the mobile storage device. The specific partition types can be determined by relevant technical personnel according to actual needs. For example, a partition can be set as a persistent partition to ensure that the system configuration and installed audit software of the mobile storage device are not lost after a restart, thereby improving system availability and user experience. The aforementioned system types include, but are not limited to, setting BIOS and UEFI file types in the mobile storage device, thereby enabling the mobile storage device to support dual-mode boot of BIOS and UEFI to adapt to more hardware devices. Different system types are adapted to different operating environments, solving the compatibility problem of traditional Live systems under different hardware environments and improving the universality and stability of the system.
[0057] In one embodiment, determining the secure execution policy includes:
[0058] Based on the trust level of the current operating environment, a corresponding security execution strategy is determined. The security execution strategy includes at least the following three types: Trusted Mode, Standard Mode, and Sandbox Mode. Trusted Mode represents the permission to fully access data in the mobile storage device. Standard Mode represents the isolation of data in the mobile storage device based on a preset standard isolation mechanism. Sandbox Mode represents the isolation of data in the mobile storage device based on a preset sandbox isolation mechanism.
[0059] Specifically, this embodiment includes three security execution strategies. Based on the collected environment fingerprint information of the current operating environment, the corresponding security execution strategy can be determined. These strategies include at least three types: Trusted Mode, Standard Mode, and Sandbox Mode. The corresponding environment trust level is determined based on the environment fingerprint information. According to the environment trust level, the control system of the mobile storage device can automatically switch to the corresponding security execution strategy. Trusted Mode represents a high level of trust in the current operating environment, indicating greater security. The Trusted Mode can be set to allow the operating environment to fully access all tools and data in the mobile storage device, including but not limited to mounting the audit directory of the mobile storage device as read-write, loading the entire audit toolchain, allowing the complete system call scope, and enabling deep interaction with the host system. Standard Mode represents a general level of trust in the current operating environment, indicating some security risks. In this case, a preset standard isolation mechanism is executed. The Standard Isolation Mechanism can be set to activate a certain level of isolation mechanism, including... This includes, but is not limited to, isolating or controlling access to the current operating environment, i.e., the host network (e.g., blocking external network access and allowing only local communication), isolating the network of the mobile storage device from the network of the current application environment, selecting to mount a preset temporary file system on the mobile storage device to avoid long-term data persistence, and restricting the scope of access to data in the mobile storage device; Sandbox mode represents a lower level of trust in the current operating environment, and the corresponding sandbox isolation mechanism can be set to adopt the strictest isolation and restriction mechanism for the mobile storage device system, including mounting the mobile storage device in read-only mode, loading only a minimum subset of encrypted and verified tools, starting kernel-level call filtering mechanisms such as Seccomp, strictly limiting system call capabilities, allowing only the lowest privileges to execute programs in the mobile storage device (such as basic file reading, necessary process calls, etc.), and using preset encryption algorithms to provide high-strength protection for operation data, preventing information leakage and unauthorized behavior, so as to prevent information leakage, tool tampering or unauthorized use to the greatest extent.
[0060] For example, if the network is detected as unreachable and the system is in UEFI secure boot mode, the system will match the "read-only audit toolchain + sandbox mode execution" based on the corresponding relationship stored in the policy rule base; if the code to be audited is detected as a Python script and the current runtime environment has more than 8GB of memory and the network is reachable, the system can choose to load the Pylint and Bandit tool combination and execute the standard security mode.
[0061] In some embodiments, after auditing the code to be audited, the method further includes:
[0062] Save the target audit toolchain and security execution policy corresponding to the current operating environment to a removable storage device.
[0063] Specifically, after determining the target audit toolchain and security execution policy corresponding to the current operating environment, the correspondence between the current operating environment and the target audit toolchain, as well as the correspondence between the current operating environment and the security execution policy, can be saved, and the correspondence in the policy rule base can be updated.
[0064] In some embodiments, after the target audit toolchain and security execution strategy are loaded, the code to be audited is audited in the current runtime environment via a removable storage device, including:
[0065] Real-time monitoring of the current operating environment;
[0066] If a change in the current operating environment is detected, the corresponding current audit toolchain and current security execution policy are determined after the change. The current audit toolchain and current security execution policy are dynamically loaded and executed. The code to be audited is then audited via a mobile storage device based on the current audit toolchain and current security execution policy.
[0067] Specifically, the aforementioned audit toolchain adopts a modular design and supports hot loading and hot unloading through the preset ToU (Toolchain over USB) protocol, and the loading process does not require a system restart.
[0068] In this embodiment, the current running environment and changes in the type of code to be audited can be monitored in real time through a preset scheduling module. If a change in the current running environment is detected, the current audit toolchain and current security execution policy corresponding to the changed current running environment can be determined, and the current audit toolchain and current security execution policy can be dynamically loaded and executed, thereby realizing real-time adjustment of toolchain content and running mode.
[0069] This application provides a system customization method for code auditing. Figure 2 This is a schematic diagram of the system customization method in a preferred embodiment.
[0070] The system customization method in this embodiment is applied to a mobile storage device, which can be a USB flash drive, a portable hard disk, etc.
[0071] Step S210: Create a customized mobile storage device system. Specifically, a customized system can be created according to actual needs, and multiple storage partitions and file system types can be set in the mobile storage device system. In some preferred embodiments, persistent storage partitions can be configured in the mobile storage device system to ensure that the audit toolchain used for code auditing, the detection model used to detect the current operating environment, and the control system corresponding to the mobile storage device can be persistently saved and will not be lost after a restart, improving system availability and user experience. Furthermore, the size of the persistent partition can be optimized according to actual needs to support larger storage space and meet users' data storage requirements. The partition types can be set to persistent partitions, temporary running partitions, etc., and the file system types can be set to BIOS and UEFI, thereby enabling the mobile storage device system to support BIOS and UEFI dual-mode booting to adapt to more hardware devices.
[0072] Step S220 involves integrating a detection module and an auditing toolchain into the mobile storage device. Specifically, this involves integrating a code auditing toolchain, including static code analysis tools, dynamic debugging tools, and dependency scanning tools, into the mobile storage device system and completing the corresponding environment configuration. For example, after the mobile storage device and the currently running host system boot up, the detection module first collects the environment fingerprint information of the current operating environment. Then, using this environment fingerprint information as a query key, the system identifies the target auditing toolchain and corresponding security execution policy corresponding to the environment fingerprint information. Based on the matching results, the system automatically configures the corresponding toolchain files and dependent environments, and starts the corresponding execution mode according to the security execution policy, performing auditing processing on the code to be audited in the current operating environment. This solution allows users to perform code auditing directly on any operating environment (such as a computer) that supports the mobile storage device, without needing to install and configure these tools locally. This improves the convenience and efficiency of code auditing and ensures environmental consistency when performing code auditing on different operating environments, avoiding inconsistencies in audit results caused by environmental differences.
[0073] Step S230 involves backing up the mobile storage devices. Specifically, by combining GNU Parallel and dcfldd (dd forensic variant) tools, the disk data in the customized mobile storage devices is backed up to multiple mobile storage devices. This parallel backup method greatly reduces the complexity of manual operation, and the efficiency and automation of the backup process ensure the consistency and reliability of data in each mobile storage device system, reduce errors that may be caused by human operation, and improve the efficiency of batch production of mobile storage devices.
[0074] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0075] Based on the same inventive concept, this application also provides a system customization apparatus for implementing the system customization method described above. The solution provided by this apparatus is similar to the solution described in the above method; therefore, the specific limitations in one or more system customization apparatus embodiments provided below can be found in the limitations of the system customization method described above, and will not be repeated here.
[0076] In one embodiment, such as Figure 3 As shown, a system customization device is provided, including: an acquisition module 31, a calculation module 32, and a generation module 33, wherein:
[0077] The acquisition module 31 is used to connect the mobile storage device to the preset current operating environment and collect the environmental fingerprint information of the current operating environment based on the detection module integrated in the mobile storage device; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated.
[0078] The calculation module 32 is used to determine the target audit toolchain and security execution policy corresponding to the environment fingerprint information based on a preset policy rule base; wherein, the security execution policy represents the trust level of the current operating environment;
[0079] The generation module 33 is used to dynamically load the target audit toolchain and security execution policy into the mobile storage device, and perform audit processing on the code to be audited based on the loaded mobile storage device and the current operating environment.
[0080] Each module in the aforementioned customized system can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device as software, so that the processor can call and execute the operations corresponding to each module.
[0081] In one embodiment, a mobile storage device is provided, the mobile storage device including at least one storage partition and a control center, wherein the storage partition stores a preset audit toolchain and a detection module; the control center is connected to the storage partition;
[0082] The control center is used to execute the methods described above.
[0083] In some embodiments, the storage partition includes a persistent storage partition, which is used for a storage audit toolchain, a probe module, and a control system corresponding to the mobile storage device; the mobile storage device is equipped with a USB toolchain, which supports a hot update target audit toolchain and a security execution policy.
[0084] Specifically, the storage partition includes a persistent storage partition, which stores an auditing toolchain, a probe module, and a control system corresponding to the mobile storage device for code auditing. Furthermore, the mobile storage device is equipped with a USB toolchain, which uses the ToU (Toolchain over USB) protocol. This protocol supports the dynamic loading or updating of toolchain components on demand during code auditing, providing a "hot update" capability without interrupting operation, thereby significantly improving tool maintenance efficiency and system responsiveness.
[0085] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, wherein the computer-calibrated storage medium is applied to the mobile storage device described above, and the computer program, when executed by a processor, performs the following steps:
[0086] Based on the detection module integrated in the mobile storage device, environmental fingerprint information of the current operating environment to which the mobile storage device is connected is collected; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated;
[0087] Based on a pre-defined policy rule base, the target audit toolchain and security execution policy corresponding to the environment fingerprint information are determined; among them, the security execution policy represents the trust level of the current operating environment;
[0088] The target audit toolchain and security execution policy are dynamically loaded into the mobile storage device, and after the target audit toolchain and security execution policy are loaded, the code to be audited is audited through the mobile storage device in the current running environment.
[0089] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties.
[0090] Those skilled in the art will understand that all or part of the processes in the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium. When executed, the computer program can include the processes of the embodiments described above. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, etc., and are not limited to these.
[0091] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0092] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A system customization method for code auditing, characterized in that, Applied to mobile storage devices, the method includes: Based on the detection module integrated in the mobile storage device, environmental fingerprint information of the current operating environment accessed by the mobile storage device is collected; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated. Based on a preset policy rule base, a target audit toolchain and a security execution policy corresponding to the environment fingerprint information are determined; wherein, the security execution policy characterizes the trust level of the current operating environment; The target audit toolchain and the security execution policy are dynamically loaded into the mobile storage device. After the target audit toolchain and the security execution policy are loaded, the code to be audited is audited through the mobile storage device in the current operating environment.
2. The method according to claim 1, characterized in that, The collection of the environmental fingerprint information of the current operating environment includes: At least the following environmental information of the current operating environment shall be collected: hardware feature information, firmware information, network environment information, system time status, and disk usage status; The environment information of the current operating environment is hashed to generate a unique environment fingerprint.
3. The method according to claim 1, characterized in that, The mobile storage device also includes: According to a preset classification strategy, at least two partition types and at least two system types are set in the storage space of the mobile storage device, wherein different system types are used to adapt to different operating environments.
4. The method according to claim 1, characterized in that, Determining the secure execution policy includes: Based on the trust level of the current operating environment, a corresponding security execution policy is determined, wherein the security execution policy includes at least the following three types: trusted mode, standard mode, and sandbox mode; the trusted mode represents the permission to fully invoke data in the mobile storage device; the standard mode represents the isolation of data in the mobile storage device based on a preset standard isolation mechanism; and the sandbox mode represents the isolation of data in the mobile storage device based on a preset sandbox isolation mechanism.
5. The method according to claim 1, characterized in that, After the code to be audited is audited, the method further includes: The target audit toolchain and the security execution policy corresponding to the current operating environment are saved to the mobile storage device.
6. The method according to claim 1, characterized in that, After the target audit toolchain and the security execution policy are loaded, the audit process for the code to be audited is performed on the mobile storage device in the current operating environment, including: The current operating environment is monitored in real time. If a change in the current operating environment is detected, the corresponding current audit toolchain and current security execution policy are determined based on the changed current operating environment. The current audit toolchain is dynamically loaded and the current security execution policy is executed. The mobile storage device then performs audit processing on the code to be audited based on the current audit toolchain and the current security execution policy.
7. A system customization device, characterized in that, The device includes: An acquisition module is used to connect a mobile storage device to a preset current operating environment and collect environmental fingerprint information of the current operating environment based on a detection module integrated in the mobile storage device; wherein, the mobile storage device has a detection module and an audit toolchain pre-integrated. The calculation module is used to determine the target audit toolchain and security execution policy corresponding to the environment fingerprint information based on a preset policy rule base; wherein, the security execution policy characterizes the trust level of the current operating environment; The generation module is used to dynamically load the target audit toolchain and the security execution policy into the mobile storage device, and perform audit processing on the code to be audited based on the loaded mobile storage device and the current operating environment.
8. A portable storage device, characterized in that, The mobile storage device includes at least one storage partition and a control center, wherein the storage partition stores a preset audit toolchain and a detection module; the control center is connected to the storage partition; The control center is used to perform the method as described in any one of claims 1 to 6.
9. The mobile storage device according to claim 8, characterized in that, The storage partition includes a persistent storage partition, which is used to store the audit toolchain, the detection module, and the control system corresponding to the mobile storage device; the mobile storage device is equipped with a USB toolchain, wherein the USB toolchain supports hot updating of the target audit toolchain and the security execution policy.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 6.